Glossary
Welcome to the Glossary! Whether you're already familiar with some of these terms or you're just becoming acquainted, our top-level glossary is a great resource for learning all of the relevant goods. Scroll through the full list below, search by term, or select by individual letter.
Password Cracking
Also referred to as Password Hacking; The process in which bad actors go through to hack, or get into computer systems illegally, in order to steal, corrupt, or illegitimately view personal data; in this case, by cracking passwords.
Paste Site
A website, used most often by multiple code developers, designed to allow the uploading and sharing of files, scripts, and code snippets.
Payment Card Industry Data Security Standard (PCI DSS, PCI)
The comprehensive set of requirements designed to ensure that any company that processes, stores, or transmits credit card information does so by maintaining a secure environment. The requirements were established to help prevent payment data breaches and payment card fraud.
PCI Security Standards Council (PCI SSC)
PCI Security Standards Council (PCI SSC), made up of major payment companies, including Visa, MasterCard, American Express, Discover, and JCB, administers and manages the PCI DSS standard. However, enforcing the compliance of PCI DSS is the responsibility of the individual payment brands.
penetration testing
Also called pen testing. An attempt to evaluate the security of an IT infrastructure by safely trying to exploit vulnerabilities. Fortra’s Core Security Core Impact, Cobalt Strike, and IBM i product lines deliver pen testing solutions.
personally identifiable information (PII)
Data that directly or indirectly identifies a specific individual, such as names, addresses, biometrics, and alphanumeric account numbers.
Phishing
A fraudulent attempt to obtain sensitive data such as usernames, passwords, and credit card details by disguising as a trustworthy entity through digital communications.
Phishing Simulation
This is a cybersecurity exercise that simulates a phishing attack for employees or users and tests to see if they can recognize and respond to it appropriately.
Phishing Website
A hoax website built to mimic reputable brands with the intention of misleading readers into giving up personal data such as usernames, passwords and financial information.
platform as a service (PaaS)
A form of cloud computing in which a provider delivers hardware and software tools on its own infrastructure to users over the internet.
Post-delivery
This is when emails bypass legacy security defenses and don't get scanned or detected until AFTER they have delivered to an exchange server, often leading to inbox delivery.
Pre-delivery
This describes when emails are scanned and detected BEFORE they get to the network exchange, which minimizes the time they are open to vulnerabilities and decreases cyber risk.
Pretty Good Privacy (PGP)
An encryption program that provides cryptographic privacy and authentication for data communication. See also Open PGP.
privileged access management (PAM)
Giving users only the access they need and ensuring that least privileged access is enforced. Fortra’s Core Privileged Access Manager (BoKS) product delivers privileged access management solutions.
purple teaming
A collaborative security practice that integrates the offensive capabilities of an organization's Red Team with the defensive capabilities of its Blue Team to ensure continuous improvement and validate security controls.