CISSP Domain 1 Review

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/74

flashcard set

Earn XP

Description and Tags

A set of vocabulary flashcards covering key security governance, legal, risk management, and business continuity concepts from CISSP Domain 1.

Last updated 1:28 AM on 7/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

75 Terms

1
New cards

Confidentiality

The practice of keeping data and secrets secret by ensuring that no unauthorized individuals can access the information.

2
New cards

Integrity

The protection against unauthorized modifications of data and systems to ensure the information remains unaltered.

3
New cards

Availability

Ensuring that authorized individuals have access to the data and systems they need when they need them.

4
New cards

The CIA Triad

The core security model consisting of Confidentiality, Integrity, and Availability, sometimes referred to as AIC.

5
New cards

Disclosure, Alteration, and Destruction (DAD)

The opposite of the CIA Triad, representing the primary threats to information security.

6
New cards

Identification

The process of a subject claiming an identity, such as providing a username, ID number, or SSN.

7
New cards

Authentication

The process of proving a claimed identity, ideally performed using multi-factor methods.

8
New cards

Type 1 Authentication

Something you know, such as a password, passphrase, or PIN.

9
New cards

Type 2 Authentication

Something you have, such as an ID card, passport, token, or smart card.

10
New cards

Type 3 Authentication

Something you are, which includes biometrics like fingerprints, iris scans, and facial geometry.

11
New cards

Authorization

Determining what an authenticated user is allowed to access within an organization's systems.

12
New cards

Accountability

The ability to trace an action back to a specific subject's identity, often referred to as auditing or non-repudiation.

13
New cards

Least Privilege

A security principle where users or systems are given the minimum necessary access required to perform their tasks.

14
New cards

Need to Know

An access control principle stating that even if a user has permissions, they should only access data required for their specific duties.

15
New cards

Non-repudiation

A condition where a user cannot deny having performed a specific action, achieved through a combination of authentication and integrity.

16
New cards

Subject

An active entity, most often a user or a program, that manipulates an object.

17
New cards

Object

A passive entity, such as data or physical paper, that is manipulated by a subject.

18
New cards

Security Governance

The C-level responsibility of evaluating stakeholder needs, setting direction through prioritization, and monitoring performance against objectives.

19
New cards

Security Management

The process of planning, building, running, and monitoring activities in alignment with the direction set by governance.

20
New cards

Risk Appetite

The high-level category of risk an enterprise is willing to take, defined by governance as aggressive, neutral, or adverse.

21
New cards

Risk Tolerance

The practical application of risk appetite within an environment, managed by the security leadership.

22
New cards

PCI-DSS

A private regulation required for organizations that handle, process, or issue credit and debit cards.

23
New cards

OCTAVE®

Operationally Critical Threat, Asset, and Vulnerability Evaluation, which is a self-directed risk management approach.

24
New cards

COBIT

Control Objectives for Information and related Technology, a framework that maps stakeholder needs to IT-related goals.

25
New cards

ISO 27001

The standard for establishing, implementing, and improving an Information Security Management System (ISMS) using the Plan-Do-Check-Act (PDCA) cycle.

26
New cards

ISO 27799

A standard providing directives on how to protect Protected Health Information (PHI).

27
New cards

Defense in Depth

Also called Layered Defense, it involves implementing multiple overlapping security controls to protect a single asset.

28
New cards

Criminal Law

Legal cases where society is the victim, proof must be beyond a reasonable doubt, and the goal is to punish and deter.

29
New cards

Civil Law (Tort Law)

Legal cases involving individuals or groups as victims, where the majority of proof is required to compensate the victim.

30
New cards

Administrative Law

Regulations enacted by government agencies, such as the FDA, HIPAA, or FAA laws.

31
New cards

Due Diligence

The research and background work performed to build an organization’s IT Security architecture and identify best practices.

32
New cards

Due Care

The "prudent person rule" involving the implementation of security architecture and following security policies to the letter.

33
New cards

Real Evidence

Tangible and physical objects relevant to IT security, such as hard disks or USB drives, excluding the data stored on them.

34
New cards

Direct Evidence

Evidence provided by the testimony of a firsthand witness describing what they experienced with their five senses.

35
New cards

Best Evidence Rule

The judicial preference for evidence that is accurate, complete, relevant, authentic, and convincing.

36
New cards

Chain of Custody

Documentation that proves the integrity of evidence by recording who handled it, when, where, and what was done with it.

37
New cards

Entrapment

The illegal and unethical act of persuading someone to commit a crime they had no prior intention of committing.

38
New cards

Enticement

The legal and ethical practice of making a crime more attractive to someone who has already decided to break the law.

39
New cards

Trademark

Protections for brand names, logos, and slogans; valid for 10 years at a time and renewable indefinitely.

40
New cards

Patent

Legal protection for inventions for a typical duration of 20 years, requiring the invention to be novel, useful, and nonobvious.

41
New cards

Trade Secret

Proprietary information, such as a formula, that is not shared; it is lost if the secret is discovered by others.

42
New cards

Cyber Squatting

The practice of purchasing a URL with the knowledge that someone else will eventually need it.

43
New cards

Typo Squatting

Buying a URL that is very similar to a well-known website name to capture traffic from user errors.

44
New cards

HIPAA

The Health Insurance Portability and Accountability Act, which sets strict rules for handling Protected Health Information (PHI).

45
New cards

Computer Fraud and Abuse Act (CFAA)

Title 18 Section 1030, the primary law used in the United States to prosecute computer-related crimes.

46
New cards

GDPR

A European Union regulation on data protection and privacy, requiring breach notification within 72 hours and granting users the "right to be forgotten."

47
New cards

Wassenaar Arrangement

An international agreement involving 41 countries that regulates the export and import of dual-use goods, including strong cryptography.

48
New cards

Policies

Mandatory, high-level, and non-specific documents that set the direction for security without detailing specific technologies or vendors.

49
New cards

Procedures

Mandatory, low-level, step-by-step guides that are specific to operating systems, encryption types, or vendor technologies.

50
New cards

Administrative Controls

Directive controls such as organizational policies, procedures, regulations, and training/awareness programs.

51
New cards

Technical Controls

Security controls implemented through hardware, software, or firmware, such as firewalls and encryption.

52
New cards

Physical Controls

Security controls designed to protect physical assets, such as locks, fences, guards, and bollards.

53
New cards

Preventative Controls

Controls designed to stop an action from happening, such as drug tests, firewalls, and the principle of least privilege.

54
New cards

Detective Controls

Controls that identify an attack while it is in progress or after it has occurred, such as CCTV and IDS.

55
New cards

Deterrent Controls

Controls meant to discourage potential attackers, such as "Beware of Dog" signs or security guards.

56
New cards

Risk Formula

An equation used to define risk mathematically: Risk=Threat×Vulnerability\text{Risk} = \text{Threat} \times \text{Vulnerability}.

57
New cards

Total Risk

The risk an organization faces before any controls are applied: Total Risk=Threat×Vulnerability×Asset Value\text{Total Risk} = \text{Threat} \times \text{Vulnerability} \times \text{Asset Value}.

58
New cards

Residual Risk

The risk remaining after security controls have been implemented: Residual Risk=Total RiskCountermeasures\text{Residual Risk} = \text{Total Risk} - \text{Countermeasures}.

59
New cards

Qualitative Risk Analysis

An assessment based on probability and impact, often using semi-vague descriptors like "High," "Medium," or "Low."

60
New cards

Quantitative Risk Analysis

A fact-based assessment that determines the actual monetary cost of risk using mathematical formulas.

61
New cards

Single Loss Expectancy (SLE)

The monetary loss expected from a single occurrence of a threat: SLE=Asset Value (AV)×Exposure Factor (EF)\text{SLE} = \text{Asset Value (AV)} \times \text{Exposure Factor (EF)}.

62
New cards

Annualized Loss Expectancy (ALE)

The expected annual cost of a risk if no action is taken: ALE=SLE×Annual Rate of Occurrence (ARO)\text{ALE} = \text{SLE} \times \text{Annual Rate of Occurrence (ARO)}.

63
New cards

Return On Investment (ROI)

A financial justification for a control where the Total Cost of Ownership is less than the Annualized Loss Expectancy: TCO<ALE\text{TCO} < \text{ALE}.

64
New cards

Key Risk Indicators (KRIs)

Metrics used by organizations to provide an early warning signal of increasing risk exposure in various areas.

65
New cards

RACI Chart

A matrix used to assign roles during tasks: Responsible, Accountable, Consulted, and Informed.

66
New cards

White Hat Hacker

Professional penetration testers who ethically search for flaws in systems to help fix them.

67
New cards

Black Hat Hacker

Malicious attackers, also known as crackers, who find and exploit vulnerabilities for personal gain.

68
New cards

Spear Phishing

A targeted phishing attack aimed at specific individuals using gathered knowledge about the target to increase success.

69
New cards

Whale Phishing

A spear phishing attack specifically targeted at the senior leadership (C-suite) of an organization.

70
New cards

Business Impact Analysis (BIA)

A process to identify and prioritize critical business systems and activities, assigning values like MTD, RTO, and RPO.

71
New cards

Recovery Point Objective (RPO)

The maximum acceptable amount of data loss for a system, function, or activity, measured in time.

72
New cards

Recovery Time Objective (RTO)

The maximum amount of time allowed to restore the physical hardware of a system after a disruption.

73
New cards

Work Recovery Time (WRT)

The time required to configure a recovered system to its software and production-ready state.

74
New cards

Maximum Tolerable Downtime (MTD)

The total time a system can be inoperable before the organization is severely impacted, calculated as: MTD ≥ RTO+WRT\text{MTD} \text{ ≥ } \text{RTO} + \text{WRT}.

75
New cards

Mean Time Between Failures (MTBF)

A metric representing how long a new or repaired system or component will function on average before failing.