Attack Path
An attack path is the sequence of weaknesses, permissions, systems, and actions an attacker can combine to reach a target outcome. Attack…
Security controls, fraud, operational risk and regulatory compliance.
An attack path is the sequence of weaknesses, permissions, systems, and actions an attacker can combine to reach a target outcome. Attack…
The attack surface is the complete set of reachable interfaces, identities, components, data, and processes that an attacker could target. For Attack…
Attack Surface Management (ASM) is the continuous discovery, classification, prioritization, and reduction of assets, exposures, identities, dependencies, and pathways that an attacker…
An attack tree is a hierarchical model that breaks an adversary's objective into alternative or combined steps required for success. Attack Tree…
An attack vector is the method or route an attacker uses to reach a target and attempt exploitation or unauthorized influence. Attack…
An Attestation of Compliance is an official PCI form declaring the results of a merchant's or service provider's PCI DSS assessment. An…
Attribute-Based Access Control (ABAC) is a security mechanism or control discipline that dynamically evaluates policies using attributes of the requester, resource, action,…
Audit evidence is the reliable information an auditor uses to evaluate whether controls, records, assertions, or compliance requirements are satisfied. Reliable results…
An audit finding is a documented condition where evidence shows a control, process, or requirement differs from the expected criteria. Audit Finding…
Audit Log is a chronological record of security-relevant and operational events that shows who or what performed an action, when it occurred,…
Audit logging is the controlled process of generating, transmitting, protecting, retaining, reviewing, and disposing of records about significant system activity. Reliable results…
An Audit Program is a documented set of audit objectives, scope, procedures, evidence requirements, responsibilities, timing, sampling approaches, and reporting steps for…
Audit Sampling is the application of audit procedures to fewer than all items in a population so the auditor can form a…
An audit trail is the linked history of records showing how a transaction, decision, balance, or configuration changed from origin to outcome.…
Auditability is the quality of a process or system that allows an independent reviewer to reconstruct events, verify controls, trace decisions, and…
Authenticated Encryption is a security mechanism or control discipline that protects data confidentiality while also detecting unauthorized modification, typically by producing ciphertext…
Authentication is the process of verifying a claimed identity before a system establishes a session or accepts protected activity. Authentication confirms whether…
An authentication credential is secret or cryptographic evidence used to prove an identity, such as a password, key, certificate, or token. An…
Authentication Failures are unsuccessful, invalid, interrupted, or suspicious attempts to prove identity or control of an authenticator, account, device, key, or session.…
An authentication token is a signed or secret value presented to prove an authenticated session, client identity, or delegated access grant. An…
Authorization is the decision process that determines whether an identified requester may perform a specific action on a particular resource. Authorization evaluates…
An authorization hold temporarily reserves part of a payer's available balance before a card transaction is completed, adjusted, or released. An authorization…
Authorization rate is the percentage of payment authorization attempts approved by issuers or relevant decision systems during a defined period. Authorization rate…
Authorization Void is a security mechanism or control discipline that cancels an approved but uncaptured card authorization so the reserved amount can…
Core concepts behind cryptocurrency, blockchain and distributed systems.
367 terms
Networks, consensus systems, protocols and blockchain infrastructure.
543 terms
Digital assets, token standards, cryptocurrencies and stablecoins.
351 terms