CC Certification : Domain 1 Security Principles

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/43

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:02 PM on 9/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

44 Terms

1
New cards

Confidentiality

Prevent unauthorized disclosure

2
New cards

Integrity

Protect accuracy and completeness against unauthorized change.

3
New cards

Availability

Ensure authorized users can access systems/data when needed.

4
New cards

Authentication

Verify the claimed identity.

5
New cards

Authorization

Decide what an authenticated identity is allowed to do.

6
New cards

Accounting

Record relevant activity so actions can be traced and reviewed.

7
New cards

Non-repudiation

Support evidence that an actor performed an action and cannot credibly deny it.

8
New cards

Privacy

Handle personal information according to applicable rights, expectations and requirements.

9
New cards

Asset

Something of value that needs protection.

10
New cards

Threat

A circumstance or actor that could cause harm.

11
New cards

Vulnerability

A weakness that could be exploited or contribute to failure.

12
New cards

Likelihood

How plausible/frequent the event is in the stated context.

13
New cards

Impact

The consequence if the event occurs.

14
New cards

Inherent risk

Risk before considering selected controls.

15
New cards

Residual risk

Risk remaining after controls are considered

16
New cards

Risk appetite

The amount/type of risk an organization is willing to pursue or retain in pursuit of objectives.

17
New cards

Risk tolerance

Acceptable variation or threshold around a specific risk/objective.

18
New cards

Treatment: Mitigate / reduce

Apply controls to reduce likelihood and/or impact.

19
New cards

Treatment: Avoid

Stop the activity that creates the unacceptable risk.

20
New cards

Transfer / share

Shift or share defined financial/operational consequences through another party or mechanism.

21
New cards

Accept

Make an authorized decision to retain the risk.

22
New cards

Is vulnerability automatically a high risk?

NO! Exposure, asset value, threat context, existing controls and business impact matter.

23
New cards

Regulation / law

Creates externally enforceable obligations.

24
New cards

Framework / guideline

Organizes recommended practices or a structured approach.

25
New cards

Policy

States management intent and mandatory organizational direction.

26
New cards

Standard

Defines specific mandatory internal requirements or approved methods.

27
New cards

Procedure

Explains the steps used to perform a task consistently.

28
New cards

Policies state what?

direction

29
New cards

standards define what?

mandatory details

30
New cards

procedures describe what?

the steps

31
New cards

frameworks and guidelines do what?

organize practices

32
New cards

laws/regulations impose what?

external obligations

33
New cards

control type: Technical

MFA, firewall, encryption, endpoint protection, logging.

34
New cards

control type: Administrative

Policy, training, risk assessment, access review, vendor process.

35
New cards

Control Type: Physical

Locks, guards, barriers, cameras, environmental safeguards.

36
New cards

functional lens: Preventive

Reduce the chance an unwanted event succeeds.

37
New cards

functional lens: Detective

Identify suspicious or policy-violating activity.

38
New cards

functional lens: Corrective

Fix or limit impact after a problem is discovered.

39
New cards

functional lens: Recovery

Restore service/data/capability after disruption.

40
New cards

Professional code of conduct

Expected professional behavior, accountability and responsible use of authority.

41
New cards

Due care

Taking reasonable protective action expected under the circumstances.

42
New cards

Due diligence

Sustained investigation, verification and monitoring before and after decisions

43
New cards

Authorization

Do not exceed approved scope simply because you technically can.

44
New cards

Competence

Recognize limits, validate assumptions and seek qualified help when needed.