Glossary79 termsPlain English
The words technology uses,in plain English.
Short, plain definitions of the terms you will meet in software testing, security, AI, the web, and business systems. Each one links to a piece that explains it in depth.
Testing basics
- Software testing
- Checking software in a planned way to find problems before the people who rely on it do, and to measure how ready it is to release.
- Learn more →
- Quality
- How well software does what its users need: working correctly, staying fast, keeping data safe, and being easy to use.
- Learn more →
- Test case
- A written description of one test: the starting conditions, the steps, the data to use, and the result you expect.
- Learn more →
- Expected result
- What should happen if the software works correctly. Written before the test is run, so the actual result can be judged fairly.
- Actual result
- What really happened when the test was run. A difference from the expected result is worth investigating.
- Test plan
- A document describing what will be tested, how, by whom, and what has to be true before the software can be released.
- Learn more →
- Requirement
- A statement of what the software must do or how well it must do it. Unclear requirements are a common source of defects.
- Regression testing
- Rerunning tests after a change to make sure things that used to work still work.
- Exploratory testing
- Learning about the software, designing tests, and running them at the same time, guided by what the tester discovers along the way.
Bugs and defects
- Defect (bug)
- A flaw in code, a design, or a document that can make the software behave wrongly. Also called a bug or a fault.
- Learn more →
- Failure
- The software visibly doing the wrong thing when it runs, such as crashing or showing a wrong total.
- Learn more →
- Root cause
- The underlying reason a defect was created. Fixing the root cause prevents similar defects in the future.
- Priority
- How soon a defect should be fixed, based on business needs as well as impact.
- Bug report
- A written description of a problem with the summary, steps to reproduce, expected and actual results, and evidence a developer needs to fix it.
- Learn more →
- Reproduce
- Make a problem happen again on purpose, by repeating the exact steps and conditions.
- False positive
- A test reports a problem that is not really a defect in the software, for example because the test itself was wrong.
- False negative
- A real defect that the tests fail to catch.
Test design
- Equivalence partitioning
- Grouping inputs the software should treat the same way, then testing one value from each group.
- Learn more →
- Boundary value analysis
- Testing values at and right next to the edges of each group, where off-by-one defects tend to hide.
- Learn more →
- Test data
- The values, records, and files a test uses. Realistic, well-chosen data finds more problems.
- Learn more →
- Coverage
- How much of something your tests exercise: requirements, risks, code, or configurations.
- Learn more →
- Functional testing
- Checking that the software does the right things: correct results, the right features, and working connections to other systems.
- Learn more →
- Non-functional testing
- Checking how well the software works rather than what it does: speed, security, usability, accessibility, and reliability.
Process and management
- Quality risk
- Something that could go wrong with the software, rated by how likely it is and how much harm it would do.
- Learn more →
- Risk-based testing
- Spending testing effort in proportion to risk, so the areas where failure would cost most get the most attention.
- Learn more →
- Exit criteria
- The conditions agreed in advance that must be met before testing can end and the software can be released.
- Test metrics
- Measurements, such as defects found or tests passed, used to understand progress and quality.
- Learn more →
- Critical Testing Processes (CTP)
- Rex Black's framework of twelve testing processes used to assess and improve a test function, prioritized by business value.
- Learn more →
- ISTQB
- The International Software Testing Qualifications Board, which publishes the syllabi behind the most common testing certifications. In the US, its exams are administered by ASTQB.
- Learn more →
- TMMi
- Test Maturity Model integration: a five-level model for rating how mature an organization's testing is.
Automation
- Test automation
- Using code to run tests and check results automatically, so they can run quickly and often.
- Learn more →
- Unit test
- An automated test of one small piece of code on its own, usually written by the developer.
- Continuous integration (CI)
- Automatically building the software and running tests every time someone changes the code.
- Flaky test
- An automated test that sometimes passes and sometimes fails without any change to the software. Flaky tests erode trust and should be fixed or removed.
- Property-based testing
- Generating many random inputs automatically and checking that a rule always holds, instead of writing each input by hand.
- Learn more →
Security basics
- Vulnerability
- A weakness in software that an attacker could use to do something they should not be able to do.
- Learn more →
- Authentication
- Proving who you are, for example with a password, a code from an app, or a fingerprint.
- Multi-factor authentication (MFA)
- Signing in with two or more kinds of proof, such as a password plus a code from your phone, so a stolen password alone is not enough.
- Learn more →
- Encryption
- Scrambling data so only someone with the right key can read it, both while it travels and while it is stored.
- Phishing
- Tricking someone into revealing passwords or other information, usually with a message that pretends to come from someone trusted.
- Learn more →
- Malware
- Software designed to cause harm, such as stealing data, spying, or locking files for ransom.
- Patch
- An update that fixes a defect or closes a vulnerability. Installing updates promptly is one of the simplest ways to stay safe.
- Learn more →
- Personal data
- Information that identifies a person, such as a name, address, email, or location. Good software collects only what it needs and protects it.
- CIA triad
- The three goals of security: confidentiality (only the right people see information), integrity (it is accurate and unaltered), and availability (it works when needed).
- Learn more →
- Threat
- Anything that could cause harm to a system or its data, such as a criminal group, a careless mistake, or a power failure.
- Learn more →
- Defense in depth
- Stacking several layers of protection so that when one fails, the next one still stops the attack.
- Learn more →
- Injection
- An attack that slips instructions into input, such as a form field, so the software runs them instead of treating them as data.
- Learn more →
- Penetration test
- An authorized, time-boxed attempt by skilled testers to break into a system the way a real attacker would.
- Learn more →
AI
- Large language model (LLM)
- An AI model trained on large amounts of text that can write, summarize, and answer questions.
- Learn more →
- Token
- A piece of a word. AI models read and write text in tokens, and are usually priced per million tokens.
- Learn more →
- Evaluation set
- A collection of real questions with known good answers, used to measure how well an AI system performs and to catch changes.
- Learn more →
- Context window
- The amount of text an AI model can consider at once: your question, any documents, earlier messages, and its own answer so far.
- Learn more →
- Prompt
- The instructions and context you give an AI model. Clear prompts that state the task, audience, and constraints get better results.
- Learn more →
- Open-weight model
- An AI model whose trained parameters are published, so an organization can run it on infrastructure it chooses.
- Learn more →
- Guardrail
- A check that limits what an AI system can say or do, such as blocking certain actions or routing them to a person for approval.
- Learn more →
- AI agent
- An AI system that takes actions, such as booking a meeting or updating a record, not just answering questions.
- Learn more →
The web
- DNS (Domain Name System)
- The internet's address book. It turns a domain name like example.com into the numeric address of the server that hosts it.
- Learn more →
- HTTPS
- The secure way browsers and websites communicate. It encrypts the connection and confirms the site's identity with a certificate.
- Learn more →
- HTML, CSS, and JavaScript
- The three languages of web pages: HTML for structure and content, CSS for presentation and layout, JavaScript for behavior.
- Learn more →
- Front end and back end
- The front end runs in the visitor's browser; the back end runs on servers, handling accounts, orders, business rules, and the database.
- Learn more →
- Content delivery network (CDN)
- A network of servers around the world that keeps copies of a site's files and serves each visitor from the nearest location.
- Learn more →
- Core Web Vitals
- Google's measurements of how fast a page feels: how quickly the main content appears, how quickly it responds to input, and how much it jumps while loading.
- Learn more →
- Accessibility
- Designing so people with disabilities can use a site, including with screen readers, keyboards, and magnification. The standard is WCAG.
- Learn more →
- SEO (search engine optimization)
- Making pages easy for search engines to understand and worth ranking: clear purpose, accurate content, speed, and good structure.
- Learn more →
- Responsive design
- A layout that adapts to each screen size, so a site works as well on a phone as on a desktop.
- Learn more →
Business systems
- CRM (customer relationship management)
- Software that keeps track of customers and prospects and every interaction with them: contacts, deals, activities, and service cases.
- Learn more →
- ERP (enterprise resource planning)
- Software that runs a company's financial and operational core: accounting, orders, inventory, purchasing, and often payroll.
- Learn more →
- API (application programming interface)
- A published set of requests one program accepts from others, and the responses it returns. Most integrations are built on APIs.
- Learn more →
- Integration
- Connecting separate systems so they share information automatically and accurately, instead of people retyping it.
- Learn more →
- System of record
- The one system whose version of a piece of data is authoritative. Other systems receive copies and do not overwrite it.
- Learn more →
- Data migration
- Moving records from an old system to a new one, cleaned and mapped so nothing is lost or corrupted.
- Learn more →
Keep reading
Related reading
- Primer
Careers in Software Quality: Roles, Skills, and First Steps
What testers, test automation engineers, quality engineers, and test managers actually do, the skills each role uses, and practical first steps for students and career changers, including the ISTQB Foundation certification.
Read → - Primer
Errors, Defects, and Failures: What a Bug Really Is
Everyone says 'bug', but testers use three precise words: error, defect, and failure. Learn the difference, why it matters, and how severity and priority decide which problems get fixed first.
Read → - Primer
How Software Gets Attacked: Common Vulnerabilities in Plain English
The most common ways attackers break into software, explained without jargon: trusting input, broken access control, weak sign-in, misconfiguration, and outdated components. Each one comes with the defense that stops it.
Read → - Primer
How to Report a Bug So It Actually Gets Fixed
Finding a bug is half the job. Learn how to write a bug report a developer can act on: a clear summary, exact steps to reproduce, expected versus actual results, and the habits professional testers use to make every report count.
Read → - Primer
Security Testing Basics: Finding Weaknesses Before Attackers Do
An introduction to security testing for new testers and developers: thinking in threats, designing abuse cases, testing access control, the role of automated scanners and penetration tests, and the rules that keep security testing legal and ethical.
Read → - Primer
Staying Safe Online: Passwords, Sign-In, Phishing, and Updates
The everyday security habits that stop most attacks: strong unique passwords, multi-factor sign-in, spotting phishing, keeping devices updated, and sharing carefully. Written for students, families, and anyone starting out.
Read →
Practices
Where this leads
- TrainingQA and AI training
ISTQB certification and hands-on courses for testers, engineers, and leaders, from one of the first ASTQB-accredited training providers in the United States.
Book a call → - QA & testingSoftware testing
Software quality consulting since 1994: we test the releases that matter, coach your team on the method, and measure how its testing matures.
Book a call →