Understand security and privacy
First describe the data, operations and people involved. Understand protections through what they prevent or allow in context. An tool name or alert list alone cannot establish that a website is safe or compromised.
57 concepts to explore with their definitions and practical advice.
Search the full glossary
A reading path
1. Identity and permissions
Separate proof of identity from permission to act on an object. Check sensitive operations on the server rather than only button visibility.
2. Protect exchanges
Identify transmitted data and relevant protections. Transport, content and access mechanisms address different risks.
3. Detection and recovery
Connect alerts to versions and configurations actually used. Plan recovery and verification of a restored state in an appropriate environment.
Useful distinctions
Authentication / Roles and permissions
Authentication establishes identity in the system. Roles and permissions define allowed actions. Being signed in does not automatically grant access to every record.
Encryption / Backup
Encryption protects data readability according to its mechanism; backup supports recovery. An encrypted copy also requires an authorised way to decrypt it for restoration.
Use the vocabulary to make a decision
Situation
An editor can open a record they do not own by changing its identifier.
Before deciding
Examine authorisation applied to the requested resource. Hiding a menu link does not protect direct access.
A concrete check
Reproduce only in an authorised environment with test accounts and data.
All concepts in this topic
Links open the full definition on its alphabet page. Acronyms and synonyms remain searchable from the main glossary.
- ACME
- ACME Renewal Information
- ACME staging environment
- AI red teaming
- Authentication
- Backup
- Brute force
- CAPTCHA
- Certificate renewal
- Cookie
- CORS
- CSP
- CSV formula injection
- Cybersecurity
- Data minimization
- DDoS
- DKIM
- DMARC
- DNS-01 challenge
- DNSSEC
- Encryption
- Firewall
- GDPR
- HMAC
- HSTS
- HTTP-01 challenge
- HTTPS
- Incident response
- JWT
- Login
- OAuth
- OWASP
- Partitioned cookie
- Passkey
- Prompt injection
- Ransomware
- Roles and permissions
- Same-origin policy
- SFTP
- Software Bill of Materials
- Spam
- SPF
- SSH
- SSL/TLS
- SSL/TLS certificate
- Subresource Integrity
- Third-party cookie
- Trojan
- Two-factor authentication
- VPN
- Vulnerability
- WAF
- Website backup
- Website restoration
- XSS
- Zero trust
- Zero-day vulnerability
Frequently asked questions
Should logs retain every detail?
Keep information useful for diagnosis and follow-up within a defined framework. Passwords, tokens and unnecessary personal data should not appear in examples or test reports.
Is an automated scan sufficient?
It supplies observations within its scope. Check versions, access, sensitive journeys and recovery; interpret alerts before presenting them as confirmed incidents.
Primary reference documents
These documents explain the technical concepts. The reading paths and decision examples are editorial methods to adapt to your project.