Resources / Glossary
Glossary
The acronyms, in English — for the half of the room who did not choose this topic.
- Access recertification
- Periodically confirming that the people who have access still need it — and keeping proof that you checked.
- Identity governance (IGA)
- The discipline of deciding who should have access, granting it, reviewing it and proving all three.
- Privileged access (PAM)
- Controlling the accounts that can change things: administrators, service accounts, anything holding the keys.
- Just-in-time access
- Granting elevated access for a specific task, which then expires on its own rather than sitting there forever.
- Standing privilege
- Administrative access that is always on, whether or not anyone is using it. The thing attackers hope to find.
- Joiner-mover-leaver
- Access following employment: granted on the first day, changed on a move, removed on exit.
- Separation of duties
- Making sure one person cannot hold a combination of access that lets them do something harmful unchecked.
- Single sign-on (SSO)
- One sign-in that opens the applications you are entitled to, instead of a password for each.
- Multi-factor / passkeys
- Proving identity with more than a password. Passkeys resist phishing rather than merely recording it.
- Non-human identity
- Anything that holds access but is not a person: service accounts, scripts and now AI agents.
- Sovereign deployment
- Running the system where the data is legally required to stay, under your control rather than a vendor’s.
- Orphaned account
- An account nobody owns, usually left behind by someone who moved on. Working access, no accountable human.