Skip to main content

Glossary79 termsPlain English

The words technology uses,in plain English.

Short, plain definitions of the terms you will meet in software testing, security, AI, the web, and business systems. Each one links to a piece that explains it in depth.

Testing basics

Software testing
Checking software in a planned way to find problems before the people who rely on it do, and to measure how ready it is to release.
Learn more →
Quality
How well software does what its users need: working correctly, staying fast, keeping data safe, and being easy to use.
Learn more →
Test case
A written description of one test: the starting conditions, the steps, the data to use, and the result you expect.
Learn more →
Expected result
What should happen if the software works correctly. Written before the test is run, so the actual result can be judged fairly.
Actual result
What really happened when the test was run. A difference from the expected result is worth investigating.
Test plan
A document describing what will be tested, how, by whom, and what has to be true before the software can be released.
Learn more →
Requirement
A statement of what the software must do or how well it must do it. Unclear requirements are a common source of defects.
Regression testing
Rerunning tests after a change to make sure things that used to work still work.
Exploratory testing
Learning about the software, designing tests, and running them at the same time, guided by what the tester discovers along the way.

Bugs and defects

Error
A human mistake, such as misreading a requirement, that can lead to a defect.
Learn more →
Defect (bug)
A flaw in code, a design, or a document that can make the software behave wrongly. Also called a bug or a fault.
Learn more →
Failure
The software visibly doing the wrong thing when it runs, such as crashing or showing a wrong total.
Learn more →
Root cause
The underlying reason a defect was created. Fixing the root cause prevents similar defects in the future.
Severity
How serious a defect's impact is, from cosmetic to losing data or money.
Learn more →
Priority
How soon a defect should be fixed, based on business needs as well as impact.
Bug report
A written description of a problem with the summary, steps to reproduce, expected and actual results, and evidence a developer needs to fix it.
Learn more →
Reproduce
Make a problem happen again on purpose, by repeating the exact steps and conditions.
False positive
A test reports a problem that is not really a defect in the software, for example because the test itself was wrong.
False negative
A real defect that the tests fail to catch.

Test design

Equivalence partitioning
Grouping inputs the software should treat the same way, then testing one value from each group.
Learn more →
Boundary value analysis
Testing values at and right next to the edges of each group, where off-by-one defects tend to hide.
Learn more →
Test data
The values, records, and files a test uses. Realistic, well-chosen data finds more problems.
Learn more →
Coverage
How much of something your tests exercise: requirements, risks, code, or configurations.
Learn more →
Functional testing
Checking that the software does the right things: correct results, the right features, and working connections to other systems.
Learn more →
Non-functional testing
Checking how well the software works rather than what it does: speed, security, usability, accessibility, and reliability.

Process and management

Quality risk
Something that could go wrong with the software, rated by how likely it is and how much harm it would do.
Learn more →
Risk-based testing
Spending testing effort in proportion to risk, so the areas where failure would cost most get the most attention.
Learn more →
Exit criteria
The conditions agreed in advance that must be met before testing can end and the software can be released.
Test estimation
Predicting how much time, effort, and money testing will take.
Learn more →
Test metrics
Measurements, such as defects found or tests passed, used to understand progress and quality.
Learn more →
Critical Testing Processes (CTP)
Rex Black's framework of twelve testing processes used to assess and improve a test function, prioritized by business value.
Learn more →
ISTQB
The International Software Testing Qualifications Board, which publishes the syllabi behind the most common testing certifications. In the US, its exams are administered by ASTQB.
Learn more →
TMMi
Test Maturity Model integration: a five-level model for rating how mature an organization's testing is.

Automation

Test automation
Using code to run tests and check results automatically, so they can run quickly and often.
Learn more →
Unit test
An automated test of one small piece of code on its own, usually written by the developer.
Integration testing
Testing how separate parts or systems work together.
Learn more →
Continuous integration (CI)
Automatically building the software and running tests every time someone changes the code.
Flaky test
An automated test that sometimes passes and sometimes fails without any change to the software. Flaky tests erode trust and should be fixed or removed.
Property-based testing
Generating many random inputs automatically and checking that a rule always holds, instead of writing each input by hand.
Learn more →

Security basics

Vulnerability
A weakness in software that an attacker could use to do something they should not be able to do.
Learn more →
Exploit
A method or piece of code that takes advantage of a vulnerability.
Learn more →
Authentication
Proving who you are, for example with a password, a code from an app, or a fingerprint.
Authorization
Deciding what a signed-in person is allowed to see and do.
Learn more →
Multi-factor authentication (MFA)
Signing in with two or more kinds of proof, such as a password plus a code from your phone, so a stolen password alone is not enough.
Learn more →
Encryption
Scrambling data so only someone with the right key can read it, both while it travels and while it is stored.
Phishing
Tricking someone into revealing passwords or other information, usually with a message that pretends to come from someone trusted.
Learn more →
Malware
Software designed to cause harm, such as stealing data, spying, or locking files for ransom.
Patch
An update that fixes a defect or closes a vulnerability. Installing updates promptly is one of the simplest ways to stay safe.
Learn more →
Personal data
Information that identifies a person, such as a name, address, email, or location. Good software collects only what it needs and protects it.
CIA triad
The three goals of security: confidentiality (only the right people see information), integrity (it is accurate and unaltered), and availability (it works when needed).
Learn more →
Threat
Anything that could cause harm to a system or its data, such as a criminal group, a careless mistake, or a power failure.
Learn more →
Defense in depth
Stacking several layers of protection so that when one fails, the next one still stops the attack.
Learn more →
Injection
An attack that slips instructions into input, such as a form field, so the software runs them instead of treating them as data.
Learn more →
Penetration test
An authorized, time-boxed attempt by skilled testers to break into a system the way a real attacker would.
Learn more →
Security testing
Testing designed to find vulnerabilities before attackers do.
Learn more →

AI

Large language model (LLM)
An AI model trained on large amounts of text that can write, summarize, and answer questions.
Learn more →
Token
A piece of a word. AI models read and write text in tokens, and are usually priced per million tokens.
Learn more →
Hallucination
When an AI model states something false as if it were true.
Learn more →
Evaluation set
A collection of real questions with known good answers, used to measure how well an AI system performs and to catch changes.
Learn more →
Context window
The amount of text an AI model can consider at once: your question, any documents, earlier messages, and its own answer so far.
Learn more →
Prompt
The instructions and context you give an AI model. Clear prompts that state the task, audience, and constraints get better results.
Learn more →
Open-weight model
An AI model whose trained parameters are published, so an organization can run it on infrastructure it chooses.
Learn more →
Guardrail
A check that limits what an AI system can say or do, such as blocking certain actions or routing them to a person for approval.
Learn more →
AI agent
An AI system that takes actions, such as booking a meeting or updating a record, not just answering questions.
Learn more →

The web

DNS (Domain Name System)
The internet's address book. It turns a domain name like example.com into the numeric address of the server that hosts it.
Learn more →
HTTPS
The secure way browsers and websites communicate. It encrypts the connection and confirms the site's identity with a certificate.
Learn more →
HTML, CSS, and JavaScript
The three languages of web pages: HTML for structure and content, CSS for presentation and layout, JavaScript for behavior.
Learn more →
Front end and back end
The front end runs in the visitor's browser; the back end runs on servers, handling accounts, orders, business rules, and the database.
Learn more →
Content delivery network (CDN)
A network of servers around the world that keeps copies of a site's files and serves each visitor from the nearest location.
Learn more →
Core Web Vitals
Google's measurements of how fast a page feels: how quickly the main content appears, how quickly it responds to input, and how much it jumps while loading.
Learn more →
Accessibility
Designing so people with disabilities can use a site, including with screen readers, keyboards, and magnification. The standard is WCAG.
Learn more →
SEO (search engine optimization)
Making pages easy for search engines to understand and worth ranking: clear purpose, accurate content, speed, and good structure.
Learn more →
Responsive design
A layout that adapts to each screen size, so a site works as well on a phone as on a desktop.
Learn more →

Business systems

CRM (customer relationship management)
Software that keeps track of customers and prospects and every interaction with them: contacts, deals, activities, and service cases.
Learn more →
ERP (enterprise resource planning)
Software that runs a company's financial and operational core: accounting, orders, inventory, purchasing, and often payroll.
Learn more →
API (application programming interface)
A published set of requests one program accepts from others, and the responses it returns. Most integrations are built on APIs.
Learn more →
Integration
Connecting separate systems so they share information automatically and accurately, instead of people retyping it.
Learn more →
System of record
The one system whose version of a piece of data is authoritative. Other systems receive copies and do not overwrite it.
Learn more →
Data migration
Moving records from an old system to a new one, cleaned and mapped so nothing is lost or corrupted.
Learn more →

Keep reading

Related reading

Practices

Where this leads

Working on something like this?Talk to the people who wrote it.

Book a call