1/558
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Control Category - Technical
Security controls implemented using automated systems, software, or hardware mechanisms (e.g., operating system controls, firewalls, anti-virus).
Control Category - Managerial
Administrative security controls focused on the design, strategic management, and implementation of security (e.g., security policies, standard operating procedures).
Control Category - Operational
Security controls executed and maintained by people rather than automated systems (e.g., security guards, awareness training programs).
Control Category - Physical
Controls that physically limit real-world access to facilities, buildings, and tangible assets (e.g., fences, locks, badge readers, guard shacks).
Control Type - Preventive
Controls that actively block, restrict, or stop unauthorized access or security events before they can occur (e.g., firewall rules, door locks).
Control Type - Deterrent
Controls that discourage or psychologically dissuade an attacker from attempting an intrusion without directly blocking access (e.g., splash screens, warning signs, front desks).
Control Type - Detective
Controls designed to identify, record, and log security events or intrusion attempts as they occur or after the fact (e.g., reviewing system logs, motion detectors).
Control Type - Corrective
Controls applied after an event is detected to mitigate impact, reverse damage, and restore systems to operational status (e.g., restoring backups, fire extinguishers).
Control Type - Compensating
Alternative controls used when primary safeguards are unavailable or insufficient to minimize weakness exploitation (e.g., separation of duties, temporary firewall blocks, backup generators).
Control Type - Directive
Administrative safeguards that guide, direct, or instruct subjects toward security compliance (e.g., compliance procedures, training, "Authorized Personnel Only" signs).
CIA Triad - Confidentiality
Preventing the unauthorized disclosure of information through controls like encryption, access permissions, and multi-factor authentication.
CIA Triad - Integrity
Ensuring data is stored and transferred without undetected modification using mechanisms like hashing, digital signatures, and certificates.
CIA Triad - Availability
Ensuring systems and networks remain operational and accessible to authorized users via redundancy, fault tolerance, and patching.
Non-Repudiation
A cryptographic guarantee that a person cannot deny the authenticity or origin of a signed message or transaction.
AAA Framework - Identification
The initial claim of an identity made by an entity, typically established using a username.
AAA Framework - Authentication
The process of proving a claimed identity using credentials such as passwords, tokens, or biometrics.
AAA Framework - Authorization
Determining and granting specific rights and resource access based on a proven identity.
AAA Framework - Accounting
Tracking and recording resource utilization, including logon times, transferred data volume, and logoff events.
Authenticating Systems
Authenticating unattended machines or network devices using digitally signed certificates issued by a trusted Certificate Authority (CA).
Authorization Models
Adding an abstraction layer (such as roles or attributes) between users and resources to streamline administration and scale access control.
Gap Analysis
An extensive comparison evaluating an organization's current security posture against a defined baseline standard or framework (e.g., NIST, ISO).
Zero Trust Architecture
A holistic security strategy where no user, device, or process is implicitly trusted, requiring continuous verification for every connection.
Zero Trust - Control Plane
The functional plane that defines policies, evaluates security rules, and governs the operational decisions of the data plane.
Control Plane - Adaptive Identity
Evaluating contextual risk indicators (e.g., geographic location, connection method, IP address) to dynamically adjust authentication strength.
Control Plane - Threat Scope Reduction
Minimizing the total number of potential entry and exploitation points across the enterprise environment.
Control Plane - Policy-Driven Access Control
Combining contextual identity attributes with a strict, predefined set of rules to determine resource access.
Control Plane - Policy Engine (PE)
The core component of the Policy Decision Point that evaluates access requests against security policies to grant, deny, or revoke access.
Control Plane - Policy Administrator (PA)
The control component that communicates with the Policy Enforcement Point to issue or revoke credentials and session access tokens.
Zero Trust - Data Plane
The operational plane that processes, encrypts, forwards, and handles the actual network frames, packets, and resource traffic.
Data Plane - Implicit Trust Zones
Network segments or zones where traffic is traditionally allowed without granular per-request verification, which Zero Trust seeks to eliminate.
Data Plane - Subject / System
The user, application, or non-human automated system requesting entry to access an enterprise resource.
Data Plane - Policy Enforcement Point (PEP)
The inline gatekeeper component that allows, monitors, and terminates network connections based on commands from the Policy Administrator.
Physical Security - Bollards / Barricades
Physical barriers used to channel pedestrian traffic safely and block vehicle ramming attempts.
Physical Security - Access Control Vestibule
A multi-door physical security portal where opening one door enforces the locking of the other to prevent unauthorized piggybacking.
Physical Security - Fencing
A physical boundary perimeter (transparent or opaque) often topped with razor wire to deter and prevent climbing.
Physical Security - Video Surveillance (CCTV)
Networked cameras providing real-time property monitoring, motion recognition alerts, and recorded evidence.
Physical Security - Guards and Access Badges
Security personnel stationed at reception areas to verify employee access badges and enforce two-person integrity.
Physical Security - Lighting
Positioned lighting fixtures designed to eliminate shadows, enhance camera and facial recognition, and discourage intruders.
Physical Sensors - Infrared
Sensors detecting thermal infrared radiation in daylight or complete darkness, commonly utilized in motion detectors.
Physical Sensors - Pressure
Sensors configured to identify changes in applied physical force on floors, mats, or window panes.
Physical Sensors - Microwave
Active sensors transmitting microwave pulses across broad areas to detect perimeter movement.
Physical Sensors - Ultrasonic
Sensors emitting high-frequency sound waves that analyze reflected sound waves to track room motion and proximity.
Deception Technology - Honeypots & Honeynets
Honeypots are decoy virtual systems built to lure and study attackers; honeynets are interconnected networks of multiple honeypots.
Deception Technology - Honeyfiles & Honeytokens
Honeyfiles are lure files (e.g., passwords.txt) alerting on access; honeytokens are fake API keys or email addresses used to trace stolen data.
Change Management - Approval Process
A formal process for managing change that includes request forms, scope definition, scheduling, impact and risk analysis, Change Control Board approval, and end-user acceptance.
Change Management - Ownership
The individual or entity who requests and manages the change process to ensure procedures are properly followed without necessarily performing the technical work.
Change Management - Stakeholders
Individuals or departments across the organization who are impacted by a system change and require input or visibility into the process.
Change Management - Impact Analysis
Evaluating the risk value (high, medium, low) of a proposed change, potential cascading system failures, and the operational risk of not making the change.
Change Management - Test Results
Validating software upgrades or patches in an isolated sandbox testing environment prior to production deployment to confirm stability and verify backout plans.
Change Management - Backout Plan
A documented, pre-tested procedure and reliable backup set used to revert systems to their original operational state if a change fails.
Change Management - Maintenance Window
A scheduled timeframe (typically overnights or non-peak production hours) designated for executing changes to minimize operational disruption.
Change Management - Standard Operating Procedure (SOP)
Well-documented, formal procedures hosted on an organization's intranet that establish the living baseline for executing enterprise changes.
Technical Implications - Allow List / Deny List
Security controls restricting application execution, where allow lists block everything unless explicitly approved and deny lists block known malicious software.
Technical Implications - Restricted Activities
Strictly defined boundaries of an approved change order ensuring technicians do not execute modifications outside the authorized scope without further review.
Technical Implications - Downtime
Planned periods of service unavailability scheduled during maintenance windows, often minimized via automation and secondary failover systems.
Technical Implications - Service Restart
Stopping and restarting a background daemon or operating system service to apply new configuration settings without a full system reboot.
Technical Implications - Application Restart
Completely closing and re-launching an application instance to enforce software modifications and load new settings.
Technical Implications - Legacy Applications
Older, mission-critical software that is no longer supported by the original developer, requiring custom internal documentation, quirks management, and operational workarounds.
Technical Implications - Dependencies
Interconnected technical relationships where one component or service requires another specific library, service, or firmware version to function before updates can occur.
Documentation - Updating Diagrams
Modifying network and system topology diagrams following a change to maintain accurate physical and logical address and connectivity maps.
Documentation - Updating Policies and Procedures
Revising internal standard operating procedures and security baselines to reflect newly added infrastructure and altered system workflows.
Version Control
Tracking configuration and file modifications over time (e.g., router configs, OS patches, registry files) to facilitate auditability and rapid rollbacks.
Public Key Infrastructure (PKI)
The comprehensive framework of policies, procedures, hardware, software, and people used to create, distribute, manage, store, and revoke digital certificates.
PKI - Public Key
An asymmetric cryptographic key that is freely distributed to anyone, used to encrypt data or verify a digital signature.
PKI - Private Key
The confidential, mathematically paired asymmetric key kept strictly secret by the owner, used to decrypt data or generate digital signatures.
PKI - Key Escrow
An arrangement where cryptographic decryption keys are held and secured by an authorized third party for recovery or legal access.
Encryption Level - Full-Disk
Encrypting an entire physical storage drive (e.g., BitLocker, FileVault) to protect all system files and data at rest.
Encryption Level - Partition / Volume
Encrypting a specific dedicated logical drive sector, volume, or partition rather than the entire physical disk.
Encryption Level - File
Encrypting individual files on a filesystem (such as Windows Encrypting File System - EFS) to restrict access per user.
Encryption Level - Database (Transparent)
Encrypting all tables and database information on disk using a centralized symmetric key.
Encryption Level - Database (Record-Level)
Encrypting specific individual columns or fields within a database using distinct symmetric keys to isolate sensitive records.
Encryption - Transport / Communication
Protecting data actively moving across a network using encrypted channels such as HTTPS, SSL/TLS, and IPsec VPN tunnels.
Encryption - Asymmetric Cryptography
A cryptographic model utilizing mathematically related public and private key pairs for encryption and digital signatures.
Encryption - Symmetric Cryptography
A fast cryptographic scheme that uses a single, shared secret key to both encrypt and decrypt data.
Key Exchange
The process of sharing an encryption key across an insecure medium, either out-of-band (telephone, courier) or in-band using asymmetric encryption.
Cryptographic Algorithms
The mathematical formulas and ciphers agreed upon by communicating endpoints to perform encryption and decryption operations.
Cryptographic Key Length
The size of a cryptographic key measured in bits, where larger keys exponentially increase mathematical resistance against brute-force attacks.
Key Stretching
Strengthening a weak key or password by repeatedly hashing the hash through thousands of iterations to slow down brute-force attacks.
Cryptographic Tools - TPM
Trusted Platform Module; a dedicated cryptographic hardware processor on a device motherboard that provides burned-in keys and secures BitLocker.
Cryptographic Tools - HSM
Hardware Security Module; a high-end, clustered hardware appliance designed to securely store and accelerate thousands of enterprise keys.
Cryptographic Tools - Key Management System
A centralized software console used to generate, store, rotate, map, and log encryption keys separately from the protected data.
Cryptographic Tools - Secure Enclave
An isolated hardware coprocessor running its own boot ROM, memory encryption, and true random number generation to protect device secrets.
Obfuscation
The process of making data, code, or payment details confusing and difficult to understand while leaving it technically readable and functional.
Obfuscation - Steganography
The technique of concealing a secret message or payload inside another non-suspicious carrier container (e.g., within image, audio, or video files).
Obfuscation - Tokenization
Replacing sensitive data (e.g., credit card numbers) with a non-sensitive placeholder token that maps back to raw values via a secure token server.
Obfuscation - Data Masking
Hiding portions of sensitive data or PII from view on display interfaces while leaving the raw data intact in storage.
Hashing
A one-way mathematical function that converts arbitrary data into a fixed-length string or fingerprint to verify data integrity.
Hash Collision
A cryptographic anomaly where two completely different plaintext inputs generate the exact same hash digest.
Salting
Adding random data to a password before hashing to ensure identical passwords generate unique hashes and defeat rainbow tables.
Digital Signatures
A cryptographic scheme where a sender hashes plaintext and encrypts the hash with their private key to provide authenticity, integrity, and non-repudiation.
Blockchain
A decentralized, distributed digital ledger that records, verifies, and cryptographically chains transaction blocks across peer nodes.
Blockchain - Open Public Ledger
A transparent, distributed ledger maintained across all network computers where transactions are replicated and visible to everyone.
Digital Certificates
An X.509 formatted credential that cryptographically binds an applicant's public key with a digital signature from a Certificate Authority.
Root of Trust
An inherently trusted foundational component (such as an HSM, Secure Enclave, or root CA) upon which subsequent system trust is established.
Certificate Authority (CA)
A trusted third party or internal server responsible for vetting applicants, issuing certificates, and digitally signing them with its private key.
Third-Party Certificate Authority
A commercial CA whose root certificates are pre-installed and inherently trusted across standard web browsers.
Self-Signed Certificates
Certificates generated and signed internally by an organization's private CA without paying for a commercial third-party signature.
Certificate Signing Request (CSR)
A formal request containing an applicant's public key and identity data submitted to a CA to obtain a digitally signed certificate.
Wildcard Certificates
A certificate that uses a wildcard notation (e.g., *.domain.com) to provide SSL/TLS protection for all first-level subdomains under a domain.
Certificate Revocation - CRL vs. OCSP
A Certificate Revocation List (CRL) is a downloaded file of revoked certs; OCSP queries an online responder via HTTP for real-time status.