Skip to main content

Reference

Cybersecurity glossary

Plain-language definitions of the security and Indonesian compliance terms we work with every day, each linked to where we go deeper.

Reviewed by Mohit Bhansali

A

B

C

D

E

G

I

M

N

O

P

PCI DSS (Payment Card Industry Data Security Standard)

Payment Card Industry Data Security Standard

PCI DSS is a global security standard for organizations that store, process, or transmit payment card data. Compliance is a condition for being able to keep processing card transactions.

Penetration testing

pentest

A penetration test is an authorised, simulated attack on a system to find and prove real weaknesses before a genuine attacker does. The output is a prioritised list of findings with evidence.

Phishing

Phishing is a social-engineering attack where criminals impersonate a trusted sender to trick people into revealing credentials, transferring money, or installing malware. It is the starting point for most breaches.

POJK 11/2022

POJK 11/2022 is an OJK regulation setting information-security and resilience requirements for commercial banks, including penetration testing and incident reporting.

POJK 34/2025

POJK 34/2025 extends structured IT and cyber-resilience obligations to rural banks (BPR/BPRS), with a compliance deadline that many smaller banks must still prepare for.

PP 71/2019

PP 71/2019 governs electronic systems and transactions in Indonesia, including rules on data placement and the obligations of electronic system operators.

Purdue Model

Purdue Enterprise Reference Architecture

The Purdue model is a framework that divides an industrial network into levels, from field devices up to business systems. This separation helps isolate and secure operational systems from the IT network.

Purple team

A purple team exercise has attackers (red) and defenders (blue) work together in the open, so every simulated attack directly improves detection and response.

R

S

SAST (Static Application Security Testing)

Static Application Security Testing

SAST analyses source code for security flaws without running it. It runs early in development and flags issues like injection risks before the application is ever deployed.

SBOM (Software Bill of Materials)

Software Bill of Materials

An SBOM is a full inventory of the components and open-source libraries inside a piece of software. When a new vulnerability appears, it tells you in minutes whether you are affected.

Shift Left

Shift-Left Security

Shift left means moving security checks to the early stages of development rather than waiting until just before release. Finding problems earlier makes fixing them far cheaper and faster.

SIEM (Security Information and Event Management)

Security Information and Event Management

A SIEM collects and correlates log data from across an organisation so analysts can spot patterns that a single system would miss. It is the data backbone most SOCs are built on.

SOAR (Security Orchestration, Automation and Response)

Security Orchestration, Automation and Response

SOAR tools automate repetitive response steps, such as enriching an alert or isolating a host, so analysts spend their time on judgement rather than manual clicks.

SOC (Security Operations Center)

Security Operations Center

A SOC is the team, process, and tooling that monitors an organisation for security threats around the clock. It collects signals from across the network, investigates suspicious activity, and coordinates the response when something is wrong.

SOC 2

SOC 2 is a reporting standard that evaluates how a service provider protects customer data across controls such as security and availability. It is frequently requested by enterprise buyers before signing.

Social engineering

Social engineering manipulates people into breaking security rules, for example by posing as IT support to reset a password. It targets human trust rather than technical flaws.

Supply Chain Attack

Supply Chain Attack

A supply chain attack breaches an organization through a trusted supplier, vendor, or software component. By compromising one party, attackers can reach many victims at once.

T

U

V

X

Z

WhatsApp