Audit LogSecurity · TermA chronological record of security-relevant or business-relevant actions showing what occurred and who or what initiated it.Read more
AuthenticationSecurity · ConceptThe process of verifying that a person system or device is the identity it claims to be.Read more
AuthorizationSecurity · ConceptThe process of deciding whether an authenticated identity may perform an action or access a resource.Read more
CAPTCHACompletely Automated Public Turing test to tell Computers and Humans Apart · SecurityA challenge or risk check used to distinguish likely human activity from automated abuse.Read more
CredentialSecurity · TermInformation or a cryptographic artifact used to prove identity or obtain authorized access.Read more
DASTDynamic Application Security Testing · SecurityA security testing approach that probes a running application from the outside to identify exploitable behavior.Read more
Device ManagementSecurity · PracticeThe administration of organization-owned or enrolled devices through policies inventory configuration and remote controls.Read more
IDORInsecure Direct Object Reference · SecurityAn access-control vulnerability where changing an object identifier can expose or modify data the requester is not authorized to access.Read more
Information SecuritySecurity · ConceptThe discipline of protecting information and systems from unauthorized access alteration disclosure disruption or destruction.Read more
JWTJSON Web Token · SecurityA compact signed token format commonly used to carry claims between systems.Read more
Least PrivilegeSecurity · ConceptThe principle of granting only the access needed for a task and no more.Read more
MFAMulti-Factor Authentication · SecurityAn authentication method requiring evidence from two or more distinct factor categories.Read more
OAuthSecurity · TermAn authorization framework used to let one application access another service on a user's behalf within an approved scope.Read more
Penetration TestingSecurity · PracticeAn authorized assessment that actively attempts to exploit weaknesses in a defined system and scope.Read more
PIIPersonally Identifiable Information · SecurityInformation that can identify a person directly or when combined with other data.Read more
RBACRole-Based Access Control · SecurityAn authorization model that grants permissions to roles and assigns people or systems to those roles.Read more
SASTStatic Application Security Testing · SecurityA security testing approach that analyzes application source code or related artifacts without running the application.Read more
Secrets ManagementSecurity · PracticeThe controlled storage distribution rotation and auditing of credentials keys and other sensitive values.Read more
SemgrepSecurity · TermA static analysis tool commonly used to scan code with rules for security defects code quality and engineering standards.Read more
SSOSingle Sign-On · SecurityAn authentication arrangement that lets employees use one organizational identity to access multiple connected systems.Read more
Threat ModelSecurity · TermA structured description of assets attackers trust boundaries threats and mitigations for a system.Read more
VPNVirtual Private Network · SecurityA technology that creates an encrypted connection between a device and a network or gateway.Read more
VulnerabilitySecurity · TermA weakness that can be exploited to compromise confidentiality integrity or availability.Read more
Zero TrustSecurity · ConceptA security approach that continuously verifies access instead of trusting requests based only on network location.Read more