Terminology Index
1801 terms
Showing 1473-1504 of 1801 terms
Security Architecture
The overall design of how security is realized across systems, identity, data, network, applications, monitoring, so the parts fit together coherently rather than working as disconnected controls.
Security Architecture Review
An assessment that evaluates a system's or organization's security architecture against best practice and threat scenarios, identifying gaps and recommending improvements early before they become problems.
Security Automation Patterns
Reusable approaches for automating security in the cloud, automated remediation, posture enforcement, response actions, that a cloud engineer applies to scale security with the environment.
Security Awareness
Building the knowledge, attitudes, and behaviors people need to act securely in their work. A foundational discipline because most attacks ultimately depend on human decisions and reactions.
Security Awareness Program Design
Designing an awareness program deliberately, audience analysis, learning objectives, content, channels, simulation, metrics, so it actually changes behavior rather than ticking a compliance box.
Security Champions Program
An awareness/culture program that recruits and supports volunteers across the organization who promote security within their teams, multiplying the security function's reach.
Security Communication Strategy
How security communicates with the rest of the organization, channels, frequency, tone, audience targeting, that shapes whether security is heard, trusted, and acted on rather than ignored.
Security Context
The identity and privileges under which a process or action operates, the user or service account whose rights apply. Reading security context is foundational to interpreting operating-system events.
Security Controls
Measures put in place to reduce security risks, technical, administrative, and physical, that together provide defense in depth. The fundamental building blocks of any security program.
Security Culture
The shared norms, behaviors, and attitudes around security in an organization. A foundational governance topic because culture determines whether formal security programs translate into actual behavior.
Security Culture Building
The deliberate work of growing security culture, leadership modeling, programs, recognition, communication, that turns abstract culture into observable behavior across the organization over time.
Security Culture Metrics
Measures that gauge security culture, reporting rates, near-misses, survey results, behavior changes, that turn culture from a feeling into something the organization can measure and improve.
Security Engineering
The discipline of building, deploying, and operating the security systems a SOC relies on, EDR, SIEM, identity, and detection infrastructure, so blue-team operations rest on capable, well-run platforms.
Security Framework Types
The different categories of security frameworks (control catalogs, risk frameworks, regulatory regimes, certifications) that serve different purposes and combine into how an organization manages compliance.
Security Governance
The structures and processes that direct and oversee security in an organization, leadership, policies, decisions, accountability, that align security with business objectives and risk.
Security Groups
Stateful firewalls attached to cloud resources (instances, services) that allow or deny inbound and outbound traffic by rules. A core building block of cloud network security every cloud engineer uses.
Security Incident
An event that compromises, or could compromise, the confidentiality, integrity, or availability of information or systems. The foundational category that incident response is organized around.
Security Investment
How an organization allocates resources, budget, people, attention, to security across competing priorities, a leadership decision that shapes which risks get treated and how the program grows.
Security Operations Center
The team and function responsible for monitoring, detecting, and responding to security threats, the operational heart of blue-team work, run continuously to defend the organization.
Security Posture
The overall state of an organization's security at a point in time, controls in place, exposures, maturity, performance, that summarizes how well-defended it is and where it needs to improve.
Security Program Charter
A foundational document establishing a security program's authority, scope, mission, and structure, signed by executive leadership, that authorizes the program and anchors its governance.
Security Program Metrics
Measures that gauge how well a security program is performing, control coverage, risk reduction, operational performance, used to demonstrate value and steer improvement at program scale.
Security Program Presentation
Communicating the security program's status, priorities, and asks to executive and board audiences clearly, persuasively, and concisely, a capstone skill that determines whether the program gets support.
Security Program Scope
What the security program covers, business units, systems, geographies, controls, that defines the program's responsibilities and boundaries so they are clear rather than assumed.
Security Questionnaire Response
Responding to customer or partner security questionnaires accurately and efficiently, a routine but high-volume task in compliance programs that often gates deals and partnerships.
Security Report Writing
The skill of writing clear, accurate, useful security reports, investigation findings, briefings, executive summaries, that turn analyst work into communication stakeholders can act on.
Security Review
A structured examination of a system, process, or change to find security issues before they cause harm, lighter than a full audit and more focused than a passing glance, foundational to embedding security in operations.
Security Roadmap
A time-phased plan of security improvements, what gets done when, that turns strategy into a sequenced set of initiatives with owners, dependencies, and milestones over months and years.
Security Steering Committee
A cross-functional body that oversees security at the executive or senior-management level, setting priorities, sponsoring initiatives, and reviewing performance, providing governance and accountability.
Security Strategy
The plan for how security will support business objectives over a multi-year horizon, priorities, capabilities, and outcomes, that gives the program direction and informs investment.
Security Testing
Testing systems for security weaknesses, ranging from automated scanning to manual penetration testing, to find issues before attackers do. A foundational defensive-web fundamentals practice.
Security Training Effectiveness
How well security training actually changes behavior, beyond completion rates, measured through behavior change, simulation results, and reporting rates, the test of whether training delivered value.