Plain words for the jargon.
Security has more acronyms than any trade has a right to. If someone has used one of these at you without explaining it, here is what they meant.
Testing
- Penetration test
- An authorised, simulated attack on a system to find weaknesses an attacker could exploit. Done by a person, using tools, within agreed rules.
- Vulnerability scan
- An automated check for known weaknesses. Fast and useful for coverage, but blind to anything that needs an understanding of how the application is meant to work.
- Black, grey and white box
- How much the tester is told in advance: nothing, credentials and a walkthrough, or full access including source code. Grey box is the usual best value for web applications.
- Rules of engagement
- The written agreement covering what may be tested, when, how hard, what is off-limits and who to call. Nothing starts without it.
- Retest
- A follow-up test confirming that fixes actually close the findings they were meant to close.
- Red team
- A longer, goal-based exercise simulating a real adversary across people, process and technology, often testing detection as much as prevention.
Web application flaws
- Broken access control
- Any way a user can do or see something they should not. Number one on the OWASP Top 10, and the most common serious finding in practice.
- IDOR / BOLA
- Insecure direct object reference, or broken object level authorisation: changing an ID in a request to reach someone else’s record.
- Injection
- Getting untrusted input interpreted as a command — SQL, operating system, template or LDAP. Less common than it was, still devastating when found.
- Cross-site scripting (XSS)
- Getting a site to run an attacker’s script in another user’s browser, usually to steal their session or act as them.
- SSRF
- Server-side request forgery: tricking a server into making requests on the attacker’s behalf, often to internal systems or cloud metadata services.
- Business-logic flaw
- Using the application exactly as built, in an order or combination nobody intended — stacking discounts, skipping approvals, racing limits.
- Race condition
- Two requests arriving close enough together that both pass a check meant to allow only one.
- Software supply chain
- The third-party libraries, packages, build tools and scripts your application depends on, and the risk that one of them is compromised.
Frameworks and standards
- OWASP
- The Open Worldwide Application Security Project, a non-profit that publishes the Top 10, ASVS, the Testing Guide and much of the field’s shared vocabulary.
- ASVS
- OWASP’s Application Security Verification Standard. Version 5.0 defines testable requirements at three levels of assurance.
- NIST CSF
- The NIST Cybersecurity Framework. Version 2.0 organises security into Govern, Identify, Protect, Detect, Respond and Recover.
- CIS Controls
- Eighteen prioritised security controls from the Center for Internet Security, grouped into three Implementation Groups by organisational maturity.
- ISO/IEC 27001
- The international standard for an information security management system. The 2022 edition has 93 Annex A controls.
- MITRE ATT&CK
- A public knowledge base of attacker tactics and techniques observed in real intrusions.
Audit and compliance
- SOC 2
- An attestation report by a CPA firm on a service organisation’s controls against the AICPA Trust Services Criteria.
- Type I and Type II
- A SOC 2 Type I report covers control design at a point in time. Type II covers how controls actually operated over a period, usually three to twelve months.
- PCI DSS
- The Payment Card Industry Data Security Standard, required of any business that stores, processes or transmits card data. Version 4.0.1 is current.
- Statement of Applicability
- The ISO 27001 document listing which Annex A controls apply to you, which do not, and why.
- Gap assessment
- A comparison of how things are done today against what a framework requires, producing a list of what is missing.
- Evidence
- The records an auditor examines to confirm a control works — tickets, logs, screenshots, approvals, configurations.
Scoring and reporting
- CVSS
- The Common Vulnerability Scoring System, a 0–10 severity score. Version 4.0 adds threat and supplemental metrics to the base score.
- CVE
- Common Vulnerabilities and Exposures: a public identifier for a specific known vulnerability in a specific product.
- CWE
- Common Weakness Enumeration: a catalogue of the types of mistake that cause vulnerabilities, such as CWE-639 for authorisation bypass through a user-controlled key.
- Proof of concept
- The minimum steps or request that demonstrate a finding is real, included so it can be reproduced and retested.
- Summary letter
- A short, shareable document confirming a test took place, its scope and dates, and the status of findings at retest — without the exploit detail.
- Risk register
- A living list of known risks, their owners, their likelihood and impact, and what is being done about each one.
Identity and infrastructure
- MFA
- Multi-factor authentication: requiring something beyond a password. Phishing-resistant MFA, such as passkeys or hardware keys, cannot be relayed by a fake login page.
- SSO
- Single sign-on: one identity provider vouching for a user across many applications. Convenient, and a single point of failure if misconfigured.
- Least privilege
- Giving each person and system only the access its job requires, and no more.
- Attack surface
- Everything an attacker could reach and try: domains, applications, APIs, cloud services, people.
- Zero trust
- An approach that verifies every request on its own merits instead of trusting anything inside the network.
- WAF
- Web application firewall: a filter in front of an application that blocks known attack patterns. Useful, and never a substitute for fixing the application.
Still not sure what you need?
Tell us who is asking you for proof — a customer, an auditor, an insurer — and we will tell you which of these actually applies.
Ask a tester
or email hello@penspycyber.com