Glossary
Security terms, explained by the people who test them.
Each entry answers in a few sentences what a term means, where it is defined and what it means for your product or plant. Written by security engineers, checked against the standards.
In short
The Zyberum glossary defines terms from penetration testing, IoT, automotive, OT and IT security and from the EU regulations that apply to them: Cyber Resilience Act, NIS2, RED and EN 18031, IEC 62443, ISO/SAE 21434 and UN R155. Every entry names its source.
All terms
From attack surface to zero trust
A
B
- Black Box, Grey Box and White Box TestingBlack box, grey box and white box describe how much the tester knows before a penetration test: nothing, partial access, or full documentation and code. When each fits.
- BLE SecurityHow Bluetooth Low Energy devices pair, encrypt and authorise access: what the Core Specification defines, which pairing modes protect and what we find in device tests.
- BSI IT-GrundschutzIT-Grundschutz is the BSI method for building an ISMS: BSI Standards 200-1 to 200-4 plus a Compendium of building blocks. How it works and when to use it.
- Bug BountyA bug bounty pays external researchers for reported vulnerabilities. How programs are structured, what they cost, and why they complement a pentest, not replace it.
C
- CAN BusThe CAN bus is the serial network that connects ECUs in vehicles and machines. How frames and arbitration work, why CAN has no built-in security, and what protects it.
- CSMS (Cybersecurity Management System)A CSMS is the organisational process framework UN R155 requires from vehicle manufacturers. What it must cover, how it is audited, and what suppliers deliver to it.
- CVECVE (Common Vulnerabilities and Exposures) gives every public vulnerability one ID. How CVE records are created, what they contain and how to use them.
- CVSSCVSS, the Common Vulnerability Scoring System, rates how severe a vulnerability is from 0 to 10. What it measures, what it does not, and how to use it in a report.
- Cyber Resilience Act (CRA)The Cyber Resilience Act (Regulation (EU) 2024/2847) sets cybersecurity requirements for products with digital elements. Scope, duties, classes, 2026 and 2027 deadlines.
D
E
F
- Firmware ExtractionFirmware extraction means getting the code and data out of a device for analysis. The methods from update files to chip-off, what attackers find, and how to make it hard.
- FuzzingFuzzing feeds a program or device large numbers of malformed inputs to find crashes and security bugs. The methods, where standards ask for it, and how it works on ECUs.
H
I
- IDOR / BOLAIDOR (Insecure Direct Object Reference) and BOLA (Broken Object Level Authorization) are one flaw: an API returns objects without checking who asked. Find and fix it.
- IEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- Incident ResponseIncident response is the organised handling of a security incident from detection to recovery. The NIST phases, the NIS2 and CRA deadlines, and what to prepare up front.
- ISO/IEC 27001ISO/IEC 27001 is the international standard for an information security management system (ISMS). What it requires, what Annex A covers, where pentests fit in.
- ISO/SAE 21434ISO/SAE 21434:2021 is the standard for cybersecurity engineering of road vehicles. Its clauses, how it relates to UN R155, and what it asks from OEMs and suppliers.
K
M
- Machinery Regulation (EU) 2023/1230The Machinery Regulation 2023/1230 replaces the Machinery Directive from 20 January 2027 and adds cybersecurity to machine safety. What Annex III requires.
- ModbusModbus is the simplest and most widespread industrial protocol: RTU over serial lines, TCP on port 502. How it works, why it has no security and how to protect it anyway.
- MQTTMQTT is the publish/subscribe protocol behind most IoT fleets, standardised by OASIS and as ISO/IEC 20922. How it works and the broker mistakes we find in IoT pentests.
N
O
- OPC UAOPC UA (IEC 62541) is the platform-independent industrial communication standard with built-in security. Security policies, certificates and the misconfigurations we see.
- OT SecurityOT security protects the operational technology that controls physical processes: PLCs, SCADA, HMIs, drives. How it differs from IT security and what typically fails.
- OWASP Top 10The OWASP Top 10 is the awareness list of the most critical web application security risks. The 2021 and 2025 categories, what the list is for, and what it is not.
P
- Penetration testA penetration test is an authorised, mostly manual attack on a system to find and prove exploitable vulnerabilities. Definition, types, process and the report.
- PhishingPhishing is social engineering by message: attackers pose as a trusted sender to steal credentials or trigger actions. How it works, the variants, and what stops it.
- PLC (Programmable Logic Controller)A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
R
- Red teamingRed teaming is a goal-based, covert attack simulation that tests detection and response, not just vulnerabilities. Definition, frameworks, difference to a pentest.
- Responsible DisclosureResponsible or coordinated vulnerability disclosure (CVD): reporting a vulnerability to the vendor and fixing it before publication. Rules, deadlines and the law.
S
- SAST and DASTSAST analyses source code, DAST attacks the running application. What each finds and misses, where they fit in the pipeline, and why neither replaces a penetration test.
- SBOMAn SBOM lists every software component in a product with version and supplier. Formats, minimum elements, what the Cyber Resilience Act requires and how to use one.
- SCADASCADA systems supervise and control distributed processes such as power grids, water networks and pipelines. Architecture, protocols and the security issues they bring.
- Secure BootSecure boot verifies the signature of every stage of firmware before it runs. How the chain of trust works, where it is specified, and where it fails in real devices.
- Security Level (IEC 62443)Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).
- SOC (Security Operations Center)A SOC monitors systems around the clock, detects attacks and coordinates the response. What it consists of, what NIS2 expects, and when a managed SOC is better.
T
- TARA (Threat Analysis and Risk Assessment)TARA is the risk analysis method of ISO/SAE 21434 for vehicles and ECUs. The seven steps, how impact and attack feasibility are rated, and what a usable TARA looks like.
- Threat ModelingThreat modeling is the structured search for what can go wrong in a system before it is built. The four questions, STRIDE and attack trees, and how it feeds a pentest.
- TISAXTISAX is the automotive industry information security assessment, run by ENX on the VDA ISA catalogue. Assessment levels, labels, validity and practical demands.
U
- UDS (Unified Diagnostic Services)UDS, Unified Diagnostic Services per ISO 14229, is the diagnostic protocol of nearly every ECU. Which services exist, how access control works and what to test.
- UN R155UN Regulation No. 155 makes cybersecurity a condition for vehicle type approval. Who it applies to, the CSMS and vehicle requirements, and how the EU enforces it.
V
Z
- Zero TrustZero trust is a security model that grants no implicit trust based on network location. What NIST SP 800-207 defines, how it maps to OT and vehicles, and what it is not.
- Zones and conduitsZones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
How to use it
Definitions with a source, not marketing
Security vocabulary is full of terms that vendors use loosely. We define each one the way the standard or the law does, cite the source and then add what we see in practice: where the term shows up in a test, what typically goes wrong and what it costs to fix.
Entries link to the related guides, comparisons and tools. If a term is missing, tell us and we add it.
FAQ
About the glossary
Who writes the entries?
The Zyberum security team. Every entry is checked against the primary source it cites, usually the standard, the regulation or the vendor documentation, and carries the date of its last update.
Can I link to or quote an entry?
Yes. Each entry has a stable URL and a Markdown copy. Quote with a link to the page. For a reuse beyond a quotation, ask us.
Why does the glossary cover regulations as well as technical terms?
Because in product security they belong together. A term like SBOM is a technical artefact and a legal requirement under the Cyber Resilience Act at the same time. The entries explain both sides.
Get started
A term that applies to your product?
In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.
- Direct answer from a security engineer
- Which standard or law applies to you
- Free and without obligation

Your call is withTom ZaubermannFounder & CEO, Zyberum
Or send us a message
We reply within one business day.