Skip to main content

Topic index

Security Operations and Risk

Learn the threats, controls, and operating practices that reduce access risk.

Topic index

Understand this domain

Pomerium coverage

Pomerium records authorization decisions for protected routes. Operators can send logs to an owned analysis and retention path and can add selected MCP fields. The surrounding applications, endpoints, identity provider, and network still need their own event sources.

Limits

  • An authorization log is not a complete application, endpoint, or network audit trail.
  • More logging can expose sensitive data when fields are not selected and protected carefully.
  • A gateway can limit an access path, but it does not isolate an unsafe tool or application runtime.

Primary sources

2 learning paths

Paths for this topic

33 related guides

Guides in this topic

GuideHuman Factors and Security Economics

Analyze Security Incentives

Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.

Open this guide
GuideCryptography and Data Protection

Protect the data lifecycle

Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.

Open this guide

62 related terms

Concepts in this topic

Security Engineering FoundationsSecurity Operations and Risk

Adversary Model

State who can attack the system, what they want, what they can do, where they start, and what constrains them.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent and Tool Inventory

Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Blast Radius

Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Cascading Failure

Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.

Learn this term
Agentic AccessSecurity Operations and Risk

Agent Credential Custody

Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.

Learn this term
Agentic AccessSecurity Operations and Risk

Agentic Supply Chain

Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.

Learn this term
Security Operations and Risk

Attack Surface

An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Attack Tree

An attack tree decomposes one attacker goal into alternate and combined paths that can achieve it.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Decision Log

Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Drift

Authorization drift is the gap that develops when effective access no longer matches intended access.

Learn this term
Security Operations and RiskCryptography and Data Protection

Backup and Restore

Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.

Learn this term
Standards and ProtocolsSecurity Operations and Risk

Certificate Lifecycle

Issue, deploy, rotate, revoke, recover, and retire certificates and private keys without breaking name or trust validation.

Learn this term
Security Operations and Risk

Cyber Threat Intelligence

Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.

Learn this term
Security Operations and Risk

Data Breach

A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Defense in Depth

Place complementary controls across distinct failure domains so one failure does not expose the protected asset.

Learn this term
Security Operations and RiskNetwork and Infrastructure

Denial of Service

Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.

Learn this term
Security Operations and Risk

Detection Quality

Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.

Learn this term
Authorization and PolicySecurity Operations and Risk

Distributed Security State

Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.

Learn this term
Security Operations and RiskStandards and Protocols

Encryption

Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.

Learn this term
Security Operations and Risk

Endpoint Security

Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.

Learn this term
Agentic AccessSecurity Operations and Risk

Hidden Trust Boundary

A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.

Learn this term
Human Factors and Security EconomicsSecurity Operations and Risk

Insider Threat

Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.

Learn this term
Security Operations and Risk

Intrusion Detection

An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.

Learn this term
Security Operations and Risk

Lateral Movement

Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.

Learn this term
Security Operations and Risk

Malware

Understand malicious code that steals, persists, disrupts, spies, moves, or changes systems and prepare to contain and rebuild affected trust.

Learn this term
Agentic AccessAuthorization and Policy

MCP Security

Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.

Learn this term
Security Operations and Risk

MITRE ATT&CK

MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.

Learn this term
Agentic AccessAuthorization and Policy

Prompt Injection

Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.

Learn this term
Security Operations and Risk

Ransomware

Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure.

Learn this term
Identity and AuthenticationSecurity Operations and Risk

Revocation Latency

Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.

Learn this term
Security Operations and Risk

Secure Enclave

Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave.

Learn this term
Security Operations and RiskCryptography and Data Protection

Secure System Decommissioning

Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.

Learn this term
Security Operations and Risk

Security Alert Triage

Qualify, categorize, prioritize, enrich, assign, and escalate a potential incident from evidence, asset criticality, identity, scope, and impact.

Learn this term
Security Operations and Risk

Security and Compliance

Security protects stated assets and properties, while compliance evaluates obligations against defined criteria and evidence.

Learn this term
Security Operations and Risk

Security Postmortem

A security postmortem turns an incident timeline, contributing conditions, and response evidence into owned system changes.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Security Risk

Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.

Learn this term
Security Operations and Risk

Security Telemetry

Security telemetry uses logs, metrics, traces, and events to answer defined detection, investigation, and control questions.

Learn this term
Security Engineering FoundationsSecurity Operations and Risk

Security Understandability

Make the system, its authority, dependencies, state, failure behavior, and evidence clear enough to change and operate safely.

Learn this term
Platform and Component SecuritySecurity Operations and Risk

System Hardening

Reduce a deployed system to required services, identities, interfaces, privileges, configurations, and recovery paths, then keep it there.

Learn this term
Security Operations and Risk

Threat Hunting

Proactively test a bounded threat hypothesis in existing evidence when no alert has yet confirmed the activity.

Learn this term
Agentic AccessSecurity Operations and Risk

Tool Surface Area

Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo