A
- API
- Application Programming Interface: a way for software to talk to other software. Insecure APIs are a leading source of data exposure.
- Attack surface
- Every place an attacker could try to get in: web apps, APIs, servers, cloud settings, employees and suppliers.
- Attestation report
- An independent auditor’s written opinion on controls, such as a SOC 2 report.
- Authentication
- Proving who you are, for example with a password and a one-time code.
- Authorisation
- Deciding what an authenticated user is allowed to do or see.
B
- Black-box testing
- Testing with no inside knowledge of the target, similar to an outside attacker.
- BOLA
- Broken Object Level Authorisation: changing an ID in a request to read or edit someone else’s record. Also called IDOR.
- Brute force
- Trying many passwords or keys until one works.
- Bug bounty
- A programme that pays outside researchers for responsibly reported vulnerabilities.
C
- CIA triad
- Confidentiality, integrity and availability: the three goals of information security.
- Control
- A safeguard, technical or procedural, that reduces risk, such as multi-factor authentication or an access review.
- CORS
- Cross-Origin Resource Sharing: browser rules about which websites can call your API. Misconfiguration can leak data.
- CSRF
- Cross-Site Request Forgery: tricking a logged-in user’s browser into sending an unwanted request.
- CVE
- Common Vulnerabilities and Exposures: a public ID for a known vulnerability, such as CVE-2021-44228.
- CVSS
- Common Vulnerability Scoring System: a 0 to 10 score for how severe a vulnerability is.
D
- DAST
- Dynamic Application Security Testing: testing a running application from the outside.
- Data minimisation
- Collecting and keeping only the personal data you actually need.
- DPA
- Data Processing Agreement: a contract that sets how a processor handles personal data for a controller.
E
- Encryption
- Scrambling data so only holders of the right key can read it. At rest means stored, in transit means moving over a network.
- Exploit
- Code or a technique that takes advantage of a vulnerability.
F
- False positive
- A reported issue that is not actually a problem. Manual validation removes them.
G
- Gray-box testing
- Testing with partial knowledge, such as a normal user account and documentation.
H
- Hardening
- Reducing risk by turning off what you do not need and tightening configuration.
I
- IAM
- Identity and Access Management: tools and policies that control who can access what.
- IDOR
- Insecure Direct Object Reference: see BOLA.
- Incident response
- The planned process of detecting, containing, fixing and learning from a security incident.
- Injection
- Sending malicious input that an application treats as code, as in SQL injection.
- ISMS
- Information Security Management System: the structure ISO 27001 requires to manage security risk.
J
- JWT
- JSON Web Token: a signed token used to prove identity to an API. Weak validation is a common flaw.
L
- Lateral movement
- An attacker moving from one compromised system to others inside a network.
- Least privilege
- Giving each person or system only the access needed for the job.
M
- Mass assignment
- An API flaw where users can set fields they should not, like “isAdmin”, by adding them to a request.
- MFA
- Multi-factor authentication: requiring two or more proofs of identity, such as a password and an app code.
P
- Penetration test
- A controlled, authorised attempt by skilled testers to break into a system and prove real impact.
- Phishing
- Fake messages designed to trick people into revealing credentials or running malware.
- Proof of concept
- A demonstration that a vulnerability can really be exploited.
R
- Red team
- A realistic, goal-driven attack simulation testing people, process and technology, including detection.
- Remediation
- Fixing a vulnerability. A retest confirms the fix worked.
- Retest
- A follow-up test that checks reported issues were truly fixed.
- Risk assessment
- Identifying threats and weaknesses and rating the likelihood and impact of each.
S
- SAST
- Static Application Security Testing: analysing source code without running it.
- Scope
- The systems, environments and rules agreed for a security test or audit.
- SIEM
- Security Information and Event Management: a system that collects logs and raises alerts.
- SQL injection
- Injecting database commands through user input to read or change data.
- SSRF
- Server-Side Request Forgery: making a server fetch a URL the attacker chooses, often reaching internal systems.
- Statement of Applicability
- An ISO 27001 document listing which Annex A controls apply and why.
T
- Threat model
- A structured way to think about who might attack a system and how.
- TLPT
- Threat-led penetration testing: advanced, intelligence-driven testing required for some financial entities under DORA.
- Type I vs Type II
- SOC 2 report types: Type I checks design at one date; Type II checks operation over a period.
V
- VAPT
- Vulnerability Assessment and Penetration Testing: finding weaknesses and proving which can be exploited.
- Vulnerability
- A weakness that could be used to harm a system or its data.
W
- WAF
- Web Application Firewall: filters malicious web traffic. Helpful, but not a substitute for fixing vulnerabilities.
X
- XSS
- Cross-Site Scripting: injecting script into a page that runs in other users’ browsers.
Z
- Zero-day
- A vulnerability that is unknown to the vendor and has no official fix yet.
No matching terms. Try a shorter word, or ask us.
Last reviewed October 2026. Educational definitions, not legal advice.