Insights on Crypto Payments, Infrastructure, and Operations

Security, Risk & Compliance

Security controls, fraud, operational risk and regulatory compliance.

673Terms
0Reviewed

Terms (673)

Attack Path

An attack path is the sequence of weaknesses, permissions, systems, and actions an attacker can combine to reach a target outcome. Attack…

Attack Surface

The attack surface is the complete set of reachable interfaces, identities, components, data, and processes that an attacker could target. For Attack…

Attack Surface Management (ASM)

Attack Surface Management (ASM) is the continuous discovery, classification, prioritization, and reduction of assets, exposures, identities, dependencies, and pathways that an attacker…

Attack Tree

An attack tree is a hierarchical model that breaks an adversary's objective into alternative or combined steps required for success. Attack Tree…

Attack Vector

An attack vector is the method or route an attacker uses to reach a target and attempt exploitation or unauthorized influence. Attack…

Attestation of Compliance (AOC)

An Attestation of Compliance is an official PCI form declaring the results of a merchant's or service provider's PCI DSS assessment. An…

Attribute-Based Access Control (ABAC)

Attribute-Based Access Control (ABAC) is a security mechanism or control discipline that dynamically evaluates policies using attributes of the requester, resource, action,…

Audit Evidence

Audit evidence is the reliable information an auditor uses to evaluate whether controls, records, assertions, or compliance requirements are satisfied. Reliable results…

Audit Finding

An audit finding is a documented condition where evidence shows a control, process, or requirement differs from the expected criteria. Audit Finding…

Audit Log

Audit Log is a chronological record of security-relevant and operational events that shows who or what performed an action, when it occurred,…

Audit Logging

Audit logging is the controlled process of generating, transmitting, protecting, retaining, reviewing, and disposing of records about significant system activity. Reliable results…

Audit Program

An Audit Program is a documented set of audit objectives, scope, procedures, evidence requirements, responsibilities, timing, sampling approaches, and reporting steps for…

Audit Sampling

Audit Sampling is the application of audit procedures to fewer than all items in a population so the auditor can form a…

Audit Trail

An audit trail is the linked history of records showing how a transaction, decision, balance, or configuration changed from origin to outcome.…

Auditability

Auditability is the quality of a process or system that allows an independent reviewer to reconstruct events, verify controls, trace decisions, and…

Authenticated Encryption

Authenticated Encryption is a security mechanism or control discipline that protects data confidentiality while also detecting unauthorized modification, typically by producing ciphertext…

Authentication

Authentication is the process of verifying a claimed identity before a system establishes a session or accepts protected activity. Authentication confirms whether…

Authentication Credential

An authentication credential is secret or cryptographic evidence used to prove an identity, such as a password, key, certificate, or token. An…

Authentication Failures

Authentication Failures are unsuccessful, invalid, interrupted, or suspicious attempts to prove identity or control of an authenticator, account, device, key, or session.…

Authentication Token

An authentication token is a signed or secret value presented to prove an authenticated session, client identity, or delegated access grant. An…

Authorization

Authorization is the decision process that determines whether an identified requester may perform a specific action on a particular resource. Authorization evaluates…

Authorization Hold

An authorization hold temporarily reserves part of a payer's available balance before a card transaction is completed, adjusted, or released. An authorization…

Authorization Rate

Authorization rate is the percentage of payment authorization attempts approved by issuers or relevant decision systems during a defined period. Authorization rate…

Authorization Void

Authorization Void is a security mechanism or control discipline that cancels an approved but uncaptured card authorization so the reserved amount can…