Insights on Crypto Payments, Infrastructure, and Operations

Security, Risk & Compliance

Security controls, fraud, operational risk and regulatory compliance.

673Terms
0Reviewed

Terms (673)

Permit Phishing

Permit phishing deceives a wallet user into signing an off-chain token approval or permit message that authorizes an attacker or malicious contract…

Personnel Security

Personnel Security is a security mechanism or control discipline that manages risks involving employees, contractors, and trusted workers throughout screening, onboarding, access,…

Phishing

Phishing is a social-engineering attack that impersonates a trusted person, brand, service, or workflow to induce disclosure of information, malware execution, funds…

Phishing Simulation

A phishing simulation is an authorized exercise that sends realistic but controlled phishing messages or scenarios to measure and improve how people…

Physical Security

Physical Security is a security mechanism or control discipline that protects people, facilities, devices, media, infrastructure, and assets from unauthorized access, theft,…

PIN Encryption

PIN encryption protects a personal identification number by transforming it into an approved encrypted form, usually within a secure payment device and…

Platform Risk

Platform risk is exposure created by dependence on a shared technology, marketplace, operating system, cloud, protocol, or service ecosystem. Platform Risk must…

Point-to-Point Encryption (P2PE)

Point-to-Point Encryption (P2PE) is a security mechanism or control discipline that protects payment data from the point of capture until controlled decryption…

Policy-Based Access Control (PBAC)

Policy-based access control makes authorization decisions by evaluating centrally defined policies against attributes and context such as user role, resource, action, device,…

Portfolio Risk

Portfolio risk is the combined uncertainty and potential loss across a collection of positions, considering concentration, correlation, liquidity, and interaction. Portfolio Risk…

Post-Incident Review

A post-incident review is a structured examination performed after stabilization to understand what happened, why controls and decisions behaved as they did,…

Principal Risk

Principal risk is the possibility of losing the full amount delivered in a transaction when the expected reciprocal asset or payment is…

Privacy

Privacy is the ability and right to control, limit, and understand how information, behavior, communications, and personal spaces are observed or used.…

Privacy by Default

Privacy by Default configures products and services so the initial settings collect, expose, retain, and share only what is necessary. Privacy by…

Privacy by Design

Privacy by Design integrates privacy principles, risks, and controls into architecture, products, processes, and decisions from the earliest stages. Privacy by Design…

Privacy Coin

A privacy coin is a cryptocurrency designed to reduce public visibility of transaction participants, amounts, balances, or payment relationships. Privacy coins use…

Privacy Impact Assessment (PIA)

A privacy impact assessment is a structured evaluation of how a project, system, product, or processing activity may affect individuals’ privacy and…

Privacy Notice

A privacy notice explains how an organization collects, uses, shares, retains, protects, and otherwise processes personal data, including relevant purposes, lawful bases,…

Privacy Policy

A privacy policy explains how an organization collects, uses, shares, protects, retains, and handles rights relating to personal information. A privacy policy…

Privacy Risk Assessment

A privacy risk assessment identifies and evaluates the likelihood and impact of problems that data processing may create for individuals, including loss…

Privacy-Preserving Analytics

Privacy-preserving analytics uses technical and organizational methods to extract useful insights while reducing exposure, identifiability, or unnecessary use of personal or sensitive…

Private Key Compromise

A private key compromise occurs when an unauthorized party obtains, reconstructs, or gains effective use of a secret cryptographic key used to…

Private Key Exposure

Private Key Exposure is a condition in which a cryptographic private key becomes accessible to an unauthorized person, process, device, log, repository,…

Privileged Role Risk

Privileged role risk is exposure created when a role can perform high-impact actions, access sensitive assets, or override normal controls. Decision-makers use…