Audit TrailA chronological, immutable record of activities that enables full traceability of actions in systems — essential for audits and forensic investigations.CVSSCommon Vulnerability Scoring System — a standardized 0–10 vulnerability scoring system classifying severity as Low, Medium, High, or Critical.DMARCDomain-based Message Authentication, Reporting and Conformance — an email authentication protocol that protects domains against unauthorized use (phishing, spoofing).IAMIdentity and Access Management — policies and technologies ensuring the right people have access only to the resources they need.MFAMulti-Factor Authentication — authentication using more than one factor: password + something you have (token, app) or something you are (biometrics).MITRE ATT&CKA global knowledge base mapping the tactics and techniques of real-world attackers. Essential for Threat Modeling and testing the effectiveness of detection controls.MTTRMean Time to Respond/Recover — average time to detect and respond to a security incident.PentestPenetration testing — an authorized simulation of a cyberattack to identify vulnerabilities before malicious actors do.SIEMSecurity Information and Event Management — a centralizing platform that collects, correlates, and analyzes security logs in real time, enabling threat detection.SOARSecurity Orchestration, Automation and Response — a platform that automates incident response by orchestrating workflows across different IT and security tools.Vulnerability ManagementA continuous, cyclical process of identifying, classifying, prioritizing, mitigating, and reporting vulnerabilities across the technology environment.Zero TrustA security paradigm that removes implicit trust from the network. It assumes the network is already compromised; every access request requires continuous verification of identity and context.EDR / XDREndpoint Detection and Response / Extended Detection and Response — solutions that monitor endpoints (EDR) or multiple layers — endpoint, network, email, cloud (XDR) — to detect and respond to threats in a correlated way.IOC (Indicator of Compromise)Forensic evidence (a file hash, malicious IP, domain, or signature) suggesting a system has been compromised, used for detection and incident response.TTP (Tactics, Techniques and Procedures)A description of a threat actor's behavior, from strategic goal (tactic) to specific execution steps (procedures) — the basis of the MITRE ATT&CK framework.RansomwareMalware that encrypts or blocks access to data and systems, demanding a ransom payment for restoration — one of the main fourth-party risks, as it can affect critical vendors and disrupt the supply chain.DLP (Data Loss Prevention)A set of technologies and policies that monitor, detect, and block the unauthorized transmission of sensitive data outside the organization.PAM (Privileged Access Management)Controls and tools dedicated to protecting, monitoring, and auditing accounts with elevated privileges (administrators, service accounts) — one of the preferred targets of attacks.SSO (Single Sign-On)A mechanism that allows a user to access multiple systems with a single set of credentials, centralizing and simplifying access control.WAF (Web Application Firewall)A protection layer that filters, monitors, and blocks malicious HTTP traffic between a web application and the internet, mitigating attacks such as SQL injection and XSS.