FastPass IT Security Glossary
Unlock Your Cybersecurity Know-How with FastPass: Your IT Security Glossary Guide.
International Information System Security Certification Consortium
A process for regularly reviewing and validating the access rights and privileges assigned to users.
A process for regularly reviewing and validating the access rights and privileges assigned to users.
The practice of managing and controlling user access across an organization's IT infrastructure.
A formal request made by a user or administrator to obtain specific access permissions or privileges.
The specific permissions and access rights assigned to a user or account, often based on their role or responsibilities.
Account Takeover (ATO) is a form of identity theft where an unauthorized person gains control of a user's digital account by obtaining credentials, bypassing authentication, or fraudulently convincing others to grant access on behalf of the legitimate user.
A formal request made by a user or administrator to obtain specific access permissions or privileges.
A formal request made by a user or administrator to obtain specific access permissions or privileges.
Australian Cyber Security Centre
A directory service used by Microsoft Windows domains to store and organize information about network resources and users.
A feature that allows external users to access an organization's resources using their own credentials, while maintaining security and compliance.
Measures and controls implemented to secure Active Directory, including authentication, access control, and policies.
Active Directory
A directory service used by Microsoft Windows domain networks that authenticates and authorizes users and computers.
A feature that allows external users to access an organization's resources using their own credentials.
A service that helps organizations manage, control, and monitor access within Azure AD.
A set of pre-configured security settings recommended by Microsoft to help protect Azure AD environments.
An approach that dynamically adjusts access controls based on contextual factors, such as user behavior or location.
An account with elevated privileges used by administrators to perform system-level tasks and configurations.
Advanced Encryption Standard
A symmetric encryption algorithm widely used to secure sensitive data.
Identifying unusual patterns or behavior in network traffic or system activities that may indicate a security threat.
Application Programming Interface
Implementing measures to secure Application Programming Interfaces (APIs) against unauthorized access and misuse.
Risk of unauthorized access to or manipulation of APIs
Biometric authentication methods used on Apple devices, utilizing facial recognition and fingerprint scanning for identity verification.
Allowing only approved applications to run on a system, reducing the risk of malicious software.
Advanced Persistent Threat
Manipulating ARP (Address Resolution Protocol) to associate fake MAC addresses with IP addresses
Categorizing and labeling IT assets based on their importance and sensitivity for effective security management.
Security practices for tracking and managing IT assets, ensuring that devices and software are accounted for and secure.
An Identity as a Service (IDaaS) platform offering mobile app authentication and other identity solutions.
The process of verifying the identity of a user, system, or entity to ensure that they are who they claim to be.
Something We Know: Authentication based on knowledge possessed by the user, such as passwords, PINs, or security questions.
Something We Have: Authentication based on possession of a physical item, such as a smart card, security token, or mobile device.
Something We Are: Authentication based on biometric characteristics unique to the individual, such as fingerprints, iris scans, or facial recognition
Defining and managing the level of access that service desk personnel have to different IT resources based on their roles and responsibilities.
Security measures and features related to Azure AD.
A service that allows organizations to provide secure remote access to on-premises applications.
Features allowing external users to access resources using their own credentials.
Features and capabilities within Azure AD that enable organizations to manage and secure access for external users.
A service that leverages machine learning and security analytics to detect and respond to identity-based risks within Azure AD.
A feature that allows administrators to grant temporary privileged access to users in Azure AD.
A service that helps organizations manage, control, and monitor access within Azure AD.
A set of pre-configured security settings recommended by Microsoft to help protect Azure AD environments.
A service that provides insights into potential security threats and vulnerabilities within Azure AD.
Business-to-Business
Offering something enticing to manipulate individuals into divulging sensitive information or taking an action.
A specially configured server that is hardened and secured to provide controlled access to critical systems.
Analyzing patterns of user behavior to detect deviations or anomalies that may indicate a security threat.
Analyzing user behavior patterns for additional security within password self-service.
Utilizes unique physical or behavioral characteristics of an individual for identity verification.
The use of biometric data (fingerprint, facial recognition) as a method of identity verification within password self-service systems.
Confirming a user's identity through biometric data, such as fingerprints or facial recognition, often used in advanced confirmation methods.
A unique digital representation of a person's biometric data (e.g., fingerprint or facial features), used for comparison during biometric authentication.
A decentralized and distributed ledger technology that ensures the integrity and immutability of data by using cryptographic hashes and consensus algorithms.
Defending against simulated attacks, often in the context of a red team/blue team exercise.
Sending unsolicited messages to Bluetooth-enabled devices.
Unauthorized access to information on a Bluetooth-enabled device.
Emergency procedures for accessing privileged accounts or systems in critical situations, often requiring multiple authorizations.
An attack method where an attacker systematically attempts all possible password combinations until the correct one is found, typically requiring significant computing power.
Potential for remote code execution.
Bring Your Own Device
A challenge-response test designed to differentiate between human users and automated bots, commonly used during authentication to prevent automated attacks.
European Organization for Nuclear Research
Computer Emergency Response Team
An entity responsible for issuing and managing digital certificates for secure communication.
Documenting the chronological history of evidence to maintain its integrity and admissibility in legal proceedings.
A method where the authentication process involves a challenge presented to the user, and the correct response is required for access to be granted.
Authentication processes where users respond to a challenge, often used in secure login and communication protocols.
Cybersecurity and Infrastructure Security Agency
Cybersecurity and Infrastructure Security Agency
Chief Information Security Officer
Tricking users into clicking on a hidden link disguised as a legitimate element
Security measures and practices designed to protect data, applications, and infrastructure in cloud environments.
Policies in Azure AD that evaluate conditions before allowing access to resources, enhancing security based on user, device, location, and other factors.
A pop-up or dialog box that appears on a user interface, prompting users to confirm a critical action or change in settings.
An email sent to users to confirm their registration, account creation, or a change in account settings, often containing a verification link or code.
The time limit within which a confirmation link must be clicked or used to confirm an action or registration, after which it becomes invalid.
The process of invalidating or revoking a confirmation link to prevent unauthorized use or access.
A clickable link sent in a confirmation email that, when accessed, verifies the user's email address and confirms their registration or action.
A pop-up window or overlay that appears on a webpage, prompting users to confirm a specific action or verify their identity.
A webpage or interface that users are directed to after successfully confirming their registration, providing feedback and possibly next steps.
Automatically directing users to a specific webpage after successful confirmation, providing a seamless user experience.
A text message sent to users containing a verification code or confirmation link to verify their identity.
Indicating whether a user has successfully confirmed their identity or completed a confirmation process, often displayed in user account settings.
A specified period within which a user must confirm their action, registration, or identity, after which the confirmation link or code may expire.
A unique token or string of characters generated during the confirmation process, validating the user's action or identity.
The process of invalidating or revoking a confirmation token to prevent unauthorized use or access.
The series of steps guiding users through the confirmation process.
Ensuring the security of containerized applications and their runtime environments.
Corporate-Owned, Personally Enabled
The practice of handling and securing user credentials, including password storage, retrieval, and authentication processes.
The practice of regularly changing passwords or access credentials for privileged accounts to enhance security.
An attack where cybercriminals use previously leaked usernames and passwords to gain unauthorized access.
Unauthorized actions performed on behalf of the user
A type of web vulnerability where attackers inject malicious scripts into web pages viewed by other users, often leading to the theft of sensitive information.
Potential for client-side attacks and data theft.
A mathematical algorithm that transforms input data into a fixed-size string of characters, commonly used for data integrity verification.
The practice and study of techniques for securing communication and data, often used in password protection through algorithms that encode and decode information.
The administration of cryptographic keys used to secure data, ensuring proper generation, storage, and disposal.
Cloud Security Alliance
Computer Security Incident Response Team
Cross-Site Request Forgery
Cyber Threat Intelligence Integration Center
Threatening individuals or organizations with exposure of sensitive information unless a ransom is paid.
The ability of an organization to withstand, recover from, and adapt to cyber threats and incidents.
A part of the internet that is intentionally hidden and often used for illegal or malicious activities.
The process of converting data into a coded form to prevent unauthorized access, especially during transmission or storage.
Measures and tools designed to prevent the unauthorized access, transfer, or disclosure of sensitive data.
Encrypting sensitive data stored in databases to protect it from unauthorized access.
Distributed Denial of Service
A type of DoS attack where multiple compromised systems are used to flood a network, service, or website with traffic, making it unavailable.
Granting specific administrative privileges to non-administrative users for managing certain tasks or resources.
Verifying a user's identity by confirming access from a trusted device, often used as an additional layer of security.
A type of brute force attack where an attacker uses a precompiled list of common passwords or dictionary words to attempt unauthorized access.
The process of collecting, analyzing, and preserving digital evidence for investigative purposes.
Creating fake online profiles or personas to deceive individuals and gather information or manipulate emotions.
A cryptographic technique that provides authentication, data integrity, and non-repudiation by associating a digital key with a piece of electronic information.
A documented plan outlining procedures for restoring IT systems and data in the event of a disaster.
Identifying and mapping privileged accounts and access rights within an IT environment to establish a baseline for security.
Spreading false or misleading information to manipulate public opinion or deceive individuals for specific purposes.
Data Loss Prevention
Domain-based Message Authentication, Reporting, and Conformance
Demilitarized Zone
Domain Name System
Implementing measures to protect the Domain Name System (DNS) from attacks and unauthorized access.
Manipulating DNS responses to redirect users to malicious sites.
A server within a Windows domain that authenticates users, enforces security policies, and manages access to network resources.
A set of security settings applied to an entire domain in AD, including password policies, account lockout policies, and user rights assignments.
Denial-of-Service Attack
Forcing a system to use a less secure version of a protocol
Automatically downloading malware onto a user's device without their knowledge
Physically searching through discarded materials, such as trash bins, to find information that can be used for social engineering.
An authentication solution supporting two-way authentication as part of its comprehensive security offerings.
Unauthorized interception of communications
European Cybercrime Centre
European Cyber Security Competence Center
European Cyber Security Month
European Cyber Security Organisation
Electronic Crimes Task Forces
European Data Protection Board
Endpoint Detection and Response
Electronic Frontier Foundation
European Information Security Certification Consortium
Extracting information from individuals through conversation or subtle questioning without raising suspicion.
A clickable link sent in a confirmation email that, when accessed, verifies the user's email address and confirms their registration or action.
A method of confirming a user's identity by sending a verification code or link to their registered email address during the password self-service process.
The administration and control of cryptographic keys used for encryption and decryption processes.
Security solutions that continuously monitor and respond to security threats on endpoints.
Measures and tools in place to secure end-user devices (endpoints) against security threats, including malware and unauthorized access.
European Network and Information Security Agency / European Union Agency for Cybersecurity
The process of managing and controlling access entitlements, ensuring users have only the necessary privileges for their roles.
European Security and Defence College
European Telecommunications Standards Institute
European Union Agency for Law Enforcement Cooperation
Creating a fake Wi-Fi network to intercept communications
A piece of software or code that takes advantage of a vulnerability to carry out an attack.
FastPass solution for user identity verification at the help desk - on-premises and cloud.
An approach that allows users to access multiple systems or applications using a single set of credentials, managed across different organizations.
Federal Risk and Authorization Management Program
Devices adhering to the FIDO2 standard, enabling passwordless authentication through biometrics or other secure methods.
A network security device that monitors and controls incoming and outgoing network traffic based on predetermined security rules.
A set of criteria defining how a firewall should handle specific network traffic, either allowing or blocking it.
Global Cyber Alliance
General Data Protection Regulation
Restricting access to password self-service features based on the user's geographical location to enhance security.
A multi-factor authentication app providing time-based one-time passcodes (TOTPs) for enhanced security.
A feature in Windows operating systems that allows administrators to manage and enforce security settings across a network.
A specific type of message authentication code involving a cryptographic hash function and a secret cryptographic key for data integrity verification.
A decoy system or network set up to attract and detect attackers, helping to gather information about their tactics and techniques.
Gathering information by directly interacting with individuals through conversations and interpersonal relationships.
The process of verifying that a user is who they claim to be, often through the use of confirmation codes, links, or additional authentication methods.
The process of confirming that an individual is who they claim to be, often required during password self-service to prevent unauthorized access. Confirming an individual's identity, often involving verification codes or methods.
See: FastPass IVM
Intrusion Detection System
Refers to the process of confirming a user’s claimed identity through various methods (e.g., government-issued IDs, biometrics, or other verification data). It’s a critical step in ensuring secure access and preventing unauthorized or fraudulent usage.
Internet Engineering Task Force
Pretending to be someone else, often a trusted individual or authority figure, to deceive and manipulate victims.
Unauthorized access and data exposure
Risk of data loss in case of system failures
Exposure to network-based attacks
Difficulty in detecting and responding to incidents
Categorizing security incidents based on their nature and impact for appropriate response and analysis.
Measures to secure the documentation and records related to security incidents, ensuring confidentiality and integrity.
The process of identifying, responding to, and mitigating security incidents, including breaches, attacks, or other security events.
A structured approach to addressing and managing the aftermath of a security incident.
A systematic approach to managing and protecting an organization's information assets.
Risk of executing malicious code on the server.
Vulnerability to attacks on connected devices.
Vulnerability to network-based attacks.
Security risks posed by individuals within an organization, intentionally or unintentionally causing harm.
Increased risk of unauthorized access
Security measures and practices to protect devices and data in the interconnected network of IoT devices.
Security measures and controls implemented to protect an organization's internal network and resources from unauthorized access and cyber threats.
A security tool that monitors network or system activities for malicious behavior or policy violations.
A security tool that actively monitors and blocks or prevents identified threats or intrusions.
Indicator of Compromise
Internet of Things
Intrusion Prevention System
Information Sharing and Analysis Centers
Information Systems Audit and Control Association
International Organization for Standardization
Internet Society
Internet Security Research Group
Granting elevated privileges to users only for the time necessary to perform a specific task, reducing the overall attack surface.
JSON Web Token
A network authentication protocol used in AD for secure authentication between clients and servers.
A network authentication protocol integrated into Active Directory for secure authentication between clients and servers.
Malicious software or hardware designed to record keystrokes, capturing sensitive information such as usernames and passwords.
Security controls and access restrictions applied to the service desk's knowledge base to protect sensitive information preventing unauthorized access or changes.
Know Your Customer (KYC) means verifying external customers during onboarding and transactions.
Risk of data interception and exposure
Risk of unauthorized access to user sessions
Vulnerability to web-based attacks
Local Area Network
A password management solution focused on secure storage and management of passwords for users.
A protocol used to access and manage directory information in AD, facilitating communication between client applications and the directory service.
The security principle of providing users and systems with the minimum level of access or permissions needed to perform their tasks.
Analyzing log files generated by systems and applications to identify security events and anomalies.
Mandatory Access Control
A subset of artificial intelligence that enables systems to learn and improve from experience without being explicitly programmed.
Distributing malware through online advertising
Implementing access controls to restrict unauthorized access to the manager verification process for password resets.
The process of seeking managerial authorization before resetting a user's password, adding an extra layer of security.
The defined sequence of steps and interactions involving a manager to approve and verify a password reset request for a team member.
Verifying the identity of a user's manager through secure authentication methods as part of the password reset approval process.
The established set of protocols and methods used to authenticate the manager's identity during the password reset approval.
A unique code or token provided to the manager for entering during the password reset process to confirm their approval.
An email sent to the user's manager, containing a confirmation link or code, to validate their authorization for a password reset.
A unique token or code generated for the manager during the password reset approval process, confirming their authorization.
The process of confirming the identity of a user's manager through secure means before allowing them to approve a password reset.
Providing a secure online platform where managers can authenticate themselves and approve password reset requests for their direct reports.
Defining and enforcing the role of a user's manager in the password reset process, ensuring proper authorization and security.
Applying RBAC principles to control the level of access managers have in the password reset process, ensuring proper authorization.
Allowing managers to securely reset the passwords of their team members, following established authentication and authorization protocols.
The step where a user's manager is required to confirm and validate a password reset request initiated by the user.
Allowing managers to initiate the password reset process for their team members, subject to secure authentication and authorization.
A cybersecurity attack where an unauthorized third party intercepts and possibly alters the communication between two parties without their knowledge or consent.
Various psychological and emotional tactics used to manipulate individuals into disclosing information or taking specific actions.
Authentication methods that require users to provide multiple forms of identification.
Implementing additional authentication factors to enhance security in the service desk's access controls.
A mobile app offering multi-factor authentication, supporting various authentication methods for Microsoft accounts.
A feature within Azure AD that enables the creation of policies evaluating conditions before granting access to resources, enhancing security.
A solution facilitating federated identity management in Windows environments, allowing users to access multiple systems with a single set of credentials.
Using psychological tactics, manipulation, and psychological pressure to influence individuals' behavior or decisions.
Increased attack surface and potential exploitation.
Exposure to potential web-based vulnerabilities
Man-in-the-Middle
Utilizing mobile applications for secure authentication and password management within self-service systems.
Utilizing mobile applications for secure authentication within the service desk's access and self-service systems.
Verifying a user's identity by confirming ownership of a mobile number through the receipt of a verification code via SMS.
Security measures and controls implemented to protect mobile devices and the data they contain from unauthorized access and cyber threats.
Allowing users to authenticate themselves through multiple channels (e.g., email, SMS, mobile app) within the password self-service process.
Allowing users to authenticate themselves through multiple channels within the service desk's access and self-service processes.
Authentication requiring two or more forms of verification from different categories, enhancing security.
Implementing additional authentication factors to enhance security in Azure AD.
Implementing additional authentication factors for privileged accounts to enhance security.
Implementing additional authentication factors to secure access to service desk tools and systems, enhancing overall security.
Implementing additional authentication factors, such as phone verification or biometrics, to enhance security in Azure AD.
National Cybersecurity Center of Excellence
National Cyber Security Centre
National Security Cyber Specialist Network
Measures and controls implemented to protect the integrity, confidentiality, and availability of data in a network.
Measures and controls implemented to protect the integrity, confidentiality, and availability of data in the service desk's network.
Dividing a network into separate segments to limit the potential impact of security incidents and control access.
National Institute of Standards and Technology
National Security Agency
Open Authorization
An identity and access management (IAM) solution providing mobile app authentication and other authentication features.
Deceptive schemes where attackers create fake online personas to establish romantic relationships for financial gain.
Managing and securing open-source software to prevent vulnerabilities and ensure code integrity.
One-Time Password
Open Web Application Security Project
A sequence of words or a sentence used as a secure password.
A secret word used to get access to computer systems and physical facilities.
A method of authenticating a user based on a secret password.
Alerts or notifications sent to users in advance of their passwords expiring, prompting them to update their passwords through self-service.
The process of converting a password into a fixed-length string of characters using a hash function.
A security feature that prevents users from reusing previous passwords when updating their credentials through self-service.
The process of securely handling, storing, and controlling access to user passwords to prevent unauthorized access.
Practices and tools for managing and securing user passwords, including password reset and recovery processes.
The implementation and monitoring of rules and requirements to ensure that users adhere to specified password policies.
The implementation of password policies within the self-service portal to ensure that new passwords meet specified security requirements.
The process of confirming a user's identity using various methods.
The process of allowing users to regain access to their accounts by resetting their passwords, often through a self-service mechanism.
A password reset portal is a secure online interface that allows users to reset their forgotten or expired passwords, in different target systems, without needing assistance from IT support.
By verifying user identity through methods like SMS codes, TOTP codes, push authentication, email codes and question and answres these portals ensure only authorized users can reset their passwords. This self-service tool helps reduce IT support workload and improve user convenience and security.
The practice of regularly changing passwords, reducing the risk associated with long-term use and potential exposure.
Systems that allow users to manage and reset their passwords without the need for direct assistance from support staff.
A visual indicator that informs users about the strength of their chosen passwords during the self-service password update process.
A secure repository for storing and managing privileged account credentials, often using encryption and access controls.
Authentication methods that do not require traditional passwords, such as biometrics, smart cards, or mobile-based authentication.
Enabling users to authenticate and manage their passwords without using traditional passwords, often through methods like biometrics or mobile authentication.
The systematic process of applying updates, patches, and fixes to software and systems to address vulnerabilities and improve security.
The systematic process of applying updates, patches, and fixes to software and systems used by the service desk.
A designated day when software vendors release security patches and updates.
Payment Card Industry Data Security Standard
The practice of testing a computer system, network, or application to identify security vulnerabilities that could be exploited by attackers.
Redirecting users from a legitimate website to a fraudulent one
Redirecting users from a legitimate website to a fraudulent one
Training and education programs to help personnel recognize and respond to phishing attempts.
Simulating phishing attacks to educate users and test an organization's susceptibility to phishing threats.
Risk of unauthorized physical access to systems
Exploiting human interactions, trust, and psychological factors to gain physical access or information.
Privileged Identity Management
An IAM solution offering mobile app authentication and secure identity management services.
Public Key Infrastructure
Detecting open ports on a network to identify potential vulnerabilities or security risks.
Creating a fabricated scenario or pretext to manipulate individuals into revealing confidential information.
Integrating privacy measures into the design and development of systems and applications from the outset.
A document outlining how an organization collects, uses, and manages user data while ensuring privacy and compliance.
A document outlining how an organization collects, uses, and manages user data while ensuring privacy and compliance.
The monitoring, recording, and controlling of sessions involving privileged accounts to prevent misuse and enhance accountability.
Offering a service or benefit in exchange for sensitive information or access, exploiting the principle of reciprocity.
Deceptive online quizzes or surveys designed to trick individuals into providing personal information.
Malicious software that encrypts files and demands payment for their release.
Deceptive tactics used in conjunction with ransomware attacks, often involving tricking individuals into opening malicious files or links.
Remote Access Trojan
Role-Based Access Control
A system that controls access to Azure resources based on roles assigned to users, groups, or applications.
Remote Desktop Protocol
A unique code or token provided to users during account setup for account recovery.
Simulating adversarial attacks to assess an organization's security posture.
A security exercise where one team simulates attackers, and the other defends against simulated attacks.
Security measures and protocols for ensuring the secure access of remote users to IT services and resources.
Measures and controls in place to secure the service desk's remote support tools, preventing unauthorized access or misuse.
Manipulating individuals in authority or trusted positions to gain information or access to secure areas.
Evaluating potential risks and vulnerabilities to determine their likelihood and potential impact.
An adaptive authentication approach that evaluates the risk level of a login attempt based on various factors.
Unauthorized devices attempting to connect to a network
Malicious software disguised as legitimate applications to deceive users into installing and compromising their systems.
Policies that define and manage the level of access that users or groups have to specific resources.
Controlling access to Azure resources based on assigned roles.
Policies defining and managing the level of access that users or groups have to privileged resources based on their roles.
Deceptive schemes where attackers form romantic relationships with individuals online to exploit them financially.
An adaptive authentication platform providing multi-channel authentication capabilities, dynamically adjusting security measures based on user behavior.
A widely used token-based authentication solution providing one-time passcodes for secure user verification.
Security Assertion Markup Language
Falsely warning individuals about non-existent threats to prompt them to take a specific action, such as purchasing fake security software.
Encrypted and protected channels for communication between service desk staff and end-users.
A set of processes and practices designed to integrate security into the software development process.
Implementing secure methods for transferring files and data between the service desk and end-users.
Procedures for securely recording and storing logs of security incidents and service desk interactions.
Utilizing remote support tools with built-in security features for secure troubleshooting and assistance.
Utilizing remote support tools with built-in security features for secure troubleshooting and assistance by the service desk.
A security platform offering multi-channel authentication capabilities, focusing on adaptive authentication for enhanced security.
The design and structure of an organization's security infrastructure, including networks, systems, and applications.
Educational programs for increasing awareness about security risks and best practices.
Educational programs for service desk staff to enhance understanding of security threats and promote secure practices.
A set of security standards and configurations established to provide a secure starting point for systems and applications.
The collective behaviors, attitudes, and awareness of an organization's members towards security.
The framework and processes that ensure security objectives are achieved effectively and aligned with organizational goals.
A group in AD created for granting access permissions to resources and managing resources efficiently.
An event that compromises the confidentiality, integrity, or availability of information, requiring investigation and response.
Procedures for securely recording and storing logs of security incidents and service desk interactions for auditing and analysis.
A documented plan outlining the steps and procedures to be followed in the event of a security incident.
A comprehensive approach to security management that combines the capabilities of SIM and SEM.
Sharing threat intelligence and information about security incidents with other organizations or entities.
Increased vulnerability to various attacks
A centralized unit responsible for monitoring, detecting, responding to, and mitigating security threats.
A set of rules and practices defining how an organization manages and protects its information assets.
The overall security status and strength of an organization, including policies and measures.
A physical or virtual device generating or receiving authentication codes for security.
Using physical or virtual security tokens as an additional factor in self-service systems.
The administration and management of security tokens.
Invalidating or revoking a security token.
A service issuing security tokens for secure access to applications and services.
Substituting sensitive data with a unique identifier (token) for enhanced security.
Balancing usability and security in authentication processes.
Balancing user-friendly authentication processes with a high level of security.
A weakness or flaw in a system or application that could be exploited.
Identifying, assessing, and mitigating vulnerabilities to prevent exploitation.
A certification for IT professionals covering foundational security knowledge.
Logging and monitoring user activities within the self-service portal to create an audit trail for security and compliance purposes.
An online platform allowing users to perform tasks without direct assistance.
The series of steps guiding users through self-service processes.
Applying security measures to enhance the resilience and security of servers against potential threats.
Processes and procedures for authenticating users seeking assistance from the service desk, ensuring secure access to support services.
The specific methods and protocols used to authenticate users contacting the service desk.
Educational programs for enhancing understanding of security threats among service desk staff.
Pre-configured security settings recommended for service desk environments.
Written guidelines defining the acceptable use of IT resources and detailing security practices.
Training programs for service desk staff to enhance their understanding of security.
Measures and controls for securing the service desk's ticketing system.
Taking over an established user session
The process of controlling and securing user sessions during their interaction with an application or system.
The process of controlling and securing user sessions during their interaction with the service desk's systems and applications.
Capturing and storing the activities and commands executed during a privileged session for auditing, analysis, and compliance.
A specified period of inactivity after which a user session is terminated.
A token generated during user login and used to identify and authenticate the session.
Security Industry Association
A unique alphanumeric string assigned to each object in Active Directory for identification.
A comprehensive approach to security management combining SIM and SEM.
Allows users to access multiple systems or applications with a single set of login credentials, streamlining the authentication process and improving user experience.
Allowing users to access multiple systems or applications with a single set of login credentials, enhancing efficiency and security.
Security Operations Center
Deceptive techniques used to manipulate individuals into divulging confidential information.
Educational programs to raise awareness among individuals about the tactics and risks associated with social engineering.
A group of ethical hackers or security professionals simulating social engineering attacks to test an organization's security awareness.
A collection of tools used by attackers to perform social engineering attacks and penetration testing.
A collection of tools used by attackers to perform social engineering attacks and penetration testing.
Targeted phishing attacks directed at specific individuals or organizations, often using personalized information.
Targeted phishing attacks directed at specific individuals or organizations, often using personalized information.
Risk of unauthorized database access
Secure Sockets Layer
Downgrading secure HTTPS connections to insecure HTTP
Protocols providing secure communication over a computer network.
A method allowing users to access multiple systems with a single set of credentials.
A level of authentication using multiple robust factors for enhanced security.
A computer worm designed to damage industrial systems.
Following an authorized individual into a secure area by closely trailing them, exploiting the lack of physical security awareness.
A Temporary Access Pass (TAP) is a short-lived, time-limited passcode designed to let users sign in or register for multi-factor authentication without using a permanent password. For example, in Microsoft Entra (Azure AD), an administrator can issue a Temporary Access Pass to help a new user securely set up their account or to quickly restore access if a user has lost their credential factors. Once the pass expires, it can no longer be used, which helps maintain strong security and reduces reliance on permanent passwords.
Trusted Computing Group
Proactively searching for signs of malicious activity within an organization's network and systems.
Information about potential or current cybersecurity threats to help organizations understand and prepare for attacks.
Information about potential or current cybersecurity threats to help the service desk understand and respond to security risks.
Limiting access to privileged accounts based on specific time periods or schedules to enhance security.
Transport Layer Security
Involves the use of a physical or virtual token to generate one-time passwords, adding an additional layer of security beyond traditional passwords.
The process of substituting sensitive data with a unique identifier (token) for enhanced security.
Manipulating trust relationships to deceive individuals into disclosing information or taking harmful actions.
Authentication requiring two distinct forms of verification, typically combining categories like something we know and something we have.
Using two forms of authentication for accessing privileged accounts to add an extra layer of security.
A security process requiring users to verify their identity through two different methods.
A firewall that monitors and controls both incoming and outgoing network traffic for enhanced security.
Registering domains with common typos to catch users' mistakes
Risk of data breaches, data loss, or system compromise
Exposure to known vulnerabilities
The balance between making authentication processes user-friendly while ensuring a high level of security.
Leaving infected USB drives in public places with the hope that individuals will pick them up and insert them into their computers.
United States Computer Emergency Readiness Team
Processes for creating, modifying, and deactivating user accounts to maintain security.
The process of verifying the identity of a user
The process of users confirming their registration, actions, or identity.
The series of steps and interactions guiding users through the confirmation process.
The series of steps and interactions guiding users through the confirmation process within the service desk's self-service systems.
The process of confirming a user's identity using various methods.
A policy defining rules for temporarily locking user accounts after multiple failed login attempts.
The ability for users to perform various tasks without direct assistance from support staff.
An online platform allowing users to perform various tasks independently.
The series of steps guiding users through self-service processes.
A secure connection that allows users to access a private network over the internet.
Securing virtualized environments and ensuring the isolation and integrity of virtual machines.
Securing virtualized environments and ensuring the isolation and integrity of virtual machines.
Voice phishing, where attackers use phone calls to deceive individuals into providing sensitive information or taking specific actions.
Virtual Local Area Network
A method of confirming a user's identity through an automated voice message.
Virtual Private Network
Ensuring the security of Virtual Private Network (VPN) connections used for secure remote access.
The automated process of identifying and assessing security vulnerabilities.
The automated process of identifying and assessing security vulnerabilities in systems and applications used by the service desk.
Web Application Firewall
Wide Area Network
Compromising a website frequented by a specific group of individuals to infect their devices with malware or gather information.
Increased likelihood of unauthorized access
A security tool protecting web applications from various online threats.
A security tool protecting web applications used by the service desk from various online threats, ensuring a secure user experience.
A security solution that monitors and filters web traffic to protect against web-based threats.
A passwordless authentication solution in Windows environments, utilizing biometrics or PIN for user identification.
Policies and settings defining the security configuration of Windows systems.
Vulnerability to unauthorized access via Wi-Fi
Measures and protocols for securing wireless networks and devices.
Measures and protocols for securing wireless networks and devices used by the service desk, preventing unauthorized access.
Workforce Identity Verification (Workforce IDV) confirms the identity of employees and contractors accessing corporate systems. Unlike Customer Identity Verification (KYC), which focuses on onboarding new consumers, Workforce IDV protects internal access points like the IT Service Desk.
Cross-Site Scripting
A type of security vulnerability in web applications that allows attackers to inject malicious scripts.
A hardware-based authentication device supporting various authentication protocols and providing a secure alternative to traditional passwords.
Security model based on the principle of "never trust, always verify"
A security approach that assumes no trust by default and requires verification from anyone attempting to access resources.
An attack that takes advantage of a software vulnerability on the same day it becomes publicly known that is not yet known or patched
Protect your Passwords today with FastPass
Get in touch with us today by filling up the form and our team will get back to you as soon as possible.