Plain words for the jargon.

Security has more acronyms than any trade has a right to. If someone has used one of these at you without explaining it, here is what they meant.

01

Testing

Penetration test
An authorised, simulated attack on a system to find weaknesses an attacker could exploit. Done by a person, using tools, within agreed rules.
Vulnerability scan
An automated check for known weaknesses. Fast and useful for coverage, but blind to anything that needs an understanding of how the application is meant to work.
Black, grey and white box
How much the tester is told in advance: nothing, credentials and a walkthrough, or full access including source code. Grey box is the usual best value for web applications.
Rules of engagement
The written agreement covering what may be tested, when, how hard, what is off-limits and who to call. Nothing starts without it.
Retest
A follow-up test confirming that fixes actually close the findings they were meant to close.
Red team
A longer, goal-based exercise simulating a real adversary across people, process and technology, often testing detection as much as prevention.
02

Web application flaws

Broken access control
Any way a user can do or see something they should not. Number one on the OWASP Top 10, and the most common serious finding in practice.
IDOR / BOLA
Insecure direct object reference, or broken object level authorisation: changing an ID in a request to reach someone else’s record.
Injection
Getting untrusted input interpreted as a command — SQL, operating system, template or LDAP. Less common than it was, still devastating when found.
Cross-site scripting (XSS)
Getting a site to run an attacker’s script in another user’s browser, usually to steal their session or act as them.
SSRF
Server-side request forgery: tricking a server into making requests on the attacker’s behalf, often to internal systems or cloud metadata services.
Business-logic flaw
Using the application exactly as built, in an order or combination nobody intended — stacking discounts, skipping approvals, racing limits.
Race condition
Two requests arriving close enough together that both pass a check meant to allow only one.
Software supply chain
The third-party libraries, packages, build tools and scripts your application depends on, and the risk that one of them is compromised.
03

Frameworks and standards

OWASP
The Open Worldwide Application Security Project, a non-profit that publishes the Top 10, ASVS, the Testing Guide and much of the field’s shared vocabulary.
ASVS
OWASP’s Application Security Verification Standard. Version 5.0 defines testable requirements at three levels of assurance.
NIST CSF
The NIST Cybersecurity Framework. Version 2.0 organises security into Govern, Identify, Protect, Detect, Respond and Recover.
CIS Controls
Eighteen prioritised security controls from the Center for Internet Security, grouped into three Implementation Groups by organisational maturity.
ISO/IEC 27001
The international standard for an information security management system. The 2022 edition has 93 Annex A controls.
MITRE ATT&CK
A public knowledge base of attacker tactics and techniques observed in real intrusions.
04

Audit and compliance

SOC 2
An attestation report by a CPA firm on a service organisation’s controls against the AICPA Trust Services Criteria.
Type I and Type II
A SOC 2 Type I report covers control design at a point in time. Type II covers how controls actually operated over a period, usually three to twelve months.
PCI DSS
The Payment Card Industry Data Security Standard, required of any business that stores, processes or transmits card data. Version 4.0.1 is current.
Statement of Applicability
The ISO 27001 document listing which Annex A controls apply to you, which do not, and why.
Gap assessment
A comparison of how things are done today against what a framework requires, producing a list of what is missing.
Evidence
The records an auditor examines to confirm a control works — tickets, logs, screenshots, approvals, configurations.
05

Scoring and reporting

CVSS
The Common Vulnerability Scoring System, a 0–10 severity score. Version 4.0 adds threat and supplemental metrics to the base score.
CVE
Common Vulnerabilities and Exposures: a public identifier for a specific known vulnerability in a specific product.
CWE
Common Weakness Enumeration: a catalogue of the types of mistake that cause vulnerabilities, such as CWE-639 for authorisation bypass through a user-controlled key.
Proof of concept
The minimum steps or request that demonstrate a finding is real, included so it can be reproduced and retested.
Summary letter
A short, shareable document confirming a test took place, its scope and dates, and the status of findings at retest — without the exploit detail.
Risk register
A living list of known risks, their owners, their likelihood and impact, and what is being done about each one.
06

Identity and infrastructure

MFA
Multi-factor authentication: requiring something beyond a password. Phishing-resistant MFA, such as passkeys or hardware keys, cannot be relayed by a fake login page.
SSO
Single sign-on: one identity provider vouching for a user across many applications. Convenient, and a single point of failure if misconfigured.
Least privilege
Giving each person and system only the access its job requires, and no more.
Attack surface
Everything an attacker could reach and try: domains, applications, APIs, cloud services, people.
Zero trust
An approach that verifies every request on its own merits instead of trusting anything inside the network.
WAF
Web application firewall: a filter in front of an application that blocks known attack patterns. Useful, and never a substitute for fixing the application.

Still not sure what you need?

Tell us who is asking you for proof — a customer, an auditor, an insurer — and we will tell you which of these actually applies.