Terminology
2185 terms, tools, patterns and metrics an architect is expected to use precisely. Each one gets a short explanation of what it is, and — where it matters — what it is commonly confused with. Search filters as you type; the column headers sort.
All areas2185
Architecture Fundamentals77
Distributed Systems107
Data Architecture110
Cloud Architecture89
Networking88
API & Integration Architecture82
Reliability & Resilience75
Observability70
Performance & Capacity Engineering72
Security Architecture81
Cost Architecture & FinOps66
Business Architecture67
Architecture Communication67
Enterprise Architecture66
Legacy Modernization66
AI-Era Architecture69
Software Architecture & Engineering71
Architecture Patterns71
Architecture Decision-Making63
The Architect's Meta-Skills61
Delivery & Release Engineering66
Platform Engineering & Developer Experience70
Testing & Quality Architecture66
Data Platform Architecture64
Streaming & Real-Time Data69
Data Governance & Semantics69
Frontend & Experience Architecture66
Edge, Mobile & IoT68
Regulatory & Data Protection Architecture65
Assurance, Audit & Model Risk64
81 terms shown.
| Term | Kind | Topic | What it is |
|---|---|---|---|
| Administrative Path Blindness Support Tool Gap, Internal Access Blind Spot | concept | Authorization | The pattern where the customer-facing data path is rigorously access-controlled while internal dashboards, support tools, analytics jobs and exports have unrestricted access - protecting against the wrong adversary. |
| Artifact Signing | practice | Supply Chain Security | Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source. |
| Attack Surface | concept | Threat Modelling | The complete set of points where an untrusted actor can interact with a system — and the quantity that reduction genuinely reduces risk. |
| Auditability | concept | Security Architecture | The ability to reconstruct who did what, to which resource, when, and from where — reliably enough to be relied upon after the fact. |
| Authentication AuthN | concept | Security Architecture | Establishing who a principal is, to a defined level of confidence. |
| Authorization AuthZ | concept | Security Architecture | Deciding whether an authenticated principal may perform a specific action on a specific resource. |
| Authorization Code Flow with PKCE PKCE | protocol | OAuth 2.0 & OIDC | The OAuth flow recommended for all client types, in which an authorisation code is exchanged for tokens using a proof key that binds the exchange to the original requester. |
| Break-Glass Access Emergency Access, Just-in-Time Elevation | practice | Identity & Access Management | A pre-agreed, heavily audited path to elevated privilege for emergencies, replacing standing administrative access. |
| Build Provenance Attestation, SLSA Provenance, Artefact Lineage | pattern | Supply Chain Security | A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the build system testable rather than assumed. |
| Build Provenance Artefact Attestation, SLSA Provenance | practice | Supply Chain Security | A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an artefact corresponds to reviewed source. |
| Capital One 2019: From SSRF to the Metadata Endpoint IMDSv1 Breach | case-study | Identity & Access Management | A server-side request forgery reached the cloud instance metadata service, obtained temporary credentials, and used an over-permissioned role to read a very large volume of data. |
| CI Secret Exposure Surface Build Credential Blast Radius, Runner Secret Surface | concept | Supply Chain Security | The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a single compromised step. |
| Compliance Framework SOC 2, ISO 27001, PCI DSS | practice | Security Architecture | A published set of control requirements an organisation is assessed against, which turns security posture into evidence somebody else will check. |
| Compliance Frameworks | concept | Compliance Frameworks | Externally defined control sets — SOC 2, ISO 27001, PCI DSS and others — whose architectural impact is scope, evidence and segmentation. |
| Confused Deputy | concept | Authorization | A privileged component tricked into performing an action on behalf of a caller who lacks the authority to perform it directly. |
| Consent Management | practice | Privacy Engineering | Capturing, storing, honouring and evidencing a data subject's permissions for specific processing purposes, including withdrawal. |
| Containment vs Eradication | concept | Security Incident Response | Stopping an attacker's ongoing access versus removing their foothold entirely — sequential phases with different urgency and different risks of doing them wrong. |
| Continuous Compliance | practice | Compliance Frameworks | Producing compliance evidence automatically and continuously from the systems themselves, rather than reconstructing it before an audit. |
| Data Discovery | practice | Data Classification | Automatically scanning stores to find where sensitive data actually resides, as distinct from where the documentation says it should. |
| Data Key Caching Key Reuse Window, Envelope Key Caching | practice | Key Management | Reusing one generated data key across a bounded number of objects, bytes and seconds, so that envelope encryption does not make one key-service request per record. |
| Dwell Time Mean Time to Detect | metric | Security Incident Response | The period between an attacker gaining access and being detected — the metric that determines how much damage an intrusion can do. |
| Dynamic Secrets | pattern | Secrets Management | Credentials generated on demand for a specific consumer with a short lease, rather than stored, shared and rotated periodically. |
| Egress Filtering | practice | Network Security | Restricting what a workload may connect out to, which is the control that turns a compromise into a contained one. |
| Encryption | concept | Encryption | Protecting data in transit, at rest and in use — where key management is the actual architecture and the cipher choice is the easy part. |
| Encryption at Rest and in Transit | practice | Security Architecture | Protecting stored data from disclosure if the medium is obtained, and network data from disclosure if the path is observed — two different controls against two different threats. |
| Envelope Encryption | pattern | Key Management | Encrypting data with a locally generated data key, then encrypting that key with a master key held in a key management service. |
| Equifax 2017: A Known Patch and an Expired Certificate Equifax Breach | case-study | Supply Chain Security | An unpatched framework vulnerability provided entry, and an expired certificate on a monitoring device meant the exfiltration went undetected for months. |
| Field-Level Encryption Application-Level Encryption | pattern | Encryption | Encrypting specific sensitive fields in the application before they reach the datastore, so the store never holds plaintext. |
| Hardware Security Module HSM | tool | Key Management | A tamper-resistant device that generates and stores keys and performs cryptographic operations without the key material ever being extractable. |
| Identity and Access Management IAM | concept | Security Architecture | The system of record for principals, credentials and permissions, and the policy engine that decides what each principal may do. |
| Insider Risk by Design | concept | Auditability | Designing so that a legitimate operator cannot silently exceed their remit, treating the trusted internal user as part of the threat model. |
| JSON Web Token JWT | protocol | Security Architecture | A signed, self-contained token carrying claims, which a service can validate locally without calling the issuer. |
| JWKS JSON Web Key Set | protocol | Tokens & JWTs | A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to survive key rotation. |
| Key Rotation | practice | Key Management | Periodically replacing a cryptographic key with a new one while retaining the old for decrypting existing data, so exposure from any single key is bounded. |
| Lateral Movement | concept | Zero Trust | An attacker's progression from an initial foothold to more valuable systems, which is what turns a minor compromise into a breach. |
| Least Privilege | concept | Security Architecture | Granting each identity only the permissions it needs, for only as long as it needs them. |
| Mass Assignment Auto-Binding, Over-Posting | concept | Secure API Design | A vulnerability where a request body is bound directly to an internal object, allowing a caller to set fields the API never intended to expose. |
| Microsegmentation | pattern | Zero Trust | Enforcing fine-grained network policy between individual workloads rather than between broad network zones, so a compromise cannot move laterally. |
| Multi-Factor Authentication MFA, 2FA | practice | Authentication | Requiring evidence from more than one category — something you know, have, or are — so a single stolen credential is insufficient. |
| OAuth 2.0 | protocol | Security Architecture | An authorisation framework that lets an application obtain scoped, delegated access to a resource without handling the user's credentials. |
| Object-Level Authorization BOLA, IDOR | concept | Authorization | Checking that the caller is entitled to the specific record they requested, not merely that they may call the endpoint. |
| OpenID Connect OIDC | protocol | Security Architecture | An identity layer over OAuth 2.0 that adds a signed ID token asserting who the user is and how they authenticated. |
| OWASP Risks OWASP Top Ten | concept | OWASP Risks | The recurring application vulnerability classes — and the architectural decisions that make each one structurally unlikely. |
| OWASP Top Ten | practice | Security Architecture | A periodically updated consensus list of the most critical web application security risks, useful as a design-review checklist. |
| Per-Record Tenancy Record-Level Ownership, Attribute-Based Tenancy, Cross-Org Data Ownership | pattern | Authorization | Attaching the owning organisation to each record rather than to its container, so that data shared across tenant boundaries can still be governed, exported, retained and deleted according to the policy of whoe… |
| Permission Boundary | concept | Identity & Access Management | A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimited privilege. |
| Personally Identifiable Information PII, Personal Data | concept | Security Architecture | Data relating to an identifiable person — a category far broader than name and address, and the trigger for most regulatory obligation. |
| Phishing-Resistant Authentication Origin-Bound Authentication, Unphishable MFA | pattern | Authentication | Authentication whose response cannot be replayed at a site other than the one it was produced for, because the authenticator signs the requesting origin rather than releasing a secret the user could pass on. |
| Policy Decision Point PDP, Authorization Service, Policy Engine | pattern | Zero Trust | The component that evaluates an authorisation question and returns a decision, kept separate from the enforcement points that ask, so policy can change without redeploying every service. |
| Privacy Engineering | practice | Privacy Engineering | Building systems whose privacy properties come from their structure rather than from policy documents. |
| Privilege Creep Access Accumulation, Permission Sprawl | concept | Identity & Access Management | The gradual accumulation of access as people change roles without losing prior permissions, producing long-tenured staff with far more access than anyone intended. |
| Reachability Triage Exploitability Prioritisation, Vulnerability Relevance | practice | Supply Chain Security | Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by severity score - which is what makes vulnerability manageme… |
| Refresh Token | concept | Tokens & JWTs | A long-lived credential used solely to obtain new short-lived access tokens, so sessions can persist without long-lived access tokens circulating. |
| Relationship-Based Access Control ReBAC, Graph Authorization | concept | Authorization | Expressing permissions as relationships between subjects and objects, with inheritance and group expansion as rules over the graph, rather than as attributes on rows. |
| Revocation Window Token Lifetime as SLA, Local Validation Trade | concept | Tokens & JWTs | The period during which a revoked credential remains accepted, which for locally-validated tokens is exactly the token lifetime - the unavoidable price of removing the identity provider from the request path. |
| Role Explosion | concept | Authorization | The proliferation of narrowly-scoped roles that occurs when RBAC is used to express rules that actually depend on context. |
| Secret Zero Bootstrapping Problem | concept | Secrets Management | The credential a workload needs in order to authenticate to the secret manager — the one secret that cannot itself be stored in the secret manager. |
| Secret Zero Problem | concept | Secrets Management | The credential a workload needs in order to authenticate to the secret manager, which cannot itself be stored in the secret manager. |
| Secrets Management | practice | Security Architecture | Storing, distributing, rotating and auditing credentials so that they never live in code, images or configuration files. |
| Secure API Design | practice | Secure API Design | Building an interface where the safe path is the default and the unsafe one requires deliberate effort. |
Nothing on this page matches. Search the whole glossary.