Automated joiner/mover/leaver workflows from HR to directory to apps; eliminates orphaned accounts and entitlement creep.
๐ Network & Edge Security
๐ก๏ธ Zero Trust
โNever trust, always verify.โ Enforce identity, device posture, and least privilege per session and resource.
๐ ZTNA
Zero Trust Network Access replaces flat VPNs with app-level access brokers for remote and third-party users.
๐ง SASE
Secure Access Service Edge converges SD-WAN with cloud security (Secure Web Gateway, Cloud Access Security Broker, Firewall-as-a-Service, ZTNA).
๐ช NAC
Network Access Control validates device health and role before granting switch/AP port access.
๐งฉ Microsegmentation
Workload-level (Layer 3โ7) policies to contain lateral movement across data centers and clouds.
๐ก๏ธ Threat Protection
๐ฅ Firewalls / IPS / IDS
Stateful inspection, Intrusion Prevention/Detection Systems for signature and behavior-based blocking.
๐ฅ DDoS Protection
Distributed Denial of Service scrubbing and blackholing to keep Internet-facing services reachable.
๐ WAF / Bot Management
Web Application Firewall for OWASP Top 10; detect and mitigate credential-stuffing, scraping, and automated fraud.
๐ง Email Security
Anti-phishing, malware scanning, URL isolation, and protection against business email compromise.
๐ Email Authentication (DMARC/SPF/DKIM)
Enforce sender authenticity with Domain-based Message Authentication, Reporting & Conformance, Sender Policy Framework, and DomainKeys Identified Mail.
๐ Detection & Response
๐ป EDR / MDR / XDR
Endpoint Detection & Response, Managed Detection & Response, Extended Detection & Response for correlated endpoint, network, and cloud telemetry.
๐ SIEM / SOAR
Security Information & Event Management + Security Orchestration, Automation, and Response to centralize logs, correlate events, and automate playbooks.
๐ง NDR
Network Detection & Response analyzes east-west flows and detects beaconing, exfiltration, and anomalous patterns.
๐ Data Security
๐ค DLP
Data Loss Prevention at endpoints, email, and cloud/SaaS to prevent sensitive data exfiltration.
๐ Encryption
At rest and in transit: disk/file/database; TLS for services; key hierarchies and rotation policies.
๐ Tokenization
Replace Personally Identifiable Information (PII) and Primary Account Numbers (PAN) with surrogates to reduce audit scope.
๐ชช PKI
Public Key Infrastructure for certificate issuance, lifecycle, and trust stores (mTLS, device certs).
๐๏ธ Key Management / HSM
Central key vaults and Hardware Security Modules for cryptographic root of trust and FIPS compliance.
๐ Resilience & Compliance
๐ฆ Backup Immutability
Write-once protections and air-gaps to ensure ransomware-resistant recovery.
๐จ Incident Response
Triage, containment, forensics, and post-incident remediation with executive communications.
๐ Tabletop Exercises
Simulated incidents to validate playbooks, roles, and cross-team coordination.
๐ BCP/DR
Business Continuity Planning / Disaster Recovery: governance for Recovery Point Objective (RPO) and Recovery Time Objective (RTO) with tested failover.
๐๏ธ Standards & Regulations (spelled out and explained)
๐ฅ HIPAA
Health Insurance Portability and Accountability Act: safeguards for Protected Health Information (PHI) in healthcare.
๐ณ PCI DSS
Payment Card Industry Data Security Standard: requirements to protect cardholder data.
๐ SOC 2
System and Organization Controls 2: attestation for security, availability, processing integrity, confidentiality, and privacy.
๐ ISO 27001
International Information Security Management System (ISMS) standard; risk-based controls and continuous improvement.
๐ก๏ธ CMMC
Cybersecurity Maturity Model Certification for U.S. Department of Defense supply chain.
๐๏ธ FedRAMP
Federal Risk and Authorization Management Program: standardized security for U.S. government cloud services.
๐ข NIST
National Institute of Standards and Technology frameworks (CSF, SP 800-53/171) for controls and risk management.
๐ GDPR / CCPA
General Data Protection Regulation (EU) / California Consumer Privacy Act (US-CA): data rights, transparency, and lawful processing.
๐ข Cybersecurity & Data Centers
Security controls extend into data centers where compute and storage run:
๐ข Colocation
Carrier-neutral facilities with access control, video, cages/racks, and redundant power/cooling. See Colocation.
๐ Hyperscale
Cloud provider data centers (AWS/Azure/GCP) with native security services. See Hyperscale Data Centers.
โก Edge
Low-latency sites near users/things; secure IoT and real-time analytics. See Edge Data Centers.
๐งฑ Modular
Prefabricated blocks that inherit policy at deploy time. See Modular Data Centers.
๐ฑ Green
Renewable-powered facilities with audited PUE; security + sustainability. See Green Data Centers.
Open a term for a concise explanation of language used on this page.
โฑ๏ธLatency
The time it takes data to travel between two points. Lower latency improves voice, video meetings, cloud applications, gaming, and other real-time services.
๐SD-WAN
Software-defined wide area networking. It manages multiple connections and chooses paths based on application needs, performance, and policy to improve resilience and control.
๐VPN
A virtual private network creates an encrypted connection across another network, commonly allowing remote users or offices to access private resources securely.
โ๏ธCloud Computing
Computing resourcesโsuch as applications, servers, storage, or databasesโdelivered from remote infrastructure and scaled as requirements change.
๐งฐSoftware as a Service (SaaS)
Software accessed as an online service instead of being installed and maintained entirely on the customerโs own computers or servers.
โป๏ธDisaster Recovery (DRaaS)
A plan and service for restoring applications, data, and operations after an outage or disruption. DRaaS provides recovery infrastructure through a managed cloud service.
๐ก๏ธCybersecurity
The practices and controls used to protect identities, devices, networks, applications, and data from unauthorized access, disruption, or manipulation.
๐ซZero Trust
A security model that does not automatically trust a user or device because of its location. Access is continuously verified and limited to what is necessary.