SECURITY GLOSSARY

Clear definitions for modern security validation .

Terminology across continuous security validation, exposure management, control assurance, detection validation, runtime risk, attack paths, evidence, and AI security.

FEATURED TERMS

Three definitions using our entry template.

Every glossary term follows the same structure.

TERM
Evidence Contract
A structured specification of what artifacts and observations must be collected for a validation outcome to be considered proven.
WHY IT MATTERS
A finding without a matching evidence contract is not audit-ready. Contracts ensure every confirmed result is supported by the same artifacts across teams and runs.
HOW IT DIFFERS
Different from an evidence artifact (a single collected item) or evidence chain (the full linked history).
TERM
Attack Path
A validated sequence of conditions — exposure, identity, workload, control, and reachability — that connects an entry point to a business-critical asset.
WHY IT MATTERS
It converts scanner findings into a graph of reachable impact. Prioritization becomes reachability-driven, not just severity-driven.
HOW IT DIFFERS
Different from Attack Graph (the full set of validated relationships) and MITRE ATT&CK (a technique taxonomy).
TERM
Prompt Injection
A class of attacks in which untrusted input alters an AI system’s behavior, bypassing intended guardrails or tool constraints.
WHY IT MATTERS
LLM-backed applications, agents, and RAG systems increasingly reach sensitive data and privileged tools. Validation must include prompt-boundary and tool-abuse scenarios.
HOW IT DIFFERS
Different from jailbreaking (bypassing model policies) — prompt injection can occur even when the model itself is compliant.
TERM GROUPS

Six domains, dozens of terms.

CORE10 TERMS
Core Validation
Continuous Security ValidationGoverned Continuous Security ValidationExposure ValidationControl ValidationDetection ValidationRuntime Presence ValidationReachability AnalysisAttack Path SimulationAutonomous Penetration TestingRevalidation
EVIDENCE9 TERMS
Evidence
Evidence ArtifactEvidence ChainEvidence ContractEvidence PackageFinding EvidenceControl EvidenceDetection EvidenceRuntime EvidenceAudit-Ready Evidence
ATTACK8 TERMS
Attack Intelligence
Attack PathAttack GraphCrown JewelToxic CombinationBlast RadiusChoke PointBusiness ImpactIdentity Path
SECOPS7 TERMS
Security Operations
Detection CoverageTelemetry ReadinessDetection GapControl FailureControl DriftAlert LatencyCompensating Control
RUNTIME6 TERMS
Software & Runtime
Software Composition AnalysisSoftware Bill of MaterialsRuntime DependencyDependency ReachabilitySupply Chain RiskBring Your Own Scanner
AI7 TERMS
AI Security
Prompt InjectionAgent Tool AbuseRetrieval-Augmented GenerationRAG Data LeakageAI GuardrailModel Access ControlAI Attack Path
ENTRY TEMPLATE

Every glossary term follows the same structure.

01
Term
The word being defined.
02
Definition
Clear one-sentence explanation.
03
Why it matters
Operational or security significance.
04
How it differs
Related or confused terminology.
05
How Hayrok uses it
Where the concept appears in the product.
A-Z INDEX

Every term, alphabetically.

Click any term to jump to its full entry.

Attack Graph
A
The complete validated relationship model between assets, identities, controls, and impact.
Attack Path
A
A validated chain from exposure to impact.
Alert Latency
A
Time from behavior to actionable detection.
Blast Radius
B
The scope of impact if a condition is exploited.
Business Impact
B
The organizational consequence of reaching an asset.
Choke Point
C
A node whose remediation breaks many paths at once.
Control Drift
C
Measured change in a control’s behavior over time.
Continuous Security Validation
C
Ongoing testing of exposure, controls, detections, and reachability.
Detection Coverage
D
Share of expected behaviors producing actionable alerts.
Detection Gap
D
A behavior with no expected or actual detection.
Evidence Chain
E
The linked history of artifacts supporting a finding.
Evidence Contract
E
The required artifact specification for a validated result.
Governed Validation
G
Validation executed under scope, policy, safety, and approval controls.
Identity Path
I
A sequence of identity transitions used in an attack chain.
Prompt Injection
P
Adversarial input that alters AI system behavior.
Reachability
R
Whether a condition can be exercised from an entry point.
Revalidation
R
Re-execution of a scenario after remediation.
Scenario
S
A named, safe, and evidence-carrying validation procedure.
Toxic Combination
T
Individually low-risk conditions that combine to critical impact.
Telemetry Readiness
T
Whether required data sources produce needed events on time.
Validated Finding
V
A finding backed by an evidence contract.
Validation Objective
V
The security outcome an assessment aims to prove.
COMPANION READING

Handbooks that use this vocabulary in production.

REFERENCE
Vocabulary of Modern Security
Field-tested definitions
Vocabulary of Modern Security
Field-tested definitions
Download PDF →
COOKBOOK
The Evidence Contract Book
Templates & examples
The Evidence Contract Book
Templates & examples
Download PDF →
PRIMER
Attack Paths in Plain English
A leader’s primer
Attack Paths in Plain English
A leader’s primer
Download PDF →
GUIDE
AI Security Terminology
From prompts to agents
AI Security Terminology
From prompts to agents
Download PDF →
USED BY OUR CUSTOMERS

How security teams talk about validation.

We standardized our internal vocabulary on the Hayrok glossary. Cross-team conversations got 40% faster.
PC
Priya Chandra
Head of ProdSec · Fortune 200 Retailer
Vendor-neutral where it can be, product-aware where it needs to be. Exactly what we needed.
MC
Marcus Chen
IT Audit Partner · Big 4
The AI security terms alone are worth bookmarking. First glossary that actually gets prompt injection right.
AI
Amara Iwuchukwu
Head of AppSec · B2B SaaS

Speak the language of evidence-driven validation.

The Hayrok glossary is vendor-neutral where possible and product-aware where it matters.