Words we use
Glossary
The terms this website uses, each explained in one or two plain sentences. On every page, a word with a dotted line under it shows the same explanation when you point at it, tap it or move to it with the keyboard.
Services and security work
- Attack vector
- The way an attacker gets into a system, such as a weak password or an unsafe link.
- CISOchief information security officer
- The person who leads security in a company.
- Correlation
- Linking alerts and records from different systems to see one event.
- DevSecOps
- Security built into how software is developed and released.
- DR and BCPdisaster recovery and business continuity planning
- Plans that keep a business running during a failure, and bring its systems back afterwards.
- Ethical hacking
- Attacking a system with the owner's permission, to find weaknesses before a real attacker does.
- Fractional
- Given as a service. One security leader works with several companies, and leads security with each company's team.
- GRCgovernance, risk and compliance
- Security policies, the review of risks, and meeting the rules and standards that apply to you.
- HAhigh availability
- A system built to keep running when one of its parts fails.
- Penetration testing
- An authorised test that attacks a system the way a real attacker would, to find what can be broken.
- Reconnaissance
- Looking for targets: collecting what is known about a system before testing or attacking it.
- Residual risk
- The part of a risk that is left once the controls in place are counted.
- Risk appetite
- The amount of risk a company decides it is willing to accept.
- SecOpssecurity operations
- The daily work of watching for attacks, responding to them and improving defences.
- Security checklist
- The questions a customer sends before it buys, to check how a supplier protects its data.
- Security posture
- The overall state of your security settings and defences.
- Threat actor
- A person or group that carries out attacks.
- Threat intelligence
- Current information about attackers and their methods.
- VAPTvulnerability assessment and penetration testing
- Finding the weak spots in apps, APIs, networks and cloud, and testing them the way an attacker would.
- Virtual CISOa fractional chief information security officer
- Security leadership as a service. A virtual CISO sets your security direction, puts it in place with your team, and reports on it to management.
Cyber forensics and training
- Anti-forensics
- Ways criminals hide or destroy digital evidence.
- Brute force
- Guessing passwords many times until one works.
- Credential dump
- Copying stored passwords from a machine.
- Cross-referencing
- Checking one piece of evidence against others, to confirm it or to find links.
- Cyber forensics
- Collecting and examining digital evidence to find out what happened in an incident.
- Cyber range
- A practice network where people learn to attack and defend safely.
- DFIRdigital forensics and incident response
- Investigating an incident and handling it, from the first alert to the report.
- Digital evidence
- Information stored or sent in digital form that can be used in an investigation, such as logs, files and messages.
- Evidence taxonomy
- A catalogue that sorts digital evidence into types, so an investigation knows what to look for.
- Forensic readiness
- Being prepared before an incident, so the evidence an investigation needs is collected and kept.
- FSLForensic Science Laboratory
- A laboratory that examines evidence for the police and courts.
- Incident response
- The steps a team takes when an attack or a breach is found: contain it, remove it and recover.
- Lateral movement
- Moving from one machine to the next inside a network.
- Malware analysis
- Studying harmful software to learn what it does and how to detect it.
- Modular
- Built from separate parts, so parts can be added or changed.
- RCAroot cause analysis
- Finding out what happened in an incident, how, and why.
- RFSLRegional Forensic Science Laboratory
- A forensic science laboratory that serves one region.
- SIEMsecurity information and event management
- The system that collects security alerts and logs in one place.
- SOCsecurity operations centre
- The team that watches for attacks and responds to them.
- SOCOscene of crime officer
- The officer who collects evidence where a crime took place.
- Triage
- Sorting evidence or alerts by urgency, so the most important are looked at first.
- Voice forensics
- Examining recorded speech as evidence, for example to compare voices.
Checking code and apps
- APKAndroid package
- The file an Android app is installed from.
- Build gate
- A check in the build that stops it when a result passes a limit you set, such as new technical debt.
- CycloneDX
- The OWASP standard format for a software bill of materials.
- Decompiled code
- Readable source code recovered from a built app.
- False positive
- A finding that is reported but is not really a problem.
- IaCinfrastructure as code
- Files that describe servers, networks and permissions, such as Terraform, Kubernetes files and Dockerfiles.
- IPAiOS App Store Package
- The file an iPhone or iPad app is installed from.
- Lock file
- A file that records the exact version of every package a project uses.
- Maintainability grade
- A grade from A to E for how easy the code is to change safely.
- Manifest
- The file that lists the packages a project needs, such as package.json.
- Open source package
- Code that others write and share openly, and that your software uses.
- Open Threat Model
- An open file format for threat models, which several threat modelling tools read.
- Root detection
- Code in a mobile app that notices when the phone's built-in protections have been removed.
- SARIFStatic Analysis Results Interchange Format
- A standard file format for analysis results that editors and build systems can read.
- SBOMsoftware bill of materials
- The list of every part your software is made of, with versions.
- Secret
- A password, key or token that gives access to a system, left in a file by mistake.
- Secure coding
- Writing software in ways that avoid common security weaknesses.
- Static analysis
- Reading code for problems without running it, so every branch is seen, including the ones tests never reach.
- Taint analysis
- Following untrusted input from where it enters a program to where it could do harm.
- Technical debt
- The estimated time to fix every open finding, worked out per finding and added up.
- Threat model
- A list of what could go wrong in a system: its parts, the boundaries between them, and the threats against each, with how serious each one is.
- Trust boundary
- Where data passes from something you do not control into something you do.
Checking running systems
- Adversary in the middle
- An attacker placed on the network path who can read or change traffic.
- APIapplication programming interface
- The interface one program uses to talk to another.
- Asset
- One thing you add to Ivy Insight to be checked, such as a host, a domain, a website, an API or a cloud account.
- Attack surface
- Everything an attacker can reach from outside: sites, services, addresses and names.
- Benchmark
- A published list of secure settings for one kind of system, checked one control at a time.
- Cloud posture
- How safely a cloud account is set up, checked against the provider's rules and published benchmarks.
- Control plane
- The central server that plans the scans and keeps the results.
- Coverage
- What a scan was able to check, and what it could not, with the reason.
- Cross origin policy
- Browser rules on which other sites may read a page.
- Dangling record
- A DNS name that still points to a service that no longer exists, which someone else could claim.
- DNSDomain Name System
- The internet's address book, which turns names into addresses.
- Drift
- Settings that move away from the approved baseline over time.
- Endpoint
- A laptop or desktop computer that people work on, in the office or away from it.
- GraphQL
- A style of web API where the caller asks for exactly the data it wants.
- HSTSHTTP Strict Transport Security
- A setting that tells browsers to use only encrypted connections to a site.
- Load balancer
- A server that shares incoming traffic between several other servers.
- Middleware
- Software such as queues and caches that sits between applications and their data.
- Mixed content
- An encrypted page that loads some of its parts without encryption.
- Prompt injection
- Text that tricks an AI model into ignoring its instructions.
- REST
- A common style of web API. Each address names one thing, such as a customer or an order.
- Scan policy
- The rules for a scan: how fast it may go, when it may run, what it must leave out, and whether checks that could change data are allowed.
- Subdomain
- A name under your main domain, such as shop.example.com.
- TLSTransport Layer Security
- The encryption that protects traffic between a browser or app and a server.
- Webhook
- A message one system sends to another address when something happens.
- Worker
- The part that runs the checks, close to the systems it checks.
Reading findings and risk
- Canonical issue
- One underlying problem that many findings describe. Findings that agree on their control, threat path, text, assets and timing are grouped into one canonical issue.
- Column mapping
- Which column of your file holds which field Ivy Farsight reads. It suggests a match for each column, with its reason, and a person approves it.
- Control effectiveness
- How much of a risk the controls in place remove, as a share from 0 to 100 per cent.
- DFDdata flow diagram
- A drawing of the parts of a system and the data that moves between them, with the trust boundaries the data crosses.
- Findings dataset
- A table of the security findings a company already has, from audits, scanners and reviews, with one finding on each row. Usually an Excel workbook or a CSV file.
- Inherent risk
- The risk before any control is counted: how likely it is, multiplied by how much harm it would do.
- IRMintegrated risk management
- The tool where an organisation keeps its risk register.
- Local language model
- A text model that runs on your own machine, with no internet connection. In Ivy Farsight it only words the facts the rules worked out, and never changes a number.
- Near duplicate
- A finding that is close to a canonical issue, but not close enough to join it by rule. An analyst decides whether it joins.
- NVDNational Vulnerability Database
- The public database of CVEs kept in the United States, with the product versions each one affects.
- OpenAPI
- A file that describes an API: its routes, its inputs, and how callers sign in.
- Provenance
- Where a figure comes from: the file and its row, the columns and formula used, the outside records, and the person who decided.
- Release line
- The versions of a product that share their first numbers, such as 5.15. A fix on the same line is a smaller change than a move to a new line.
- Risk concentration
- Where most of the remaining risk gathers: in which themes, services or owners.
- Risk theme
- A group of canonical issues that management can steer as one topic, such as vulnerability management or access control.
- Rule-based AI
- AI built from fixed rules that can be read, not from a trained machine learning model. The same data and the same question always give the same answer.
- SHA-256
- A code worked out from every byte of a file, used as its fingerprint. Any change to the file gives a different code.
- SLAservice level agreement
- The number of days a finding of its severity may stay open. After that it is overdue.
- Snapshot
- One export of your findings at one point in time. Two snapshots can be compared.
- STRIDEspoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege
- The six kinds of threat used in threat modelling.
- Turnaround time
- The time from a request to its signed off result, such as a threat model from intake to sign-off.
Standards, lists and scores
- Annex A
- The list of security controls in ISO/IEC 27001. A company chooses the ones that apply to it.
- CIS Benchmark
- Free lists of secure settings for each kind of system, from the Center for Internet Security.
- CISACybersecurity and Infrastructure Security Agency
- The cybersecurity agency of the United States. It publishes the list of known exploited vulnerabilities.
- CVECommon Vulnerabilities and Exposures
- The public identifier for one known vulnerability in one product.
- CWECommon Weakness Enumeration
- The common list of software weakness types.
- CWE Top 25
- The 25 most dangerous software weaknesses, ranked each year from published data.
- Cyber Resilience Act
- The European Union law that sets security rules for products with digital parts, such as software and connected devices.
- DPDPDigital Personal Data Protection
- India's law on personal data in digital form: the DPDP Act, 2023, with the DPDP Rules, 2025. It sets duties for the organisations that use personal data, and rights for the people it is about.
- EPSSExploit Prediction Scoring System
- A daily score for how likely a vulnerability is to be exploited in the next 30 days.
- FIRSTForum of Incident Response and Security Teams
- A global forum of security response teams. It publishes the EPSS scores.
- HIPAAHealth Insurance Portability and Accountability Act
- A United States law that protects health information. Its Security Rule says how that information must be kept safe.
- ISO 27001ISO/IEC 27001
- The international standard for an information security management system.
- KEVKnown Exploited Vulnerabilities
- CISA's list of vulnerabilities that attackers are known to have used.
- MASVSOWASP Mobile Application Security Verification Standard
- The list of controls a secure mobile app should meet.
- MITRE ATT&CK
- MITRE's catalogue of what attackers do, grouped by their goals and their methods.
- MITRE CAPECCommon Attack Pattern Enumeration and Classification
- MITRE's catalogue of the ways attackers break into software.
- NIST CSFNIST Cybersecurity Framework
- A widely used framework from the US National Institute of Standards and Technology for organising security work.
- NIST SP 800-53
- A large catalogue of security and privacy controls from the US National Institute of Standards and Technology.
- OWASPOpen Worldwide Application Security Project
- A non-profit foundation that publishes widely used security lists and standards.
- OWASP ASVSOWASP Application Security Verification Standard
- A list of security requirements a web application should meet, used to build it and to test it.
- OWASP Top 10
- OWASP's list of the ten most critical security risks to web applications.
- PCI DSSPayment Card Industry Data Security Standard
- The security rules for any company that stores, processes or sends payment card data.
- Severity
- How much damage a finding could allow: critical, high, medium, low or info.
- SOC 2
- An audit of how a service company protects customer data.
General terms
- Air gapped
- A machine or network with no connection to the internet at all, usually on purpose.
- ARM
- A family of computer processors, used in Apple silicon Macs, in phones and in many servers. The other common family is x86, used in most Windows and Linux computers.
- BSONbinary JSON
- The file format MongoDB exports its records in.
- Container
- A packaged program that runs apart from the rest of the machine, with everything it needs inside.
- Cookie
- A small file a website stores in your browser, to recognise you when you come back.
- Credits
- The units a scan is paid with. You pay for the scans you run, not for each user.
- CSVcomma separated values
- A plain text table, one row per line, that any spreadsheet can open.
- Exploit
- A way to use a vulnerability to attack a system. To exploit a vulnerability is to use it in this way.
- Finding
- One problem a check reports, with its evidence and how to fix it.
- Hyperscaling
- Building systems that grow to very large numbers of users and data.
- IP address
- The number that identifies a device on the internet, or the network it connects through.
- JSON
- A plain text file format for data.
- Median
- The middle value. Half of the values are above it, and half are below it.
- On premises
- On your own hardware, in your own building or data centre.
- Telemetry
- Usage data a tool sends back to its maker.
- TSVtab separated values
- A plain text table with a tab between the columns.
- User agent
- A line of text your browser sends with each request. It names the browser and the system it runs on.
- VoIPvoice over IP
- Phone calls over the internet.
- Vulnerability
- A weakness that an attacker could use to cause harm.
A term we have not explained
Tell us the word, and the page where you saw it. The address is info@visiminds.com.