Reference

IT Glossary for South African Businesses

This glossary defines 34 IT, cybersecurity, cloud and compliance terms that South African business owners and nonprofit leaders meet when buying or managing technology, written in plain English by the AMEA Technologies engineering team.

What is Managed IT services?

Managed IT services is the outsourcing of a company's day-to-day IT support, monitoring, maintenance and administration to a specialist provider for a fixed monthly fee.

In South Africa it is usually priced per user or per device and replaces break-fix support, where you pay per incident after something has already failed.

Managed IT services

What is MSP (managed service provider)?

An MSP, or managed service provider, is a company that remotely manages a client's IT infrastructure and end-user systems on an ongoing contract.

AMEA Technologies operates as an MSP for businesses and nonprofits across South Africa, with on-site support in Gauteng.

Managed IT services

What is Fractional CIO?

A Fractional CIO is a senior technology executive who provides part-time, ongoing IT leadership, owning the technology roadmap, budget, vendor relationships and governance for a fraction of a full-time CIO's cost.

Typical cost is 30 to 50 percent of a full-time CIO, and the role is independent of any hardware or licence quota.

Fractional CIO services

What is vCIO (virtual CIO)?

A vCIO, or virtual CIO, is an advisory role, usually offered by a managed service provider, that reviews a client's IT strategy periodically without owning the budget.

The difference from a Fractional CIO is ownership and independence: a vCIO advises from inside the provider it would need to hold accountable.

Fractional CIO vs vCIO

What is POPIA?

POPIA, the Protection of Personal Information Act, is South Africa's data protection law, in force since 1 July 2021, that governs how organisations collect, store, process and secure personal information.

It requires reasonable security measures, an appointed Information Officer, a PAIA manual and breach notification to the Information Regulator and affected people.

POPIA compliance services

What is Information Officer?

An Information Officer is the person legally responsible under POPIA for an organisation's compliance, by default the head of the organisation, who must be registered with the Information Regulator.

Duties can be delegated to deputy Information Officers, but accountability stays with the head of the organisation.

POPIA compliance guide

What is PAIA manual?

A PAIA manual is the document every South African organisation must publish under the Promotion of Access to Information Act, describing what records it holds and how people can request access to them.

Since POPIA, the manual also has to describe the purposes of processing and the security measures in place.

Policy and documentation

What is Multi-factor authentication (MFA)?

Multi-factor authentication (MFA) is a login control that requires a second proof of identity, such as an app prompt or hardware key, in addition to a password.

Microsoft reports that MFA blocks more than 99 percent of automated account-compromise attacks, which makes it the highest-value security control most businesses can enable.

Cybersecurity services

What is Phishing?

Phishing is a fraudulent message, usually email, designed to trick the recipient into revealing credentials, approving a payment or opening malware.

Variants include spear phishing (targeted), whaling (aimed at executives), smishing (SMS), vishing (voice) and quishing (QR codes).

Phishing prevention guide

What is Business email compromise (BEC)?

Business email compromise (BEC) is a scam in which an attacker impersonates or takes over a business email account to redirect payments or steal data.

Invoice fraud aimed at finance teams is the most common form in South Africa, and MFA plus payment verification procedures are the primary defences.

Cybersecurity services

What is Ransomware?

Ransomware is malware that encrypts an organisation's files and systems and demands payment for the decryption key, often also stealing data to extort a second payment.

Modern ransomware deliberately seeks out and encrypts backups first, which is why immutable, off-site backups are the recovery control that matters.

Backup and disaster recovery

What is Endpoint protection (EDR)?

Endpoint protection is security software on laptops, desktops and servers that detects and blocks malware; endpoint detection and response (EDR) adds behaviour monitoring and the ability to isolate a compromised device.

It replaces traditional antivirus, which only matches known file signatures.

Cybersecurity services

What is Zero trust?

Zero trust is a security model in which no user or device is trusted by default, and every access request is verified against identity, device health and context.

In practice it means MFA everywhere, device compliance checks and access to specific applications rather than the whole network.

Secure remote access

What is ISO 27001?

ISO 27001 is the international standard for an information security management system (ISMS), specifying how an organisation identifies, manages and reduces information security risk.

South African businesses usually align to it to satisfy enterprise customers and tenders rather than certifying immediately.

ISO 27001 alignment

What is CIS Controls?

The CIS Controls are a prioritised set of 18 safeguards published by the Center for Internet Security that describe the most effective actions for defending against common cyber attacks.

Implementation Group 1 is the recommended baseline for small and mid-sized businesses.

CIS Controls mapping

What is Security risk assessment?

A security risk assessment is a structured review of an organisation's defences against common attack paths, producing a risk rating and a prioritised plan to close the gaps.

AMEA's assessment covers identity and MFA, patching, backups, endpoint protection, email security, access control and staff awareness.

Security risk assessment

What is Incident response plan (IRP)?

An incident response plan (IRP) is a documented procedure for detecting, containing, eradicating and reporting a security incident, including who does what and when.

Under POPIA it must include how and when the Information Regulator and affected people are notified.

Incident response planning

What is Disaster recovery plan (DRP)?

A disaster recovery plan (DRP) is a documented procedure for restoring IT systems after a major outage, with recovery priorities, objectives and step-by-step restoration runbooks.

It differs from an incident response plan, which covers security incidents; most businesses need both.

Disaster recovery planning

What is RTO and RPO?

RTO (recovery time objective) is how quickly a system must be restored after failure; RPO (recovery point objective) is how much data, measured in time, the business can afford to lose.

A four-hour RTO and one-hour RPO means back online within four hours having lost at most one hour of work.

Backup and disaster recovery

What is 3-2-1 backup rule?

The 3-2-1 backup rule is the practice of keeping three copies of your data, on two different types of storage, with one copy off-site or in the cloud.

Cloud sync services such as OneDrive or Google Drive are mirrors, not backups, and do not satisfy the rule on their own.

Backup and disaster recovery

What is Immutable backup?

An immutable backup is a backup copy that cannot be altered or deleted for a set retention period, even by an administrator account.

Immutability is the control that guarantees a clean copy exists after a ransomware attack that has compromised admin credentials.

Ransomware-proof backup

What is SaaS backup (Microsoft 365 and Google Workspace backup)?

SaaS backup is a separate, third-party backup of cloud productivity data such as Microsoft 365 or Google Workspace mailboxes, files, Teams and SharePoint.

Microsoft and Google guarantee platform availability, not the recovery of your data after deletion, ransomware or a malicious insider; that responsibility stays with the customer.

Microsoft 365 backup

What is Microsoft 365?

Microsoft 365 is Microsoft's subscription productivity suite combining Office applications (Word, Excel, PowerPoint, Outlook), Exchange email, Teams, OneDrive and SharePoint with security and device management.

Business Basic, Standard and Premium are the plans for organisations up to 300 users; eligible nonprofits get Business Basic free and Business Premium discounted.

Microsoft 365 setup

What is Google Workspace?

Google Workspace is Google's browser-first productivity suite combining Gmail, Calendar, Drive, Docs, Sheets, Slides, Meet and Chat under a business domain with central administration.

Google Workspace for Nonprofits is free for eligible South African organisations.

Microsoft 365 vs Google Workspace

What is Microsoft Entra ID?

Microsoft Entra ID, formerly Azure Active Directory, is Microsoft's cloud identity service that manages user accounts, sign-in, MFA and conditional access for Microsoft 365 and connected applications.

Conditional access policies in Entra ID are how a business enforces MFA, blocks legacy sign-ins and requires compliant devices.

Microsoft 365 management

What is Microsoft Intune?

Microsoft Intune is Microsoft's cloud device management service that enrols laptops, desktops and phones, enforces encryption and security settings, and deploys applications remotely.

It is included in Microsoft 365 Business Premium and is the usual answer to managing remote and hybrid staff devices.

Device management

What is Microsoft 365 Copilot?

Microsoft 365 Copilot is Microsoft's generative AI assistant embedded in Word, Excel, PowerPoint, Outlook and Teams that answers questions and drafts content using the organisation's own Microsoft 365 data.

It is licensed per user on top of a Microsoft 365 plan and inherits the permissions of the person using it, which is why access hygiene matters before rollout.

AI adoption services

What is RAG (retrieval-augmented generation)?

Retrieval-augmented generation (RAG) is an AI technique in which a language model answers questions by first retrieving relevant passages from an organisation's own documents and then generating a response grounded in them.

It is how business AI assistants answer from your policies, contracts and email rather than from general internet knowledge, and it reduces fabricated answers.

AI adoption services

What is AI acceptable use policy?

An AI acceptable use policy is a written rule set defining which AI tools staff may use, what data may be entered into them, how outputs must be checked and disclosed, and who is accountable.

It is the control that stops confidential data being pasted into personal ChatGPT accounts.

AI usage policy

What is SD-WAN?

SD-WAN (software-defined wide area network) is a networking technology that connects multiple sites and internet links under central software control, routing traffic over the best available connection.

For South African businesses it is the practical way to combine fibre and LTE so an ISP outage or load shedding at one site does not stop work.

Networking services

What is UPS (uninterruptible power supply)?

A UPS (uninterruptible power supply) is a battery unit that keeps equipment powered through an outage and conditions the supply so that servers, network equipment and desktops are not damaged by surges or dips.

Sizing depends on the load in watts and the runtime needed to either ride through a short outage or shut down cleanly.

Load shedding IT continuity

What is Microsoft Teams Rooms and Zoom Rooms?

Microsoft Teams Rooms and Zoom Rooms are dedicated meeting room systems, combining a room controller, camera, microphones and display, that join a video meeting with one touch without a laptop.

They are built on certified hardware from vendors such as Logitech, Yealink, Poly and Crestron.

Video conferencing and AV

What is Nonprofit technology grants?

Nonprofit technology grants are free or heavily discounted software, cloud services and advertising credits that vendors such as Microsoft, Google, Adobe, Canva and Zoom provide to validated nonprofit organisations.

South African NPOs, NPCs, PBOs and charitable trusts generally qualify; the Google Ad Grant alone is worth up to 10,000 US dollars a month in search advertising.

Nonprofit IT and tech grants

What is Section 18A status?

Section 18A status is a SARS approval that allows a public benefit organisation to issue tax-deductible donation receipts to its donors.

It is not required for Microsoft or Google nonprofit programmes, but the underlying PBO approval speeds up validation.

Nonprofit eligibility checker

Definitions written and reviewed by the AMEA Technologies engineering team in Johannesburg. Last updated .

Need help applying any of this?

Talk to an engineer about your environment, or run the free IT health check first.