Visiminds Technologies, home

Words we use

Glossary

The terms this website uses, each explained in one or two plain sentences. On every page, a word with a dotted line under it shows the same explanation when you point at it, tap it or move to it with the keyboard.

Services and security work

Attack vector
The way an attacker gets into a system, such as a weak password or an unsafe link.
CISOchief information security officer
The person who leads security in a company.
Correlation
Linking alerts and records from different systems to see one event.
DevSecOps
Security built into how software is developed and released.
DR and BCPdisaster recovery and business continuity planning
Plans that keep a business running during a failure, and bring its systems back afterwards.
Ethical hacking
Attacking a system with the owner's permission, to find weaknesses before a real attacker does.
Fractional
Given as a service. One security leader works with several companies, and leads security with each company's team.
GRCgovernance, risk and compliance
Security policies, the review of risks, and meeting the rules and standards that apply to you.
HAhigh availability
A system built to keep running when one of its parts fails.
Penetration testing
An authorised test that attacks a system the way a real attacker would, to find what can be broken.
Reconnaissance
Looking for targets: collecting what is known about a system before testing or attacking it.
Residual risk
The part of a risk that is left once the controls in place are counted.
Risk appetite
The amount of risk a company decides it is willing to accept.
SecOpssecurity operations
The daily work of watching for attacks, responding to them and improving defences.
Security checklist
The questions a customer sends before it buys, to check how a supplier protects its data.
Security posture
The overall state of your security settings and defences.
Threat actor
A person or group that carries out attacks.
Threat intelligence
Current information about attackers and their methods.
VAPTvulnerability assessment and penetration testing
Finding the weak spots in apps, APIs, networks and cloud, and testing them the way an attacker would.
Virtual CISOa fractional chief information security officer
Security leadership as a service. A virtual CISO sets your security direction, puts it in place with your team, and reports on it to management.

Cyber forensics and training

Anti-forensics
Ways criminals hide or destroy digital evidence.
Brute force
Guessing passwords many times until one works.
Credential dump
Copying stored passwords from a machine.
Cross-referencing
Checking one piece of evidence against others, to confirm it or to find links.
Cyber forensics
Collecting and examining digital evidence to find out what happened in an incident.
Cyber range
A practice network where people learn to attack and defend safely.
DFIRdigital forensics and incident response
Investigating an incident and handling it, from the first alert to the report.
Digital evidence
Information stored or sent in digital form that can be used in an investigation, such as logs, files and messages.
Evidence taxonomy
A catalogue that sorts digital evidence into types, so an investigation knows what to look for.
Forensic readiness
Being prepared before an incident, so the evidence an investigation needs is collected and kept.
FSLForensic Science Laboratory
A laboratory that examines evidence for the police and courts.
Incident response
The steps a team takes when an attack or a breach is found: contain it, remove it and recover.
Lateral movement
Moving from one machine to the next inside a network.
Malware analysis
Studying harmful software to learn what it does and how to detect it.
Modular
Built from separate parts, so parts can be added or changed.
RCAroot cause analysis
Finding out what happened in an incident, how, and why.
RFSLRegional Forensic Science Laboratory
A forensic science laboratory that serves one region.
SIEMsecurity information and event management
The system that collects security alerts and logs in one place.
SOCsecurity operations centre
The team that watches for attacks and responds to them.
SOCOscene of crime officer
The officer who collects evidence where a crime took place.
Triage
Sorting evidence or alerts by urgency, so the most important are looked at first.
Voice forensics
Examining recorded speech as evidence, for example to compare voices.

Checking code and apps

APKAndroid package
The file an Android app is installed from.
Build gate
A check in the build that stops it when a result passes a limit you set, such as new technical debt.
CycloneDX
The OWASP standard format for a software bill of materials.
Decompiled code
Readable source code recovered from a built app.
False positive
A finding that is reported but is not really a problem.
IaCinfrastructure as code
Files that describe servers, networks and permissions, such as Terraform, Kubernetes files and Dockerfiles.
IPAiOS App Store Package
The file an iPhone or iPad app is installed from.
Lock file
A file that records the exact version of every package a project uses.
Maintainability grade
A grade from A to E for how easy the code is to change safely.
Manifest
The file that lists the packages a project needs, such as package.json.
Open source package
Code that others write and share openly, and that your software uses.
Open Threat Model
An open file format for threat models, which several threat modelling tools read.
Root detection
Code in a mobile app that notices when the phone's built-in protections have been removed.
SARIFStatic Analysis Results Interchange Format
A standard file format for analysis results that editors and build systems can read.
SBOMsoftware bill of materials
The list of every part your software is made of, with versions.
Secret
A password, key or token that gives access to a system, left in a file by mistake.
Secure coding
Writing software in ways that avoid common security weaknesses.
Static analysis
Reading code for problems without running it, so every branch is seen, including the ones tests never reach.
Taint analysis
Following untrusted input from where it enters a program to where it could do harm.
Technical debt
The estimated time to fix every open finding, worked out per finding and added up.
Threat model
A list of what could go wrong in a system: its parts, the boundaries between them, and the threats against each, with how serious each one is.
Trust boundary
Where data passes from something you do not control into something you do.

Checking running systems

Adversary in the middle
An attacker placed on the network path who can read or change traffic.
APIapplication programming interface
The interface one program uses to talk to another.
Asset
One thing you add to Ivy Insight to be checked, such as a host, a domain, a website, an API or a cloud account.
Attack surface
Everything an attacker can reach from outside: sites, services, addresses and names.
Benchmark
A published list of secure settings for one kind of system, checked one control at a time.
Cloud posture
How safely a cloud account is set up, checked against the provider's rules and published benchmarks.
Control plane
The central server that plans the scans and keeps the results.
Coverage
What a scan was able to check, and what it could not, with the reason.
Cross origin policy
Browser rules on which other sites may read a page.
Dangling record
A DNS name that still points to a service that no longer exists, which someone else could claim.
DNSDomain Name System
The internet's address book, which turns names into addresses.
Drift
Settings that move away from the approved baseline over time.
Endpoint
A laptop or desktop computer that people work on, in the office or away from it.
GraphQL
A style of web API where the caller asks for exactly the data it wants.
HSTSHTTP Strict Transport Security
A setting that tells browsers to use only encrypted connections to a site.
Load balancer
A server that shares incoming traffic between several other servers.
Middleware
Software such as queues and caches that sits between applications and their data.
Mixed content
An encrypted page that loads some of its parts without encryption.
Prompt injection
Text that tricks an AI model into ignoring its instructions.
REST
A common style of web API. Each address names one thing, such as a customer or an order.
Scan policy
The rules for a scan: how fast it may go, when it may run, what it must leave out, and whether checks that could change data are allowed.
Subdomain
A name under your main domain, such as shop.example.com.
TLSTransport Layer Security
The encryption that protects traffic between a browser or app and a server.
Webhook
A message one system sends to another address when something happens.
Worker
The part that runs the checks, close to the systems it checks.

Reading findings and risk

Canonical issue
One underlying problem that many findings describe. Findings that agree on their control, threat path, text, assets and timing are grouped into one canonical issue.
Column mapping
Which column of your file holds which field Ivy Farsight reads. It suggests a match for each column, with its reason, and a person approves it.
Control effectiveness
How much of a risk the controls in place remove, as a share from 0 to 100 per cent.
DFDdata flow diagram
A drawing of the parts of a system and the data that moves between them, with the trust boundaries the data crosses.
Findings dataset
A table of the security findings a company already has, from audits, scanners and reviews, with one finding on each row. Usually an Excel workbook or a CSV file.
Inherent risk
The risk before any control is counted: how likely it is, multiplied by how much harm it would do.
IRMintegrated risk management
The tool where an organisation keeps its risk register.
Local language model
A text model that runs on your own machine, with no internet connection. In Ivy Farsight it only words the facts the rules worked out, and never changes a number.
Near duplicate
A finding that is close to a canonical issue, but not close enough to join it by rule. An analyst decides whether it joins.
NVDNational Vulnerability Database
The public database of CVEs kept in the United States, with the product versions each one affects.
OpenAPI
A file that describes an API: its routes, its inputs, and how callers sign in.
Provenance
Where a figure comes from: the file and its row, the columns and formula used, the outside records, and the person who decided.
Release line
The versions of a product that share their first numbers, such as 5.15. A fix on the same line is a smaller change than a move to a new line.
Risk concentration
Where most of the remaining risk gathers: in which themes, services or owners.
Risk theme
A group of canonical issues that management can steer as one topic, such as vulnerability management or access control.
Rule-based AI
AI built from fixed rules that can be read, not from a trained machine learning model. The same data and the same question always give the same answer.
SHA-256
A code worked out from every byte of a file, used as its fingerprint. Any change to the file gives a different code.
SLAservice level agreement
The number of days a finding of its severity may stay open. After that it is overdue.
Snapshot
One export of your findings at one point in time. Two snapshots can be compared.
STRIDEspoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege
The six kinds of threat used in threat modelling.
Turnaround time
The time from a request to its signed off result, such as a threat model from intake to sign-off.

Standards, lists and scores

Annex A
The list of security controls in ISO/IEC 27001. A company chooses the ones that apply to it.
CIS Benchmark
Free lists of secure settings for each kind of system, from the Center for Internet Security.
CISACybersecurity and Infrastructure Security Agency
The cybersecurity agency of the United States. It publishes the list of known exploited vulnerabilities.
CVECommon Vulnerabilities and Exposures
The public identifier for one known vulnerability in one product.
CWECommon Weakness Enumeration
The common list of software weakness types.
CWE Top 25
The 25 most dangerous software weaknesses, ranked each year from published data.
Cyber Resilience Act
The European Union law that sets security rules for products with digital parts, such as software and connected devices.
DPDPDigital Personal Data Protection
India's law on personal data in digital form: the DPDP Act, 2023, with the DPDP Rules, 2025. It sets duties for the organisations that use personal data, and rights for the people it is about.
EPSSExploit Prediction Scoring System
A daily score for how likely a vulnerability is to be exploited in the next 30 days.
FIRSTForum of Incident Response and Security Teams
A global forum of security response teams. It publishes the EPSS scores.
HIPAAHealth Insurance Portability and Accountability Act
A United States law that protects health information. Its Security Rule says how that information must be kept safe.
ISO 27001ISO/IEC 27001
The international standard for an information security management system.
KEVKnown Exploited Vulnerabilities
CISA's list of vulnerabilities that attackers are known to have used.
MASVSOWASP Mobile Application Security Verification Standard
The list of controls a secure mobile app should meet.
MITRE ATT&CK
MITRE's catalogue of what attackers do, grouped by their goals and their methods.
MITRE CAPECCommon Attack Pattern Enumeration and Classification
MITRE's catalogue of the ways attackers break into software.
NIST CSFNIST Cybersecurity Framework
A widely used framework from the US National Institute of Standards and Technology for organising security work.
NIST SP 800-53
A large catalogue of security and privacy controls from the US National Institute of Standards and Technology.
OWASPOpen Worldwide Application Security Project
A non-profit foundation that publishes widely used security lists and standards.
OWASP ASVSOWASP Application Security Verification Standard
A list of security requirements a web application should meet, used to build it and to test it.
OWASP Top 10
OWASP's list of the ten most critical security risks to web applications.
PCI DSSPayment Card Industry Data Security Standard
The security rules for any company that stores, processes or sends payment card data.
Severity
How much damage a finding could allow: critical, high, medium, low or info.
SOC 2
An audit of how a service company protects customer data.

General terms

Air gapped
A machine or network with no connection to the internet at all, usually on purpose.
ARM
A family of computer processors, used in Apple silicon Macs, in phones and in many servers. The other common family is x86, used in most Windows and Linux computers.
BSONbinary JSON
The file format MongoDB exports its records in.
Container
A packaged program that runs apart from the rest of the machine, with everything it needs inside.
Cookie
A small file a website stores in your browser, to recognise you when you come back.
Credits
The units a scan is paid with. You pay for the scans you run, not for each user.
CSVcomma separated values
A plain text table, one row per line, that any spreadsheet can open.
Exploit
A way to use a vulnerability to attack a system. To exploit a vulnerability is to use it in this way.
Finding
One problem a check reports, with its evidence and how to fix it.
Hyperscaling
Building systems that grow to very large numbers of users and data.
IP address
The number that identifies a device on the internet, or the network it connects through.
JSON
A plain text file format for data.
Median
The middle value. Half of the values are above it, and half are below it.
On premises
On your own hardware, in your own building or data centre.
Telemetry
Usage data a tool sends back to its maker.
TSVtab separated values
A plain text table with a tab between the columns.
User agent
A line of text your browser sends with each request. It names the browser and the system it runs on.
VoIPvoice over IP
Phone calls over the internet.
Vulnerability
A weakness that an attacker could use to cause harm.

A term we have not explained

Tell us the word, and the page where you saw it. The address is info@visiminds.com.