Authorized simulated attack used to evaluate security.

Boot process verifying trusted software components.

Function producing a hash from arbitrary input.

Identifying threats and designing defenses.

Running software in an isolated environment.

Random data added before password hashing.

Programming practices designed to reduce vulnerabilities.

Boundary separating resources with different trust levels.

Percentage of time a service is operational.

Potential impact resulting from a threat exploiting a vulnerability.