Glossary
static application security testing (SAST)
Static application security testing is used to secure software by reviewing the source code of the software to identify sources of vulnerabilities.
supervisory control and data acquisition (SCADA)
A system used in manufacturing for acquiring measurements of process variables and machine states, and for performing regulatory or machine control across a process area or work cell.
Takedown API
A mechanism of digital threat mitigation that enables organizations to automate the process of submitting and managing site and post takedown requests that have infringed their copyrighted content or intellectual property.
threat intelligence (TI)
The analysis of data using tools and techniques to generate meaningful information about existing or emerging threats targeting the organization that helps mitigate risks.
Threat Mitigation
Assessing vulnerabilities to create proactive threat prevention measures and an ongoing threat detection strategy.
threat vulnerability management (TVM)
The cyclical practice of identifying, assessing, classifying, remediating, and mitigating security weaknesses together with fully understanding root cause analysis to address potential flaws in policy, process and, standards – such as configuration standards.
Top-level Domain (TLD)
The first stop after the root zone of a domain in the DNS hierarchy, or everything following the final dot in the domain name. Common examples include ‘.com’, ‘.org’, ‘.gov’, and country codes like '.uk'.
transport layer security (TLS)
A cryptographic protocol that provides end-to-end communications security over networks and is widely used for internet communications and online transactions.
Typosquatting
Typosquatting is a form of cybersquatting that relies on typos made by users typing a particular URL, leading them to a fraudulent website. Also known as URL hijacking, a sting site, or fake URL, threat actors intentionally register misspelled or similar-sounding URLs to lure victims.
unified threat management (UTM)
An approach to information security where a single hardware or software installation provides multiple security functions. This contrasts with the traditional method of having point solutions for each security function.
URL Rewriting
The precautionary measure of rewriting and replacing URL addresses so that security teams can perform a preliminary scan to make sure there is no malicious content embedded before the user launches or visits it.
vishing, voice phishing
The use of manipulative, phone-based tactics to get victims to reveal private information that can be used for digital theft.
vulnerability assessment (VA)
A rapid automated review of network devices, servers and systems to identify key vulnerabilities and configuration issues that an attacker may be able to take advantage of.
vulnerability assessment and penetration test (VAPT)
A security testing to identify security vulnerabilities in an application, network, endpoint, and cloud. Vulnerability Assessment scans the digital assets and notifies organizations about pre-existing flaws. Penetration test exploits the vulnerabilities in the system & determines the security gaps.
Vulnerability Management (VM)
The process of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and the software that runs on them.
web application firewall (WAF)
A specific form of application firewall that filters, monitors, and blocks HTTP traffic to and from a web service. By inspecting HTTP traffic, it can prevent attacks exploiting a web application's known vulnerabilities.
Whale Phishing
workload automation (WLA)
Solutions designed to maintain service levels across a diverse mix of platforms and applications with unified job scheduling and workload automation. Products from Fortra’s JAMS and Automate product lines provide WLA solutions.
zero trust
A security concept centered on the belief that organizations should not automatically trust anything inside or outside their perimeters and instead must verify anything and everything trying to connect to systems before granting access.
zero-day attack, zero-day exploit
An attack that exploits a previously unknown hardware, firmware, or software vulnerability.
Zone File
A Domain Name System (DNS) zone file is a plain text file that describes a DNS zone, containing all the resource records for the domains within that zone.
Pagination
- Previous page
- Page 7