Glossary: security terms in plain language
Supply-chain security is full of acronyms. Here is what each one actually means, in plain language, so you can read a supplier assessment without a decoder ring.
- BEC
- Business Email Compromise: fraud where an attacker impersonates a trusted person to trick staff into payments or disclosing data.
- BIMI
- Brand Indicators for Message Identification: a standard that shows your verified logo next to authenticated email in supporting inboxes; it requires DMARC at enforcement.
- CVE
- Common Vulnerabilities and Exposures: a public identifier for a specific known security vulnerability.
- CVSS
- Common Vulnerability Scoring System: a 0 to 10 score for how severe a vulnerability is.
- DANE
- DNS-based Authentication of Named Entities: publishes your TLS certificate fingerprint in DNS so senders can verify it. Requires DNSSEC.
- DKIM
- DomainKeys Identified Mail: a cryptographic signature proving an email really came from your domain and was not altered.
- DMARC
- Domain-based Message Authentication, Reporting and Conformance: an email standard that lets you control and monitor who can send email using your domain.
- DNSSEC
- Domain Name System Security Extensions: signs your DNS records so attackers cannot forge them and redirect your traffic.
- DORA
- Digital Operational Resilience Act: EU regulation on operational and ICT resilience for the financial sector, a sibling of NIS2.
- EASM
- External Attack Surface Management: continuous visibility into everything of yours that is reachable from the internet, seen the way an attacker sees it.
- EPSS
- Exploit Prediction Scoring System: the probability that a vulnerability will be exploited in the wild in the near term.
- HSTS
- HTTP Strict Transport Security: a header that tells browsers to only ever connect to your site over encrypted HTTPS.
- Infostealer
- Malware that steals saved passwords, cookies and other credentials from an infected device.
- KEV
- Known Exploited Vulnerabilities: a catalogue of vulnerabilities confirmed to be actively exploited by attackers.
- MCP
- Model Context Protocol: a standard for connecting AI models to tools and data. An MCP endpoint exposed to the internet can leak data or grant unintended access.
- MFA
- Multi-Factor Authentication: requiring a second factor (app code, security key) in addition to a password. Expected by NIS2 Art. 21(2)(j).
- MTA-STS
- Mail Transfer Agent Strict Transport Security: forces email sent to your domain to use encrypted connections.
- NIS2
- The EU Network and Information Security Directive 2, setting cybersecurity and supply-chain obligations for many organisations.
- RBL
- Realtime Blackhole List / DNS blocklist: a published list of IP addresses known for spam or abuse; if your mail server's IP is listed, receivers may reject your email.
- RPKI
- Resource Public Key Infrastructure: cryptographically proves which network is allowed to announce your IP ranges, preventing route hijacking.
- SAQ
- Supplier Assessment Questionnaire: a structured security questionnaire sent to suppliers, whose answers norppa cross-checks against scan evidence.
- SBOM
- Software Bill of Materials: an inventory of the components a piece of software is built from.
- Shadow IT
- Systems and services used within an organisation without the knowledge or approval of its IT function.
- SPF
- Sender Policy Framework: a DNS record listing the servers allowed to send email for your domain.
- TLS
- Transport Layer Security: the encryption behind HTTPS that protects data in transit and identifies a website.
- TLS-RPT
- SMTP TLS Reporting: mail receivers report daily whether email delivered to your domain used encrypted TLS, so failed or downgraded connections become visible.
- TPRM
- Third-Party Risk Management: the practice of assessing and monitoring the risk your suppliers and partners bring into your own organisation.
7-day free trial · no credit card · cancel anytime