SECURITY GLOSSARY

Security and VAPT glossary

Plain definitions of the penetration testing and application security terms buyers and engineers meet most, each with how PoCForge tests it and where to go deeper. Starter set — more terms are being added.

Terms

  • VAPT — VAPT pairs a vulnerability assessment (finding and listing known weaknesses, often with scanners) with a penetration tes…
  • BOLA — BOLA is an API flaw where the server does not check that the caller may access the specific object they asked for, so ch…
  • IDOR — IDOR is an access-control flaw where an application exposes a direct reference to an internal object (a database ID, a f…
  • Assumed breach testing — An assumed-breach test starts from inside: the tester is given the access an attacker might already have, such as a stan…
  • CERT-In empanelment — CERT-In empanelment is the Indian Computer Emergency Response Team’s programme that lists information security auditing …

Have a term you want defined?

Tell us what you are trying to scope and we will point you to the right assessment.

Request a free scope review →