Knowledge Base
The Practitioner's Cybersecurity Glossary.
Enterprise security and technology terms — defined by Paxanimi practitioners who have implemented, assessed, and operated these concepts at enterprise scale. Not theoretical. Not vendor-sponsored.
Cybersecurity
10 termsZero Trust Architecture
A security model that eliminates implicit trust and continuously verifies every user, device, and connection.
Penetration Testing
Authorized simulated attacks on systems, networks, or applications to identify exploitable vulnerabilities before adversaries do.
SOC-as-a-Service
A managed security operations center that provides 24/7 threat monitoring, detection, and response without the cost of building in-house.
Threat Intelligence
Analyzed, contextualized data about threat actors, their tactics, and the indicators used to detect their activity.
Incident Response
The structured process for detecting, containing, eradicating, and recovering from a cybersecurity breach.
Red Team Assessment
A full-scope adversary simulation that tests an organization's people, processes, and technology as a unified system.
Attack Surface Management
Continuous discovery, inventory, and risk monitoring of all external-facing assets that an attacker could target.
MTTD / MTTR
Mean Time to Detect and Mean Time to Respond — the two most important metrics for measuring security operations effectiveness.
DevSecOps
The practice of integrating security testing and controls into the software development lifecycle from the first sprint.
SAST / DAST
Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST) — the two primary automated approaches to finding application vulnerabilities.
Compliance
9 termsCMMC (Cybersecurity Maturity Model Certification)
The DoD's mandatory cybersecurity framework for defense contractors handling Controlled Unclassified Information (CUI).
SOC 2 Type II
An independent audit report verifying that a technology company's security controls operated effectively over a period of time.
FedRAMP
The U.S. federal government's standardized security authorization program for cloud service providers.
HIPAA Security Rule
Federal regulations requiring healthcare organizations to protect the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI).
HITRUST CSF
A comprehensive, certifiable security framework designed specifically for healthcare organizations that incorporates HIPAA, NIST, ISO 27001, and other standards.
NERC CIP
Mandatory cybersecurity standards for bulk electric system owners, operators, and users in North America.
PCI DSS
The Payment Card Industry Data Security Standard — mandatory security requirements for any organization that stores, processes, or transmits cardholder data.
NIST Cybersecurity Framework
A voluntary but widely adopted framework organizing cybersecurity activities around five functions: Identify, Protect, Detect, Respond, and Recover.
ISO 27001
The international standard for information security management systems (ISMS) — certifiable and globally recognized.
Cloud Security
6 termsCSPM (Cloud Security Posture Management)
Automated tools that continuously monitor cloud infrastructure for misconfigurations and compliance violations.
CIEM (Cloud Infrastructure Entitlement Management)
Tools that discover and right-size excessive permissions in cloud environments to enforce least-privilege at scale.
Cloud-Native Architecture
An approach to building and running applications that fully exploits cloud computing — using microservices, containers, dynamic orchestration, and continuous delivery.
Kubernetes Security
Security hardening, policy enforcement, and runtime protection for container orchestration environments.
Cloud IAM
Identity and Access Management in cloud environments — controlling who and what can access which cloud resources.
Shared Responsibility Model
The division of security responsibilities between a cloud provider and the customer — a framework that defines who owns what in cloud security.
AI Security
4 termsLLM Security
Security practices, threat modeling, and controls for applications built on Large Language Models.
Prompt Injection
An attack that manipulates an AI system's behavior by embedding malicious instructions in its input.
AI Red Teaming
Structured adversarial testing of AI systems to identify safety, security, and reliability failures before deployment.
MLOps
The practice of deploying, monitoring, and operating machine learning models in production reliably and efficiently.
Consulting
4 termsDigital Transformation
The strategic reimagining and technical overhaul of how an organization delivers value using digital technology.
Technology Strategy
A multi-year plan aligning technology investments and architecture decisions to business outcomes and competitive positioning.
Change Management
The structured approach to transitioning individuals, teams, and organizations from a current state to a desired future state.
Operating Model Design
The design of how an organization structures its people, processes, technology, and governance to deliver its strategy.
All Terms
Complete Glossary
Need help implementing what you've learned?
Paxanimi's practitioners don't just define these concepts — we deploy them in enterprise environments.