Reference

Security terms, in plain English.

54 terms from penetration testing, application security and compliance, defined without the jargon.

A

API
Application Programming Interface: a way for software to talk to other software. Insecure APIs are a leading source of data exposure.
Attack surface
Every place an attacker could try to get in: web apps, APIs, servers, cloud settings, employees and suppliers.
Attestation report
An independent auditor’s written opinion on controls, such as a SOC 2 report.
Authentication
Proving who you are, for example with a password and a one-time code.
Authorisation
Deciding what an authenticated user is allowed to do or see.

B

Black-box testing
Testing with no inside knowledge of the target, similar to an outside attacker.
BOLA
Broken Object Level Authorisation: changing an ID in a request to read or edit someone else’s record. Also called IDOR.
Brute force
Trying many passwords or keys until one works.
Bug bounty
A programme that pays outside researchers for responsibly reported vulnerabilities.

C

CIA triad
Confidentiality, integrity and availability: the three goals of information security.
Control
A safeguard, technical or procedural, that reduces risk, such as multi-factor authentication or an access review.
CORS
Cross-Origin Resource Sharing: browser rules about which websites can call your API. Misconfiguration can leak data.
CSRF
Cross-Site Request Forgery: tricking a logged-in user’s browser into sending an unwanted request.
CVE
Common Vulnerabilities and Exposures: a public ID for a known vulnerability, such as CVE-2021-44228.
CVSS
Common Vulnerability Scoring System: a 0 to 10 score for how severe a vulnerability is.

D

DAST
Dynamic Application Security Testing: testing a running application from the outside.
Data minimisation
Collecting and keeping only the personal data you actually need.
DPA
Data Processing Agreement: a contract that sets how a processor handles personal data for a controller.

E

Encryption
Scrambling data so only holders of the right key can read it. At rest means stored, in transit means moving over a network.
Exploit
Code or a technique that takes advantage of a vulnerability.

F

False positive
A reported issue that is not actually a problem. Manual validation removes them.

G

Gray-box testing
Testing with partial knowledge, such as a normal user account and documentation.

H

Hardening
Reducing risk by turning off what you do not need and tightening configuration.

I

IAM
Identity and Access Management: tools and policies that control who can access what.
IDOR
Insecure Direct Object Reference: see BOLA.
Incident response
The planned process of detecting, containing, fixing and learning from a security incident.
Injection
Sending malicious input that an application treats as code, as in SQL injection.
ISMS
Information Security Management System: the structure ISO 27001 requires to manage security risk.

J

JWT
JSON Web Token: a signed token used to prove identity to an API. Weak validation is a common flaw.

L

Lateral movement
An attacker moving from one compromised system to others inside a network.
Least privilege
Giving each person or system only the access needed for the job.

M

Mass assignment
An API flaw where users can set fields they should not, like “isAdmin”, by adding them to a request.
MFA
Multi-factor authentication: requiring two or more proofs of identity, such as a password and an app code.

P

Penetration test
A controlled, authorised attempt by skilled testers to break into a system and prove real impact.
Phishing
Fake messages designed to trick people into revealing credentials or running malware.
Proof of concept
A demonstration that a vulnerability can really be exploited.

R

Red team
A realistic, goal-driven attack simulation testing people, process and technology, including detection.
Remediation
Fixing a vulnerability. A retest confirms the fix worked.
Retest
A follow-up test that checks reported issues were truly fixed.
Risk assessment
Identifying threats and weaknesses and rating the likelihood and impact of each.

S

SAST
Static Application Security Testing: analysing source code without running it.
Scope
The systems, environments and rules agreed for a security test or audit.
SIEM
Security Information and Event Management: a system that collects logs and raises alerts.
SQL injection
Injecting database commands through user input to read or change data.
SSRF
Server-Side Request Forgery: making a server fetch a URL the attacker chooses, often reaching internal systems.
Statement of Applicability
An ISO 27001 document listing which Annex A controls apply and why.

T

Threat model
A structured way to think about who might attack a system and how.
TLPT
Threat-led penetration testing: advanced, intelligence-driven testing required for some financial entities under DORA.
Type I vs Type II
SOC 2 report types: Type I checks design at one date; Type II checks operation over a period.

V

VAPT
Vulnerability Assessment and Penetration Testing: finding weaknesses and proving which can be exploited.
Vulnerability
A weakness that could be used to harm a system or its data.

W

WAF
Web Application Firewall: filters malicious web traffic. Helpful, but not a substitute for fixing vulnerabilities.

X

XSS
Cross-Site Scripting: injecting script into a page that runs in other users’ browsers.

Z

Zero-day
A vulnerability that is unknown to the vendor and has no official fix yet.

Last reviewed October 2026. Educational definitions, not legal advice.

Want these explained for your stack?

Book a quick call with a Summit tester.

Get a Quote in 15 mins