WinMagic Resource Center & Newsroom

Company news, press coverage, white papers, and brand assets: everything to keep you up to date about our products and company.

Glossary

Authentication, endpoint security, compliance and identity terms used across WinMagic's products and white papers.

Authentication & Identity

12 terms

MFA Multi-Factor Authentication

Requiring two or more proofs of identity to log in, such as password plus phone code.

2FA Two-Factor Authentication

A subset of MFA using exactly two factors, commonly password plus SMS code.

Passwordless

Authentication methods that remove passwords and use biometrics, hardware keys, or cryptographic keys.

Passkeys

FIDO2-based credentials that replace passwords with public/private key pairs.

FIDO / FIDO2 Fast Identity Online

An open standard for strong, phishing-resistant authentication using public key cryptography.

WebAuthn Web Authentication

A W3C standard that allows websites to use public key cryptography for user authentication.

SSO Single Sign-On

Logging in once and accessing multiple applications without repeated authentication.

IdP Identity Provider

A system that authenticates users and issues identity tokens.

IAM Identity and Access Management

Tools and policies for managing who can access what.

PAM Privileged Access Management

Tools for securing and monitoring privileged users and admin accounts.

OIDC OpenID Connect

An identity layer built on OAuth 2.0 for user identity verification.

OAuth 2.0 Open Authorization 2.0

A standard for delegated authorization that lets apps access resources without sharing passwords.

Endpoint & Device Security

8 terms

EDR Endpoint Detection and Response

Security software that monitors endpoints for threats and responds automatically.

TPM Trusted Platform Module

A hardware security chip that stores cryptographic keys and performs secure operations.

FDE Full Disk Encryption

Encrypting the entire drive so data is unreadable without the correct authentication.

PBA Pre-Boot Authentication

Authentication before the operating system loads.

RoT Root of Trust

The foundational security component the rest of the security chain relies on.

MDM Mobile Device Management

Tools for managing and securing mobile devices and laptops.

SCCM System Center Configuration Manager

Microsoft tool for deploying software, updates, and policies to Windows endpoints.

Intune Microsoft Intune

Microsoft cloud-based endpoint management service.

Attack Types & Threats

8 terms

AiTM Adversary-in-the-Middle

A phishing attack where the attacker sits between the victim and real login page.

Token Theft

Stealing a session token that proves a user is authenticated.

Session Hijacking

Taking over an active user session by stealing or replaying session tokens.

BEC Business Email Compromise

Fraud where attackers access a business email account to trick employees or customers.

Phishing

Social engineering attacks that trick users into revealing credentials or clicking malicious links.

Credential Stuffing

Automated attacks using stolen username and password combinations.

Lateral Movement

When an attacker moves from one system to another inside a network.

PhaaS Phishing-as-a-Service

Criminal platforms that sell ready-made phishing kits.

Frameworks, Standards & Compliance

8 terms

Zero Trust

A security approach where no user, device, or network is automatically trusted.

mTLS Mutual TLS

A protocol where both client and server authenticate each other using certificates.

M2M Machine-to-Machine

Communication directly between devices or systems without human action.

CMMC Cybersecurity Maturity Model Certification

A U.S. DoD cybersecurity standard for defense contractors.

NIST 800-171

Security requirements for protecting controlled unclassified information.

CUI Controlled Unclassified Information

Sensitive government information that requires safeguarding.

FIPS Federal Information Processing Standards

U.S. government standards for cryptographic modules and security requirements.

HIPAA Health Insurance Portability and Accountability Act

U.S. law requiring protection of patient health information.

Products & Vendors

8 terms

MagicEndpoint

WinMagic passwordless authentication product using TPM-based continuous verification.

SecureDoc

WinMagic full-disk encryption product.

Microsoft Entra ID

Microsoft cloud identity and access management service.

Microsoft Authenticator

Microsoft mobile app for MFA and passkey storage.

Okta

Independent identity and access management platform.

CrowdStrike Falcon

Endpoint detection and response platform.

SentinelOne

EDR platform and competitor to CrowdStrike and Microsoft Defender.

YubiKey

Physical FIDO2 security keys used for phishing-resistant authentication.

Networking & Protocols

4 terms

TLS Transport Layer Security

Cryptographic protocol that secures HTTPS connections.

VPN Virtual Private Network

Encrypted tunnel between a device and a network.

GPO Group Policy Object

Windows mechanism for configuring domain-joined computers.

LDAP Lightweight Directory Access Protocol

Protocol for accessing and managing directory services.

Business Terms

8 terms

CISO Chief Information Security Officer

Executive responsible for cybersecurity strategy.

CIO Chief Information Officer

Executive responsible for overall IT strategy.

POV Proof of Value

Limited pilot used to prove business value before purchase.

SIEM Security Information and Event Management

Platform that aggregates and analyzes security logs.

SOC Security Operations Center

Team responsible for monitoring and responding to security incidents.

BYOD Bring Your Own Device

Employees using personal devices for work.

TAM Total Addressable Market

Total revenue opportunity if a product captured the full market.

PII Personally Identifiable Information

Data that can identify a person.

keyboard_arrow_up