Course 2 Glossary Cybersecurity Terms

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/48

flashcard set

Earn XP

Description and Tags

Vocabulary flashcards covering key cybersecurity terms and definitions from Course 2.

Last updated 3:47 AM on 9/14/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

49 Terms

1
New cards

Assess

The fifth step of the NIST RMF that means to determine if established controls are implemented correctly

2
New cards

Asset

An item perceived as having value to an organization

3
New cards

Attack vectors

The pathways attackers use to penetrate security defenses

4
New cards

Authentication

The process of verifying who someone is

5
New cards

Authorization

The concept of granting access to specific resources in a system

6
New cards

Authorize

The sixth step of the NIST RMF that refers to being accountable for the security and privacy risks that might exist in an organization

7
New cards

Availability

The idea that data is accessible to those who are authorized to access it

8
New cards

Biometrics

The unique physical characteristics that can be used to verify a person’s identity

9
New cards

Business continuity

An organization's ability to maintain their everyday productivity by establishing risk disaster recovery plans

10
New cards

Categorize

The second step of the NIST RMF that is used to develop risk management processes and tasks

11
New cards

Chronicle

A cloud-native tool designed to retain, analyze, and search data

12
New cards

Confidentiality

The idea that only authorized users can access specific assets or data

13
New cards

Confidentiality, integrity, availability (CIA) triad

A model that helps inform how organizations consider risk when setting up systems and security policies

14
New cards

Detect

A NIST core function related to identifying potential security incidents and improving monitoring capabilities to increase the speed and efficiency of detections

15
New cards

Encryption

The process of converting data from a readable format to an encoded format

16
New cards

External threat

Anything outside the organization that has the potential to harm organizational assets

17
New cards

Identify

A NIST core function related to management of cybersecurity risk and its effect on an organization’s people and assets

18
New cards

Implement

The fourth step of the NIST RMF that means to implement security and privacy plans for an organization

19
New cards

Incident response

An organization’s quick attempt to identify an attack, contain the damage, and correct the effects of a security breach

20
New cards

Integrity

The idea that the data is correct, authentic, and reliable

21
New cards

Internal threat

A current or former employee, external vendor, or trusted partner who poses a security risk

22
New cards

Log

A record of events that occur within an organization’s systems

23
New cards

Metrics

Key technical attributes such as response time, availability, and failure rate, which are used to assess the performance of a software application

24
New cards

Monitor

The seventh step of the NIST RMF that means be aware of how systems are operating

25
New cards

National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)

A voluntary framework that consists of standards, guidelines, and best practices to manage cybersecurity risk

26
New cards

National Institute of Standards and Technology (NIST) Special Publication (S.P.) 800-53

A unified framework for protecting the security of information systems within the U.S. federal government

27
New cards

Open Web Application Security Project/Open Worldwide Application Security Project (OWASP)

A non-profit organization focused on improving software security

28
New cards

Operating system (OS)

The interface between computer hardware and the user

29
New cards

Playbook

A manual that provides details about any operational action

30
New cards

Prepare

The first step of the NIST RMF related to activities that are necessary to manage security and privacy risks before a breach occurs

31
New cards

Protect

A NIST core function used to protect an organization through the implementation of policies, procedures, training, and tools that help mitigate cybersecurity threats

32
New cards

Ransomware

A malicious attack where threat actors encrypt an organization’s data and demand payment to restore access

33
New cards

Recover

A NIST core function related to returning affected systems back to normal operation

34
New cards

Respond

A NIST core function related to making sure that the proper procedures are used to contain, neutralize, and analyze security incidents, and implement improvements to the security process

35
New cards

Risk

Anything that can impact the confidentiality, integrity, or availability of an asset

36
New cards

Risk mitigation

The process of having the right procedures and rules in place to quickly reduce the impact of a risk like a breach

37
New cards

Security audit

A review of an organization's security controls, policies, and procedures against a set of expectations

38
New cards

Security controls

Safeguards designed to reduce specific security risks

39
New cards

Security frameworks

Guidelines used for building plans to help mitigate risk and threats to data and privacy

40
New cards

Security information and event management (SIEM)

An application that collects and analyzes log data to monitor critical activities in an organization

41
New cards

Security orchestration, automation, and response (SOAR)

A collection of applications, tools, and workflows that use automation to respond to security events

42
New cards

Security posture

An organization’s ability to manage its defense of critical assets and data and react to change

43
New cards

Select

The third step of the NIST RMF that means to choose, customize, and capture documentation of the controls that protect an organization

44
New cards

Shared responsibility

The idea that all individuals within an organization take an active role in lowering risk and maintaining both physical and virtual security

45
New cards

Social engineering

A manipulation technique that exploits human error to gain private information, access, or valuables

46
New cards

Splunk Cloud

A cloud-hosted tool used to collect, search, and monitor log data

47
New cards

Splunk Enterprise

A self-hosted tool used to retain, analyze, and search an organization's log data to provide security information and alerts in real-time

48
New cards

Threat

Any circumstance or event that can negatively impact assets

49
New cards

Vulnerability

A weakness that can be exploited by a threat