Insights on Crypto Payments, Infrastructure, and Operations

Security, Risk & Compliance

Security controls, fraud, operational risk and regulatory compliance.

673Terms
0Reviewed

Terms (673)

Product Risk

Product risk is the possibility that a product’s design, operation, distribution, or use causes financial, legal, security, or customer harm. Decision-makers use…

Protocol Audit

Protocol Audit is an assurance or evaluation activity that evaluates a protocol’s design, implementation, assumptions, incentives, and operating controls for security or…

Protocol Exploit

Protocol Exploit is an attack or weakness pattern that abuses a design, implementation, economic, or integration weakness to violate a protocol’s intended…

Protocol Risk

Protocol risk is exposure to loss or failure arising from a protocol’s rules, assumptions, implementation, governance, incentives, or dependencies. Protocol Risk must…

Protocol Security

Protocol Security is a security mechanism or control discipline that protects a protocol’s intended correctness, availability, authorization, privacy, and economic properties against…

Purchasing Power Risk

Purchasing power risk is the possibility that inflation or price changes reduce what money or stored value can buy over time. Decision-makers…

QR Code Phishing (Quishing)

QR code phishing, or quishing, uses a deceptive QR code to direct a person to a malicious site, payment address, application, credential…

Qualified Security Assessor (QSA)

A Qualified Security Assessor is an eligible professional employed by a PCI SSC-qualified company to perform specified PCI DSS assessments. Qualified Security…

Rate Risk

Rate risk is exposure to loss when an interest, exchange, fee, discount, or other economically relevant rate changes unexpectedly. Decision-makers use Rate…

Re-identification Risk

Re-identification risk is the possibility that data intended to be anonymous, aggregated, or pseudonymous can be linked back to an identifiable person…

Recovery Control

A recovery control is a preventive, detective, or corrective measure designed to restore systems, data, access, or business services after disruption while…

Reentrancy Attack

Reentrancy Attack is an attack or weakness pattern that exploits external calls that re-enter vulnerable code before its previous execution has safely…

Referral Fraud

Referral fraud is the manipulation of a referral or affiliate program to obtain rewards, discounts, commissions, or account benefits through fake users,…

Refund Fraud

Refund fraud manipulates refund processes to obtain money, goods, credits, or duplicate reimbursement without a legitimate entitlement from a merchant. A fraud…

Regulatory Audit

A regulatory audit is an examination by or for a regulator to assess compliance with applicable legal and supervisory requirements. A regulatory…

Regulatory Risk

Regulatory risk is the possibility of loss, restriction, cost, or disruption caused by regulatory requirements, interpretation, enforcement, or change. Regulatory risk arises…

Reinvestment Risk

Reinvestment risk is the possibility that returned principal or interim cash flows can only be reinvested at less favorable rates. Reinvestment Risk…

Remote Access Security

Remote Access Security is a security mechanism or control discipline that protects systems and data when users, administrators, or services connect from…

Reorg Risk

Reorg risk is the possibility that a blockchain’s recently accepted history is replaced, changing transaction inclusion, order, or confirmation status. A score…

Reorganization Risk

Reorganization risk is exposure to changed transaction history when a distributed ledger replaces one accepted branch with another. Decision-makers use Reorganization Risk…

Replacement-Cost Risk

Replacement-cost risk is the possibility that replacing a failed transaction, asset, service, or position costs more than the original arrangement. Replacement-Cost Risk…

Replay Attack

Replay Attack is an attack or weakness pattern that resubmits a previously valid message or transaction so a system performs an authorized…

Replicated Security

Replicated security uses multiple independent system instances or participants to preserve security properties despite individual faults or compromise. Replicated security distributes validation,…

Report on Compliance (ROC)

Report on Compliance (ROC) is a compliance or privacy requirement that documents a formal PCI DSS assessment, the assessed environment, evidence, testing,…