1/45
Vocabulary flashcards covering core protocols, security models, ISO/IEC 27001 components, and cybersecurity frameworks.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
ARP
Maps a local IPv4 address to a MAC address.
ARP poisoning
Forged ARP information that redirects local traffic.
DAI
Dynamic ARP Inspection validates ARP messages against trusted binding information.
IP
Internet Protocol addresses and routes packets across networks.
ICMP
Carries network control and diagnostic messages.
NAT
Translates addresses between networks.
IPsec
A suite protecting traffic at the IP layer.
ESP
IPsec protocol 50, commonly providing encryption plus integrity/authentication.
AH
IPsec protocol 51, providing integrity/authentication without payload encryption.
TCP
Connection-oriented transport with ordered, reliable delivery.
UDP
Connectionless transport with low overhead and no delivery guarantee.
Port
A number identifying a service endpoint on a host.
DNSSEC
Authenticates DNS data using signatures; it does not encrypt DNS queries.
NIST CSF
NIST CSF 2.0 organizes cybersecurity outcomes into Govern, Identify, Protect, Detect, Respond, and Recover.
Cyber Killchain
A staged model of attack progression from reconnaissance through actions on objectives.
MITRE ATT&CK
A knowledge base of adversary tactics and techniques.
ISO/IEC 27001:2022
Requirements for establishing, implementing, maintaining, and continually improving an information security management system (ISMS).
ISMS scope
The boundaries and applicability of the management system, set with the organization's context, interested parties, and interfaces in mind.
Statement of Applicability (SoA)
A record of necessary controls, why they are included, whether they are implemented, and why any Annex A controls are excluded.
Annex A
The 2022 standard's reference set of 93 possible controls in organizational, people, physical, and technological groups.
Risk owner
The person or role assigned responsibility for a specific information security risk.
Residual risk
The risk that remains after the selected treatment and controls.
COBIT
ISACA's framework for governing and managing enterprise information and technology.
CIS Controls
A prioritized set of cybersecurity safeguards focused on practical defensive actions.
Regulatory obligation
A binding legal or regulatory requirement that applies because of jurisdiction, industry, data, or organizational status.