Glossary
55 terms across intelligence, financial crime, cybersecurity and governance, defined plainly and linked to deeper references.
A
- Air-gapped deploymentGovernance
An installation of software on a network that has no connection to the internet or to other untrusted networks. Updates and data cross the gap only through controlled, inspected transfers rather than a live link. Governments use air-gapped deployments for classified work where the risk of remote access or data leakage cannot be accepted.
See also: Trust and security
- AMLAnti-money launderingFinancial crime
The laws, controls and processes that stop criminals from disguising the proceeds of crime as legitimate funds. Laundering is usually described in three stages: placement of illicit funds into the financial system, layering through transfers that obscure their origin, and integration back into the legitimate economy. An AML program combines customer due diligence, transaction monitoring, sanctions screening and suspicious-transaction reporting.
See also: FinCrimes, Fraud and AML typologies
- Audit trailGovernance
A chronological, tamper-evident record of who did what, when, and to which record in a system. A useful audit trail captures views, edits, approvals and exports, not only logins. It supports internal oversight and regulatory examinations, and it underpins the chain of custody that evidence needs before it can be relied on in court.
See also: Trust and security
C
- COMINTCommunications intelligenceIntelligence
Intelligence derived from communications between people, such as calls, messages and group chats. It is traditionally a branch of signals intelligence. In lawful-access and commercial settings, the term often covers analysis of messaging channels and groups an agency is authorized to monitor, turning high-volume message streams into reviewable evidence.
See also: Messaging intelligence
- Community detectionFinancial crime
A family of graph algorithms that find groups of nodes more densely connected to each other than to the rest of the network. In financial crime it surfaces candidate rings: accounts, devices and parties that transact with or share attributes among themselves far more than ordinary customers do. The groups are leads for an investigator, not findings in themselves.
See also: Graph analytics
- Coordinated inauthentic behaviorIntelligence
Activity in which groups of accounts work together to mislead people about who is behind them or how much support a message really has. Typical signs include accounts created in batches, near-identical posts published within seconds of each other, and shared profile images or contact details. The concern is deception about origin and coordination, not the opinion being expressed.
See also: Counter-disinformation, Social media intelligence
- CSPMCloud security posture managementCybersecurity
Tools and practices that continuously check cloud accounts against security baselines and flag misconfigurations, such as storage left open to the internet, overly broad permissions or disabled logging. CSPM gives security teams one view of risk across several cloud providers and tracks each fix to closure.
See also: Cloud security
- CTRCurrency or cash transaction reportFinancial crime
A report a financial institution files with its financial intelligence unit for cash transactions at or above a set threshold, whether or not anything looks suspicious. Thresholds, names and formats are set nationally; in South Africa the equivalent is the cash threshold report under the FIC Act. Splitting deposits to stay below the threshold is the structuring typology.
See also: Structuring typology, Central banks and regulators
D
- Data residencyGovernance
A requirement that data be stored, and sometimes processed, within a particular country or region. It can come from law, regulation, contract or government policy. Data residency is related to, but narrower than, data sovereignty, which concerns whose laws and authorities can reach the data.
See also: Trust and security, South Africa
- DisinformationIntelligence
False or misleading content created or shared with the intent to deceive. Misinformation is false content shared without that intent, often by people who believe it. The distinction shapes the response: misinformation usually calls for clear correction, while disinformation also calls for attention to the actors and networks spreading it.
See also: Counter-disinformation
E
- EDDEnhanced due diligenceFinancial crime
Additional checks applied to customers or relationships that present higher money-laundering or terrorist-financing risk, such as politically exposed persons, complex ownership structures or links to high-risk jurisdictions. EDD typically means establishing source of funds and source of wealth, obtaining senior management approval and monitoring the relationship more closely. It builds on standard customer due diligence rather than replacing it.
See also: Banking fraud and AML
- End-to-end encryptionCybersecurity
Encryption in which data is encrypted on the owner’s device and decrypted only on an authorized device, so the service that stores or relays it holds nothing but ciphertext. In a password manager it means the provider cannot read vault contents, and also cannot reset a forgotten master password.
See also: KeyCare Pass
- Entity resolutionIntelligence
The process of working out which records refer to the same real-world person, organization, device or account, even when names are spelled differently or details are incomplete. It matches on attributes such as identity numbers, phone numbers, addresses and devices, then links or merges the records. In fraud work, entity resolution is often what reveals that several “separate” customers are one ring.
See also: FinCrimes, Gov AI, Graph analytics
F
- False positiveFinancial crime
An alert that flags legitimate activity as suspicious. Every detection system produces some, and each one costs analyst time and can inconvenience a genuine customer. Teams reduce them by tuning rules against past outcomes, scoring activity against each customer’s own history and making alerts state why they fired, so a reviewer can close a weak one quickly.
See also: FinCrimes
- FININTFinancial intelligenceIntelligence
Intelligence derived from financial records: transactions, account ownership, company registries, suspicious transaction reports and payment flows. It shows who pays whom, who controls what and how money moves between people and jurisdictions, which makes it central to counter-terrorist financing, organized crime and corruption cases. Financial intelligence units produce most of it and share it with law enforcement under statutory gateways.
See also: Financial intelligence in Gov AI, Central banks and regulators
- FIUFinancial intelligence unitFinancial crime
The national agency that receives, analyzes and disseminates reports of suspicious financial activity. An FIU passes its analysis to law enforcement and other authorities and exchanges information with counterparts in other countries. South Africa’s FIU is the Financial Intelligence Centre, established under the Financial Intelligence Centre Act, 2001; in the United States the role is held by FinCEN.
See also: South Africa, United States, Central banks and regulators
G
- GDPRGeneral Data Protection RegulationGovernance
The European Union regulation that governs how personal data about people in the EU is collected, used, stored and transferred. It sets principles such as lawfulness, purpose limitation and data minimization, gives individuals rights over their data and restricts transfers outside the European Economic Area. It can apply to organizations based outside the EU when they offer goods or services to, or monitor, people in the EU.
See also: European Union, Trust and security
- GEOINTGeospatial intelligenceIntelligence
Intelligence derived from imagery and geospatial information about physical features and human activity on the earth. It combines maps, satellite and aerial imagery and location data to show where events happen and how activity moves over time.
See also: Gov AI, Geospatial intelligence
- goAMLFinancial crime
A software application developed by the United Nations Office on Drugs and Crime that financial intelligence units use to receive and analyze reports from reporting institutions. South Africa’s Financial Intelligence Centre receives regulatory reports through goAML, including suspicious and unusual transaction reports, and many FIUs in other countries use it as well. Institutions submit reports through a web portal or as structured XML files.
See also: South Africa, Banking fraud and AML, AML compliance
- Graph analyticsFinancial crime
Analysis of data modeled as nodes (people, accounts, devices, addresses) and edges (payments, shared attributes, relationships). Path finding, centrality, cycle detection and community detection reveal structures that row-by-row rules miss: funds that leave and return through intermediaries, hubs that collect from many mules, or claimants who share a phone. The results are only as good as the entity resolution underneath them.
See also: Graph analytics in FinCrimes, Mule rings typology
H
- HUMINTHuman intelligenceIntelligence
Intelligence gathered from people, through interviews, debriefings, liaison relationships or recruited sources. Because it depends on individuals, HUMINT requires careful source handling, protection of identities and an assessment of each source’s reliability and access.
See also: Gov AI, Signals and human intelligence
I
- Indicators and warningsI&WIntelligence
A structured method for detecting that a threat is developing before it materializes. Analysts define the observable indicators that would precede an event, such as procurement, travel, rhetoric or movement, monitor collection against them and escalate a warning when enough are met. A sound warning records which indicators fired and on what evidence, so a decision-maker can judge it.
See also: Decision advantage, Crisis early warning
- Intelligence fusionIntelligence
Combining information from several intelligence disciplines into one assessed picture. Fusion resolves the same people, places and events across sources, weighs each source’s reliability and shows where reporting corroborates or contradicts. Fusion centers apply it to bring national, regional and local holdings together for a single mission.
See also: Intelligence fusion in Gov AI, Gov AI missions
- Intelligence lifecycleIntelligence
The repeating process by which intelligence is produced. Requirements are set, information is collected and processed, analysts assess it, and the resulting product is disseminated to decision-makers, whose feedback shapes the next set of requirements. Organizations name the stages slightly differently, but the cycle starts with a question and ends with an answer someone can act on.
See also: Gov AI
- IOCIndicator of compromiseCybersecurity
A piece of forensic evidence that suggests a system has been breached, such as a malicious file hash, an IP address or domain linked to an attacker, or an unexpected configuration change. IOCs are useful for finding known threats quickly, but attackers can change them easily, so mature teams pair them with detections based on attacker behavior.
See also: Threat hunting
J
- Just-in-time accessCybersecurity
Granting elevated rights only when they are needed, for a specific task and period, instead of leaving standing administrator permissions in place. Requests are approved, scoped to a system and account, and expire on their own, which shrinks the window in which a stolen credential is useful.
See also: GovPAM
K
- KYCKnow your customerFinancial crime
The checks a financial institution performs to confirm who a customer is and understand the risk they present. KYC covers identity verification at onboarding, customer due diligence (CDD) on the purpose of the relationship and its beneficial owners, and ongoing review as circumstances change. It is the foundation of an anti-money laundering program.
See also: Banking fraud and AML
L
- Link analysisIntelligence
An analytical technique that maps the relationships between entities, such as people, accounts, phone numbers, addresses and events, as a network graph. Seeing the connections exposes structures that are hard to spot in tables, such as a hub account that many others feed or a cluster of customers sharing one device.
See also: Analysis and reporting, Mule rings typology, Graph analytics
M
- MITRE ATT&CKCybersecurity
A publicly available knowledge base of the tactics and techniques attackers use, organized from initial access through to impact. Security teams use it as a shared vocabulary to plan detections, map coverage gaps, structure threat hunts and report on incidents.
See also: Threat hunting, SIEM engineering
- Money muleFinancial crime
A person who moves money on behalf of someone else, usually by receiving funds into their own account or wallet and passing them on. Some mules are recruited knowingly with offers of easy commission; others are deceived through fake job offers, and some mule accounts are opened with stolen or synthetic identities. Mules put distance between a crime and its proceeds, which is why networks of them are a core laundering method.
See also: Mule rings typology, Funnel accounts typology
N
- Narrative analysisIntelligence
The study of the storylines that circulate in an information environment: what claim is being made, who originates and amplifies it, which audiences it reaches and how it changes over time. Tracking narratives rather than individual posts lets analysts see a campaign as a whole, even when its wording shifts across platforms and languages.
See also: Counter-disinformation
O
- OntologyIntelligence
In data platforms, the shared model of the object types an organization works with (people, organizations, places, accounts, vehicles, events) and the relationships between them. Mapping every source to one ontology lets analysts query and link across sources without knowing how each is structured, and lets access rules attach to the objects themselves.
See also: Intelligence fusion
- OSINTOpen-source intelligenceIntelligence
Intelligence produced from publicly available information, such as websites, news, public records, social media and commercially available data. The value lies in the analysis: verifying sources, connecting findings and documenting how each piece was obtained so the result can be relied on.
See also: OSINT investigations
P
- PAMPrivileged access managementCybersecurity
Controls for the accounts that can change systems: administrators, service accounts, root and database owners. A PAM system discovers these accounts, vaults and rotates their credentials, grants access for a limited time with approval and records privileged sessions. Attackers who gain a foothold usually look for privileged credentials next, which is why frameworks such as ISO/IEC 27001 and NIST SP 800-53 treat privileged access as its own control.
See also: GovPAM
- Penetration testingCybersecurity
An authorized, simulated attack on a system, application or network to find weaknesses before a real attacker does. Testers attempt to exploit what they find and report each issue with evidence, impact and remediation advice. Red teaming is a broader exercise that also tests an organization’s ability to detect and respond, usually over a longer period and with a realistic objective.
See also: Penetration testing
- PEPPolitically exposed personFinancial crime
Someone who holds, or has held, a prominent public function, such as a senior politician, judge, senior military officer or executive of a state-owned enterprise, together with their close family members and known associates. Because their position can be abused for bribery or corruption, financial institutions must identify PEPs and apply enhanced due diligence where the risk warrants it. South African law uses the terms foreign prominent public official and domestic prominent influential person.
See also: Banking fraud and AML
- POPIAProtection of Personal Information ActGovernance
South Africa’s data protection law, the Protection of Personal Information Act, 2013. It sets conditions for the lawful processing of personal information, gives data subjects rights of access and correction, and requires responsible parties to notify the regulator and affected people of security compromises. It is enforced by the Information Regulator.
See also: South Africa, Trust and security
R
- RBACRole-based access controlGovernance
An access model in which permissions are attached to roles, such as analyst, supervisor or administrator, and people receive access by being assigned a role. It makes least-privilege access easier to manage and audit than granting rights person by person.
See also: Trust and security
S
- Sanctions screeningFinancial crime
Checking customers, counterparties and transactions against sanctions lists published by governments and international bodies such as the United Nations Security Council. A confirmed match can require funds to be blocked or frozen and the match reported. Screening has to cope with spelling variants and transliteration, so good tools score how close each match is and route borderline hits to a reviewer.
See also: FinCrimes
- SAR / STRSuspicious activity report / suspicious transaction reportFinancial crime
A report that a regulated institution files with its national financial intelligence unit when it knows or suspects that activity may be linked to crime or terrorist financing. In the United States, SARs are filed with FinCEN; in South Africa, suspicious and unusual transaction reports are filed with the Financial Intelligence Centre under section 29 of the FIC Act. A useful report states clearly who did what, when, through which accounts, and why it appears suspicious.
See also: FinCrimes, South Africa
- SIEMSecurity information and event managementCybersecurity
A platform that collects logs and events from across an organization’s systems, normalizes them and applies correlation rules to detect suspicious activity. A SIEM is only as good as the data fed into it and the detections written for it, which is why ongoing engineering and tuning matter as much as the tool itself.
See also: SIEM engineering
- SIGINTSignals intelligenceIntelligence
Intelligence derived from intercepted electronic signals. It includes communications intelligence (COMINT) and electronic intelligence (ELINT), which comes from non-communication emissions such as radar. SIGINT collection is generally reserved for authorized state agencies operating under specific legal frameworks.
See also: Gov AI, Signals and human intelligence
- SOCSecurity operations centerCybersecurity
The team, processes and technology that monitor an organization’s environment, triage alerts, investigate incidents and coordinate the response. A SOC can be run in-house, fully outsourced or co-managed with a provider; managed detection and response (MDR) is a closely related service model. Incident response, the structured process of containing a breach, removing the attacker and restoring normal operations, is one of its core functions.
See also: SOC-as-a-Service
- SOCMINTSocial media intelligenceIntelligence
Intelligence derived from social media platforms, including posts, comments, profiles, groups and the relationships between accounts. It is used to track emerging threats, public sentiment and coordinated campaigns. SOCMINT is most reliable when it covers the platforms and languages the relevant audience actually uses.
See also: Social media intelligence
- StructuringFinancial crime
Splitting a large amount of cash or value into smaller transactions to stay under reporting thresholds or avoid scrutiny. It can be done by one person over several days, or by several people depositing at different branches or agents. In many jurisdictions, deliberately structuring transactions to evade a reporting obligation is an offense even when the money itself is legitimate.
See also: Structuring typology, Corridor structuring typology
- SupTechSupervisory technologyFinancial crime
Technology central banks, financial regulators and financial intelligence units use to supervise the institutions they oversee: collecting and validating regulatory reports, analyzing data across institutions and focusing examinations where risk is highest. In AML supervision it lets an authority see networks and trends that span many reporting institutions.
See also: Central banks and regulators
T
- Threat huntingCybersecurity
A proactive search for attackers who have evaded existing defenses, starting from a hypothesis about how an intrusion might look rather than waiting for an alert. Hunters query endpoint, identity and network data for signs of specific tactics and techniques. Findings from a hunt are turned into new automated detections.
See also: Threat hunting
- TOGAFThe Open Group Architecture FrameworkGovernance
A widely used enterprise architecture framework. It provides a method for developing architecture across business, data, application and technology layers, along with guidance on architecture governance and on planning the move from a current state to a target state.
See also: Enterprise architecture
- TokenizationGovernance
Replacing a sensitive value, such as an identity number or account number, with a token that has no meaning outside the system that issued it. The original values sit in a separate, tightly controlled store, often called a PII vault, and only authorized processes can exchange a token for the real value. Tokenization lets analytics and AI tools work with masked records while limiting who can see personal data.
See also: Trust and security
- Transaction monitoringFinancial crime
The ongoing review of customer transactions to detect activity that may indicate money laundering, fraud or terrorist financing. Monitoring can run in real time, before a payment completes, or in batches after the fact. Rules and models compare activity against known typologies and against the customer’s own normal behavior, and anything unusual becomes an alert for review.
See also: Banking fraud and AML, Velocity spikes typology
- TTPTactics, techniques and proceduresCybersecurity
A description of how an adversary operates: the goals they pursue (tactics), the methods they use to achieve them (techniques) and the specific way they carry those methods out (procedures). Detections built on TTPs are harder to evade than those built on indicators of compromise, because changing behavior costs an attacker more than changing an IP address or a file.
See also: Threat hunting
- TypologyFinancial crime
A documented pattern of financial crime that describes how a scheme works, the red flags it leaves and the data that reveals it. Financial intelligence units and standard-setting bodies publish typologies to help institutions recognize risks, and detection systems encode them as rules or models. Structuring, mule rings and staged motor accidents are all typologies.
See also: Typology library
V
- vCISOVirtual chief information security officerCybersecurity
A part-time or fractional security executive provided as a service. A vCISO sets security strategy, owns the policies and the risk register, prepares the organization for audits and reports to the board, without the commitment of a full-time executive hire.
See also: vCISO advisory
- Vulnerability managementCybersecurity
The continuous cycle of discovering weaknesses across an organization’s systems, prioritizing them by risk, fixing or mitigating them and verifying each fix. Prioritization should weigh how exploitable a flaw is and how important the affected asset is, not only its severity rating.
See also: Vulnerability management
Z
- Zero trustCybersecurity
A security model that grants no implicit trust based on network location. Every request is authenticated, authorized and checked against policy, access is limited to what each user or service needs, and activity is monitored continuously. Zero trust is an architecture approach adopted over time rather than a single product.
See also: Enterprise architecture, Trust and security
Put the vocabulary to work
Read the typology library for the schemes behind the terms, or take the maturity assessment to see where your program stands.