Full engagement
Full consultation
Discuss your complete cloud and security strategy with the principal consultant. For comprehensive transformations and multi-quarter engagements.
Glossary
A plain-language reference for cloud security terms across AWS, Azure, and Google Cloud.
39 terms across 10 categories
Terms
Set of policies, technologies, and controls designed to protect cloud-based systems, data, and infrastructure from cyber threats.
Security framework where cloud provider secures the infrastructure while customer secures their data, applications, and configurations.
Automated tools and processes that identify misconfigurations and compliance violations in cloud environments.
Security model that requires verification for every user and device before granting network access, regardless of location.
Security strategies and tools designed to protect workloads and data across multiple cloud providers (AWS, Azure, GCP).
Security solution designed to protect workloads in cloud environments, including VMs, containers, and serverless functions.
Terms
Framework for managing digital identities and controlling access to cloud resources based on user roles and permissions.
Access control method that assigns permissions to users based on their role within an organisation.
Security method requiring two or more verification factors to gain access to cloud resources.
Authentication service allowing users to access multiple applications with one set of login credentials.
Security strategy for controlling and monitoring access to critical systems and sensitive data by privileged users.
Terms
Isolated section of cloud infrastructure where you can launch resources in a logically separated network.
Practice of dividing network into smaller segments to limit attack spread and improve security monitoring.
Security solution that monitors HTTP traffic between web applications and the internet to block malicious requests.
Security measures designed to protect against Distributed Denial of Service attacks that overwhelm systems with traffic.
Encrypted connection between networks that allows secure communication over public internet infrastructure.
Terms
Data protection method that encrypts stored data to prevent unauthorized access even if storage media is compromised.
Data protection method that encrypts data while it moves between systems, applications, or networks.
Cloud service for creating, managing, and controlling cryptographic keys used for data encryption.
Security strategy and tools designed to prevent sensitive data from leaving the organisation unauthorized.
Process of organizing data by sensitivity level to apply appropriate security controls and access restrictions.
Terms
Security practices for protecting containerized applications including image scanning, runtime protection, and orchestration security.
Security considerations specific to serverless computing including function-level permissions and event-driven vulnerabilities.
Security measures for protecting Application Programming Interfaces from attacks and unauthorized access.
Practice of integrating security testing and controls throughout the software development and deployment process.
Terms
Amazon's threat detection service that monitors for malicious activity and unauthorized behavior in AWS accounts.
AWS service that logs API calls and user activity for governance, compliance, and security analysis.
AWS service that tracks resource configurations and evaluates compliance against desired configurations.
Centralized dashboard for managing security findings from multiple AWS security services and third-party tools.
Terms
Microsoft's unified security management system providing threat protection across hybrid cloud workloads.
Microsoft's cloud-native SIEM (Security Information and Event Management) solution for threat detection and response.
Terms
Google's centralized security and risk management platform for Google Cloud Platform resources.
Terms
Technology that aggregates and analyzes security data from multiple sources to detect threats and support incident response.
Technologies that automate security operations tasks and orchestrate responses to security incidents.
Continuous observation of cloud infrastructure and applications to detect security threats and compliance violations.
Terms
Systematic examination of systems to identify security weaknesses that could be exploited by attackers.
Authorized simulated cyber attack against cloud infrastructure to evaluate security posture and identify vulnerabilities.
Systematic examination of cloud security controls, configurations, and practices against established standards and regulations.
Process of identifying, analyzing, and evaluating security risks to cloud infrastructure and applications.
Work with a senior team to turn cloud security concepts into practical controls for your AWS, Azure, or Google Cloud stack.
Next step
Choose how you'd like to begin your engagement with Pilotcore.
Full engagement
Discuss your complete cloud and security strategy with the principal consultant. For comprehensive transformations and multi-quarter engagements.
Recommended start
Test the engagement with a focused 1-4 week scope. See real results, on a fixed timeline, before committing to anything larger.