Cybersecurity & Compliance
Application and enterprise security, from vulnerability classes and security testing to detection, response, identity and cryptography, plus the compliance frameworks that govern information security.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
62 terms
- API SecurityThe practices and controls that protect application programming interfaces from abuse, covering authentication, authorisation, input…
- Broken Access ControlA class of vulnerabilities in which an application fails to enforce what users are allowed to do, letting them view or change data or…
- Common Vulnerabilities and Exposures (CVE)A programme that assigns unique identifiers, such as CVE-2021-44228, to publicly disclosed cybersecurity vulnerabilities, so that vendors…
- Common Vulnerability Scoring System (CVSS)An open framework maintained by FIRST for rating the severity of software vulnerabilities on a scale from 0.0 to 10.0, based on how a…
- Compliance Gap AnalysisAn assessment that compares an organisation's current policies, processes and controls with the requirements of a chosen standard or…
- Content Security Policy (CSP)A browser security mechanism, delivered as an HTTP response header, that declares which sources of scripts, styles, images, frames and…
- Cookie Security AttributesAttributes set on HTTP cookies, chiefly Secure, HttpOnly and SameSite, that control when browsers send cookies and whether scripts can…
- Cross-Origin Resource Sharing (CORS)A browser mechanism that lets a server declare, through HTTP headers, which other origins may read its responses, relaxing the same-origin…
- Cross-Site Request Forgery (CSRF)An attack that tricks a logged-in user's browser into sending an unwanted, state-changing request to a web application, which accepts it…
- Cross-Site Scripting (XSS)A web vulnerability that lets an attacker inject malicious script into pages viewed by other users, so that the script runs in the…
- Cryptographic Key ManagementThe policies, processes and systems for generating, storing, distributing, using, rotating, backing up and destroying cryptographic keys…
- Cyber Resilience Act (CRA)Regulation (EU) 2024/2847, which sets mandatory cybersecurity requirements for hardware and software products with digital elements placed…
- Digital Personal Data Protection Act, 2023 (DPDP Act)India's law on the processing of digital personal data, which sets obligations for organisations that decide how personal data is…
- Distributed Denial of Service (DDoS)An attack that uses many compromised or rented systems to flood a target with traffic or requests, exhausting bandwidth, server resources…
- Dynamic Application Security Testing (DAST)A black-box testing method that examines a running application from the outside, sending crafted requests and analysing responses to find…
- Encryption at Rest and in TransitThe use of cryptography to protect data both while it is stored on disks, in databases and in backups, and while it moves across networks…
- Endpoint Detection and Response (EDR)Security software that continuously records activity on endpoints such as laptops and servers, detects suspicious behaviour and enables…
- EU Artificial Intelligence Act (AI Act)Regulation (EU) 2024/1689, the European Union's risk-based legal framework for artificial intelligence, which bans certain AI practices…
- Extended Detection and Response (XDR)An approach that unifies threat detection, investigation and response across several security layers, such as endpoints, email, identity…
- General Data Protection Regulation (GDPR)The European Union regulation, applicable since 25 May 2018, that governs the processing of personal data of individuals in the EU…
- Health Insurance Portability and Accountability Act (HIPAA)A United States federal law of 1996 whose rules set national standards for protecting the privacy and security of individually…
- HTTP Security HeadersHTTP response headers that instruct browsers to enable protective behaviours, such as enforcing HTTPS, restricting content sources…
- HTTP Strict Transport Security (HSTS)A web security policy, delivered through the Strict-Transport-Security response header, that tells browsers to connect to a site only over…
- Incident ResponseThe organised approach to preparing for, detecting, containing, eradicating and recovering from cybersecurity incidents, and to learning…
- Interactive Application Security Testing (IAST)A testing method that places instrumentation inside a running application to observe code execution and data flow while the application is…
- ISO/IEC 27001The international standard that specifies requirements for establishing, implementing, maintaining and continually improving an…
- ISO/IEC 27002The international standard that provides guidance on information security controls, describing the purpose of each control and how to…
- MITRE ATT&CKA globally accessible knowledge base of adversary tactics and techniques based on real-world observations, used to describe attacker…
- Multi-Factor Authentication (MFA)An authentication method that requires two or more independent factors from different categories, such as a password plus a hardware key…
- NIS2 DirectiveEU Directive 2022/2555, which sets cybersecurity risk management and incident reporting obligations for mainly medium and large…
- NIST Cybersecurity Framework (CSF)A voluntary framework from the US National Institute of Standards and Technology that organises cybersecurity outcomes into functions…
- OAuth 2.0An authorisation framework, defined in IETF RFC 6749, that lets an application obtain limited, delegated access to a user's resources on…
- OWASP Top 10An awareness document from the Open Worldwide Application Security Project (OWASP) that ranks the ten most critical security risk…
- PasskeysPasswordless credentials based on the FIDO2 and WebAuthn standards, in which a device holds a private key bound to a specific website or…
- Password HashingThe practice of storing passwords as the output of a slow, salted, one-way function rather than as plain text or reversible encryption, so…
- Payment Card Industry Data Security Standard (PCI DSS)A global security standard maintained by the PCI Security Standards Council that sets technical and operational requirements for…
- Penetration TestingAn authorised, simulated attack on a system, application or network in which testers attempt to exploit vulnerabilities, showing how an…
- PhishingA social engineering attack in which fraudulent emails, messages or websites impersonate trusted parties to trick people into revealing…
- Principle of Least PrivilegeA security principle stating that every user, process and system should have only the minimum access rights needed to perform its…
- Public Key Infrastructure (PKI)The set of roles, policies, software and hardware that issues, manages and revokes digital certificates, binding public keys to identities…
- RansomwareMalicious software that encrypts or locks an organisation's data and systems and demands payment for their release, often combined with…
- Secrets ManagementThe secure storage, distribution, rotation and auditing of sensitive credentials such as API keys, passwords, tokens, certificates and…
- Security Awareness TrainingAn ongoing programme that teaches staff to recognise and respond to cyber threats such as phishing and social engineering, and to follow…
- Security Information and Event Management (SIEM)A platform that collects, normalises and correlates log and event data from across an organisation's IT environment to detect threats…
- Security MisconfigurationInsecure settings in an application, framework, server, cloud service or device, such as default credentials, unnecessary features…
- Security Operations Centre (SOC)A team, with supporting processes and technology, that continuously monitors an organisation's systems for security threats, investigates…
- Security Orchestration, Automation and Response (SOAR)Technology that connects security tools and automates repeatable investigation and response tasks through playbooks, helping security…
- Server-Side Request Forgery (SSRF)A vulnerability in which an attacker makes a server send requests to a destination of the attacker's choosing, often reaching internal…
- SOC 2An attestation report, defined by the American Institute of Certified Public Accountants (AICPA), in which an independent auditor…
- Software Bill of Materials (SBOM)A formal, machine-readable inventory of the components, libraries and dependencies that make up a piece of software, with details such as…
- Software Composition Analysis (SCA)The automated identification of open-source and third-party components in an application, including transitive dependencies, to detect…
- Software Supply Chain AttackAn attack that compromises software before it reaches its users, by tampering with source code, build systems, update mechanisms or…
- SQL Injection (SQLi)A vulnerability in which untrusted input is incorporated into a database query in a way that changes its structure, allowing an attacker…
- Static Application Security Testing (SAST)A white-box testing method that analyses source code, bytecode or binaries without running the application, to find security flaws such as…
- Threat IntelligenceEvidence-based knowledge about existing or emerging threats, including attacker groups, their motives, tactics and indicators, collected…
- Threat ModellingA structured, design-stage activity that identifies what could go wrong with a system, which threats matter most and which mitigations are…
- Transport Layer Security (TLS)The standard cryptographic protocol that provides encryption, integrity and server authentication for data in transit, used by HTTPS and…
- Vulnerability Assessment and Penetration Testing (VAPT)A combined security testing service that pairs broad, largely automated vulnerability assessment with targeted manual penetration testing…
- Vulnerability ManagementThe continuous process of identifying, evaluating, prioritising, remediating and verifying security vulnerabilities across an…
- Web Application Firewall (WAF)A security control that inspects HTTP and HTTPS traffic between clients and a web application or API, blocking requests that match attack…
- Zero Trust Architecture (ZTA)A security model that grants no implicit trust based on network location or asset ownership, instead authenticating and authorising every…
- Zero-Day VulnerabilityA software or hardware flaw that is unknown to the vendor, or for which no fix is available, when attackers discover or exploit it, so…
Other topics
- AI & Machine LearningMachine learning and deep learning fundamentals, LLMs and generative AI, RAG, AI agents and their protocols…
- Cloud & AI InfrastructureCloud computing and AI infrastructure terms: service models, containers and Kubernetes, DevOps and SRE practice, data…
- CNC & Precision MachiningCNC machine tools and machining practice: axes, spindles, feeds and speeds, G-code, offsets, CAM, tooling and tool…
- Industrial IoT & EdgeIndustrial IoT architecture and edge computing: OPC UA and MQTT, unified namespace, gateways and protocol translation…
- Industry 4.0 & Manufacturing OperationsIndustry 4.0 and smart factory concepts, OEE and production losses, lean methods, Six Sigma and statistical process…
- OT & Industrial CybersecuritySecurity of operational technology and industrial control systems: IEC 62443, the Purdue model, segmentation, secure…
- PLC & Industrial ControlProgrammable controllers and IEC 61131-3 programming, I/O, HMI, SCADA and DCS, PID and motion control, functional…
- Quality, Reliability & MaintenanceMaintenance strategies, reliability metrics and analysis, condition monitoring techniques, maintenance management…
- Robotics & Physical AIIndustrial and collaborative robots, kinematics, programming and simulation, grippers, machine vision, mobile robots…
- Textile & Automotive ManufacturingTextile production from spinning, weaving and knitting to dyeing and finishing, and automotive and EV production from…