(518) 292-4500|sales@logical.net|M-F 8am-5pm · 24/7 SOC
MSP 501 Winner 2025Client Portal →
Resources · Glossary

Cybersecurity and IT,
in plain language.

The words that show up in a proposal, a security audit, or the middle of an incident, explained clearly by the engineers who use them every day, so nothing trips you up.

Written by our engineers No jargon left unexplained Accurate, not marketing
Jump to a letter 28 terms
ABCDEFG HIJKLMN OPQRSTU VWXYZ
Terms we actually use in our reports
28
Terms defined
A–Z
Indexed for fast lookup
Plain
English, no jargon
24/7
SOC behind the terms
Free
Vulnerability scan
The A–Z

Every term, defined honestly.

No acronym soup and no fear-selling. Pick a letter, or read straight through, each definition says what the thing literally is and why it matters to a small or midsize organization.

A

Attack Surface

Every point where an attacker could try to get in — internet-facing servers, logins, applications, and devices. The smaller and better-monitored it is, the less there is to defend.

C

CMMC Cybersecurity Maturity Model Certification

A U.S. Department of Defense program requiring companies in its supply chain to meet defined cybersecurity practices before they can handle certain contract information.

Conditional Access

A policy that decides whether a sign-in is allowed based on context — who, what device, where, and how risky the login looks, rather than just a correct password.

E

EDR Endpoint Detection & Response

Security software on laptops, servers, and phones that detects suspicious behavior, not just known viruses, and can isolate a device or roll back changes when something is wrong.

Endpoint

Any device that connects to your network and touches your data: a laptop, desktop, server, phone, or tablet. Each one is a potential way in, which is why each one is monitored.

F

Firewall

A barrier between your network and the internet that permits wanted traffic and blocks the rest, based on rules. A first line of defense — necessary, but not sufficient on its own.

V

VPN Virtual Private Network

An encrypted tunnel that lets remote users reach internal systems as if they were in the office, keeping traffic private over the public internet.

Vulnerability

A weakness in software, configuration, or process that an attacker can exploit. Finding and fixing them before attackers do is what vulnerability management is for.

In context

Where these words actually show up.

A glossary is more useful when you know where you'll meet the term. Here's where each cluster lands, and where to go when you'd rather have a person walk you through it.

Questions

About this glossary.

Is SOC 2 a certification?

No. SOC 2 Type II is an independent attestation, an auditor examines whether your security controls were in place and operating effectively over a period of time and issues a report. There's no certificate and no pass/fail badge, so the accurate phrasing is "SOC 2 Type II compliant," not "SOC 2 certified."

What's the difference between EDR and MDR?

EDR is the endpoint detection technology, the software that spots suspicious behavior on a device. MDR is that technology plus a staffed security operations center that investigates and acts on what it finds. The tool detects; the SOC responds. We provide both.

RPO and RTO sound the same — how do I keep them straight?

RPO is about data: how much you can afford to lose, measured in time (an RPO of one hour means backups every hour or better). RTO is about downtime: how fast a system has to be back (an RTO of four hours means restored within four hours). Point equals data lost; Time equals time down.

Do I need to understand all of this to work with you?

Not at all — that's our job. This glossary exists so the language in our reports and proposals is never a black box, but you're never expected to become the expert. Ask us anything, and we'll translate it into a plain business decision.

Why does the definition matter if the vendor sells the same thing?

Because two vendors can use the same acronym and deliver very different things — "managed EDR" with a real SOC behind it is not the same as a tool nobody watches. Knowing the term lets you ask the follow-up question that separates them.

Have a term we should add?

If a word in a proposal or report has you second-guessing, we'll define it, and if it turns out to be a gap, we'll help you close it.