Glossary55 termsPlain English
The words testers use,in plain English.
Short, plain definitions of the terms you will meet in software testing, quality, security, and AI. Each one links to a piece that explains it in depth.
Testing basics
- Software testing
- Checking software in a planned way to find problems before the people who rely on it do, and to measure how ready it is to release.
- Learn more →
- Quality
- How well software does what its users need: working correctly, staying fast, keeping data safe, and being easy to use.
- Learn more →
- Test case
- A written description of one test: the starting conditions, the steps, the data to use, and the result you expect.
- Learn more →
- Expected result
- What should happen if the software works correctly. Written before the test is run, so the actual result can be judged fairly.
- Actual result
- What really happened when the test was run. A difference from the expected result is worth investigating.
- Test plan
- A document describing what will be tested, how, by whom, and what has to be true before the software can be released.
- Learn more →
- Requirement
- A statement of what the software must do or how well it must do it. Unclear requirements are a common source of defects.
- Regression testing
- Rerunning tests after a change to make sure things that used to work still work.
- Exploratory testing
- Learning about the software, designing tests, and running them at the same time, guided by what the tester discovers along the way.
Bugs and defects
- Defect (bug)
- A flaw in code, a design, or a document that can make the software behave wrongly. Also called a bug or a fault.
- Learn more →
- Failure
- The software visibly doing the wrong thing when it runs, such as crashing or showing a wrong total.
- Learn more →
- Root cause
- The underlying reason a defect was created. Fixing the root cause prevents similar defects in the future.
- Priority
- How soon a defect should be fixed, based on business needs as well as impact.
- Bug report
- A written description of a problem with the summary, steps to reproduce, expected and actual results, and evidence a developer needs to fix it.
- Learn more →
- Reproduce
- Make a problem happen again on purpose, by repeating the exact steps and conditions.
- False positive
- A test reports a problem that is not really a defect in the software, for example because the test itself was wrong.
- False negative
- A real defect that the tests fail to catch.
Test design
- Equivalence partitioning
- Grouping inputs the software should treat the same way, then testing one value from each group.
- Learn more →
- Boundary value analysis
- Testing values at and right next to the edges of each group, where off-by-one defects tend to hide.
- Learn more →
- Test data
- The values, records, and files a test uses. Realistic, well-chosen data finds more problems.
- Learn more →
- Coverage
- How much of something your tests exercise: requirements, risks, code, or configurations.
- Learn more →
- Functional testing
- Checking that the software does the right things: correct results, the right features, and working connections to other systems.
- Learn more →
- Non-functional testing
- Checking how well the software works rather than what it does: speed, security, usability, accessibility, and reliability.
Process and management
- Quality risk
- Something that could go wrong with the software, rated by how likely it is and how much harm it would do.
- Learn more →
- Risk-based testing
- Spending testing effort in proportion to risk, so the areas where failure would cost most get the most attention.
- Learn more →
- Exit criteria
- The conditions agreed in advance that must be met before testing can end and the software can be released.
- Test metrics
- Measurements, such as defects found or tests passed, used to understand progress and quality.
- Learn more →
- Critical Testing Processes (CTP)
- Rex Black's framework of twelve testing processes used to assess and improve a test function, prioritized by business value.
- Learn more →
- ISTQB
- The International Software Testing Qualifications Board, which publishes the syllabi behind the most common testing certifications. In the US, its exams are administered by ASTQB.
- Learn more →
- TMMi
- Test Maturity Model integration: a five-level model for rating how mature an organization's testing is.
Automation
- Test automation
- Using code to run tests and check results automatically, so they can run quickly and often.
- Learn more →
- Unit test
- An automated test of one small piece of code on its own, usually written by the developer.
- Continuous integration (CI)
- Automatically building the software and running tests every time someone changes the code.
- Flaky test
- An automated test that sometimes passes and sometimes fails without any change to the software. Flaky tests erode trust and should be fixed or removed.
- Property-based testing
- Generating many random inputs automatically and checking that a rule always holds, instead of writing each input by hand.
- Learn more →
Security basics
- Vulnerability
- A weakness in software that an attacker could use to do something they should not be able to do.
- Learn more →
- Exploit
- A method or piece of code that takes advantage of a vulnerability.
- Authentication
- Proving who you are, for example with a password, a code from an app, or a fingerprint.
- Multi-factor authentication (MFA)
- Signing in with two or more kinds of proof, such as a password plus a code from your phone, so a stolen password alone is not enough.
- Encryption
- Scrambling data so only someone with the right key can read it, both while it travels and while it is stored.
- Phishing
- Tricking someone into revealing passwords or other information, usually with a message that pretends to come from someone trusted.
- Malware
- Software designed to cause harm, such as stealing data, spying, or locking files for ransom.
- Patch
- An update that fixes a defect or closes a vulnerability. Installing updates promptly is one of the simplest ways to stay safe.
- Personal data
- Information that identifies a person, such as a name, address, email, or location. Good software collects only what it needs and protects it.
AI
- Large language model (LLM)
- An AI model trained on large amounts of text that can write, summarize, and answer questions.
- Token
- A piece of a word. AI models read and write text in tokens, and are usually priced per million tokens.
- Learn more →
- Hallucination
- When an AI model states something false as if it were true.
- Evaluation set
- A collection of real questions with known good answers, used to measure how well an AI system performs and to catch changes.
- Learn more →
- AI agent
- An AI system that takes actions, such as booking a meeting or updating a record, not just answering questions.
Keep reading
Related reading
- Primer
Careers in Software Quality: Roles, Skills, and First Steps
What testers, test automation engineers, quality engineers, and test managers actually do, the skills each role uses, and practical first steps for students and career changers, including the ISTQB Foundation certification.
Read → - Primer
Errors, Defects, and Failures: What a Bug Really Is
Everyone says 'bug', but testers use three precise words: error, defect, and failure. Learn the difference, why it matters, and how severity and priority decide which problems get fixed first.
Read → - Primer
How to Report a Bug So It Actually Gets Fixed
Finding a bug is half the job. Learn how to write a bug report a developer can act on: a clear summary, exact steps to reproduce, expected versus actual results, and the habits professional testers use to make every report count.
Read → - Primer
What Is Software Testing? A Plain-English Introduction
Software testing explained from the beginning: why every program has mistakes in it, what testers actually do all day, and the handful of ideas the whole profession is built on. No experience needed.
Read → - Primer
Your First Test Cases: Designing Tests That Find Problems
A hands-on introduction to test design. Learn what goes into a test case, then use two classic techniques, equivalence partitioning and boundary value analysis, to test a sign-up form the way professionals do.
Read → - Whitepaper
Beyond ISTQB: A Multi-Domain Certification Roadmap for Technical L&D
Most engineering L&D programs over-index on a single certification family, usually ISTQB on the QA side, AWS on the infrastructure side, and under-invest across the rest of the technical domains the org actually needs. This paper covers a multi-domain certification roadmap (QA, AI, cloud, data, security, project management, software engineering) with sequencing logic for each level of the engineering ladder, plus the maintenance discipline that keeps the roadmap relevant as the technology shifts underneath it.
Read →
Practices
Where this leads
- TrainingQA and AI training
ISTQB certification and hands-on courses for testers, engineers, and leaders, from one of the first ASTQB-accredited training providers in the United States.
Book a call → - QA & testingSoftware testing
Software quality consulting since 1994: we test the releases that matter, coach your team on the method, and measure how its testing matures.
Book a call →