Term Kind Topic What it is
Administrative Path Blindness Support Tool Gap, Internal Access Blind Spot concept Authorization The pattern where the customer-facing data path is rigorously access-controlled while internal dashboards, support tools, analytics jobs and exports have unrestricted access - protecting against the wrong adversary.
Attack Surface concept Threat Modelling The complete set of points where an untrusted actor can interact with a system — and the quantity that reduction genuinely reduces risk.
Auditability concept Security Architecture The ability to reconstruct who did what, to which resource, when, and from where — reliably enough to be relied upon after the fact.
Authentication AuthN concept Security Architecture Establishing who a principal is, to a defined level of confidence.
Authorization AuthZ concept Security Architecture Deciding whether an authenticated principal may perform a specific action on a specific resource.
CI Secret Exposure Surface Build Credential Blast Radius, Runner Secret Surface concept Supply Chain Security The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a single compromised step.
Compliance Frameworks concept Compliance Frameworks Externally defined control sets — SOC 2, ISO 27001, PCI DSS and others — whose architectural impact is scope, evidence and segmentation.
Confused Deputy concept Authorization A privileged component tricked into performing an action on behalf of a caller who lacks the authority to perform it directly.
Containment vs Eradication concept Security Incident Response Stopping an attacker's ongoing access versus removing their foothold entirely — sequential phases with different urgency and different risks of doing them wrong.
Encryption concept Encryption Protecting data in transit, at rest and in use — where key management is the actual architecture and the cipher choice is the easy part.
Identity and Access Management IAM concept Security Architecture The system of record for principals, credentials and permissions, and the policy engine that decides what each principal may do.
Insider Risk by Design concept Auditability Designing so that a legitimate operator cannot silently exceed their remit, treating the trusted internal user as part of the threat model.
Lateral Movement concept Zero Trust An attacker's progression from an initial foothold to more valuable systems, which is what turns a minor compromise into a breach.
Least Privilege concept Security Architecture Granting each identity only the permissions it needs, for only as long as it needs them.
Mass Assignment Auto-Binding, Over-Posting concept Secure API Design A vulnerability where a request body is bound directly to an internal object, allowing a caller to set fields the API never intended to expose.
Object-Level Authorization BOLA, IDOR concept Authorization Checking that the caller is entitled to the specific record they requested, not merely that they may call the endpoint.
OWASP Risks OWASP Top Ten concept OWASP Risks The recurring application vulnerability classes — and the architectural decisions that make each one structurally unlikely.
Permission Boundary concept Identity & Access Management A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimited privilege.
Personally Identifiable Information PII, Personal Data concept Security Architecture Data relating to an identifiable person — a category far broader than name and address, and the trigger for most regulatory obligation.
Privilege Creep Access Accumulation, Permission Sprawl concept Identity & Access Management The gradual accumulation of access as people change roles without losing prior permissions, producing long-tenured staff with far more access than anyone intended.
Refresh Token concept Tokens & JWTs A long-lived credential used solely to obtain new short-lived access tokens, so sessions can persist without long-lived access tokens circulating.
Relationship-Based Access Control ReBAC, Graph Authorization concept Authorization Expressing permissions as relationships between subjects and objects, with inheritance and group expansion as rules over the graph, rather than as attributes on rows.
Revocation Window Token Lifetime as SLA, Local Validation Trade concept Tokens & JWTs The period during which a revoked credential remains accepted, which for locally-validated tokens is exactly the token lifetime - the unavoidable price of removing the identity provider from the request path.
Role Explosion concept Authorization The proliferation of narrowly-scoped roles that occurs when RBAC is used to express rules that actually depend on context.
Secret Zero Bootstrapping Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager — the one secret that cannot itself be stored in the secret manager.
Secret Zero Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager, which cannot itself be stored in the secret manager.
Security Group Sprawl concept Network Security The accumulation of firewall and security group rules that nobody can safely remove, producing a permissive posture nobody chose.
Server-Side Request Forgery SSRF concept OWASP Risks Inducing a server to make an HTTP request to an attacker-chosen destination, turning it into a proxy into networks and services the attacker cannot reach directly.
Standing Credential Long-Lived Credential, Persistent Secret, Static Key concept Secrets Management A credential that remains valid indefinitely, so a single leak grants permanent access - the property that converts a small compromise into a large one, and the one a secrets manager does not fix.
Threat Model Trust Boundary concept Threat Modelling The line across which data or control passes from a less trusted context to a more trusted one, and where validation and authorisation must occur.
Token Revocation Gap concept Tokens & JWTs The window between deciding a token should no longer be valid and it actually ceasing to work, which for self-contained tokens is its remaining lifetime.
Workload Identity SPIFFE, Managed Identity, Service Identity concept Identity & Access Management Giving a running workload a cryptographic identity derived from its platform context, so it can authenticate without a stored credential.
Zero Trust concept Security Architecture A security model that grants no implicit trust from network position, and authenticates and authorises every request individually.