Cyber defense, explained

Understand the term.
Keep the nuance.

Plain, vendor-neutral explanations of cybersecurity technology, threats, operations and European regulation — reviewed by practitioners.

Sourced definitions · limitations included
450 terms
CFoundations

Cybersecurity

Cybersecurity is the practice of managing risks to information, technology, and digitally enabled operations.

Read definition
IFoundations

Information security

Information security is the coordinated protection of information and the systems, people, facilities, and processes that handle it.

Read definition
CFoundations

Cyber defense

Cyber defense is the operational work of protecting digital systems, networks, identities, applications, and data against hostile activity — and restoring secure operation when defenses fail.

Read definition
CFoundations

Cyberattack

A cyberattack is a deliberate action or attempted action conducted through digital systems or communications to gain unauthorized access to, compromise, disrupt, manipulate, or otherwise affect systems, networks, services, data, or cyber-enabled operations.

Read definition
HFoundations

Hacking and ethical hacking

Hacking is a broad, informal label for exploring, modifying, bypassing, or gaining access to technology in ways its designers or operators may not have intended.

Read definition
CFoundations

Cyber risk

Cyber risk is the effect of uncertainty on organizational objectives arising from digital technology, information, or dependence on connected services.

Read definition
RFoundations

Risk assessment

A risk assessment is the structured process of identifying what could go wrong — the threats, vulnerabilities, likelihoods, and impacts relevant to an asset, system, or organization — so that treatment decisions can be prioritized and justified.

Read definition
AFoundations

Attack surface

An attack surface is the collection of points where an attacker could attempt to enter a system, influence its behavior, gain access, or remove data.

Read definition
DFoundations

Defense in depth

Defense in depth is a security strategy that uses multiple layers of people, process, architectural, and technical controls so that one failure does not expose the entire system.

Read definition
SFoundations

Security architecture

Security architecture is the coherent set of security-relevant structures, principles, responsibilities, interfaces, trust boundaries, and design decisions for a system, product, or enterprise.

Read definition
CFoundations

Compensating control

A compensating control is an alternative security or privacy safeguard used in place of a prescribed or selected control when the original cannot reasonably be implemented.

Read definition
AFoundations

Active defense

Active defense is an umbrella term for deliberate, adaptive actions that detect, disrupt, constrain, or learn from adversary activity rather than relying only on fixed barriers.

Read definition
CFoundations

Confidentiality, integrity, and availability (CIA triad)

The CIA triad is a model for three fundamental information-security objectives: confidentiality, integrity, and availability.

Read definition
IFoundations

Information security policy

An information security policy is an authoritative statement of management’s direction, intent, and requirements for protecting information and supporting systems.

Read definition
SFoundations

Security audit

A security audit is a systematic, independent, documented, and evidence-based examination of security-related activities, controls, records, or management systems against defined criteria.

Read definition
OPSECFoundations

Operational security (OPSEC)

Operational security (OPSEC), formally called operations security in many government sources, is a risk-management process for protecting critical information about activities, capabilities, intentions, and vulnerabilities.

Read definition
VFoundations

Vulnerability

A vulnerability is a weakness or adverse condition in a system, product, process, control, or implementation that a threat could exploit or an event could trigger, causing unintended security consequences.

Read definition
CVEFoundations

Common Vulnerabilities and Exposures (CVE)

Common Vulnerabilities and Exposures (CVE) is an international program that gives publicly disclosed cybersecurity vulnerabilities stable identifiers and publishes structured CVE Records in the CVE List.

Read definition
NVDFoundations

National Vulnerability Database (NVD)

The National Vulnerability Database (NVD) is a National Institute of Standards and Technology (NIST) repository that ingests published Common Vulnerabilities and Exposures (CVE) Records and adds structured vulnerability-management data.

Read definition
CVSSFoundations

Common Vulnerability Scoring System (CVSS)

The Common Vulnerability Scoring System (CVSS) is a framework maintained by the Forum of Incident Response and Security Teams (FIRST) for describing a vulnerability’s technical characteristics and expressing severity through metrics, a vector string, and, for scored combinations, a value from 0.0 to 10.0.

Read definition
SFoundations

Secure boot

Secure boot is a startup control that allows only software components authorized by platform policy to execute at covered stages of a device’s boot process.

Read definition
FFoundations

Firmware security

Firmware security is the protection of low-level software embedded in hardware components or devices across its design, production, delivery, installation, operation, update, recovery, and retirement.

Read definition
PQCFoundations

Post-quantum cryptography (PQC)

Post-quantum cryptography (PQC) is cryptography designed to resist attacks from both conventional and cryptographically relevant quantum computers while running on conventional computing and communications systems.

Read definition
QFoundations

Quantum computing security

Quantum computing security is the practice of assessing and managing how quantum computing affects information security, cryptographic dependencies, and any quantum-enabled systems an organization uses.

Read definition
QKDFoundations

Quantum key distribution (QKD)

Quantum key distribution (QKD) is a method for two endpoints to generate and distribute shared symmetric key material using quantum signals together with classical communication.

Read definition
MThreats, malware, and adversary tradecraft

Malware

Malware is software or firmware intentionally designed or modified to perform unauthorized or harmful actions in a system.

Read definition
CThreats, malware, and adversary tradecraft

Computer virus

A computer virus is self-replicating malicious code that inserts or attaches itself to a host, such as a program, document, script, or boot-related object.

Read definition
CThreats, malware, and adversary tradecraft

Computer worm

A computer worm is a self-contained, self-replicating program that can propagate a working copy to other systems, usually through network mechanisms, without attaching to a host program.

Read definition
TThreats, malware, and adversary tradecraft

Trojan horse

A Trojan horse is a program or package presented as useful, benign, or expected while containing a hidden malicious function.

Read definition
RThreats, malware, and adversary tradecraft

Rootkit

A rootkit is a collection of code or tools that conceals programs, files, processes, connections, or other activity and helps maintain privileged presence on a compromised system.

Read definition
BThreats, malware, and adversary tradecraft

Backdoor

A backdoor is a hidden or unauthorized mechanism that bypasses normal authentication to grant access to a system, application, or device.

Read definition
SThreats, malware, and adversary tradecraft

Spyware

Spyware is software that covertly collects information about a person, organization, device, or activity without adequate knowledge or permission and makes that information available to another party.

Read definition
AThreats, malware, and adversary tradecraft

Adware

Adware is software that displays, inserts, redirects, or selects advertising, possibly using device or user information.

Read definition
SThreats, malware, and adversary tradecraft

Scareware

Scareware is deceptive software or content that uses false or seriously misleading warnings about infections, threats, account danger, data loss, or system problems to pressure someone into acting.

Read definition
KThreats, malware, and adversary tradecraft

Keylogger

A keylogger is software, firmware, or hardware that records a person’s keystrokes.

Read definition
IThreats, malware, and adversary tradecraft

Infostealer

An infostealer is malware specialized in harvesting credentials, session tokens, browser data, and other stored secrets and personal information from an infected device for resale or follow-on access.

Read definition
RATThreats, malware, and adversary tradecraft

Remote access trojan (RAT)

A remote access trojan (RAT) is malware that gives a remote operator unauthorized control of a device while concealing or misrepresenting its purpose.

Read definition
FThreats, malware, and adversary tradecraft

Fileless malware

Fileless malware is malicious code or activity that executes mainly from memory or through existing system facilities instead of relying on a conventional executable stored on disk.

Read definition
MThreats, malware, and adversary tradecraft

Malvertising

Malvertising is the malicious use of online advertising to deliver malware, deceptive redirects, credential theft, fraud, or other harmful activity.

Read definition
CThreats, malware, and adversary tradecraft

Cryptojacking

Cryptojacking is the unauthorized use of another party’s devices, accounts, or computing services to mine cryptocurrency.

Read definition
BThreats, malware, and adversary tradecraft

Botnet

A botnet is a collection of compromised or otherwise illicitly controlled connected systems that an operator coordinates to perform tasks at scale.

Read definition
EThreats, malware, and adversary tradecraft

Exploit

An exploit is code, data, commands, or a sequence of actions created or used to take advantage of a vulnerability and produce behavior that the affected system did not intend or authorize.

Read definition
RCEThreats, malware, and adversary tradecraft

Remote code execution (RCE)

Remote code execution (RCE) is the capability or impact whereby an attacker causes code or commands of their choice to run on a target system from another system or network location.

Read definition
BThreats, malware, and adversary tradecraft

Buffer overflow

A buffer overflow is a memory-safety weakness in which software writes more data to a memory buffer than its allocated bounds can hold, causing adjacent memory or control data to be overwritten.

Read definition
ZThreats, malware, and adversary tradecraft

Zero-day vulnerability

A zero-day vulnerability is a security weakness unknown to the affected technology’s supplier or maintainer when it is first disclosed or exploited, typically before a practical correction is available.

Read definition
LThreats, malware, and adversary tradecraft

Lateral movement

Lateral movement is post-compromise activity in which an adversary uses an existing foothold to access or control additional systems, accounts, services, or environments.

Read definition
PThreats, malware, and adversary tradecraft

Persistence

Persistence is the set of mechanisms an attacker uses to retain access to a compromised environment across reboots, credential resets, software updates, and partial remediation.

Read definition
LOTLThreats, malware, and adversary tradecraft

Living off the land (LOTL)

Living off the land (LOTL) is attacker tradecraft that abuses legitimate software, built-in system utilities, administration features, credentials, or trusted services to perform malicious actions.

Read definition
C2Threats, malware, and adversary tradecraft

Command and control (C2)

Command and control (C2) is the attacker communication and coordination function that lets compromised systems, accounts, or services receive instructions and return status, results, or data.

Read definition
APTThreats, malware, and adversary tradecraft

Advanced persistent threat (APT)

An advanced persistent threat (APT) is a capable, well-resourced adversary — or, in common industry usage, its sustained campaign — that pursues strategic objectives over an extended period, uses multiple attack paths, adapts to resistance, and seeks to establish or renew access.

Read definition
TThreats, malware, and adversary tradecraft

Threat actor

A threat actor is an individual, group, or organization that is believed to conduct, direct, or support malicious cyber activity.

Read definition
CThreats, malware, and adversary tradecraft

Cyber kill chain

The cyber kill chain is a staged model of intrusion progression — reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives — originally published by Lockheed Martin.

Read definition
IThreats, malware, and adversary tradecraft

Identity-based attack

An identity-based attack is an industry umbrella term for an attack that targets or abuses digital identities, credentials, authenticators, sessions, entitlements, or identity infrastructure to obtain or retain unauthorized access.

Read definition
ATOThreats, malware, and adversary tradecraft

Account takeover (ATO)

Account takeover (ATO) is unauthorized control or effective use of an existing digital account by someone other than the legitimate account holder.

Read definition
SThreats, malware, and adversary tradecraft

Session hijacking

Session hijacking is the takeover of an authenticated session — typically by stealing or replaying its token or cookie — so the attacker inherits the victim’s access without performing a login.

Read definition
IThreats, malware, and adversary tradecraft

Identity theft

Identity theft is the unauthorized use of another person’s personal or financial information to impersonate them, obtain money, services, credit, benefits, employment, or medical care, or commit another deception.

Read definition
SThreats, malware, and adversary tradecraft

SIM swapping

SIM swapping is the fraudulent transfer of a victim’s phone number to an attacker-controlled SIM card, handing the attacker the victim’s calls and text messages — including one-time codes and account-recovery links.

Read definition
BThreats, malware, and adversary tradecraft

Brute-force attack

A brute-force attack repeatedly tests candidate values or credential combinations to obtain access or recover a secret.

Read definition
CThreats, malware, and adversary tradecraft

Credential stuffing

Credential stuffing is the automated or repeated use of previously exposed username-and-password pairs to attempt access to other accounts or services.

Read definition
PThreats, malware, and adversary tradecraft

Password spraying

Password spraying is an attack that tries a small set of common or likely passwords across many accounts, staying below per-account lockout thresholds while exploiting the statistical chance that some account uses a weak password.

Read definition
PThreats, malware, and adversary tradecraft

Pharming

Pharming is an attack that redirects a user who intends to reach a legitimate online service to a fraudulent destination, usually by altering name resolution, network or device configuration, or another trusted navigation mechanism.

Read definition
WThreats, malware, and adversary tradecraft

Watering hole attack

A watering hole attack targets a group by compromising or abusing an online destination that its members are likely to visit, then using that destination to profile, redirect, deceive, or attack selected visitors.

Read definition
DThreats, malware, and adversary tradecraft

Drive-by compromise

A drive-by compromise is unauthorized access gained through a victim’s visit to a website — by exploiting the browser or its components, or by deceiving the visitor into downloading or running content — without requiring the victim to knowingly install software.

Read definition
DNSThreats, malware, and adversary tradecraft

Domain Name System (DNS) hijacking

Domain Name System (DNS) hijacking is unauthorized takeover or alteration of DNS administration, delegation, authoritative data, resolver selection, or network or device configuration so queries use attacker-chosen infrastructure or records.

Read definition
DNSThreats, malware, and adversary tradecraft

Domain Name System (DNS) cache poisoning

Domain Name System (DNS) cache poisoning occurs when a recursive resolver accepts false DNS data and stores it as though authentic.

Read definition
FThreats, malware, and adversary tradecraft

Fast-flux network

A fast-flux network uses frequent changes in the Internet Protocol (IP) addresses or name-server infrastructure associated with a domain to keep an online service reachable while making its controlling systems harder to identify or block.

Read definition
DThreats, malware, and adversary tradecraft

Deepfake

A deepfake is audio, video, or imagery generated or significantly manipulated with artificial intelligence to resemble a person, object, place, entity, or event and falsely appear authentic or truthful.

Read definition
CThreats, malware, and adversary tradecraft

Cybersquatting

Cybersquatting is the bad-faith registration or use of a domain name that targets another party’s trademark or service mark, commonly to profit from confusion, divert users, demand payment, or support impersonation.

Read definition
TThreats, malware, and adversary tradecraft

Typosquatting

Typosquatting is the registration of lookalike domain names based on misspellings, keyboard slips, or visual confusion with legitimate names — capturing mistyped traffic or supporting phishing and impersonation.

Read definition
IThreats, malware, and adversary tradecraft

Internet fraud

Internet fraud is intentional deception conducted primarily or exclusively through online services to obtain money, property, credentials, personal information, or another benefit, or to cause a victim to act against their interests.

Read definition
DThreats, malware, and adversary tradecraft

Dark web

The dark web is the intentionally obscured part of the internet whose services require specialized software, configuration, or authorization to reach.

Read definition
WThreats, malware, and adversary tradecraft

Wardriving

Wardriving is an industry term for discovering, recording, or mapping wireless networks while moving through an area.

Read definition
RThreats, malware, and adversary tradecraft

Ransomware

Ransomware is malicious activity designed to coerce payment by denying access to systems or data, threatening disclosure, or combining both.

Read definition
RThreats, malware, and adversary tradecraft

Ransomware as a service (RaaS)

Ransomware as a service (RaaS) is a criminal service model in which a provider develops or maintains ransomware capabilities and makes them available to other operators, often called affiliates, who conduct intrusions or extortion.

Read definition
CThreats, malware, and adversary tradecraft

Cyber extortion

Cyber extortion is coercion carried out through or against digital systems in which an actor demands money, access, services, or another benefit and threatens cyber-enabled harm if the demand is refused.

Read definition
SThreats, malware, and adversary tradecraft

Supply-chain attack

A supply-chain attack uses a product, service, supplier, development or delivery process, trusted update path, or other upstream dependency as a route to affect downstream users.

Read definition
CThreats, malware, and adversary tradecraft

Cyberwarfare

Cyberwarfare is a contested policy and legal term for cyber operations used as means or methods of warfare, or otherwise integrated with military action, to create strategic or operational effects.

Read definition
HThreats, malware, and adversary tradecraft

Hacktivism

Hacktivism is a motive-based label for cyber activity carried out to promote, oppose, or draw attention to a political, social, religious, or ideological cause.

Read definition
CThreats, malware, and adversary tradecraft

Cyber espionage

Cyber espionage is covert, unauthorized access to digital systems or communications to obtain sensitive information for strategic, political, military, technological, or commercial intelligence advantage.

Read definition
EThreats, malware, and adversary tradecraft

Eavesdropping attack

An eavesdropping attack is unauthorized observation or capture of communications, commonly performed without altering the traffic or alerting the communicating parties.

Read definition
MITMThreats, malware, and adversary tradecraft

Man-in-the-middle (MITM) attack

A man-in-the-middle (MITM) attack is an active communications attack in which an adversary interposes between two parties, relays their exchanges, and may read, alter, inject, delay, or block data while each party believes it is communicating directly with the other.

Read definition
IRIncident response and threat intelligence

Incident response (IR)

Incident response is the organized way an organization prepares for, detects, analyzes, contains, recovers from, and learns from cybersecurity incidents.

Read definition
SIncident response and threat intelligence

Security incident

A security incident is an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of information or systems and meets the organization’s threshold for coordinated handling.

Read definition
DFIRIncident response and threat intelligence

Digital forensics and incident response (DFIR)

Digital forensics and incident response is an operating discipline that integrates incident response with the collection and analysis of digital evidence.

Read definition
SIncident response and threat intelligence

Security playbook

A security playbook is a documented response approach for a recurring security scenario, such as ransomware, credential compromise or data exposure.

Read definition
SIncident response and threat intelligence

Security runbook

A security runbook is a repeatable, task-level procedure for carrying out a defined operational action.

Read definition
MIncident response and threat intelligence

Malware analysis

Malware analysis is the authorized examination of suspected malicious software or related artifacts to determine their structure, capabilities, behavior, indicators, dependencies, and potential impact.

Read definition
CIncident response and threat intelligence

Chain of custody

Chain of custody is the documented, auditable record of who collected, handled, transferred, stored, and analyzed evidence — proving it was not altered or substituted between collection and use.

Read definition
RIncident response and threat intelligence

Root cause analysis

Root cause analysis is the structured investigation of why an incident or failure occurred, so fixes remove the underlying cause rather than only its symptoms.

Read definition
CTIIncident response and threat intelligence

Cyber threat intelligence (CTI)

Cyber threat intelligence is evidence-based knowledge about threats that is collected, analyzed, and placed in context to support a decision.

Read definition
IIncident response and threat intelligence

Indicator of compromise (IoC)

An indicator of compromise (IoC) is an observable artifact or condition that suggests malicious activity may be occurring or may have occurred.

Read definition
TIncident response and threat intelligence

Tactics, techniques, and procedures (TTPs)

Tactics, techniques, and procedures (TTPs) describe how threat actors pursue objectives and carry out attacks.

Read definition
TIPIncident response and threat intelligence

Threat intelligence platform (TIP)

A threat intelligence platform is a system used to manage the lifecycle of cyber threat information and intelligence from multiple internal and external sources.

Read definition
SIncident response and threat intelligence

STIX and TAXII

STIX and TAXII are OASIS open standards for cyber threat intelligence — STIX defines how intelligence is represented as structured objects, and TAXII defines how that intelligence is exchanged between systems.

Read definition
TIncident response and threat intelligence

Threat intelligence feed

A threat intelligence feed is a machine-readable stream of indicators, observations, or reports from external or internal sources, consumed into security tools to inform detection and blocking.

Read definition
OSINTIncident response and threat intelligence

Open-source intelligence (OSINT)

Open-source intelligence is intelligence derived exclusively from publicly or commercially available information, collected and analyzed to answer specific requirements.

Read definition
SOCSecurity operations and managed security

Security operations center (SOC)

A security operations center (SOC) is the people, processes, and technology responsible for continuously monitoring an organization’s digital environment and coordinating the detection, investigation, and response to security incidents.

Read definition
SSecurity operations and managed security

Security operations (SecOps)

Security operations (SecOps) is the ongoing organizational function and set of practices used to monitor security-relevant activity, operate defensive controls, detect and investigate threats, coordinate response, and improve protections from operational evidence.

Read definition
SIEMSecurity operations and managed security

Security information and event management (SIEM)

Security information and event management (SIEM) is a platform for collecting, normalizing, searching, correlating, and retaining security-relevant event data from multiple systems.

Read definition
SOARSecurity operations and managed security

Security orchestration, automation and response (SOAR)

Security orchestration, automation and response (SOAR) is a capability for coordinating security tools, case data, and repeatable workflows.

Read definition
DSecurity operations and managed security

Detection engineering

Detection engineering is the disciplined process of designing, testing, deploying, and maintaining ways to identify suspicious or harmful activity.

Read definition
TSecurity operations and managed security

Threat hunting

Threat hunting is a proactive, evidence-driven search for malicious activity that existing controls have not already surfaced with sufficient confidence.

Read definition
SSecurity operations and managed security

Security telemetry

Security telemetry is the security-relevant evidence generated by systems, identities, endpoints, applications, networks, cloud services, and protective controls.

Read definition
ASecurity operations and managed security

Alert triage

Alert triage is the initial, structured assessment of a security alert to decide what it may represent, how urgently it needs attention, and what should happen next.

Read definition
FSecurity operations and managed security

False positive

A false positive is a security finding that incorrectly indicates that a defined malicious condition, policy violation or vulnerability is present.

Read definition
FSecurity operations and managed security

False negative

A false negative is a failure to detect or report a real threat — the dangerous counterpart of a false positive, because it produces silent misses rather than noise.

Read definition
MTTDSecurity operations and managed security

Mean time to detect (MTTD)

Mean time to detect is the arithmetic average time between a defined starting event and the point at which an organization detects it.

Read definition
MTTRSecurity operations and managed security

Mean time to respond (MTTR)

Mean time to respond is the arithmetic average time between a defined starting point and a defined response milestone across a stated set of events or incidents.

Read definition
DSecurity operations and managed security

Dwell time

Dwell time is how long an attacker remains inside an environment before detection — the interval between initial compromise and discovery.

Read definition
SSecurity operations and managed security

Security metrics

Security metrics are the measurements used to describe control coverage, detection performance, exposure, and program effectiveness over time.

Read definition
ASecurity operations and managed security

Artificial intelligence for IT operations (AIOps)

Artificial intelligence for IT operations (AIOps) is a market term for applying machine learning and other AI techniques to information-technology operations data and workflows.

Read definition
ASecurity operations and managed security

AI in cybersecurity

Artificial intelligence (AI) in cybersecurity is the use of AI methods to support defensive security work such as analyzing telemetry, detecting anomalies, prioritizing alerts, finding malicious patterns, summarizing evidence, generating or reviewing code, and recommending response actions.

Read definition
EDRSecurity operations and managed security

Endpoint detection and response (EDR)

Endpoint detection and response (EDR) is a security capability that continuously records and analyzes activity on endpoint devices so defenders can detect suspicious behavior, investigate what happened, and take response actions.

Read definition
NDRSecurity operations and managed security

Network detection and response (NDR)

Network detection and response (NDR) is a security capability that analyzes network communications to identify suspicious behavior, support investigation, and trigger or guide response.

Read definition
XDRSecurity operations and managed security

Extended detection and response (XDR)

Extended detection and response (XDR) is a security technology approach that collects and correlates telemetry from multiple control points — commonly endpoints, identities, email, cloud workloads, and networks — to support detection, investigation, and response from a more unified view.

Read definition
UEBASecurity operations and managed security

User and entity behavior analytics (UEBA)

User and entity behavior analytics is an analytical approach that models activity associated with users and other entities, then identifies deviations or combinations of behavior that may deserve investigation.

Read definition
BSecurity operations and managed security

Behavioral analytics

Behavioral analytics is a broad analytical approach that examines activity, sequences, relationships, and changes over time to identify behavior that is relevant to a security question.

Read definition
HSecurity operations and managed security

Heuristic analysis

Heuristic analysis evaluates rules, features, structural clues, or behavioral patterns to flag activity or content that appears suspicious even when it does not exactly match a known signature.

Read definition
SSecurity operations and managed security

Sandboxing

Sandboxing is the practice of running code or processing content inside a controlled environment whose policy restricts access to resources such as files, devices, memory, processes, credentials, and networks.

Read definition
MSecurity operations and managed security

MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)

MITRE ATT&CK is a publicly accessible, maintained knowledge base that organizes adversary behavior observed in real-world activity.

Read definition
CDRSecurity operations and managed security

Cloud detection and response (CDR)

Cloud detection and response (CDR) is a non-standard industry label for capabilities and practices that use cloud-specific telemetry to detect suspicious activity, investigate its scope, and take or guide response actions.

Read definition
DSecurity operations and managed security

Deception technology

Deception technology is an industry umbrella term for controlled decoys, fabricated artifacts, misleading responses, and monitoring designed to attract, divert, delay, or reveal unauthorized activity.

Read definition
HSecurity operations and managed security

Honeypot

A honeypot is a monitored decoy system, service, or network resource designed to attract and record unauthorized or suspicious interaction.

Read definition
HSecurity operations and managed security

Honeytoken

A honeytoken is a deliberately fabricated data item, identifier, or credential placed where legitimate activity should not access or use it.

Read definition
CSecurity operations and managed security

Canary token

A canary token is a common, non-standard label for a honeytoken or lightweight decoy artifact configured to generate a signal when someone resolves, opens, accesses, or attempts to use it.

Read definition
ESecurity operations and managed security

Endpoint security

Endpoint security is the discipline of protecting devices and workloads that connect to organizational services, process data, or run applications.

Read definition
EPPSecurity operations and managed security

Endpoint protection platform (EPP)

An endpoint protection platform (EPP) is an industry category for centrally managed safeguards on endpoint devices, with an emphasis on preventing or blocking attacks.

Read definition
ASecurity operations and managed security

Antivirus

Antivirus is malware-focused software that attempts to detect, block, quarantine, or remove malicious code on a device or at a content-processing point.

Read definition
MSecurity operations and managed security

Mobile security

Mobile security is the discipline of protecting smartphones, tablets, their data, applications, identities, communications, and access to organizational services throughout acquisition, enrollment, use, maintenance, loss, transfer, and disposal.

Read definition
DSecurity operations and managed security

Device control

Device control is an endpoint security capability that governs the connection and use of peripheral devices and external interfaces.

Read definition
MSSPSecurity operations and managed security

Managed security service provider (MSSP)

A managed security service provider is an external organization that delivers ongoing cybersecurity functions for a customer under a service agreement.

Read definition
MDRSecurity operations and managed security

Managed detection and response (MDR)

Managed detection and response (MDR) is a security service in which an external team monitors agreed parts of a customer’s environment, investigates suspicious activity, and helps contain or remediate confirmed threats.

Read definition
MXDRSecurity operations and managed security

Managed extended detection and response (MXDR)

Managed extended detection and response is an industry label for a managed security service that uses extended detection and response capabilities across multiple technology domains.

Read definition
SSecurity operations and managed security

Security operations center as a service (SOCaaS)

SOC as a service (SOCaaS) is an outsourced model in which a provider performs an agreed set of security operations functions for a customer.

Read definition
SLASecurity operations and managed security

Service-level agreement (SLA)

A security service-level agreement is the contractual commitment defining what a provider will deliver — response times, availability, coverage, notification duties — and what happens when it falls short.

Read definition
PSecurity validation and exposure management

Penetration testing

Penetration testing is an authorized, time-bounded security assessment in which skilled testers attempt to identify and safely exploit weaknesses within an agreed scope.

Read definition
RSecurity validation and exposure management

Red team

A red team is an authorized group that emulates the behavior of a plausible adversary to test how well an organization protects important missions, business processes, assets, and data.

Read definition
PSecurity validation and exposure management

Purple team

Purple teaming is a collaborative security-testing approach in which offensive testers and defenders work together to improve preventive controls, telemetry, detections, investigations, and response.

Read definition
BSecurity validation and exposure management

Blue team

A blue team is the defensive side in security exercises and operations — the people and processes that detect, respond to, and withstand simulated or real attacks.

Read definition
BASSecurity validation and exposure management

Breach and attack simulation (BAS)

Breach and attack simulation (BAS) is an industry term for controlled, usually automated security testing that executes predefined attack-like actions and records how selected controls, telemetry, alerts, and response processes behave.

Read definition
CSecurity validation and exposure management

Cyber range

A cyber range is an isolated or controlled environment that represents networks, systems, applications, security tools, users, and attack activity for hands-on cybersecurity learning, exercises, research, or testing.

Read definition
TSecurity validation and exposure management

Tabletop exercise

A tabletop exercise is a discussion-based simulation where participants walk through a hypothetical incident to test plans, roles, and decision-making — without touching live systems.

Read definition
ASecurity validation and exposure management

Adversary emulation

Adversary emulation is the practice of reproducing a specific threat actor’s known tactics, techniques, and procedures to test whether defenses detect and stop that actor’s real behavior.

Read definition
RSecurity validation and exposure management

Rules of engagement

Rules of engagement are the agreed boundaries for a security exercise or test — what may be attacked, when, how, by whom, and what is explicitly off-limits.

Read definition
ASMSecurity validation and exposure management

Attack surface management (ASM)

Attack surface management (ASM) is an ongoing practice of discovering, attributing, tracking, and reducing assets and exposures that contribute to an organization’s attack surface.

Read definition
EASMSecurity validation and exposure management

External attack surface management (EASM)

External attack surface management is the continuous discovery and monitoring of an organization’s internet-facing assets and exposures — the view an outside attacker sees without internal access.

Read definition
CTEMSecurity validation and exposure management

Continuous threat exposure management (CTEM)

Continuous threat exposure management (CTEM) is a Gartner-defined, recurring program model for identifying, prioritizing, validating, and reducing exposures that could harm important business services.

Read definition
TSecurity validation and exposure management

Threat modeling

Threat modeling is a structured, repeatable analysis of how a system could be harmed or abused and what design decisions can reduce that risk.

Read definition
PSecurity validation and exposure management

Port scanning

Port scanning is the active testing of multiple transport-layer ports on a host or address to infer whether network services are reachable, listening, closed, or filtered from the scanner’s vantage point.

Read definition
VSecurity validation and exposure management

Vulnerability management

Vulnerability management is the ongoing, risk-informed process of finding, recording, evaluating, prioritizing, treating, and verifying vulnerabilities across technology and its lifecycle.

Read definition
PSecurity validation and exposure management

Patch management

Patch management is the governed process of identifying, prioritizing, testing, deploying, and verifying software updates — including the security fixes that close exploitable vulnerabilities.

Read definition
VSecurity validation and exposure management

Vulnerability assessment

A vulnerability assessment is a scoped evaluation that identifies and analyzes weaknesses in a system, product, service, process, or defined environment.

Read definition
VSecurity validation and exposure management

Vulnerability scanning

Vulnerability scanning is the automated probing or analysis of systems, applications, configurations, software inventories, or artifacts to identify conditions associated with known weaknesses or unsafe settings.

Read definition
CVDSecurity validation and exposure management

Coordinated vulnerability disclosure (CVD)

Coordinated vulnerability disclosure (CVD) is a process in which a vulnerability reporter, affected supplier or maintainer, deployers, coordinators, and other relevant parties exchange information so a weakness can be validated, addressed, and communicated with reduced avoidable harm.

Read definition
BSecurity validation and exposure management

Bug bounty

A bug bounty is a program that rewards external security researchers for reporting qualifying vulnerabilities in an organization’s systems or products under a defined scope and rules.

Read definition
IAMIdentity and access

Identity and access management (IAM)

Identity and access management (IAM) is the discipline and supporting technology used to establish digital identities and control their access to systems, applications, and data.

Read definition
AIdentity and access

Access control

Access control is the process of allowing or denying a subject’s request to use a resource, perform an action, or enter a protected environment.

Read definition
AIdentity and access

Authentication

Authentication is the process of establishing confidence that a claimant controls one or more authenticators bound to the identity or account being presented.

Read definition
AIdentity and access

Authorization

Authorization is the process or decision that determines whether a subject may perform a requested action on a resource.

Read definition
AAAIdentity and access

Authentication, authorization, and accounting (AAA)

Authentication, authorization, and accounting (AAA) is an architectural model for coordinating three access functions: verifying a requesting identity, determining which services or actions it may use, and recording relevant activity or resource consumption.

Read definition
RBACIdentity and access

Role-based access control (RBAC)

Role-based access control (RBAC) is an access-control model in which permissions are assigned to roles representing job functions or responsibilities, and identities receive permissions by being assigned to those roles.

Read definition
LIdentity and access

Least privilege

Least privilege is the principle of giving a user, service, device, or process only the permissions and resources needed to perform its authorized function.

Read definition
SIdentity and access

Separation of duties

Separation of duties splits critical tasks and powers across multiple people or roles so that no single individual can complete a sensitive or fraudulent action alone.

Read definition
MFAIdentity and access

Multi-factor authentication (MFA)

Multi-factor authentication (MFA) verifies a user with factors from at least two different categories: something the user knows, something the user possesses, or something the user is.

Read definition
PIdentity and access

Passwordless authentication

Passwordless authentication verifies a user without requiring that user to supply a reusable password to the target service.

Read definition
PIdentity and access

Passkey

A passkey is a discoverable FIDO credential used for passwordless authentication.

Read definition
PIdentity and access

Phishing-resistant authentication

Phishing-resistant authentication binds the authentication proof to the legitimate service, so a credential captured or replayed on a fake site is useless — typically via passkeys, FIDO2/WebAuthn, or certificate-based methods.

Read definition
AIdentity and access

Authentication token

Authentication token is a context-dependent term for a value or device used during authentication or to carry forward the result of successful authentication.

Read definition
LIdentity and access

Login credentials

The phrase “login credentials” is a common umbrella term for the identifiers and authenticators used to sign in to an account or service.

Read definition
PIdentity and access

Password manager

A password manager is an application or built-in platform feature that generates, stores, and fills unique credentials so that people do not have to memorize — or reuse — passwords.

Read definition
AIdentity and access

API key

An application programming interface (API) key is a string issued by an API provider to identify a calling application, project, or client and associate requests with permissions, quotas, or billing rules.

Read definition
CIdentity and access

Conditional access

Conditional access is an authorization approach that evaluates contextual signals before allowing, denying, or restricting access to a resource.

Read definition
JIdentity and access

Just-in-time access (JIT access)

Just-in-time access is a method of granting access or elevated privileges only when they are needed for a defined task, then revoking them automatically after a short period or when the task ends.

Read definition
SIdentity and access

Session management

Session management controls what happens after login — how session tokens are issued, bound, refreshed, expired, and revoked so an authenticated session stays tied to its legitimate user.

Read definition
AIdentity and access

Account recovery

Account recovery is the process that restores access when credentials are lost or compromised — and because it bypasses normal authentication, it is a prime target for social engineering.

Read definition
IIdentity and access

Identity proofing

Identity proofing verifies that a person claiming an identity really is that person — by checking evidence such as documents, biometrics, or records before a credential is issued.

Read definition
PAMIdentity and access

Privileged access management (PAM)

Privileged access management (PAM) is the set of policies, processes, and technologies used to control, monitor, and reduce access that can make high-impact changes to systems or data.

Read definition
PIMIdentity and access

Privileged identity management (PIM)

Privileged identity management (PIM) is an industry term for governing which human or non-human identities are eligible for privileged roles and controlling when those roles become active.

Read definition
SIdentity and access

Service account

A service account is a non-human account created so an application, operating-system service, script, agent, or automated process can authenticate and access resources.

Read definition
NHIIdentity and access

Non-human identity (NHI)

A non-human identity is any identity used by software rather than a person — service accounts, API keys, workload identities, certificates, tokens, and agents that authenticate to systems.

Read definition
FIdentity and access

Federated identity

Federated identity is an arrangement in which one administrative domain relies on identity and authentication information supplied by another trusted domain.

Read definition
IIdentity and access

Identity provider (IdP)

An identity provider is the system that authenticates users and issues proof of identity that other applications trust — the central sign-in behind SSO and federation.

Read definition
SSOIdentity and access

Single sign-on (SSO)

Single sign-on (SSO) is an authentication process in which one account and its authenticators let a user access multiple applications without performing a full sign-in separately at each one.

Read definition
SAMLIdentity and access

Security Assertion Markup Language (SAML)

Security Assertion Markup Language (SAML) is an OASIS standard for XML-encoded assertions about authentication, subject attributes, and authorization decisions, together with protocols and profiles for exchanging them.

Read definition
OIDCIdentity and access

OpenID Connect (OIDC)

OpenID Connect (OIDC) is an authentication and identity-federation layer built on OAuth 2.0.

Read definition
OIdentity and access

OAuth 2.0

OAuth 2.0 is an authorization framework that lets a client obtain limited access to an HTTP service without receiving the resource owner’s credentials.

Read definition
SCIMIdentity and access

System for Cross-domain Identity Management (SCIM)

System for Cross-domain Identity Management (SCIM) is an IETF standard for exchanging identity-resource data between systems so that accounts and groups can be created, read, updated, searched, disabled, or removed consistently.

Read definition
KIdentity and access

Kerberos authentication

Kerberos authentication is a ticket-based network authentication protocol in which a trusted Key Distribution Center (KDC) helps a client and network service establish authenticated, time-limited credentials.

Read definition
LDAPIdentity and access

Lightweight Directory Access Protocol (LDAP)

Lightweight Directory Access Protocol (LDAP) is an IETF protocol for accessing and managing information in a distributed directory service.

Read definition
RADIUSIdentity and access

Remote Authentication Dial-In User Service (RADIUS)

Remote Authentication Dial-In User Service (RADIUS) is a protocol for carrying authentication, authorization, configuration, and accounting information between a network access device and a central RADIUS server.

Read definition
IIdentity and access

IEEE 802.1X authentication

IEEE 802.1X authentication is the use of the IEEE 802.1X port-based network access-control standard to authenticate and authorize a device or user before granting normal access through a wired or wireless local area network port.

Read definition
ADIdentity and access

Active Directory (AD)

Active Directory (AD) usually refers to Microsoft Active Directory Domain Services (AD DS), a distributed directory and identity service for Windows domain environments.

Read definition
IIdentity and access

Identity as a service (IDaaS)

Identity as a service (IDaaS) is a cloud service model in which a provider delivers identity, credential, and access-management capabilities for customer organizations.

Read definition
CIAMIdentity and access

Customer identity and access management (CIAM)

Customer identity and access management (CIAM) is the branch of identity and access management that supports people using an organization’s customer-facing digital services.

Read definition
ITDRIdentity and access

Identity threat detection and response (ITDR)

Identity threat detection and response is an industry label for the practices and capabilities used to detect, investigate, and contain attacks involving identities and identity infrastructure.

Read definition
ZTNAIdentity and access

Zero trust network access (ZTNA)

Zero trust network access (ZTNA) is an access approach that connects an authenticated and authorized user or device to a specific application or resource instead of granting broad reachability to a network.

Read definition
MDMIdentity and access

Mobile device management (MDM)

Mobile device management (MDM) centrally enrolls devices, applies configuration and security policy, distributes managed applications or credentials, collects status, and performs remote actions.

Read definition
UEMIdentity and access

Unified endpoint management (UEM)

Unified endpoint management (UEM) is an industry category for administering endpoint types through a management plane and policy model.

Read definition
BYODIdentity and access

Bring your own device (BYOD)

Bring your own device (BYOD) is the practice of using a personally owned smartphone, tablet, or computer for work or access to organizational data and services.

Read definition
INetwork fundamentals

IP addressing: static and dynamic addresses

IP addressing assigns an Internet Protocol address and related configuration to a network interface so packets can be delivered within the address’s scope.

Read definition
NATNetwork fundamentals

Network address translation (NAT)

Network address translation (NAT) maps IP addresses from one address realm to another as packets cross a translating device.

Read definition
TNetwork fundamentals

TCP/IP protocol suite

The TCP/IP protocol suite is the family of interoperating protocols that underpins the internet and many private networks.

Read definition
UDPNetwork fundamentals

User Datagram Protocol (UDP)

User Datagram Protocol (UDP) is a transport protocol that carries independent messages, called datagrams, between application endpoints over Internet Protocol networks.

Read definition
OSINetwork fundamentals

Open Systems Interconnection (OSI) model

The Open Systems Interconnection (OSI) model is a seven-layer reference framework for describing how open systems communicate.

Read definition
TTLNetwork fundamentals

Time to live (TTL)

Time to live (TTL) is an eight-bit Internet Protocol version 4 (IPv4) header field that limits packet travel.

Read definition
DNSNetwork fundamentals

Domain Name System (DNS)

The Domain Name System (DNS) is a distributed, hierarchical naming system, database, and query-response protocol.

Read definition
DDNSNetwork fundamentals

Dynamic DNS (DDNS)

Dynamic DNS (DDNS) is a method for updating Domain Name System records automatically when the underlying information changes.

Read definition
DHCPNetwork fundamentals

Dynamic Host Configuration Protocol (DHCP)

Dynamic Host Configuration Protocol (DHCP) automatically supplies hosts with network configuration.

Read definition
ARPNetwork fundamentals

Address Resolution Protocol (ARP)

Address Resolution Protocol (ARP) is used on IPv4 local networks to determine the link-layer address associated with an IPv4 address.

Read definition
ICMPNetwork fundamentals

Internet Control Message Protocol (ICMP)

Internet Control Message Protocol (ICMP) carries error reports and operational information for Internet Protocol communications.

Read definition
SNMPNetwork fundamentals

Simple Network Management Protocol (SNMP)

Simple Network Management Protocol (SNMP) is an application-layer framework and protocol family for observing and managing networked systems.

Read definition
BGPNetwork fundamentals

Border Gateway Protocol (BGP)

Border Gateway Protocol (BGP) is the routing protocol used to exchange network reachability information between autonomous systems (ASes), such as internet service providers, cloud networks, and large organizations.

Read definition
MPLSNetwork fundamentals

Multiprotocol Label Switching (MPLS)

Multiprotocol Label Switching (MPLS) is a forwarding architecture in which network devices assign packets to a forwarding equivalence class and use short labels to direct them across an MPLS domain.

Read definition
QNetwork fundamentals

Quality of service (QoS)

Quality of service (QoS) is the use of network policies and resource-management mechanisms to provide different forwarding treatment to selected traffic.

Read definition
NNetwork fundamentals

Network latency

Network latency is the elapsed time for data to travel between defined points in a network.

Read definition
PNetwork fundamentals

Packet loss

Packet loss is the failure of one or more transmitted packets to arrive at a defined destination within a stated waiting period.

Read definition
TNetwork fundamentals

Traceroute

Traceroute is an active network diagnostic technique that estimates the sequence of Internet Protocol (IP) hops toward a destination.

Read definition
NNetwork fundamentals

Network traffic

Network traffic is the collection or stream of frames, packets, and higher-layer messages carried across network links and devices.

Read definition
ENetwork fundamentals

Ethernet switching

Ethernet switching is the forwarding of Ethernet frames between ports in a bridged local-area network.

Read definition
WNetwork fundamentals

Wireless network

A wireless network carries communications over electromagnetic signals rather than requiring a cable for every connected device.

Read definition
SSIDNetwork fundamentals

Service set identifier (SSID)

A service set identifier (SSID) is an identifier of up to 32 octets used for an IEEE 802.11 wireless service set.

Read definition
WANNetwork fundamentals

Wide area network (WAN)

A wide area network (WAN) is a physical or logical network that connects users, sites, data centers, cloud environments, or other networks across a broader geographic area than a local area network.

Read definition
FNetwork and edge security

Firewall

A firewall is a device, service, or software control that permits, rejects, or otherwise handles network traffic according to defined policy.

Read definition
NGFWNetwork and edge security

Next-generation firewall (NGFW)

A next-generation firewall (NGFW) is an industry label for a firewall that combines traditional traffic control with deeper application-aware inspection and additional security functions.

Read definition
SNetwork and edge security

Stateful firewall

A stateful firewall filters network traffic using both a ruleset and recorded information about flows or connections.

Read definition
SNetwork and edge security

Stateless packet filtering

Stateless packet filtering permits or denies each packet independently according to a ruleset, without maintaining a table that relates it to an established flow.

Read definition
PNetwork and edge security

Proxy firewall

“Proxy firewall” is a broad, non-standard label for a firewall architecture that uses a proxy as an intermediary between communicating endpoints.

Read definition
DNetwork and edge security

Distributed firewall

A distributed firewall is a non-standard architectural label for coordinated firewall policy enforced at multiple points rather than only at a central appliance.

Read definition
VNetwork and edge security

Virtual firewall

A virtual firewall is software that performs firewall policy enforcement inside a virtualized infrastructure rather than on a dedicated physical appliance.

Read definition
FNetwork and edge security

Firewall as a service (FWaaS)

Firewall as a service (FWaaS) is a market category for firewall capabilities operated as a network-accessible service, usually from provider-managed cloud points of presence.

Read definition
CNetwork and edge security

Cloud firewall

Cloud firewall is an industry term for firewall policy enforcement deployed in, integrated with, or delivered from a cloud environment.

Read definition
UTMNetwork and edge security

Unified threat management (UTM)

Unified threat management (UTM) is a market category for combining several network-security functions in one product or managed platform.

Read definition
IDSNetwork and edge security

Intrusion detection system (IDS)

An intrusion detection system (IDS) monitors network, host, wireless, application, or other events and analyzes them for signs of possible incidents or policy violations.

Read definition
IPSNetwork and edge security

Intrusion prevention system (IPS)

An intrusion prevention system (IPS) analyzes network, host, wireless, or application activity for signs of possible incidents and can attempt to stop what it detects.

Read definition
DPINetwork and edge security

Deep packet inspection (DPI)

Deep packet inspection (DPI) is a non-standard industry term for examining packet payloads and protocol context beyond basic network and transport headers.

Read definition
TLSNetwork and edge security

Transport Layer Security (TLS) inspection

TLS inspection is the deliberate decryption and re-encryption of TLS traffic at a trusted middlebox so security controls can see inside encrypted sessions.

Read definition
CNetwork and edge security

Content filtering

Content filtering is the policy-based inspection of application data or user-requested material to decide whether it should be allowed, blocked, quarantined, transformed, warned about, or recorded.

Read definition
URLNetwork and edge security

Uniform Resource Locator (URL) filtering

URL filtering is the policy-based evaluation of a requested web address or related destination information to allow, block, warn, redirect, isolate, or record access.

Read definition
SWGNetwork and edge security

Secure web gateway (SWG)

A secure web gateway (SWG) is a security service that mediates user or device access to web destinations and applies an organization’s outbound web-use and data-protection policies.

Read definition
VPNNetwork and edge security

Virtual private network (VPN)

A virtual private network (VPN) creates a logically separated communication environment over shared or public network infrastructure.

Read definition
RNetwork and edge security

Remote-access VPN

A remote-access virtual private network (VPN) connects an individual client outside an organization’s local network to a VPN gateway or access service.

Read definition
SNetwork and edge security

Site-to-site VPN

A site-to-site virtual private network (VPN) connects two or more networks through VPN gateways across another network, commonly the internet.

Read definition
SNetwork and edge security

SSL/TLS VPN

An SSL/TLS virtual private network (VPN) is an industry label for remote-access technology that uses Transport Layer Security (TLS) to protect communication between a client and a VPN gateway.

Read definition
SNetwork and edge security

Split tunneling

Split tunneling is a remote-access routing arrangement in which selected traffic uses a protected tunnel to an organization while other traffic follows the device’s ordinary local or internet route.

Read definition
RDPNetwork and edge security

Remote Desktop Protocol (RDP) security

Remote Desktop Protocol (RDP) security is the protection of remote interactive Windows sessions, their clients, hosts, credentials, gateways, and network paths.

Read definition
PNetwork and edge security

Proxy server

A proxy server is an intermediary that receives a client’s request and makes a corresponding request toward another server.

Read definition
RNetwork and edge security

Reverse proxy

A reverse proxy is a server-side intermediary that presents an endpoint to clients and forwards accepted requests to one or more backend or origin servers.

Read definition
TNetwork and edge security

Transparent proxy

A transparent proxy is an industry term for a proxy deployment in which network traffic is redirected to an intermediary without each client being explicitly configured to use it.

Read definition
ONetwork and edge security

Open proxy

An open proxy is a forward proxy that accepts relay requests from arbitrary or insufficiently restricted clients, commonly from the public internet.

Read definition
NNetwork and edge security

Network segmentation

Network segmentation divides an environment into zones and controls the communications allowed between them.

Read definition
MNetwork and edge security

Microsegmentation

Microsegmentation is a security design approach that places granular policy boundaries around small groups of, or individual, workloads, services, endpoints, or application components.

Read definition
DMZNetwork and edge security

Demilitarized zone (DMZ)

A demilitarized zone (DMZ) is a controlled network segment placed between networks with different trust levels, commonly the public internet and an internal enterprise network.

Read definition
ANetwork and edge security

Air gap

An air gap physically or logically isolates a system or network from untrusted networks — no shared cabling, wireless, or routine data path to the outside.

Read definition
NACNetwork and edge security

Network access control (NAC)

Network access control (NAC) is a policy and enforcement capability that governs which users and devices may connect to a network and what network access they receive.

Read definition
ACLNetwork and edge security

Network access control list (ACL)

A network access control list (ACL) is a set of rules that permits or denies network traffic according to packet and interface attributes.

Read definition
NNetwork and edge security

Network security

Network security is the discipline of protecting network communications, infrastructure, services, and connected resources against unauthorized access, misuse, disruption, and manipulation while preserving required availability.

Read definition
SDPNetwork and edge security

Software-defined perimeter (SDP)

A software-defined perimeter (SDP) is an access architecture that limits network connectivity to explicitly authorized resources.

Read definition
SASENetwork and edge security

Secure access service edge (SASE)

Secure access service edge (SASE) is an architecture and service-delivery model that combines wide-area networking with cloud-delivered security controls close to users, branches, applications, and other resources.

Read definition
SSENetwork and edge security

Security service edge (SSE)

Security service edge (SSE) is an architecture and service model that delivers multiple network-security capabilities — usually from cloud-based points of presence — to protect access to the web, software-as-a-service platforms, and private applications.

Read definition
SD-WANNetwork and edge security

Software-defined wide area network (SD-WAN)

A software-defined wide area network (SD-WAN) uses centrally defined policy and software-controlled edge functions to connect sites, data centers, cloud environments, and remote locations across one or more WAN transports.

Read definition
SDNNetwork and edge security

Software-defined networking (SDN)

Software-defined networking (SDN) is a programmable approach to networking that separates or abstracts decisions about traffic handling from the devices that forward packets.

Read definition
NNetwork and edge security

Network as a service (NaaS)

Network as a service (NaaS) is a service-delivery label for network capabilities consumed from a provider instead of wholly customer-operated infrastructure.

Read definition
NNetwork and edge security

Network edge

The network edge is a context-dependent boundary or zone where an organization’s network connects to users, devices, workloads, providers, partner networks, access networks, or the public internet.

Read definition
5Network and edge security

5G network security

5G network security protects fifth-generation mobile-network services and their supporting infrastructure, identities, communications, and operations.

Read definition
BNetwork and edge security

Branch networking

Branch networking is the architecture and operation of network services at a facility outside an organization’s main campus or data center.

Read definition
WNetwork and edge security

WAN aggregation

WAN aggregation is a non-standard industry label for using multiple wide area network (WAN) links as coordinated logical connectivity.

Read definition
NNetwork and edge security

Network monitoring

Network monitoring continuously collects and analyzes information about network infrastructure, connectivity, traffic, and service behavior to understand health, performance, capacity, availability, and security-relevant change.

Read definition
NNetwork and edge security

Network automation

Network automation uses software to perform repeatable network lifecycle tasks from machine-readable inputs.

Read definition
WNetwork and edge security

Wireless security

Wireless security protects wireless networks, devices, communications, and management systems against unauthorized access, disclosure, manipulation, and disruption while preserving availability.

Read definition
DNetwork and edge security

Distributed denial-of-service (DDoS) attack

A distributed denial-of-service (DDoS) attack uses many systems or traffic sources to make a service unavailable or severely degraded.

Read definition
DNetwork and edge security

Distributed denial-of-service (DDoS) mitigation

DDoS mitigation is the combination of architecture, services, controls, and response procedures used to keep an online service available during a distributed denial-of-service attack.

Read definition
DNSNetwork and edge security

Domain Name System (DNS) security

DNS security protects the availability, integrity, authenticity, and appropriate confidentiality of the Domain Name System and uses DNS activity as a source of defensive context.

Read definition
DNSSECNetwork and edge security

Domain Name System Security Extensions (DNSSEC)

DNSSEC adds cryptographic signatures to DNS data, letting resolvers verify that an answer came from the authoritative zone and was not altered in transit.

Read definition
PNetwork and edge security

Protective DNS

Protective DNS is a resolver service that blocks lookups for domains known or assessed to be malicious — stopping connections to phishing, malware, and command-and-control infrastructure before they start.

Read definition
ZTANetwork and edge security

Zero trust architecture (ZTA)

Zero trust architecture (ZTA) is an enterprise security design in which access is not implicitly trusted solely because of network location, device ownership, or an earlier login.

Read definition
CCloud and application security

Cloud security

Cloud security is the discipline of protecting data, identities, applications, workloads, management interfaces, and supporting services used in cloud computing.

Read definition
CCloud and application security

Cloud service models: IaaS, PaaS, and SaaS

The cloud service models describe how responsibility and control are divided between a cloud provider and customer.

Read definition
CCloud and application security

Cloud security architecture

Cloud security architecture is the documented structure of security responsibilities, trust boundaries, components, data flows, and control decisions for a cloud-based system or portfolio.

Read definition
SCloud and application security

Shared responsibility model

The shared responsibility model divides security duties between a cloud provider and its customer — the provider secures the cloud itself, while the customer secures what it places and configures in the cloud.

Read definition
PCloud and application security

Public cloud security

Public cloud security is the protection of data, identities, applications, configurations, and customer-controlled resources used in a public cloud deployment.

Read definition
HCloud and application security

Hybrid cloud security

Hybrid cloud security is the protection of a cloud environment composed of two or more distinct deployment models — such as private and public clouds — that remain separate but are connected to support data or application portability.

Read definition
MCloud and application security

Multi-cloud security

Multi-cloud security is an industry term for protecting an organization’s use of cloud services from more than one cloud provider.

Read definition
HCloud and application security

Hybrid IT

Hybrid IT is a non-standard industry term for an information-technology estate that combines environments or delivery models under coordinated operation — for example, on-premises systems, private and public cloud services, hosted infrastructure, software as a service, edge locations, and legacy platforms.

Read definition
VPCCloud and application security

Virtual private cloud (VPC)

A virtual private cloud (VPC) is a provider-defined, logically isolated virtual network in a public cloud.

Read definition
CCloud and application security

Cloud-native security

Cloud-native security is the application of security engineering and operations to cloud-native architectures and delivery models, including loosely coupled services, containers, declarative application programming interfaces (APIs), immutable infrastructure that is replaced rather than modified, orchestration, and extensive automation.

Read definition
CCloud and application security

Cloud application security

Cloud application security is the practice of protecting applications delivered through or hosted on cloud services, together with their application data, identities, interfaces, configurations, secrets, and integrations.

Read definition
SCloud and application security

SaaS security

Software as a service (SaaS) security is the practice of protecting an organization’s data, identities, configurations, integrations, and business processes in provider-operated applications.

Read definition
SCloud and application security

Serverless security

Serverless security is the protection of applications built with cloud services that abstract server provisioning and operational management from the customer.

Read definition
VCloud and application security

Virtualization security

Virtualization security is the practice of protecting the software and hardware layers that create and run virtual machines and other virtual resources.

Read definition
VDICloud and application security

Virtual desktop infrastructure (VDI) security

Virtual desktop infrastructure (VDI) security protects centrally hosted desktop operating-system instances and the services that deliver their display and input to user endpoints.

Read definition
ECloud and application security

Edge computing

Edge computing places selected computation, storage, and application functions close to a data source, user, device, or required action instead of relying exclusively on a distant centralized service.

Read definition
DCloud and application security

Data center security

Data center security is the coordinated protection of the facilities, people, hardware, networks, storage, virtualization layers, management systems, and operational processes that host computing services.

Read definition
CCloud and application security

Cloud network security

Cloud network security is the practice of protecting the network paths, services, control interfaces, and traffic that connect cloud resources, users, on-premises systems, and external services.

Read definition
CSPMCloud and application security

Cloud security posture management (CSPM)

Cloud security posture management (CSPM) is an industry category for continuously discovering cloud resources and assessing their configuration against security policies, architecture rules, and compliance requirements.

Read definition
CWPPCloud and application security

Cloud workload protection platform (CWPP)

A cloud workload protection platform (CWPP) is an industry category for technology that protects software workloads running in cloud or cloud-like environments.

Read definition
CIEMCloud and application security

Cloud infrastructure entitlement management (CIEM)

Cloud infrastructure entitlement management (CIEM) is an industry category for discovering, analyzing, and governing permissions across cloud infrastructure.

Read definition
CNAPPCloud and application security

Cloud-native application protection platform (CNAPP)

A cloud-native application protection platform (CNAPP) is an industry category for an integrated set of capabilities that helps secure cloud-native applications and infrastructure from development through production.

Read definition
CASBCloud and application security

Cloud access security broker (CASB)

A cloud access security broker (CASB) is an industry category for a security capability placed logically between cloud-service consumers and providers or connected through provider application programming interfaces.

Read definition
SSPMCloud and application security

SaaS security posture management (SSPM)

SaaS security posture management (SSPM) is a non-standard market category for processes and tools that inventory supported software-as-a-service tenants and assess their security configuration over time.

Read definition
ACloud and application security

Application security

Application security is the discipline of reducing security risk in software and the systems on which it depends throughout planning, design, development, testing, release, operation, and retirement.

Read definition
WCloud and application security

Web application security

Web application security is the application-security discipline applied to software delivered through web technologies and used through browsers or other web clients.

Read definition
OWASPCloud and application security

Open Worldwide Application Security Project (OWASP) Top 10

The OWASP Top 10 is a periodically updated awareness document from the Open Worldwide Application Security Project (OWASP) that groups and explains ten of the most significant categories of web application security risk.

Read definition
MCloud and application security

Mobile application security

Mobile application security is the discipline of protecting software designed for mobile platforms throughout its design, development, distribution, operation, and retirement.

Read definition
BCloud and application security

Browser security

Browser security is the protection of web-browsing software, its users, and the surrounding device from hostile content, unsafe downloads, vulnerable components, malicious or overprivileged extensions, credential theft, and misuse of browser data.

Read definition
RASPCloud and application security

Runtime application self-protection (RASP)

Runtime application self-protection (RASP) is a variable industry category for controls integrated with or closely coupled to an application’s runtime so they can observe execution context and detect, report, or block selected malicious behavior while the application runs.

Read definition
VCloud and application security

Virtual patching

Virtual patching is a compensating security measure that places an enforcement rule between an exploitable system and relevant requests or traffic, blocking or constraining known exploit paths while the underlying code or component remains unchanged.

Read definition
SCloud and application security

Security misconfiguration

Security misconfiguration is a security-relevant setting or operational state that is missing, incorrect, inconsistent, excessively permissive, or unsuitable for its intended environment.

Read definition
SQLCloud and application security

Structured Query Language (SQL) injection

SQL injection is an injection weakness in which untrusted data alters the structure or meaning of a Structured Query Language (SQL) command.

Read definition
XSSCloud and application security

Cross-site scripting (XSS)

Cross-site scripting (XSS) is a web application weakness that allows attacker-controlled content to be interpreted as executable code in another user’s browser within a trusted application context.

Read definition
CSRFCloud and application security

Cross-site request forgery (CSRF)

Cross-site request forgery (CSRF) is a web weakness in which an attacker causes a user’s browser or client-side code to send an unintended request to an application that trusts the user’s existing authenticated context.

Read definition
CCloud and application security

Clickjacking

Clickjacking, also called user-interface redressing, is an attack in which a malicious interface conceals, overlays, or repositions content from another application so a user’s click or tap activates a control different from the one the user perceives.

Read definition
DCloud and application security

DevSecOps

DevSecOps is an operating practice that integrates security work into software development and operations instead of assigning it to a final review or a separate team.

Read definition
SCloud and application security

Shift-left security

Shift-left security is an industry practice of moving suitable security decisions, evidence, and feedback earlier in the software or system lifecycle, closer to requirements, design, and implementation.

Read definition
CI/CDCloud and application security

Continuous integration and continuous delivery or deployment (CI/CD) pipeline security

Continuous integration and continuous delivery or deployment (CI/CD) pipeline security is the protection of the systems, identities, code, dependencies, instructions, execution environments, and artifacts used to build, test, approve, and release software.

Read definition
ICloud and application security

Infrastructure as code (IaC) security

Infrastructure as code (IaC) security is the protection of machine-readable definitions and automation used to provision, configure, change, and remove infrastructure.

Read definition
SASTCloud and application security

Static application security testing (SAST)

Static application security testing analyzes software without executing it to identify patterns that may indicate security defects.

Read definition
DASTCloud and application security

Dynamic application security testing (DAST)

Dynamic application security testing evaluates a running application by interacting with its exposed interfaces and observing the resulting behavior.

Read definition
SCACloud and application security

Software composition analysis (SCA)

Software composition analysis identifies software components used in an application and evaluates information associated with them.

Read definition
SBOMCloud and application security

Software bill of materials (SBOM)

A software bill of materials is a formal record of the software components and supply-chain relationships associated with a defined product, package, or artifact.

Read definition
SCloud and application security

Secrets management

Secrets management is the controlled lifecycle for sensitive values that systems use to authenticate, authorize actions, establish trust, or protect data.

Read definition
SCloud and application security

Software supply-chain security

Software supply-chain security is the discipline of protecting source code, dependencies, development tools, identities, build and test systems, artifact repositories, release processes, and update channels against unauthorized or unsafe change.

Read definition
CCloud and application security

Container security

Container security is the set of practices and controls used to protect container images, registries, runtimes, orchestrators, host systems, networks, identities, secrets, and delivery pipelines throughout the container lifecycle.

Read definition
KCloud and application security

Kubernetes security

Kubernetes security is the practice of protecting the container orchestration platform — its API, control plane, workloads, and supply chain — and the applications it runs.

Read definition
APICloud and application security

Application programming interface (API) security

API security is the design, implementation, testing, and operation of controls that protect application programming interfaces and the data and services they expose.

Read definition
APICloud and application security

Application programming interface (API) gateway

An API gateway is a managed entry point in front of APIs — routing requests, enforcing authentication, rate limits, and policy, and unifying how clients reach backend services.

Read definition
SCloud and application security

Secure by design

Secure by design means building products and systems with security as a design requirement from the start — rather than adding defenses after architecture and code already exist.

Read definition
WAFCloud and application security

Web application firewall (WAF)

A web application firewall (WAF) is a security control that inspects HTTP and HTTPS traffic between clients and web applications and applies policy.

Read definition
IData and insider risk

Insider threat

An insider threat is the potential for a person with authorized access or special knowledge of an organization to cause harm.

Read definition
IData and insider risk

Insider risk management

Insider risk management is the coordinated process of reducing harm that could arise when people with legitimate access or organizational knowledge make unsafe, negligent, compromised, or malicious use of that position.

Read definition
SData and insider risk

Shadow IT

Shadow IT is technology used inside an organization without the knowledge, approval, or governance of the IT or security organization — unapproved SaaS, personal cloud storage, unsanctioned tools, and unregistered systems.

Read definition
DLPData and insider risk

Data loss prevention (DLP)

Data loss prevention (DLP) is a set of policies and technical capabilities used to identify sensitive data, monitor how it is handled, and prevent or record unauthorized disclosure or transfer.

Read definition
DData and insider risk

Data exfiltration

Data exfiltration is the unauthorized transfer of data from a system, service, device, or organization to a location or party that should not receive it.

Read definition
DData and insider risk

Data breach

A data breach is a security incident in which data’s confidentiality, integrity, or availability is compromised through unauthorized access, disclosure, alteration, destruction, or loss.

Read definition
DData and insider risk

Data leakage and exposure

Data leakage and exposure describe overlapping situations in which data crosses, or becomes accessible beyond, its intended trust or authorization boundary.

Read definition
FData and insider risk

File-sharing security

File-sharing security is the governance and protection of files made available to other people, organizations, devices, or applications through shared repositories, collaboration services, network shares, links, synchronization, or similar mechanisms.

Read definition
DData and insider risk

Data classification

Data classification is the process of assigning data to categories based on its sensitivity, criticality, legal or contractual requirements, and value to the organization.

Read definition
DData and insider risk

Data retention

Data retention is the deliberate management of how long data is kept — balancing legal and business requirements to retain it against the risk that accumulated data becomes a breach and privacy liability.

Read definition
DData and insider risk

Data discovery

Data discovery is the process of locating data across defined systems and describing enough of it to support security, privacy, governance, or operational decisions.

Read definition
DData and insider risk

Data governance

Data governance is the system by which an organization directs, controls, and holds people accountable for decisions about data and its use.

Read definition
DData and insider risk

Data security

Data security is the discipline of protecting data against unauthorized access, use, disclosure, alteration, destruction, or loss while keeping it available to authorized users when needed.

Read definition
DData and insider risk

Data protection

Data protection is the coordinated governance and handling of data throughout its lifecycle so it is used for authorized purposes, safeguarded from harm, kept appropriately accurate and available, and retained or disposed of as required.

Read definition
DData and insider risk

Data privacy

Data privacy concerns how data processing affects people and whether collection, inference, use, sharing, retention, and deletion are appropriate for the stated context.

Read definition
PIIData and insider risk

Personally identifiable information (PII)

Personally identifiable information (PII) is information that can distinguish or trace an individual’s identity, either by itself or when combined with other information that is linked or linkable to that person.

Read definition
DData and insider risk

Data integrity

Data integrity is the property that data remains accurate, complete, consistent, traceable, and protected from unauthorized or unintended alteration or destruction throughout its lifecycle.

Read definition
DSPMData and insider risk

Data security posture management (DSPM)

Data security posture management (DSPM) is an emerging, non-standard market category for processes and tools that discover data stores, identify sensitive information, relate it to access, exposure, use, and protective controls, and prioritize data-security risk.

Read definition
DCAPData and insider risk

Data-centric audit and protection (DCAP)

Data-centric audit and protection (DCAP) is an older analyst-defined market category for capabilities that discover and classify data, govern access, monitor or audit data activity, and apply protective controls around the data itself.

Read definition
DRMData and insider risk

Digital rights management (DRM)

Digital rights management (DRM) is the use of policy, cryptography, licensing, and trusted software or hardware to control how digital content may be accessed and used.

Read definition
CData and insider risk

Cryptography

Cryptography is the discipline of designing, analyzing, and applying mathematical techniques to protect information and communications against defined adversaries.

Read definition
EData and insider risk

Encryption

Encryption is the reversible cryptographic transformation of readable data, called plaintext, into ciphertext using an algorithm and cryptographic key.

Read definition
CData and insider risk

Cryptographic key management

Cryptographic key management governs the full lifecycle of encryption keys — generation, distribution, storage, use, rotation, backup, and destruction — because encrypted data is only as safe as its keys.

Read definition
DData and insider risk

Digital signature

A digital signature is a cryptographic proof attached to data showing who signed it and that the content was not altered after signing — providing authenticity and integrity, and supporting non-repudiation.

Read definition
CData and insider risk

Cryptographic hashing

Cryptographic hashing is a one-way function that maps arbitrary input to a fixed-length digest, designed so the input cannot be practically recovered from the digest and two different inputs cannot practically produce the same digest.

Read definition
PKIData and insider risk

Public key infrastructure (PKI)

Public key infrastructure (PKI) is the governed combination of roles, policies, processes, systems, cryptographic keys, and digital certificates used to establish and maintain trust relationships involving public keys.

Read definition
TLSData and insider risk

Transport Layer Security (TLS)

Transport Layer Security is the cryptographic protocol that authenticates endpoints — typically the server — and protects the confidentiality and integrity of data in transit, forming the security layer behind HTTPS and many other protocols.

Read definition
DData and insider risk

Digital certificate

A digital certificate is a signed data structure that associates a public key with a named subject, identity, role, device, service, or other attributes under an issuer’s rules.

Read definition
CData and insider risk

Certificate management

Certificate management is the controlled lifecycle of digital certificates and their associated requests, private keys, owners, deployments, dependencies, and trust relationships.

Read definition
OCSPData and insider risk

Online Certificate Status Protocol (OCSP)

The Online Certificate Status Protocol (OCSP) is an internet protocol for checking a digital certificate’s revocation status without downloading a certificate revocation list.

Read definition
HSMData and insider risk

Hardware security module (HSM)

A hardware security module (HSM) is a physical computing device that safeguards cryptographic keys and performs cryptographic operations within a defined security boundary.

Read definition
MACData and insider risk

Message authentication code (MAC)

A message authentication code (MAC) is a short cryptographic tag computed from a message and a secret key.

Read definition
PGPData and insider risk

Pretty Good Privacy (PGP)

Pretty Good Privacy (PGP) began as a named cryptographic software product for encrypting and digitally signing files and messages.

Read definition
HData and insider risk

Homomorphic encryption

Homomorphic encryption is cryptography that allows specified computations to be performed on encrypted data without first exposing its plaintext.

Read definition
CData and insider risk

Confidential computing

Confidential computing protects data in use by performing computation within a hardware-backed, attested trusted execution environment (TEE).

Read definition
POSData and insider risk

Point-of-sale (POS) security

Point-of-sale (POS) security protects the devices, applications, networks, data, people, and services used to record sales and accept payment at checkout.

Read definition
EEmail and human risk

Email security

Email security is the combination of controls used to protect email identities, infrastructure, messages, users, and business processes.

Read definition
DMARCEmail and human risk

Domain-based Message Authentication, Reporting, and Conformance (DMARC)

DMARC is an email-authentication, policy, and reporting protocol that lets a domain owner publish a requested handling policy for messages that fail DMARC validation and specify where receivers should send reports.

Read definition
SPFEmail and human risk

Sender Policy Framework (SPF)

Sender Policy Framework (SPF) is an email-authentication protocol that lets a domain owner publish which mail systems are authorized to use that domain in an SMTP envelope identity.

Read definition
DKIMEmail and human risk

DomainKeys Identified Mail (DKIM)

DomainKeys Identified Mail (DKIM) is an email-authentication protocol that allows a domain to attach a cryptographic signature to a message.

Read definition
EEmail and human risk

Email encryption

Email encryption is the use of cryptography to protect email from unauthorized reading while it is transmitted, stored, or carried as protected message content.

Read definition
EEmail and human risk

Email spoofing

Email spoofing is the falsification or imitation of sender information so that a message appears to come from a trusted person, organization, or domain.

Read definition
SEmail and human risk

Spam filtering

Spam filtering is the automated evaluation of email to identify unsolicited, unwanted, or abusive messaging and decide whether to reject, defer, quarantine, label, route, or deliver it.

Read definition
PEmail and human risk

Phishing

Phishing is a social-engineering attack that uses a deceptive digital message or interaction to make someone reveal information, authorize an action, open malicious content, or visit an attacker-controlled service.

Read definition
AEmail and human risk

Adversary-in-the-middle (AiTM) phishing

Adversary-in-the-middle phishing places attacker infrastructure between the victim and the real service, relaying the genuine authentication exchange live so the attacker captures credentials and the resulting session token.

Read definition
SEmail and human risk

Spear phishing

Spear phishing is phishing deliberately tailored to a specific person, team, organization, or narrowly defined group.

Read definition
BECEmail and human risk

Business email compromise (BEC)

Business email compromise (BEC) is a form of fraud in which an attacker impersonates or takes over a trusted business identity to persuade someone to transfer money, reveal sensitive information, or change a legitimate business process.

Read definition
WEmail and human risk

Whaling

Whaling is spear phishing selected around a target’s seniority, public profile, authority, or access to high-value information and transactions.

Read definition
VEmail and human risk

Vishing

Vishing, short for voice phishing, is phishing conducted through a live or recorded voice interaction, including telephone calls and voice messages.

Read definition
SEmail and human risk

Smishing

Smishing is phishing delivered through Short Message Service (SMS) or similar mobile text messaging.

Read definition
SEmail and human risk

Social engineering

Social engineering is an umbrella term for attacks that use deception, impersonation, influence, or manufactured pressure to persuade a person to disclose information, grant access, transfer value, or perform another action that weakens security.

Read definition
PEmail and human risk

Pretexting

Pretexting is a social-engineering technique in which an attacker invents or misrepresents a role, relationship, event, or need to make a request seem legitimate.

Read definition
TEmail and human risk

Tailgating

A tailgating attack is an attempt to enter a controlled physical area by following an authorized person through an access point without presenting independent authorization.

Read definition
SEmail and human risk

Security awareness training

Security awareness training is the planned learning activity that helps people recognize security and privacy risks, make safer decisions, and follow the organization’s reporting and response procedures.

Read definition
OTOperational technology, IoT, and critical infrastructure

Operational technology (OT) security

Operational technology (OT) security protects systems that monitor or control physical processes, devices, and infrastructure.

Read definition
ICSOperational technology, IoT, and critical infrastructure

Industrial control system (ICS)

An industrial control system (ICS) is a system used to monitor and control an industrial process.

Read definition
SCADAOperational technology, IoT, and critical infrastructure

Supervisory control and data acquisition (SCADA)

Supervisory control and data acquisition (SCADA) is an industrial control architecture used to supervise processes and collect operational data across distributed assets.

Read definition
PLCOperational technology, IoT, and critical infrastructure

Programmable logic controller (PLC)

A programmable logic controller (PLC) is an industrial solid-state controller with user-programmable memory for executing functions such as logic, sequencing, timing, counting, arithmetic, communication, input and output control, and proportional-integral-derivative control.

Read definition
HMIOperational technology, IoT, and critical infrastructure

Human-machine interface (HMI)

A human-machine interface (HMI) is the hardware or software through which an operator interacts with an industrial controller or process.

Read definition
SISOperational technology, IoT, and critical infrastructure

Safety instrumented system (SIS)

A safety instrumented system (SIS) comprises one or more safety instrumented functions that achieve or maintain a safe state when defined process conditions are violated.

Read definition
POperational technology, IoT, and critical infrastructure

Purdue model

The Purdue model is a layered reference model for organizing manufacturing and control functions from the physical process and basic control through supervisory and site operations to enterprise systems.

Read definition
IOperational technology, IoT, and critical infrastructure

IEC 62443

IEC 62443 is a series of international standards and technical reports for cybersecurity of industrial automation and control systems (IACS).

Read definition
IDMZOperational technology, IoT, and critical infrastructure

Industrial demilitarized zone (IDMZ)

An industrial demilitarized zone (IDMZ) is a controlled network zone placed between enterprise IT and operational technology networks to prevent direct communication across their boundary.

Read definition
IOperational technology, IoT, and critical infrastructure

Information technology and operational technology convergence (IT/OT convergence)

IT/OT convergence is the increasing integration of information technology with operational technology systems, data, processes, and teams.

Read definition
OTOperational technology, IoT, and critical infrastructure

Operational technology (OT) asset inventory

An OT asset inventory is a maintained record of the devices, software, communications, dependencies, and physical functions that make up an operational technology environment.

Read definition
SOperational technology, IoT, and critical infrastructure

Secure remote access

Secure remote access is the governed capability for an authorized person or system outside an operational trust boundary to reach specified OT resources for an approved purpose.

Read definition
DOperational technology, IoT, and critical infrastructure

Data diode / unidirectional gateway

A data diode is a boundary device designed to permit data transfer in only one physical direction.

Read definition
IOperational technology, IoT, and critical infrastructure

Internet of Things (IoT)

The Internet of Things (IoT) is an ecosystem of connected physical objects that combine computation with sensors or actuators to observe, communicate, or affect their environment.

Read definition
IOperational technology, IoT, and critical infrastructure

IoT security

Internet of Things (IoT) security is the discipline of protecting connected devices, their data, communications, physical interactions, applications, services, and lifecycle processes.

Read definition
IOperational technology, IoT, and critical infrastructure

IoT edge

The Internet of Things (IoT) edge is the part of an IoT ecosystem where data is collected, processed, or acted upon close to connected devices and their physical environment.

Read definition
CPSOperational technology, IoT, and critical infrastructure

Cyber-physical system (CPS)

A cyber-physical system (CPS) is an engineered system in which digital, analog, physical, and often human components interact to perform a function through integrated computation and physical behavior.

Read definition
DOperational technology, IoT, and critical infrastructure

Digital twin

A digital twin is a digital representation of a real-world asset, process, or system that is connected to observations from its counterpart so the representation can be updated at a fit-for-purpose rate.

Read definition
COperational technology, IoT, and critical infrastructure

Critical infrastructure protection

Critical infrastructure protection is the coordinated use of physical security, cybersecurity, personnel safeguards, emergency management, and resilience measures to reduce risks to assets, systems, networks, and services whose disruption could seriously harm safety, health, security, the economy, or society.

Read definition
NRegulation, governance, and resilience

NIS2 Directive

The NIS2 Directive is the European Union’s updated framework for achieving a high common level of cybersecurity across the EU.

Read definition
ERegulation, governance, and resilience

Essential and important entities under NIS2

Essential entities and important entities are the two principal supervisory categories used by the NIS2 Directive.

Read definition
DORARegulation, governance, and resilience

Digital Operational Resilience Act (DORA)

The Digital Operational Resilience Act (DORA) is the European Union regulation that establishes a common framework for managing information and communication technology risk in the financial sector.

Read definition
CRARegulation, governance, and resilience

Cyber Resilience Act (CRA)

The Cyber Resilience Act (CRA) is the European Union regulation establishing horizontal cybersecurity requirements for products with digital elements made available on the EU market.

Read definition
GDPRRegulation, governance, and resilience

General Data Protection Regulation (GDPR) security

GDPR security is the set of legal obligations and accountable practices used to protect personal data processed under the EU General Data Protection Regulation.

Read definition
ARegulation, governance, and resilience

Artificial Intelligence Act (AI Act)

The EU Artificial Intelligence Act — Regulation (EU) 2024/1689 — is the bloc’s risk-based law for AI systems, banning some uses outright and imposing graded obligations on high-risk systems, general-purpose models, and deployers.

Read definition
FISMARegulation, governance, and resilience

Federal Information Security Modernization Act (FISMA)

The Federal Information Security Modernization Act of 2014 (FISMA) is a United States law that establishes a government-wide framework for managing information-security risk to federal operations, assets, information, and systems.

Read definition
FRegulation, governance, and resilience

Federal Risk and Authorization Management Program (FedRAMP)

The Federal Risk and Authorization Management Program (FedRAMP) is a United States government-wide program that standardizes reusable security information about in-scope cloud services processing unclassified federal information.

Read definition
HRegulation, governance, and resilience

HIPAA Security Rule

The Health Insurance Portability and Accountability Act (HIPAA) Security Rule is a United States regulation requiring covered entities and business associates to protect electronic protected health information (ePHI).

Read definition
SOXRegulation, governance, and resilience

Sarbanes–Oxley Act (SOX) cybersecurity

Sarbanes–Oxley Act (SOX) cybersecurity is an informal label for cybersecurity work that supports a public company’s obligations under the United States Sarbanes–Oxley Act of 2002.

Read definition
NRegulation, governance, and resilience

North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP)

North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) refers to a family of mandatory reliability standards addressing security of the Bulk Electric System in North America.

Read definition
ISO/IECRegulation, governance, and resilience

International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001

ISO/IEC 27001 is an international requirements standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).

Read definition
NRegulation, governance, and resilience

National Institute of Standards and Technology Special Publication (NIST SP) 800-53

National Institute of Standards and Technology Special Publication (NIST SP) 800-53 is a catalog of security and privacy controls for information systems and organizations.

Read definition
CSFRegulation, governance, and resilience

NIST Cybersecurity Framework (CSF)

The NIST Cybersecurity Framework is a voluntary framework of outcomes that helps organizations understand, manage, and reduce cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.

Read definition
CRegulation, governance, and resilience

COBIT

COBIT is a framework published by ISACA, formerly the Information Systems Audit and Control Association, for governing and managing enterprise information and technology (I&T).

Read definition
PRegulation, governance, and resilience

Payment Card Industry Data Security Standard (PCI DSS)

The Payment Card Industry Data Security Standard (PCI DSS) is an industry security standard containing technical and operational requirements for protecting payment account data.

Read definition
SRegulation, governance, and resilience

SOC 1 report

A System and Organization Controls 1 (SOC 1) report is an independent service-auditor report on controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting.

Read definition
SRegulation, governance, and resilience

SOC 2 report

A System and Organization Controls 2 (SOC 2) report is an independent service-auditor report on controls at a service organization relevant to the American Institute of Certified Public Accountants' Trust Services Criteria.

Read definition
SRegulation, governance, and resilience

SOC 3 report

A SOC 3 report is a general-use service-auditor report on controls at a service organization relevant to the Trust Services Criteria — covering the same subject matter as SOC 2 but with less detail, so it can be shared publicly.

Read definition
CRegulation, governance, and resilience

Compliance automation

Compliance automation is the use of software, structured data, and repeatable workflows to perform selected compliance activities with less manual effort.

Read definition
CRegulation, governance, and resilience

Cyber resilience

Cyber resilience is the ability to anticipate, withstand, recover from, and adapt to adverse conditions, attacks, or compromises involving digital systems and resources.

Read definition
BRegulation, governance, and resilience

Business continuity

Business continuity is an organization’s capability and management practice for continuing prioritized products and services at an acceptable level during a disruption and restoring normal operations afterward.

Read definition
BIARegulation, governance, and resilience

Business impact analysis (BIA)

A business impact analysis identifies what an organization cannot afford to lose — the processes, dependencies, and time limits that determine how damaging an outage or disruption would be.

Read definition
DRegulation, governance, and resilience

Disaster recovery

Disaster recovery is the coordinated restoration of technology services, infrastructure, and data after a serious disruption.

Read definition
CRegulation, governance, and resilience

Cyber recovery

Cyber recovery is the discipline of restoring systems and data after a destructive cyberattack — where the attack itself may have corrupted or reached the very backups and tools normal recovery relies on.

Read definition
RPORegulation, governance, and resilience

Recovery point objective (RPO)

A recovery point objective is the point in time before a disruption to which data must be recoverable.

Read definition
RTORegulation, governance, and resilience

Recovery time objective (RTO)

A recovery time objective is the target duration after a defined disruption within which a specified system, service, or business capability should be restored to an agreed level.

Read definition
MTDRegulation, governance, and resilience

Maximum tolerable downtime (MTD)

Maximum tolerable downtime is the absolute ceiling on how long a process or service can be unavailable before the impact becomes unacceptable — the outer bound that RTOs must stay within.

Read definition
BRegulation, governance, and resilience

Backup

A backup is a separate, recoverable copy of data kept so it can be restored after loss — the baseline control against deletion, corruption, ransomware, and failure.

Read definition
IRegulation, governance, and resilience

Immutable backup

An immutable backup is a backup whose retained recovery points are protected from alteration or deletion for a defined period.

Read definition
FRegulation, governance, and resilience

Failover

Failover is the capability and process of transferring a service from an active component, system, connection, or site to a redundant or standby alternative after a failure or abnormal condition.

Read definition
FRegulation, governance, and resilience

Fault tolerance

Fault tolerance is a system property that allows a required function to continue correctly when one or more anticipated hardware or software faults occur.

Read definition
CRegulation, governance, and resilience

Crisis management

Crisis management is the leadership process for handling a disruption severe enough to threaten the organization itself — coordinating decisions, communication, and stakeholders beyond any single team’s playbook.

Read definition
TRegulation, governance, and resilience

Third-party cyber risk

Third-party cyber risk is the potential for harm arising from an organization’s reliance on suppliers, service providers, contractors, partners, and other external parties.

Read definition
TPRMRegulation, governance, and resilience

Third-party risk management (TPRM)

Third-party risk management is the governance discipline that identifies, assesses, contracts for, and monitors the security risk introduced by vendors, suppliers, and partners across the relationship lifecycle.

Read definition
SRegulation, governance, and resilience

Supply-chain security

Supply-chain security is the protection of products, services, components, data, and delivery relationships against compromise, substitution, disruption, or unacceptable dependency risk throughout their lifecycle.

Read definition
CRegulation, governance, and resilience

Concentration risk

Concentration risk is the exposure created when critical operations depend on too few providers, platforms, or suppliers — so a single failure or compromise cascades across the organization.

Read definition
CRegulation, governance, and resilience

Cyber insurance

Cyber insurance is a contract under which an insurer agrees, subject to the policy’s terms, to fund specified losses, liabilities, or response services arising from covered cyber events.

Read definition
ARegulation, governance, and resilience

AI risk management

Artificial intelligence (AI) risk management is the coordinated process of identifying, assessing, treating, monitoring, and communicating risks arising from the design, development, acquisition, deployment, use, and retirement of AI systems.

Read definition
AAI security

AI security

AI security is the discipline of protecting artificial intelligence systems and the environments around them from malicious manipulation, unauthorized access, disclosure, theft and disruption.

Read definition
AAI security

AI governance

AI governance is the organizational framework of policies, roles, and processes that decides how AI may be selected, built, deployed, and monitored — before models reach production or users.

Read definition
AI-SPMAI security

AI security posture management (AI-SPM)

AI security posture management is an emerging, non-standard industry label for processes and capabilities that discover AI assets and assess their security state.

Read definition
MAI security

Machine learning security operations (MLSecOps)

Machine learning security operations (MLSecOps) is an emerging practice that integrates security responsibilities and controls into machine learning development and operations across data preparation, model development, evaluation, release, deployment, monitoring, change, and retirement.

Read definition
AAI security

Agentic AI security

Agentic AI security is the practice of protecting AI systems that pursue goals through delegated access to tools, services or other agents.

Read definition
AAI security

AI red teaming

AI red teaming is an authorized, structured adversarial evaluation of an AI system.

Read definition
PAI security

Prompt injection

Prompt injection is the manipulation of a generative AI system through instructions that cause a model to override or conflict with the application’s intended instructions.

Read definition
MAI security

Model poisoning

Model poisoning is a training-stage attack in which an adversary manipulates a model or its parameters to change later behavior.

Read definition
DAI security

Data poisoning

Data poisoning is a training-stage attack in which an adversary inserts, deletes, alters or relabels data used to train or adapt a machine-learning model.

Read definition
AAI security

Adversarial machine learning

Adversarial machine learning is the field concerned with attacks that exploit machine-learning systems and with methods for understanding and mitigating those attacks.

Read definition
SAI security

Shadow AI

Shadow AI is an industry governance term for AI systems, services or features used, connected, developed or deployed without the visibility or approval required by an organization.

Read definition

Built to be cited

Useful to people.
Legible to agents.

Every published entry begins with a standalone definition, links factual claims to primary sources and declares an important limitation.

Suggest a term or correction
Open datasetJSON and CSV exports will be generated from the same approved source files as the pages.Planned

Let’s Build Smarter Cyber Defenses Together

Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.

Get in touch with Yellow Cube