Insights on Crypto Payments, Infrastructure, and Operations

Security, Risk & Compliance

Security controls, fraud, operational risk and regulatory compliance.

673Terms
0Reviewed

Terms (673)

Allowed Address

Allowed Address is a specific blockchain address that has been approved for use within a defined account, beneficiary, asset, network, transaction type,…

AML Control

An AML control is a policy, process, system, or review designed to prevent, detect, investigate, or report money-laundering risk. An Anti-Money Laundering…

AML Officer

An AML officer is the designated person responsible for overseeing an organization's anti-money laundering and counter-financing compliance framework. An Anti-Money Laundering officer…

AML Policy

AML Policy is a compliance or privacy requirement that clearly states an organization's principles, responsibilities, and mandatory rules for managing money-laundering and…

AML Program

An AML program is the coordinated governance, people, controls, technology, training, testing, and reporting used to manage financial-crime risk. An Anti-Money Laundering…

AML Risk Assessment

An AML Risk Assessment is a structured evaluation of exposure to money laundering, terrorist financing, proliferation financing, and related financial-crime risks arising…

Anti-Money Laundering (AML)

Anti-Money Laundering refers to laws, controls, and practices intended to prevent criminals from disguising the origin or ownership of illicit funds. Anti-Money…

API Authentication

API authentication verifies the identity of a client, user, or service before an application programming interface accepts protected requests. API authentication confirms…

API Authorization

API authorization determines which endpoints, objects, fields, and actions an authenticated identity may access under defined policies and context. API authorization enforces…

API Credential Management

API credential management securely governs how machine credentials are issued, stored, scoped, used, monitored, rotated, revoked, and retired. API credential management covers…

API Credential Rotation

API Credential Rotation is a security mechanism or control discipline that replaces an existing key, secret, certificate, or token with a new…

API Credential Separation

API credential separation uses distinct credentials for different applications, users, environments, purposes, or privilege levels to contain exposure. API credential separation prevents…

API Inventory

An API Inventory is an authoritative catalog of APIs, endpoints, versions, owners, environments, consumers, data classifications, dependencies, authentication methods, and operational status.…

API Security

API Security is a security mechanism or control discipline that protects application programming interfaces, their data, business logic, credentials, dependencies, and infrastructure…

Application Security

Application security is the discipline of designing, building, testing, deploying, and operating software to resist vulnerabilities, misuse, and unauthorized access. Application security…

Application Security Verification Standard

The Application Security Verification Standard is OWASP's structured set of requirements for evaluating and specifying technical security controls in applications. Application Security…

Approval Phishing

Approval Phishing is a wallet-targeted attack that tricks a user into signing a token allowance, operator approval, permit, or similar authorization that…

Artifact Signing

Artifact Signing is the cryptographic signing of software packages, container images, binaries, manifests, attestations, or other build outputs so recipients can verify…

Asset Inventory

An Asset Inventory is a maintained record of hardware, software, cloud resources, services, data stores, identities, certificates, APIs, and other assets that…

Asset Recovery Risk

Asset recovery risk is the possibility that stolen, lost, frozen, or misdirected assets cannot be located, controlled, returned, or legally reclaimed. Asset…

Asset Risk

Asset risk is the potential for loss arising from an asset's price, liquidity, issuer, technology, legal status, custody, or market structure. A…

Asset Tracing

Asset Tracing is the investigation and reconstruction of value movement across accounts, wallets, transactions, entities, services, blockchains, and conversion points to identify…

Asymmetric Cryptography

Asymmetric Cryptography is cryptography that uses a mathematically related public and private key pair for digital signatures, key establishment, encryption, or identity…

Attack

An attack is a deliberate attempt to compromise confidentiality, integrity, availability, authorization, assets, or trust within a system. Defenses against Attack combine…