Rules governing security practices.

Replacing sensitive data with non-sensitive tokens.

Secret cryptographic key known only to its owner.

Examination of security controls and practices.

Hiding sensitive information while retaining its structure.

Cryptographic proof of message authenticity and integrity.

Automated search for known weaknesses.

Sensitive values such as passwords and API keys.

Fixed-size value generated from input data.

Authorized simulated attack used to evaluate security.