Term Kind Topic What it is
Security Group Sprawl concept Network Security The accumulation of firewall and security group rules that nobody can safely remove, producing a permissive posture nobody chose.
Security Incident Response practice Security Incident Response Responding to a compromise — where the architecture determines whether you can detect it, contain it, and prove what happened.
Server-Side Request Forgery SSRF concept OWASP Risks Inducing a server to make an HTTP request to an attacker-chosen destination, turning it into a proxy into networks and services the attacker cannot reach directly.
Signing Boundary Policy Policy at the HSM, Constrained Signing pattern Key Management Enforcing transaction policy at the hardware signing boundary rather than in application code, so that a compromised application cannot obtain an arbitrary signature.
Software Bill of Materials SBOM tool Supply Chain Security A machine-readable inventory of every component and dependency in a piece of software, including transitive ones, used to answer exposure questions quickly.
Standing Credential Long-Lived Credential, Persistent Secret, Static Key concept Secrets Management A credential that remains valid indefinitely, so a single leak grants permanent access - the property that converts a small compromise into a large one, and the one a secrets manager does not fix.
Step-Up Authentication pattern Authentication Requiring stronger proof of identity at the moment a consequential action is attempted, rather than applying maximum friction to every session.
STRIDE practice Threat Modelling A mnemonic for six threat categories — spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege — walked across each component and data flow.
Supply Chain Attestation SLSA, Provenance Attestation practice Supply Chain Security A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.
Tag-Bound Access Policy Classification-Driven Access Control, Tag-Based Masking pattern Data Classification An access rule attached to a classification label rather than to a table, so that tagging data is what applies the control and derived copies inherit it through lineage.
Tamper-Evident Log pattern Auditability An audit log constructed so that any modification or deletion of past entries is detectable, typically by chaining entries cryptographically.
Threat Model Trust Boundary concept Threat Modelling The line across which data or control passes from a less trusted context to a more trusted one, and where validation and authorisation must occur.
Threat Modelling practice Security Architecture A structured exercise that identifies what can go wrong with a design, before it is built, by walking the system's trust boundaries.
Token Audience Validation Audience Restriction, aud Claim practice Tokens & JWTs Verifying that a signed token was issued for the service consuming it, without which a legitimately obtained low-privilege token is replayable against a high-privilege service.
Token Exchange RFC 8693, Delegation Token protocol OAuth 2.0 & OIDC Trading one token for another with different scope, audience or subject, so a service can call downstream on a user's behalf without reusing the original token.
Token Introspection protocol OAuth 2.0 & OIDC Asking the authorisation server whether a token is currently valid, rather than validating it locally from its signature.
Token Revocation Gap concept Tokens & JWTs The window between deciding a token should no longer be valid and it actually ceasing to work, which for self-contained tokens is its remaining lifetime.
Transactional Audit Emission Audit in the Same Transaction, Complete Audit Guarantee practice Auditability Writing the audit record in the same transaction as the state change it describes, so that a crash cannot produce a change with no record - the property that distinguishes an audit trail from application logging.
Web Application Firewall WAF tool Network Security A filter in front of an application that inspects HTTP requests and blocks those matching known attack patterns — useful as a layer, dangerous as a substitute.
Workload Identity SPIFFE, Managed Identity, Service Identity concept Identity & Access Management Giving a running workload a cryptographic identity derived from its platform context, so it can authenticate without a stored credential.
Zero Trust concept Security Architecture A security model that grants no implicit trust from network position, and authenticates and authorises every request individually.