Broken Object Property Level Authorization (BOPLA)
Broken Object Property Level Authorization (BOPLA) is an API flaw that exposes or permits modification of object fields that the requesting principal…
Security controls, fraud, operational risk and regulatory compliance.
Broken Object Property Level Authorization (BOPLA) is an API flaw that exposes or permits modification of object fields that the requesting principal…
Brute-Force Attack is an attack or weakness pattern that repeatedly tries passwords, keys, codes, or other possibilities until one succeeds or a…
Bundler Risk is a measurable uncertainty or exposure that arises when account-abstraction transaction bundlers censor, delay, reorder, simulate incorrectly, or fail to…
Business Email Compromise (BEC) is a fraud scheme in which attackers impersonate or compromise a trusted business email identity to redirect payments,…
A Business Logic Vulnerability is a weakness that lets an attacker misuse a valid feature sequence, rule, state transition, pricing assumption, or…
Business model risk is the possibility that an organization's way of creating revenue and delivering value becomes unprofitable, unsustainable, or noncompliant. Business…
Business Verification is the process of confirming that a legal entity or commercial organization exists and that its submitted identity, ownership, control,…
Bust-Out Fraud is a fraud or abuse pattern that builds an apparently legitimate credit history before rapidly exhausting available credit or payment…
Buyer fraud occurs when a purchaser deceives a merchant or payment provider to obtain goods, services, refunds, or funds without legitimate payment.…
The CCPA is a California privacy law granting consumers rights and imposing notice, data-handling, and request obligations on covered businesses. The California…
Card fraud is unauthorized or deceptive use of payment-card credentials, accounts, transactions, disputes, or merchant processes for financial gain. Card Fraud must…
Card-Not-Present Fraud is unauthorized use of payment-card credentials in a transaction where the physical card is not read or presented to the…
Card-Present Fraud is unauthorized or deceptive use of a payment card or payment device in a transaction where it is physically presented…
Case Management is the controlled workflow for collecting evidence, assigning ownership, documenting analysis, making decisions, and tracking actions for an investigation or…
Censorship Attack is an attack or weakness pattern that deliberately prevents selected valid transactions or users from receiving normal processing, confirmation, relay,…
Centralization risk is the exposure created when critical authority, infrastructure, data, liquidity, or decision-making depends on too few parties. A score for…
CEO Fraud is a form of business email compromise or impersonation in which an attacker poses as a senior executive to pressure…
Certificate Management is the lifecycle control of digital certificates and their associated keys from request and issuance through deployment, monitoring, renewal, revocation,…
Chain Hopping is the movement of virtual assets across different blockchains, often through bridges, swaps, exchanges, or intermediary assets. It is used…
Channel risk is the exposure created by the route through which customers, data, payments, or instructions reach an organization. Decision-makers use Channel…
Chargeback fraud occurs when a cardholder or fraudster improperly disputes a legitimate transaction to recover funds after receiving value. Controls for Chargeback…
A Chief Compliance Officer is the senior executive responsible for overseeing an organization's compliance framework, reporting, advice, monitoring, and escalation. The Chief…
The CIS Critical Security Controls are a prioritized set of safeguards published by the Center for Internet Security to help organizations reduce…
Client Asset Safeguarding is the legal, operational, accounting, and technical protection of customer assets from misuse, loss, insolvency exposure, error, unauthorized access,…
Core concepts behind cryptocurrency, blockchain and distributed systems.
367 terms
Networks, consensus systems, protocols and blockchain infrastructure.
543 terms
Digital assets, token standards, cryptocurrencies and stablecoins.
351 terms