Translated from Portuguese with AI assistance and reviewed by the author.
Read the original (PT)
The information security world is full of terms and acronyms that not everyone knows.
Unfamiliar jargon feels alien and pushes people apart, so there is always room to spell out what may seem obvious and bring people closer together.
With that in mind, I started a mini dictionary of the terms I use day to day. The goal is simply to give a brief overview of each one.
Terms and acronyms
Applications and laws
- OWASP: An open, collaborative project that gathers best practices for secure development.
- SAST: Static application security testing tools. For example, a source code analyzer.
- DAST: Dynamic application security testing tools. For example, OWASP Zap.
- LGPD: Short for Lei Geral de Proteção de Dados (Brazil’s General Data Protection Law). The Brazilian law that regulates the protection of individuals’ personal data.
- ANPD: Short for Autoridade Nacional de Proteção de Dados (Brazil’s National Data Protection Authority). The government agency that oversees compliance with the LGPD.
- GDPR: The European Union’s General Data Protection Regulation.
- SIEM: Short for Security Information and Event Management. Solutions that bring together the many technical events and logs generated by security tools. Usually presented through dashboards and alerts to make infrastructure management easier.
- SOC: Short for Security Operation Center. Think of it as a broader SIEM that covers processes and people, not just technology. Its goal is to monitor, prevent, detect, investigate, and respond to cyber threats.
- MSS / MSSP: Short for Managed Security Services. A third-party company or provider that delivers monitoring services. It can be seen as an extension of the SOC.
- HSM: Short for Hardware Security Module. A physical device used to store and manage the keys or certificates used inside a corporate network.
- KMS: Short for Key Management Service. Makes it easier to create and manage cryptographic keys and to control how they are used, usually integrated with an HSM.
- WAF: Short for Web Application Firewall. A web application firewall filters, monitors, and blocks HTTP traffic to and from a web application or website. Examples include Sucuri, Cloudflare, and Incapsula.
- PCI: Short for Security Standards Council. Defines the security standards to be adopted in payment environments.
General terms
- CheatSheet: A collection of payloads or countermeasures focused on a given subject. For example, the XSS CheatSheet.
- Payload: The set of data used to simulate or carry out the exploitation of a flaw.
- Red Team: A company’s internal team responsible for offensive testing of the organization’s own environments and applications.
- Blue Team: Handles attack attempts, monitors the environment, and puts defenses in place against external attacks or those uncovered by the Red Team.
- Purple Team: Promotes and organizes communication between the Red and Blue Teams.
- PoC: Short for Proof of Concept. A demonstration that proves what is being shown or explained.
- 2FA: Short for Two-Factor Authentication. A feature many systems let you enable to add a second authentication factor and make logins more secure.
- ML: Abbreviation for Machine Learning.
- CSIRT: Short for Computer Security Incident Response Team. The team that responds to security incidents.
Security terms
- Hash: A signature, or reduced representation, of a file or text. A hash cannot be reversed to recover the original content.
- Encryption: Scrambling or protecting content using keys, which can be symmetric or asymmetric (public and private).
- Cookies: Information a website stores about you in the browser you are using.
- SSL/TLS: Encryption protocols used to protect the content of sites that use HTTPS.
- HSTS: Short for Strict Transport Security. Forces the browser to use HTTPS when browsing.
- Exploit: The term used to refer to the exploitation of a flaw.
- CVE: Publicly known flaws are recorded in a database and given a CVE number. Example.
- Hacker: A person with a high level of specific knowledge in a given subject.
- Pentest: The name for running a battery of penetration tests against a target system.
- Brute Force: Forcing an exploitation through sheer trial and error, working through every possibility one by one.
- RSA: An asymmetric encryption system based on a public and private key pair.
- AES: Short for Advanced Encryption Standard. A symmetric encryption system. Rijndael encryption is AES.
- CISO / CSO: Short for Chief Information Security Officer. The senior executive within an organization responsible for establishing and maintaining the company’s vision, strategy, and program to make sure information assets and technologies are properly protected.
Vulnerability acronyms
- XSS: Short for Cross-Site Scripting. A vulnerability involving the injection of JavaScript or DOM content, mainly in web environments.
- XXE: Short for XML External Entity. Associated with vulnerabilities that allow information gathering through the processing of XML. Learn more here.
- CORS: Short for Cross-Origin Resource. A mechanism that restricts access to resources across domains in web environments.
- CSRF or XSRF: Short for Cross-Site Request Forgery. The name for forged requests built inside a trusted application environment to trigger malicious actions.
- MitM: Short for Man-in-the-Middle. The act of intercepting messages between two endpoints, with or without tampering with the messages in transit.
- SQLi: Abbreviation for SQL Injection.
- RCE: Remote Code Execution.
- RFI: Remote File Inclusion.
Types of attacks and viruses
- Malware: A malicious, harmful computer program. Its purpose is to cause damage or to steal or spy on information.
- Ransomware: A malicious program that encrypts the files on a machine and locks the user out, usually tied to a ransom demand in cryptocurrency.
- DDoS: Short for Denial of Service. A type of denial-of-service attack, carried out when the goal is to take down a system, website, or service.
Missing something?
Send it my way and I’ll add it to the dictionary.