List of prohibited items.

Identifying and evaluating potential security threats.

Tool detecting potentially insecure coding patterns.

Security rule explicitly preventing an action.

Collection of points where a system can be attacked.

Running software in an isolated environment.

Component evaluating security or business policies.

Weakness that can be exploited.

Separating software or processes to limit interaction.

Component deciding whether an action is allowed.