Terminology Index
2953 terms
OpenTelemetry
An open standard and toolset for collecting telemetry, traces, metrics, and logs, from applications and infrastructure in a vendor-neutral way, giving consistent observability that also supports security monitoring in cloud-native systems.
Operational Evidence
Compliance evidence showing that a control operated consistently over time, logs, tickets, records of recurring activities, as opposed to point-in-time proof, demonstrating the control works in practice, not just on paper.
Operational Handoff
An operational handoff transfers supported facts, stable identifiers, evidence references, confidence, urgency, prior actions, limitations, and required decisions between responsible functions.
Operational Intelligence
Threat intelligence about specific campaigns, operations, or imminent threats, more detailed than strategic intelligence but broader than individual indicators, helping defenders prepare for and respond to active threat activity.
Operations Metric Quality
Operations metric quality requires a purpose, owner, definition, population, source, refresh, validation, interpretation, limitations, and decision or action for each measure.
Opportunistic Attacker
An adversary who selects targets largely from broad scanning, exposed weaknesses, stolen credentials, or easy gain rather than a preselected organization.
Opportunistic Attackers
Attackers who target whatever is easy and vulnerable rather than a specific victim, exploiting widely scanned weaknesses and known vulnerabilities at scale. Most organizations face them constantly.
Orchestration Security Boundary
An orchestration security boundary includes control plane, nodes, workloads, admission, identities, secrets, network, storage, audit, upgrades, and recovery responsibilities.
Organizational Incident Learning
How an organization, not just individuals, learns from incidents, capturing lessons, changing processes and controls, and building institutional memory, so it gets measurably better after each incident.
Organizational Threat Modeling Capability
An organization's overall ability to do threat modeling consistently and well, the skills, processes, tools, and culture that make threat modeling a routine practice rather than an occasional or ad-hoc activity.
Organizational Unit
A directory container used to organize objects and apply delegated administration or policy; its exact behavior depends on the directory platform.
Organizational Units
Containers within a directory (like Active Directory) used to group and organize users, computers, and other objects, so administration, policy, and delegation can be applied to logical groupings.
Origin
The scheme, host, and port that define where a web page or request comes from.
Orphaned Account Control
Orphaned account control identifies and resolves target accounts that lack a valid correlated identity and accountable owner.
Outlier Detection
A hunting and analysis technique that finds data points deviating markedly from the norm, unusual hosts, accounts, or behaviors, on the principle that statistical outliers often warrant investigation as possible threats.
Output Encoding
Safely representing data for a specific context so it is treated as text instead of code.
Overlap and Efficiency
The principle that security frameworks share many common requirements, so mapping their overlap lets one control and its evidence satisfy multiple frameworks, the key to efficient multi-framework compliance.
PAM
Privileged Access Management: the discipline and tools for securing, controlling, and monitoring access to privileged accounts, the powerful admin and service accounts attackers prize, through vaulting, just-in-time access, and session control.
PAM Account Onboarding
PAM account onboarding brings a privileged identity, role, credential, target, connector, and direct access paths under an approved control and ownership model.
PAM Exception Management
PAM exception management governs privileged identities or systems that temporarily cannot meet the required access-control pattern.
PAM Product Evaluation
PAM product evaluation compares candidate controls against the organization's human, workload, target-system, session, governance, recovery, and integration requirements.
PAM Program Governance
The oversight structures that keep a privileged access management program effective, ownership, policies, scope, approval workflows, and review, so privileged access stays controlled and accountable over time rather than degrading.
PAM Program Metrics
Measures that show how well a privileged access management program is working, coverage of privileged accounts, use of just-in-time access, session recording, vaulted credentials, so the program's effectiveness is visible and improvable.
PAM SIEM Integration
Feeding privileged access management activity, session logs, credential checkouts, access grants, into the SIEM, so privileged-account use is monitored, correlated, and alerted on alongside other telemetry.
PAM Vault Architecture
The design of the secure vault at the heart of a PAM system, where privileged credentials are stored, encrypted, rotated, and access-controlled, so privileged secrets are protected and brokered rather than held by users.
PASTA
PASTA, the Process for Attack Simulation and Threat Analysis, is a risk-centered threat-modeling method that connects business objectives, system decomposition, attack paths, and impact.
PASTA Methodology
Process for Attack Simulation and Threat Analysis: a risk-centric, seven-stage threat-modeling methodology that ties technical threats to business impact, producing attacker-informed, prioritized findings.
PAT
Port Address Translation: a form of NAT that lets many devices share one public IP address by mapping each connection to a different port, common on networks and relevant to interpreting addresses in traffic.
PBAC
Policy-Based Access Control: an access model where access decisions are driven by centrally defined policies (often using attributes and context) rather than static role assignments, enabling fine-grained, dynamic authorization.
PBC Request Governance
PBC request governance controls evidence and information requested from management or provided by the client during an assurance engagement.
PBKDF2
Password-Based Key Derivation Function 2: a widely used function that derives a cryptographic key (or password hash) from a password by applying a hash many times with a salt, deliberately slow to resist brute-forcing.
PCI Audit Cycle
The recurring assessment cycle for PCI DSS compliance, annual validation (by self-assessment or external assessor) plus ongoing requirements, that organizations handling payment-card data must complete to stay compliant.