CSA Security Guidance v4.0 Vocabulary Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/41

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:02 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

42 Terms

1
New cards

Cloud Computing

A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

2
New cards

Resource Pooling

An essential cloud characteristic where the provider abstracts resources and collects them into a shared pool to be allocated to multiple consumers based on demand.

3
New cards
4
New cards

On-Demand Self-Service

An essential cloud characteristic allowing consumers to provision computing capabilities (such as server time and network storage) automatically without requiring human interaction with each service provider.

5
New cards

Rapid Elasticity

An essential cloud characteristic enabling capabilities to be elastically provisioned and released, often automatically, to scale rapidly outward and inward commensurate with demand.

6
New cards

Measured Service

An essential cloud characteristic where resource usage is automatically controlled, monitored, metered, and reported for transparency and utility-style billing.

7
New cards

Software as a Service (SaaS)

A cloud service model where a complete application is hosted and managed by the provider, accessible to consumers via client interfaces such as a web browser or mobile app.

8
New cards

Platform as a Service (PaaS)

A cloud service model providing development or application processing platforms (such as databases or middleware) without requiring consumers to manage the underlying infrastructure.

9
New cards

Infrastructure as a Service (IaaS)

A cloud service model offering access to a pooled resource of fundamental computing infrastructure, such as compute processing, storage, and networking.

10
New cards

Public Cloud

A deployment model where cloud infrastructure is made available to the general public or a large industry group and owned by an organization selling cloud services.

11
New cards

Private Cloud

A deployment model where cloud infrastructure is operated solely for a single organization, managed internally or by a third party, located on-premises or off-premises.

12
New cards

Community Cloud

A deployment model where cloud infrastructure is shared by several organizations supporting a specific community with shared concerns such as mission, security requirements, policy, or compliance considerations.

13
New cards

Hybrid Cloud

A deployment model composed of two or more distinct clouds (private, community, or public) bound together by standardized or proprietary technology enabling data and application portability.

14
New cards

Cloud Management Plane

The combination of remotely accessible Application Programming Interfaces (APIs) and web-based user interfaces used by consumers to configure and manage their cloud resources.

15
New cards

Metastructure

The protocols and mechanisms that provide the interface between the infrastructure layer and other layers, acting as the glue that enables remote management and configuration in cloud environments.

16
New cards

Shared Responsibility Model

A security responsibility framework mapping security duties across the cloud provider and cloud customer based on the specific service model, deployment model, and level of control.

17
New cards

Consensus Assessments Initiative Questionnaire (CAIQ)

A standard template created by the Cloud Security Alliance for cloud providers to document and disclose their security and compliance controls.

18
New cards

Cloud Controls Matrix (CCM)

A Cloud Security Alliance baseline tool listing cloud security controls mapped against multiple international security and compliance standards.

19
New cards

Enterprise Risk Management (ERM)

The discipline of managing overall risk for an organization aligned with its corporate governance and risk tolerance, encompassing all areas of organizational risk.

20
New cards

General Data Protection Regulation (GDPR)

A binding European Union regulation establishing comprehensive rules for processing personal data of EU data subjects, including strict cross-border transfer limits and breach notification requirements.

21
New cards

Network Information Security Directive (NIS Directive)

An EU legal framework requiring member states to enforce network and information security requirements on operators of essential services and digital service providers.

22
New cards

Litigation Hold

A legal mandate requiring a party to take reasonable steps to preserve electronically stored information (ESI) relevant to pending or reasonably anticipated litigation or government investigations.

23
New cards

Pass-Through Audit

A form of compliance inheritance where a cloud provider's certified underlying infrastructure removes those provider-managed components from the customer's direct audit scope.

24
New cards

Data Owner

The individual or entity that legally owns data and defines the legal, policy, and business rules regarding its collection, use, and handling.

25
New cards

Data Custodian

The person or organization responsible for managing, storing, and applying security controls to data on behalf of the data owner.

26
New cards

Data Security Lifecycle

A six-phase security framework describing the stages through which data passes: Create, Store, Use, Share, Archive, and Destroy.

27
New cards

Software-Defined Infrastructure

The practice of defining and configuring infrastructure components (networks, compute, storage, and security) using software code and automated templates rather than manual hardware setups.

28
New cards

Chaos Engineering

A methodology of testing business continuity by intentionally and continuously introducing controlled failures into a production environment to build system resiliency.

29
New cards

Software Defined Networking (SDN)

A network virtualization architecture that decouples the network control plane from the data plane, enabling flexible, automated, and isolated virtual networks.

30
New cards

Microsegmentation

An architectural security technique using software-defined networks to isolate workloads into highly granular, separate virtual networks to reduce blast radius.

31
New cards

Software Defined Perimeter (SDP)

A security framework combining device and user authentication to dynamically provision network connections and enforce access control outside traditional perimeters.

32
New cards

Immutable Workload

A deployment pattern where running virtual machines or containers are never updated or modified in place; changes are deployed by replacing instances with updated baseline images.

33
New cards

Hypervisor

A virtual machine manager software layer that abstracts underlying physical hardware to allow multiple operating system environments to run concurrently.

34
New cards

Container

A lightweight code execution environment that provides isolated user space while sharing the underlying host operating system kernel.

35
New cards

Incident Response Lifecycle

The four-phase framework defined in NIST 800-61rev2 consisting of Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Mortem.

36
New cards

Secure Software Development Lifecycle (SSDLC)

A structured framework integrating security activities and controls across all phases of software creation, from design through deployment and operations.

37
New cards

DevOps

A software development culture and philosophy integrating development and operations through automation, CI/CD deployment pipelines, and programmatic infrastructure management.

38
New cards

Static Application Security Testing (SAST)

An application security testing method that inspects application source code or binaries for security vulnerabilities without executing the program.

39
New cards

Dynamic Application Security Testing (DAST)

An application security testing method that evaluates a running application for vulnerabilities by interacting with its exposed interfaces and endpoints.

40
New cards

Tokenization

A data security mechanism that substitutes sensitive data with a non-sensitive, randomized token value, storing the original mapping securely in a database.

41
New cards

Cloud Access Security Broker (CASB)

A security policy enforcement gateway placed inline or via API between cloud consumers and cloud providers to monitor usage, enforce security policies, and protect data.

42
New cards

Identity Provider (IdP)

The entity or system in federated identity management that maintains