Glossary
Welcome to the Glossary! Whether you're already familiar with some of these terms or you're just becoming acquainted, our top-level glossary is a great resource for learning all of the relevant goods. Scroll through the full list below, search by term, or select by individual letter.
Post-delivery
This is when emails bypass legacy security defenses and don't get scanned or detected until AFTER they have delivered to an exchange server, often leading to inbox delivery.
Pre-delivery
This describes when emails are scanned and detected BEFORE they get to the network exchange, which minimizes the time they are open to vulnerabilities and decreases cyber risk.
Pretty Good Privacy (PGP)
An encryption program that provides cryptographic privacy and authentication for data communication. See also Open PGP.
privileged access management (PAM)
Giving users only the access they need and ensuring that least privileged access is enforced. Fortra’s Core Privileged Access Manager (BoKS) product delivers privileged access management solutions.
purple teaming
A collaborative security practice that integrates the offensive capabilities of an organization's Red Team with the defensive capabilities of its Blue Team to ensure continuous improvement and validate security controls.
QR Code Phishing
Also called Quishing; A newer form of phishing attack that features a hyperlink embedded in a QR code that brings the user to a fraudulent or malicious website that when logged into, is used for credential harvesting.
ransomware
A type of malware that locks users and system administrators out of computers, files, and networks until a ransom is paid. Ransomware can be unknowingly downloaded and launched when users click on email or website links.
ransomware as a service (RaaS)
A business model where threat actors can purchase pre-packaged ransomware kits to launch on their targets without needing the expertise to develop the code themselves.
rapid penetration test (RPT)
Automation that enables admins to discover, test, and report on vulnerabilities easily.
Sandbox
This type of environment is a safe space in which executable content that enters an organization via email, such as ransomware or phishing attacks, can be deployed or executed in isolation, without affecting the network server or any of its applications.
sanitization
Permanent removal of sensitive data from a document, image or dataset, including any hidden fields. Also known as document sanitization or data sanitization.
Sarbanes-Oxley (SOX)
A United States federal law that addresses financial recordkeeping and reporting. It requires that any publicly traded American or overseas company registered with the Securities and Exchange Commission (SEC) demonstrate strong and transparent internal control over their financial reporting (ICFR). Companies that provide financial services to such firms also fall under SOX compliance obligation. In addition, top executives ultimately are held responsible for the accuracy of the financial data of their organization, under SOX.
Secure Email Gateway (SEG)
An on-premise email security solution that monitors emails coming into and out of an organization before they reach an email inbox.
secure file transfer (SFT)
Secure file transfer is a data sharing method that uses secure protocols and encryption to safeguard data in transit and at rest.
secure file transfer protocol (Secure FTP)
A secure version of FTP, which facilitates data access and transfer over a Secure Shell (SSH) data stream. What is Enterprise SFTP Software?
secure mail transfer protocol/secure (SMTPs)
A more secure version of SMTP, this is a protocol for sending email messages between servers using TLS, or Transport Layer Security, and formerly SSL.
secure shell file transfer protocol (SFTP)
A network protocol that organizations can use to secure and send file transfers over SSH (Secure Shell).
security awareness training
Technology that implements educational programs designed to inform employees about cybersecurity threats, company policies, and best practices to better prepare them to recognize and avoid risks like phishing and social engineering.
security configuration management (SCM)
The management and control of configurations for an information system to enable security and facilitate the management of risk.
security information and event management (SIEM)
Software that gives organizations helpful insights into potential security threats across critical business networks. This is possible via centralized collection and analysis of normalized security data pulled from a variety of systems, including antivirus applications, firewalls, and intrusion prevention solutions. Fortra’s Core Security and Powertech product lines deliver SIEM solutions.
security operations center (SOC)
A security operations center is a strategic command center facility for fighting cyberattacks through monitoring, threat analysis, and more. SOC analysts perform around-the-clock monitoring of an organization's network and investigate any potential security incidents.
Sender Policy Framework (SPF)
SPF is an email authentication protocol that domain owners use to specify the email servers they send email from, making it harder for fraudsters to spoof sender information
SEO Poisoning
A practice by threat actors to bend search engine results pages (SERPs) to their malicious websites for cyberattack tactics.
shadow IT
When a company’s employees use hardware or software, particularly SaaS applications, on the corporate network without the knowledge of the IT team. This puts the organization at risk.
Simple Mail Transfer Protocol (SMTP)
SMTP is a standard communication protocol for transmitting emails over the Internet.
single pane of glass (SPOG)
Single pane of glass is a term used throughout the IT and management fields relating to a management tool that unifies data or interfaces across several different sources and presents them in a single view.
SMS Phishing
Also called Smishing; A newer form of phishing attack, or business email compromise, initiated with an email sent to a prospective victim written to elicit a response with the recipient's cell phone number so the scammer can access their cell phone and applications.
Social Engineering
These types of advanced attacks rely on human interaction presented in a personal and business context in order to establish trust and convince the recipient to take action.
Social Media Gripe Site
A website or platform designed for users to post negative complaints, criticism, and feedback targeting specific individuals, organizations, products, or services.
Social Media Spoofing
Also known as a “fake social media profile,” social media spoofing is the practice of creating or using a fabricated social media account to impersonate someone else or mislead people online.
software as a service (SaaS)
A software distribution model in which software is licensed on a subscription basis and is centrally hosted. It is a form of cloud computing that gives users access to software that runs on a shared resource online.
Source Code Leak
An exposure of source code data or snippets including operating system or application code.
Spam
A broad category of unsolicited commercial bulk email sent out vast recipient lists; often referred to as junk email.
spear phishing
A cybercrime that uses emails to carry out targeted attacks against individuals and businesses.
Pagination
- Previous page
- Page 6
- Next page