What are Indicators of Attack (IOA)?
Indicators of Attack (IOAs) are behavioral patterns that reveal an attacker's active techniques and intent in real time, before a breach is confirmed.
Indicators of Attack (IOAs) are behavioral patterns that reveal an attacker's active techniques and intent in real time, before a breach is confirmed.
802.1X is an IEEE standard for port-based network access control that authenticates devices before granting them access to wired or wireless networks.
A blue team is a group of defensive cybersecurity professionals responsible for protecting an organization's information systems from cyber threats.
A botnet is a network of internet-connected devices compromised by malware and controlled remotely by an attacker known as a bot herder.
A Certificate Authority (CA) is a trusted organization that validates identities and issues digital certificates, binding public cryptographic keys to verified entities such as websites, businesses, and individuals.
A Change Advisory Board (CAB) is a cross-functional group that evaluates and provides guidance on proposed IT infrastructure and service changes before implementation.
A Cloud Access Security Broker (CASB) is a security policy enforcement point that sits between enterprise users and cloud service providers to monitor activity, enforce security policies, and protect data across SaaS, IaaS, and PaaS environments.
A Configuration Management Database (CMDB) is a centralized repository that stores information about an organization's IT assets (called Configuration Items, or CIs) and the relationships between them.
Containers are a form of operating system-level virtualization that package an application's code, runtime, system libraries, and dependencies into a single, portable unit running consistently across any computing environment.
A Data Protection Impact Assessment (DPIA) is a mandatory risk evaluation framework that identifies, analyzes, and mitigates privacy risks before processing personal data in high-risk scenarios.
A feature flag is a software development technique that enables teams to control functionality at runtime without deploying new code.
A Hardware Security Module (HSM) is a physical computing device that safeguards and manages cryptographic keys through tamper-resistant hardware.
A honeypot is a decoy system deliberately configured to appear legitimate and vulnerable in order to attract attackers into a controlled environment where their methods, tools, and behavior can be monitored and analyzed.
A Kubernetes Ingress Controller routes external HTTP/HTTPS traffic to services inside a cluster using URL, hostname, and path-based rules at Layer 7.
A load balancer is a network component that distributes incoming traffic across multiple servers to prevent overload and maintain application availability.
A managed service provider (MSP) is a third-party company that remotely manages a client's IT infrastructure and business technology functions on an ongoing subscription basis under a defined service level agreement.
A Master Service Agreement (MSA) is a contract that establishes the foundational legal and commercial terms governing an ongoing business relationship between two parties, so each new project can launch under a separate Statement of Work without renegotiating core terms.
A Secure Email Gateway (SEG) is email security software that filters inbound and outbound email traffic for malicious content, spam, and policy violations before messages reach user inboxes or leave the organization.
Access management is the cybersecurity discipline that controls and governs who can access an organization's digital resources and what actions they can perform once authenticated.
Adware is software that automatically displays, delivers, or downloads advertisements on a user's device, typically through pop-ups, banners, or browser redirects.
An Acceptable Use Policy (AUP) defines how authorized users interact with an organization's IT resources, networks, devices, software, and data.
An API gateway is a server or service that acts as a centralized entry point between client applications and backend services in microservices architectures.
An attack surface is the total number of potential entry points where an unauthorized user can gain access to a system, network, or data.
An error budget is a quantified measure of acceptable service unreliability within a defined timeframe, calculated as the inverse of a Service Level Objective (SLO).
An escalation policy is a formalized procedure that defines how IT incidents and alerts are elevated through organizational tiers to ensure prompt resolution when primary responders can't acknowledge or resolve them within defined timeframes.
An Incident Response Plan (IRP) is a formally documented, organization-approved strategy that defines how a business will detect, contain, eradicate, and recover from cybersecurity incidents.
An Indicator of Compromise (IOC) is a forensic artifact collected from a network, endpoint, or system that signals a breach has occurred or is in progress.
An Intrusion Detection System (IDS) is a network security technology that monitors traffic and system activity for malicious behavior and alerts administrators without blocking or intercepting traffic.
An Intrusion Prevention System (IPS) is a network security technology that sits inline in the traffic path and automatically blocks malicious traffic in real time before it reaches its destination.
Annual Recurring Revenue (ARR) is the total predictable subscription-based revenue a company expects to generate over a 12-month period, normalized to exclude one-time fees.
Application Performance Monitoring (APM) is the practice of using software tools and telemetry data to track, diagnose, and optimize the performance and availability of software applications.
Application Security (AppSec) is the discipline of identifying, preventing, and remediating security vulnerabilities in software applications throughout their entire lifecycle from design and development through deployment and ongoing maintenance.
Attribute-Based Access Control (ABAC) is an authorization model that determines access permissions by evaluating attributes associated with users, resources, actions, and environmental conditions, rather than assigning permissions based solely on predefined roles.
Auto scaling is a cloud computing technique that dynamically adjusts the number of active server instances based on real-time or predicted demand.
Availability Management is an ITIL practice that ensures IT services deliver agreed levels of availability to meet business needs.
Backup as a Service (BaaS) is a cloud-based subscription model that enables organizations to outsource data backup, storage, and recovery operations to a third-party provider.
BIMI (Brand Indicators for Message Identification) is an email specification that enables organizations to display verified brand logos alongside authenticated emails in recipient inboxes.
Binary hardening is a cybersecurity technique that modifies compiled executable files to resist exploitation, reverse engineering, and tampering without requiring access to source code.
Blue-green deployment is a software release strategy that maintains two identical production environments to enable zero-downtime deployments and instant rollback capability.
Business Email Compromise (BEC) is a cyberattack where criminals impersonate executives, vendors, or colleagues to trick employees into transferring funds or sharing sensitive data.
A Business Impact Analysis (BIA) is a systematic process that evaluates the consequences of disruptions to critical business functions and gathers information needed to develop recovery strategies.
Business Relationship Management (BRM) is a philosophy, capability, discipline, and organizational role focused on building partnerships between strategic business functions (IT, Finance, HR, external providers) and the business units they serve.
A canary release is a deployment strategy that rolls out a new software version to a small subset of users or servers before releasing it to the entire infrastructure, serving as an early warning system for problems.
Capacity management is the ongoing process of planning, monitoring, and optimizing IT resources to meet current and future business demands cost-effectively.
Capacity planning is a strategic process that determines the resources and infrastructure an organization needs to meet current and anticipated future demand.
CCPA / CPRA is California's comprehensive consumer privacy framework consisting of the California Consumer Privacy Act (CCPA, effective January 2020) and the California Privacy Rights Act (CPRA, effective January 2023).
Chain of custody is a documented process that tracks digital evidence through its collection, safeguarding, and analysis lifecycle to ensure legal admissibility and integrity.
Change Management is a structured discipline that guides individuals, teams, and organizations through transitions from a current state to a desired future state.
CIS Critical Security Controls (CIS Controls) are a prescriptive, prioritized set of 18 cybersecurity best practices developed by the Center for Internet Security that organizations implement to defend against the most prevalent cyberattacks.
CJIS is both an FBI division and a compliance standard governing the security and privacy of criminal justice information across the United States.
Client onboarding is the structured process that integrates a new client into a business's systems, workflows, and service delivery model from the moment they sign a contract through the point where they are fully operational and realizing value.
Cloud computing is the on-demand delivery of computing resources over the internet, enabling organizations to access servers, storage, databases, networking, software, and analytics without owning physical infrastructure.
Cloud cost optimization is the practice of reducing cloud infrastructure spending while maintaining or improving application performance and business value.
Cloud governance is a framework of policies, rules, and controls that guides how an organization uses, manages, and secures its cloud environments.
Cloud migration is the process of moving applications, data, workloads, and IT resources from on-premises infrastructure to cloud computing environments provided by AWS, Azure, or Google Cloud.
Cloud orchestration is the process of coordinating multiple automated tasks, tools, APIs, and infrastructure across private, public, hybrid, and multi-cloud environments into unified, end-to-end workflows.
Cloud Security Posture Management (CSPM) continuously monitors cloud infrastructure configurations to identify misconfigurations, compliance violations, and security risks across IaaS, PaaS, and SaaS environments.
Cloud-native is an architectural approach to building applications that exploit cloud computing's distributed scalability, elasticity, and automation.
Co-managed IT is a hybrid model where an MSP partners with an organization's internal IT team rather than replacing it.
Code signing is a cryptographic security process that applies a digital signature to software executables, scripts, firmware, and other code artifacts to verify the publisher's identity and confirm the code has not been tampered with since signing.
Command & Control (C2) is the infrastructure and techniques attackers use to maintain communication with compromised systems after initial exploitation.
Configuration management tools automate the setup, maintenance, and enforcement of consistent system states across IT infrastructure by replacing manual processes with version-controlled, repeatable code.
Continual Service Improvement (CSI) is a systematic, metrics-driven approach to identifying and implementing improvements to IT services, processes, and overall IT service management practices.
Continuous Delivery is a software engineering practice in which teams produce software in short cycles, ensuring code remains in a deployable state and can be released to production at any time on demand.
Continuous Deployment is a software engineering practice that automatically releases every code change to production after it passes all automated pipeline stages, without manual approval or human intervention.
Continuous Integration is a software development practice where developers frequently merge code changes into a shared repository, with each integration automatically triggering builds and automated tests to verify correctness.
CVE (Common Vulnerabilities and Exposures) is a standardized system for identifying, naming, and cataloging publicly known security vulnerabilities in software and hardware.
The Common Vulnerability Scoring System (CVSS) is a standardized framework owned by FIRST (Forum of Incident Response and Security Teams) that rates the severity of software and hardware vulnerabilities on a scale from 0.0 to 10.0.
DAST is a black-box security testing methodology that analyzes running web applications from an external perspective to identify vulnerabilities without requiring access to source code.
Data classification is the process of categorizing data based on sensitivity, value, and regulatory requirements to apply appropriate protection measures.
Data Loss Prevention (DLP) is a security framework that identifies, monitors, and protects sensitive data across three states: data at rest (storage), data in motion (network transmission), and data in use (endpoint actions).
Data masking is a data security technique that creates structurally intact but inauthentic replicas of sensitive data by replacing or obfuscating original values while preserving usability.
Data residency is the physical or geographic location where an organization's data is stored, whether on-premises, in specific regional data centers, or distributed across cloud infrastructure.
Data sovereignty is the principle that data is subject to the laws and governance structures of the country or region where it is generated, stored, or processed.
Deception Technology is a proactive cybersecurity defense mechanism that deploys realistic decoys (fake servers, applications, databases, credentials, and network assets) throughout enterprise infrastructure to lure attackers away from legitimate resources while simultaneously detecting and analyzing their activities.
Defense in Depth is a cybersecurity strategy that deploys multiple layers of security controls throughout an IT system to protect data and network integrity.
DFIR (Digital Forensics and Incident Response) is a cybersecurity discipline that integrates digital forensics and incident response into unified workflows.
Digital Employee Experience (DEX) is the holistic measurement and management of how employees interact with and are supported by an organization's digital workplace technology.
Disaster Recovery as a Service (DRaaS) is a cloud-based solution where third-party providers replicate and host an organization's servers, applications, and data in remote infrastructure, delivering automated failover capabilities to restore operations when disasters strike.
Distributed tracing is a technique that tracks and observes requests as they move through distributed systems and microservices, providing end-to-end visibility into complete transaction paths from frontend devices through backend services and databases.
DKIM is an email authentication method that validates a domain's responsibility for a message by attaching a cryptographic signature to outgoing emails.
DMARC is an email authentication protocol that allows domain owners to specify how receiving mail servers should handle messages failing SPF or DKIM checks.
DNS over HTTPS (DoH) is a protocol that encrypts Domain Name System queries by transmitting them through HTTPS connections over port 443.
DNS over TLS (DoT) is a network security protocol that encrypts Domain Name System queries and responses within Transport Layer Security connections over port 853.
DNSSEC is a suite of cryptographic extensions to the Domain Name System that verifies DNS responses are authentic and unaltered through digital signatures.
Docker is a containerization platform using operating system-level virtualization to deliver software in lightweight, portable packages called containers.
DORA (Digital Operational Resilience Act) is an EU regulation establishing mandatory ICT risk management, incident reporting, resilience testing, and third-party oversight requirements for financial entities across the European Union.
Edge computing is a distributed computing framework that processes data at or near its source (at the network's edge) rather than transmitting all information to centralized datacenters or cloud servers.
Encryption at rest is a cryptographic protection method that converts stored data into unreadable ciphertext, accessible only with decryption keys.
Encryption in transit is a security control that protects data actively moving between locations by transforming it into unreadable ciphertext during transmission across networks.
Endpoint Detection and Response (EDR) is cybersecurity technology that continuously monitors endpoint devices to detect and respond to threats bypassing prevention-based tools.
Endpoint management is the IT and cybersecurity process of authenticating, monitoring, and controlling all devices connected to an organization's network, including laptops, desktops, smartphones, tablets, IoT devices, servers, and printers.
Envoy Sidecar Proxy is an open-source Layer 7 proxy that runs as a companion container alongside application containers in Kubernetes pods to intercept and manage all network traffic transparently.
Event correlation analysis examines relationships between IT events from multiple sources to identify root causes and consolidate alerts into actionable incidents.
Exploit protection encompasses OS-level security mechanisms that prevent memory-based attacks through Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR).
Extended Detection and Response (XDR) is a unified cybersecurity platform that integrates threat detection and response across endpoints, networks, cloud workloads, email, and identity systems.
FedRAMP is a United States government-wide program that standardizes security assessment, authorization, and continuous monitoring for cloud services handling federal data.
FIDO2 and WebAuthn are passwordless authentication standards enabling users to sign in using biometrics, PINs, or security keys instead of passwords.
Financial Management for IT Services, commonly abbreviated ITFM, is the discipline of managing technology spending as a strategic investment rather than a disconnected cost
FinOps is an operational framework and cultural practice that maximizes business value from cloud and technology investments through data-driven decision-making, financial accountability, and cross-functional collaboration between engineering, finance, and business teams.
Flat rate pricing is a billing model that charges a single fixed fee regardless of time spent, materials consumed, or complexity variations.
Full Disk Encryption (FDE) encrypts all data on storage drives using cryptographic algorithms, converting stored information into an unreadable format accessible only with proper authentication keys.
Function as a Service (FaaS) is a cloud computing service model that executes application code as modular functions in response to events without requiring infrastructure management
The General Data Protection Regulation (GDPR) is a European Union privacy law that establishes protections for personal data of individuals in the European Economic Area.
GitOps is an operational framework that uses Git repositories as the single source of truth for declarative infrastructure definitions, with automated processes continuously synchronizing the desired state in Git with the actual state of production environments
The Gramm-Leach-Bliley Act (GLBA) is a federal law enacted in 1999 that requires financial institutions to protect consumers' personal financial information through mandatory privacy disclosures and written information security programs.
Governance, Risk, and Compliance (GRC) is an integrated framework aligning governance policies, risk management, and compliance activities to help organizations achieve objectives while addressing uncertainty.
Grafana is an open-source analytics and visualization platform that connects to time series databases and other data sources, enabling users to build dashboards displaying metrics, logs, and traces.
Hashing is a one-way cryptographic function that converts data of any size into a fixed-length string of characters that cannot be reversed to reveal the original input.
Helm is a package manager for Kubernetes that bundles application configurations into versioned, reusable charts.
Hybrid cloud is a computing environment that combines on-premises infrastructure (or a private cloud) with one or more public cloud services, linking them through a unified management platform that enables applications, data, and workloads to move and operate across both environments.
IAST is an application security testing methodology that identifies vulnerabilities in running web applications by monitoring them from the inside using software sensors.
Identity and Access Management (IAM) is a cybersecurity framework that controls which users and systems can access which resources in an IT environment, and under what conditions.
Immutable infrastructure is a deployment model in which servers, containers, and other compute components are never modified after deployment.
Incident management is a structured IT process that identifies, logs, classifies, investigates, resolves, and reviews unplanned events that disrupt or degrade services.
Incident response (IR) is a structured process that organizations use to detect, contain, eradicate, and recover from cybersecurity breaches and attacks.
Infrastructure as a Service (IaaS) is a cloud computing model that delivers virtualized compute, storage, and networking resources on demand over the internet, eliminating the need to own or maintain physical hardware.
Infrastructure as Code (IaC) is the practice of managing and provisioning cloud infrastructure through machine-readable code rather than manual processes, enabling infrastructure to be versioned, tested, and deployed using the same software engineering practices applied to application code.
ISO/IEC 27001 is an international standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
IT Asset Management (ITAM) is the process of tracking, managing, and optimizing an organization's IT assets throughout their lifecycle, from procurement through deployment, maintenance, and disposal.
IT Operations Management (ITOM) is the discipline that administers an organization's IT infrastructure, applications, and services to keep systems reliable, available, and performing within defined parameters.
IT Service Management (ITSM) is an organizational discipline that governs how IT services are designed, delivered, operated, and continuously improved to meet business objectives.
ITIL is a globally adopted framework of best practices that organizations use to design, deliver, and continually improve IT services in alignment with business goals.
Key Management Service (KMS) is a centralized platform that creates, stores, distributes, rotates, and revokes cryptographic keys used to protect encrypted data across an organization's systems and cloud infrastructure.
Knowledge Management (KM) is the systematic practice of capturing, organizing, sharing, and applying an organization's collective knowledge to improve decision-making and operational performance.
Kubernetes (K8s) is an open-source container orchestration platform that automates the deployment, scaling, and lifecycle management of containerized applications across clusters of physical or virtual machines.
LGPD is Brazil's federal data protection law that governs how organizations collect, process, store, and share the personal data of individuals located in Brazil.
Log management is the process of collecting, storing, analyzing, and disposing of log data from IT systems to support troubleshooting, security, and compliance.
Malware is any software intentionally designed to damage, disrupt, or gain unauthorized access to computer systems, networks, or devices.
Managed Print Services (MPS) is a contract-based program in which an external provider assesses, optimizes, and continuously manages an organization's entire fleet of printers, copiers, and multifunction devices.
Mean Time to Acknowledge (MTTA) is an incident response metric that measures the average time between when a monitoring system generates an alert and when a team member formally acknowledges that alert and begins working on it.
Mean Time to Repair (MTTR) is an incident management metric that measures the average time to restore a failed system or service to full operational status.
The break/fix model is a reactive IT support approach where businesses contact a service provider only when equipment or software fails, paying per incident with no ongoing maintenance contract or monitoring.
Cost of Goods Sold (COGS) is the direct costs a company incurs to produce or purchase the goods it sells during a specific accounting period.
The Cyber Kill Chain is a cybersecurity framework that breaks down a cyberattack into seven sequential stages to help security teams identify and disrupt threats before they achieve their objectives.
The HIPAA Security Rule requires covered entities and business associates to protect electronic protected health information through administrative, physical, and technical safeguards.
The NIS2 Directive (Directive EU 2022/2555) is the European Union's cybersecurity legislative framework establishing mandatory security risk management and incident reporting for approximately 160,000 organizations across 15 critical sectors.
The NIST Cybersecurity Framework (CSF) is a voluntary set of guidelines developed by the U.S.
The Principle of Least Privilege (PoLP) is a security control requiring that every user, account, process, and system receive only the minimum access rights needed to perform its authorized function.
No glossary terms match the selected filters.