In these Regulations —“advanced persistent threat” means an adversary, possessing sophisticated levels of expertise, that —
(a) employs advanced techniques; and
(b) demonstrates persistence (for example, by pursuing its objectives repeatedly and over an extended period of time while taking measures to stay undetected),in an effort to jeopardise or adversely affect the cybersecurity of the computer or computer system which it is targeting, for a purpose such as espionage, deception or disruption;ExamplesExamples of advanced techniques are techniques which involve time‑stomping, chaining exploits, attacking system memory, the bypassing or disarming of protective measures, or the use of fileless malware.“indicator of compromise” means a technical artifact or event on a network or system that suggests a cybersecurity incident is imminent or is underway, or that a cybersecurity incident may have already occurred;“interception”, in relation to a communication to or from a relevant computer or computer system, includes —
(a) listening to or the recording of the communication; and
(b) acquiring the substance, meaning or purport of that communication;“quarter” means a period of 3 months beginning on 1 January, 1 April, 1 July or 1 October of any year;“relevant computer or computer system”, in relation to a designated provider responsible for third‑party‑owned critical information infrastructure, means a computer or computer system mentioned in section 16I(4)(a), (b) or (c) of the Act, being —
(a) the third‑party‑owned critical information infrastructure;
(b) a computer or computer system under the owner’s control or the provider’s control, that is interconnected with or that communicates with the third‑party‑owned critical information infrastructure; or
(c) any other computer or computer system under the provider’s control that does not fall within section 16I(4)(b) of the Act;“working day” means any day except a Saturday, Sunday or public holiday;“zero‑day vulnerability” means a hardware, firmware or software weakness, susceptibility or flaw, which can be exploited to jeopardise or adversely affect the cybersecurity of a computer or computer system, that is not previously known to the cybersecurity industry at a relevant point in time, as evidenced by the weakness, susceptibility or flaw not being included in any of the following:
(a) the Common Vulnerabilities and Exposures List published on the Common Vulnerabilities and Exposures Program’s website at https://www.cve.org;
(b) the National Vulnerability Database published on the United States National Institute of Standards and Technology’s website at https://nvd.nist.gov;
(c) the Known Exploited Vulnerabilities Catalog published on the United States Cybersecurity and Infrastructure Security Agency’s website at https://www.cisa.gov/known‑exploited‑vulnerabilities‑catalog;
(d) the European Union Vulnerability Database published on the European Union Agency for Cybersecurity’s website at https://euvd.enisa.europa.eu.