Index / Glossary

Glossary

Definitions as used on this site. Where a term is used inconsistently across the industry, that is noted.

Access review. Periodic confirmation that the people who can reach a system or data category still need to. The single most effective insider control and the least popular.

At rest / in motion / in use. The three states data can be in. Each permits different controls. See data states.

Baseline. A statistical profile of normal activity for a person or peer group. Requires a stable population and a stable role; both are frequently absent.

Blocking mode. Enforcement that prevents an action. Contrasted with monitor mode. Deploying in blocking mode before tuning is the most common way to lose organisational support.

CASB. Cloud access security broker. Sits between users and cloud services to apply policy at that layer.

Content inspection. Examining the payload of a file or message against patterns. Effective for structured identifiers, poor for unstructured intellectual property.

Data classification. Assigning sensitivity levels to information. The prerequisite for everything else and the step most often skipped.

Discovery. Scanning repositories to find where sensitive data actually is. Finds instances; does not decide what matters.

DLP. Data loss prevention. A set of controls inspecting data against policy and acting on matches. Narrower than the name implies.

Egress channel. A route by which data can leave. Email, cloud sharing, removable media, print, and several that cannot be observed at all.

Exclusion. A documented exception for a legitimate workflow that resembles a violation. Necessary, and dangerous when undocumented or unexpiring.

Fingerprinting. Registering specific documents or datasets so the system matches derivatives of them. Far more precise than generic pattern matching.

Insider. Anyone with legitimate access. Includes contractors, suppliers and service providers, not only employees.

Just-in-time access. Privilege granted on request, for a limited period, expiring automatically. Replaces standing administrative rights.

Monitor mode. Detection running with no user-visible effect. Where every deployment should begin and remain longer than feels comfortable.

Negligent insider. Someone causing exposure through error or a shortcut. The majority of incidents by volume.

Precision. The proportion of alerts that are genuine findings. More useful than any count of alerts.

Privileged user. Someone with administrative access. Smallest population, highest consequence, able to affect the controls themselves.

Shadow IT. Services in use without approval. Usually a signal that the sanctioned tool is inadequate.

TLS inspection. Decrypting encrypted traffic to inspect it. Restores visibility and carries real privacy and operational costs.

True positive. An alert that identified something genuinely worth acting on. Rare, and the only quality measure that matters.

UEBA. User and entity behaviour analytics. Detects deviation from a baseline, which is not the same as detecting intent. See behavioural analytics.