---
title: "Application Security Glossary"
date: "2024-09-30T08:52:51+00:00"
url: "https://staging.checkmarx.com/glossary/"
description: "Checkmarx AppSec glossary is created to enhance your cybersecurity knowledge. Gain clarity on key terms, technologies, and their significance in today's dynamic threat landscape."
---

# Application Security Glossary

# Application Security Glossary

Explaining essential AppSec terminology in a comprehensive resource. Explore the page to gain a thorough understanding of key concepts in application security. Having a clear grasp of these terms empowers you to make informed decisions and navigate the ever-evolving AppSec landscape.

- [A](#A)
- [B](#B)
- [C](#C)
- [D](#D)
- [E](#E)
- [F](#F)
- [G](#G)
- [H](#H)
- [I](#I)
- [J](#J)
- [K](#K)
- [L](#L)
- [M](#M)
- [N](#N)
- [O](#O)
- [P](#P)
- [Q](#Q)
- [R](#R)
- [S](#S)
- [T](#T)
- [U](#U)
- [V](#V)
- [W](#W)
- [X](#X)
- [Y](#Y)
- [Z](#Z)

A

 [Agile Security](https://staging.checkmarx.com/glossary/agile-security/)

 [AI Security](https://staging.checkmarx.com/glossary/what-ai-security/)

 [API](https://staging.checkmarx.com/glossary/api/)

 [API Security](https://staging.checkmarx.com/glossary/what-is-api-security/)

 [Application Lifecycle Management (ALM)](https://staging.checkmarx.com/glossary/application-lifecycle-management-alm/)

 [Application Security Vulnerability](https://staging.checkmarx.com/glossary/application-vulnerability/)

 [ASCA](https://staging.checkmarx.com/glossary/what-is-ai-code-security-assistance-acsa/)

 [ASPM](https://staging.checkmarx.com/learn/aspm/what-is-aspm/)

B

 [Bamboo Static Code Analysis](https://staging.checkmarx.com/glossary/bamboo-static-code-analysis-2/)

 [Botnet Detection and Prevention](https://staging.checkmarx.com/glossary/botnet-detection-and-prevention/)

 [Build Server](https://staging.checkmarx.com/glossary/build-server/)

C

 [C# Static Code Analysis](https://staging.checkmarx.com/learn/sast/effective-static-source-code-analysis/)

 [C++ Static Code Analysis](https://staging.checkmarx.com/glossary/c-static-code-analysis-2/)

 [CBOM](https://staging.checkmarx.com/glossary/what-is-a-cbom/)

 [Checkmarx Visual Studio Static Code Analysis Plugin](https://staging.checkmarx.com/glossary/checkmarx-visual-studio-static-code-analysis-plugin/)

 [CI/CD](https://staging.checkmarx.com/learn/devsecops/what-is-cicd-security/)

 [Cloud Computing](https://staging.checkmarx.com/glossary/cloud-computing/)

 [Cloud Infrastructure](https://staging.checkmarx.com/glossary/cloud-infrastructure/)

 [Cloud Native](https://staging.checkmarx.com/glossary/cloud-native/)

 [Cloud Native Development](https://staging.checkmarx.com/glossary/cloud-native-development/)

 [CNCF](https://staging.checkmarx.com/glossary/cncf/)

 [CNI](https://staging.checkmarx.com/glossary/cni/)

 [Code to Cloud Security](https://staging.checkmarx.com/glossary/what-is-code-to-cloud-security/)

 [Codebashing](https://staging.checkmarx.com/glossary/codebashing-definition/)

 [Container](https://staging.checkmarx.com/glossary/what-is-container-security/)

 [Container Security](https://staging.checkmarx.com/glossary/what-is-container-security/)

 [Correlation](https://staging.checkmarx.com/glossary/correlation/)

 [Cross-Site Request Forgery (CSRF) attacks](https://staging.checkmarx.com/glossary/cross-site-request-forgery-csrf-attacks/)

 [Cross-Site Scripting (XSS) Attacks](https://staging.checkmarx.com/glossary/cross-site-scripting-xss-attacks/)

 [CVE](https://staging.checkmarx.com/glossary/cve-2/)

 [CVS Static Code Analysis](https://staging.checkmarx.com/learn/sast/effective-static-source-code-analysis/)

 [Cybersecurity](https://staging.checkmarx.com/glossary/cyber-security/)

D

 [DevOps](https://staging.checkmarx.com/glossary/devops/)

 [Devops Metrics](https://staging.checkmarx.com/glossary/devops-metrics-what-they-are-and-how-to-achieve-devops-excellence/)

 [DevOps Security](https://staging.checkmarx.com/glossary/devops-security/)

 [Directory Traversal Vulnerability](https://staging.checkmarx.com/glossary/directory-traversal-vulnerability/)

 [Docker Architecture](https://staging.checkmarx.com/glossary/what-is-docker-architecture-and-how-does-it-work/)

 [Docker Swarm](https://staging.checkmarx.com/glossary/docker-swarm/)

 [Droid Intent Data Flow Analysis for Information Leakage (DidFail)](https://staging.checkmarx.com/glossary/droid-intent-data-flow-analysis-for-information-leakage-didfail/)

E

 [Engine](https://staging.checkmarx.com/glossary/engine/)

 [Enterprise Application Security](https://staging.checkmarx.com/glossary/what-is-enterprise-application-security/)

 [Enterprise Application Security through Secure Development](https://staging.checkmarx.com/glossary/enterprise-application-security-through-secure-development/)

 [Ethical Hacking For Company Security](https://staging.checkmarx.com/glossary/ethical-hacking-for-company-security/)

F

 [False Negative](https://staging.checkmarx.com/glossary/false-negative/)

 [False Positive](https://staging.checkmarx.com/glossary/false-positive/)

 [Flash Security](https://staging.checkmarx.com/glossary/how-to-maintain-proper-securityagainst-flash-vulnerabilities/)

 [Function as a service](https://staging.checkmarx.com/glossary/function-as-a-service/)

G

 [Gartner Magic Quadrant](https://staging.checkmarx.com/glossary/gartner-magic-quadrant/)

 [GIT Static Code Analysis](https://staging.checkmarx.com/glossary/git-static-code-analysis/)

H

 [HIPAA ](https://staging.checkmarx.com/glossary/what-is-hipaa/)

 [How to Avoid Wireless Sniffers](https://staging.checkmarx.com/glossary/how-to-avoid-wireless-sniffers/)

 [Hudson Static Code Analysis](https://staging.checkmarx.com/glossary/hudson-static-code-analysis/)

I

 [Infrastructure-as-Code (IaC)](https://staging.checkmarx.com/glossary/infrastructure-as-code-iac/)

 [Insecure Cryptographic Storage](https://staging.checkmarx.com/glossary/insecure-cryptographic-storage/)

 [Integrated Development Environment (IDE)](https://staging.checkmarx.com/glossary/integrated-development-environment-ide/)

 [Internet Security](https://staging.checkmarx.com/glossary/internet-security/)

J

 [JavaScript Static Code Analysis](https://staging.checkmarx.com/glossary/javascript-static-code-analysis/)

 [Jenkins Static Code Analysis](https://staging.checkmarx.com/glossary/jenkins-static-code-analysis/)

K

 [Keylogger: The Invisible Threat](https://staging.checkmarx.com/glossary/keylogger-the-invisible-threat/)

 [KICS](https://staging.checkmarx.com/glossary/kics/)

 [Kubernetes (K8s)](https://staging.checkmarx.com/glossary/kubernetes-k8s/)

L

 [Lambda Function](https://staging.checkmarx.com/glossary/lambda-function/)

 [LDAP Injection](https://staging.checkmarx.com/glossary/ldap-injection-tutorial/)

 [Linux Hacking](https://staging.checkmarx.com/glossary/linux-hacking/)

M

 [Malicious Code Definition](https://staging.checkmarx.com/glossary/malicious-code/)

 [Malware](https://staging.checkmarx.com/glossary/malware/)

 [Man-In-The-Middle (MiM) Attacks](https://staging.checkmarx.com/glossary/how-to-properly-defend-against-man-in-the-middle-attacks/)

 [Microservices](https://staging.checkmarx.com/glossary/microservices/)

 [MITRE ATT&amp;CK framework](https://staging.checkmarx.com/glossary/what-is-the-mitre-attck-framework/)

 [MLBOM](https://staging.checkmarx.com/glossary/what-is-an-mlbom/)

 [Mobile Application Security (Android/iOS)](https://staging.checkmarx.com/glossary/mobile-application-security-android-ios/)

 [Multi-Platform JavaScript Code Analysis](https://staging.checkmarx.com/glossary/javascript-code-analysis/)

 [Multi-tenant](https://staging.checkmarx.com/glossary/multi-tenant/)

N

 [.NET Scanner](https://staging.checkmarx.com/glossary/net-scanner/)

 [NIST CSF](https://staging.checkmarx.com/glossary/what-is-nist-csf/)

O

 [On Premises](https://staging.checkmarx.com/glossary/on-premises/)

P

 [ Product Security](https://staging.checkmarx.com/glossary/what-is-product-security/)

 [Path Traversal](https://staging.checkmarx.com/glossary/path-traversal/)

 [PCI DSS Compliance](https://staging.checkmarx.com/glossary/pci-dss-compliance/)

 [Penetration Testing For Company Security](https://staging.checkmarx.com/glossary/penetration-testing-for-company-security/)

 [PHP Scanner](https://staging.checkmarx.com/glossary/php-scanner/)

 [PHP Static Code Analysis](https://staging.checkmarx.com/glossary/php-static-code-analysis/)

 [Private Cloud](https://staging.checkmarx.com/glossary/private-cloud/)

 [Public Cloud](https://staging.checkmarx.com/glossary/public-cloud/)

R

 [RabbitMQ](https://staging.checkmarx.com/glossary/rabbitmq/)

 [RBAC](https://staging.checkmarx.com/glossary/rbac/)

 [Refactoring](https://staging.checkmarx.com/glossary/refactoring/)

 [Registry](https://staging.checkmarx.com/glossary/registry/)

 [Regular Expression Denial of Service Attack (ReDoS)](https://staging.checkmarx.com/glossary/redos-attack/)

 [Repository](https://staging.checkmarx.com/glossary/repository/)

 [Rootkit](https://staging.checkmarx.com/glossary/rootkit/)

 [Ruby On Rails Security](https://staging.checkmarx.com/glossary/ruby-on-rails-preventative-security/)

 [runC](https://staging.checkmarx.com/glossary/runc/)

 [RUST Language](https://staging.checkmarx.com/glossary/what-is-rust-and-how-developers-can-benefit-from-rust-language-security/)

S

 [SAMATE](https://staging.checkmarx.com/glossary/samate/)

 [Secrets Detection](https://staging.checkmarx.com/glossary/what-is-secrets-detection/)

 [Security Vulnerability](https://staging.checkmarx.com/glossary/security-vulnerability/)

 [SLSA Framework](https://staging.checkmarx.com/glossary/what-is-the-slsa-framework/)

 [Source Code Manager (SCM)](https://staging.checkmarx.com/glossary/source-code-manager-scm/)

 [Spoofing Attack](https://staging.checkmarx.com/glossary/spoofing-attack/)

 [Static Code Analysis for Java](https://staging.checkmarx.com/glossary/static-code-analysis-for-java/)

 [Static Code Analysis with Eclipse](https://staging.checkmarx.com/glossary/svn-static-code-analysis/)

 [SVN Static Code Analysis](https://staging.checkmarx.com/glossary/svn-static-code-analysis/)

T

 [Terraform](https://staging.checkmarx.com/glossary/terraform/)

 [Ticketing System](https://staging.checkmarx.com/glossary/ticketing-system/)

V

 [Vulnerability Assessment and Penetration Testing](https://staging.checkmarx.com/glossary/vulnerability-assessment-and-penetration-testing/)

 [Vulnerability Assessments](https://staging.checkmarx.com/glossary/vulnerability-assessments/)

 [Vulnerability Scan of Software Code](https://staging.checkmarx.com/glossary/vulnerability-scan/)

 [Vulnerability scanning](https://staging.checkmarx.com/glossary/why-vulnerability-scanning-is-critical-for-companies/)

W

 [What are APIs and Why is API Security Important?](https://staging.checkmarx.com/glossary/api-security/)

 [What is Docker Container Architecture and How Does it Work?](https://staging.checkmarx.com/glossary/docker/)

 [What is Platform Engineering?](https://staging.checkmarx.com/glossary/what-is-platform-engineering/)

 [Workload](https://staging.checkmarx.com/glossary/workload/)

Y

 [YAML](https://staging.checkmarx.com/glossary/yaml/)

## Checkmarx Provides Your Go-To Application Security Glossary &amp; Definitions

Understand the Language of AppSec and Secure Software Development
 Looking to decode the complex world of application security?
 The Checkmarx Application Security Glossary is your resource for clear definitions of today’s most critical AppSec terms and phrases. Whether you’re a developer, security professional, CISO, or DevSecOps leader, our glossary helps provide context and define some of the most common AppSec language. Use us as your trusted AppSec reference hub and check back often as it’s regularly updated with new terms and trending topics.

## Related Resources

 [Glossary](https://staging.checkmarx.com/glossary/application-vulnerability/) [What is Application Security Vulnerability: Definition](https://staging.checkmarx.com/glossary/application-vulnerability/)

 [ Read More          ](https://staging.checkmarx.com/glossary/application-vulnerability/)

 [Glossary](https://staging.checkmarx.com/glossary/cloud-native/) [Cloud Native](https://staging.checkmarx.com/glossary/cloud-native/)

 [ Read More          ](https://staging.checkmarx.com/glossary/cloud-native/)

 [Glossary](https://staging.checkmarx.com/glossary/what-is-code-to-cloud-security/) [Code to Cloud Security: Definition, Benefits and Best Practices](https://staging.checkmarx.com/glossary/what-is-code-to-cloud-security/)

 [ Read More          ](https://staging.checkmarx.com/glossary/what-is-code-to-cloud-security/)

 [Glossary](https://staging.checkmarx.com/glossary/devops-metrics-what-they-are-and-how-to-achieve-devops-excellence/) [DevOps Metrics: What They Are, and How to Achieve DevOps Excellence ](https://staging.checkmarx.com/glossary/devops-metrics-what-they-are-and-how-to-achieve-devops-excellence/)

 [ Read More          ](https://staging.checkmarx.com/glossary/devops-metrics-what-they-are-and-how-to-achieve-devops-excellence/)

 [AppSec Knowledge Hub Post](https://staging.checkmarx.com/learn/devsecops/a-secure-sdlc-with-static-source-code-analysis-tools/) [Secure SDLC (SSDLC): Core Stages, SAST &amp; AI Automation](https://staging.checkmarx.com/learn/devsecops/a-secure-sdlc-with-static-source-code-analysis-tools/)

 [ Read More          ](https://staging.checkmarx.com/learn/devsecops/a-secure-sdlc-with-static-source-code-analysis-tools/)
