The vocabulary, in plain words
Every term carries what it is and why a practitioner cares. The second line is the part that makes it usable. Free at every tier, because vocabulary is the first barrier into this work and the wrong thing to charge for.
S
- Software bill of materials SBOM
-
A machine-readable parts list of every component in a build, with versions and relationships.
It is the inventory, not the deliverable. Published without exploitability judgements it hands customers a list of concerns they cannot rank.
Taught in CYB-201 · See also: Vulnerability exploitability exchange, Vulnerability management
T
- Threat intelligence
-
Information about breaches, vulnerabilities and attacker behaviour, matched against what you hold, use and depend on.
Without inventories to match against it produces reading rather than action. Measure the programme by decisions, not by items processed.
Taught in CYB-210 · See also: Vulnerability management, concentration-risk
V
- Vulnerability exploitability exchange VEX
-
A statement giving, per vulnerability and product, whether it is affected, not affected, fixed or under investigation, with a justification.
One line of VEX answers the fourteen customer tickets a single publicised vulnerability would otherwise generate.
Taught in CYB-201 · See also: Software bill of materials, Vulnerability management
- Vulnerability management
-
The programme that finds, prioritises, fixes and evidences the closure of weaknesses across the estate.
Coverage comes before volume and exposure before severity: a seven-day target is credible when the queue holds a dozen items, not ninety.
Taught in CYB-220 · See also: Software bill of materials, Threat intelligence
Maintained by the association. A term here is a summary; the course named beside it is where the practice is taught.