- GIGW 3.0
- The Guidelines for Indian Government Websites and Apps, which include the requirement for a security audit clearance before hosting.
- Audit clearance certificate
- The certificate issued after a security audit that allows an application to be hosted in production — from NIC, STQC, or an STQC- or CERT-In-empanelled lab.
- CERT-In-empanelled auditor
- An auditing organisation on CERT-In’s approved list. It may not sub-let or outsource an audit.
- STQC
- Standardisation Testing and Quality Certification, the MeitY directorate that tests and certifies, and empanels laboratories.
- Closure report
- The report at the end of an audit confirming that the findings were remediated or closed.
- Hash value
- A fingerprint of the exact build that was audited, recorded so anyone can tell whether the live application is the one that was cleared.
- SBOM
- A software bill of materials: the list of components and versions inside an application, needed to know what a new vulnerability affects.
- IDOR
- Insecure direct object reference — an application trusting an identifier in a request instead of checking the user may see that record.
- Cloaking
- Showing search engines and visitors different content from what the site’s administrators see, used to hide hijacked pages.
- CCMP
- Cyber Crisis Management Plan — the documented response every State and department is expected to have, deployed and tested.
- State CISO
- The chief information security officer each State or UT is expected to empower, one of MeitY’s four foundational requirements.
- GeM
- The Government e-Marketplace, through which ministries and departments procure goods and services under Rule 149 of the General Financial Rules.