glossary

IT Operations Glossary

253 terms defined for Indian SMEs. From AMC to ZTA — everything you need to know about helpdesks, asset management, and compliance.

A

Aadhaar Authentication

Using Aadhaar (India's biometric ID) to verify identity for employee onboarding, visitor access, or service requests.

Acceptable Use Policy (AUP)

A policy that defines what employees can and cannot do with company IT resources.

Access Control

The practice of restricting who can access systems, data, or physical locations based on their role and need.

Access Control Matrix

A document or system that defines exactly which users or roles can access which systems, data, or physical areas.

Active Directory

A Microsoft directory service that stores user accounts, devices, and permissions for a Windows network.

Aging Report

A report that groups open items — tickets, invoices, or stock — by how long they have been outstanding, to surface what is overdue.

AMC (Annual Maintenance Contract)

A yearly contract with a vendor to maintain and repair equipment, typically covering parts and labour for a fixed fee.

AMC Renewal

The process of reviewing, negotiating, and renewing an Annual Maintenance Contract before the current one expires to avoid coverage gaps.

Antivirus (AV)

Software that detects, blocks, and removes malicious programs like viruses, worms, and trojans from endpoints.

API (Application Programming Interface)

A set of protocols that allows different software systems to communicate with each other.

Asset Audit

A physical verification exercise that checks recorded assets against what actually exists on the ground, flagging missing or untracked items.

Asset Disposal

The final stage of an asset's life — securely wiping data, deregistering, and selling, donating, or scrapping the hardware.

Asset Health Score

A composite metric combining age, repair history, warranty status, and uptime to rank how reliable an asset is.

Asset Lifecycle Management

The process of managing an IT asset from procurement through usage to disposal.

Asset Register

A master list of every asset an organisation owns, with details like location, owner, value, and status.

Asset Tag

A unique identifier (barcode, QR code, or RFID) attached to a physical asset for tracking purposes.

Asset Tagging

Affixing a physical identifier — barcode, QR, or RFID tag — to each asset so it can be tracked across locations and audits.

Asset Utilisation

A measure of how much an asset is actually used versus its capacity, used to spot idle or over-stretched equipment.

Audit Trail

A chronological record of all actions taken on a system, including who did what and when.

Auto-Discovery

A network scanning technique that identifies every device connected to a network without manual entry, populating a live asset register.

Availability

The proportion of time a system or asset is operational and usable, often expressed as a percentage or in "nines" (e.g. 99.9%).

C

CAB (Change Advisory Board)

A group that reviews and approves significant IT changes to balance their benefit against the risk of disruption.

CapEx (Capital Expenditure)

Spending on long-lived assets such as servers, laptops, or machinery, capitalised and depreciated over time rather than expensed at once.

CCTV Maintenance

Scheduled checks and repairs of camera systems, DVRs/NVRs, and cabling to keep surveillance footage available for security and compliance.

Certificate Expiry

The date an SSL/TLS certificate stops being valid, after which users see browser warnings and encrypted services may fail.

Change Management

A process to ensure IT changes are planned, tested, and implemented in a controlled manner to minimise disruptions.

Change Request (CR)

A formal proposal to alter an IT system or process, submitted for review and approval before implementation.

Cloud Migration

Moving applications, data, and workloads from on-premise servers to a public cloud like AWS, Azure, or GCP.

CMDB (Configuration Management Database)

A repository of IT assets (configuration items) and the relationships between them, used to understand the impact of changes.

CMMS (Computerised Maintenance Management System)

Software that helps organisations manage maintenance activities, track assets, and schedule preventive maintenance.

Cold Site

A backup location with space and power but no ready systems, requiring setup before operations can resume after a disaster.

Compliance

Adherence to laws, regulations, standards, and policies relevant to the organisation.

Configuration Item (CI)

Any component — hardware, software, or service — tracked in a CMDB because it must be managed to deliver an IT service.

Consumables

Low-cost items used up in operations — cables, toner, batteries — tracked by quantity rather than as individual assets.

Containerisation

Packaging an application with its dependencies into a lightweight, isolated container (e.g. Docker) for consistent deployment across environments.

Cost Centre

A department or unit to which costs are attributed, used to allocate IT and asset spend across the business.

CRAC Unit (Computer Room Air Conditioner)

A precision cooling unit for server rooms that maintains constant temperature and humidity for IT equipment.

Critical Asset

An asset whose failure would cause significant operational, financial, or safety impact — flagged for priority maintenance and monitoring.

CSAT (Customer Satisfaction Score)

A metric measuring how satisfied users are with the support they received, typically on a 1-5 scale.

CSP (Cloud Service Provider)

A company that offers cloud infrastructure, platforms, or software on a pay-as-you-go basis, such as AWS, Azure, or Google Cloud.

Cyber Insurance

A policy that covers financial losses from cyber incidents like data breaches, ransomware, and business interruption.

D

Data Breach

An incident where sensitive, protected, or confidential data is accessed or disclosed without authorisation.

Data Classification

The practice of categorising data based on its sensitivity and criticality to determine appropriate security controls.

Data Masking

Replacing sensitive data with realistic but fictitious values so developers and testers work with safe datasets.

Data Retention

The policy defining how long different types of data are kept before being securely deleted.

Data Sovereignty

The principle that data is subject to the laws of the country where it is stored — relevant for Indian companies using global cloud providers.

Decommissioning

The controlled retirement of an asset from service, including data wiping, deregistration, and disposal or resale.

Depreciation (Reducing Balance)

Writing off a fixed percentage of an asset's remaining value each year, front-loading the expense in early years.

Depreciation (Straight-Line)

Writing off an asset's cost evenly over its useful life — e.g. a Rs 1,20,000 laptop over 3 years = Rs 40,000/year.

DHCP (Dynamic Host Configuration Protocol)

A network protocol that automatically assigns IP addresses and other network settings to devices when they connect.

Disaster Recovery (DR)

The process of restoring IT systems and data after a catastrophic event like a natural disaster, cyberattack, or hardware failure.

DNS (Domain Name System)

The internet's phone book — it translates domain names like workro.in into IP addresses that computers use to connect.

Downtime

A period when a system, server, or application is unavailable or non-operational.

DPDP Act

Digital Personal Data Protection Act 2023 — India's comprehensive data protection law governing how personal data is collected, stored, and processed.

DPDP Compliance Audit

An internal or third-party review to verify that personal data handling practices align with India's Digital Personal Data Protection Act 2023.

DR Site (Disaster Recovery Site)

A secondary physical location used to restore IT systems and data if the primary site becomes unavailable.

E

E-Waste

Electronic waste — discarded electrical or electronic devices that must be disposed of through certified recyclers in India.

E-Waste Certificate

A document issued by a certified e-waste recycler confirming that discarded electronics were disposed of in compliance with India's E-Waste Rules.

Edge Device

Any device at the boundary of a network — routers, switches, IoT gateways — that connects local networks to the internet.

Email-to-Ticket

A feature that converts incoming support emails into tickets automatically, so no request gets lost in an inbox.

Encryption

The process of converting data into a coded format that can only be read with the correct decryption key.

Endpoint

Any end-user device that connects to a network — laptop, desktop, phone, or tablet.

EOL (End of Life)

The point at which a vendor stops selling or developing a product; it may still work but no longer receives new features.

EOSL (End of Service Life)

The point at which a vendor stops supporting a product, including security patches — a strong signal to replace it.

ERP (Enterprise Resource Planning)

Software that integrates core business processes — finance, inventory, procurement, HR — into one system, such as SAP or Oracle.

Escalation

The process of routing a ticket to a higher-level support team when the current team cannot resolve it within the required time.

Escalation Matrix

A predefined chart of who a ticket moves to, and within what time, when it cannot be resolved at the current level.

Event Management

Monitoring IT systems for events — errors, warnings, threshold breaches — and acting on them before they become incidents.

I

IaaS (Infrastructure as a Service)

Cloud services providing virtualised computing resources — servers, storage, networking — on a pay-as-you-go model.

IMAC (Install, Move, Add, Change)

The routine deskside activities of installing, moving, adding, or changing IT equipment and user setups.

Incident Management

The process of identifying, analysing, and resolving IT incidents to restore normal service as quickly as possible.

Incident Response Plan (IRP)

A documented playbook for detecting, containing, and recovering from security incidents like ransomware or data breaches.

Indemnification

A contractual provision where one party agrees to cover losses or damages incurred by the other, common in vendor and service agreements.

Input Tax Credit (ITC)

A GST mechanism letting businesses claim credit for tax paid on purchases against their output tax liability.

Internal Audit

An independent, objective review of an organisation's processes, controls, and records to identify gaps and recommend improvements.

Inventory Reorder

The process of ordering new stock when quantities fall below a predefined reorder point to avoid stockouts.

IoT (Internet of Things)

Networked devices — sensors, meters, smart equipment — that collect and transmit data over the internet for monitoring and automation.

IP Address Management (IPAM)

The practice of planning, tracking, and managing IP address assignments across a network to prevent conflicts.

IPS (Intrusion Prevention System)

A network security device that monitors traffic in real time and blocks detected threats automatically.

ISO 27001

An international standard for information security management systems (ISMS).

IT Act 2000

India's primary law governing electronic commerce, digital records, and cybercrime.

IT Chargeback

A billing model where IT costs are allocated back to business units based on their actual usage of services.

IT Policy

A formal document establishing rules for using company technology — covering security, acceptable use, data retention, and more.

ITC Leakage

The loss of input tax credit due to missing GST invoices, mismatched HSN codes, or delayed vendor payments — a preventable financial leak.

ITIL

A widely used framework of best practices for IT service management, covering incidents, changes, problems, and service delivery.

ITSM (IT Service Management)

A set of policies and processes for managing IT service delivery to users.

M

MAC Address

A unique hardware identifier assigned to every network interface, used for device identification and access control.

Maintenance Window

A scheduled period during which systems may be taken offline for updates or repairs with minimal business impact.

Major Incident

A high-impact incident — such as a critical outage — that triggers an accelerated response and senior communication.

MDM (Mobile Device Management)

Software to enrol, configure, secure, and remotely manage phones, tablets, and laptops across an organisation.

Mean Time to Acknowledge (MTTA)

The average time between ticket creation and the first acknowledgment from the support team.

Memo of Understanding (MoU)

A non-binding agreement outlining the terms and understanding between two parties before a formal contract is signed.

MFA (Multi-Factor Authentication)

A security method requiring two or more verification factors to gain access to an account.

Micro-segmentation

Dividing a network into small, isolated zones so a breach in one zone cannot easily move laterally to others.

Monthly Recurring Revenue (MRR)

The predictable revenue a company expects to receive every month from subscriptions.

MSP (Managed Service Provider)

A company that remotely manages a client's IT — helpdesk, devices, networks — usually for a recurring fee.

MTBF (Mean Time Between Failures)

The average time between equipment failures, used to measure reliability.

MTTR (Mean Time To Resolution)

The average time to resolve a ticket from creation to closure.

P

PaaS (Platform as a Service)

Cloud services that provide a platform for developing, running, and managing applications without managing underlying infrastructure.

PAN (Permanent Account Number)

A 10-character alphanumeric identifier issued by the Indian Income Tax Department, required for TDS compliance.

Password Manager

Software that securely stores and auto-fills credentials, reducing the risk of weak or reused passwords across accounts.

Patch Management

The process of acquiring, testing, and deploying software updates to fix vulnerabilities and bugs.

Patch Tuesday

The second Tuesday of each month when Microsoft releases security and quality updates for Windows and Office products.

Penetration Testing

A simulated cyberattack performed by ethical hackers to identify vulnerabilities before real attackers do.

Phishing

A social engineering attack where fraudulent messages trick recipients into revealing passwords, financial data, or other sensitive information.

Physical Inventory

A hands-on count of all physical stock or assets at a location, reconciled against the system register to correct discrepancies.

Policy Enforcement

Automatically ensuring that devices and users comply with security policies — or restricting access if they do not.

Portfolio Management

The centralised management of a collection of IT projects, assets, or services to align with business priorities.

Predictive Maintenance

Using sensors and data analytics to predict when equipment is likely to fail, so repair can happen just before breakdown.

Preventive Maintenance

Scheduled maintenance activities performed to prevent equipment failures before they occur.

Privileged Access Management (PAM)

Controlling and monitoring access for accounts with elevated permissions (admin, root) to prevent misuse.

Problem Management

The process of finding and eliminating the root causes of recurring incidents, rather than just fixing each incident individually.

Procurement

The end-to-end process of sourcing, ordering, and acquiring goods and services for the organisation.

Provisioning

Setting up and granting a user or device the accounts, access, and equipment needed to start work.

Psyber Security

The practice of protecting psychological safety in digital environments, including reducing alert fatigue and support burnout.

Purchase Order (PO)

A formal document issued to a vendor to buy goods or services, specifying items, quantities, and agreed prices.

R

Ransomware

Malware that encrypts a victim's files and demands payment (often in cryptocurrency) to restore access.

RBAC (Role-Based Access Control)

A method of regulating access to systems based on a user's role within the organisation.

RCA (Root Cause Analysis)

A structured investigation to find the underlying cause of an incident so it can be permanently prevented.

Redundancy

Duplicating critical components — power supplies, servers, network links — so a failure in one does not cause a service outage.

Remediation

The act of fixing a security vulnerability or non-compliance finding — applying a patch, updating a policy, or reconfiguring a system.

Reorder Point

The stock level at which a new order should be placed to avoid running out before replenishment arrives.

RFID (Radio-Frequency Identification)

A tagging technology that identifies and tracks assets wirelessly using radio waves, without line-of-sight scanning.

RFP (Request for Proposal)

A formal document soliciting bids from vendors for products or services, detailing requirements and evaluation criteria.

RFQ (Request for Quotation)

A document requesting price quotes from vendors for specific goods or services, usually simpler than an RFP.

Risk Assessment

Identifying, analysing, and rating the potential impact of threats to assets, operations, or compliance.

RPO (Recovery Point Objective)

The maximum acceptable amount of data loss measured in time — how far back in time you can recover.

RTO (Recovery Time Objective)

The maximum acceptable time to restore a system after a failure — how quickly you need to be back online.

Runbook

A documented set of step-by-step procedures for carrying out a routine or emergency operational task.

S

SaaS (Software as a Service)

A software delivery model where applications are hosted centrally and accessed via the internet on a subscription basis.

SaaS Management

Tracking all SaaS subscriptions used across a company — licences, usage, costs — to prevent sprawl and overspend.

SAM (Software Asset Management)

Managing software licences and usage to stay compliant and avoid paying for more (or fewer) licences than needed.

SAN (Storage Area Network)

A high-speed network of storage devices that provides block-level storage to servers, used for databases and critical applications.

SCADA (Supervisory Control and Data Acquisition)

A control system architecture used in manufacturing, energy, and utilities to monitor and control industrial processes.

Security Operations Center (SOC)

A team that monitors, detects, and responds to security threats across the organisation around the clock.

Seed Capital

Early-stage funding used to develop a product idea into a viable business, typically before revenue begins.

Service Catalogue

A published list of the IT services available to users, with what each includes and how to request it.

Service Desk

The single point of contact between users and IT, handling requests, incidents, and communications.

Service Desk Automation

Using rules, AI, and self-service portals to resolve common requests without needing a human agent.

ServiceNow

An enterprise ITSM platform used by large organisations to manage incidents, changes, problems, and service requests.

Shadow IT

Hardware or software used within an organisation without the IT department's knowledge or approval.

SIEM (Security Information and Event Management)

A system that collects and analyses security logs from across the network to detect suspicious activity in real time.

Single Sign-On (SSO)

An authentication method allowing users to log in once and access multiple applications without re-entering credentials.

Six Sigma

A data-driven methodology for eliminating defects and reducing variability in processes, widely used in manufacturing and IT operations.

SKU (Stock Keeping Unit)

A unique code identifying a specific product or item for inventory tracking and reordering.

SLA (Service Level Agreement)

A commitment between a service provider and customer defining the expected level of service, including response and resolution times.

Smoke Testing

A quick, preliminary test to check whether a system's critical functions work before deeper testing begins.

SOC 2

A security framework for service organisations that manage customer data, based on five trust principles.

Software Compliance

Ensuring that all software installed on company devices is properly licensed and not exceeding agreed usage limits.

Software Lifecycle

The stages software goes through — planning, development, deployment, maintenance, and retirement — managed for cost and compliance.

Spare Parts

Components kept in stock to repair or replace failed parts of equipment quickly, reducing downtime.

Splunk

A platform for searching, monitoring, and analysing machine-generated data, commonly used for IT operations and security logging.

SRE (Site Reliability Engineering)

A discipline that applies software engineering principles to operations, treating infrastructure as code and automating toil.

SSL/TLS Certificate

A digital certificate that encrypts communications between a web server and browser, securing data in transit.

Standard Operating Procedure (SOP)

A written, step-by-step instruction for performing a routine task, ensuring consistency and quality across the team.

Statement of Work (SoW)

A document defining the scope, deliverables, timeline, and costs of a project or service engagement.

Storage

Any medium — HDD, SSD, cloud object storage — used to retain digital data for immediate or future use.

Synthetic Monitoring

Simulating user interactions with an application at scheduled intervals to detect performance degradation before real users are affected.

T

Tagging Convention

A standardised naming system for asset tags (e.g. LPT-001 for laptop 1, SRV-042 for server 42) to keep physical tags consistent and scannable.

TAT (Turnaround Time)

The total time taken to complete a request or repair from the moment it is raised to the moment it is closed.

TCO (Total Cost of Ownership)

The complete cost of an asset over its lifecycle, including purchase, maintenance, operation, and disposal.

TDP (Tax Deducted at Source) Return

The quarterly statement an Indian business must file with the Income Tax Department detailing all TDS deducted and deposited.

TDS (Tax Deducted at Source)

An Indian tax mechanism where the payer deducts tax before making certain payments and remits it to the government.

Technology Refresh

The periodic replacement of ageing IT hardware — laptops after 3 years, servers after 5 — to maintain performance and security.

Telnet

A network protocol for remote terminal access to devices, largely replaced by SSH due to its lack of encryption.

Tenant

An isolated instance of a software application serving one customer, common in SaaS products where each workspace is a tenant.

Threat Hunting

A proactive method of searching for hidden threats inside a network that automated security tools may have missed.

Ticket Drift

The phenomenon where a ticket's actual resolution drifts from its SLA target due to reassignments, waiting times, or unclear ownership.

Ticket Fatigue

The decline in response quality and speed when support agents are overloaded with a high volume of repetitive tickets.

Ticketing System

Software that logs, assigns, tracks, and resolves support requests as individual tickets with a full history.

Time to Value (TTV)

The time a customer takes to experience the first meaningful benefit from a product — faster TTV correlates with higher retention.

Total Addressable Market (TAM)

The total revenue opportunity available for a product or service in a given market, used for strategic planning.

Triage

Quickly assessing incoming tickets to set priority and route them to the right person or queue.

Two-Factor Authentication (2FA)

A login method requiring a second proof of identity — such as an OTP — in addition to a password.

Ready to put these terms into practice?

Start free — no card needed