| Explicit deny | A deny that overrides applicable allows |
| Federation | Using an external identity system for AWS sessions |
| Permission boundary | Maximum permission limit for an IAM user or role |
| SCP | Organization guardrail limiting available permissions |
| Session policy | Policy further limiting one assumed-role session |
| Trust policy | Resource policy defining who may assume a role |
| ABAC | Access control using attributes or tags |
| Envelope encryption | Encrypting data with a data key protected by a KMS key |
| Finding | Security observation from a detection or posture service |
| Delegated administrator | Member account authorized to administer an AWS service for the organization |
| Conformance pack | Collection of Config rules and remediation definitions |
| Residual risk | Risk remaining after controls are applied |