Security Glossary
Clear, concise definitions of the threat-intelligence and security terms that matter to mid-market teams.
Security Posture Assessment
A security posture assessment is a structured evaluation of an organization's security controls and configurations that produces a scored picture of how well it can prevent, detect, and respond to threats.
CISA KEV (Known Exploited Vulnerabilities)
The CISA KEV catalog is a U.S. government list of vulnerabilities that are confirmed to be actively exploited in the wild — making it one of the highest-signal sources for vulnerability prioritization.
NVD (National Vulnerability Database)
The NVD is the U.S. National Vulnerability Database — the authoritative repository of CVE records enriched with severity scores (CVSS), affected products, and references.
NIST CSF 2.0 (Cybersecurity Framework)
The NIST Cybersecurity Framework (CSF) 2.0 is a widely adopted framework that organizes security activities into six functions — Govern, Identify, Protect, Detect, Respond, and Recover.
CIS Controls v8
The CIS Controls are a prioritized set of 18 safeguards, maintained by the Center for Internet Security, that defend against the most common attack patterns.
MITRE ATT&CK
MITRE ATT&CK is a globally used knowledge base of real-world adversary tactics and techniques, used to describe how attackers operate and to map defensive coverage.
DMARC
DMARC is an email-authentication standard that tells receiving servers how to handle messages that fail SPF and DKIM checks, protecting a domain from spoofing and impersonation.
The Relevance Engine
Vigil's Relevance Engine is the matching layer that compares every new threat — from CISA KEV and the NVD — against an organization's specific technology stack and surfaces only the items that actually apply.
Threat Intelligence
Threat intelligence is evidence-based knowledge about cyber threats — vulnerabilities, attackers, and campaigns — packaged so an organization can make faster, better security decisions.
Continuous Threat Monitoring
Continuous threat monitoring is the ongoing process of watching threat sources and your environment for newly relevant risks, rather than checking periodically.