Idira (formerly CyberArk) - Glossary

Common terms and acronyms used within Idira.

PAM Offerings

(PAM Self-Hosted + Privilege Cloud SAAS)

This includes the traditional EPV architecture components plus their SaaS equivalents:

PAM Acronyms

Acronym

Long Name

Formerly Known As

Summary

PAM

Privileged Access Manager

PAS (Privileged Access Security)

CyberArk’s core vault-based platform for securing, rotating, and monitoring privileged accounts.

EPV

Enterprise Password Vault

—

The hardened digital vault that securely stores privileged credentials and secrets.

PVWA

Password Vault Web Access

—

Web interface used to manage safes, accounts, access requests, and policies.

CPM

Central Policy Manager

—

Rotates passwords, enforces credential policies, and reconciles accounts automatically.

PSM

Privileged Session Manager

—

Proxies, monitors, and records privileged sessions (RDP, SSH, etc.) for audit and control.

PSMP

Privileged Session Manager for SSH

—

Provides SSH access control and session monitoring without requiring agents.

PTA

Privileged Threat Analytics

—

Detects suspicious privileged activity using behavioral analytics.

OPM

On-Demand Privileges Manager

—

Grants temporary local admin rights on endpoints without vaulting credentials.

CP

Credential Provider

—

Local SDK-based component that retrieves secrets directly from the Vault for applications.

CCP

Central Credential Provider

—

Web service that allows applications to retrieve credentials via REST API.

AAM

Application Access Manager

—

Framework for securing and managing application-to-secret interactions.

AIM

Application Identity Manager

—

Legacy naming often used to describe application credential retrieval capabilities.

PC

Privilege Cloud

—

SaaS-delivered version of CyberArk PAM, removing the need to manage Vault infrastructure.

VRA

Vendor Remote Access

Alero

Provides secure third-party access without VPN or direct network exposure.

DPA

Dynamic Privileged Access

Now SIA

Provided vaultless, just-in-time infrastructure access (renamed to SIA).

SIEM

Secure Information and Event Management

 

A combination of security information management and security event management to enable real-time analysis of security alerts generated by applications and network hardware.

ZSP

Zero Standing Privilege

 

A security principle that eliminates persistent access rights for users, granting them privileges only when needed and for a limited time.

Identity Security Platform

(ISPSS + SaaS Services + Machine Identity)

This includes SaaS-delivered services, Secrets Manager, Secure Infrastructure Access, IGA, and Machine Identity Security.

Identity Security Platform Acronyms

Acronym

Long Name

Formerly Known As

Summary

ISPSS

Identity Security Platform Shared Services

—

The shared SaaS foundation that powers CyberArk cloud services.

DisCo

Discovery & Context

—

Platform intelligence layer that discovers identities, entitlements, and risk context across environments.

TDR

Threat Detection & Response

Replaces ISI & UBA

Detects identity-based threats using behavioral analytics and risk modeling.

ISI

Identity Security Intelligence

 

Former identity analytics service; now phased into TDR.

UBA

User Behavior Analytics

 

 Also being retired for TDR

SIA

Secure Infrastructure Access

DPA

Provides vaultless, just-in-time access to servers, Kubernetes, and infrastructure.

SCA

Secure Cloud Access

—

Secures cloud control plane access (AWS, Azure, GCP) with least privilege and JIT enforcement.

CDS

Cloud Discovery Service

—

Discovers cloud environments, accounts, roles, and permissions for visibility and risk analysis.

CCE

Connect Cloud Environment

—

Onboards and connects cloud tenants to CyberArk services securely.

SA

Secure Access

—

Protects workforce SaaS access with session monitoring and browser isolation.

SWS

Secure Web Sessions

—

Monitors and protects SaaS sessions from browser-based threats.

WPM

Workforce Password Management

—

Enterprise password manager for workforce credentials.

SM (SaaS)

Secrets Manager SaaS

Conjur Cloud

Manages machine and application secrets in cloud-native environments.

SM (Self-Hosted)

Secrets Manager Self-Hosted

Conjur Enterprise

On-prem version of CyberArk’s secrets management platform.

CEM

Cloud Entitlements Manager

C3M

Governs and right-sizes cloud permissions to reduce standing privilege.

CIEM

Cloud Infrastructure Entitlements Management

—

Industry category describing cloud entitlement governance solutions (like CEM).

IGA

Identity Governance & Administration

Zilla Security

Manages identity lifecycle, access certifications, and entitlement governance.

EPM

Endpoint Privilege Manager

Viewfinity

Enforces least privilege and application control on endpoints.

MIS

Machine Identity Security

Venafi portfolio

Manages certificates and machine identities across hybrid environments.

TLS Protect (SaaS)

Certificate Manager SaaS

Venafi TLS Protect Cloud

Manages and automates certificate lifecycle in cloud environments.

TLS Protect (Self-Hosted)

Certificate Manager Self-Hosted

Venafi TLS Protect

On-prem certificate lifecycle management solution.

SRS

Secrets Rotation Service

—

SaaS rotation engine that automatically rotates cloud and SaaS secrets.

SAI

Secure AI Agents

—

Controls and secures AI agents’ access to enterprise systems and secrets.

CRDR

Cross-Region Disaster Recovery

—

High-Availability SaaS Platform

LCD

Loosely Connected Devices

—

Devices that are not consistently connected to the corporate network (e.g., remote laptops) and therefore require cloud-based privilege enforcement and policy management.

Secure Access Family

(SA and Related Acronyms)

Below is how Secure Access and its related terms fit structurally:

Secure Access Family Acronyms

Acronym

Where It Fits

SA

Identity Security Platform

SWS

Component of Secure Access

WPM

Often bundled with Secure Access

Secure Browser

Delivered as part of Secure Access

Adaptive MFA

Identity platform service

SCA

Identity Security Platform

CDS

Component of SCA

CCE

Component of SCA onboarding

CEM

Often paired with SCA (governance layer)

DisCo

Broad platform intelligence layer

Think of Idira's structure as:

PAM → Vault-centric privileged account security

SIA / SCA / SA → Vaultless access enforcement layers

DisCo → Visibility + context engine

TDR → Threat detection layer

CEM / IGA → Governance layers

SM / MIS → Machine & application identity security

EPM → Endpoint privilege control



Keywords:
CyberArk, PAM, vault, glossary, Idira 
Doc ID:
110936
Owned by:
CyberArk Team in Cybersecurity
Created:
2021-05-20
Updated:
2026-08-19
Sites:
Office of Cybersecurity