Glossary

Cybersecurity glossary

Plain-English definitions of security categories, acronyms, operating principles, and threat language. Search for a term or browse the full alphabetical index.

25 definitions 4 reference types

Find a definition

Search the glossary

Search by term, full name, category, or wording in the definition.

Term index

Browse all cybersecurity terms.

Each entry starts with a direct definition, distinguishes the term from related concepts, and links to adjacent reference material where it helps.

01

Market category

AI Security

AI security is the practice of protecting AI models, data, applications, agents, infrastructure, and workflows from unauthorized access, manipulation, data leakage, abuse, and other security threats.

02

Platform acronym

ASPM

Application Security Posture Management

ASPM stands for application security posture management. It is a security approach and platform category that correlates application findings with ownership, deployment, reachability, and business context to prioritize and manage remediation across the software lifecycle.

03

Market category

Attack Surface Management

Attack surface management is the practice of identifying, monitoring, and understanding the assets, services, systems, and exposure points that an attacker could discover, reach, or exploit across an environment.

04

Platform acronym

CNAPP

Cloud-Native Application Protection Platform

CNAPP stands for cloud-native application protection platform. It is a cloud security platform category that combines posture management, workload protection, identity and entitlement analysis, development-stage controls, and risk prioritization across cloud-native applications.

Related term DSPM

Open term
05

Platform acronym

DSPM

Data Security Posture Management

DSPM stands for data security posture management. It is a security practice and platform category that discovers and classifies sensitive data, evaluates its storage and access conditions, identifies exposure, and supports risk reduction across cloud and software environments.

Related term CNAPP

Open term
06

Market category

Exposure Management

Exposure management is a continuous security process for discovering assets, identifying weaknesses and attack paths, validating their relevance, prioritizing them by risk, and tracking remediation across an environment.

Related term ASPM

Open term
07

Market category

Identity Security

Identity security is the practice of protecting human and non-human identities, credentials, privileges, and access paths through authentication, authorization, governance, monitoring, and threat response.

Related term MDM

Open term
08

Platform acronym

ITDR

Identity Threat Detection and Response

ITDR stands for identity threat detection and response. It refers to the detection, investigation, and response practices or platforms focused on identity compromise, misuse, privilege abuse, and other identity-centered attack activity.

09

Operating principle

Least Privilege

Least privilege is the security principle of granting a user, identity, process, or workload only the minimum level of access and permission necessary to perform its intended task.

Related term PAM

Open term
10

Platform acronym

MDM

Mobile Device Management

MDM stands for mobile device management. It is the technology and administrative process used to enroll, configure, monitor, secure, and remotely manage mobile devices and their access to organizational resources.

11

Market category

Non-Human Identity

A non-human identity is a digital identity used by software, workloads, services, applications, scripts, bots, devices, or infrastructure components rather than by a human user. These identities still need authentication, authorization, governance, and security controls because they can create significant access risk.

12

Platform acronym

PAM

Privileged Access Management

PAM stands for privileged access management. It refers to the tools, controls, and workflows used to govern, restrict, monitor, and secure elevated access to critical systems, accounts, infrastructure, and administrative functions.

13

Operating principle

Passkeys

Passkeys are passwordless sign-in credentials built on public key cryptography. They let a user authenticate with a device-based credential, usually unlocked with biometrics or a PIN, instead of typing a traditional password.

14

Operating principle

Passwordless Authentication

Passwordless authentication is an approach to sign-in that does not rely on the user typing a traditional password. Instead, it uses other factors or credential models, such as passkeys, device-bound credentials, biometrics, or hardware-backed authentication, to verify identity.

Related term Passkeys

Open term
15

Operating principle

Phishing-Resistant MFA

Phishing-resistant MFA is multi-factor authentication that is designed to prevent attackers from stealing and replaying login factors through phishing or real-time interception. It typically relies on cryptographic, device-bound, or origin-aware authentication methods rather than reusable one-time codes alone.

Related term Passkeys

Open term
16

Threat language

Prompt Injection

Prompt injection is an attack in which an adversary provides crafted input that causes an AI system or language model to ignore, override, or manipulate its intended instructions, often leading to unsafe behavior, data exposure, or unintended actions.

Related term AI Security

Open term
17

Threat language

Ransomware

Ransomware is malware used to deny access to data or systems, usually through encryption, while attackers demand payment. Modern ransomware operations often steal data before disruption and use the threat of disclosure as additional extortion pressure.

Related term XDR

Open term
18

Platform acronym

SBOM

Software Bill of Materials

SBOM stands for software bill of materials. It is a structured inventory of the components, dependencies, libraries, and other building blocks that make up a software product or application.

19

Platform acronym

SCA

Software Composition Analysis

SCA stands for software composition analysis. It refers to the tools and processes used to identify, inventory, and analyze the open-source or third-party components inside software so teams can understand licensing, dependency, and security risk.

Related term SBOM

Open term
20

Operating principle

Secure by Design

Secure by design is a development principle that treats customer security as a core product requirement and reduces foreseeable risk through architecture, engineering, testing, and lifecycle decisions made before release.

Related term AI Security

Open term
21

Software supply chain security is the practice of reducing risk across the components, dependencies, build processes, tools, repositories, and delivery paths involved in creating, packaging, and distributing software.

Related term SBOM

Open term
22

Platform acronym

SSPM

SaaS Security Posture Management

SSPM stands for SaaS security posture management. It refers to the practices or platforms used to identify, evaluate, and reduce security risk across SaaS applications by examining configuration, permissions, exposure, integrations, and related control weaknesses.

Related term DSPM

Open term
23

Market category

Workload Identity

Workload identity is the identity used by a workload such as an application, container, service, or compute instance to authenticate and access other resources. It gives that workload a controlled way to prove who it is and what it is allowed to do.

24

Platform acronym

XDR

Extended Detection and Response

XDR stands for extended detection and response. It is a security operations approach and platform category that combines telemetry and detections from multiple security domains to correlate activity, support investigations, and coordinate response actions.

25

Operating principle

Zero Trust

Zero trust is a cybersecurity approach that assumes no user, device, workload, or network flow should be trusted implicitly. Access decisions are made through explicit verification, context-aware policy, and continuous evaluation rather than broad default trust.

Related term Least Privilege

Open term