HTTP Request Smuggling
HTTP request smuggling is an attack that exploits inconsistent parsing of HTTP message boundaries between front-end and back-end systems so hidden or…
Security controls, fraud, operational risk and regulatory compliance.
HTTP request smuggling is an attack that exploits inconsistent parsing of HTTP message boundaries between front-end and back-end systems so hidden or…
HSTS is a browser-enforced web security policy that requires future connections to a declared host to use HTTPS instead of insecure HTTP.…
An ICT response and recovery plan is a documented set of roles, decisions, procedures, communications, and technical actions for containing technology incidents…
ICT risk is the possibility of loss, disruption, security harm, data compromise, or business impact arising from information and communication technology systems,…
An ICT-related incident is an unplanned event or linked series of events that compromises, or may compromise, the security, availability, authenticity, integrity,…
Identity fraud is the unauthorized use, fabrication, takeover, or manipulation of identity information to obtain access, open accounts, approve payments, receive benefits,…
Identity Security is a security mechanism or control discipline that protects human and machine identities, credentials, sessions, privileges, enrollment, and recovery from…
Identity threat detection and response is the capability to identify, investigate, contain, and remediate attacks that target accounts, credentials, authentication systems, privileges,…
An immutable backup is a backup copy that cannot be altered or deleted during a defined retention period, including by ordinary administrators…
An incident is an event or series of events that disrupts operations, causes harm, or violates defined security, compliance, or service expectations.…
Incident classification is the consistent assignment of an event to defined categories based on its cause, affected assets, impact, data exposure, threat…
Incident recovery restores affected systems, data, services, and business processes to a trusted and sustainable state after disruption or compromise. Incident Recovery…
Incident response is the coordinated process for detecting, analyzing, containing, eradicating, recovering from, and learning after harmful events. Incident Response must define…
An incident runbook is a maintained set of actionable steps, decisions, roles, and evidence requirements for responding to a defined incident scenario.…
Incident severity is a graded assessment of the actual or potential harm caused by an incident, commonly considering service impact, affected users,…
Independent AML Testing is an objective evaluation of an organization’s anti-money laundering program by qualified persons who are sufficiently independent from the…
Inflation risk is the possibility that rising prices reduce the real purchasing power of money, returns, revenues, collateral, or future cash flows.…
Infrastructure as Code Security is a security mechanism or control discipline that protects machine-readable infrastructure definitions, pipelines, state, credentials, and deployed environments…
Infrastructure Security is a security mechanism or control discipline that protects computing, cloud, network, storage, identity, and platform foundations that applications and…
Inherent risk is the level of exposure associated with an activity before considering the effect of controls intended to reduce that risk.…
Insolvency risk is the possibility that an entity cannot meet obligations or that its liabilities exceed available assets under applicable standards. A…
Integration is the stage of money laundering in which illicit proceeds are reintroduced into the legitimate economy in forms that appear to…
Integration Security is a security mechanism or control discipline that protects data, identities, credentials, messages, and business actions exchanged between connected applications,…
Interactive Fraud Proof is a fraud or abuse pattern that resolves a disputed computation through multiple challenge rounds that narrow disagreement to…
Core concepts behind cryptocurrency, blockchain and distributed systems.
367 terms
Networks, consensus systems, protocols and blockchain infrastructure.
543 terms
Digital assets, token standards, cryptocurrencies and stablecoins.
351 terms