Glossary: security terms in plain language

Supply-chain security is full of acronyms. Here is what each one actually means, in plain language, so you can read a supplier assessment without a decoder ring.

BEC
Business Email Compromise: fraud where an attacker impersonates a trusted person to trick staff into payments or disclosing data.
BIMI
Brand Indicators for Message Identification: a standard that shows your verified logo next to authenticated email in supporting inboxes; it requires DMARC at enforcement.
CVE
Common Vulnerabilities and Exposures: a public identifier for a specific known security vulnerability.
CVSS
Common Vulnerability Scoring System: a 0 to 10 score for how severe a vulnerability is.
DANE
DNS-based Authentication of Named Entities: publishes your TLS certificate fingerprint in DNS so senders can verify it. Requires DNSSEC.
DKIM
DomainKeys Identified Mail: a cryptographic signature proving an email really came from your domain and was not altered.
DMARC
Domain-based Message Authentication, Reporting and Conformance: an email standard that lets you control and monitor who can send email using your domain.
DNSSEC
Domain Name System Security Extensions: signs your DNS records so attackers cannot forge them and redirect your traffic.
DORA
Digital Operational Resilience Act: EU regulation on operational and ICT resilience for the financial sector, a sibling of NIS2.
EASM
External Attack Surface Management: continuous visibility into everything of yours that is reachable from the internet, seen the way an attacker sees it.
EPSS
Exploit Prediction Scoring System: the probability that a vulnerability will be exploited in the wild in the near term.
HSTS
HTTP Strict Transport Security: a header that tells browsers to only ever connect to your site over encrypted HTTPS.
Infostealer
Malware that steals saved passwords, cookies and other credentials from an infected device.
KEV
Known Exploited Vulnerabilities: a catalogue of vulnerabilities confirmed to be actively exploited by attackers.
MCP
Model Context Protocol: a standard for connecting AI models to tools and data. An MCP endpoint exposed to the internet can leak data or grant unintended access.
MFA
Multi-Factor Authentication: requiring a second factor (app code, security key) in addition to a password. Expected by NIS2 Art. 21(2)(j).
MTA-STS
Mail Transfer Agent Strict Transport Security: forces email sent to your domain to use encrypted connections.
NIS2
The EU Network and Information Security Directive 2, setting cybersecurity and supply-chain obligations for many organisations.
RBL
Realtime Blackhole List / DNS blocklist: a published list of IP addresses known for spam or abuse; if your mail server's IP is listed, receivers may reject your email.
RPKI
Resource Public Key Infrastructure: cryptographically proves which network is allowed to announce your IP ranges, preventing route hijacking.
SAQ
Supplier Assessment Questionnaire: a structured security questionnaire sent to suppliers, whose answers norppa cross-checks against scan evidence.
SBOM
Software Bill of Materials: an inventory of the components a piece of software is built from.
Shadow IT
Systems and services used within an organisation without the knowledge or approval of its IT function.
SPF
Sender Policy Framework: a DNS record listing the servers allowed to send email for your domain.
TLS
Transport Layer Security: the encryption behind HTTPS that protects data in transit and identifies a website.
TLS-RPT
SMTP TLS Reporting: mail receivers report daily whether email delivered to your domain used encrypted TLS, so failed or downgraded connections become visible.
TPRM
Third-Party Risk Management: the practice of assessing and monitoring the risk your suppliers and partners bring into your own organisation.

7-day free trial · no credit card · cancel anytime