# Cyber Defense Glossary

> Plain, vendor-neutral explanations of cybersecurity technology, threats, operations and European regulation.

- Canonical URL: https://yellowcube.eu/glossary/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

### Foundations

- [Cybersecurity](<https://yellowcube.eu/glossary/cybersecurity/index.md>): Cybersecurity is the practice of managing risks to information, technology, and digitally enabled operations.
- [Information security](<https://yellowcube.eu/glossary/information-security/index.md>): Information security is the coordinated protection of information and the systems, people, facilities, and processes that handle it.
- [Cyber defense](<https://yellowcube.eu/glossary/cyber-defense/index.md>): Cyber defense is the operational work of protecting digital systems, networks, identities, applications, and data against hostile activity — and restoring secure operation when defenses fail.
- [Cyberattack](<https://yellowcube.eu/glossary/cyberattack/index.md>): A cyberattack is a deliberate action or attempted action conducted through digital systems or communications to gain unauthorized access to, compromise, disrupt, manipulate, or otherwise affect systems, networks, services, data, or cyber-enabled operations.
- [Hacking and ethical hacking](<https://yellowcube.eu/glossary/hacking-and-ethical-hacking/index.md>): Hacking is a broad, informal label for exploring, modifying, bypassing, or gaining access to technology in ways its designers or operators may not have intended.
- [Cyber risk](<https://yellowcube.eu/glossary/cyber-risk/index.md>): Cyber risk is the effect of uncertainty on organizational objectives arising from digital technology, information, or dependence on connected services.
- [Risk assessment](<https://yellowcube.eu/glossary/risk-assessment/index.md>): A risk assessment is the structured process of identifying what could go wrong — the threats, vulnerabilities, likelihoods, and impacts relevant to an asset, system, or organization — so that treatment decisions can be prioritized and justified.
- [Attack surface](<https://yellowcube.eu/glossary/attack-surface/index.md>): An attack surface is the collection of points where an attacker could attempt to enter a system, influence its behavior, gain access, or remove data.
- [Defense in depth](<https://yellowcube.eu/glossary/defense-in-depth/index.md>): Defense in depth is a security strategy that uses multiple layers of people, process, architectural, and technical controls so that one failure does not expose the entire system.
- [Security architecture](<https://yellowcube.eu/glossary/security-architecture/index.md>): Security architecture is the coherent set of security-relevant structures, principles, responsibilities, interfaces, trust boundaries, and design decisions for a system, product, or enterprise.
- [Compensating control](<https://yellowcube.eu/glossary/compensating-control/index.md>): A compensating control is an alternative security or privacy safeguard used in place of a prescribed or selected control when the original cannot reasonably be implemented.
- [Active defense](<https://yellowcube.eu/glossary/active-defense/index.md>): Active defense is an umbrella term for deliberate, adaptive actions that detect, disrupt, constrain, or learn from adversary activity rather than relying only on fixed barriers.
- [Confidentiality, integrity, and availability (CIA triad)](<https://yellowcube.eu/glossary/confidentiality-integrity-and-availability/index.md>): The CIA triad is a model for three fundamental information-security objectives: confidentiality, integrity, and availability.
- [Information security policy](<https://yellowcube.eu/glossary/information-security-policy/index.md>): An information security policy is an authoritative statement of management’s direction, intent, and requirements for protecting information and supporting systems.
- [Security audit](<https://yellowcube.eu/glossary/security-audit/index.md>): A security audit is a systematic, independent, documented, and evidence-based examination of security-related activities, controls, records, or management systems against defined criteria.
- [Operational security (OPSEC)](<https://yellowcube.eu/glossary/operational-security/index.md>): Operational security (OPSEC), formally called operations security in many government sources, is a risk-management process for protecting critical information about activities, capabilities, intentions, and vulnerabilities.
- [Vulnerability](<https://yellowcube.eu/glossary/vulnerability/index.md>): A vulnerability is a weakness or adverse condition in a system, product, process, control, or implementation that a threat could exploit or an event could trigger, causing unintended security consequences.
- [Common Vulnerabilities and Exposures (CVE)](<https://yellowcube.eu/glossary/common-vulnerabilities-and-exposures/index.md>): Common Vulnerabilities and Exposures (CVE) is an international program that gives publicly disclosed cybersecurity vulnerabilities stable identifiers and publishes structured CVE Records in the CVE List.
- [National Vulnerability Database (NVD)](<https://yellowcube.eu/glossary/national-vulnerability-database/index.md>): The National Vulnerability Database (NVD) is a National Institute of Standards and Technology (NIST) repository that ingests published Common Vulnerabilities and Exposures (CVE) Records and adds structured vulnerability-management data.
- [Common Vulnerability Scoring System (CVSS)](<https://yellowcube.eu/glossary/common-vulnerability-scoring-system/index.md>): The Common Vulnerability Scoring System (CVSS) is a framework maintained by the Forum of Incident Response and Security Teams (FIRST) for describing a vulnerability’s technical characteristics and expressing severity through metrics, a vector string, and, for scored combinations, a value from 0.0 to 10.0.
- [Secure boot](<https://yellowcube.eu/glossary/secure-boot/index.md>): Secure boot is a startup control that allows only software components authorized by platform policy to execute at covered stages of a device’s boot process.
- [Firmware security](<https://yellowcube.eu/glossary/firmware-security/index.md>): Firmware security is the protection of low-level software embedded in hardware components or devices across its design, production, delivery, installation, operation, update, recovery, and retirement.
- [Post-quantum cryptography (PQC)](<https://yellowcube.eu/glossary/post-quantum-cryptography/index.md>): Post-quantum cryptography (PQC) is cryptography designed to resist attacks from both conventional and cryptographically relevant quantum computers while running on conventional computing and communications systems.
- [Quantum computing security](<https://yellowcube.eu/glossary/quantum-computing-security/index.md>): Quantum computing security is the practice of assessing and managing how quantum computing affects information security, cryptographic dependencies, and any quantum-enabled systems an organization uses.
- [Quantum key distribution (QKD)](<https://yellowcube.eu/glossary/quantum-key-distribution/index.md>): Quantum key distribution (QKD) is a method for two endpoints to generate and distribute shared symmetric key material using quantum signals together with classical communication.

### Threats, malware, and adversary tradecraft

- [Malware](<https://yellowcube.eu/glossary/malware/index.md>): Malware is software or firmware intentionally designed or modified to perform unauthorized or harmful actions in a system.
- [Computer virus](<https://yellowcube.eu/glossary/computer-virus/index.md>): A computer virus is self-replicating malicious code that inserts or attaches itself to a host, such as a program, document, script, or boot-related object.
- [Computer worm](<https://yellowcube.eu/glossary/computer-worm/index.md>): A computer worm is a self-contained, self-replicating program that can propagate a working copy to other systems, usually through network mechanisms, without attaching to a host program.
- [Trojan horse](<https://yellowcube.eu/glossary/trojan-horse/index.md>): A Trojan horse is a program or package presented as useful, benign, or expected while containing a hidden malicious function.
- [Rootkit](<https://yellowcube.eu/glossary/rootkit/index.md>): A rootkit is a collection of code or tools that conceals programs, files, processes, connections, or other activity and helps maintain privileged presence on a compromised system.
- [Backdoor](<https://yellowcube.eu/glossary/backdoor/index.md>): A backdoor is a hidden or unauthorized mechanism that bypasses normal authentication to grant access to a system, application, or device.
- [Spyware](<https://yellowcube.eu/glossary/spyware/index.md>): Spyware is software that covertly collects information about a person, organization, device, or activity without adequate knowledge or permission and makes that information available to another party.
- [Adware](<https://yellowcube.eu/glossary/adware/index.md>): Adware is software that displays, inserts, redirects, or selects advertising, possibly using device or user information.
- [Scareware](<https://yellowcube.eu/glossary/scareware/index.md>): Scareware is deceptive software or content that uses false or seriously misleading warnings about infections, threats, account danger, data loss, or system problems to pressure someone into acting.
- [Keylogger](<https://yellowcube.eu/glossary/keylogger/index.md>): A keylogger is software, firmware, or hardware that records a person’s keystrokes.
- [Infostealer](<https://yellowcube.eu/glossary/infostealer/index.md>): An infostealer is malware specialized in harvesting credentials, session tokens, browser data, and other stored secrets and personal information from an infected device for resale or follow-on access.
- [Remote access trojan (RAT)](<https://yellowcube.eu/glossary/remote-access-trojan/index.md>): A remote access trojan (RAT) is malware that gives a remote operator unauthorized control of a device while concealing or misrepresenting its purpose.
- [Fileless malware](<https://yellowcube.eu/glossary/fileless-malware/index.md>): Fileless malware is malicious code or activity that executes mainly from memory or through existing system facilities instead of relying on a conventional executable stored on disk.
- [Malvertising](<https://yellowcube.eu/glossary/malvertising/index.md>): Malvertising is the malicious use of online advertising to deliver malware, deceptive redirects, credential theft, fraud, or other harmful activity.
- [Cryptojacking](<https://yellowcube.eu/glossary/cryptojacking/index.md>): Cryptojacking is the unauthorized use of another party’s devices, accounts, or computing services to mine cryptocurrency.
- [Botnet](<https://yellowcube.eu/glossary/botnet/index.md>): A botnet is a collection of compromised or otherwise illicitly controlled connected systems that an operator coordinates to perform tasks at scale.
- [Exploit](<https://yellowcube.eu/glossary/exploit/index.md>): An exploit is code, data, commands, or a sequence of actions created or used to take advantage of a vulnerability and produce behavior that the affected system did not intend or authorize.
- [Remote code execution (RCE)](<https://yellowcube.eu/glossary/remote-code-execution/index.md>): Remote code execution (RCE) is the capability or impact whereby an attacker causes code or commands of their choice to run on a target system from another system or network location.
- [Buffer overflow](<https://yellowcube.eu/glossary/buffer-overflow/index.md>): A buffer overflow is a memory-safety weakness in which software writes more data to a memory buffer than its allocated bounds can hold, causing adjacent memory or control data to be overwritten.
- [Zero-day vulnerability](<https://yellowcube.eu/glossary/zero-day-vulnerability/index.md>): A zero-day vulnerability is a security weakness unknown to the affected technology’s supplier or maintainer when it is first disclosed or exploited, typically before a practical correction is available.
- [Lateral movement](<https://yellowcube.eu/glossary/lateral-movement/index.md>): Lateral movement is post-compromise activity in which an adversary uses an existing foothold to access or control additional systems, accounts, services, or environments.
- [Persistence](<https://yellowcube.eu/glossary/persistence/index.md>): Persistence is the set of mechanisms an attacker uses to retain access to a compromised environment across reboots, credential resets, software updates, and partial remediation.
- [Living off the land (LOTL)](<https://yellowcube.eu/glossary/living-off-the-land/index.md>): Living off the land (LOTL) is attacker tradecraft that abuses legitimate software, built-in system utilities, administration features, credentials, or trusted services to perform malicious actions.
- [Command and control (C2)](<https://yellowcube.eu/glossary/command-and-control/index.md>): Command and control (C2) is the attacker communication and coordination function that lets compromised systems, accounts, or services receive instructions and return status, results, or data.
- [Advanced persistent threat (APT)](<https://yellowcube.eu/glossary/advanced-persistent-threat/index.md>): An advanced persistent threat (APT) is a capable, well-resourced adversary — or, in common industry usage, its sustained campaign — that pursues strategic objectives over an extended period, uses multiple attack paths, adapts to resistance, and seeks to establish or renew access.
- [Threat actor](<https://yellowcube.eu/glossary/threat-actor/index.md>): A threat actor is an individual, group, or organization that is believed to conduct, direct, or support malicious cyber activity.
- [Cyber kill chain](<https://yellowcube.eu/glossary/cyber-kill-chain/index.md>): The cyber kill chain is a staged model of intrusion progression — reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives — originally published by Lockheed Martin.
- [Identity-based attack](<https://yellowcube.eu/glossary/identity-based-attack/index.md>): An identity-based attack is an industry umbrella term for an attack that targets or abuses digital identities, credentials, authenticators, sessions, entitlements, or identity infrastructure to obtain or retain unauthorized access.
- [Account takeover (ATO)](<https://yellowcube.eu/glossary/account-takeover/index.md>): Account takeover (ATO) is unauthorized control or effective use of an existing digital account by someone other than the legitimate account holder.
- [Session hijacking](<https://yellowcube.eu/glossary/session-hijacking/index.md>): Session hijacking is the takeover of an authenticated session — typically by stealing or replaying its token or cookie — so the attacker inherits the victim’s access without performing a login.
- [Identity theft](<https://yellowcube.eu/glossary/identity-theft/index.md>): Identity theft is the unauthorized use of another person’s personal or financial information to impersonate them, obtain money, services, credit, benefits, employment, or medical care, or commit another deception.
- [SIM swapping](<https://yellowcube.eu/glossary/sim-swapping/index.md>): SIM swapping is the fraudulent transfer of a victim’s phone number to an attacker-controlled SIM card, handing the attacker the victim’s calls and text messages — including one-time codes and account-recovery links.
- [Brute-force attack](<https://yellowcube.eu/glossary/brute-force-attack/index.md>): A brute-force attack repeatedly tests candidate values or credential combinations to obtain access or recover a secret.
- [Credential stuffing](<https://yellowcube.eu/glossary/credential-stuffing/index.md>): Credential stuffing is the automated or repeated use of previously exposed username-and-password pairs to attempt access to other accounts or services.
- [Password spraying](<https://yellowcube.eu/glossary/password-spraying/index.md>): Password spraying is an attack that tries a small set of common or likely passwords across many accounts, staying below per-account lockout thresholds while exploiting the statistical chance that some account uses a weak password.
- [Pharming](<https://yellowcube.eu/glossary/pharming/index.md>): Pharming is an attack that redirects a user who intends to reach a legitimate online service to a fraudulent destination, usually by altering name resolution, network or device configuration, or another trusted navigation mechanism.
- [Watering hole attack](<https://yellowcube.eu/glossary/watering-hole-attack/index.md>): A watering hole attack targets a group by compromising or abusing an online destination that its members are likely to visit, then using that destination to profile, redirect, deceive, or attack selected visitors.
- [Drive-by compromise](<https://yellowcube.eu/glossary/drive-by-compromise/index.md>): A drive-by compromise is unauthorized access gained through a victim’s visit to a website — by exploiting the browser or its components, or by deceiving the visitor into downloading or running content — without requiring the victim to knowingly install software.
- [Domain Name System (DNS) hijacking](<https://yellowcube.eu/glossary/domain-name-system-hijacking/index.md>): Domain Name System (DNS) hijacking is unauthorized takeover or alteration of DNS administration, delegation, authoritative data, resolver selection, or network or device configuration so queries use attacker-chosen infrastructure or records.
- [Domain Name System (DNS) cache poisoning](<https://yellowcube.eu/glossary/domain-name-system-cache-poisoning/index.md>): Domain Name System (DNS) cache poisoning occurs when a recursive resolver accepts false DNS data and stores it as though authentic.
- [Fast-flux network](<https://yellowcube.eu/glossary/fast-flux-network/index.md>): A fast-flux network uses frequent changes in the Internet Protocol (IP) addresses or name-server infrastructure associated with a domain to keep an online service reachable while making its controlling systems harder to identify or block.
- [Deepfake](<https://yellowcube.eu/glossary/deepfake/index.md>): A deepfake is audio, video, or imagery generated or significantly manipulated with artificial intelligence to resemble a person, object, place, entity, or event and falsely appear authentic or truthful.
- [Cybersquatting](<https://yellowcube.eu/glossary/cybersquatting/index.md>): Cybersquatting is the bad-faith registration or use of a domain name that targets another party’s trademark or service mark, commonly to profit from confusion, divert users, demand payment, or support impersonation.
- [Typosquatting](<https://yellowcube.eu/glossary/typosquatting/index.md>): Typosquatting is the registration of lookalike domain names based on misspellings, keyboard slips, or visual confusion with legitimate names — capturing mistyped traffic or supporting phishing and impersonation.
- [Internet fraud](<https://yellowcube.eu/glossary/internet-fraud/index.md>): Internet fraud is intentional deception conducted primarily or exclusively through online services to obtain money, property, credentials, personal information, or another benefit, or to cause a victim to act against their interests.
- [Dark web](<https://yellowcube.eu/glossary/dark-web/index.md>): The dark web is the intentionally obscured part of the internet whose services require specialized software, configuration, or authorization to reach.
- [Wardriving](<https://yellowcube.eu/glossary/wardriving/index.md>): Wardriving is an industry term for discovering, recording, or mapping wireless networks while moving through an area.
- [Ransomware](<https://yellowcube.eu/glossary/ransomware/index.md>): Ransomware is malicious activity designed to coerce payment by denying access to systems or data, threatening disclosure, or combining both.
- [Ransomware as a service (RaaS)](<https://yellowcube.eu/glossary/ransomware-as-a-service/index.md>): Ransomware as a service (RaaS) is a criminal service model in which a provider develops or maintains ransomware capabilities and makes them available to other operators, often called affiliates, who conduct intrusions or extortion.
- [Cyber extortion](<https://yellowcube.eu/glossary/cyber-extortion/index.md>): Cyber extortion is coercion carried out through or against digital systems in which an actor demands money, access, services, or another benefit and threatens cyber-enabled harm if the demand is refused.
- [Supply-chain attack](<https://yellowcube.eu/glossary/supply-chain-attack/index.md>): A supply-chain attack uses a product, service, supplier, development or delivery process, trusted update path, or other upstream dependency as a route to affect downstream users.
- [Cyberwarfare](<https://yellowcube.eu/glossary/cyberwarfare/index.md>): Cyberwarfare is a contested policy and legal term for cyber operations used as means or methods of warfare, or otherwise integrated with military action, to create strategic or operational effects.
- [Hacktivism](<https://yellowcube.eu/glossary/hacktivism/index.md>): Hacktivism is a motive-based label for cyber activity carried out to promote, oppose, or draw attention to a political, social, religious, or ideological cause.
- [Cyber espionage](<https://yellowcube.eu/glossary/cyber-espionage/index.md>): Cyber espionage is covert, unauthorized access to digital systems or communications to obtain sensitive information for strategic, political, military, technological, or commercial intelligence advantage.
- [Eavesdropping attack](<https://yellowcube.eu/glossary/eavesdropping-attack/index.md>): An eavesdropping attack is unauthorized observation or capture of communications, commonly performed without altering the traffic or alerting the communicating parties.
- [Man-in-the-middle (MITM) attack](<https://yellowcube.eu/glossary/man-in-the-middle-attack/index.md>): A man-in-the-middle (MITM) attack is an active communications attack in which an adversary interposes between two parties, relays their exchanges, and may read, alter, inject, delay, or block data while each party believes it is communicating directly with the other.

### Incident response and threat intelligence

- [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/index.md>): Incident response is the organized way an organization prepares for, detects, analyzes, contains, recovers from, and learns from cybersecurity incidents.
- [Security incident](<https://yellowcube.eu/glossary/security-incident/index.md>): A security incident is an occurrence that actually or potentially jeopardizes the confidentiality, integrity, or availability of information or systems and meets the organization’s threshold for coordinated handling.
- [Digital forensics and incident response (DFIR)](<https://yellowcube.eu/glossary/digital-forensics-and-incident-response/index.md>): Digital forensics and incident response is an operating discipline that integrates incident response with the collection and analysis of digital evidence.
- [Security playbook](<https://yellowcube.eu/glossary/security-playbook/index.md>): A security playbook is a documented response approach for a recurring security scenario, such as ransomware, credential compromise or data exposure.
- [Security runbook](<https://yellowcube.eu/glossary/security-runbook/index.md>): A security runbook is a repeatable, task-level procedure for carrying out a defined operational action.
- [Malware analysis](<https://yellowcube.eu/glossary/malware-analysis/index.md>): Malware analysis is the authorized examination of suspected malicious software or related artifacts to determine their structure, capabilities, behavior, indicators, dependencies, and potential impact.
- [Chain of custody](<https://yellowcube.eu/glossary/chain-of-custody/index.md>): Chain of custody is the documented, auditable record of who collected, handled, transferred, stored, and analyzed evidence — proving it was not altered or substituted between collection and use.
- [Root cause analysis](<https://yellowcube.eu/glossary/root-cause-analysis/index.md>): Root cause analysis is the structured investigation of why an incident or failure occurred, so fixes remove the underlying cause rather than only its symptoms.
- [Cyber threat intelligence (CTI)](<https://yellowcube.eu/glossary/cyber-threat-intelligence/index.md>): Cyber threat intelligence is evidence-based knowledge about threats that is collected, analyzed, and placed in context to support a decision.
- [Indicator of compromise (IoC)](<https://yellowcube.eu/glossary/indicator-of-compromise/index.md>): An indicator of compromise (IoC) is an observable artifact or condition that suggests malicious activity may be occurring or may have occurred.
- [Tactics, techniques, and procedures (TTPs)](<https://yellowcube.eu/glossary/tactics-techniques-and-procedures/index.md>): Tactics, techniques, and procedures (TTPs) describe how threat actors pursue objectives and carry out attacks.
- [Threat intelligence platform (TIP)](<https://yellowcube.eu/glossary/threat-intelligence-platform/index.md>): A threat intelligence platform is a system used to manage the lifecycle of cyber threat information and intelligence from multiple internal and external sources.
- [STIX and TAXII](<https://yellowcube.eu/glossary/stix-and-taxii/index.md>): STIX and TAXII are OASIS open standards for cyber threat intelligence — STIX defines how intelligence is represented as structured objects, and TAXII defines how that intelligence is exchanged between systems.
- [Threat intelligence feed](<https://yellowcube.eu/glossary/threat-intelligence-feed/index.md>): A threat intelligence feed is a machine-readable stream of indicators, observations, or reports from external or internal sources, consumed into security tools to inform detection and blocking.
- [Open-source intelligence (OSINT)](<https://yellowcube.eu/glossary/open-source-intelligence/index.md>): Open-source intelligence is intelligence derived exclusively from publicly or commercially available information, collected and analyzed to answer specific requirements.

### Security operations and managed security

- [Security operations center (SOC)](<https://yellowcube.eu/glossary/security-operations-center/index.md>): A security operations center (SOC) is the people, processes, and technology responsible for continuously monitoring an organization’s digital environment and coordinating the detection, investigation, and response to security incidents.
- [Security operations (SecOps)](<https://yellowcube.eu/glossary/security-operations/index.md>): Security operations (SecOps) is the ongoing organizational function and set of practices used to monitor security-relevant activity, operate defensive controls, detect and investigate threats, coordinate response, and improve protections from operational evidence.
- [Security information and event management (SIEM)](<https://yellowcube.eu/glossary/security-information-and-event-management/index.md>): Security information and event management (SIEM) is a platform for collecting, normalizing, searching, correlating, and retaining security-relevant event data from multiple systems.
- [Security orchestration, automation and response (SOAR)](<https://yellowcube.eu/glossary/security-orchestration-automation-and-response/index.md>): Security orchestration, automation and response (SOAR) is a capability for coordinating security tools, case data, and repeatable workflows.
- [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/index.md>): Detection engineering is the disciplined process of designing, testing, deploying, and maintaining ways to identify suspicious or harmful activity.
- [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/index.md>): Threat hunting is a proactive, evidence-driven search for malicious activity that existing controls have not already surfaced with sufficient confidence.
- [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/index.md>): Security telemetry is the security-relevant evidence generated by systems, identities, endpoints, applications, networks, cloud services, and protective controls.
- [Alert triage](<https://yellowcube.eu/glossary/alert-triage/index.md>): Alert triage is the initial, structured assessment of a security alert to decide what it may represent, how urgently it needs attention, and what should happen next.
- [False positive](<https://yellowcube.eu/glossary/false-positive/index.md>): A false positive is a security finding that incorrectly indicates that a defined malicious condition, policy violation or vulnerability is present.
- [False negative](<https://yellowcube.eu/glossary/false-negative/index.md>): A false negative is a failure to detect or report a real threat — the dangerous counterpart of a false positive, because it produces silent misses rather than noise.
- [Mean time to detect (MTTD)](<https://yellowcube.eu/glossary/mean-time-to-detect/index.md>): Mean time to detect is the arithmetic average time between a defined starting event and the point at which an organization detects it.
- [Mean time to respond (MTTR)](<https://yellowcube.eu/glossary/mean-time-to-respond/index.md>): Mean time to respond is the arithmetic average time between a defined starting point and a defined response milestone across a stated set of events or incidents.
- [Dwell time](<https://yellowcube.eu/glossary/dwell-time/index.md>): Dwell time is how long an attacker remains inside an environment before detection — the interval between initial compromise and discovery.
- [Security metrics](<https://yellowcube.eu/glossary/security-metrics/index.md>): Security metrics are the measurements used to describe control coverage, detection performance, exposure, and program effectiveness over time.
- [Artificial intelligence for IT operations (AIOps)](<https://yellowcube.eu/glossary/artificial-intelligence-for-it-operations/index.md>): Artificial intelligence for IT operations (AIOps) is a market term for applying machine learning and other AI techniques to information-technology operations data and workflows.
- [AI in cybersecurity](<https://yellowcube.eu/glossary/ai-in-cybersecurity/index.md>): Artificial intelligence (AI) in cybersecurity is the use of AI methods to support defensive security work such as analyzing telemetry, detecting anomalies, prioritizing alerts, finding malicious patterns, summarizing evidence, generating or reviewing code, and recommending response actions.
- [Endpoint detection and response (EDR)](<https://yellowcube.eu/glossary/endpoint-detection-and-response/index.md>): Endpoint detection and response (EDR) is a security capability that continuously records and analyzes activity on endpoint devices so defenders can detect suspicious behavior, investigate what happened, and take response actions.
- [Network detection and response (NDR)](<https://yellowcube.eu/glossary/network-detection-and-response/index.md>): Network detection and response (NDR) is a security capability that analyzes network communications to identify suspicious behavior, support investigation, and trigger or guide response.
- [Extended detection and response (XDR)](<https://yellowcube.eu/glossary/extended-detection-and-response/index.md>): Extended detection and response (XDR) is a security technology approach that collects and correlates telemetry from multiple control points — commonly endpoints, identities, email, cloud workloads, and networks — to support detection, investigation, and response from a more unified view.
- [User and entity behavior analytics (UEBA)](<https://yellowcube.eu/glossary/user-and-entity-behavior-analytics/index.md>): User and entity behavior analytics is an analytical approach that models activity associated with users and other entities, then identifies deviations or combinations of behavior that may deserve investigation.
- [Behavioral analytics](<https://yellowcube.eu/glossary/behavioral-analytics/index.md>): Behavioral analytics is a broad analytical approach that examines activity, sequences, relationships, and changes over time to identify behavior that is relevant to a security question.
- [Heuristic analysis](<https://yellowcube.eu/glossary/heuristic-analysis/index.md>): Heuristic analysis evaluates rules, features, structural clues, or behavioral patterns to flag activity or content that appears suspicious even when it does not exactly match a known signature.
- [Sandboxing](<https://yellowcube.eu/glossary/sandboxing/index.md>): Sandboxing is the practice of running code or processing content inside a controlled environment whose policy restricts access to resources such as files, devices, memory, processes, credentials, and networks.
- [MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge)](<https://yellowcube.eu/glossary/mitre-att-and-ck-adversarial-tactics-techniques-and-common-knowledge/index.md>): MITRE ATT&CK is a publicly accessible, maintained knowledge base that organizes adversary behavior observed in real-world activity.
- [Cloud detection and response (CDR)](<https://yellowcube.eu/glossary/cloud-detection-and-response/index.md>): Cloud detection and response (CDR) is a non-standard industry label for capabilities and practices that use cloud-specific telemetry to detect suspicious activity, investigate its scope, and take or guide response actions.
- [Deception technology](<https://yellowcube.eu/glossary/deception-technology/index.md>): Deception technology is an industry umbrella term for controlled decoys, fabricated artifacts, misleading responses, and monitoring designed to attract, divert, delay, or reveal unauthorized activity.
- [Honeypot](<https://yellowcube.eu/glossary/honeypot/index.md>): A honeypot is a monitored decoy system, service, or network resource designed to attract and record unauthorized or suspicious interaction.
- [Honeytoken](<https://yellowcube.eu/glossary/honeytoken/index.md>): A honeytoken is a deliberately fabricated data item, identifier, or credential placed where legitimate activity should not access or use it.
- [Canary token](<https://yellowcube.eu/glossary/canary-token/index.md>): A canary token is a common, non-standard label for a honeytoken or lightweight decoy artifact configured to generate a signal when someone resolves, opens, accesses, or attempts to use it.
- [Endpoint security](<https://yellowcube.eu/glossary/endpoint-security/index.md>): Endpoint security is the discipline of protecting devices and workloads that connect to organizational services, process data, or run applications.
- [Endpoint protection platform (EPP)](<https://yellowcube.eu/glossary/endpoint-protection-platform/index.md>): An endpoint protection platform (EPP) is an industry category for centrally managed safeguards on endpoint devices, with an emphasis on preventing or blocking attacks.
- [Antivirus](<https://yellowcube.eu/glossary/antivirus/index.md>): Antivirus is malware-focused software that attempts to detect, block, quarantine, or remove malicious code on a device or at a content-processing point.
- [Mobile security](<https://yellowcube.eu/glossary/mobile-security/index.md>): Mobile security is the discipline of protecting smartphones, tablets, their data, applications, identities, communications, and access to organizational services throughout acquisition, enrollment, use, maintenance, loss, transfer, and disposal.
- [Device control](<https://yellowcube.eu/glossary/device-control/index.md>): Device control is an endpoint security capability that governs the connection and use of peripheral devices and external interfaces.
- [Managed security service provider (MSSP)](<https://yellowcube.eu/glossary/managed-security-service-provider/index.md>): A managed security service provider is an external organization that delivers ongoing cybersecurity functions for a customer under a service agreement.
- [Managed detection and response (MDR)](<https://yellowcube.eu/glossary/managed-detection-and-response/index.md>): Managed detection and response (MDR) is a security service in which an external team monitors agreed parts of a customer’s environment, investigates suspicious activity, and helps contain or remediate confirmed threats.
- [Managed extended detection and response (MXDR)](<https://yellowcube.eu/glossary/managed-extended-detection-and-response/index.md>): Managed extended detection and response is an industry label for a managed security service that uses extended detection and response capabilities across multiple technology domains.
- [Security operations center as a service (SOCaaS)](<https://yellowcube.eu/glossary/security-operations-center-as-a-service/index.md>): SOC as a service (SOCaaS) is an outsourced model in which a provider performs an agreed set of security operations functions for a customer.
- [Service-level agreement (SLA)](<https://yellowcube.eu/glossary/service-level-agreement/index.md>): A security service-level agreement is the contractual commitment defining what a provider will deliver — response times, availability, coverage, notification duties — and what happens when it falls short.

### Security validation and exposure management

- [Penetration testing](<https://yellowcube.eu/glossary/penetration-testing/index.md>): Penetration testing is an authorized, time-bounded security assessment in which skilled testers attempt to identify and safely exploit weaknesses within an agreed scope.
- [Red team](<https://yellowcube.eu/glossary/red-team/index.md>): A red team is an authorized group that emulates the behavior of a plausible adversary to test how well an organization protects important missions, business processes, assets, and data.
- [Purple team](<https://yellowcube.eu/glossary/purple-team/index.md>): Purple teaming is a collaborative security-testing approach in which offensive testers and defenders work together to improve preventive controls, telemetry, detections, investigations, and response.
- [Blue team](<https://yellowcube.eu/glossary/blue-team/index.md>): A blue team is the defensive side in security exercises and operations — the people and processes that detect, respond to, and withstand simulated or real attacks.
- [Breach and attack simulation (BAS)](<https://yellowcube.eu/glossary/breach-and-attack-simulation/index.md>): Breach and attack simulation (BAS) is an industry term for controlled, usually automated security testing that executes predefined attack-like actions and records how selected controls, telemetry, alerts, and response processes behave.
- [Cyber range](<https://yellowcube.eu/glossary/cyber-range/index.md>): A cyber range is an isolated or controlled environment that represents networks, systems, applications, security tools, users, and attack activity for hands-on cybersecurity learning, exercises, research, or testing.
- [Tabletop exercise](<https://yellowcube.eu/glossary/tabletop-exercise/index.md>): A tabletop exercise is a discussion-based simulation where participants walk through a hypothetical incident to test plans, roles, and decision-making — without touching live systems.
- [Adversary emulation](<https://yellowcube.eu/glossary/adversary-emulation/index.md>): Adversary emulation is the practice of reproducing a specific threat actor’s known tactics, techniques, and procedures to test whether defenses detect and stop that actor’s real behavior.
- [Rules of engagement](<https://yellowcube.eu/glossary/rules-of-engagement/index.md>): Rules of engagement are the agreed boundaries for a security exercise or test — what may be attacked, when, how, by whom, and what is explicitly off-limits.
- [Attack surface management (ASM)](<https://yellowcube.eu/glossary/attack-surface-management/index.md>): Attack surface management (ASM) is an ongoing practice of discovering, attributing, tracking, and reducing assets and exposures that contribute to an organization’s attack surface.
- [External attack surface management (EASM)](<https://yellowcube.eu/glossary/external-attack-surface-management/index.md>): External attack surface management is the continuous discovery and monitoring of an organization’s internet-facing assets and exposures — the view an outside attacker sees without internal access.
- [Continuous threat exposure management (CTEM)](<https://yellowcube.eu/glossary/continuous-threat-exposure-management/index.md>): Continuous threat exposure management (CTEM) is a Gartner-defined, recurring program model for identifying, prioritizing, validating, and reducing exposures that could harm important business services.
- [Threat modeling](<https://yellowcube.eu/glossary/threat-modeling/index.md>): Threat modeling is a structured, repeatable analysis of how a system could be harmed or abused and what design decisions can reduce that risk.
- [Port scanning](<https://yellowcube.eu/glossary/port-scanning/index.md>): Port scanning is the active testing of multiple transport-layer ports on a host or address to infer whether network services are reachable, listening, closed, or filtered from the scanner’s vantage point.
- [Vulnerability management](<https://yellowcube.eu/glossary/vulnerability-management/index.md>): Vulnerability management is the ongoing, risk-informed process of finding, recording, evaluating, prioritizing, treating, and verifying vulnerabilities across technology and its lifecycle.
- [Patch management](<https://yellowcube.eu/glossary/patch-management/index.md>): Patch management is the governed process of identifying, prioritizing, testing, deploying, and verifying software updates — including the security fixes that close exploitable vulnerabilities.
- [Vulnerability assessment](<https://yellowcube.eu/glossary/vulnerability-assessment/index.md>): A vulnerability assessment is a scoped evaluation that identifies and analyzes weaknesses in a system, product, service, process, or defined environment.
- [Vulnerability scanning](<https://yellowcube.eu/glossary/vulnerability-scanning/index.md>): Vulnerability scanning is the automated probing or analysis of systems, applications, configurations, software inventories, or artifacts to identify conditions associated with known weaknesses or unsafe settings.
- [Coordinated vulnerability disclosure (CVD)](<https://yellowcube.eu/glossary/coordinated-vulnerability-disclosure/index.md>): Coordinated vulnerability disclosure (CVD) is a process in which a vulnerability reporter, affected supplier or maintainer, deployers, coordinators, and other relevant parties exchange information so a weakness can be validated, addressed, and communicated with reduced avoidable harm.
- [Bug bounty](<https://yellowcube.eu/glossary/bug-bounty/index.md>): A bug bounty is a program that rewards external security researchers for reporting qualifying vulnerabilities in an organization’s systems or products under a defined scope and rules.

### Identity and access

- [Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/index.md>): Identity and access management (IAM) is the discipline and supporting technology used to establish digital identities and control their access to systems, applications, and data.
- [Access control](<https://yellowcube.eu/glossary/access-control/index.md>): Access control is the process of allowing or denying a subject’s request to use a resource, perform an action, or enter a protected environment.
- [Authentication](<https://yellowcube.eu/glossary/authentication/index.md>): Authentication is the process of establishing confidence that a claimant controls one or more authenticators bound to the identity or account being presented.
- [Authorization](<https://yellowcube.eu/glossary/authorization/index.md>): Authorization is the process or decision that determines whether a subject may perform a requested action on a resource.
- [Authentication, authorization, and accounting (AAA)](<https://yellowcube.eu/glossary/authentication-authorization-and-accounting/index.md>): Authentication, authorization, and accounting (AAA) is an architectural model for coordinating three access functions: verifying a requesting identity, determining which services or actions it may use, and recording relevant activity or resource consumption.
- [Role-based access control (RBAC)](<https://yellowcube.eu/glossary/role-based-access-control/index.md>): Role-based access control (RBAC) is an access-control model in which permissions are assigned to roles representing job functions or responsibilities, and identities receive permissions by being assigned to those roles.
- [Least privilege](<https://yellowcube.eu/glossary/least-privilege/index.md>): Least privilege is the principle of giving a user, service, device, or process only the permissions and resources needed to perform its authorized function.
- [Separation of duties](<https://yellowcube.eu/glossary/separation-of-duties/index.md>): Separation of duties splits critical tasks and powers across multiple people or roles so that no single individual can complete a sensitive or fraudulent action alone.
- [Multi-factor authentication (MFA)](<https://yellowcube.eu/glossary/multi-factor-authentication/index.md>): Multi-factor authentication (MFA) verifies a user with factors from at least two different categories: something the user knows, something the user possesses, or something the user is.
- [Passwordless authentication](<https://yellowcube.eu/glossary/passwordless-authentication/index.md>): Passwordless authentication verifies a user without requiring that user to supply a reusable password to the target service.
- [Passkey](<https://yellowcube.eu/glossary/passkey/index.md>): A passkey is a discoverable FIDO credential used for passwordless authentication.
- [Phishing-resistant authentication](<https://yellowcube.eu/glossary/phishing-resistant-authentication/index.md>): Phishing-resistant authentication binds the authentication proof to the legitimate service, so a credential captured or replayed on a fake site is useless — typically via passkeys, FIDO2/WebAuthn, or certificate-based methods.
- [Authentication token](<https://yellowcube.eu/glossary/authentication-token/index.md>): Authentication token is a context-dependent term for a value or device used during authentication or to carry forward the result of successful authentication.
- [Login credentials](<https://yellowcube.eu/glossary/login-credentials/index.md>): The phrase “login credentials” is a common umbrella term for the identifiers and authenticators used to sign in to an account or service.
- [Password manager](<https://yellowcube.eu/glossary/password-manager/index.md>): A password manager is an application or built-in platform feature that generates, stores, and fills unique credentials so that people do not have to memorize — or reuse — passwords.
- [API key](<https://yellowcube.eu/glossary/api-key/index.md>): An application programming interface (API) key is a string issued by an API provider to identify a calling application, project, or client and associate requests with permissions, quotas, or billing rules.
- [Conditional access](<https://yellowcube.eu/glossary/conditional-access/index.md>): Conditional access is an authorization approach that evaluates contextual signals before allowing, denying, or restricting access to a resource.
- [Just-in-time access (JIT access)](<https://yellowcube.eu/glossary/just-in-time-access/index.md>): Just-in-time access is a method of granting access or elevated privileges only when they are needed for a defined task, then revoking them automatically after a short period or when the task ends.
- [Session management](<https://yellowcube.eu/glossary/session-management/index.md>): Session management controls what happens after login — how session tokens are issued, bound, refreshed, expired, and revoked so an authenticated session stays tied to its legitimate user.
- [Account recovery](<https://yellowcube.eu/glossary/account-recovery/index.md>): Account recovery is the process that restores access when credentials are lost or compromised — and because it bypasses normal authentication, it is a prime target for social engineering.
- [Identity proofing](<https://yellowcube.eu/glossary/identity-proofing/index.md>): Identity proofing verifies that a person claiming an identity really is that person — by checking evidence such as documents, biometrics, or records before a credential is issued.
- [Privileged access management (PAM)](<https://yellowcube.eu/glossary/privileged-access-management/index.md>): Privileged access management (PAM) is the set of policies, processes, and technologies used to control, monitor, and reduce access that can make high-impact changes to systems or data.
- [Privileged identity management (PIM)](<https://yellowcube.eu/glossary/privileged-identity-management/index.md>): Privileged identity management (PIM) is an industry term for governing which human or non-human identities are eligible for privileged roles and controlling when those roles become active.
- [Service account](<https://yellowcube.eu/glossary/service-account/index.md>): A service account is a non-human account created so an application, operating-system service, script, agent, or automated process can authenticate and access resources.
- [Non-human identity (NHI)](<https://yellowcube.eu/glossary/non-human-identity/index.md>): A non-human identity is any identity used by software rather than a person — service accounts, API keys, workload identities, certificates, tokens, and agents that authenticate to systems.
- [Federated identity](<https://yellowcube.eu/glossary/federated-identity/index.md>): Federated identity is an arrangement in which one administrative domain relies on identity and authentication information supplied by another trusted domain.
- [Identity provider (IdP)](<https://yellowcube.eu/glossary/identity-provider/index.md>): An identity provider is the system that authenticates users and issues proof of identity that other applications trust — the central sign-in behind SSO and federation.
- [Single sign-on (SSO)](<https://yellowcube.eu/glossary/single-sign-on/index.md>): Single sign-on (SSO) is an authentication process in which one account and its authenticators let a user access multiple applications without performing a full sign-in separately at each one.
- [Security Assertion Markup Language (SAML)](<https://yellowcube.eu/glossary/security-assertion-markup-language/index.md>): Security Assertion Markup Language (SAML) is an OASIS standard for XML-encoded assertions about authentication, subject attributes, and authorization decisions, together with protocols and profiles for exchanging them.
- [OpenID Connect (OIDC)](<https://yellowcube.eu/glossary/openid-connect/index.md>): OpenID Connect (OIDC) is an authentication and identity-federation layer built on OAuth 2.0.
- [OAuth 2.0](<https://yellowcube.eu/glossary/oauth-2-0/index.md>): OAuth 2.0 is an authorization framework that lets a client obtain limited access to an HTTP service without receiving the resource owner’s credentials.
- [System for Cross-domain Identity Management (SCIM)](<https://yellowcube.eu/glossary/system-for-cross-domain-identity-management/index.md>): System for Cross-domain Identity Management (SCIM) is an IETF standard for exchanging identity-resource data between systems so that accounts and groups can be created, read, updated, searched, disabled, or removed consistently.
- [Kerberos authentication](<https://yellowcube.eu/glossary/kerberos-authentication/index.md>): Kerberos authentication is a ticket-based network authentication protocol in which a trusted Key Distribution Center (KDC) helps a client and network service establish authenticated, time-limited credentials.
- [Lightweight Directory Access Protocol (LDAP)](<https://yellowcube.eu/glossary/lightweight-directory-access-protocol/index.md>): Lightweight Directory Access Protocol (LDAP) is an IETF protocol for accessing and managing information in a distributed directory service.
- [Remote Authentication Dial-In User Service (RADIUS)](<https://yellowcube.eu/glossary/remote-authentication-dial-in-user-service/index.md>): Remote Authentication Dial-In User Service (RADIUS) is a protocol for carrying authentication, authorization, configuration, and accounting information between a network access device and a central RADIUS server.
- [IEEE 802.1X authentication](<https://yellowcube.eu/glossary/ieee-802-1x-authentication/index.md>): IEEE 802.1X authentication is the use of the IEEE 802.1X port-based network access-control standard to authenticate and authorize a device or user before granting normal access through a wired or wireless local area network port.
- [Active Directory (AD)](<https://yellowcube.eu/glossary/active-directory/index.md>): Active Directory (AD) usually refers to Microsoft Active Directory Domain Services (AD DS), a distributed directory and identity service for Windows domain environments.
- [Identity as a service (IDaaS)](<https://yellowcube.eu/glossary/identity-as-a-service/index.md>): Identity as a service (IDaaS) is a cloud service model in which a provider delivers identity, credential, and access-management capabilities for customer organizations.
- [Customer identity and access management (CIAM)](<https://yellowcube.eu/glossary/customer-identity-and-access-management/index.md>): Customer identity and access management (CIAM) is the branch of identity and access management that supports people using an organization’s customer-facing digital services.
- [Identity threat detection and response (ITDR)](<https://yellowcube.eu/glossary/identity-threat-detection-and-response/index.md>): Identity threat detection and response is an industry label for the practices and capabilities used to detect, investigate, and contain attacks involving identities and identity infrastructure.
- [Zero trust network access (ZTNA)](<https://yellowcube.eu/glossary/zero-trust-network-access/index.md>): Zero trust network access (ZTNA) is an access approach that connects an authenticated and authorized user or device to a specific application or resource instead of granting broad reachability to a network.
- [Mobile device management (MDM)](<https://yellowcube.eu/glossary/mobile-device-management/index.md>): Mobile device management (MDM) centrally enrolls devices, applies configuration and security policy, distributes managed applications or credentials, collects status, and performs remote actions.
- [Unified endpoint management (UEM)](<https://yellowcube.eu/glossary/unified-endpoint-management/index.md>): Unified endpoint management (UEM) is an industry category for administering endpoint types through a management plane and policy model.
- [Bring your own device (BYOD)](<https://yellowcube.eu/glossary/bring-your-own-device/index.md>): Bring your own device (BYOD) is the practice of using a personally owned smartphone, tablet, or computer for work or access to organizational data and services.

### Network fundamentals

- [IP addressing: static and dynamic addresses](<https://yellowcube.eu/glossary/ip-addressing-static-and-dynamic-addresses/index.md>): IP addressing assigns an Internet Protocol address and related configuration to a network interface so packets can be delivered within the address’s scope.
- [Network address translation (NAT)](<https://yellowcube.eu/glossary/network-address-translation/index.md>): Network address translation (NAT) maps IP addresses from one address realm to another as packets cross a translating device.
- [TCP/IP protocol suite](<https://yellowcube.eu/glossary/tcp-ip-protocol-suite/index.md>): The TCP/IP protocol suite is the family of interoperating protocols that underpins the internet and many private networks.
- [User Datagram Protocol (UDP)](<https://yellowcube.eu/glossary/user-datagram-protocol/index.md>): User Datagram Protocol (UDP) is a transport protocol that carries independent messages, called datagrams, between application endpoints over Internet Protocol networks.
- [Open Systems Interconnection (OSI) model](<https://yellowcube.eu/glossary/open-systems-interconnection-model/index.md>): The Open Systems Interconnection (OSI) model is a seven-layer reference framework for describing how open systems communicate.
- [Time to live (TTL)](<https://yellowcube.eu/glossary/time-to-live/index.md>): Time to live (TTL) is an eight-bit Internet Protocol version 4 (IPv4) header field that limits packet travel.
- [Domain Name System (DNS)](<https://yellowcube.eu/glossary/domain-name-system/index.md>): The Domain Name System (DNS) is a distributed, hierarchical naming system, database, and query-response protocol.
- [Dynamic DNS (DDNS)](<https://yellowcube.eu/glossary/dynamic-dns/index.md>): Dynamic DNS (DDNS) is a method for updating Domain Name System records automatically when the underlying information changes.
- [Dynamic Host Configuration Protocol (DHCP)](<https://yellowcube.eu/glossary/dynamic-host-configuration-protocol/index.md>): Dynamic Host Configuration Protocol (DHCP) automatically supplies hosts with network configuration.
- [Address Resolution Protocol (ARP)](<https://yellowcube.eu/glossary/address-resolution-protocol/index.md>): Address Resolution Protocol (ARP) is used on IPv4 local networks to determine the link-layer address associated with an IPv4 address.
- [Internet Control Message Protocol (ICMP)](<https://yellowcube.eu/glossary/internet-control-message-protocol/index.md>): Internet Control Message Protocol (ICMP) carries error reports and operational information for Internet Protocol communications.
- [Simple Network Management Protocol (SNMP)](<https://yellowcube.eu/glossary/simple-network-management-protocol/index.md>): Simple Network Management Protocol (SNMP) is an application-layer framework and protocol family for observing and managing networked systems.
- [Border Gateway Protocol (BGP)](<https://yellowcube.eu/glossary/border-gateway-protocol/index.md>): Border Gateway Protocol (BGP) is the routing protocol used to exchange network reachability information between autonomous systems (ASes), such as internet service providers, cloud networks, and large organizations.
- [Multiprotocol Label Switching (MPLS)](<https://yellowcube.eu/glossary/multiprotocol-label-switching/index.md>): Multiprotocol Label Switching (MPLS) is a forwarding architecture in which network devices assign packets to a forwarding equivalence class and use short labels to direct them across an MPLS domain.
- [Quality of service (QoS)](<https://yellowcube.eu/glossary/quality-of-service/index.md>): Quality of service (QoS) is the use of network policies and resource-management mechanisms to provide different forwarding treatment to selected traffic.
- [Network latency](<https://yellowcube.eu/glossary/network-latency/index.md>): Network latency is the elapsed time for data to travel between defined points in a network.
- [Packet loss](<https://yellowcube.eu/glossary/packet-loss/index.md>): Packet loss is the failure of one or more transmitted packets to arrive at a defined destination within a stated waiting period.
- [Traceroute](<https://yellowcube.eu/glossary/traceroute/index.md>): Traceroute is an active network diagnostic technique that estimates the sequence of Internet Protocol (IP) hops toward a destination.
- [Network traffic](<https://yellowcube.eu/glossary/network-traffic/index.md>): Network traffic is the collection or stream of frames, packets, and higher-layer messages carried across network links and devices.
- [Ethernet switching](<https://yellowcube.eu/glossary/ethernet-switching/index.md>): Ethernet switching is the forwarding of Ethernet frames between ports in a bridged local-area network.
- [Wireless network](<https://yellowcube.eu/glossary/wireless-network/index.md>): A wireless network carries communications over electromagnetic signals rather than requiring a cable for every connected device.
- [Service set identifier (SSID)](<https://yellowcube.eu/glossary/service-set-identifier/index.md>): A service set identifier (SSID) is an identifier of up to 32 octets used for an IEEE 802.11 wireless service set.
- [Wide area network (WAN)](<https://yellowcube.eu/glossary/wide-area-network/index.md>): A wide area network (WAN) is a physical or logical network that connects users, sites, data centers, cloud environments, or other networks across a broader geographic area than a local area network.

### Network and edge security

- [Firewall](<https://yellowcube.eu/glossary/firewall/index.md>): A firewall is a device, service, or software control that permits, rejects, or otherwise handles network traffic according to defined policy.
- [Next-generation firewall (NGFW)](<https://yellowcube.eu/glossary/next-generation-firewall/index.md>): A next-generation firewall (NGFW) is an industry label for a firewall that combines traditional traffic control with deeper application-aware inspection and additional security functions.
- [Stateful firewall](<https://yellowcube.eu/glossary/stateful-firewall/index.md>): A stateful firewall filters network traffic using both a ruleset and recorded information about flows or connections.
- [Stateless packet filtering](<https://yellowcube.eu/glossary/stateless-packet-filtering/index.md>): Stateless packet filtering permits or denies each packet independently according to a ruleset, without maintaining a table that relates it to an established flow.
- [Proxy firewall](<https://yellowcube.eu/glossary/proxy-firewall/index.md>): “Proxy firewall” is a broad, non-standard label for a firewall architecture that uses a proxy as an intermediary between communicating endpoints.
- [Distributed firewall](<https://yellowcube.eu/glossary/distributed-firewall/index.md>): A distributed firewall is a non-standard architectural label for coordinated firewall policy enforced at multiple points rather than only at a central appliance.
- [Virtual firewall](<https://yellowcube.eu/glossary/virtual-firewall/index.md>): A virtual firewall is software that performs firewall policy enforcement inside a virtualized infrastructure rather than on a dedicated physical appliance.
- [Firewall as a service (FWaaS)](<https://yellowcube.eu/glossary/firewall-as-a-service/index.md>): Firewall as a service (FWaaS) is a market category for firewall capabilities operated as a network-accessible service, usually from provider-managed cloud points of presence.
- [Cloud firewall](<https://yellowcube.eu/glossary/cloud-firewall/index.md>): Cloud firewall is an industry term for firewall policy enforcement deployed in, integrated with, or delivered from a cloud environment.
- [Unified threat management (UTM)](<https://yellowcube.eu/glossary/unified-threat-management/index.md>): Unified threat management (UTM) is a market category for combining several network-security functions in one product or managed platform.
- [Intrusion detection system (IDS)](<https://yellowcube.eu/glossary/intrusion-detection-system/index.md>): An intrusion detection system (IDS) monitors network, host, wireless, application, or other events and analyzes them for signs of possible incidents or policy violations.
- [Intrusion prevention system (IPS)](<https://yellowcube.eu/glossary/intrusion-prevention-system/index.md>): An intrusion prevention system (IPS) analyzes network, host, wireless, or application activity for signs of possible incidents and can attempt to stop what it detects.
- [Deep packet inspection (DPI)](<https://yellowcube.eu/glossary/deep-packet-inspection/index.md>): Deep packet inspection (DPI) is a non-standard industry term for examining packet payloads and protocol context beyond basic network and transport headers.
- [Transport Layer Security (TLS) inspection](<https://yellowcube.eu/glossary/transport-layer-security-inspection/index.md>): TLS inspection is the deliberate decryption and re-encryption of TLS traffic at a trusted middlebox so security controls can see inside encrypted sessions.
- [Content filtering](<https://yellowcube.eu/glossary/content-filtering/index.md>): Content filtering is the policy-based inspection of application data or user-requested material to decide whether it should be allowed, blocked, quarantined, transformed, warned about, or recorded.
- [Uniform Resource Locator (URL) filtering](<https://yellowcube.eu/glossary/uniform-resource-locator-filtering/index.md>): URL filtering is the policy-based evaluation of a requested web address or related destination information to allow, block, warn, redirect, isolate, or record access.
- [Secure web gateway (SWG)](<https://yellowcube.eu/glossary/secure-web-gateway/index.md>): A secure web gateway (SWG) is a security service that mediates user or device access to web destinations and applies an organization’s outbound web-use and data-protection policies.
- [Virtual private network (VPN)](<https://yellowcube.eu/glossary/virtual-private-network/index.md>): A virtual private network (VPN) creates a logically separated communication environment over shared or public network infrastructure.
- [Remote-access VPN](<https://yellowcube.eu/glossary/remote-access-vpn/index.md>): A remote-access virtual private network (VPN) connects an individual client outside an organization’s local network to a VPN gateway or access service.
- [Site-to-site VPN](<https://yellowcube.eu/glossary/site-to-site-vpn/index.md>): A site-to-site virtual private network (VPN) connects two or more networks through VPN gateways across another network, commonly the internet.
- [SSL/TLS VPN](<https://yellowcube.eu/glossary/ssl-tls-vpn/index.md>): An SSL/TLS virtual private network (VPN) is an industry label for remote-access technology that uses Transport Layer Security (TLS) to protect communication between a client and a VPN gateway.
- [Split tunneling](<https://yellowcube.eu/glossary/split-tunneling/index.md>): Split tunneling is a remote-access routing arrangement in which selected traffic uses a protected tunnel to an organization while other traffic follows the device’s ordinary local or internet route.
- [Remote Desktop Protocol (RDP) security](<https://yellowcube.eu/glossary/remote-desktop-protocol-security/index.md>): Remote Desktop Protocol (RDP) security is the protection of remote interactive Windows sessions, their clients, hosts, credentials, gateways, and network paths.
- [Proxy server](<https://yellowcube.eu/glossary/proxy-server/index.md>): A proxy server is an intermediary that receives a client’s request and makes a corresponding request toward another server.
- [Reverse proxy](<https://yellowcube.eu/glossary/reverse-proxy/index.md>): A reverse proxy is a server-side intermediary that presents an endpoint to clients and forwards accepted requests to one or more backend or origin servers.
- [Transparent proxy](<https://yellowcube.eu/glossary/transparent-proxy/index.md>): A transparent proxy is an industry term for a proxy deployment in which network traffic is redirected to an intermediary without each client being explicitly configured to use it.
- [Open proxy](<https://yellowcube.eu/glossary/open-proxy/index.md>): An open proxy is a forward proxy that accepts relay requests from arbitrary or insufficiently restricted clients, commonly from the public internet.
- [Network segmentation](<https://yellowcube.eu/glossary/network-segmentation/index.md>): Network segmentation divides an environment into zones and controls the communications allowed between them.
- [Microsegmentation](<https://yellowcube.eu/glossary/microsegmentation/index.md>): Microsegmentation is a security design approach that places granular policy boundaries around small groups of, or individual, workloads, services, endpoints, or application components.
- [Demilitarized zone (DMZ)](<https://yellowcube.eu/glossary/demilitarized-zone/index.md>): A demilitarized zone (DMZ) is a controlled network segment placed between networks with different trust levels, commonly the public internet and an internal enterprise network.
- [Air gap](<https://yellowcube.eu/glossary/air-gap/index.md>): An air gap physically or logically isolates a system or network from untrusted networks — no shared cabling, wireless, or routine data path to the outside.
- [Network access control (NAC)](<https://yellowcube.eu/glossary/network-access-control/index.md>): Network access control (NAC) is a policy and enforcement capability that governs which users and devices may connect to a network and what network access they receive.
- [Network access control list (ACL)](<https://yellowcube.eu/glossary/network-access-control-list/index.md>): A network access control list (ACL) is a set of rules that permits or denies network traffic according to packet and interface attributes.
- [Network security](<https://yellowcube.eu/glossary/network-security/index.md>): Network security is the discipline of protecting network communications, infrastructure, services, and connected resources against unauthorized access, misuse, disruption, and manipulation while preserving required availability.
- [Software-defined perimeter (SDP)](<https://yellowcube.eu/glossary/software-defined-perimeter/index.md>): A software-defined perimeter (SDP) is an access architecture that limits network connectivity to explicitly authorized resources.
- [Secure access service edge (SASE)](<https://yellowcube.eu/glossary/secure-access-service-edge/index.md>): Secure access service edge (SASE) is an architecture and service-delivery model that combines wide-area networking with cloud-delivered security controls close to users, branches, applications, and other resources.
- [Security service edge (SSE)](<https://yellowcube.eu/glossary/security-service-edge/index.md>): Security service edge (SSE) is an architecture and service model that delivers multiple network-security capabilities — usually from cloud-based points of presence — to protect access to the web, software-as-a-service platforms, and private applications.
- [Software-defined wide area network (SD-WAN)](<https://yellowcube.eu/glossary/software-defined-wide-area-network/index.md>): A software-defined wide area network (SD-WAN) uses centrally defined policy and software-controlled edge functions to connect sites, data centers, cloud environments, and remote locations across one or more WAN transports.
- [Software-defined networking (SDN)](<https://yellowcube.eu/glossary/software-defined-networking/index.md>): Software-defined networking (SDN) is a programmable approach to networking that separates or abstracts decisions about traffic handling from the devices that forward packets.
- [Network as a service (NaaS)](<https://yellowcube.eu/glossary/network-as-a-service/index.md>): Network as a service (NaaS) is a service-delivery label for network capabilities consumed from a provider instead of wholly customer-operated infrastructure.
- [Network edge](<https://yellowcube.eu/glossary/network-edge/index.md>): The network edge is a context-dependent boundary or zone where an organization’s network connects to users, devices, workloads, providers, partner networks, access networks, or the public internet.
- [5G network security](<https://yellowcube.eu/glossary/5g-network-security/index.md>): 5G network security protects fifth-generation mobile-network services and their supporting infrastructure, identities, communications, and operations.
- [Branch networking](<https://yellowcube.eu/glossary/branch-networking/index.md>): Branch networking is the architecture and operation of network services at a facility outside an organization’s main campus or data center.
- [WAN aggregation](<https://yellowcube.eu/glossary/wan-aggregation/index.md>): WAN aggregation is a non-standard industry label for using multiple wide area network (WAN) links as coordinated logical connectivity.
- [Network monitoring](<https://yellowcube.eu/glossary/network-monitoring/index.md>): Network monitoring continuously collects and analyzes information about network infrastructure, connectivity, traffic, and service behavior to understand health, performance, capacity, availability, and security-relevant change.
- [Network automation](<https://yellowcube.eu/glossary/network-automation/index.md>): Network automation uses software to perform repeatable network lifecycle tasks from machine-readable inputs.
- [Wireless security](<https://yellowcube.eu/glossary/wireless-security/index.md>): Wireless security protects wireless networks, devices, communications, and management systems against unauthorized access, disclosure, manipulation, and disruption while preserving availability.
- [Distributed denial-of-service (DDoS) attack](<https://yellowcube.eu/glossary/distributed-denial-of-service-attack/index.md>): A distributed denial-of-service (DDoS) attack uses many systems or traffic sources to make a service unavailable or severely degraded.
- [Distributed denial-of-service (DDoS) mitigation](<https://yellowcube.eu/glossary/distributed-denial-of-service-mitigation/index.md>): DDoS mitigation is the combination of architecture, services, controls, and response procedures used to keep an online service available during a distributed denial-of-service attack.
- [Domain Name System (DNS) security](<https://yellowcube.eu/glossary/domain-name-system-security/index.md>): DNS security protects the availability, integrity, authenticity, and appropriate confidentiality of the Domain Name System and uses DNS activity as a source of defensive context.
- [Domain Name System Security Extensions (DNSSEC)](<https://yellowcube.eu/glossary/domain-name-system-security-extensions/index.md>): DNSSEC adds cryptographic signatures to DNS data, letting resolvers verify that an answer came from the authoritative zone and was not altered in transit.
- [Protective DNS](<https://yellowcube.eu/glossary/protective-dns/index.md>): Protective DNS is a resolver service that blocks lookups for domains known or assessed to be malicious — stopping connections to phishing, malware, and command-and-control infrastructure before they start.
- [Zero trust architecture (ZTA)](<https://yellowcube.eu/glossary/zero-trust-architecture/index.md>): Zero trust architecture (ZTA) is an enterprise security design in which access is not implicitly trusted solely because of network location, device ownership, or an earlier login.

### Cloud and application security

- [Cloud security](<https://yellowcube.eu/glossary/cloud-security/index.md>): Cloud security is the discipline of protecting data, identities, applications, workloads, management interfaces, and supporting services used in cloud computing.
- [Cloud service models: IaaS, PaaS, and SaaS](<https://yellowcube.eu/glossary/cloud-service-models-iaas-paas-and-saas/index.md>): The cloud service models describe how responsibility and control are divided between a cloud provider and customer.
- [Cloud security architecture](<https://yellowcube.eu/glossary/cloud-security-architecture/index.md>): Cloud security architecture is the documented structure of security responsibilities, trust boundaries, components, data flows, and control decisions for a cloud-based system or portfolio.
- [Shared responsibility model](<https://yellowcube.eu/glossary/shared-responsibility-model/index.md>): The shared responsibility model divides security duties between a cloud provider and its customer — the provider secures the cloud itself, while the customer secures what it places and configures in the cloud.
- [Public cloud security](<https://yellowcube.eu/glossary/public-cloud-security/index.md>): Public cloud security is the protection of data, identities, applications, configurations, and customer-controlled resources used in a public cloud deployment.
- [Hybrid cloud security](<https://yellowcube.eu/glossary/hybrid-cloud-security/index.md>): Hybrid cloud security is the protection of a cloud environment composed of two or more distinct deployment models — such as private and public clouds — that remain separate but are connected to support data or application portability.
- [Multi-cloud security](<https://yellowcube.eu/glossary/multi-cloud-security/index.md>): Multi-cloud security is an industry term for protecting an organization’s use of cloud services from more than one cloud provider.
- [Hybrid IT](<https://yellowcube.eu/glossary/hybrid-it/index.md>): Hybrid IT is a non-standard industry term for an information-technology estate that combines environments or delivery models under coordinated operation — for example, on-premises systems, private and public cloud services, hosted infrastructure, software as a service, edge locations, and legacy platforms.
- [Virtual private cloud (VPC)](<https://yellowcube.eu/glossary/virtual-private-cloud/index.md>): A virtual private cloud (VPC) is a provider-defined, logically isolated virtual network in a public cloud.
- [Cloud-native security](<https://yellowcube.eu/glossary/cloud-native-security/index.md>): Cloud-native security is the application of security engineering and operations to cloud-native architectures and delivery models, including loosely coupled services, containers, declarative application programming interfaces (APIs), immutable infrastructure that is replaced rather than modified, orchestration, and extensive automation.
- [Cloud application security](<https://yellowcube.eu/glossary/cloud-application-security/index.md>): Cloud application security is the practice of protecting applications delivered through or hosted on cloud services, together with their application data, identities, interfaces, configurations, secrets, and integrations.
- [SaaS security](<https://yellowcube.eu/glossary/saas-security/index.md>): Software as a service (SaaS) security is the practice of protecting an organization’s data, identities, configurations, integrations, and business processes in provider-operated applications.
- [Serverless security](<https://yellowcube.eu/glossary/serverless-security/index.md>): Serverless security is the protection of applications built with cloud services that abstract server provisioning and operational management from the customer.
- [Virtualization security](<https://yellowcube.eu/glossary/virtualization-security/index.md>): Virtualization security is the practice of protecting the software and hardware layers that create and run virtual machines and other virtual resources.
- [Virtual desktop infrastructure (VDI) security](<https://yellowcube.eu/glossary/virtual-desktop-infrastructure-security/index.md>): Virtual desktop infrastructure (VDI) security protects centrally hosted desktop operating-system instances and the services that deliver their display and input to user endpoints.
- [Edge computing](<https://yellowcube.eu/glossary/edge-computing/index.md>): Edge computing places selected computation, storage, and application functions close to a data source, user, device, or required action instead of relying exclusively on a distant centralized service.
- [Data center security](<https://yellowcube.eu/glossary/data-center-security/index.md>): Data center security is the coordinated protection of the facilities, people, hardware, networks, storage, virtualization layers, management systems, and operational processes that host computing services.
- [Cloud network security](<https://yellowcube.eu/glossary/cloud-network-security/index.md>): Cloud network security is the practice of protecting the network paths, services, control interfaces, and traffic that connect cloud resources, users, on-premises systems, and external services.
- [Cloud security posture management (CSPM)](<https://yellowcube.eu/glossary/cloud-security-posture-management/index.md>): Cloud security posture management (CSPM) is an industry category for continuously discovering cloud resources and assessing their configuration against security policies, architecture rules, and compliance requirements.
- [Cloud workload protection platform (CWPP)](<https://yellowcube.eu/glossary/cloud-workload-protection-platform/index.md>): A cloud workload protection platform (CWPP) is an industry category for technology that protects software workloads running in cloud or cloud-like environments.
- [Cloud infrastructure entitlement management (CIEM)](<https://yellowcube.eu/glossary/cloud-infrastructure-entitlement-management/index.md>): Cloud infrastructure entitlement management (CIEM) is an industry category for discovering, analyzing, and governing permissions across cloud infrastructure.
- [Cloud-native application protection platform (CNAPP)](<https://yellowcube.eu/glossary/cloud-native-application-protection-platform/index.md>): A cloud-native application protection platform (CNAPP) is an industry category for an integrated set of capabilities that helps secure cloud-native applications and infrastructure from development through production.
- [Cloud access security broker (CASB)](<https://yellowcube.eu/glossary/cloud-access-security-broker/index.md>): A cloud access security broker (CASB) is an industry category for a security capability placed logically between cloud-service consumers and providers or connected through provider application programming interfaces.
- [SaaS security posture management (SSPM)](<https://yellowcube.eu/glossary/saas-security-posture-management/index.md>): SaaS security posture management (SSPM) is a non-standard market category for processes and tools that inventory supported software-as-a-service tenants and assess their security configuration over time.
- [Application security](<https://yellowcube.eu/glossary/application-security/index.md>): Application security is the discipline of reducing security risk in software and the systems on which it depends throughout planning, design, development, testing, release, operation, and retirement.
- [Web application security](<https://yellowcube.eu/glossary/web-application-security/index.md>): Web application security is the application-security discipline applied to software delivered through web technologies and used through browsers or other web clients.
- [Open Worldwide Application Security Project (OWASP) Top 10](<https://yellowcube.eu/glossary/open-worldwide-application-security-project-top-10/index.md>): The OWASP Top 10 is a periodically updated awareness document from the Open Worldwide Application Security Project (OWASP) that groups and explains ten of the most significant categories of web application security risk.
- [Mobile application security](<https://yellowcube.eu/glossary/mobile-application-security/index.md>): Mobile application security is the discipline of protecting software designed for mobile platforms throughout its design, development, distribution, operation, and retirement.
- [Browser security](<https://yellowcube.eu/glossary/browser-security/index.md>): Browser security is the protection of web-browsing software, its users, and the surrounding device from hostile content, unsafe downloads, vulnerable components, malicious or overprivileged extensions, credential theft, and misuse of browser data.
- [Runtime application self-protection (RASP)](<https://yellowcube.eu/glossary/runtime-application-self-protection/index.md>): Runtime application self-protection (RASP) is a variable industry category for controls integrated with or closely coupled to an application’s runtime so they can observe execution context and detect, report, or block selected malicious behavior while the application runs.
- [Virtual patching](<https://yellowcube.eu/glossary/virtual-patching/index.md>): Virtual patching is a compensating security measure that places an enforcement rule between an exploitable system and relevant requests or traffic, blocking or constraining known exploit paths while the underlying code or component remains unchanged.
- [Security misconfiguration](<https://yellowcube.eu/glossary/security-misconfiguration/index.md>): Security misconfiguration is a security-relevant setting or operational state that is missing, incorrect, inconsistent, excessively permissive, or unsuitable for its intended environment.
- [Structured Query Language (SQL) injection](<https://yellowcube.eu/glossary/structured-query-language-injection/index.md>): SQL injection is an injection weakness in which untrusted data alters the structure or meaning of a Structured Query Language (SQL) command.
- [Cross-site scripting (XSS)](<https://yellowcube.eu/glossary/cross-site-scripting/index.md>): Cross-site scripting (XSS) is a web application weakness that allows attacker-controlled content to be interpreted as executable code in another user’s browser within a trusted application context.
- [Cross-site request forgery (CSRF)](<https://yellowcube.eu/glossary/cross-site-request-forgery/index.md>): Cross-site request forgery (CSRF) is a web weakness in which an attacker causes a user’s browser or client-side code to send an unintended request to an application that trusts the user’s existing authenticated context.
- [Clickjacking](<https://yellowcube.eu/glossary/clickjacking/index.md>): Clickjacking, also called user-interface redressing, is an attack in which a malicious interface conceals, overlays, or repositions content from another application so a user’s click or tap activates a control different from the one the user perceives.
- [DevSecOps](<https://yellowcube.eu/glossary/devsecops/index.md>): DevSecOps is an operating practice that integrates security work into software development and operations instead of assigning it to a final review or a separate team.
- [Shift-left security](<https://yellowcube.eu/glossary/shift-left-security/index.md>): Shift-left security is an industry practice of moving suitable security decisions, evidence, and feedback earlier in the software or system lifecycle, closer to requirements, design, and implementation.
- [Continuous integration and continuous delivery or deployment (CI/CD) pipeline security](<https://yellowcube.eu/glossary/continuous-integration-and-continuous-delivery-or-deployment-pipeline-security/index.md>): Continuous integration and continuous delivery or deployment (CI/CD) pipeline security is the protection of the systems, identities, code, dependencies, instructions, execution environments, and artifacts used to build, test, approve, and release software.
- [Infrastructure as code (IaC) security](<https://yellowcube.eu/glossary/infrastructure-as-code-security/index.md>): Infrastructure as code (IaC) security is the protection of machine-readable definitions and automation used to provision, configure, change, and remove infrastructure.
- [Static application security testing (SAST)](<https://yellowcube.eu/glossary/static-application-security-testing/index.md>): Static application security testing analyzes software without executing it to identify patterns that may indicate security defects.
- [Dynamic application security testing (DAST)](<https://yellowcube.eu/glossary/dynamic-application-security-testing/index.md>): Dynamic application security testing evaluates a running application by interacting with its exposed interfaces and observing the resulting behavior.
- [Software composition analysis (SCA)](<https://yellowcube.eu/glossary/software-composition-analysis/index.md>): Software composition analysis identifies software components used in an application and evaluates information associated with them.
- [Software bill of materials (SBOM)](<https://yellowcube.eu/glossary/software-bill-of-materials/index.md>): A software bill of materials is a formal record of the software components and supply-chain relationships associated with a defined product, package, or artifact.
- [Secrets management](<https://yellowcube.eu/glossary/secrets-management/index.md>): Secrets management is the controlled lifecycle for sensitive values that systems use to authenticate, authorize actions, establish trust, or protect data.
- [Software supply-chain security](<https://yellowcube.eu/glossary/software-supply-chain-security/index.md>): Software supply-chain security is the discipline of protecting source code, dependencies, development tools, identities, build and test systems, artifact repositories, release processes, and update channels against unauthorized or unsafe change.
- [Container security](<https://yellowcube.eu/glossary/container-security/index.md>): Container security is the set of practices and controls used to protect container images, registries, runtimes, orchestrators, host systems, networks, identities, secrets, and delivery pipelines throughout the container lifecycle.
- [Kubernetes security](<https://yellowcube.eu/glossary/kubernetes-security/index.md>): Kubernetes security is the practice of protecting the container orchestration platform — its API, control plane, workloads, and supply chain — and the applications it runs.
- [Application programming interface (API) security](<https://yellowcube.eu/glossary/application-programming-interface-security/index.md>): API security is the design, implementation, testing, and operation of controls that protect application programming interfaces and the data and services they expose.
- [Application programming interface (API) gateway](<https://yellowcube.eu/glossary/application-programming-interface-gateway/index.md>): An API gateway is a managed entry point in front of APIs — routing requests, enforcing authentication, rate limits, and policy, and unifying how clients reach backend services.
- [Secure by design](<https://yellowcube.eu/glossary/secure-by-design/index.md>): Secure by design means building products and systems with security as a design requirement from the start — rather than adding defenses after architecture and code already exist.
- [Web application firewall (WAF)](<https://yellowcube.eu/glossary/web-application-firewall/index.md>): A web application firewall (WAF) is a security control that inspects HTTP and HTTPS traffic between clients and web applications and applies policy.

### Data and insider risk

- [Insider threat](<https://yellowcube.eu/glossary/insider-threat/index.md>): An insider threat is the potential for a person with authorized access or special knowledge of an organization to cause harm.
- [Insider risk management](<https://yellowcube.eu/glossary/insider-risk-management/index.md>): Insider risk management is the coordinated process of reducing harm that could arise when people with legitimate access or organizational knowledge make unsafe, negligent, compromised, or malicious use of that position.
- [Shadow IT](<https://yellowcube.eu/glossary/shadow-it/index.md>): Shadow IT is technology used inside an organization without the knowledge, approval, or governance of the IT or security organization — unapproved SaaS, personal cloud storage, unsanctioned tools, and unregistered systems.
- [Data loss prevention (DLP)](<https://yellowcube.eu/glossary/data-loss-prevention/index.md>): Data loss prevention (DLP) is a set of policies and technical capabilities used to identify sensitive data, monitor how it is handled, and prevent or record unauthorized disclosure or transfer.
- [Data exfiltration](<https://yellowcube.eu/glossary/data-exfiltration/index.md>): Data exfiltration is the unauthorized transfer of data from a system, service, device, or organization to a location or party that should not receive it.
- [Data breach](<https://yellowcube.eu/glossary/data-breach/index.md>): A data breach is a security incident in which data’s confidentiality, integrity, or availability is compromised through unauthorized access, disclosure, alteration, destruction, or loss.
- [Data leakage and exposure](<https://yellowcube.eu/glossary/data-leakage-and-exposure/index.md>): Data leakage and exposure describe overlapping situations in which data crosses, or becomes accessible beyond, its intended trust or authorization boundary.
- [File-sharing security](<https://yellowcube.eu/glossary/file-sharing-security/index.md>): File-sharing security is the governance and protection of files made available to other people, organizations, devices, or applications through shared repositories, collaboration services, network shares, links, synchronization, or similar mechanisms.
- [Data classification](<https://yellowcube.eu/glossary/data-classification/index.md>): Data classification is the process of assigning data to categories based on its sensitivity, criticality, legal or contractual requirements, and value to the organization.
- [Data retention](<https://yellowcube.eu/glossary/data-retention/index.md>): Data retention is the deliberate management of how long data is kept — balancing legal and business requirements to retain it against the risk that accumulated data becomes a breach and privacy liability.
- [Data discovery](<https://yellowcube.eu/glossary/data-discovery/index.md>): Data discovery is the process of locating data across defined systems and describing enough of it to support security, privacy, governance, or operational decisions.
- [Data governance](<https://yellowcube.eu/glossary/data-governance/index.md>): Data governance is the system by which an organization directs, controls, and holds people accountable for decisions about data and its use.
- [Data security](<https://yellowcube.eu/glossary/data-security/index.md>): Data security is the discipline of protecting data against unauthorized access, use, disclosure, alteration, destruction, or loss while keeping it available to authorized users when needed.
- [Data protection](<https://yellowcube.eu/glossary/data-protection/index.md>): Data protection is the coordinated governance and handling of data throughout its lifecycle so it is used for authorized purposes, safeguarded from harm, kept appropriately accurate and available, and retained or disposed of as required.
- [Data privacy](<https://yellowcube.eu/glossary/data-privacy/index.md>): Data privacy concerns how data processing affects people and whether collection, inference, use, sharing, retention, and deletion are appropriate for the stated context.
- [Personally identifiable information (PII)](<https://yellowcube.eu/glossary/personally-identifiable-information/index.md>): Personally identifiable information (PII) is information that can distinguish or trace an individual’s identity, either by itself or when combined with other information that is linked or linkable to that person.
- [Data integrity](<https://yellowcube.eu/glossary/data-integrity/index.md>): Data integrity is the property that data remains accurate, complete, consistent, traceable, and protected from unauthorized or unintended alteration or destruction throughout its lifecycle.
- [Data security posture management (DSPM)](<https://yellowcube.eu/glossary/data-security-posture-management/index.md>): Data security posture management (DSPM) is an emerging, non-standard market category for processes and tools that discover data stores, identify sensitive information, relate it to access, exposure, use, and protective controls, and prioritize data-security risk.
- [Data-centric audit and protection (DCAP)](<https://yellowcube.eu/glossary/data-centric-audit-and-protection/index.md>): Data-centric audit and protection (DCAP) is an older analyst-defined market category for capabilities that discover and classify data, govern access, monitor or audit data activity, and apply protective controls around the data itself.
- [Digital rights management (DRM)](<https://yellowcube.eu/glossary/digital-rights-management/index.md>): Digital rights management (DRM) is the use of policy, cryptography, licensing, and trusted software or hardware to control how digital content may be accessed and used.
- [Cryptography](<https://yellowcube.eu/glossary/cryptography/index.md>): Cryptography is the discipline of designing, analyzing, and applying mathematical techniques to protect information and communications against defined adversaries.
- [Encryption](<https://yellowcube.eu/glossary/encryption/index.md>): Encryption is the reversible cryptographic transformation of readable data, called plaintext, into ciphertext using an algorithm and cryptographic key.
- [Cryptographic key management](<https://yellowcube.eu/glossary/cryptographic-key-management/index.md>): Cryptographic key management governs the full lifecycle of encryption keys — generation, distribution, storage, use, rotation, backup, and destruction — because encrypted data is only as safe as its keys.
- [Digital signature](<https://yellowcube.eu/glossary/digital-signature/index.md>): A digital signature is a cryptographic proof attached to data showing who signed it and that the content was not altered after signing — providing authenticity and integrity, and supporting non-repudiation.
- [Cryptographic hashing](<https://yellowcube.eu/glossary/cryptographic-hashing/index.md>): Cryptographic hashing is a one-way function that maps arbitrary input to a fixed-length digest, designed so the input cannot be practically recovered from the digest and two different inputs cannot practically produce the same digest.
- [Public key infrastructure (PKI)](<https://yellowcube.eu/glossary/public-key-infrastructure/index.md>): Public key infrastructure (PKI) is the governed combination of roles, policies, processes, systems, cryptographic keys, and digital certificates used to establish and maintain trust relationships involving public keys.
- [Transport Layer Security (TLS)](<https://yellowcube.eu/glossary/transport-layer-security/index.md>): Transport Layer Security is the cryptographic protocol that authenticates endpoints — typically the server — and protects the confidentiality and integrity of data in transit, forming the security layer behind HTTPS and many other protocols.
- [Digital certificate](<https://yellowcube.eu/glossary/digital-certificate/index.md>): A digital certificate is a signed data structure that associates a public key with a named subject, identity, role, device, service, or other attributes under an issuer’s rules.
- [Certificate management](<https://yellowcube.eu/glossary/certificate-management/index.md>): Certificate management is the controlled lifecycle of digital certificates and their associated requests, private keys, owners, deployments, dependencies, and trust relationships.
- [Online Certificate Status Protocol (OCSP)](<https://yellowcube.eu/glossary/online-certificate-status-protocol/index.md>): The Online Certificate Status Protocol (OCSP) is an internet protocol for checking a digital certificate’s revocation status without downloading a certificate revocation list.
- [Hardware security module (HSM)](<https://yellowcube.eu/glossary/hardware-security-module/index.md>): A hardware security module (HSM) is a physical computing device that safeguards cryptographic keys and performs cryptographic operations within a defined security boundary.
- [Message authentication code (MAC)](<https://yellowcube.eu/glossary/message-authentication-code/index.md>): A message authentication code (MAC) is a short cryptographic tag computed from a message and a secret key.
- [Pretty Good Privacy (PGP)](<https://yellowcube.eu/glossary/pretty-good-privacy/index.md>): Pretty Good Privacy (PGP) began as a named cryptographic software product for encrypting and digitally signing files and messages.
- [Homomorphic encryption](<https://yellowcube.eu/glossary/homomorphic-encryption/index.md>): Homomorphic encryption is cryptography that allows specified computations to be performed on encrypted data without first exposing its plaintext.
- [Confidential computing](<https://yellowcube.eu/glossary/confidential-computing/index.md>): Confidential computing protects data in use by performing computation within a hardware-backed, attested trusted execution environment (TEE).
- [Point-of-sale (POS) security](<https://yellowcube.eu/glossary/point-of-sale-security/index.md>): Point-of-sale (POS) security protects the devices, applications, networks, data, people, and services used to record sales and accept payment at checkout.

### Email and human risk

- [Email security](<https://yellowcube.eu/glossary/email-security/index.md>): Email security is the combination of controls used to protect email identities, infrastructure, messages, users, and business processes.
- [Domain-based Message Authentication, Reporting, and Conformance (DMARC)](<https://yellowcube.eu/glossary/domain-based-message-authentication-reporting-and-conformance/index.md>): DMARC is an email-authentication, policy, and reporting protocol that lets a domain owner publish a requested handling policy for messages that fail DMARC validation and specify where receivers should send reports.
- [Sender Policy Framework (SPF)](<https://yellowcube.eu/glossary/sender-policy-framework/index.md>): Sender Policy Framework (SPF) is an email-authentication protocol that lets a domain owner publish which mail systems are authorized to use that domain in an SMTP envelope identity.
- [DomainKeys Identified Mail (DKIM)](<https://yellowcube.eu/glossary/domainkeys-identified-mail/index.md>): DomainKeys Identified Mail (DKIM) is an email-authentication protocol that allows a domain to attach a cryptographic signature to a message.
- [Email encryption](<https://yellowcube.eu/glossary/email-encryption/index.md>): Email encryption is the use of cryptography to protect email from unauthorized reading while it is transmitted, stored, or carried as protected message content.
- [Email spoofing](<https://yellowcube.eu/glossary/email-spoofing/index.md>): Email spoofing is the falsification or imitation of sender information so that a message appears to come from a trusted person, organization, or domain.
- [Spam filtering](<https://yellowcube.eu/glossary/spam-filtering/index.md>): Spam filtering is the automated evaluation of email to identify unsolicited, unwanted, or abusive messaging and decide whether to reject, defer, quarantine, label, route, or deliver it.
- [Phishing](<https://yellowcube.eu/glossary/phishing/index.md>): Phishing is a social-engineering attack that uses a deceptive digital message or interaction to make someone reveal information, authorize an action, open malicious content, or visit an attacker-controlled service.
- [Adversary-in-the-middle (AiTM) phishing](<https://yellowcube.eu/glossary/adversary-in-the-middle-phishing/index.md>): Adversary-in-the-middle phishing places attacker infrastructure between the victim and the real service, relaying the genuine authentication exchange live so the attacker captures credentials and the resulting session token.
- [Spear phishing](<https://yellowcube.eu/glossary/spear-phishing/index.md>): Spear phishing is phishing deliberately tailored to a specific person, team, organization, or narrowly defined group.
- [Business email compromise (BEC)](<https://yellowcube.eu/glossary/business-email-compromise/index.md>): Business email compromise (BEC) is a form of fraud in which an attacker impersonates or takes over a trusted business identity to persuade someone to transfer money, reveal sensitive information, or change a legitimate business process.
- [Whaling](<https://yellowcube.eu/glossary/whaling/index.md>): Whaling is spear phishing selected around a target’s seniority, public profile, authority, or access to high-value information and transactions.
- [Vishing](<https://yellowcube.eu/glossary/vishing/index.md>): Vishing, short for voice phishing, is phishing conducted through a live or recorded voice interaction, including telephone calls and voice messages.
- [Smishing](<https://yellowcube.eu/glossary/smishing/index.md>): Smishing is phishing delivered through Short Message Service (SMS) or similar mobile text messaging.
- [Social engineering](<https://yellowcube.eu/glossary/social-engineering/index.md>): Social engineering is an umbrella term for attacks that use deception, impersonation, influence, or manufactured pressure to persuade a person to disclose information, grant access, transfer value, or perform another action that weakens security.
- [Pretexting](<https://yellowcube.eu/glossary/pretexting/index.md>): Pretexting is a social-engineering technique in which an attacker invents or misrepresents a role, relationship, event, or need to make a request seem legitimate.
- [Tailgating](<https://yellowcube.eu/glossary/tailgating/index.md>): A tailgating attack is an attempt to enter a controlled physical area by following an authorized person through an access point without presenting independent authorization.
- [Security awareness training](<https://yellowcube.eu/glossary/security-awareness-training/index.md>): Security awareness training is the planned learning activity that helps people recognize security and privacy risks, make safer decisions, and follow the organization’s reporting and response procedures.

### Operational technology, IoT, and critical infrastructure

- [Operational technology (OT) security](<https://yellowcube.eu/glossary/operational-technology-security/index.md>): Operational technology (OT) security protects systems that monitor or control physical processes, devices, and infrastructure.
- [Industrial control system (ICS)](<https://yellowcube.eu/glossary/industrial-control-system/index.md>): An industrial control system (ICS) is a system used to monitor and control an industrial process.
- [Supervisory control and data acquisition (SCADA)](<https://yellowcube.eu/glossary/supervisory-control-and-data-acquisition/index.md>): Supervisory control and data acquisition (SCADA) is an industrial control architecture used to supervise processes and collect operational data across distributed assets.
- [Programmable logic controller (PLC)](<https://yellowcube.eu/glossary/programmable-logic-controller/index.md>): A programmable logic controller (PLC) is an industrial solid-state controller with user-programmable memory for executing functions such as logic, sequencing, timing, counting, arithmetic, communication, input and output control, and proportional-integral-derivative control.
- [Human-machine interface (HMI)](<https://yellowcube.eu/glossary/human-machine-interface/index.md>): A human-machine interface (HMI) is the hardware or software through which an operator interacts with an industrial controller or process.
- [Safety instrumented system (SIS)](<https://yellowcube.eu/glossary/safety-instrumented-system/index.md>): A safety instrumented system (SIS) comprises one or more safety instrumented functions that achieve or maintain a safe state when defined process conditions are violated.
- [Purdue model](<https://yellowcube.eu/glossary/purdue-model/index.md>): The Purdue model is a layered reference model for organizing manufacturing and control functions from the physical process and basic control through supervisory and site operations to enterprise systems.
- [IEC 62443](<https://yellowcube.eu/glossary/iec-62443/index.md>): IEC 62443 is a series of international standards and technical reports for cybersecurity of industrial automation and control systems (IACS).
- [Industrial demilitarized zone (IDMZ)](<https://yellowcube.eu/glossary/industrial-demilitarized-zone/index.md>): An industrial demilitarized zone (IDMZ) is a controlled network zone placed between enterprise IT and operational technology networks to prevent direct communication across their boundary.
- [Information technology and operational technology convergence (IT/OT convergence)](<https://yellowcube.eu/glossary/information-technology-and-operational-technology-convergence/index.md>): IT/OT convergence is the increasing integration of information technology with operational technology systems, data, processes, and teams.
- [Operational technology (OT) asset inventory](<https://yellowcube.eu/glossary/operational-technology-asset-inventory/index.md>): An OT asset inventory is a maintained record of the devices, software, communications, dependencies, and physical functions that make up an operational technology environment.
- [Secure remote access](<https://yellowcube.eu/glossary/secure-remote-access/index.md>): Secure remote access is the governed capability for an authorized person or system outside an operational trust boundary to reach specified OT resources for an approved purpose.
- [Data diode / unidirectional gateway](<https://yellowcube.eu/glossary/data-diode-unidirectional-gateway/index.md>): A data diode is a boundary device designed to permit data transfer in only one physical direction.
- [Internet of Things (IoT)](<https://yellowcube.eu/glossary/internet-of-things/index.md>): The Internet of Things (IoT) is an ecosystem of connected physical objects that combine computation with sensors or actuators to observe, communicate, or affect their environment.
- [IoT security](<https://yellowcube.eu/glossary/iot-security/index.md>): Internet of Things (IoT) security is the discipline of protecting connected devices, their data, communications, physical interactions, applications, services, and lifecycle processes.
- [IoT edge](<https://yellowcube.eu/glossary/iot-edge/index.md>): The Internet of Things (IoT) edge is the part of an IoT ecosystem where data is collected, processed, or acted upon close to connected devices and their physical environment.
- [Cyber-physical system (CPS)](<https://yellowcube.eu/glossary/cyber-physical-system/index.md>): A cyber-physical system (CPS) is an engineered system in which digital, analog, physical, and often human components interact to perform a function through integrated computation and physical behavior.
- [Digital twin](<https://yellowcube.eu/glossary/digital-twin/index.md>): A digital twin is a digital representation of a real-world asset, process, or system that is connected to observations from its counterpart so the representation can be updated at a fit-for-purpose rate.
- [Critical infrastructure protection](<https://yellowcube.eu/glossary/critical-infrastructure-protection/index.md>): Critical infrastructure protection is the coordinated use of physical security, cybersecurity, personnel safeguards, emergency management, and resilience measures to reduce risks to assets, systems, networks, and services whose disruption could seriously harm safety, health, security, the economy, or society.

### Regulation, governance, and resilience

- [NIS2 Directive](<https://yellowcube.eu/glossary/nis2-directive/index.md>): The NIS2 Directive is the European Union’s updated framework for achieving a high common level of cybersecurity across the EU.
- [Essential and important entities under NIS2](<https://yellowcube.eu/glossary/essential-and-important-entities-under-nis2/index.md>): Essential entities and important entities are the two principal supervisory categories used by the NIS2 Directive.
- [Digital Operational Resilience Act (DORA)](<https://yellowcube.eu/glossary/digital-operational-resilience-act/index.md>): The Digital Operational Resilience Act (DORA) is the European Union regulation that establishes a common framework for managing information and communication technology risk in the financial sector.
- [Cyber Resilience Act (CRA)](<https://yellowcube.eu/glossary/cyber-resilience-act/index.md>): The Cyber Resilience Act (CRA) is the European Union regulation establishing horizontal cybersecurity requirements for products with digital elements made available on the EU market.
- [General Data Protection Regulation (GDPR) security](<https://yellowcube.eu/glossary/general-data-protection-regulation-security/index.md>): GDPR security is the set of legal obligations and accountable practices used to protect personal data processed under the EU General Data Protection Regulation.
- [Artificial Intelligence Act (AI Act)](<https://yellowcube.eu/glossary/artificial-intelligence-act/index.md>): The EU Artificial Intelligence Act — Regulation (EU) 2024/1689 — is the bloc’s risk-based law for AI systems, banning some uses outright and imposing graded obligations on high-risk systems, general-purpose models, and deployers.
- [Federal Information Security Modernization Act (FISMA)](<https://yellowcube.eu/glossary/federal-information-security-modernization-act/index.md>): The Federal Information Security Modernization Act of 2014 (FISMA) is a United States law that establishes a government-wide framework for managing information-security risk to federal operations, assets, information, and systems.
- [Federal Risk and Authorization Management Program (FedRAMP)](<https://yellowcube.eu/glossary/federal-risk-and-authorization-management-program/index.md>): The Federal Risk and Authorization Management Program (FedRAMP) is a United States government-wide program that standardizes reusable security information about in-scope cloud services processing unclassified federal information.
- [HIPAA Security Rule](<https://yellowcube.eu/glossary/hipaa-security-rule/index.md>): The Health Insurance Portability and Accountability Act (HIPAA) Security Rule is a United States regulation requiring covered entities and business associates to protect electronic protected health information (ePHI).
- [Sarbanes–Oxley Act (SOX) cybersecurity](<https://yellowcube.eu/glossary/sarbanes-oxley-act-cybersecurity/index.md>): Sarbanes–Oxley Act (SOX) cybersecurity is an informal label for cybersecurity work that supports a public company’s obligations under the United States Sarbanes–Oxley Act of 2002.
- [North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP)](<https://yellowcube.eu/glossary/north-american-electric-reliability-corporation-critical-infrastructure-protection/index.md>): North American Electric Reliability Corporation Critical Infrastructure Protection (NERC CIP) refers to a family of mandatory reliability standards addressing security of the Bulk Electric System in North America.
- [International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 27001](<https://yellowcube.eu/glossary/international-organization-for-standardization-international-electrotechnical-commission-27001/index.md>): ISO/IEC 27001 is an international requirements standard for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
- [National Institute of Standards and Technology Special Publication (NIST SP) 800-53](<https://yellowcube.eu/glossary/national-institute-of-standards-and-technology-special-publication-800-53/index.md>): National Institute of Standards and Technology Special Publication (NIST SP) 800-53 is a catalog of security and privacy controls for information systems and organizations.
- [NIST Cybersecurity Framework (CSF)](<https://yellowcube.eu/glossary/nist-cybersecurity-framework/index.md>): The NIST Cybersecurity Framework is a voluntary framework of outcomes that helps organizations understand, manage, and reduce cybersecurity risk, organized around six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
- [COBIT](<https://yellowcube.eu/glossary/cobit/index.md>): COBIT is a framework published by ISACA, formerly the Information Systems Audit and Control Association, for governing and managing enterprise information and technology (I&T).
- [Payment Card Industry Data Security Standard (PCI DSS)](<https://yellowcube.eu/glossary/payment-card-industry-data-security-standard/index.md>): The Payment Card Industry Data Security Standard (PCI DSS) is an industry security standard containing technical and operational requirements for protecting payment account data.
- [SOC 1 report](<https://yellowcube.eu/glossary/soc-1-report/index.md>): A System and Organization Controls 1 (SOC 1) report is an independent service-auditor report on controls at a service organization that are likely to be relevant to its customers' internal control over financial reporting.
- [SOC 2 report](<https://yellowcube.eu/glossary/soc-2-report/index.md>): A System and Organization Controls 2 (SOC 2) report is an independent service-auditor report on controls at a service organization relevant to the American Institute of Certified Public Accountants' Trust Services Criteria.
- [SOC 3 report](<https://yellowcube.eu/glossary/soc-3-report/index.md>): A SOC 3 report is a general-use service-auditor report on controls at a service organization relevant to the Trust Services Criteria — covering the same subject matter as SOC 2 but with less detail, so it can be shared publicly.
- [Compliance automation](<https://yellowcube.eu/glossary/compliance-automation/index.md>): Compliance automation is the use of software, structured data, and repeatable workflows to perform selected compliance activities with less manual effort.
- [Cyber resilience](<https://yellowcube.eu/glossary/cyber-resilience/index.md>): Cyber resilience is the ability to anticipate, withstand, recover from, and adapt to adverse conditions, attacks, or compromises involving digital systems and resources.
- [Business continuity](<https://yellowcube.eu/glossary/business-continuity/index.md>): Business continuity is an organization’s capability and management practice for continuing prioritized products and services at an acceptable level during a disruption and restoring normal operations afterward.
- [Business impact analysis (BIA)](<https://yellowcube.eu/glossary/business-impact-analysis/index.md>): A business impact analysis identifies what an organization cannot afford to lose — the processes, dependencies, and time limits that determine how damaging an outage or disruption would be.
- [Disaster recovery](<https://yellowcube.eu/glossary/disaster-recovery/index.md>): Disaster recovery is the coordinated restoration of technology services, infrastructure, and data after a serious disruption.
- [Cyber recovery](<https://yellowcube.eu/glossary/cyber-recovery/index.md>): Cyber recovery is the discipline of restoring systems and data after a destructive cyberattack — where the attack itself may have corrupted or reached the very backups and tools normal recovery relies on.
- [Recovery point objective (RPO)](<https://yellowcube.eu/glossary/recovery-point-objective/index.md>): A recovery point objective is the point in time before a disruption to which data must be recoverable.
- [Recovery time objective (RTO)](<https://yellowcube.eu/glossary/recovery-time-objective/index.md>): A recovery time objective is the target duration after a defined disruption within which a specified system, service, or business capability should be restored to an agreed level.
- [Maximum tolerable downtime (MTD)](<https://yellowcube.eu/glossary/maximum-tolerable-downtime/index.md>): Maximum tolerable downtime is the absolute ceiling on how long a process or service can be unavailable before the impact becomes unacceptable — the outer bound that RTOs must stay within.
- [Backup](<https://yellowcube.eu/glossary/backup/index.md>): A backup is a separate, recoverable copy of data kept so it can be restored after loss — the baseline control against deletion, corruption, ransomware, and failure.
- [Immutable backup](<https://yellowcube.eu/glossary/immutable-backup/index.md>): An immutable backup is a backup whose retained recovery points are protected from alteration or deletion for a defined period.
- [Failover](<https://yellowcube.eu/glossary/failover/index.md>): Failover is the capability and process of transferring a service from an active component, system, connection, or site to a redundant or standby alternative after a failure or abnormal condition.
- [Fault tolerance](<https://yellowcube.eu/glossary/fault-tolerance/index.md>): Fault tolerance is a system property that allows a required function to continue correctly when one or more anticipated hardware or software faults occur.
- [Crisis management](<https://yellowcube.eu/glossary/crisis-management/index.md>): Crisis management is the leadership process for handling a disruption severe enough to threaten the organization itself — coordinating decisions, communication, and stakeholders beyond any single team’s playbook.
- [Third-party cyber risk](<https://yellowcube.eu/glossary/third-party-cyber-risk/index.md>): Third-party cyber risk is the potential for harm arising from an organization’s reliance on suppliers, service providers, contractors, partners, and other external parties.
- [Third-party risk management (TPRM)](<https://yellowcube.eu/glossary/third-party-risk-management/index.md>): Third-party risk management is the governance discipline that identifies, assesses, contracts for, and monitors the security risk introduced by vendors, suppliers, and partners across the relationship lifecycle.
- [Supply-chain security](<https://yellowcube.eu/glossary/supply-chain-security/index.md>): Supply-chain security is the protection of products, services, components, data, and delivery relationships against compromise, substitution, disruption, or unacceptable dependency risk throughout their lifecycle.
- [Concentration risk](<https://yellowcube.eu/glossary/concentration-risk/index.md>): Concentration risk is the exposure created when critical operations depend on too few providers, platforms, or suppliers — so a single failure or compromise cascades across the organization.
- [Cyber insurance](<https://yellowcube.eu/glossary/cyber-insurance/index.md>): Cyber insurance is a contract under which an insurer agrees, subject to the policy’s terms, to fund specified losses, liabilities, or response services arising from covered cyber events.
- [AI risk management](<https://yellowcube.eu/glossary/ai-risk-management/index.md>): Artificial intelligence (AI) risk management is the coordinated process of identifying, assessing, treating, monitoring, and communicating risks arising from the design, development, acquisition, deployment, use, and retirement of AI systems.

### AI security

- [AI security](<https://yellowcube.eu/glossary/ai-security/index.md>): AI security is the discipline of protecting artificial intelligence systems and the environments around them from malicious manipulation, unauthorized access, disclosure, theft and disruption.
- [AI governance](<https://yellowcube.eu/glossary/ai-governance/index.md>): AI governance is the organizational framework of policies, roles, and processes that decides how AI may be selected, built, deployed, and monitored — before models reach production or users.
- [AI security posture management (AI-SPM)](<https://yellowcube.eu/glossary/ai-security-posture-management/index.md>): AI security posture management is an emerging, non-standard industry label for processes and capabilities that discover AI assets and assess their security state.
- [Machine learning security operations (MLSecOps)](<https://yellowcube.eu/glossary/machine-learning-security-operations/index.md>): Machine learning security operations (MLSecOps) is an emerging practice that integrates security responsibilities and controls into machine learning development and operations across data preparation, model development, evaluation, release, deployment, monitoring, change, and retirement.
- [Agentic AI security](<https://yellowcube.eu/glossary/agentic-ai-security/index.md>): Agentic AI security is the practice of protecting AI systems that pursue goals through delegated access to tools, services or other agents.
- [AI red teaming](<https://yellowcube.eu/glossary/ai-red-teaming/index.md>): AI red teaming is an authorized, structured adversarial evaluation of an AI system.
- [Prompt injection](<https://yellowcube.eu/glossary/prompt-injection/index.md>): Prompt injection is the manipulation of a generative AI system through instructions that cause a model to override or conflict with the application’s intended instructions.
- [Model poisoning](<https://yellowcube.eu/glossary/model-poisoning/index.md>): Model poisoning is a training-stage attack in which an adversary manipulates a model or its parameters to change later behavior.
- [Data poisoning](<https://yellowcube.eu/glossary/data-poisoning/index.md>): Data poisoning is a training-stage attack in which an adversary inserts, deletes, alters or relabels data used to train or adapt a machine-learning model.
- [Adversarial machine learning](<https://yellowcube.eu/glossary/adversarial-machine-learning/index.md>): Adversarial machine learning is the field concerned with attacks that exploit machine-learning systems and with methods for understanding and mitigating those attacks.
- [Shadow AI](<https://yellowcube.eu/glossary/shadow-ai/index.md>): Shadow AI is an industry governance term for AI systems, services or features used, connected, developed or deployed without the visibility or approval required by an organization.

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

