Cybersecurity glossary
The terms that show up in security proposals, audits and reports — explained plainly, with what each one means in practice.
C
CVECVE (Common Vulnerabilities and Exposures) is the public system that assigns a unique identifier, in the format CVE-year-number, to each disclosed vulnerability, so vendors, tools and teams can refer to the same flaw without ambiguity.Exposure and testing
CVSSCVSS (Common Vulnerability Scoring System) is the open standard, maintained by FIRST, that gives each vulnerability a score from 0 to 10 based on its technical severity. It measures how serious the flaw is, not the risk to a specific company.Exposure and testing
D
DDoSDDoS (Distributed Denial of Service) is an attack that overwhelms a website, application or network with traffic from many sources at once, usually a botnet, to make it slow or unavailable to legitimate users.Threats
DFIR / Incident responseDFIR (Digital Forensics and Incident Response) is the discipline that combines incident response, which contains the attack and restores operations, with digital forensics, which collects and analyzes evidence to understand what happened, how and to what extent.Security operations
E
EDR (Endpoint Detection and Response)EDR (Endpoint Detection and Response) is a solution that continuously monitors the behavior of endpoints, such as workstations and servers, records their activity and makes it possible to detect, investigate and contain attacks directly on those devices.Security operations
EPSSEPSS (Exploit Prediction Scoring System) is a model maintained by FIRST that estimates the probability, from 0 to 1, that a vulnerability with a CVE will be exploited in the next 30 days, based on signals observed in the real world.Exposure and testing
M
MalwareMalware (malicious software) is any program created to cause harm, steal data, spy, extort or give an attacker control over a system. Viruses, worms, trojans, ransomware and spyware are all types of malware.Threats
MDR (Managed Detection and Response)MDR (Managed Detection and Response) is a managed security service in which a provider monitors the customer's environment, investigates threats and takes response actions, such as isolating an endpoint or blocking an account, instead of just sending alerts.Security operations
MFA (multi-factor authentication)MFA (multi-factor authentication) is a login method that requires two or more factors from different categories, such as something you know (password), something you have (token or phone) and something you are (biometrics), to confirm the identity of whoever is signing in.Governance and compliance
MITRE ATT&CKMITRE ATT&CK is a free, public knowledge base maintained by MITRE that catalogs the tactics and techniques adversaries use in real-world attacks. It provides a common vocabulary to describe, detect and test attack behavior.Security operations
MSS / MSSP (Managed Security Services)MSS (Managed Security Services) is the outsourcing of security control operations, such as firewalls, VPN, IPS and endpoint protection, including administration, updates and monitoring. An MSSP (Managed Security Service Provider) is the company that delivers this service.Security operations
MTTD and MTTRMTTD (Mean Time to Detect) is the average time between the start of malicious activity and its detection. MTTR (Mean Time to Respond) is the average time between detection and containment or resolution. Together, they measure how long an attacker operates in the environment.Security operations
N
NDR (Network Detection and Response)NDR (Network Detection and Response) is a solution that continuously analyzes network traffic to identify suspicious behavior, such as lateral movement, communication with command-and-control servers and data exfiltration, and to support response.Security operations
NIST CSFThe NIST CSF (Cybersecurity Framework) is a voluntary framework from NIST, the US standards institute, for organizing and improving cybersecurity risk management. Version 2.0, published in February 2024, structures the expected outcomes into six functions.Governance and compliance
P
PAM (privileged access management)PAM (privileged access management) is the set of processes and tools that controls, monitors and records the use of accounts with elevated permissions, such as system administrators, service accounts and vendor access.Governance and compliance
Pentest (penetration testing)A pentest, or penetration test, is an authorized, simulated attack with a defined scope in which specialists try to exploit flaws in applications, networks or cloud environments to prove what a real attacker could achieve.Exposure and testing
PhishingPhishing is a scam in which the attacker impersonates a trusted person or organization, by email, message, phone call or fake website, to trick the victim into handing over credentials, data or payments, or into running a malicious file.Threats
Purple TeamA Purple Team is the collaboration between offense and defense: the Red Team and the Blue Team work side by side, technique by technique, so that each simulated attack becomes a concrete improvement in detection or response.Exposure and testing
R
RansomwareRansomware is a type of malware that encrypts files or systems and demands a ransom payment to restore them. Many groups also copy the data beforehand and threaten to leak it, a practice known as double extortion.Threats
Red TeamA Red Team is a group authorized to emulate a real adversary against the organization, attacking people, processes and technology, to show where an intruder would get in and test whether the defense detects and contains the attack.Exposure and testing
RTO and RPORTO (Recovery Time Objective) is the maximum acceptable time to restore a system or process after a disruption. RPO (Recovery Point Objective) is the maximum amount of data, measured in time, that can be lost. Together, they guide backup and continuity.Governance and compliance
S
SIEM (Security Information and Event Management)SIEM (Security Information and Event Management) is a platform that collects, centralizes and correlates logs and events from many IT sources to detect suspicious activity, raise alerts, support investigations and keep records for audit and compliance.Security operations
SOAR (Security Orchestration, Automation and Response)SOAR (Security Orchestration, Automation and Response) is a technology that integrates security tools and automates triage, investigation and response tasks through playbooks, reducing manual work and the SOC's response time.Security operations
SOC (Security Operations Center)A SOC (Security Operations Center) is the combination of people, processes and technology that continuously monitors an organization's environment to detect, investigate and respond to security threats and incidents, usually on a 24/7 basis.Security operations
Social engineeringSocial engineering is the psychological manipulation of people into handing over information, access or money, or into taking actions that compromise security. Instead of exploiting technical flaws, it exploits trust, fear, haste and respect for hierarchy.Threats
T
Third-party risk (TPRM)Third-party risk is the exposure that suppliers, service providers and partners bring to an organization through their access to its data, systems or processes. TPRM (Third-Party Risk Management) is the discipline that identifies, assesses and monitors that risk throughout the relationship.Governance and compliance
Threat HuntingThreat hunting is the proactive, analyst-led search for signs of attackers who are already in the environment and have gone unnoticed by detection tools. It starts from hypotheses about adversary behavior instead of waiting for an alert.Security operations
Threat IntelligenceThreat Intelligence is information about attackers, campaigns, techniques and indicators of compromise, collected and analyzed to support defense decisions, such as prioritizing risks, tuning detections and guiding incident response.Security operations
No terms found.