Security Acronyms

This glossary provides a quick reference for common security acronyms and terms used in modern cybersecurity frameworks and tools. Use this guide to better understand security documentation, compliance requirements, and technical discussions related to application and cloud security.

AICPA SOC 2 - System and Organization Controls 2 arrow-up-right

CI/CD Pipeline Securityarrow-up-right

CVE - Common Vulnerabilities and Exposuresarrow-up-right

ISO 27001:2022arrow-up-right

ASPM - Application Security Posture Management

CSPM - Cloud Security Posture Management

SAST - Static Application Security Testingarrow-up-right

SCA - Software Composition Analysisarrow-up-right

DAST - Dynamic Application Security Testingarrow-up-right

EASM - External Attack Surface Management

IaC - Infrastructure as Codearrow-up-right

CNAPP - Cloud-Native Application Protection Platform

DSPM - Data security posture management

SIEM - Security Information and Event Management

RASP - Runtime Application Self Protection

WAF - Web App Firewall

GRC - Governance Risk & Compliance

MDR - Managed Detection Response

SBOM - Software Bill of Materialsarrow-up-right

NIS2 - Network and Information Security Directive 2

OWASP - Open Worldwide Application Security Projectarrow-up-right

XSS Vulnerabilitiesarrow-up-right

Last updated

Was this helpful?