Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » Generic » APT- Advanced Persistent Threat

APT- Advanced Persistent Threat

An Advanced Persistent Threat (APT) is a highly sophisticated and long-lasting cyberattack strategy. In an APT, intruders infiltrate a network covertly, aiming to steal sensitive data over an extended period while avoiding detection.

Key APT objectives:

  • APT attackers target sensitive data like credit card information, bank accounts, passport details, and more.
  • APTs may seek to disrupt an entire system, including cloud resources, by deleting crucial databases.
  • Attackers may gain control of critical websites, potentially impacting stock markets or vital services like hospitals.
  • APTs aim to access essential systems using stolen user credentials.
  • Attackers seek sensitive or incriminating information via intercepted communications.

GhostNet APT

One notable example of an APT is GhostNet. Discovered in March 2009, GhostNet is considered one of the most sophisticated APTs. While its control infrastructure was largely traced to China, the Chinese government denied involvement. 

GhostNet executed attacks by sending spear-phishing emails with malicious files, leading to Trojan horse infections. Once compromised, the attacker could remotely control the infiltrated system, allowing malware downloads and full system control.

Additional reading

Cybersecurity Insurance: Why Every Business Needs It

With cybercrime on the rise, more companies face the threat of data breaches, ransomware attacks, and other cybersecurity incidents. A data breach can harm more than just your computer system. It can tarnish your reputation and jeopardize your customers and employees. Surprisingly, among companies affected by data breaches, 76% say that the impact is as…

Information Security Policy – Everything You Should Know

TL,DR: An information security policy lays the foundation for protecting an organization’s data assets by defining procedures, techniques, and technology for safeguarding confidentiality, integrity, and availability ISO 27001 requires the policy to have management buy-in and mandates that it be shared with all staff. Annex 5 of the standard sets the objectives and must-haves for…

Information Assurance vs Cybersecurity: Differences & Similarities

TL,DR: Information assurance protects information reliability through 5 pillars: availability, integrity, authentication, confidentiality, and non-repudiation. Cybersecurity defends digital assets from cyberattacks and unauthorized access to systems Information assurance takes a broader governance approach covering policies, risk management, compliance, and business continuity. Cybersecurity takes a technical approach using firewalls, antivirus software, and intrusion detection systems Information…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.