1/19
A collection of key terms and definitions covering basic security concepts, incident response teams, control categories, control types, and organizational security roles.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Security operations center (SOC)
The location where security professionals monitor and protect critical information assets in an organization.
Development and operations (DevOps)
A combination of software development and systems operations and refers to the practice of integrating one discipline with the other.
DevSecOps
A combination of software development, security operations, and systems operations and refers to the practice of integrating each discipline with the others.
Computer incident response team (CIRT)/computer security incident response team (CSIRT)/computer emergency response team (CERT)
Team with responsibility for incident response. The CSIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).
Security control
A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.
Managerial
A category of security control that provides oversight of information systems.
Operational
A category of security control that is implemented by people.
Technical
A category of security control that is implemented as a system.
Physical
A category of security control that is implemented by hardware used to deter or detect, such as alarms, gateways, locks, lighting, and security cameras.
Preventive
A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.
Access control lists (ACLs)
The collection of access control entries (ACEs) that determines which subjects (user accounts, host IP addresses, and so on) are allowed or denied access to the object and the privileges given (read-only, read/write, and so on).
Detective
A type of security control that acts during an incident to identify or record that it is happening.
Corrective
A type of security control that acts after an incident to eliminate or minimize its impact.
Directive
A type of control that enforces a rule of behavior through a policy or contract.
Deterrent
A type of security control that discourages intrusion attempts.
Compensating
A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.
Chief Information Officer (CIO)
A company officer with the primary responsibility of managing information technology assets and procedures.
Chief Technology Officer (CTO)
A company officer with the primary role of making effective use of new and emerging computing platforms and innovations.
Chief Security Officer (CSO)
Typically, the job title of the person with overall responsibility for information assurance and systems security.
Information Systems Security Officer (ISSO)
Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.