← Back to Academy

Trusteed Academy

Security Glossary: Core Concepts Every Security Program Depends On

Clear definitions for ASM, Zero Trust, WAAP, SOC, threat intelligence, CSPM, DevSecOps, and shift-left security — and how they fit into a CTEM program.

URL: trusteed.io/academy/glossary/

Security terminology gets used loosely — "we do vulnerability management" and "we run a SOC" and "we're Zero Trust" mean very different things depending on who's saying them. This glossary series gives clear, precise definitions for the foundational concepts behind modern security programs, how they relate to each other, and where each one fits into a Continuous Threat Exposure Management (CTEM) program.

The Concepts

Term What It Answers
Attack Surface Management (ASM/EASM) What counts as "your attack surface," and how do you keep track of it as it grows?
Zero Trust Architecture Why "trusted internal network" is an outdated security assumption
WAF vs. WAAP What's the actual difference, and when has WAF alone stopped being enough?
Penetration Testing vs. Vulnerability Scanning Two different activities constantly confused for one another
Security Operations Center (SOC) What a SOC actually does, and why most of them are drowning in alerts
Threat Intelligence The difference between a raw feed and intelligence you can act on
Cloud Security Posture Management (CSPM) How organizations catch cloud misconfigurations before attackers do
DevSecOps What it actually means to build security into engineering, not bolt it on after
Shift-Left Security Why fixing a vulnerability in code review is cheaper than fixing it in production

How These Concepts Fit Together

None of these exist in isolation. Attack Surface Management tells you what you have. CSPM and vulnerability scanning tell you what's wrong with it. Zero Trust and WAAP enforce access and traffic policy around it. DevSecOps and Shift-Left Security determine how early problems get caught in the development lifecycle. Threat Intelligence tells your SOC what's actually dangerous versus background noise. Together, they form the operational backbone of a Continuous Threat Exposure Management (CTEM) program — the five-stage cycle of scoping, discovering, prioritizing, validating, and mobilizing that ties all of this into one continuous loop rather than a collection of disconnected tools.

If you're building a security program from the ground up, or trying to understand how the tools you already have relate to each other, this glossary is the reference to start with.


This series is part of Trusteed Academy. For the developer-focused half of the academy, see the API Security Top 10 series.