1/74
A set of vocabulary flashcards covering key security governance, legal, risk management, and business continuity concepts from CISSP Domain 1.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Confidentiality
The practice of keeping data and secrets secret by ensuring that no unauthorized individuals can access the information.
Integrity
The protection against unauthorized modifications of data and systems to ensure the information remains unaltered.
Availability
Ensuring that authorized individuals have access to the data and systems they need when they need them.
The CIA Triad
The core security model consisting of Confidentiality, Integrity, and Availability, sometimes referred to as AIC.
Disclosure, Alteration, and Destruction (DAD)
The opposite of the CIA Triad, representing the primary threats to information security.
Identification
The process of a subject claiming an identity, such as providing a username, ID number, or SSN.
Authentication
The process of proving a claimed identity, ideally performed using multi-factor methods.
Type 1 Authentication
Something you know, such as a password, passphrase, or PIN.
Type 2 Authentication
Something you have, such as an ID card, passport, token, or smart card.
Type 3 Authentication
Something you are, which includes biometrics like fingerprints, iris scans, and facial geometry.
Authorization
Determining what an authenticated user is allowed to access within an organization's systems.
Accountability
The ability to trace an action back to a specific subject's identity, often referred to as auditing or non-repudiation.
Least Privilege
A security principle where users or systems are given the minimum necessary access required to perform their tasks.
Need to Know
An access control principle stating that even if a user has permissions, they should only access data required for their specific duties.
Non-repudiation
A condition where a user cannot deny having performed a specific action, achieved through a combination of authentication and integrity.
Subject
An active entity, most often a user or a program, that manipulates an object.
Object
A passive entity, such as data or physical paper, that is manipulated by a subject.
Security Governance
The C-level responsibility of evaluating stakeholder needs, setting direction through prioritization, and monitoring performance against objectives.
Security Management
The process of planning, building, running, and monitoring activities in alignment with the direction set by governance.
Risk Appetite
The high-level category of risk an enterprise is willing to take, defined by governance as aggressive, neutral, or adverse.
Risk Tolerance
The practical application of risk appetite within an environment, managed by the security leadership.
PCI-DSS
A private regulation required for organizations that handle, process, or issue credit and debit cards.
OCTAVE®
Operationally Critical Threat, Asset, and Vulnerability Evaluation, which is a self-directed risk management approach.
COBIT
Control Objectives for Information and related Technology, a framework that maps stakeholder needs to IT-related goals.
ISO 27001
The standard for establishing, implementing, and improving an Information Security Management System (ISMS) using the Plan-Do-Check-Act (PDCA) cycle.
ISO 27799
A standard providing directives on how to protect Protected Health Information (PHI).
Defense in Depth
Also called Layered Defense, it involves implementing multiple overlapping security controls to protect a single asset.
Criminal Law
Legal cases where society is the victim, proof must be beyond a reasonable doubt, and the goal is to punish and deter.
Civil Law (Tort Law)
Legal cases involving individuals or groups as victims, where the majority of proof is required to compensate the victim.
Administrative Law
Regulations enacted by government agencies, such as the FDA, HIPAA, or FAA laws.
Due Diligence
The research and background work performed to build an organization’s IT Security architecture and identify best practices.
Due Care
The "prudent person rule" involving the implementation of security architecture and following security policies to the letter.
Real Evidence
Tangible and physical objects relevant to IT security, such as hard disks or USB drives, excluding the data stored on them.
Direct Evidence
Evidence provided by the testimony of a firsthand witness describing what they experienced with their five senses.
Best Evidence Rule
The judicial preference for evidence that is accurate, complete, relevant, authentic, and convincing.
Chain of Custody
Documentation that proves the integrity of evidence by recording who handled it, when, where, and what was done with it.
Entrapment
The illegal and unethical act of persuading someone to commit a crime they had no prior intention of committing.
Enticement
The legal and ethical practice of making a crime more attractive to someone who has already decided to break the law.
Trademark
Protections for brand names, logos, and slogans; valid for 10 years at a time and renewable indefinitely.
Patent
Legal protection for inventions for a typical duration of 20 years, requiring the invention to be novel, useful, and nonobvious.
Trade Secret
Proprietary information, such as a formula, that is not shared; it is lost if the secret is discovered by others.
Cyber Squatting
The practice of purchasing a URL with the knowledge that someone else will eventually need it.
Typo Squatting
Buying a URL that is very similar to a well-known website name to capture traffic from user errors.
HIPAA
The Health Insurance Portability and Accountability Act, which sets strict rules for handling Protected Health Information (PHI).
Computer Fraud and Abuse Act (CFAA)
Title 18 Section 1030, the primary law used in the United States to prosecute computer-related crimes.
GDPR
A European Union regulation on data protection and privacy, requiring breach notification within 72 hours and granting users the "right to be forgotten."
Wassenaar Arrangement
An international agreement involving 41 countries that regulates the export and import of dual-use goods, including strong cryptography.
Policies
Mandatory, high-level, and non-specific documents that set the direction for security without detailing specific technologies or vendors.
Procedures
Mandatory, low-level, step-by-step guides that are specific to operating systems, encryption types, or vendor technologies.
Administrative Controls
Directive controls such as organizational policies, procedures, regulations, and training/awareness programs.
Technical Controls
Security controls implemented through hardware, software, or firmware, such as firewalls and encryption.
Physical Controls
Security controls designed to protect physical assets, such as locks, fences, guards, and bollards.
Preventative Controls
Controls designed to stop an action from happening, such as drug tests, firewalls, and the principle of least privilege.
Detective Controls
Controls that identify an attack while it is in progress or after it has occurred, such as CCTV and IDS.
Deterrent Controls
Controls meant to discourage potential attackers, such as "Beware of Dog" signs or security guards.
Risk Formula
An equation used to define risk mathematically: Risk=Threat×Vulnerability.
Total Risk
The risk an organization faces before any controls are applied: Total Risk=Threat×Vulnerability×Asset Value.
Residual Risk
The risk remaining after security controls have been implemented: Residual Risk=Total Risk−Countermeasures.
Qualitative Risk Analysis
An assessment based on probability and impact, often using semi-vague descriptors like "High," "Medium," or "Low."
Quantitative Risk Analysis
A fact-based assessment that determines the actual monetary cost of risk using mathematical formulas.
Single Loss Expectancy (SLE)
The monetary loss expected from a single occurrence of a threat: SLE=Asset Value (AV)×Exposure Factor (EF).
Annualized Loss Expectancy (ALE)
The expected annual cost of a risk if no action is taken: ALE=SLE×Annual Rate of Occurrence (ARO).
Return On Investment (ROI)
A financial justification for a control where the Total Cost of Ownership is less than the Annualized Loss Expectancy: TCO<ALE.
Key Risk Indicators (KRIs)
Metrics used by organizations to provide an early warning signal of increasing risk exposure in various areas.
RACI Chart
A matrix used to assign roles during tasks: Responsible, Accountable, Consulted, and Informed.
White Hat Hacker
Professional penetration testers who ethically search for flaws in systems to help fix them.
Black Hat Hacker
Malicious attackers, also known as crackers, who find and exploit vulnerabilities for personal gain.
Spear Phishing
A targeted phishing attack aimed at specific individuals using gathered knowledge about the target to increase success.
Whale Phishing
A spear phishing attack specifically targeted at the senior leadership (C-suite) of an organization.
Business Impact Analysis (BIA)
A process to identify and prioritize critical business systems and activities, assigning values like MTD, RTO, and RPO.
Recovery Point Objective (RPO)
The maximum acceptable amount of data loss for a system, function, or activity, measured in time.
Recovery Time Objective (RTO)
The maximum amount of time allowed to restore the physical hardware of a system after a disruption.
Work Recovery Time (WRT)
The time required to configure a recovered system to its software and production-ready state.
Maximum Tolerable Downtime (MTD)
The total time a system can be inoperable before the organization is severely impacted, calculated as: MTD ≥ RTO+WRT.
Mean Time Between Failures (MTBF)
A metric representing how long a new or repaired system or component will function on average before failing.