Reference
Glossary
36 terms
A
Agentic AI
Agentic AI describes systems where an LLM is given tools (shell access, file editing, API calls), memory, and a goal, then autonomously plans and executes multi-step tasks toward that goal.
AI code generation security
AI code generation security means analyzing and remediating vulnerabilities in code produced by AI coding tools.
Air-gapped
An air-gapped system has no physical connection, and no automated logical connection, to untrusted networks; data moves in or out only by manual transfer, such as approved removable media.
AST analysis
AST analysis parses source code into an Abstract Syntax Tree and queries the tree for vulnerable patterns.
C
Classified environment
A classified environment is a system or facility accredited to process information classified under Executive Order 13526 (Confidential, Secret, or Top Secret).
CMMC Level 2
CMMC Level 2 requires the 110 security requirements of NIST SP 800-171 Rev. 2.
CVE (Common Vulnerabilities and Exposures)
Common Vulnerabilities and Exposures is the public catalog of disclosed software vulnerabilities.
CWE (Common Weakness Enumeration)
Common Weakness Enumeration is a category system maintained by MITRE for software security weaknesses.
Controlled environment
A computing environment whose policies restrict data egress, model access, or third-party software.
CUI (Controlled Unclassified Information)
Controlled Unclassified Information is unclassified but sensitive information that requires safeguarding under government-wide policies (Executive Order 13556).
CMMC (Cybersecurity Maturity Model Certification)
Cybersecurity Maturity Model Certification is the US Department of Defense program for verifying that contractors protect FCI and CUI.
D
G
H
I
IAST (Interactive Application Security Testing)
Interactive Application Security Testing combines SAST and DAST by instrumenting a running application to observe both source code paths and execution behavior.
ITGC (IT General Controls)
IT General Controls are the policies and procedures that govern the IT environment supporting financial reporting.
N
P
PCI-DSS (Payment Card Industry Data Security Standard)
Payment Card Industry Data Security Standard is the security requirement set for entities that store, process, or transmit cardholder data.
PAN (Primary Account Number)
Primary Account Number is the cardholder account number on a credit, debit, or stored-value card.
Prompt injection
Prompt injection is an attack class in which an adversary embeds instructions in content that an LLM consumes (a fetched web page, a document, an email body, a database row).
S
SOX (Sarbanes-Oxley Act)
The Sarbanes-Oxley Act of 2002 imposes accuracy and accountability requirements on US public-company financial reporting.
SOC 2 (System and Organization Controls 2)
SOC 2 is an AICPA attestation report on a service organization's controls relevant to the Trust Services Criteria: Security, Availability, Processing Integrity, Confidentiality, and Privacy.
SBOM (Software Bill of Materials)
Software Bill of Materials is a formal inventory of the components, libraries, and dependencies that make up a software product.
SCA (Software Composition Analysis)
Software Composition Analysis matches a project's open-source dependencies, including transitive ones, against known vulnerability databases.
SAST (Static Application Security Testing)
Static Application Security Testing analyzes source code, bytecode, or binaries without executing them.
Supply chain attack
A supply chain attack targets a software product indirectly, by compromising one of its upstream dependencies, build tools, or distribution channels.