Skip to content
Weekly Signal

Plain-language cyber security

Glossary

Clear definitions, practical context and connected guidance for the terms used across vulnerability and exposure management.

Reference library

Terms and concepts

C

CPE

A structured naming scheme used to identify hardware, operating systems and applications.

Read definition →
C

CTEM

A continuous programme for scoping, discovering, prioritising, validating and mobilising action around material exposure.

Read definition →
C

CWE

A classification of the underlying software and hardware weakness types that can lead to vulnerabilities.

Read definition →
E

EASM

The continuous discovery and assessment of internet-visible assets and services from an external perspective.

Read definition →
E

EPSS

A daily estimate of the probability that a published CVE will be exploited in the wild during the next 30 days.

Read definition →
R

RCE

A vulnerability impact that can allow an attacker to run code on a system from another location.

Read definition →
S

SSVC

A decision-tree approach that maps vulnerability evidence and stakeholder context to an action outcome.

Read definition →