Collection of points where a system can be attacked.

Running software in an isolated environment.

Component evaluating security or business policies.

Weakness that can be exploited.

Separating software or processes to limit interaction.

Component deciding whether an action is allowed.

Technique or code taking advantage of a vulnerability.

Separating workloads using container mechanisms.

Component enforcing policy decisions.

Software update fixing a security weakness.