# Security terms, explained by the people who test them.

> The Zyberum glossary defines terms from penetration testing, IoT, automotive, OT and IT security and from the EU regulations that apply to them: Cyber Resilience Act, NIS2, RED and EN 18031, IEC 62443, ISO/SAE 21434 and UN R155. Every entry names its source.

Plain-language definitions of cybersecurity terms from penetration testing, IoT, automotive and OT security, and the EU regulations CRA, NIS2, RED and IEC 62443.

Source: https://zyberum.com/glossary

Each entry answers in a few sentences what a term means, where it is defined and what it means for your product or plant. Written by security engineers, checked against the standards.

## From attack surface to zero trust

## Definitions with a source, not marketing

Security vocabulary is full of terms that vendors use loosely. We define each one the way the standard or the law does, cite the source and then add what we see in practice: where the term shows up in a test, what typically goes wrong and what it costs to fix.

Entries link to the related guides, comparisons and tools. If a term is missing, tell us and we add it.

## FAQ

**Who writes the entries?**

The Zyberum security team. Every entry is checked against the primary source it cites, usually the standard, the regulation or the vendor documentation, and carries the date of its last update.

**Can I link to or quote an entry?**

Yes. Each entry has a stable URL and a Markdown copy. Quote with a link to the page. For a reuse beyond a quotation, ask us.

**Why does the glossary cover regulations as well as technical terms?**

Because in product security they belong together. A term like SBOM is a technical artefact and a legal requirement under the Cyber Resilience Act at the same time. The entries explain both sides.

---
Zyberum GmbH. Canonical page: https://zyberum.com/glossary
