Idira (formerly CyberArk) - Glossary
PAM Offerings
(PAM Self-Hosted + Privilege Cloud SAAS)
This includes the traditional EPV architecture components plus their SaaS equivalents:
|
Acronym |
Long Name |
Formerly Known As |
Summary |
|---|---|---|---|
|
PAM |
Privileged Access Manager |
PAS (Privileged Access Security) |
CyberArk’s core vault-based platform for securing, rotating, and monitoring privileged accounts. |
|
EPV |
Enterprise Password Vault |
— |
The hardened digital vault that securely stores privileged credentials and secrets. |
|
PVWA |
Password Vault Web Access |
— |
Web interface used to manage safes, accounts, access requests, and policies. |
|
CPM |
Central Policy Manager |
— |
Rotates passwords, enforces credential policies, and reconciles accounts automatically. |
|
PSM |
Privileged Session Manager |
— |
Proxies, monitors, and records privileged sessions (RDP, SSH, etc.) for audit and control. |
|
PSMP |
Privileged Session Manager for SSH |
— |
Provides SSH access control and session monitoring without requiring agents. |
|
PTA |
Privileged Threat Analytics |
— |
Detects suspicious privileged activity using behavioral analytics. |
|
OPM |
On-Demand Privileges Manager |
— |
Grants temporary local admin rights on endpoints without vaulting credentials. |
|
CP |
Credential Provider |
— |
Local SDK-based component that retrieves secrets directly from the Vault for applications. |
|
CCP |
Central Credential Provider |
— |
Web service that allows applications to retrieve credentials via REST API. |
|
AAM |
Application Access Manager |
— |
Framework for securing and managing application-to-secret interactions. |
|
AIM |
Application Identity Manager |
— |
Legacy naming often used to describe application credential retrieval capabilities. |
|
PC |
Privilege Cloud |
— |
SaaS-delivered version of CyberArk PAM, removing the need to manage Vault infrastructure. |
|
VRA |
Vendor Remote Access |
Alero |
Provides secure third-party access without VPN or direct network exposure. |
|
DPA |
Dynamic Privileged Access |
Now SIA |
Provided vaultless, just-in-time infrastructure access (renamed to SIA). |
|
SIEM |
Secure Information and Event Management |
|
A combination of security information management and security event management to enable real-time analysis of security alerts generated by applications and network hardware. |
|
ZSP |
Zero Standing Privilege |
|
A security principle that eliminates persistent access rights for users, granting them privileges only when needed and for a limited time. |
Identity Security Platform
(ISPSS + SaaS Services + Machine Identity)
This includes SaaS-delivered services, Secrets Manager, Secure Infrastructure Access, IGA, and Machine Identity Security.
|
Acronym |
Long Name |
Formerly Known As |
Summary |
|---|---|---|---|
|
ISPSS |
Identity Security Platform Shared Services |
— |
The shared SaaS foundation that powers CyberArk cloud services. |
|
DisCo |
Discovery & Context |
— |
Platform intelligence layer that discovers identities, entitlements, and risk context across environments. |
|
TDR |
Threat Detection & Response |
Replaces ISI & UBA |
Detects identity-based threats using behavioral analytics and risk modeling. |
|
ISI |
Identity Security Intelligence |
|
Former identity analytics service; now phased into TDR. |
|
UBA |
User Behavior Analytics |
|
Also being retired for TDR |
|
SIA |
Secure Infrastructure Access |
DPA |
Provides vaultless, just-in-time access to servers, Kubernetes, and infrastructure. |
|
SCA |
Secure Cloud Access |
— |
Secures cloud control plane access (AWS, Azure, GCP) with least privilege and JIT enforcement. |
|
CDS |
Cloud Discovery Service |
— |
Discovers cloud environments, accounts, roles, and permissions for visibility and risk analysis. |
|
CCE |
Connect Cloud Environment |
— |
Onboards and connects cloud tenants to CyberArk services securely. |
|
SA |
Secure Access |
— |
Protects workforce SaaS access with session monitoring and browser isolation. |
|
SWS |
Secure Web Sessions |
— |
Monitors and protects SaaS sessions from browser-based threats. |
|
WPM |
Workforce Password Management |
— |
Enterprise password manager for workforce credentials. |
|
SM (SaaS) |
Secrets Manager SaaS |
Conjur Cloud |
Manages machine and application secrets in cloud-native environments. |
|
SM (Self-Hosted) |
Secrets Manager Self-Hosted |
Conjur Enterprise |
On-prem version of CyberArk’s secrets management platform. |
|
CEM |
Cloud Entitlements Manager |
C3M |
Governs and right-sizes cloud permissions to reduce standing privilege. |
|
CIEM |
Cloud Infrastructure Entitlements Management |
— |
Industry category describing cloud entitlement governance solutions (like CEM). |
|
IGA |
Identity Governance & Administration |
Zilla Security |
Manages identity lifecycle, access certifications, and entitlement governance. |
|
EPM |
Endpoint Privilege Manager |
Viewfinity |
Enforces least privilege and application control on endpoints. |
|
MIS |
Machine Identity Security |
Venafi portfolio |
Manages certificates and machine identities across hybrid environments. |
|
TLS Protect (SaaS) |
Certificate Manager SaaS |
Venafi TLS Protect Cloud |
Manages and automates certificate lifecycle in cloud environments. |
|
TLS Protect (Self-Hosted) |
Certificate Manager Self-Hosted |
Venafi TLS Protect |
On-prem certificate lifecycle management solution. |
|
SRS |
Secrets Rotation Service |
— |
SaaS rotation engine that automatically rotates cloud and SaaS secrets. |
|
SAI |
Secure AI Agents |
— |
Controls and secures AI agents’ access to enterprise systems and secrets. |
|
CRDR |
Cross-Region Disaster Recovery |
— |
High-Availability SaaS Platform |
|
LCD |
Loosely Connected Devices |
— |
Devices that are not consistently connected to the corporate network (e.g., remote laptops) and therefore require cloud-based privilege enforcement and policy management. |
Secure Access Family
(SA and Related Acronyms)
Below is how Secure Access and its related terms fit structurally:
|
Acronym |
Where It Fits |
|---|---|
|
SA |
Identity Security Platform |
|
SWS |
Component of Secure Access |
|
WPM |
Often bundled with Secure Access |
|
Secure Browser |
Delivered as part of Secure Access |
|
Adaptive MFA |
Identity platform service |
|
SCA |
Identity Security Platform |
|
CDS |
Component of SCA |
|
CCE |
Component of SCA onboarding |
|
CEM |
Often paired with SCA (governance layer) |
|
DisCo |
Broad platform intelligence layer |
Think of Idira's structure as:
PAM → Vault-centric privileged account security
SIA / SCA / SA → Vaultless access enforcement layers
DisCo → Visibility + context engine
TDR → Threat detection layer
CEM / IGA → Governance layers
SM / MIS → Machine & application identity security
EPM → Endpoint privilege control