Knowledge
IT glossary
By Redaktion techport.ai, IT-Beratung · Last updated on
Terms from IT projects, vendor conversations and regulation, explained briefly and without jargon. Where we have a page on the subject, it is linked.
- Access concept
- A definition of which role may access which systems and data and why. The basis for granting, withdrawing and regularly reviewing access rights. More on this
- Accessibility
- Designing digital offerings so they can also be used by people with disabilities, for example by keyboard or with a screen reader. Legally required for many offerings in Germany since 2025. More on this
- AI Act
- The European Union regulation on artificial intelligence. It classifies AI systems by risk and attaches graduated duties for providers and deployers to that classification. More on this
- Application landscape
- All applications of a company together with their relationships. A documented landscape answers which system carries which process, where data originates and what is being phased out. More on this
- Backup
- A copy of data and systems made for the purpose of recovery. Not to be confused with archiving, which serves retention over statutory periods. More on this
- Business continuity management
- Planning and preparation to keep critical business processes running during disruption or to resume them quickly. It covers more than technology, particularly fallback procedures and communication. More on this
- Change management
- Two meanings. In the organisation: guiding people through a change. In IT operations: the controlled procedure for changes to productive systems. More on this
- Cloud
- Using IT services over the network rather than from your own data centre, billed by consumption or subscription. The decision for or against is sensibly made per system. More on this
- Criticality
- The importance of a system or process to the business, measured by the impact of an outage. The basis for priorities in operations, backup and emergency planning.
- CRM
- A system for managing customer relationships, contacts, activities and sales opportunities. Frequently the second largest system after the ERP.
- Custom software
- Software developed specifically for one company. Sensible for processes that differentiate the business, risky when it depends on a single person. More on this
- Cyber Resilience Act
- An EU regulation setting cyber security requirements for products with digital elements across their life cycle. It covers manufacturers, importers and distributors, with reporting duties from September 2026.
- Data Act
- An EU regulation on fair access to and use of data, applicable since September 2025. For users it matters mainly because of the rules on changing cloud provider.
- Data migration
- Transferring data from an old system into a new one. It covers analysis, cleansing, transformation rules, test runs and a documented reconciliation after the transfer. More on this
- Data processing agreement
- A contract required under Article 28 GDPR where a service provider processes personal data on your behalf and on your instructions. Responsibility remains with the commissioning company.
- Data protection impact assessment
- An assessment carried out in advance for processing likely to result in a high risk to the rights of the individuals concerned. Provided for in Article 35 GDPR.
- DORA
- An EU regulation on digital operational resilience in the financial sector, applicable since January 2025. It sets requirements for ICT risk management, incident reporting, testing and provider oversight.
- E-invoice
- An invoice in a structured electronic format complying with EN 16931 that can be processed automatically. A PDF without structured data is not an e-invoice. More on this
- EN 16931
- The European standard for the semantic data model of the electronic invoice. In Germany implemented primarily through XRechnung and ZUGFeRD.
- ERP
- A system for running the central business processes, typically orders, purchasing, stock, production and accounting. In most companies the system everything hangs on. More on this
- GDPR
- The General Data Protection Regulation of the European Union. It governs the processing of personal data, including legal bases, individual rights, documentation and technical security measures. More on this
- Integration
- Connecting systems so that data flows without manual transfer. It presupposes that one system is defined as authoritative per data object. More on this
- Interface
- A defined connection through which two systems exchange data. It needs documentation, error handling and monitoring like any other component. More on this
- ISMS
- An information security management system. It combines risk assessment, measures, policies and regular effectiveness reviews into a closed cycle. More on this
- ISO 27001
- The internationally recognised standard for information security management systems. Customers frequently request certification as evidence.
- IT-Grundschutz
- The methodology of the German Federal Office for Information Security for building information security, with concrete requirements per subject area and graduated levels starting from basic protection.
- Legacy system
- An older system still in productive use but technically outdated, often without vendor support and with knowledge held by only a few people. More on this
- Licence audit
- A review by a software vendor of whether the use of their products matches the licences purchased. Back claims frequently arise from indirect usage through interfaces. More on this
- Low-code
- Tools that let you build applications and workflows largely without programming. Useful for simple automation, and needing the same rules as any software. More on this
- Managed service
- Outsourcing the operation of an IT service to a provider with an agreed scope. Steering the provider remains the company's task. More on this
- Master data
- Data used permanently such as customers, suppliers, articles and prices, as opposed to transaction data such as orders and postings. More on this
- MDM
- Mobile device management, used to configure devices, supply them with software, secure them and lock or wipe them if lost. More on this
- Monitoring
- Continuous observation of systems and workflows with the aim of detecting incidents before users notice them. Only effective if alerts reach people who act. More on this
- Multi-factor authentication
- Signing in with at least two independent factors, for example a password and a confirmation on a phone. The most effective single measure against stolen credentials. More on this
- NIS2
- The EU directive on cyber security, implemented in Germany through the NIS2 implementation act and the new BSI Act. It obliges companies in scope to manage risk, report incidents and register. More on this
- On-premises
- Operating systems on your own hardware in your own premises, as opposed to operating in the cloud or at a provider.
- Patch
- A correction or update to software, frequently to close security vulnerabilities. The time until deployment is one of the most informative security metrics.
- Phishing
- An attempt to obtain credentials or distribute malware through forged messages. The most common route into company networks. More on this
- Process documentation
- A description of how records relevant for tax purposes are created, captured, processed and retained. In German tax audits it is the evidence of a proper procedure. More on this
- Project portfolio
- All initiatives together with their assessment and sequence. A portfolio is above all a decision about what is not being done right now. More on this
- Ransomware
- Malware that encrypts data and demands a ransom. The most common severe security incident, best countered by separate, non-overwritable backups.
- Record of processing activities
- An overview of all processing of personal data with purpose, categories, recipients and periods. Required under Article 30 GDPR and to be kept current.
- Recovery
- Bringing systems back up after an outage in a defined order. The time required should be measured rather than estimated. More on this
- Requirements specification
- A description of requirements from the client's point of view. The vendor's response setting out how they intend to meet them is the functional specification. More on this
- Rollout
- Introducing a system or a change at scale, including training, communication and support after go-live. More on this
- RPO
- The tolerable data loss, expressed as the time between the last usable backup and the outage. It determines how frequently backups are needed.
- RTO
- The tolerable time until a system is restored after an outage. Together with the RPO it determines the requirements on technology and preparedness.
- Service desk
- A central point of contact for user incidents and requests, with recording, prioritisation and analysis. The basis for fixing causes rather than symptoms. More on this
- Shadow IT
- Software and services procured and used without the knowledge of IT. Usually the consequence of an official route that is too slow, not of rule breaking. More on this
- Single sign-on
- A sign-in method letting users authenticate once and then use several systems. It improves convenience and makes central revocation of access easier.
- SLA
- An agreement on the scope and quality of a service, for example availability and response and restoration times. Without measurement it has no consequence.
- Software bill of materials
- A record of all software components contained in a product, including open source. A precondition for assigning vulnerabilities quickly.
- System owner
- The person in the department responsible for the content of a system, while IT is responsible for technical operations. Without this role IT decides on business questions. More on this
- TISAX
- An assessment and exchange mechanism for information security in the automotive industry, based on the requirements of the German automotive industry association. Regularly required by manufacturers.
- XRechnung
- A format for the electronic invoice widely used in Germany, consisting of pure data. Required by public sector clients.
- Zero trust
- A security approach in which no access is treated as trustworthy merely because it comes from the internal network. Every access is verified and limited to what is needed.
- ZUGFeRD
- A format for the electronic invoice combining a structured file and a readable representation in one PDF. Practical for mixed recipient groups.
A
B
C
D
E
G
I
L
M
N
O
P
R
S
T
X
Z
More from techport.ai
Software
Custom process software for mid-sized companies.
HR consulting
People processes and the systems behind them.
IT maturity check
Ten minutes to a clear position.
HR maturity check
24 statements, a result per field.
Funding
BAFA grant plus more than 50 programmes for delivery.
Process in practice
How workflows become reliable software.
Data and AI
Analysis, forecasts and assistance systems.
About us
The people behind techport.ai.