Cybersecurity glossary
Cybersecurity, EASM, DNS, and TLS glossary
These definitions connect protocol meaning with the ownership, detection, remediation, and monitoring decisions security and operations teams make in practice.
Attack surface
The complete set of points where an unauthorized person could try to interact with systems, data, identities, people, or processes. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should keep inventories current, remove unnecessary interfaces, and monitor material changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
External attack surface
The portion of an organization's attack surface that is reachable or observable from the public internet, including domains, addresses, applications, certificates, and services. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should discover from outside the network and validate ownership before prioritizing. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
EASM
External Attack Surface Management is the continuous discovery, validation, prioritization, and monitoring of internet-facing assets. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should connect discovery evidence to ownership, risk decisions, and continuous monitoring. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Asset discovery
The process of finding systems and relationships using known seeds and public technical evidence. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should preserve evidence and confidence so candidates can be verified. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
External asset inventory
A maintained record of internet-facing assets, ownership, purpose, evidence, importance, and lifecycle state. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should track unowned assets, last-seen timestamps, and monitoring coverage. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Shadow IT
Technology used without the normal visibility, ownership, procurement, or security controls of the organization. In an external attack-surface program, the concept matters because inventory quality determines what receives ownership, vulnerability review, and monitoring. Public evidence should be timestamped and treated as an observation until an accountable owner confirms the relationship and intended exposure.
Operationally, teams should compare external assets with identity, procurement, registrar, cloud, and CMDB records. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Subdomain
A DNS name beneath another domain, such as api.example.com beneath example.com. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should monitor creation, ownership, DNS targets, certificates, and retirement. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Domain name
A hierarchical human-readable identifier in DNS made of labels separated by dots. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should protect registrar access and monitor delegation and critical records. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DNS
The Domain Name System is the distributed naming system that maps names to records used by internet services. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should monitor authoritative availability, delegation, answers, response codes, and changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DNS resolver
Software or a service that obtains DNS answers for a client, often using caches and recursive queries. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should compare several resolvers when diagnosing inconsistent or stale answers. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Authoritative nameserver
A DNS server that publishes the official records for a zone it serves. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should monitor reachability, delegation consistency, response codes, and zone changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
A record
A DNS resource record that maps a name to an IPv4 address. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should check expected addresses, TTL, regional consistency, and unauthorized changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
AAAA record
A DNS resource record that maps a name to an IPv6 address. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should test IPv6 reachability separately because IPv4 health does not prove IPv6 health. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
CNAME
A DNS record that makes one name an alias of another canonical name. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should resolve the full chain and remove stale vendor targets or unnecessary depth. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
MX record
A DNS record that identifies mail exchangers for a domain and their preference values. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should verify intended mail providers, target resolution, and unauthorized changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
TXT record
A DNS record carrying text used by systems including domain verification and email authentication. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should validate syntax, ownership, duplication, and lifecycle of verification tokens. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
NS record
A DNS record identifying nameservers responsible for a zone or delegation. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should compare parent delegation with authoritative data and monitor provider changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DNS TTL
Time to live tells recursive resolvers how long they may cache a DNS answer. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should plan TTL changes before migrations and account for existing cache lifetime. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DNSSEC
DNS Security Extensions add signatures that let validating resolvers verify DNS data origin and integrity. DNS is distributed and cached, so a single answer is not always the whole operational picture. Useful investigation compares authoritative data, delegation, several recursive resolvers, TTL values, and recent change history before deciding whether a result is expected.
Operationally, teams should monitor DS, DNSKEY, signatures, expiration, and rollover behavior. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
SPF
Sender Policy Framework publishes which systems are authorized to send mail for a domain. Email authentication depends on DNS records and alignment with real sending systems. Policy should be introduced from an accurate sender inventory, validated with reports, and monitored because vendors, selectors, and sending paths change over time.
Operationally, teams should check syntax, DNS lookup limits, included providers, and alignment expectations. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DKIM
DomainKeys Identified Mail lets senders sign messages and publish verification keys in DNS. Email authentication depends on DNS records and alignment with real sending systems. Policy should be introduced from an accurate sender inventory, validated with reports, and monitored because vendors, selectors, and sending paths change over time.
Operationally, teams should monitor selector records, key rotation, key size, and signing coverage. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
DMARC
DMARC lets domain owners publish alignment, reporting, and handling policy for messages using their visible From domain. Email authentication depends on DNS records and alignment with real sending systems. Policy should be introduced from an accurate sender inventory, validated with reports, and monitored because vendors, selectors, and sending paths change over time.
Operationally, teams should review reports and sender alignment before moving toward enforcement. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
TCP
Transmission Control Protocol provides reliable, ordered byte streams between endpoints identified by addresses and ports. Network reachability is only one layer of service health. Teams should relate an address and port to an owner, expected protocol, authentication controls, patching path, and business purpose before deciding whether exposure is acceptable.
Operationally, teams should monitor connection success, latency, resets, and timeouts for required services. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
UDP
User Datagram Protocol sends independent datagrams without TCP-style connection establishment or delivery guarantees. Network reachability is only one layer of service health. Teams should relate an address and port to an owner, expected protocol, authentication controls, patching path, and business purpose before deciding whether exposure is acceptable.
Operationally, teams should use protocol-aware checks because an absent response may have several meanings. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Port
A numeric transport-layer identifier used to direct TCP or UDP traffic to a service on a host. Network reachability is only one layer of service health. Teams should relate an address and port to an owner, expected protocol, authentication controls, patching path, and business purpose before deciding whether exposure is acceptable.
Operationally, teams should compare public reachability with approved exposure and ownership. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Exposed service
A network service reachable from the public internet on an address and port. Network reachability is only one layer of service health. Teams should relate an address and port to an owner, expected protocol, authentication controls, patching path, and business purpose before deciding whether exposure is acceptable.
Operationally, teams should identify the protocol safely, validate purpose, restrict unnecessary access, and monitor changes. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
HTTP
Hypertext Transfer Protocol defines request and response semantics used by websites, APIs, and many internet services. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should monitor status, headers, content expectations, redirects, and latency. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
HTTPS
HTTP carried over TLS, providing transport encryption, integrity, and server authentication when validation succeeds. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should monitor TCP, TLS, certificate, redirect, and application layers together. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
HTTP status code
A three-digit response code communicating the result of an HTTP request, such as 200, 404, 502, or 503. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should alert on meaningful transitions and keep endpoint-specific expectations. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
TLS
Transport Layer Security authenticates endpoints and protects application data in transit using negotiated cryptography. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should monitor versions, handshake success, certificates, and endpoint compatibility. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
SSL
Secure Sockets Layer is the obsolete predecessor to TLS; the term remains common shorthand for HTTPS certificates. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should disable obsolete SSL protocols and evaluate modern TLS behavior instead. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
TLS handshake
The exchange that negotiates security parameters, authenticates the server, derives shared keys, and starts encrypted traffic. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should measure success, latency, negotiated version, and certificate validation. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Digital certificate
A signed data structure binding an identity such as a DNS name to a public key and validity period. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should inventory certificates, validate hostname and chain, and monitor expiration. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Certificate authority
An organization or internal trust service that signs certificates under a defined validation and policy framework. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should limit authorized issuers where possible and monitor unexpected issuance. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Certificate chain
The signature path from a server certificate through intermediate authorities to a trusted root. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should verify every endpoint serves the required intermediates and valid signatures. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Certificate transparency
Public append-only logs of publicly trusted certificate issuance used for accountability and discovery. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should monitor owned domains for unexpected certificates and new hostnames. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Wildcard certificate
A certificate containing a wildcard name such as *.example.com that covers a defined set of one-label subdomains. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should understand coverage limits and protect the broadly reusable private key. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Self-signed certificate
A certificate signed by its own private key rather than a separately trusted certificate authority. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should use only with an explicit trust model and avoid presenting it to ordinary public clients. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Hostname validation
The client check that the requested DNS name matches a certificate Subject Alternative Name. TLS reliability depends on every termination point serving compatible protocol settings and the correct certificate chain. CDN, load balancer, proxy, and origin deployments may differ, so monitoring should test the public hostname and path users actually reach.
Operationally, teams should test every public hostname and SNI path, not just the certificate dates. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
HSTS
HTTP Strict Transport Security is a response policy telling browsers to use secure connections for a host for a defined period. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should validate max-age, subdomain scope, preload implications, and HTTPS readiness. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Content Security Policy
CSP is a browser policy that restricts which sources may provide scripts, styles, frames, connections, and other resources. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should start with an inventory or report-only rollout and avoid unsafe broad exceptions. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Security header
An HTTP response header that communicates a browser security or privacy policy. Browser and HTTP controls work as part of a wider application architecture. A header or status code should be interpreted with redirects, TLS, caching, proxy behavior, and application requirements rather than scored as an isolated checkbox.
Operationally, teams should evaluate policy quality and application compatibility rather than presence alone. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Uptime monitoring
Scheduled checks that determine whether a selected service remains reachable and meets an expected response condition. Monitoring is most useful when the expected state and owner are defined in advance. Alerts should include evidence, avoid repeated noise, and distinguish a local observation from a confirmed incident using retries or independent checks where appropriate.
Operationally, teams should use multiple evidence layers and alert on confirmed state transitions. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Synthetic monitoring
Automated requests or scripted interactions that simulate user or service behavior from controlled locations. Monitoring is most useful when the expected state and owner are defined in advance. Alerts should include evidence, avoid repeated noise, and distinguish a local observation from a confirmed incident using retries or independent checks where appropriate.
Operationally, teams should choose checks that represent critical public paths and dependencies. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Availability
The proportion of time a service meets its defined usable-state criteria during a measurement period. Monitoring is most useful when the expected state and owner are defined in advance. Alerts should include evidence, avoid repeated noise, and distinguish a local observation from a confirmed incident using retries or independent checks where appropriate.
Operationally, teams should define exclusions, regions, confirmation rules, and partial-degradation handling. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Latency
Elapsed time for an operation such as DNS resolution, TCP connection, TLS handshake, or HTTP response. Monitoring is most useful when the expected state and owner are defined in advance. Alerts should include evidence, avoid repeated noise, and distinguish a local observation from a confirmed incident using retries or independent checks where appropriate.
Operationally, teams should track component timing and percentiles instead of relying only on averages. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
False positive
A result indicating a problem that does not exist under the intended scope or context. Security assessment results need scope, evidence, confidence, and business context. No single technique proves complete safety, so mature programs combine discovery, scanning, testing, configuration review, monitoring, and accountable remediation.
Operationally, teams should preserve evidence, confidence, and owner feedback to improve precision. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
False negative
A missed problem that the assessment or monitor should have detected. Security assessment results need scope, evidence, confidence, and business context. No single technique proves complete safety, so mature programs combine discovery, scanning, testing, configuration review, monitoring, and accountable remediation.
Operationally, teams should measure coverage, test detection paths, and use complementary evidence sources. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Vulnerability scanning
Automated evaluation of known assets for software, configuration, or behavior associated with known weaknesses. Security assessment results need scope, evidence, confidence, and business context. No single technique proves complete safety, so mature programs combine discovery, scanning, testing, configuration review, monitoring, and accountable remediation.
Operationally, teams should maintain accurate scope and validate findings before remediation decisions. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Penetration testing
An authorized, time-bound security assessment that attempts to demonstrate exploitable paths and impact under agreed rules. Security assessment results need scope, evidence, confidence, and business context. No single technique proves complete safety, so mature programs combine discovery, scanning, testing, configuration review, monitoring, and accountable remediation.
Operationally, teams should use current asset discovery to define scope and track remediation after the engagement. A useful record includes the observed value, source, timestamp, expected state, accountable owner, and the action taken when the state changes.
This term should not be treated as an isolated score. Its importance depends on how the system is used, whether the exposure is intentional, which users or data depend on it, and what compensating controls are present.
For detection and remediation, begin with evidence from the relevant protocol or system rather than an unverified label. Confirm the observation from another suitable vantage point, compare it with the documented baseline, identify the owner, record the intended change, and repeat the same check afterward. Monitoring should alert on meaningful state changes while retaining enough context to distinguish a real regression from transient behavior.
Authoritative technical references
- RFC 1034: Domain Names - Concepts and Facilities
- RFC 1035: Domain Names - Implementation and Specification
- RFC 8446: The Transport Layer Security Protocol Version 1.3
- RFC 7489: Domain-based Message Authentication, Reporting, and Conformance
- RFC 7208: Sender Policy Framework
- RFC 6376: DomainKeys Identified Mail Signatures
- RFC 6797: HTTP Strict Transport Security
- RFC 9110: HTTP Semantics
- Content Security Policy Level 3
- RFC 9162: Certificate Transparency Version 2.0