GC SOLUTIONS EXECUTIVE REFERENCE

Cryptography, translated into business language.

A concise, searchable reference for the terms shaping enterprise security architecture, compliance, and modernization decisions.

20 terms in view
Algorithms

AES

Advanced Encryption Standard

A widely used symmetric encryption standard that protects data using the same secret key for encryption and decryption.

Algorithms

RSA

Rivest–Shamir–Adleman

A public-key algorithm commonly used for encryption and digital signatures; many organizations are evaluating its long-term use as part of post-quantum planning.

Algorithms

ECC

Elliptic Curve Cryptography

A public-key approach that provides strong security with comparatively small keys, often used in certificates, mobile systems, and secure protocols.

Trust

PKI

Public Key Infrastructure

The people, policies, systems, and processes used to issue, manage, validate, and revoke digital certificates.

Key Management

HSM

Hardware Security Module

A specialized device that generates, protects, and uses cryptographic keys within a controlled, tamper-resistant boundary.

Key Management

KMS

Key Management System

A service or platform for creating, storing, rotating, controlling, and auditing the use of cryptographic keys.

Key Management

KEK

Key Encryption Key

A key used to encrypt or wrap other keys, reducing how often sensitive key material must be handled directly.

Key Management

LMK

Local Master Key

A high-level key used inside certain cryptographic systems to protect other keys stored or processed by that system.

Cloud

BYOK

Bring Your Own Key

A model in which an organization supplies key material for use with a cloud or service provider’s encryption controls.

Cloud

HYOK

Hold Your Own Key

A model designed to keep key control outside a provider’s environment, giving the organization a stronger separation of custody.

Strategy

Crypto-Agility

The ability to identify and change cryptographic algorithms, keys, certificates, libraries, or providers without uncontrolled disruption.

Strategy

PQC

Post-Quantum Cryptography

Cryptographic algorithms designed to resist attacks from both conventional and sufficiently capable quantum computers.

Algorithms

ML-KEM

Module-Lattice-Based Key-Encapsulation Mechanism

A standardized post-quantum mechanism used to establish shared secret keys over an untrusted network.

Trust

Digital Certificates

Electronic credentials that bind an identity to a public key and help systems establish authenticated, encrypted connections.

Trust

Certificate Authority

A trusted entity that issues and signs digital certificates under defined validation and governance policies.

Operations

Key Rotation

The controlled replacement of a cryptographic key to limit exposure and satisfy security or compliance requirements.

Operations

Key Lifecycle

The full sequence of key generation, distribution, storage, use, rotation, archival, revocation, and destruction.

Data Protection

Tokenization

The replacement of sensitive data with a non-sensitive surrogate token while the original value is protected in a controlled vault or equivalent service. Unlike encryption, a token typically has no direct mathematical relationship to the source data.

Assurance

Common Criteria

An international framework for evaluating and certifying the security properties of technology products against defined requirements.

Compliance

PCI-DSS

Payment Card Industry Data Security Standard

A security standard for organizations that store, process, or transmit payment card data, including requirements affecting encryption and key management.