The Cybersecurity Glossary

allglossary.xyz

The Cybersecurity Glossary

Foundations & Risk

Cybersecurity
The people, processes, and technologies used to protect computers, networks, services, and data from unauthorized access, damage, or disruption.
CIA triad
A basic security model built around confidentiality, integrity, and availability: keeping information private, correct, and accessible when needed.
Asset
Anything an organization values and may need to protect, such as data, devices, software, services, people, or facilities.
Threat
A circumstance or actor with the potential to cause harm by exploiting a weakness or disrupting an asset.
Threat actor
A person or group that may attempt harmful activity against systems or information, whether for profit, influence, espionage, or another motive.
Vulnerability
A weakness in software, hardware, configuration, or a process that could be used to cause harm or gain unauthorized access.
Risk
The possibility of loss or harm, considered in terms of how likely a threat is to affect an asset and how serious the impact could be.
Attack surface
The set of places where an attacker could try to enter, interact with, or affect a system, including exposed services, accounts, devices, and people.
Security control
A safeguard or measure—such as a policy, process, or technical mechanism—used to reduce security risk.

Identity & Access

Authentication
Checking evidence to establish that a user, device, or service is the identity it claims to be.
Authorization
Determining what an authenticated identity is permitted to see or do.
Multi-factor authentication (MFA)
Authentication that requires evidence from at least two different factor categories, such as something you know, have, or are.
Least privilege
Giving each user, device, or service only the permissions it needs, for only as long as it needs them.
Access control
The rules and mechanisms that decide who or what may access a resource and which actions are allowed.
Role-based access control (RBAC)
An access-control approach where permissions are assigned to roles, and users receive permissions through their assigned roles.
Single sign-on (SSO)
A sign-in arrangement that lets a user authenticate once with a trusted identity provider and access multiple connected services.
Identity and access management (IAM)
The policies and systems used to create, verify, manage, and remove identities and control their access to resources.
Zero trust
A security approach that does not grant trust solely because of network location; access is evaluated using identity, context, and policy.

Networks & Endpoints

Network segmentation
Dividing a network into smaller, controlled zones so access between them can be limited and a compromise is less likely to spread.
Firewall
A device or software control that permits or blocks network traffic according to configured rules.
Intrusion detection system (IDS)
A system that monitors activity for signs of suspicious or prohibited behavior and raises alerts; it typically does not block traffic by itself.
Virtual private network (VPN)
A technology that creates an authenticated, protected connection across a network that is not fully trusted; it does not by itself make a device or service safe.
Domain Name System (DNS)
The naming system that helps devices find internet services by translating domain names, such as example.com, into network addresses.
Transport Layer Security (TLS)
A protocol used to protect data in transit and help authenticate a server, commonly used for HTTPS connections.
Endpoint
A device that connects to or participates in a network, such as a laptop, phone, server, or workstation.
Endpoint detection and response (EDR)
Security technology that collects endpoint activity to help detect suspicious behavior, investigate it, and take response actions.
Secure configuration
Setting up systems with security in mind, including removing unnecessary services, changing unsafe defaults, and limiting access.

Vulnerabilities & Attacks

Malware
Software or code intentionally designed to perform harmful or unauthorized actions, such as stealing information or disrupting systems.
Ransomware
Malicious software or an attack that blocks access to data or systems—often by encrypting data—and demands payment or another concession.
Phishing
A deceptive message or website designed to trick someone into revealing information, opening a harmful file, or taking an unsafe action.
Social engineering
Manipulating people into disclosing information or performing actions that weaken security, often by using urgency, authority, or trust.
Exploit
A method, code, or sequence of actions that takes advantage of a vulnerability to cause an unintended effect.
Zero-day vulnerability
A vulnerability that is unknown to, or lacks an available fix from, the responsible vendor or defender; the term's use can vary by context.
Patch
A software update that corrects defects or security weaknesses, or otherwise changes a product; applying patches helps reduce exposure to known issues.
SQL injection
A web-application flaw where untrusted input is handled as part of a database command, potentially allowing an attacker to read or alter data.
Supply-chain attack
An attack that compromises a target by abusing a supplier, software dependency, service provider, or distribution process connected to it.

Detection & Response

Security log
A time-stamped record of system or user activity that can help explain what happened and support detection or investigation.
Security information and event management (SIEM)
A system that collects and correlates security events from multiple sources to help analysts find suspicious patterns and investigate alerts.
Security alert
A notification that activity may match a security rule or indicate a possible threat; an alert needs assessment and is not automatically proof of an incident.
Security incident
An event, or series of events, that has compromised or threatens the confidentiality, integrity, or availability of systems or information.
Incident response
The coordinated process for preparing for, identifying, analyzing, containing, and recovering from security incidents, then improving from what was learned.
Triage
The initial assessment and prioritization of alerts or incidents to determine what needs investigation first and what response is appropriate.
Containment
Actions taken to limit an incident's spread or impact while investigation and remediation continue.
Recovery
Restoring affected systems and services to normal operation in a controlled way and checking that they remain secure.
Threat hunting
A proactive search through available data and systems for signs of malicious activity that automated alerts may have missed.

Cryptography & Data Protection

Cryptography
The use of mathematical techniques to protect information or verify its origin, including encryption, hashing, and digital signatures.
Encryption
Transforming readable data into a protected form using a key so that it cannot be understood without the appropriate decryption capability.
Hashing
Applying a one-way function to data to produce a fixed-size digest, often used to check integrity or safely verify stored passwords when done with a suitable password-hashing method.
Digital signature
A cryptographic proof, created with a private key and checked with a corresponding public key, that can help verify a message's origin and detect changes.
Digital certificate
A digitally signed document that binds an identity or named subject to a public key, with details that allow relying systems to validate it.
Data classification
Labeling information by sensitivity or importance so appropriate handling and protection requirements can be applied.
Backup
A separate, recoverable copy of data or system information, maintained so it can be restored after loss, damage, or an attack.

Governance & Resilience

Security policy
An organization's documented rules and expectations for protecting systems and information and assigning security responsibilities.
Risk assessment
A structured process for identifying assets, threats, vulnerabilities, and possible impacts so risks can be compared and addressed.
Security awareness
Helping people recognize security responsibilities and common risks, and know how to report or avoid unsafe activity.
Vulnerability management
The ongoing work of finding, prioritizing, addressing, and tracking vulnerabilities across an organization's systems.
Penetration testing
An authorized, scoped test that safely simulates selected attacker techniques to find and validate weaknesses in systems or processes.
Red team
A group that conducts authorized, realistic adversary simulations to test how well an organization can prevent, detect, and respond to attacks.
Security framework
A structured set of guidance, outcomes, or controls that helps an organization organize and improve its security program.
Business continuity
The plans and capabilities that help an organization continue delivering important services during disruption and restore normal operations afterward.