Idira (formerly CyberArk) - Glossary

Common terms and acronyms used within Idira.

PAM Offerings

(PAM Self-Hosted + Privilege Cloud SAAS)

This includes the traditional EPV architecture components plus their SaaS equivalents:

PAM Acronyms

Acronym

Long Name

Formerly Known As

Summary

PAM

Privileged Access Manager

PAS (Privileged Access Security)

CyberArk’s core vault-based platform for securing, rotating, and monitoring privileged accounts.

EPV

Enterprise Password Vault

The hardened digital vault that securely stores privileged credentials and secrets.

PVWA

Password Vault Web Access

Web interface used to manage safes, accounts, access requests, and policies.

CPM

Central Policy Manager

Rotates passwords, enforces credential policies, and reconciles accounts automatically.

PSM

Privileged Session Manager

Proxies, monitors, and records privileged sessions (RDP, SSH, etc.) for audit and control.

PSMP

Privileged Session Manager for SSH

Provides SSH access control and session monitoring without requiring agents.

PTA

Privileged Threat Analytics

Detects suspicious privileged activity using behavioral analytics.

OPM

On-Demand Privileges Manager

Grants temporary local admin rights on endpoints without vaulting credentials.

CP

Credential Provider

Local SDK-based component that retrieves secrets directly from the Vault for applications.

CCP

Central Credential Provider

Web service that allows applications to retrieve credentials via REST API.

AAM

Application Access Manager

Framework for securing and managing application-to-secret interactions.

AIM

Application Identity Manager

Legacy naming often used to describe application credential retrieval capabilities.

PC

Privilege Cloud

SaaS-delivered version of CyberArk PAM, removing the need to manage Vault infrastructure.

VRA

Vendor Remote Access

Alero

Provides secure third-party access without VPN or direct network exposure.

DPA

Dynamic Privileged Access

Now SIA

Provided vaultless, just-in-time infrastructure access (renamed to SIA).

SIEM

Secure Information and Event Management

 

A combination of security information management and security event management to enable real-time analysis of security alerts generated by applications and network hardware.

ZSP

Zero Standing Privilege

 

A security principle that eliminates persistent access rights for users, granting them privileges only when needed and for a limited time.

Identity Security Platform

(ISPSS + SaaS Services + Machine Identity)

This includes SaaS-delivered services, Secrets Manager, Secure Infrastructure Access, IGA, and Machine Identity Security.

Identity Security Platform Acronyms

Acronym

Long Name

Formerly Known As

Summary

ISPSS

Identity Security Platform Shared Services

The shared SaaS foundation that powers CyberArk cloud services.

DisCo

Discovery & Context

Platform intelligence layer that discovers identities, entitlements, and risk context across environments.

TDR

Threat Detection & Response

Replaces ISI & UBA

Detects identity-based threats using behavioral analytics and risk modeling.

ISI

Identity Security Intelligence

 

Former identity analytics service; now phased into TDR.

UBA

User Behavior Analytics

 

 Also being retired for TDR

SIA

Secure Infrastructure Access

DPA

Provides vaultless, just-in-time access to servers, Kubernetes, and infrastructure.

SCA

Secure Cloud Access

Secures cloud control plane access (AWS, Azure, GCP) with least privilege and JIT enforcement.

CDS

Cloud Discovery Service

Discovers cloud environments, accounts, roles, and permissions for visibility and risk analysis.

CCE

Connect Cloud Environment

Onboards and connects cloud tenants to CyberArk services securely.

SA

Secure Access

Protects workforce SaaS access with session monitoring and browser isolation.

SWS

Secure Web Sessions

Monitors and protects SaaS sessions from browser-based threats.

WPM

Workforce Password Management

Enterprise password manager for workforce credentials.

SM (SaaS)

Secrets Manager SaaS

Conjur Cloud

Manages machine and application secrets in cloud-native environments.

SM (Self-Hosted)

Secrets Manager Self-Hosted

Conjur Enterprise

On-prem version of CyberArk’s secrets management platform.

CEM

Cloud Entitlements Manager

C3M

Governs and right-sizes cloud permissions to reduce standing privilege.

CIEM

Cloud Infrastructure Entitlements Management

Industry category describing cloud entitlement governance solutions (like CEM).

IGA

Identity Governance & Administration

Zilla Security

Manages identity lifecycle, access certifications, and entitlement governance.

EPM

Endpoint Privilege Manager

Viewfinity

Enforces least privilege and application control on endpoints.

MIS

Machine Identity Security

Venafi portfolio

Manages certificates and machine identities across hybrid environments.

TLS Protect (SaaS)

Certificate Manager SaaS

Venafi TLS Protect Cloud

Manages and automates certificate lifecycle in cloud environments.

TLS Protect (Self-Hosted)

Certificate Manager Self-Hosted

Venafi TLS Protect

On-prem certificate lifecycle management solution.

SRS

Secrets Rotation Service

SaaS rotation engine that automatically rotates cloud and SaaS secrets.

SAI

Secure AI Agents

Controls and secures AI agents’ access to enterprise systems and secrets.

CRDR

Cross-Region Disaster Recovery

High-Availability SaaS Platform

LCD

Loosely Connected Devices

Devices that are not consistently connected to the corporate network (e.g., remote laptops) and therefore require cloud-based privilege enforcement and policy management.

Secure Access Family

(SA and Related Acronyms)

Below is how Secure Access and its related terms fit structurally:

Secure Access Family Acronyms

Acronym

Where It Fits

SA

Identity Security Platform

SWS

Component of Secure Access

WPM

Often bundled with Secure Access

Secure Browser

Delivered as part of Secure Access

Adaptive MFA

Identity platform service

SCA

Identity Security Platform

CDS

Component of SCA

CCE

Component of SCA onboarding

CEM

Often paired with SCA (governance layer)

DisCo

Broad platform intelligence layer

Think of Idira's structure as:

PAM → Vault-centric privileged account security

SIA / SCA / SA → Vaultless access enforcement layers

DisCo → Visibility + context engine

TDR → Threat detection layer

CEM / IGA → Governance layers

SM / MIS → Machine & application identity security

EPM → Endpoint privilege control



Keywords:
CyberArk, PAM, vault, glossary, Idira 
Doc ID:
110936
Owned by:
CyberArk Team in Cybersecurity
Created:
2021-05-20
Updated:
2026-08-19
Sites:
Office of Cybersecurity