196 Security terms
Showing 121–180, alphabetical
-
Attack Detection
Attack detection is the process of identifying malicious activities or unauthorized access attempts within an organization's IT systems. It involves…
-
Attack Dwell Time
Attack dwell time refers to the duration an unauthorized intruder or malicious actor remains active within a compromised network or…
-
Attack Emulation
Attack emulation is a cybersecurity practice that simulates the tactics, techniques, and procedures TTPs of known threat actors. It involves…
-
Attack Exposure
Attack exposure is the total sum of all potential weaknesses and entry points within an organization's systems, networks, and applications…
-
Attack Feasibility
Attack feasibility is an assessment of how likely and easy it is for a threat actor to successfully exploit a…
-
Attack Frequency
Attack frequency refers to the rate at which a system, network, or application is targeted by cyberattack attempts over a…
-
Attack Graph
An attack graph is a visual representation that illustrates all possible sequences of actions an attacker could take to achieve…
-
Attack Lifecycle
The Attack Lifecycle describes the sequential phases an attacker typically follows to achieve their objectives within a target environment. It…
-
Attack Likelihood
Attack Likelihood is a measure of how probable it is that a specific cyber threat will successfully exploit a vulnerability…
-
Attack Mitigation
Attack mitigation refers to the processes and technologies used to reduce the severity and impact of a cyberattack once it…
-
Attack Path
An attack path is a series of interconnected vulnerabilities and misconfigurations that an attacker can exploit to gain unauthorized access…
-
Attack Precondition
An attack precondition is a specific set of circumstances or a particular state that must be present for a cyberattack…
-
Attack Prevention
Attack prevention refers to the proactive strategies and technologies designed to stop cyberattacks before they can successfully breach an organization's…
-
Attack Probability
Attack probability is a metric used in cybersecurity to quantify the likelihood that a specific threat will successfully exploit a…
-
Attack Readiness
Attack readiness refers to an organization's comprehensive state of preparedness against potential cyber threats. It involves evaluating and enhancing security…
-
Attack Recovery
Attack recovery is the process of restoring compromised systems, data, and services to their normal operational state following a cyberattack.…
-
Attack Resilience
Attack resilience refers to an organization's ability to withstand, adapt to, and quickly recover from cyberattacks. It involves designing systems…
-
Attack Simulation
Attack simulation is a cybersecurity practice that involves safely replicating real-world cyberattacks to test an organization's security posture. It uses…
-
Attack Success Rate
Attack Success Rate is a cybersecurity metric that quantifies the percentage of attempted cyberattacks that successfully achieve their intended objective…
-
Attack Surface
An attack surface refers to the total sum of all potential entry points or vulnerabilities that an unauthorized user could…
-
Attack Surface Drift
Attack surface drift refers to the uncontrolled and often unmonitored expansion of an organization's digital assets and potential entry points…
-
Attack Surface Management
Attack Surface Management (ASM) is the continuous process of discovering, inventorying, classifying, and prioritizing all potential entry points that an…
-
Attack Surface Reduction
Attack Surface Reduction is the process of identifying, minimizing, and controlling the number of potential entry points or vectors where…
-
Attack Surface Visibility
Attack surface visibility refers to the ability of an organization to identify and understand all potential points where an unauthorized…
-
Attack Vector
An attack vector is a specific path or method that a cyber threat actor uses to gain unauthorized access to…
-
Attribution
In cybersecurity, attribution is the process of identifying the individual, group, or nation-state responsible for a cyberattack or malicious activity.…
-
Attribution Accuracy
Attribution accuracy in cybersecurity refers to the precision and reliability with which the true origin or perpetrator of a cyberattack…
-
Attribution Confidence
Attribution confidence refers to the degree of certainty an organization has in identifying the specific threat actor or group responsible…
-
Attribution Model
An attribution model in cybersecurity is a structured approach used to identify the source and perpetrators of a cyberattack. It…
-
Attribution Risk
Attribution risk is the difficulty in accurately identifying the true origin or perpetrator of a cyberattack or security incident. This…
-
Attribution Uncertainty
Attribution uncertainty refers to the difficulty in cybersecurity of confidently identifying the perpetrator of a cyberattack. This challenge arises from…
-
Audit
An audit in cybersecurity is a systematic and independent examination of an organization's information systems, processes, and controls. Its purpose…
-
Audit Assurance
Audit assurance in cybersecurity involves the independent review and verification of an organization's security controls, policies, and processes. Its purpose…
-
Audit Compliance
Audit compliance refers to the process of ensuring an organization adheres to established regulations, policies, and standards. This involves systematically…
-
Audit Evidence
Audit evidence consists of all information used by an auditor to conclude whether an organization's cybersecurity controls are operating as…
-
Audit Governance
Audit governance refers to the structured approach an organization takes to manage its security audit activities. It involves setting policies,…
-
Audit Logging
Audit logging is the systematic recording of events that occur within an information system or network. These logs capture details…
-
Audit Maturity
Audit maturity refers to an organization's developed capability to perform systematic and effective security audits. It evaluates the sophistication of…
-
Audit Readiness
Audit readiness refers to an organization's state of being prepared to successfully undergo an external or internal audit of its…
-
Audit Risk
Audit risk refers to the possibility that an auditor may fail to detect a material misstatement or control weakness during…
-
Audit Scope
Audit scope refers to the defined boundaries and parameters of a cybersecurity audit. It specifies which systems, networks, applications, data,…
-
Audit Traceability
Audit traceability refers to the ability to track and verify every action, event, or change within an information system. It…
-
Audit Trail
An audit trail is a sequential record of activities within an information system. It logs who performed what action, when,…
-
Authentication
Authentication is the process of verifying the identity of a user, system, or device. It confirms that an entity is…
-
Authentication Assurance
Authentication assurance refers to the level of confidence that a claimed identity is genuine during a login attempt. It involves…
-
Authentication Assurance Level
An Authentication Assurance Level AAL indicates the degree of confidence that an authenticator verifies a user's claimed identity. It considers…
-
Authentication Bypass
Authentication bypass is a security vulnerability that enables an attacker to gain unauthorized access to a system, application, or data…
-
Authentication Context
Authentication context refers to the specific details and conditions present during a user's authentication event. This includes factors like the…
-
Authentication Entropy
Authentication entropy quantifies the randomness and unpredictability of a credential, such as a password or cryptographic key. It indicates how…
-
Authentication Factor
An authentication factor is a distinct piece of information or characteristic used to verify a user's identity during a login…
-
Authentication Policy
An authentication policy is a formal document that outlines the rules and procedures for verifying the identity of users, devices,…
-
Authentication Risk
Authentication risk refers to the potential for unauthorized individuals or systems to gain access by bypassing or compromising identity verification…
-
Authentication Security
Authentication security refers to the measures and protocols used to verify the identity of a user, device, or system attempting…
-
Authentication Strength
Authentication strength refers to the effectiveness of an authentication method in verifying a user's identity. It evaluates how resistant a…
-
Authorization
Authorization is the process of determining what an authenticated user, system, or application is permitted to do within a system.…
-
Authorization Boundary
An authorization boundary is a logical or physical perimeter that defines the extent of control and access rights for a…
-
Authorization Bypass
An authorization bypass occurs when a system fails to properly enforce access controls, allowing an attacker to gain unauthorized access…
-
Authorization Policy
An authorization policy is a set of rules that specifies which users, roles, or systems are permitted to access particular…
-
Authorization Risk
Authorization risk refers to the potential for an entity, such as a user or system, to gain or retain access…
-
Authorization Scope
Authorization scope specifies the precise set of permissions granted to a user or application when accessing a protected resource. It…