Glossary

The Terms Shaping Modern Identity Security

Search

A

Access Certification

Access Certification Campaign

Access Control

Access Control Framework

Access Control Policy

Access Creep

Access Deprovisioning

Access Drift

Access Governance

Access Governance Framework

Access Lifecycle Management (ALM)

Access Management

Access Provisioning

Access Request

Access Review

Access Review Campaign

Access Risk Management

Access Sprawl

Access Tokens

Access Transparency

Account Lockout Policy

Account Takeover (ATO)

Account Takeover Prevention

Active Directory Security

Adaptive Authentication

Adaptive MFA

AI Identity Impersonation Risk

AI-Driven Access Decisions

Anomalous Access Detection

API Identity Security

API Key Management

API Security

Application-Level Identity

Asymmetric Encryption

Attack Surface Management

Attribute-Based Access Control (ABAC)

Audit Automation

Audit Compliance

Audit Evidence

Audit Logs

Audit Readiness

Audit Trail

Authentication

Automated Access Reviews

Automated Deprovisioning

Automated Provisioning

Autonomous Identity Governance

B

B2B Identity Governance

Bastion Host

Behavioral Analytics

Behavioral Biometrics

Biometric Authentication

Biometric Liveness Detection

Breach Detection

Brute Force Attack

C

Certificate Authority (CA)

Certificate Lifecycle Management

Certificate-Based Authentication

CI/CD Pipeline Security

Cloud Access Security Broker (CASB)

Cloud Entitlement Sprawl

Cloud Identity

Cloud Identity Governance

Cloud Infrastructure Entitlement Management (CIEM)

Cloud PAM

Cloud Privileged Access Management

Cloud Security Posture Management (CSPM)

Compliance Automation

Compliance Framework

Compliance Management

Compliance Reporting

Conditional Access

Consent Management

Container Identity

Context-Aware Authorization

Continuous Authentication

Continuous Compliance

Continuous Control Monitoring

Continuous Identity Verification

Continuous Monitoring

Continuous Privilege Validation

Continuous Threat Exposure Management (CTEM)

Credential Deception Technology

Credential Exposure

Credential Management

Credential Rotation

Credential Stuffing

Credential Theft

Credential Vaulting

Cross-Border Identity Compliance

Cross-Site Scripting (XSS)

Cross-Tenant Access Risk

Cryptographic Agility

Cryptographic Identity Binding

Customer Identity and Access Management (CIAM)

CVE (Common Vulnerabilities and Exposures)

Cybersecurity Mesh Architecture (CSMA)

D

Data Breach

Data Classification

Data Governance

Data Loss Prevention (DLP)

Data Privacy

Data Residency

Data Security

Data Security Posture Management (DSPM)

DDoS Protection

Decentralized Identifiers (DIDs)

Decentralized Identity (DID)

Deception Technology

Defense in Depth

Delegated Administration

Deny by Default

Device Authentication

DevSecOps Identity Integration

Digital Certificate

Digital Identity

Digital Identity Verification

Digital Identity Wallet

Digital Signature

Directory Services

DMZ (Demilitarized Zone)

DPDPA Compliance

Dynamic Access Control

E

Electronic Signature

Encryption Key Management

Endpoint Detection and Response (EDR)

Entitlement Creep

Entitlement Intelligence

Entitlement Management

Entitlement Review

Ephemeral Credentials

Exposure Management

F

Fast Identity Online (FIDO)

Federated Identity

Federated Identity Management

FIDO2 / WebAuthn

G

General Data Protection Regulation (GDPR)

GitOps Identity Controls

Governance Automation

Governance Framework

Governance, Risk, and Compliance (GRC)

Governance, Risk, and Compliance (GRC)

H

Hardware Security Module (HSM)

Hash Function

HMAC (Hash-Based Message Authentication Code)

Human vs Non-Human Identity

Hybrid Identity

I

IaC Security Posture

Identity Analytics

Identity and Access Management (IAM)

Identity Assurance

Identity Assurance Level (IAL)

Identity Attack Path Analysis

Identity Attack Surface

Identity Blast Radius

Identity Choreography

Identity Compliance

Identity Correlation

Identity Data Lineage

Identity Fabric

Identity Fabric Architecture

Identity Federation

Identity Governance (IGA)

Identity Governance and Administration (IGA)

Identity Graph

Identity Honeytokens

Identity Intelligence

Identity is the New Perimeter

Identity Lifecycle Management

Identity Mesh

Identity Orchestration

Identity Posture

Identity Proofing

Identity Provider (IdP)

Identity Resilience

Identity Risk Management

Identity Risk Scoring

Identity Security

Identity Security Posture Management (ISPM)

Identity Segmentation

Identity Sprawl

Identity Threat Detection

Identity Threat Detection and Response (ITDR)

Identity Threat Intelligence

Identity Verification

Identity-Based Access Control

Identity-Centric Security

Implicit Deny

Incident Response

Indicators of Compromise (IOC)

Infrastructure Identity

Insider Threat

Insider Threat Detection

Intrusion Prevention System (IPS)

J

Joiner-Mover-Leaver (JML)

JSON Web Token (JWT)

Jump Server

Just-in-Time (JIT) Access

Just-in-Time Elevation

Just-in-Time Provisioning

K

Kerberos Authentication

Key Management

Know Your Customer (KYC)

Knowledge-Based Authentication (KBA)

L

Lateral Movement

Lateral Movement Detection

LDAP (Lightweight Directory Access Protocol)

Least Privilege

Least Privilege Access

Least Privilege Enforcement

Lifecycle Automation

M

Machine Identity Management

Machine-to-Machine Authentication

Managed Identity

Microsegmentation

MITRE ATT&CK Framework

Multi-Factor Authentication (MFA)

Mutual Authentication

Mutual TLS (mTLS)

N

Network Detection and Response (NDR)

Network Segmentation

NIST SP 800-63

Non-Human Identity (NHI)

Non-Human Identity Governance

Non-Repudiation

O

OAuth 2.0

OAuth 2.0 Security

OAuth App Governance

One-Time Password (OTP)

OpenID Connect (OIDC)

Orphan Accounts

Out-of-Band Authentication

OWASP Top 10

P

Passkeys

Passkeys and FIDO2

Password Management

Password Policy

Password Spraying

Passwordless Authentication

Patch Management

Peer Group Analytics

Personally Identifiable Information (PII)

Phishing Attack

Phishing Detection

Phishing-Resistant Authentication

Policy Enforcement

Policy Management

Policy-as-Code

Post-Quantum Authentication

Post-Quantum Cryptography (PQC)

Presentation Attack Detection (PAD)

Principle of Least Privilege

Privacy-Preserving Authentication

Privilege Creep

Privilege Escalation

Privileged Access Management (PAM)

Privileged Account

Privileged Cloud Access

Privileged Identity Management (PIM)

Privileged Session Management

Public Key Infrastructure (PKI)

Q

Quantum Computing

Quantum Cryptography

R

Risk Assessment

Risk Management

Risk-Based Access

Risk-Based Authentication

Role Certification

Role Engineering

Role Governance

Role Management

Role Mining (LP Page link )

Role-Based Access Control (RBAC)

Role-Based Provisioning

Root Access

Root Privileges

Runtime Access Controls

Runtime Application Self-Protection (RASP)

S

SaaS Governance

SaaS Identity Sprawl

SaaS Security Posture Management (SSPM)

SAML

SAP GRC Access Control

Secrets Management

Secrets Rotation Automation

Secure Access Service Edge (SASE)

Secure Email Gateway

Security Information and Event Management (SIEM)

Security Operations Center (SOC)

Security Service Edge (SSE)

Segregation of Duties (SoD)

Self-Sovereign Identity (SSI)

Separation of Duties

Service Account

Service Account Governance

Service Provider (SP)

Session Hijacking

Session Management

Session Recording

Shadow IT

Single Sign-On (SSO)

SOC 2 Compliance

Social Engineering

Software-Defined WAN (SD-WAN)

SPIFFE / SPIRE

SQL Injection

SSH Key Management

SSL/TLS Certificate

Step-Up Authentication

Strong Authentication

Supply Chain Identity Risk

Synthetic Identity Fraud

T

Tenant Isolation

Third-Party Access Management

Third-Party Risk Management (TPRM)

Threat Detection

Threat Detection and Response

Threat Intelligence

Time-Based One-Time Password (TOTP)

Token Management

Token Theft Prevention

Token-Based Authentication

Tokenized Identity

Transport Layer Security (TLS)

Trust Score

Two-Factor Authentication (2FA)

W

Web Application and API Protection (WAAP)

Web Application Firewall (WAF)

WebAuthn

Workforce Identity Federation

Workload Identity

Workload Identity Federation

Z

Zero Standing Privilege

Zero Trust Architecture

Zero Trust Identity

Zero Trust Network Access (ZTNA)

Zero Trust Security

Zero-Day Vulnerability

ZKP (Zero-Knowledge Proof)

GET A PERSONALIZED DEMO

Ready to see Tech Prescient in action?

“As an industrial, securing capacity and optimizing budget are key. In that perspective, you are looking for a transport”

quote
Murli Ramsunder

Murli Ramsunder

Senior Architect, Vonage