# Security Acronyms

This glossary provides a quick reference for common security acronyms and terms used in modern cybersecurity frameworks and tools. Use this guide to better understand security documentation, compliance requirements, and technical discussions related to application and cloud security.

[AICPA SOC 2 - System and Organization Controls 2 ](https://www.aikido.dev/glossary/aicpa-soc-2)

[CI/CD Pipeline Security](https://www.aikido.dev/glossary/ci-cd-pipeline-security)

[CVE - Common Vulnerabilities and Exposures](https://www.aikido.dev/glossary/common-vulnerabilities-and-exposures-cve)

[ISO 27001:2022](https://www.aikido.dev/glossary/iso-27001-2022)

ASPM - Application Security Posture Management

CSPM - Cloud Security Posture Management

[SAST - Static Application Security Testing](https://www.aikido.dev/glossary/static-application-security-testing-sast)

[SCA - Software Composition Analysis](https://www.aikido.dev/glossary/software-composition-analysis-sca)

[DAST - Dynamic Application Security Testing](https://www.aikido.dev/glossary/dynamic-application-security-testing-dast)

EASM - External Attack Surface Management

[IaC - Infrastructure as Code](https://www.aikido.dev/glossary/infrastructure-as-code-iac-scanning)

CNAPP - Cloud-Native Application Protection Platform

DSPM - Data security posture management

SIEM - Security Information and Event Management

RASP - Runtime Application Self Protection

WAF - Web App Firewall

GRC - Governance Risk & Compliance

MDR - Managed Detection Response

[SBOM - Software Bill of Materials](https://www.aikido.dev/glossary/software-bill-of-materials-sbom)

NIS2 - Network and Information Security Directive 2

[OWASP - Open Worldwide Application Security Project](https://www.aikido.dev/glossary/owasp-top-10)

[XSS Vulnerabilities](https://www.aikido.dev/glossary/xss-vulnerabilities)
