Insights on Crypto Payments, Infrastructure, and Operations

Security, Risk & Compliance

Security controls, fraud, operational risk and regulatory compliance.

673Terms
0Reviewed

Terms (673)

Outsourcing Risk

Outsourcing risk is exposure created when an external provider performs important processes, technology, support, compliance, custody, or operational functions. Outsourcing Risk must…

OWASP API Security Top 10

The OWASP API Security Top 10 is an awareness document identifying prominent security-risk categories affecting application programming interfaces. The OWASP API Security…

Passwordless Authentication

Passwordless authentication verifies a user without requiring a memorized password, using methods such as passkeys, hardware security keys, device-bound credentials, or cryptographic…

Paymaster Risk

Paymaster risk is exposure created when a third party sponsors transaction fees or determines whether user operations receive gas funding. Paymaster Risk…

Payment Audit

A payment audit independently examines payment records, controls, processing, settlement, reconciliation, fees, and compliance against defined criteria and scope. Reliable results for…

Payment Audit Trail

A payment audit trail is a chronological, attributable record of payment states, actions, approvals, messages, changes, and settlement evidence. Payment Audit Trail…

Payment Authentication

Payment authentication verifies the identity, credential, device, or cryptographic authority associated with a payer before accepting a payment action. Payment authentication determines…

Payment Authorization

Payment authorization is the decision that a specific payer, account, or credential may execute a defined transaction under current rules and limits.…

Payment Blocklist

A payment blocklist is a list of customers, accounts, addresses, assets, countries, devices, or other identifiers that a payment system refuses or…

Payment Compliance

Payment compliance is adherence to the legal, regulatory, network, contractual, tax, privacy, and security obligations governing payment activity. Payment compliance depends on…

Payment Credential

A payment credential is information, a token, key, device, or account reference used to authenticate or authorize payment activity. Payment credentials include…

Payment Incident

A payment incident is an event that disrupts, compromises, misroutes, duplicates, delays, or incorrectly processes payment or settlement activity. Payment Incident must…

Payment Page Script Attack

A payment page script attack compromises, injects, or abuses JavaScript and other client-side resources to steal payment data, change transaction details, redirect…

Payment Risk

Payment risk is the combined possibility of financial, fraud, compliance, security, settlement, liquidity, operational, and customer harm across a payment lifecycle. A…

Payment Security

Payment security protects payment identities, credentials, instructions, data, systems, funds, and settlement processes from theft, manipulation, fraud, and disruption. Payment security covers…

Payment Services Directive (PSD2)

PSD2 is Directive (EU) 2015/2366, the European Union framework governing payment services, payment institutions, user rights, security, strong customer authentication, and access…

Payment Terminal Security

Payment terminal security is the protection of point-of-sale and payment acceptance devices against tampering, malware, key extraction, skimming, unauthorized replacement, and misuse…

Payment Testing Attack

Payment Testing Attack is an attack or weakness pattern that submits many low-value or varied transactions to identify valid credentials, working accounts,…

PCI compliance

PCI compliance means meeting applicable PCI Security Standards Council requirements and validation obligations for a defined payment role, environment, and period. PCI…

PCI PIN Security

PCI PIN Security defines requirements for securely managing, processing, transmitting, and protecting payment-card PIN data and associated cryptographic keys. The PCI PIN…

PCI Security Standards Council

PCI Security Standards Council is a compliance or privacy requirement that develops and maintains global payment-security standards, programs, training, and qualification resources…

Perimeter Security

Perimeter Security is a security mechanism or control discipline that protects a defined boundary between trusted resources and external or less-trusted networks…