1/43
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Confidentiality
Prevent unauthorized disclosure
Integrity
Protect accuracy and completeness against unauthorized change.
Availability
Ensure authorized users can access systems/data when needed.
Authentication
Verify the claimed identity.
Authorization
Decide what an authenticated identity is allowed to do.
Accounting
Record relevant activity so actions can be traced and reviewed.
Non-repudiation
Support evidence that an actor performed an action and cannot credibly deny it.
Privacy
Handle personal information according to applicable rights, expectations and requirements.
Asset
Something of value that needs protection.
Threat
A circumstance or actor that could cause harm.
Vulnerability
A weakness that could be exploited or contribute to failure.
Likelihood
How plausible/frequent the event is in the stated context.
Impact
The consequence if the event occurs.
Inherent risk
Risk before considering selected controls.
Residual risk
Risk remaining after controls are considered
Risk appetite
The amount/type of risk an organization is willing to pursue or retain in pursuit of objectives.
Risk tolerance
Acceptable variation or threshold around a specific risk/objective.
Treatment: Mitigate / reduce
Apply controls to reduce likelihood and/or impact.
Treatment: Avoid
Stop the activity that creates the unacceptable risk.
Transfer / share
Shift or share defined financial/operational consequences through another party or mechanism.
Accept
Make an authorized decision to retain the risk.
Is vulnerability automatically a high risk?
NO! Exposure, asset value, threat context, existing controls and business impact matter.
Regulation / law
Creates externally enforceable obligations.
Framework / guideline
Organizes recommended practices or a structured approach.
Policy
States management intent and mandatory organizational direction.
Standard
Defines specific mandatory internal requirements or approved methods.
Procedure
Explains the steps used to perform a task consistently.
Policies state what?
direction
standards define what?
mandatory details
procedures describe what?
the steps
frameworks and guidelines do what?
organize practices
laws/regulations impose what?
external obligations
control type: Technical
MFA, firewall, encryption, endpoint protection, logging.
control type: Administrative
Policy, training, risk assessment, access review, vendor process.
Control Type: Physical
Locks, guards, barriers, cameras, environmental safeguards.
functional lens: Preventive
Reduce the chance an unwanted event succeeds.
functional lens: Detective
Identify suspicious or policy-violating activity.
functional lens: Corrective
Fix or limit impact after a problem is discovered.
functional lens: Recovery
Restore service/data/capability after disruption.
Professional code of conduct
Expected professional behavior, accountability and responsible use of authority.
Due care
Taking reasonable protective action expected under the circumstances.
Due diligence
Sustained investigation, verification and monitoring before and after decisions
Authorization
Do not exceed approved scope simply because you technically can.
Competence
Recognize limits, validate assumptions and seek qualified help when needed.