Term Kind Topic What it is
Administrative Path Blindness Support Tool Gap, Internal Access Blind Spot concept Authorization The pattern where the customer-facing data path is rigorously access-controlled while internal dashboards, support tools, analytics jobs and exports have unrestricted access - protecting against the wrong adversary.
Artifact Signing practice Supply Chain Security Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
Attack Surface concept Threat Modelling The complete set of points where an untrusted actor can interact with a system — and the quantity that reduction genuinely reduces risk.
Auditability concept Security Architecture The ability to reconstruct who did what, to which resource, when, and from where — reliably enough to be relied upon after the fact.
Authentication AuthN concept Security Architecture Establishing who a principal is, to a defined level of confidence.
Authorization AuthZ concept Security Architecture Deciding whether an authenticated principal may perform a specific action on a specific resource.
Authorization Code Flow with PKCE PKCE protocol OAuth 2.0 & OIDC The OAuth flow recommended for all client types, in which an authorisation code is exchanged for tokens using a proof key that binds the exchange to the original requester.
Break-Glass Access Emergency Access, Just-in-Time Elevation practice Identity & Access Management A pre-agreed, heavily audited path to elevated privilege for emergencies, replacing standing administrative access.
Build Provenance Attestation, SLSA Provenance, Artefact Lineage pattern Supply Chain Security A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the build system testable rather than assumed.
Build Provenance Artefact Attestation, SLSA Provenance practice Supply Chain Security A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an artefact corresponds to reviewed source.
Capital One 2019: From SSRF to the Metadata Endpoint IMDSv1 Breach case-study Identity & Access Management A server-side request forgery reached the cloud instance metadata service, obtained temporary credentials, and used an over-permissioned role to read a very large volume of data.
CI Secret Exposure Surface Build Credential Blast Radius, Runner Secret Surface concept Supply Chain Security The set of credentials reachable by any code that executes in a build job, which is usually far larger than the job needs and is exposed in full by a single compromised step.
Compliance Framework SOC 2, ISO 27001, PCI DSS practice Security Architecture A published set of control requirements an organisation is assessed against, which turns security posture into evidence somebody else will check.
Compliance Frameworks concept Compliance Frameworks Externally defined control sets — SOC 2, ISO 27001, PCI DSS and others — whose architectural impact is scope, evidence and segmentation.
Confused Deputy concept Authorization A privileged component tricked into performing an action on behalf of a caller who lacks the authority to perform it directly.
Consent Management practice Privacy Engineering Capturing, storing, honouring and evidencing a data subject's permissions for specific processing purposes, including withdrawal.
Containment vs Eradication concept Security Incident Response Stopping an attacker's ongoing access versus removing their foothold entirely — sequential phases with different urgency and different risks of doing them wrong.
Continuous Compliance practice Compliance Frameworks Producing compliance evidence automatically and continuously from the systems themselves, rather than reconstructing it before an audit.
Data Discovery practice Data Classification Automatically scanning stores to find where sensitive data actually resides, as distinct from where the documentation says it should.
Data Key Caching Key Reuse Window, Envelope Key Caching practice Key Management Reusing one generated data key across a bounded number of objects, bytes and seconds, so that envelope encryption does not make one key-service request per record.
Dwell Time Mean Time to Detect metric Security Incident Response The period between an attacker gaining access and being detected — the metric that determines how much damage an intrusion can do.
Dynamic Secrets pattern Secrets Management Credentials generated on demand for a specific consumer with a short lease, rather than stored, shared and rotated periodically.
Egress Filtering practice Network Security Restricting what a workload may connect out to, which is the control that turns a compromise into a contained one.
Encryption concept Encryption Protecting data in transit, at rest and in use — where key management is the actual architecture and the cipher choice is the easy part.
Encryption at Rest and in Transit practice Security Architecture Protecting stored data from disclosure if the medium is obtained, and network data from disclosure if the path is observed — two different controls against two different threats.
Envelope Encryption pattern Key Management Encrypting data with a locally generated data key, then encrypting that key with a master key held in a key management service.
Equifax 2017: A Known Patch and an Expired Certificate Equifax Breach case-study Supply Chain Security An unpatched framework vulnerability provided entry, and an expired certificate on a monitoring device meant the exfiltration went undetected for months.
Field-Level Encryption Application-Level Encryption pattern Encryption Encrypting specific sensitive fields in the application before they reach the datastore, so the store never holds plaintext.
Hardware Security Module HSM tool Key Management A tamper-resistant device that generates and stores keys and performs cryptographic operations without the key material ever being extractable.
Identity and Access Management IAM concept Security Architecture The system of record for principals, credentials and permissions, and the policy engine that decides what each principal may do.
Insider Risk by Design concept Auditability Designing so that a legitimate operator cannot silently exceed their remit, treating the trusted internal user as part of the threat model.
JSON Web Token JWT protocol Security Architecture A signed, self-contained token carrying claims, which a service can validate locally without calling the issuer.
JWKS JSON Web Key Set protocol Tokens & JWTs A published endpoint listing an issuer's current public keys, allowing resource servers to validate token signatures without a shared secret and to survive key rotation.
Key Rotation practice Key Management Periodically replacing a cryptographic key with a new one while retaining the old for decrypting existing data, so exposure from any single key is bounded.
Lateral Movement concept Zero Trust An attacker's progression from an initial foothold to more valuable systems, which is what turns a minor compromise into a breach.
Least Privilege concept Security Architecture Granting each identity only the permissions it needs, for only as long as it needs them.
Mass Assignment Auto-Binding, Over-Posting concept Secure API Design A vulnerability where a request body is bound directly to an internal object, allowing a caller to set fields the API never intended to expose.
Microsegmentation pattern Zero Trust Enforcing fine-grained network policy between individual workloads rather than between broad network zones, so a compromise cannot move laterally.
Multi-Factor Authentication MFA, 2FA practice Authentication Requiring evidence from more than one category — something you know, have, or are — so a single stolen credential is insufficient.
OAuth 2.0 protocol Security Architecture An authorisation framework that lets an application obtain scoped, delegated access to a resource without handling the user's credentials.
Object-Level Authorization BOLA, IDOR concept Authorization Checking that the caller is entitled to the specific record they requested, not merely that they may call the endpoint.
OpenID Connect OIDC protocol Security Architecture An identity layer over OAuth 2.0 that adds a signed ID token asserting who the user is and how they authenticated.
OWASP Risks OWASP Top Ten concept OWASP Risks The recurring application vulnerability classes — and the architectural decisions that make each one structurally unlikely.
OWASP Top Ten practice Security Architecture A periodically updated consensus list of the most critical web application security risks, useful as a design-review checklist.
Per-Record Tenancy Record-Level Ownership, Attribute-Based Tenancy, Cross-Org Data Ownership pattern Authorization Attaching the owning organisation to each record rather than to its container, so that data shared across tenant boundaries can still be governed, exported, retained and deleted according to the policy of whoe…
Permission Boundary concept Identity & Access Management A policy limiting the maximum permissions an identity can have, used so that the ability to create roles does not become the ability to grant unlimited privilege.
Personally Identifiable Information PII, Personal Data concept Security Architecture Data relating to an identifiable person — a category far broader than name and address, and the trigger for most regulatory obligation.
Phishing-Resistant Authentication Origin-Bound Authentication, Unphishable MFA pattern Authentication Authentication whose response cannot be replayed at a site other than the one it was produced for, because the authenticator signs the requesting origin rather than releasing a secret the user could pass on.
Policy Decision Point PDP, Authorization Service, Policy Engine pattern Zero Trust The component that evaluates an authorisation question and returns a decision, kept separate from the enforcement points that ask, so policy can change without redeploying every service.
Privacy Engineering practice Privacy Engineering Building systems whose privacy properties come from their structure rather than from policy documents.
Privilege Creep Access Accumulation, Permission Sprawl concept Identity & Access Management The gradual accumulation of access as people change roles without losing prior permissions, producing long-tenured staff with far more access than anyone intended.
Reachability Triage Exploitability Prioritisation, Vulnerability Relevance practice Supply Chain Security Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by severity score - which is what makes vulnerability manageme…
Refresh Token concept Tokens & JWTs A long-lived credential used solely to obtain new short-lived access tokens, so sessions can persist without long-lived access tokens circulating.
Relationship-Based Access Control ReBAC, Graph Authorization concept Authorization Expressing permissions as relationships between subjects and objects, with inheritance and group expansion as rules over the graph, rather than as attributes on rows.
Revocation Window Token Lifetime as SLA, Local Validation Trade concept Tokens & JWTs The period during which a revoked credential remains accepted, which for locally-validated tokens is exactly the token lifetime - the unavoidable price of removing the identity provider from the request path.
Role Explosion concept Authorization The proliferation of narrowly-scoped roles that occurs when RBAC is used to express rules that actually depend on context.
Secret Zero Bootstrapping Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager — the one secret that cannot itself be stored in the secret manager.
Secret Zero Problem concept Secrets Management The credential a workload needs in order to authenticate to the secret manager, which cannot itself be stored in the secret manager.
Secrets Management practice Security Architecture Storing, distributing, rotating and auditing credentials so that they never live in code, images or configuration files.
Secure API Design practice Secure API Design Building an interface where the safe path is the default and the unsafe one requires deliberate effort.