Cybersecurity Glossary
Cybersecurity Glossary
A practical reference to common cybersecurity terms, concepts and security language.
Search for a term, browse alphabetically or use the comparisons below to understand concepts that are commonly confused.
Search
Find a security concept quickly.
LOOK IT UPUnderstand
Definitions are written in clear, practical language.
LEARN THE IDEAConnect
See how related cybersecurity concepts differ and overlap.
JOIN THE DOTSThis glossary focuses on cybersecurity concepts and terms. If you need to find what an acronym such as SIEM, SAML, AES, RTO or CASB stands for, visit the dedicated Cybersecurity Abbreviations page.
Search the Glossary
Try words such as encryption, risk, phishing, authentication or zero trust.
Showing 0 terms
Browse AāZ
Security standards, laws, vendors and professional frameworks sometimes define the same term slightly differently.
The definitions on CyberPrepHub are intended as clear learning explanations. Where a formal definition matters, consult the relevant standard, regulation or authoritative source.
Commonly confused cybersecurity terms
Proves or verifies WHO you are.
Determines WHAT you are allowed to do.
Something capable of causing harm.
A weakness that could be exploited.
The potential consequence when threats can exploit vulnerabilities.
Reversible protection using appropriate cryptographic keys.
Produces a one-way digest and is not intended to be decrypted.
Detects suspicious activity and normally alerts.
Detects suspicious activity and can actively block it.
How much DATA LOSS can be tolerated?
How much DOWNTIME can be tolerated?
Five security concepts worth remembering
Threat ā Vulnerability ā Risk ā Control ā Residual Risk
A
The policies, processes and technical mechanisms used to determine who or what is allowed to access a resource and what actions they are permitted to perform.
A person, group, organisation or other entity attempting to compromise, disrupt, misuse or otherwise act against the security objectives of a target.
Separation of a system or network from other networks, particularly untrusted environments such as the internet.
An air gap can substantially reduce connectivity-based exposure but should not be treated as absolute protection against every attack.
A security approach in which only explicitly approved applications, connections, actions or entities are permitted.
Everything not specifically permitted is denied by default.
Processing information so that it can no longer reasonably be linked to an identifiable individual.
The exact legal threshold for anonymisation can vary between privacy frameworks.
Anything of value to an organisation that should be appropriately protected or managed.
Assets can include hardware, software, information, services, people, intellectual property and reputation.
The collection of points through which an attacker could attempt to enter, influence, extract data from or otherwise interact with a system.
Examples include network services, APIs, user accounts, applications, devices and human processes.
The method or path an attacker uses to reach or compromise a target.
Phishing emails, vulnerable web applications and exposed remote-access services are examples of attack vectors.
The process of verifying that a claimed identity is genuine.
Passwords, cryptographic credentials, biometrics and security keys can all form part of authentication.
Memory: Authentication = Who are you?
The process of determining what an authenticated user, service or other entity is permitted to access or perform.
Memory: Authorisation = What are you allowed to do?
The security objective of ensuring information, systems and services are accessible to authorised users when they are required.
Availability is one of the three elements of the CIA Triad.
B
A hidden or alternative method of accessing a system that bypasses normal authentication or security controls.
Backdoors may be deliberately created for malicious purposes or unintentionally introduced through insecure design.
An approved starting point used for comparison or control.
A security baseline may define the minimum configuration or safeguards expected for a particular type of system.
A deliberately hardened system positioned where it may be exposed to untrusted networks or used as a controlled access point to sensitive environments.
A privileged-access jump server is a common example.
Authentication or identification techniques that use measurable physical or behavioural characteristics.
Examples include fingerprints, facial characteristics, iris patterns and voice characteristics.
A collection of compromised systems or devices controlled together, usually without the legitimate owners' knowledge.
Botnets can be used for activities such as distributed denial-of-service attacks, spam, credential attacks and malware distribution.
An attack that repeatedly tries possible passwords, keys or other values until the correct one is discovered.
Rate limiting, strong authentication and multifactor authentication can help reduce the effectiveness of password brute forcing.
C
A digitally signed electronic record used to associate information such as an identity or system name with a public cryptographic key.
Digital certificates are an important component of Public Key Infrastructure.
The documented history of who collected, handled, transferred, stored and controlled evidence from the point it was acquired onwards.
A reliable chain of custody helps demonstrate that evidence has been appropriately protected from alteration or substitution.
A cryptographic algorithm used to transform information between readable and protected forms.
Modern ciphers normally operate together with cryptographic keys.
The policies, controls, technologies and responsibilities used to protect data, identities, workloads and services operating in cloud environments.
An alternative safeguard used when the preferred or required control cannot be implemented as originally intended.
The alternative should address the relevant security objective and reduce the associated risk appropriately.
The security objective of preventing information from being disclosed to unauthorised people, systems or processes.
Confidentiality is one of the three elements of the CIA Triad.
The controlled process of establishing, documenting, maintaining and changing the configuration of systems and technology.
Good configuration management helps prevent unauthorised or accidental changes from creating security weaknesses.
Information or evidence used to support an identity or authentication process.
Passwords, certificates, security tokens and cryptographic keys can all function as credentials in different systems.
The use of mathematical techniques to protect information and communications.
Cryptography can support confidentiality, integrity, authentication and non-repudiation.
The discipline concerned with protecting digital systems, networks, services and information against threats, attacks, misuse and disruption.
D
The process of assigning information to categories based on factors such as sensitivity, value, criticality or required protection.
Classification helps determine appropriate handling and security controls.
The unauthorised transfer or removal of information from an organisation, system or controlled environment.
Exfiltration may occur over networks, cloud services, email, removable media or other channels.
Technologies and processes designed to identify sensitive information and detect or prevent inappropriate storage, use or movement of that information.
DLP can operate across data at rest, in transit and in use.
The principle of limiting the collection, processing and retention of information to what is genuinely required for the intended purpose.
Less unnecessary data generally means less unnecessary exposure.
Residual information that remains on storage media after an attempt has been made to delete or remove it.
This is why ordinary file deletion should not automatically be treated as secure data destruction.
A security strategy that uses multiple layers of safeguards so that the failure of one control does not automatically result in complete compromise.
It is also commonly written as Defense in Depth.
A cryptographic mechanism used to provide evidence about the origin and integrity of digital information.
Digital signatures typically use asymmetric cryptography.
The processes and capabilities used to restore technology, systems and supporting services following a serious disruption or disaster.
Disaster recovery is usually a component of the wider business continuity programme.
Taking reasonable and appropriate actions to protect assets, people and the organisation against recognised risks.
Think: doing what a responsible organisation should do.
The ongoing investigation, assessment and monitoring used to understand risk and confirm that appropriate protective measures continue to be effective.
Think: checking that due care remains appropriate.
E
A device or system that connects to and communicates across a network.
Laptops, desktops, smartphones and servers can all be considered endpoints depending on context.
The cryptographic transformation of readable information into a protected form that should be unintelligible without appropriate cryptographic key material.
Encryption primarily supports confidentiality.
Code, a technique or a sequence of actions that takes advantage of a vulnerability to produce an unintended result.
A condition in which an asset is reachable or subject to circumstances that could result in compromise, loss or other adverse impact.
Exposure does not necessarily mean a vulnerability has already been exploited.
F
The process of switching operations from a failed or unavailable system to an alternative system or component.
Failover can support resilience and availability.
An identity arrangement in which separate organisations, systems or security domains establish trust so that identity information can be accepted across boundaries.
A security control that permits, blocks or otherwise manages network traffic according to defined rules and security policy.
Firewalls may operate at different layers and can be deployed on networks, individual hosts or cloud environments.
The disciplined collection, preservation, examination and analysis of evidence for investigation.
Digital forensics focuses specifically on evidence associated with digital devices, systems and data.
G
The structures, responsibilities, policies and decision-making processes used to direct and oversee an organisation.
Security governance helps ensure cybersecurity supports organisational objectives and that appropriate accountability exists.
H
The process of reducing a system's attack surface and improving its security configuration.
Hardening may include removing unnecessary software, disabling unused services, changing insecure defaults and applying appropriate security settings.
A one-way mathematical process that transforms input data into a fixed-size output commonly called a hash or digest.
Hashing is commonly used for integrity checking and as part of secure password-storage designs.
Important: hashing is not encryption and is not intended to be decrypted.
A deliberately created decoy system, service or resource designed to attract or detect attackers and help defenders observe malicious activity.
I
The act of claiming or presenting an identity to a system.
Entering a username identifies the account being claimed; authentication then attempts to verify that claim.
The collection of attributes or characteristics used to represent a person, device, service or other entity within a system.
An event or series of events that compromises, threatens or violates security policies, systems, information or business operations.
The organised process used to prepare for, detect, analyse, contain, eradicate and recover from cybersecurity incidents.
Mature incident response also includes learning from incidents and improving controls afterwards.
Observable information that may indicate that malicious activity or a security compromise has occurred.
Examples can include malicious file hashes, network addresses, unusual process activity or attacker-created artefacts.
The security objective of protecting information and systems against unauthorised or improper modification or destruction.
Integrity also supports confidence that information remains accurate and trustworthy.
A security system that monitors activity for signs of attacks, suspicious behaviour or policy violations and generates alerts when relevant activity is detected.
Memory: IDS = Detect and alert.
A security system capable of detecting suspicious activity and taking action to prevent or block it.
Memory: IPS = Detect and prevent.
K
The processes used to securely generate, distribute, store, protect, rotate, recover, revoke and destroy cryptographic keys.
Strong encryption can be undermined by poor key management.
L
The principle that users, applications and processes should receive only the permissions necessary to perform their authorised functions.
Permissions should not be granted merely because they may be convenient.
Recording events and activity generated by systems, applications, networks or security controls.
Logs can support monitoring, troubleshooting, investigations, accountability and auditing.
Malicious code designed to execute when a specific condition or event occurs.
The trigger might be a date, account deletion, file change or another system condition.
M
Software or code created to perform malicious or unauthorised actions.
Malware includes categories such as ransomware, trojans, worms, spyware and malicious remote-access tools.
An attack in which an adversary positions themselves between communicating parties so they can intercept and potentially modify communications.
It is commonly abbreviated as MitM.
Fine-grained segmentation that creates smaller security boundaries around workloads, applications or resources.
It can help restrict lateral movement and unnecessary communication within an environment.
Authentication using two or more independent categories of authentication factors.
Common factor categories are something you know, something you have and something you are.
Two passwords are not multifactor authentication because both belong to the same factor category.
N
Dividing a network into separate zones or segments and controlling communication between them.
Segmentation can limit exposure, reduce lateral movement and help apply different security controls to different environments.
The ability to provide evidence supporting the origin or occurrence of an action so that the responsible party cannot credibly deny it later.
Digital signatures can contribute to non-repudiation.
A value intended for one-time or unique use within a cryptographic or security protocol.
Nonces can help prevent replay of previously valid messages or transactions.
O
Deliberately making code, data or behaviour harder for people or tools to understand.
Obfuscation can hinder analysis but should not be confused with cryptographic protection such as encryption.
P
A modern authentication credential based on public-key cryptography that can replace traditional passwords for supported services.
The user normally proves access to the passkey through a trusted device using a mechanism such as a device PIN or biometric unlock.
The process of identifying, evaluating, testing, deploying and tracking software or firmware updates used to correct defects and security vulnerabilities.
An authorised security assessment in which testers attempt to identify and exploit weaknesses to demonstrate how an attacker might compromise systems or information.
Penetration testing should operate within an agreed scope and rules of engagement.
A social-engineering attack that uses deceptive messages or websites to persuade victims to disclose information, execute malicious actions or provide access.
Phishing commonly uses email but can also occur through messaging, websites and other communication channels.
Gaining permissions greater than those originally available to an account, process or attacker.
An attacker moving from a normal user account to administrator or root privileges is a common example.
The people, policies, technologies and processes used to create, manage, distribute, validate and revoke digital certificates and associated cryptographic keys.
It is commonly abbreviated as PKI.
R
Malware used to deny access to systems or information and demand payment or another action from the victim.
Modern ransomware operations may also steal information and threaten publication in addition to encrypting systems.
The maximum acceptable amount of data loss measured in time following a disruption.
Memory: RPO = how far back can the data go?
The target maximum period within which a system, service or business activity should be restored following disruption.
Memory: RTO = how long can we be down?
The risk that remains after security controls or other risk treatments have been applied.
Security rarely reduces every risk to zero.
The potential for an uncertain event or condition to negatively affect objectives, assets or operations.
Cybersecurity risk is often considered using factors such as likelihood, threat, vulnerability and potential impact.
The broad amount and type of risk an organisation is willing to pursue or retain in support of its objectives.
Risk appetite should be determined by appropriate organisational leadership rather than individual technical teams.
The structured process of identifying and analysing risk so that organisations can understand potential threats, vulnerabilities, likelihoods and consequences.
The action chosen to address an identified risk.
Common approaches include reducing or mitigating the risk, avoiding it, transferring or sharing it, and accepting it where appropriate.
A structured investigation intended to identify the underlying causes of a problem or incident rather than focusing only on its immediate symptoms.
Effective root-cause analysis can help prevent recurrence.
S
A unique or suitably random value combined with data before hashing.
In password storage, salts help ensure identical passwords do not automatically produce identical stored hashes and make large-scale precomputed attacks less effective.
A process intended to make access to data on media infeasible to the level required by the selected sanitisation method.
Depending on requirements and media technology, approaches can include Clear, Purge or Destroy.
The structured design of security principles, components, controls and relationships within systems and technology environments.
Good security architecture attempts to build appropriate protection into the design rather than adding security only after deployment.
A safeguard or countermeasure intended to reduce security risk or help achieve a security objective.
Controls may be administrative, technical or physical and may perform preventive, detective, corrective or other functions.
A high-level statement of management direction and expectations for security within an organisation.
Policies generally define what is required rather than every technical detail of how it must be implemented.
Dividing critical responsibilities between multiple people or roles so that one individual does not control every stage of a sensitive activity.
It can reduce fraud, abuse and accidental misuse.
A temporary logical interaction established between a user or system and a service, often after successful authentication.
Session identifiers and tokens therefore require appropriate protection.
Manipulating people into performing actions or revealing information that benefits an attacker.
Social engineering exploits human trust, urgency, fear, authority, curiosity and other behavioural factors rather than relying purely on technical vulnerabilities.
Falsifying identity or technical information so that malicious activity appears to originate from a trusted or different source.
Examples include email spoofing, IP spoofing and caller-ID spoofing.
An attack that compromises a target through a supplier, software dependency, service provider, update mechanism or another component of its supply chain.
Attackers may target a trusted provider because compromising one supplier can create access to many downstream organisations.
T
A circumstance, event or entity capable of causing harm to systems, information, people or organisational objectives.
A threat does not need to have successfully exploited anything yet.
A person, group or organisation responsible for or capable of carrying out malicious cyber activity.
Threat actors can include criminals, insiders, hacktivists, state-sponsored groups and other adversaries.
Analysed information about threats, adversaries and malicious activity intended to support security decisions.
Useful threat intelligence should provide context rather than simply presenting disconnected indicators.
A structured process for identifying potential threats, attack paths, security weaknesses and required controls during the design or review of a system.
The goal is to think about how a system might be attacked before those attacks become real incidents.
Replacing sensitive information with a substitute value or token so that systems which do not need the original information can operate without directly storing it.
Tokenisation is commonly used to reduce unnecessary exposure of sensitive data.
Malware that disguises itself as legitimate or desirable software in order to persuade a user or system to execute it.
Unlike a worm, a trojan is not defined by automatically self-propagating between systems.
V
A weakness or flaw in technology, configuration, design, process or behaviour that could be exploited or otherwise contribute to a security compromise.
Memory: Threat = potential danger. Vulnerability = weakness.
The ongoing process of identifying, assessing, prioritising, remediating and tracking vulnerabilities across an organisation's assets.
Vulnerability management is a lifecycle process rather than simply running a vulnerability scanner.
W
An attack in which an adversary compromises or imitates a website or online resource that members of the intended target group are likely to visit.
The attacker waits for victims to come to the compromised location rather than contacting each victim directly.
A targeted form of phishing aimed at senior executives, high-value decision makers or other prominent individuals.
Whaling attacks often use carefully researched business scenarios to make the request appear credible.
Malware capable of propagating between systems or across networks, often without requiring the user to manually copy or execute it on every new target.
Worm functionality can allow malware to spread rapidly through vulnerable environments.
Z
A vulnerability for which an effective fix may not yet be available to defenders at the time it becomes known or is exploited.
A zero-day exploit is an exploit used against such a vulnerability.
A security approach that avoids granting implicit trust simply because a user or system is inside a particular network or organisational boundary.
Access decisions instead consider factors such as identity, device, resource, policy, context and risk.
It means trust should not be assumed solely from network location or previous access.
How important security terms fit together
Identity
Risk
Cryptography
Operations
Attack
Resilience
š§ How to learn cybersecurity terminology Don't try to memorise isolated dictionary definitions
Cybersecurity terminology becomes much easier to remember when concepts are connected rather than memorised independently.
Key takeaways
Cybersecurity terminology is easier to understand when related concepts are learned together rather than memorised as isolated definitions.
Authentication verifies identity; authorisation determines permissions.
A threat is a potential source of harm, while a vulnerability is a weakness.
Risk describes the potential adverse consequence created by uncertainty, threats, vulnerabilities and impact.
Security controls reduce risk, but some residual risk normally remains.
Encryption and hashing are not interchangeable: encryption is designed to be reversible with appropriate key material, while hashing is designed as a one-way transformation.
Least privilege limits users and systems to the access they actually require.
Defence in depth uses multiple security layers rather than relying on a single safeguard.
Vulnerability management is an ongoing lifecycle, not simply the act of running a scanner.
Incident response extends beyond detection and should include containment, recovery and organisational learning.
Most importantly: understanding what a security term means is useful ā understanding how it connects to other security concepts is better.
š Sources & Further Reading Authoritative security terminology resources
CyberPrepHub definitions are written as concise learning explanations rather than copied dictionary definitions. Formal terminology should be interpreted in the context of the relevant standard or publication.
- NIST Computer Security Resource Center ā Glossary
Browse the NIST cybersecurity glossary - NIST IR 7298 Rev. 3 ā Glossary of Key Information Security Terms
View the NIST publication - OWASP ā Security Terminology Cheat Sheet
View OWASP security terminology guidance - MITRE ATT&CK
Explore MITRE ATT&CK terminology and adversary behaviour
