1/41
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Cloud Computing
A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.
Resource Pooling
An essential cloud characteristic where the provider abstracts resources and collects them into a shared pool to be allocated to multiple consumers based on demand.
On-Demand Self-Service
An essential cloud characteristic allowing consumers to provision computing capabilities (such as server time and network storage) automatically without requiring human interaction with each service provider.
Rapid Elasticity
An essential cloud characteristic enabling capabilities to be elastically provisioned and released, often automatically, to scale rapidly outward and inward commensurate with demand.
Measured Service
An essential cloud characteristic where resource usage is automatically controlled, monitored, metered, and reported for transparency and utility-style billing.
Software as a Service (SaaS)
A cloud service model where a complete application is hosted and managed by the provider, accessible to consumers via client interfaces such as a web browser or mobile app.
Platform as a Service (PaaS)
A cloud service model providing development or application processing platforms (such as databases or middleware) without requiring consumers to manage the underlying infrastructure.
Infrastructure as a Service (IaaS)
A cloud service model offering access to a pooled resource of fundamental computing infrastructure, such as compute processing, storage, and networking.
Public Cloud
A deployment model where cloud infrastructure is made available to the general public or a large industry group and owned by an organization selling cloud services.
Private Cloud
A deployment model where cloud infrastructure is operated solely for a single organization, managed internally or by a third party, located on-premises or off-premises.
Community Cloud
A deployment model where cloud infrastructure is shared by several organizations supporting a specific community with shared concerns such as mission, security requirements, policy, or compliance considerations.
Hybrid Cloud
A deployment model composed of two or more distinct clouds (private, community, or public) bound together by standardized or proprietary technology enabling data and application portability.
Cloud Management Plane
The combination of remotely accessible Application Programming Interfaces (APIs) and web-based user interfaces used by consumers to configure and manage their cloud resources.
Metastructure
The protocols and mechanisms that provide the interface between the infrastructure layer and other layers, acting as the glue that enables remote management and configuration in cloud environments.
Shared Responsibility Model
A security responsibility framework mapping security duties across the cloud provider and cloud customer based on the specific service model, deployment model, and level of control.
Consensus Assessments Initiative Questionnaire (CAIQ)
A standard template created by the Cloud Security Alliance for cloud providers to document and disclose their security and compliance controls.
Cloud Controls Matrix (CCM)
A Cloud Security Alliance baseline tool listing cloud security controls mapped against multiple international security and compliance standards.
Enterprise Risk Management (ERM)
The discipline of managing overall risk for an organization aligned with its corporate governance and risk tolerance, encompassing all areas of organizational risk.
General Data Protection Regulation (GDPR)
A binding European Union regulation establishing comprehensive rules for processing personal data of EU data subjects, including strict cross-border transfer limits and breach notification requirements.
Network Information Security Directive (NIS Directive)
An EU legal framework requiring member states to enforce network and information security requirements on operators of essential services and digital service providers.
Litigation Hold
A legal mandate requiring a party to take reasonable steps to preserve electronically stored information (ESI) relevant to pending or reasonably anticipated litigation or government investigations.
Pass-Through Audit
A form of compliance inheritance where a cloud provider's certified underlying infrastructure removes those provider-managed components from the customer's direct audit scope.
Data Owner
The individual or entity that legally owns data and defines the legal, policy, and business rules regarding its collection, use, and handling.
Data Custodian
The person or organization responsible for managing, storing, and applying security controls to data on behalf of the data owner.
Data Security Lifecycle
A six-phase security framework describing the stages through which data passes: Create, Store, Use, Share, Archive, and Destroy.
Software-Defined Infrastructure
The practice of defining and configuring infrastructure components (networks, compute, storage, and security) using software code and automated templates rather than manual hardware setups.
Chaos Engineering
A methodology of testing business continuity by intentionally and continuously introducing controlled failures into a production environment to build system resiliency.
Software Defined Networking (SDN)
A network virtualization architecture that decouples the network control plane from the data plane, enabling flexible, automated, and isolated virtual networks.
Microsegmentation
An architectural security technique using software-defined networks to isolate workloads into highly granular, separate virtual networks to reduce blast radius.
Software Defined Perimeter (SDP)
A security framework combining device and user authentication to dynamically provision network connections and enforce access control outside traditional perimeters.
Immutable Workload
A deployment pattern where running virtual machines or containers are never updated or modified in place; changes are deployed by replacing instances with updated baseline images.
Hypervisor
A virtual machine manager software layer that abstracts underlying physical hardware to allow multiple operating system environments to run concurrently.
Container
A lightweight code execution environment that provides isolated user space while sharing the underlying host operating system kernel.
Incident Response Lifecycle
The four-phase framework defined in NIST 800-61rev2 consisting of Preparation; Detection & Analysis; Containment, Eradication & Recovery; and Post-Mortem.
Secure Software Development Lifecycle (SSDLC)
A structured framework integrating security activities and controls across all phases of software creation, from design through deployment and operations.
DevOps
A software development culture and philosophy integrating development and operations through automation, CI/CD deployment pipelines, and programmatic infrastructure management.
Static Application Security Testing (SAST)
An application security testing method that inspects application source code or binaries for security vulnerabilities without executing the program.
Dynamic Application Security Testing (DAST)
An application security testing method that evaluates a running application for vulnerabilities by interacting with its exposed interfaces and endpoints.
Tokenization
A data security mechanism that substitutes sensitive data with a non-sensitive, randomized token value, storing the original mapping securely in a database.
Cloud Access Security Broker (CASB)
A security policy enforcement gateway placed inline or via API between cloud consumers and cloud providers to monitor usage, enforce security policies, and protect data.
Identity Provider (IdP)
The entity or system in federated identity management that maintains