Security Glossary
Plain-English definitions of the 50 terms a CISO, an engineering lead, or an auditor is most likely to ask AxVeil to explain. Every entry says why the concept matters and how it is tested or exploited, then links into the relevant service and research pages where we have written the deeper material.
A
ASVS Level 2
Application securityThe middle verification tier of OWASP ASVS — the de-facto industry bar for any application handling business or personal data.
Attack Surface Management
Offensive testingContinuous discovery and monitoring of every internet-exposed asset an organisation owns, including assets the security team did not know about.
B
C
CIS Benchmarks
Compliance & frameworksConsensus-developed security configuration baselines for operating systems, cloud platforms, network devices and applications.
CISA KEV
Vulnerability managementCISA's Known Exploited Vulnerabilities catalog — the authoritative list of CVEs confirmed exploited in the wild, with binding remediation timelines for US federal agencies.
CPE
Vulnerability managementCommon Platform Enumeration — the structured naming scheme that uniquely identifies a hardware or software product for vulnerability matching.
CSAF
Vulnerability managementCommon Security Advisory Framework — OASIS-standard JSON format for machine-readable vendor vulnerability advisories.
CTI
Threat intelligenceCyber Threat Intelligence — collection, analysis and dissemination of information about adversaries, their tools and their behaviour.
CVE
Vulnerability managementCommon Vulnerabilities and Exposures — the globally unique identifier system for publicly disclosed security vulnerabilities.
CVSS
Vulnerability managementCommon Vulnerability Scoring System — a numeric framework (0.0–10.0) for rating the severity of a vulnerability.
CWE
Vulnerability managementCommon Weakness Enumeration — the taxonomy that classifies the underlying programming-error category that gives rise to vulnerabilities.
D
DAST
Application securityDynamic Application Security Testing — exercises a running application from the outside, like a black-box attacker.
Detection Engineering
Defensive operationsThe discipline of writing, testing and maintaining security detections as code with the same rigour as application code.
DevSecOps
Application securityOperating model where security is a shared responsibility of development, security and operations teams, automated into the delivery pipeline.
E
EDR
Defensive operationsEndpoint Detection and Response — agent-based platform that records endpoint telemetry and supports investigation and response.
EPSS
Vulnerability managementExploit Prediction Scoring System — a daily-updated probability score (0-100%) estimating how likely a CVE is to be exploited in the next 30 days.
G
H
I
IAM
Defensive operationsIdentity and Access Management — the system of record for who can do what to which resources, under what conditions.
IAST
Application securityInteractive Application Security Testing — instruments the running application from inside, combining SAST visibility with DAST realism.
IOC
Threat intelligenceIndicator of Compromise — observable artefact (hash, IP, domain, registry key) that suggests a system has been breached.
ISO 27001
Compliance & frameworksInternational standard for an Information Security Management System (ISMS), certifiable by accredited bodies.
M
MITRE ATT&CK
Threat intelligenceGlobally adopted knowledge base of real-world adversary tactics, techniques and procedures, organised as a matrix.
MITRE D3FEND
Defensive operationsMITRE's defensive-technique knowledge graph that complements ATT&CK by enumerating concrete countermeasures and their relationships.
N
O
OWASP ASVS
Application securityApplication Security Verification Standard — a 280-control catalogue OWASP publishes as the canonical checklist for verifying web application security.
OWASP Top 10
Application securityConsensus list of the ten most critical web application security risks, refreshed every three to four years.
P
R
S
SAST
Application securityStatic Application Security Testing — analyses source code or compiled binaries without executing them.
SBOM
Vulnerability managementSoftware Bill of Materials — a machine-readable manifest of every component (and version) that makes up a software product.
Shift Left
Application securityMoving security activities earlier in the software development lifecycle so defects are caught when fixing them is cheap.
Shift Right
Application securityExtending security activities into production — runtime protection, observability and feedback loops that complement shift-left controls.
SIEM
Defensive operationsSecurity Information and Event Management — centralised log collection, correlation and alerting platform.
SOAR
Defensive operationsSecurity Orchestration, Automation and Response — codified playbooks that respond to alerts at machine speed.
SOC 2
Compliance & frameworksAICPA attestation report (Type 1 or Type 2) evaluating a service organisation's controls against the Trust Services Criteria.
SSDLC
Application securitySecure Software Development Life Cycle — the systematic integration of security activities into every phase of software delivery.
Supply Chain Security
Application securityEnd-to-end protection of the software production pipeline — source, build, dependencies, artefacts and delivery — against tampering and compromise.
T
Tabletop Exercise
Defensive operationsDiscussion-based simulation of a security incident, walking stakeholders through their response in a no-pressure setting.
Threat Hunting
Defensive operationsProactive, hypothesis-driven search through telemetry for adversary activity that automated detections did not catch.
Threat Modeling
Application securityStructured analysis of what could go wrong in a system, performed early so design changes are still cheap.
TTPs
Threat intelligenceTactics, Techniques and Procedures — the behavioural signatures that describe how an adversary operates.
U
V
VAPT
Offensive testingVulnerability Assessment and Penetration Testing — automated discovery layered with manual exploitation against an in-scope asset.
VEX Document
Vulnerability managementVulnerability Exploitability eXchange — a machine-readable statement of whether a known CVE is actually exploitable in a given product.
X
Z
Need this applied to your environment?
Definitions are the easy part. Scoping a VAPT, a red team engagement, or a compliance programme against your real architecture is what AxVeil does. Send the asset list, the target framework and the audit deadline.
Request a scoping call →