Every term of art this book uses, defined briefly and precisely, with the ones that mean different things to different authorities flagged before they cost you an hour at 03:00.
Who needs this: everyone who reads any other page of this book | Read time: 14 min | Verified as of: 5 September 2026 | Owns: definitions only — procedures live in the chapters each entry names
Incidents rarely go sideways on tooling. They go sideways on a word. Legal hears "breach" and starts a 72-hour clock nobody meant to start. An engineer says "we contained it" meaning the host is off the network, and the Incident Commander hears "the adversary is evicted," which is not remotely the same claim. Somebody types "remediated" in the tracker when they mean "we put a firewall rule in front of it," and three weeks later an auditor asks why a KEV-listed CVE was closed with the patch still missing.
That is not a communication-skills problem, and no amount of goodwill fixes it mid-incident. It is a definitions problem, and it is fixable in peacetime for free — no license, no headcount, no procurement cycle. A shared vocabulary is the only control in this book with no invoice attached.
So this appendix is deliberately boring. Two rules govern it. Where a term has a legal or standards definition, that definition wins over whatever your team has drifted into, and it is quoted here. Where two authorities genuinely disagree — several do, in ways that change what you are obliged to do — the entry says so rather than picking a winner and hoping nobody notices.
Actionable takeaway: put those six terms in your incident response plan tonight with your organization's chosen definition beside each, and make agreeing them an exit criterion for your next tabletop. If your Legal Liaison and your Operations Lead cannot state the same definition of "breach" without checking, you have found tomorrow's problem today.
| Term | Definition |
|---|---|
| A2A | Agent-to-agent protocols, by which autonomous AI agents exchange tasks and context. Treated here as an identity and authorization surface, not a transport detail. Chapter 7. |
| Access broker (IAB) | A criminal specialist who obtains and resells footholds. Mandiant puts the median hand-off to the follow-on operator at 22 seconds, down from over eight hours in 2022 (M-Trends 2026). |
| Access token | A short-lived bearer credential presented to a resource. Valid until expiry regardless of password changes — up to 28 hours in Entra CAE sessions (Microsoft). Contrast refresh token. |
| ADS (Alerting and Detection Strategy) | Palantir's nine-section template for documenting a detection: Goal, Categorization, Strategy Abstract, Technical Context, Blind Spots and Assumptions, False Positives, Validation, Priority, Response (Palantir). |
| Agentic AI | An AI system that plans and executes multi-step actions against real tools and data with limited per-step approval. Its security properties come from its runtime's privileges, not from the model. |
| AiTM (adversary-in-the-middle) | Reverse-proxy phishing — Tycoon 2FA, Evilginx2, Modlishka, Muraena — that captures the session token after genuine MFA completes (Group-IB). MFA is not bypassed; it is made irrelevant. Containment is token revocation, not a password reset. |
| ASM (attack surface management) | Continuous discovery of internet-reachable assets from the attacker's vantage point — as distinct from scanning an inventory you already trust. Chapter 10. |
| ATLAS | MITRE's Adversarial Threat Landscape for AI Systems, v5.6.0: 16 tactics including AI Model Access (AML.TA0000) and AI Attack Staging (AML.TA0001) (atlas-data). Older references say "ML Model Access." |
| ATT&CK | MITRE's adversary behavior knowledge base, v19.2 since 28 April 2026 (MITRE). v19 split Defense Evasion into TA0005 Stealth and TA0112 Defense Impairment — coverage maps built on v18 or earlier have a stale tactic axis. |
| Term | Definition |
|---|---|
| BEC (business email compromise) | Fraud executed through authenticated access to, or convincing impersonation of, a trusted mailbox, usually ending in a payment diversion. Playbook 14.2. |
| BOD (Binding Operational Directive) | "A compulsory direction to federal executive branch, civilian departments, and agencies … for purposes of safeguarding federal information and information systems," issued under FISMA (44 U.S.C. § 3553). BOD 22-01 created the KEV catalog. |
| Breach | Here, a legal conclusion, not an engineering observation: a determination that regulated data was accessed or acquired such that a notification duty attaches. Engineers say "confirmed unauthorized access." Triggers differ — GDPR runs from awareness, CIRCIA from reasonable belief, SEC from a materiality determination. Appendix C. |
| Break-glass account | A pre-provisioned emergency identity independent of the normal auth path — excluded from every Conditional Access policy including vendor-managed ones, credentialed out-of-band, alerted on at every use (Microsoft). Chapter 4. |
| Breakout time | Foothold to first lateral movement. CrowdStrike's 2026 eCrime average: 29 minutes, fastest observed 27 seconds (CrowdStrike). |
| Term | Definition |
|---|---|
| CAE (Continuous Access Evaluation) | Microsoft's near-real-time revocation channel for critical events such as an admin revoking refresh tokens. Propagation may take up to 15 minutes, coverage across services is uneven, and it does not apply to guests (Microsoft). |
| CCM (Cloud Controls Matrix) | CSA's cloud control framework, v4.1 (27 January 2026) — 207 controls, 17 domains, paired with the CAIQ vendor questionnaire (CSA). |
| CIEM | Cloud infrastructure entitlement management: inventories and right-sizes permissions across cloud identities, human and non-human. Answers "what could this principal reach?" Contrast CSPM. |
| CIRCIA | The US Cyber Incident Reporting for Critical Infrastructure Act: once in force, 72 hours from reasonable belief of a covered incident and 24 hours from a ransom payment. As of 5 September 2026 the final rule is unpublished and reporting remains voluntary (CISA). |
| CIS Controls | The prioritized control set, v8.1 (24 June 2024) — 18 Controls, 153 Safeguards, mapped to CSF 2.0 (CIS). Distinct from CIS Benchmarks, which are per-technology configuration baselines with Level 1 and Level 2 profiles. |
| Implementation Group (IG1/IG2/IG3) | CIS's cumulative tiers. IG1: "essential cyber hygiene," 56 Safeguards, general non-targeted attacks. IG2: adds Safeguards for orgs with dedicated security staff. IG3: all 153, for orgs facing targeted adversaries (CIS). Every checklist item in this book carries an IG tag. |
| Clean room (IRE, isolated recovery environment) | A network-isolated environment with its own credentials — not the production IdP — into which backups are restored, scanned and validated before promotion. Modern ransomware leaves persistence behind, so restoring straight into production reintroduces the intrusion (Broadcom; CISA). Chapter 12. |
| CMMC | The US Department of Defense Cybersecurity Maturity Model Certification program, phased in under 32 CFR and 48 CFR rules from 2024–2025. Chapter 16. |
| CNSA 2.0 | The NSA's quantum-resistant algorithm suite for National Security Systems, with full NSS compliance required by 2035 in line with NSM-10. Per-technology interim dates circulate widely in secondary summaries — verify against NSA before committing one to a plan. |
| Community Profile | A CSF 2.0 baseline built for a sector, technology or threat type, adopted as the starting point for your own Target Profile (NIST CSWP 29). SP 800-61r3 is itself a Community Profile — which is why it has no phase diagram. |
| Compromised | CISA's third evaluation state: "The system was vulnerable, signs of exploitation were found, and incident response and vulnerability remediation has begun." |
| Conditional Access | Policy evaluating user, device, location and risk signals at authentication time. A blunt containment lever — it stops new sign-ins and does not by itself kill live tokens. Chapters 4 and 5. |
| Confused deputy | A privileged component induced to use its own authority for an attacker. The 2026 reference case: an agent inherited a mounted Kubernetes service-account token and replayed it against the API server — no exploit, only the access its runtime carried (Sysdig). |
| Containment | Action that stops the adversary acting further. Not eradication, not recovery. Say "host isolated" or "sessions revoked," never "we contained it." Chapter 13. |
| Control plane | The management and identity layer — cloud API, Kubernetes API server, hypervisor manager, IdP — as opposed to the workloads it governs. Modern cloud intrusion is predominantly control-plane abuse using valid credentials. |
| Crypto-agility | Being able to change algorithms, key sizes and libraries without re-architecting. The prerequisite for any PQC migration. Chapter 8. |
| CSPM | Cloud security posture management: continuous evaluation of resource configuration against a baseline. Answers "is this configured badly?" — not "who can reach it?" See CIEM. |
| CVE | A public identifier for one vulnerability. An identifier only: no severity, no exploitation evidence, no claim that it exists in your environment. |
| CVSS | A score describing a vulnerability's intrinsic characteristics. Not a prioritization output and not a probability of exploitation. Pair with KEV and EPSS. Chapter 10. |
| CycloneDX / SPDX | The two SBOM formats CISA names as widely used and tool-supported. SWID tags were removed from the accepted list in the 2026 minimum elements (CISA); guidance still listing SWID is out of date. |
| Term | Definition |
|---|---|
| D3FEND | MITRE's defensive counterpart to ATT&CK, v1.6.0, with the tactics Model, Harden, Detect, Isolate, Deceive, Evict and Restore (MITRE). Its Isolate/Evict/Restore vocabulary maps onto containment, eradication and recovery. |
| Detection-as-code | Managing detection logic as version-controlled, peer-reviewed, tested artefacts in CI rather than console-authored rules. Chapter 9. |
| DLP | Data loss prevention: controls that inspect data in motion, at rest or in use and block or alert on policy-violating movement. Chapter 8. |
| Double / triple extortion | Double = encryption plus exfiltration and a leak threat; now the floor, not a differentiator. Triple adds a third pressure layer — DDoS, direct outreach to customers and journalists, or regulatory weaponization. |
| Dwell time | The period an adversary was present before detection, measured per intrusion — distinct from MTTD, which is averaged over alerts you investigated. Mandiant's 2025 global median: 14 days; 10 when detected internally, 26 when a third party told you (M-Trends 2026). |
| Term | Definition |
|---|---|
| ED (Emergency Directive) | A directive the Secretary of Homeland Security — delegated to CISA's Director — may issue to a federal agency facing a substantial information-security threat, requiring any lawful protective action (44 U.S.C. § 3553). ED 25-03 (Cisco ASA) and ED 26-01 (F5) are the edge-appliance reference cases. |
| EDR / XDR / NDR | Endpoint detection and response; the extended variant correlating endpoint with identity, email, cloud and network telemetry; and the network-traffic-analysis variant. Chapter 9. |
| Elevation vs. escalation | NIST separates them: "Escalation generally refers to increasing resources or time frames, while elevation usually indicates involving a higher level of management" (SP 800-61r3). Write them as two gates; most plans conflate them and wake the wrong person. |
| EPSS | The Exploit Prediction Scoring System: a daily, calibrated probability that a CVE is exploited in the wild within 30 days, published with a percentile (FIRST). A KEV listing overrides the score — treat a KEV entry as actively exploited regardless of its EPSS value (Using EPSS). |
| Eradication | Removal of adversary access and persistence. Distinct from containment (present but unable to act) and recovery (service restored). |
| Term | Definition |
|---|---|
| FAIR | Factor Analysis of Information Risk — expresses risk as "the probable frequency and magnitude of future loss," annualized, as a distribution rather than a heat-map color (FAIR Institute). |
| Forms of loss | FAIR's six: Productivity, Response, Replacement, Competitive Advantage, Fines & Judgements, Reputation. They are not confidentiality/integrity/availability — a common and expensive substitution. |
| FAIR-CAM | The FAIR Controls Analytics Model — measures how controls reduce risk in real units, including systemic effects where one control works only because another does (FAIR Institute). |
| FIDO2 / WebAuthn / passkey | Phishing-resistant authentication where the credential is cryptographically bound to the real domain, so a proxy site captures nothing usable. A passkey is a discoverable FIDO2 credential; device-bound versus cloud-synced is a material security distinction. Chapter 4. |
| Term | Definition |
|---|---|
| GOVERN | The Function added in CSF 2.0 (six Functions; 1.1 had five). Holds organizational context, risk strategy including risk appetite and tolerance, roles and authorities, policy, oversight, and supply chain risk management as its own Category, GV.SC (NIST CSWP 29). |
| HNDL (harvest now, decrypt later) | Collecting encrypted traffic or data today to decrypt once a cryptographically relevant quantum computer exists — which makes anything with a long confidentiality lifetime a present-tense risk. NIST IR 8547: RSA-2048 and ECC-256 deprecated by 2030, disallowed after 2035 (NIST). |
| Hotwash | The structured, blameless post-incident review. CISA's stated objective includes reviewing and updating "roles, responsibilities, interfaces, and authority to ensure clarity" (CISA). Chapter 18. |
| Term | Definition |
|---|---|
| Incident | Statutorily, an occurrence that "actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system," or that "constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies" (EO 14028 Sec. 10; 44 U.S.C. § 3552(b)(2)). That second limb is far broader than most corporate queues assume. Adopt it only alongside a severity schema. |
| ICT service providers | In CISA's usage, information and communications technology service providers — "includes IT, OT, and cloud service providers" (EO 14028 Sec. 2). |
| Immutability | Storage that cannot be altered or deleted for a retention period. S3 Object Lock compliance mode cannot be overridden "by any user, including the root user"; governance mode yields to s3:BypassGovernanceRetention — a header the console sends by default (AWS). Governance mode plus a console-capable admin is not immutability. |
| IMDS / IMDSv2 | The cloud instance metadata service that vends temporary credentials for the attached role. IMDSv1 is reachable through SSRF; IMDSv2 requires a session token. In CloudTrail, ec2RoleDelivery of "1.0" confirms IMDSv1 was used (AWS). |
| Indirect prompt injection | Injection delivered through content the model retrieves — an email, wiki page, ticket, fetched page, tool description — rather than through the user's prompt. EchoLeak (CVE-2025-32711), a zero-click chain in Microsoft 365 Copilot at CVSS 9.3, is the reference case (arXiv). |
| ITDR | Identity threat detection and response: detection whose primary telemetry is the identity plane — sign-ins, token issuance, consent grants, directory and privilege changes — rather than endpoints. Chapter 4. |
| Term | Definition |
|---|---|
| JIT elevation | Granting privilege for a bounded window against a stated justification, with automatic expiry, instead of standing privilege. "Dynamic just-in-time policy" characterises the Optimal stage of CISA's ZTMM (CISA). |
| KEV | CISA's Known Exploited Vulnerabilities catalog, created by BOD 22-01 — vulnerabilities with reliable evidence of active exploitation (CISA). Beware the older phrase: CISA's 2021 playbook counts a released proof-of-concept as "known exploitation," which KEV does not. A program written against the 2021 wording over-includes. |
| krbtgt | The Active Directory account whose key signs Kerberos tickets. Reset it twice, at least 10 hours apart so the first fully replicates, because the account keeps a two-password history (CISA CM0050). |
| Term | Definition |
|---|---|
| Legal hold | An instruction suspending routine deletion of potentially relevant data. Holds are not retroactive — placed after the retention window rolls, one recovers nothing. Step one of identity containment in this book. |
| Lethal trifecta | The agent pattern of private data access + exposure to untrusted content + an external communication channel, in one context. Any two are manageable; all three is an exfiltration primitive (Willison). |
| Major incident | An OMB term of art, not an adjective: an incident "likely to result in demonstrable harm to the national security interests, foreign relations, or the economy of the United States or to the public confidence, civil liberties, or public health and safety of the American people" (OMB M-20-04), or an equivalent PII breach. Federal agencies report it to CISA within one hour of declaration. If you use "major" informally, choose another word for your top severity. |
| MCP (Model Context Protocol) | An open protocol connecting LLM applications to external tools and data. It carries no built-in cryptographic verification of tool origin — names, descriptions and provider claims are spoofable — which is what enables tool poisoning, rug pulls and cross-server attacks (Microsoft). Chapter 7. |
| MFA fatigue / push bombing | Repeated push prompts until a tired user approves one. Number matching mitigates push fatigue; it does not make MFA phishing-resistant — CISA is explicit, and treating it as the destination is a consequential error (CISA). |
| Micro-segmentation | Per-workload or per-flow network policy rather than per-zone, so lateral movement needs a fresh authorization decision at each hop. Chapter 5. |
| Mitigated | CISA's middle remediation state: "Other compensating controls — such as detection or access restriction — are in place and the risk of the vulnerability is reduced." Mitigated is not closed. Compensating controls are temporary: "Once patches are available and can be safely applied, mitigations can be removed, and patches applied." |
| ML-KEM / ML-DSA / SLH-DSA | The NIST post-quantum algorithms finalized August 2024: FIPS 203 ML-KEM for key establishment (formerly Kyber), FIPS 204 ML-DSA for signatures (formerly Dilithium), FIPS 205 SLH-DSA as hash-based backup (formerly SPHINCS+). FN-DSA (FIPS 206) is draft; HQC is a selected backup KEM, not a finalized FIPS (NIST). |
| MTTD / MTTC / MTTR | Mean time to detect (first adversary activity to detection — retrospective, since the start timestamp is knowable only after investigation); to contain (detection to the point the adversary can no longer act); and to respond/remediate/recover — three different things to three different teams. Define which you mean or the trend line is meaningless. Appendix E. |
| Term | Definition |
|---|---|
| NCISS | CISA's National Cyber Incident Scoring System: a 0–100 weighted mean across eight categories — Functional Impact, Observed Activity, Location of Observed Activity, Actor Characterization, Information Impact, Recoverability, Cross-Sector Dependency, Potential Impact — mapping to six priority levels (Emergency/black, Severe/red, High/orange, Medium/yellow, Low/green, Baseline/blue-white) (CISA). CISA assigns the score; you receive it. |
| Non-human identity (NHI, machine identity) | Any authenticating principal that is not a person: service accounts, service principals and app registrations, CI publishing tokens, API keys, workload identities, Kubernetes service-account tokens, agent credentials. Two of 2026's most instructive intrusions were pure NHI events. Most pre-2025 playbooks have no NHI branch. |
| NIS2 | EU Directive 2022/2555. Three-staged reporting for a significant incident: early warning within 24 hours, incident notification within 72 hours, final report within one month. Appendix C. |
| OAuth consent phishing (illicit consent grant) | Inducing a user to approve a malicious app through a genuine consent screen, yielding persistent access without the password. Microsoft: "normal remediation steps (for example, resetting passwords or requiring multifactor authentication) aren't effective against this type of attack" (Microsoft). |
| OFAC | The US Treasury's Office of Foreign Assets Control. Its ransomware advisory applies strict liability — penalties can attach "regardless of intent or knowledge" — and license applications to pay face a presumption of denial. It binds victims and insurers, forensic firms and banks; documented diligence and prompt reporting are named mitigating factors (OFAC). Chapter 15. |
| Order of volatility | RFC 3227's collection priority: registers and cache; routing table, ARP cache, process table, kernel statistics, memory; temporary file systems; disk; remote logging and monitoring data; physical configuration and topology; archival media (RFC 3227). |
| Term | Definition |
|---|---|
| PAM | Privileged access management: the system that vaults, brokers, records and time-bounds privileged access, so admin credentials are checked out rather than held. Chapter 4. |
| PDP / PEP | Policy Decision Point (Policy Engine plus Policy Administrator) and Policy Enforcement Point — the core logical components of a zero trust architecture in NIST SP 800-207 (NIST). |
| Phishing-resistant MFA | Authentication that cannot be relayed through a proxy because the credential is bound to the origin — FIDO2/WebAuthn or PKI. Microsoft reports it blocks over 99% of identity-based attacks even where the attacker holds valid credentials (MDDR 2025). Push, SMS and OTP codes are not phishing-resistant. |
| PICERL | The SANS lifecycle: Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned. Used here for runbook sequencing, with 800-61r3/CSF 2.0 for program architecture. One real disagreement: in PICERL, Preparation is step 1 inside the lifecycle; in 800-61r3 it is Govern/Identify/Protect and explicitly not part of incident response itself. |
| Plan / playbook / runbook | This book's most load-bearing distinction. A plan governs: authority, roles, severity schema, escalation. A playbook is the scenario-specific ordered response for one incident type. A runbook is the tool-level, single-task procedure a playbook step invokes. Never interchangeable. Chapter 2. |
| PQC | Post-quantum cryptography: algorithms believed secure against a cryptographically relevant quantum computer. See ML-KEM, HNDL, crypto-agility. Chapter 8. |
| Profile (Current / Target) | CSF 2.0's gap-analysis instrument: a Current Profile states today's outcomes, a Target Profile the desired ones; the gap drives the action plan (NIST CSWP 29). Not the same as Tiers (1 Partial → 4 Adaptive), which describe governance rigour and are explicitly not a maturity model. |
| Prompt injection | Instructions supplied as data that the model executes as commands — direct from the user, indirect from retrieved content. Structural cause: LLMs process instructions and data on the same channel, so there is no reliable in-band separation. #1 in the OWASP Top 10 for LLM Applications two editions running (OWASP). |
| Purdue-model location scale | NCISS's "Location of Observed Activity" axis, a modified Purdue model, levels 0–7: Unsuccessful, Business DMZ, Business Network, Business Network Management (admin workstations, AD, trust stores), Critical System DMZ, Critical System Management, Critical Systems, Safety Systems. The defensible reason a domain controller outranks a laptop. |
| Purple team | An exercise running offensive emulation and defensive detection together, to measure and close detection coverage rather than to prove compromise is possible. Chapter 18. |
| Term | Definition |
|---|---|
| RAG | Retrieval-augmented generation: fetching documents at query time into the model's context. Two consequences — every retrievable document is an injection vector, and the vector store inherits the access-control obligations of everything indexed into it. OWASP covers the class as LLM08:2025 (OWASP). |
| RE&CT | An ATT&CK-shaped response knowledge base whose cells are atomic, reusable Response Actions composed into playbooks (atc-project). The idea this book borrows: one fix to "isolate host" propagates everywhere. |
| Recoverability | An NCISS dimension — resources needed to recover — at four levels: Regular (predictable with existing resources), Supplemented (predictable with additional resources), Extended (unpredictable; outside assistance may be required), Not Recoverable. |
| Recovery denial | Mandiant's framing of the 2026 shift: operators deliberately target backup infrastructure, identity services, virtualization management planes, AD CS certificate templates and hypervisor datastores — attacking your ability to recover, not only to operate (M-Trends 2026). |
| Refresh token | A long-lived credential used to mint new access tokens, independent of the password. Revoke sessions and reset the credential in the same action — reversing the order leaves a valid token in the adversary's hands. Chapter 4. |
| Remediated | CISA's terminal state: "The patch or configuration change has been applied and the system is no longer vulnerable." Everything short of that is Mitigated or Susceptible/Compromised. Do not let a tracker collapse the three into "closed." |
| Risk appetite / tolerance | Appetite is the aggregate risk the organization will accept; tolerance is acceptable variation around it for a specific objective. CSF 2.0 requires both to be stated (GV.RM); FAIR supplies the units. Chapter 16. |
| Term | Definition |
|---|---|
| SASE / SSE | Converged cloud-delivered network and security edge services; SSE is the security subset. Chapter 5. |
| SBOM | A machine-readable inventory of software components and their relationships. The federal baseline is CISA's 2026 Minimum Elements (July 2026) — 17 data fields, replacing NTIA's 2021 document, now covering open source, AI systems and SaaS (CISA). New obligations: SBOM Author Signature, SBOM Generation Context, Component Hash. |
| SEV-1 … SEV-4 | This book's severity scale, SEV-1 highest, defined in Chapter 13. Some organizations number the other way — state your direction explicitly, because inheriting the wrong direction from a vendor runbook is a real failure mode. |
| Service principal | The directory object representing an application's identity in a tenant. SolarWinds/SUNBURST remains the template for its abuse: persistent, stealthy, and immune to MFA because no human authenticates. |
| Shadow AI | Use of AI services outside sanctioned channels. An inventory problem, not a discipline problem — which is why Chapter 7 starts with discovery rather than policy. |
| Shared responsibility / shared fate | The provider secures "security of the cloud"; the customer secures "security in the cloud," with the boundary set by which services they select (AWS). Google frames its version as "shared fate" (Google Cloud). A responsibility boundary, not a liability boundary — your duty to notify a regulator is never shared. |
| Sigma | The vendor-neutral YAML detection rule format, converted to platform query languages via sigma-cli and pySigma backends (SigmaHQ). Chapter 9. |
| SLSA | Supply-chain Levels for Software Artifacts, v1.2, organized into tracks with Build most mature: L1 provenance exists; L2 provenance signed by a hosted build platform; L3 hardened platform, signing material inaccessible to user-defined build steps (slsa.dev). Addresses tampering between source and consumer, which neither SAST nor an SBOM covers. |
| SOAR | Security orchestration, automation and response. This book's gate rule: automation may gather, enrich, correlate and recommend without approval; it may act only where the action is reversible, scoped and rate-limited; irreversible or organization-wide actions require a named human approver. Chapter 17. |
| SSDF | NIST SP 800-218, four practice groups: PO Prepare the Organization, PS Protect the Software, PW Produce Well-Secured Software, RV Respond to Vulnerabilities (NIST). SP 800-218A is the generative-AI Community Profile on top. It underpins federal secure-software attestation, which is why it appears in commercial questionnaires. |
| SSVC | Stakeholder-Specific Vulnerability Categorization — the decision-tree prioritization method named in CISA's vulnerability response playbook. Produces a decision, not a score. |
| Susceptible | CISA's middle evaluation state: "The system is vulnerable, but no signs of exploitation were found, and remediation has begun." |
| Term | Definition |
|---|---|
| TLP (Traffic Light Protocol) | The marking scheme governing onward disclosure of shared information: TLP:CLEAR, TLP:GREEN, TLP:AMBER, TLP:AMBER+STRICT, TLP:RED. Every playbook here carries a TLP marking in its metadata, because "who may I forward this to?" arrives at hour two, not hour twenty. |
| Tool poisoning / rug pull | Two named MCP attack classes: a malicious tool masquerading as legitimate, and a tool that silently redefines itself after approval. Both exploit the absence of tool-origin verification. |
| UEBA | User and entity behavior analytics: baselining principals and flagging deviation. Chapter 9. |
| Vishing | Voice phishing. Mandiant records it as the #2 initial infection vector globally at 11% of investigations — which is why this book treats the service desk as both a detection surface and a containment target (M-Trends 2026). |
| Vulnerability | Statutorily broader than most teams assume: "any attribute of hardware, software, process, or procedure that could enable or facilitate the defeat of a security control" (Cybersecurity Information Sharing Act of 2015, § 102). A help-desk verification procedure that can be talked past is a vulnerability under this definition, and it has no CVE. |
| Zero-day | A vulnerability exploited before a patch is available. CrowdStrike recorded a 42% year-over-year increase in zero-days exploited before public disclosure (CrowdStrike). |
| Zero trust | Per NIST SP 800-207: no implicit trust from network location or asset ownership; protection oriented around individual resources; authentication and authorization of both subject and device performed as discrete functions before a session is established (NIST). |
| ZTMM | CISA's Zero Trust Maturity Model v2.0 (April 2023): five pillars — Identity, Devices, Networks, Applications and Workloads, Data — plus three cross-cutting capabilities (Visibility and Analytics, Automation and Orchestration, Governance), across four stages: Traditional, Initial, Advanced, Optimal (CISA). Pillar counts differ by authority: the DoD strategy uses seven, promoting those two capabilities to full pillars. When someone says "pillar four," ask whose. |
| ZTNA | Zero trust network access: brokered, per-application access replacing broad network-layer VPN access, with the policy decision made per session. Chapter 5. |
Words are infrastructure. They cost nothing to maintain and fail silently when neglected — nobody gets a monitoring alert for "Legal and Engineering are using the same noun to mean two different things." Read this once in peacetime, argue about three entries with your team, write down what you decided.
Define it before you need it, and agree it before you have to argue it at three in the morning.