Practical reference

Digital intelligence glossary

Twenty-four concepts explained through practical use, with a guide for taking each topic further.

Map of key digital intelligence concepts

OSINT

Research and analysis of lawfully public information to answer a defined question. A screenshot alone is insufficient: origin, date and confidence level need to remain traceable.

Read the related guide

Evidence chain

A recorded sequence of sources, copies, dates and transformations that shows how a conclusion was reached. It makes corrections possible when a source changes or disappears.

Read the related guide

Exposure surface

The domains, applications, accounts, services and suppliers accessible from or dependent on the outside. An inventory should assign an owner and priority to each asset.

Read the related guide

Third-party risk

Risk introduced by reliance on a supplier, software product or platform. Assess it through entrusted data, granted access, service criticality and exit options.

Read the related guide

DNS resilience

The ability to maintain or restore resolution for essential domains after error, outage or lost access. It calls for an inventory, access protections and a recovery exercise.

Read the related guide

Idempotency

A property that keeps the same business effect when an operation is replayed with the same request identity. It helps retry an API call after an uncertain response without creating a duplicate.

Read the related guide

SBOM

An inventory of software components and versions for a specific release. It becomes useful when it matches the deployed artifact and helps locate affected components after an alert.

Read the related guide

RAG

A method that supplies a model with documents retrieved while answering. Quality depends on source selection, freshness and citation checks as well as the model itself.

Read the related guide

AI agent

A system that can chain decisions and call tools to reach a goal. Its scope, permissions, audit trail and human approval points should be defined before sensitive use.

Read the related guide

Hreflang

An annotation connecting equivalent language versions of a page. Each accessible version should name itself and its counterparts so search engines can show the appropriate language.

Read the related guide

AI search visibility

The measurable presence of a page as a source or destination in AI-assisted search journeys. Useful measurement separates impressions, clicks, observed citations and conversions.

Read the related guide

Information provenance

A description of content origin, date and known transformations. It helps separate a primary document, a repost and an interpretation that still carries uncertainty.

Read the related guide

Phishing-resistant MFA

Multifactor authentication bound to the legitimate site or service, reducing the chance that a code can be reused on a fake page. Deployment also needs secure account recovery procedures.

Read the related guide

Cyber incident exercise

A controlled simulation that tests roles, decisions, communication and service restoration. Its value comes from the gaps corrected after the session.

Read the related guide

Digital due diligence

A documented review of an asset, organisation or supplier before a decision. It compares claims with evidence, dependencies, risks and exit conditions.

Read the related guide

Structured data

Information added to page code to describe its content and entities explicitly. It should match visible material and cannot replace clear text or eligibility for indexing.

Read the related guide

Canonical URL

The preferred address of a page when several similar URLs exist. It helps consolidate search signals and should point to an accessible page carrying the relevant content.

Read the related guide

Web performance

The loading and responsiveness quality of a site under real conditions. Assess it across important journeys, devices and networks alongside security.

Read the related guide

Data lifecycle

The stages of collection, use, retention, archiving and deletion. Each stage benefits from a purpose, owner, time limit and evidence of completion.

Read the related guide

AI vendor evaluation

Assessment of an AI service through permitted uses, data handling, tests, operating limits and reversibility. A sales demonstration does not prove production quality.

Read the related guide

Human approval point

A control where a person can inspect, change or reject an automated action before a sensitive effect. Specify what they see, their deadline and their real decision authority.

Read the related guide

RPO and RTO

RPO defines the maximum acceptable data loss after an incident; RTO defines the target time to restore service. Both need to be tied to services and tested in exercises.

Read the related guide

Graceful degradation

Limited but intentional operation when a dependency fails. It defines retained functions, potentially delayed data and the information shown to users.

Read the related guide

Confidence assessment

An explicit judgement of how certain a conclusion is, based on evidence quality and convergence. Keep it separate from the importance of the decision.

Read the related guide