Knowledge base

ICT Management & Technology Glossary

Short, plain-English definitions of the terms used in ICT management — IT assets, infrastructure, networks, cybersecurity, compliance, risk, continuity and Zambian data protection.

3CX
A popular software-based business phone system (IP-PBX) that provides extensions, call queues, IVR, recording and video, running on-premise or in the cloud.
API (Application Programming Interface)
A defined way for software systems to exchange data and functionality, enabling integrations between applications.
Audit Trail
A chronological record of who did what, when and from where in a system, used for accountability, investigation and audit. Its value depends on protecting entries from alteration and retaining them for a defined period. Learn more →
Backup
A copy of data stored separately so it can be restored after loss; a backup is only reliable if it is recent, off-site, protected and tested. Learn more →
Baseboard Management Controller (BMC)
A dedicated management controller on a server that reports hardware health — temperatures, fans, power supplies and disks — and allows remote management independently of the operating system. Examples include Dell iDRAC and HPE iLO. Learn more →
Business Continuity
An organisation's ability to keep delivering its essential services during and after a disruption, covering people and processes as well as technology. Learn more →
Business Continuity Plan (BCP)
A documented plan for keeping critical business activities running during and after a disruption, covering people, premises, suppliers, communication and technology, with roles and recovery steps. Learn more →
Business Impact Analysis (BIA)
An analysis that identifies an organisation's critical activities and how the impact of their disruption grows over time, setting recovery priorities and targets such as MTD, RTO and RPO. Learn more →
Change Management
The controlled process for proposing, assessing, approving, implementing and reviewing changes to IT systems, including a risk assessment and rollback plan, to reduce disruption. Learn more →
CIS Controls
A prioritised set of cybersecurity safeguards published by the Center for Internet Security. Version 8 groups them into 18 controls, beginning with inventories of enterprise and software assets. Learn more →
Cloud Computing
The delivery of computing resources — servers, storage, applications and backup — over the internet, on demand, instead of from hardware you own and maintain.
Cloud Migration
The process of moving an organisation's systems, applications and data from on-premise infrastructure to a cloud platform, ideally in tested phases to minimise downtime.
Compliance Gap Analysis
An assessment comparing the controls an organisation has in place with the requirements of a law, regulation or framework, identifying what is missing and what to fix first. Learn more →
Concentration Risk
The risk that arises when many critical services depend on the same supplier, technology or location, so that a single failure affects all of them at once. Learn more →
Configuration Management Database (CMDB)
A database of configuration items — servers, applications, network devices and services — and the relationships between them, used to assess the impact of changes and incidents. Learn more →
Control Framework
A structured set of security and management controls — such as ISO/IEC 27001 or the CIS Controls — against which an organisation designs, assesses and evidences its practices. Learn more →
Critical Information Infrastructure (CII)
Information or information infrastructure that the Zambia Cyber Security Agency designates as critical by Gazette notice under the Cyber Security Act No. 3 of 2025 (s.9), bringing security, audit and incident-reporting duties. Learn more →
CRM (Customer Relationship Management)
Software that centralises customer data and interactions to manage sales, service and marketing relationships.
CVE (Common Vulnerabilities and Exposures)
A public catalogue of disclosed security vulnerabilities, each with a unique identifier such as CVE-2021-44228. The US National Vulnerability Database adds severity scores and further detail. Learn more →
Cybersecurity
The practice of protecting systems, networks and data from digital attacks such as ransomware, phishing and unauthorised access, using layered technology, processes and people. Learn more →
Data Controller and Data Processor
A data controller decides why and how personal data is processed; a data processor processes it on the controller's behalf. Under Zambia's Data Protection Act 2021 both must register with the Data Protection Commissioner. Learn more →
Data Localisation
A requirement to store and process data within a country's borders. Zambia's Data Protection Act 2021 requires controllers to process and store personal data on a server or data centre in Zambia (s.70(1)), subject to exceptions. Learn more →
Data Protection Act (Zambia)
Zambia's Data Protection Act No. 3 of 2021 regulates personal data processing and established the Office of the Data Protection Commissioner. Controllers and processors must register and secure data; controllers notify breaches within 24 hours (s.49) and, subject to exceptions, keep personal data in Zambia (s.70). Learn more →
Data Protection Impact Assessment (DPIA)
An assessment of the risks a processing activity poses to individuals' personal data and of the measures to address them. Zambia's Data Protection Act 2021 requires one in the circumstances set out in s.46. Learn more →
Data Protection Officer (DPO)
The person responsible for overseeing an organisation's data protection compliance. Zambia's Data Protection Act 2021 requires data controllers and data processors to appoint one (s.48). Learn more →
Digital Transformation
The use of digital technology to fundamentally improve how an organisation operates and delivers value, involving changes to processes and people as well as systems.
Disaster Recovery (DR)
The backups, procedures and infrastructure that restore IT systems and data quickly after a disruption such as hardware failure, ransomware or disaster. Learn more →
Disaster Recovery Exercise
A planned test of disaster recovery arrangements — from a tabletop walkthrough to a full technical restore — comparing actual recovery time and data loss with RTO and RPO targets and recording lessons. Learn more →
Endpoint
Any device that connects to a network — such as a laptop, desktop, server or mobile — and which must be secured against threats.
Endpoint Detection and Response (EDR)
Security software on individual devices that detects, investigates and responds to threats based on behaviour, going beyond traditional signature-based antivirus.
Enterprise Wi-Fi
A managed wireless network using multiple coordinated access points to provide seamless, secure coverage for many users across a large area.
ERP (Enterprise Resource Planning)
Software that integrates core business operations — finance, inventory, HR, procurement — into a single system for real-time visibility.
Firewall
A security device or software that monitors and controls network traffic based on rules, blocking unauthorised access while allowing legitimate traffic.
Flow Monitoring (NetFlow, IPFIX, sFlow)
Analysing summaries of network conversations — source, destination, ports and volume — exported by routers, switches and firewalls. NetFlow, IPFIX and sFlow are the common export formats. Learn more →
Hybrid Cloud
An infrastructure approach that combines on-premise systems with public cloud, keeping some workloads local while using the cloud for others.
ICMP Ping Monitoring
Checking whether a device is reachable, and how quickly it responds, by sending ICMP echo requests at intervals and alerting when replies stop or latency rises. Learn more →
ICT Management
The planning, operation, security and governance of an organisation's information and communication technology — hardware, software, networks, data and communication services — so that it is reliable, secure, compliant and aligned with business needs. Learn more →
Identity and Access Management (IAM)
The policies and technology that control who can access which systems and data, covering accounts, authentication, roles, privileges and periodic access reviews. Learn more →
Immutable Backup
A backup that cannot be altered or deleted for a set period, protecting it from ransomware and ensuring clean data is always recoverable.
Inherent and Residual Risk
Inherent risk is the level of a risk before any controls are applied; residual risk is the level that remains once existing controls and mitigations are taken into account. Learn more →
IP Address Management (IPAM)
The planning and tracking of IP address space — subnets, allocations and reservations — to prevent address conflicts and keep an accurate record of which device uses which address. Learn more →
ISO/IEC 27001
The international standard for information security management systems. The current edition, ISO/IEC 27001:2022, sets requirements for managing information security risk and lists reference controls in Annex A. Learn more →
IT Asset Management (ITAM)
The practice of keeping an accurate record of hardware, software and cloud assets through their lifecycle — ownership, location, cost, licences, dependencies and disposal — to control cost and risk. Learn more →
IT Compliance
Meeting the legal, regulatory, contractual and policy obligations that apply to an organisation's technology and data, and keeping evidence that the required controls are in place. Learn more →
IT Governance
The decision rights, policies, oversight and accountability that direct how an organisation uses technology, so that it supports objectives, manages risk and meets obligations. Governance sets direction; management delivers. Learn more →
IT Infrastructure Management
The monitoring, maintenance and capacity planning of the servers, storage, networks, data centres and cloud resources that applications run on. Learn more →
IT Risk Management
The continuous process of identifying technology risks, assessing their likelihood and impact, treating them and monitoring them, recorded in a risk register with owners and actions. Learn more →
Known Exploited Vulnerabilities (KEV) Catalog
A list maintained by the US Cybersecurity and Infrastructure Security Agency (CISA) of vulnerabilities confirmed to be exploited in real attacks, widely used to prioritise patching. Learn more →
Managed IT Services
The ongoing, outsourced management of an organisation's technology by a specialist provider for a fixed monthly fee, covering monitoring, support, security, patching and backup.
Managed Service Provider (MSP)
A company that remotely manages a customer's IT infrastructure and end-user systems proactively under a subscription and service-level agreement.
Maximum Tolerable Downtime (MTD)
The longest a business activity can be unavailable before the impact becomes unacceptable. Recovery time objectives for the systems supporting it must be shorter than the MTD. Learn more →
Microsoft 365
A Microsoft cloud subscription bundling email, Office applications, file storage and security features for collaboration from anywhere.
MITRE ATT&CK
A publicly available knowledge base of adversary tactics and techniques observed in real attacks, used to describe threats, map detections and identify coverage gaps. Learn more →
Multi-Factor Authentication (MFA)
A security method that requires two or more proofs of identity — such as a password plus a code from a phone — significantly reducing account-takeover risk.
Network Detection and Response (NDR)
Security technology that analyses network traffic, often flow records, to detect suspicious behaviour such as port scans, command-and-control beaconing, lateral movement or data exfiltration, and to support investigation. Learn more →
Network Monitoring
The continuous observation of network devices, links and traffic to detect faults and performance problems before users are affected. Learn more →
NIST Cybersecurity Framework (CSF)
A voluntary framework from the US National Institute of Standards and Technology for managing cybersecurity risk. Version 2.0 groups outcomes into six functions: Govern, Identify, Protect, Detect, Respond and Recover. Learn more →
Office of the Data Protection Commissioner
The regulator established under s.4 of Zambia's Data Protection Act No. 3 of 2021, within the ministry responsible for communications, to regulate data protection and privacy, including registering data controllers and processors. Learn more →
Patch Management
The scheduled process of applying updates to operating systems and applications to fix security vulnerabilities and improve stability. Learn more →
PCI DSS
The Payment Card Industry Data Security Standard, which sets security requirements for organisations that store, process or transmit payment card data. Version 4.0 is the current major version. Learn more →
Penetration Testing
An authorised, simulated attack on systems or applications to find exploitable weaknesses and demonstrate their impact, followed by a report of findings and recommended fixes. Learn more →
Personal Data Breach
A security incident leading to the loss, alteration, unauthorised disclosure of or access to personal data. In Zambia, data controllers must notify the Data Protection Commissioner within 24 hours (Data Protection Act 2021, s.49). Learn more →
Phishing
A cyber-attack that uses fraudulent emails or messages to trick people into revealing credentials or installing malware; it is the most common entry point for breaches.
Policy Management
Drafting, approving, publishing, communicating and periodically reviewing an organisation's policies, with version history and records of who has acknowledged each version. Learn more →
Privileged Access Management
Controls for administrator and other high-risk accounts, such as granting elevated rights only when needed, for a limited time, with approval and logging. Learn more →
Ransomware
Malicious software that encrypts an organisation's files and systems and demands payment for their release; recovery is best assured through tested, immutable backups.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss, measured in time; an RPO of one hour means backups must run at least hourly. Learn more →
Recovery Time Objective (RTO)
The maximum acceptable time to restore a system after an outage; it drives the design of the recovery solution. Learn more →
Redfish and IPMI
Standard interfaces for communicating with a server's baseboard management controller. IPMI is the older protocol; Redfish is its modern, RESTful successor published by the DMTF. Learn more →
Risk Matrix
A grid, commonly five by five, that scores a risk by combining likelihood and impact and bands the result — for example low, medium, high or critical — to prioritise treatment. Learn more →
Risk Register
A record of identified risks with their description, owner, likelihood, impact, score before and after controls, treatment actions and next review date. Learn more →
Security Awareness Training
Education that helps staff recognise and report threats such as phishing and social engineering and follow security policies, typically delivered as courses with assessments. Learn more →
Service Level Agreement (SLA)
A formal agreement defining the level of service to be delivered, including response and resolution times, availability targets and responsibilities.
Single Point of Failure (SPOF)
Any component, supplier or person whose failure alone would stop a service, because there is no redundancy or alternative in place. Learn more →
SMS Gateway
A service that lets applications send and receive text messages programmatically, used for alerts, one-time passwords and notifications.
SOC 2
An attestation report, based on the AICPA Trust Services Criteria, in which an independent auditor examines a service organisation's controls for security and, optionally, availability, processing integrity, confidentiality and privacy. Learn more →
Software Licence Management
Tracking software entitlements, seats, renewal dates and terms against actual deployment, so an organisation stays within licence terms and avoids paying for unused licences. Learn more →
Structured Cabling
A standardised, organised approach to installing network cabling in a building, ensuring reliable, high-performance and easily-maintained connectivity.
Syslog
A standard protocol (RFC 5424, and the earlier RFC 3164) that devices and applications use to send event and log messages to a central collector for storage and analysis. Learn more →
USSD (Unstructured Supplementary Service Data)
A GSM technology behind menu-based mobile services accessed by dialling codes like *123#, working on any phone without internet or an app.
Vendor Management
Managing relationships with technology suppliers — contracts, service levels, renewals, performance and risk — so that third parties deliver what was agreed without creating unmanaged risk. Learn more →
Virtualization
Technology that runs multiple independent virtual servers on a single physical machine, improving efficiency, flexibility and recoverability.
VoIP (Voice over Internet Protocol)
Technology that carries phone calls over the internet instead of traditional phone lines, reducing costs and adding features like call queues and mobile apps.
VPN (Virtual Private Network)
An encrypted connection over the internet that securely links remote users or sites to an organisation's network.
Vulnerability Scanning
Automated testing of systems and applications for known weaknesses — missing patches, outdated service versions and insecure configurations — producing findings to prioritise and fix. Learn more →
Zambia Cyber Security Agency
The agency established in the Office of the President by s.3 of the Cyber Security Act No. 3 of 2025; the same Act repealed the Cyber Security and Cyber Crimes Act, 2021 (s.73). It designates critical information infrastructure and receives incident reports. Learn more →

Manage these disciplines in one place

Ontech ICTM brings IT assets, monitoring, security, compliance, risk and continuity together. Book a walkthrough or start a free trial.