1/59
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
VMI
Virtual Machine Introspection. An agentless security technique that examines a virtual machine's physical address, network settings, and operating system to ensure its security baseline has not changed.
iSCSI
Internet Small Computer System. A storage networking standard used to link data storage to systems using the Internet Protocol (IP).
CMM
Capability Maturity Model. A development model where the maturity relates to the formality and optimization of processes. When applied to cloud security it would focus on those aspects as they relate to cloud security.
ASHRAE
American Society of Heating, Refrigerating and Air-Conditioning Engineers. An American professional association seeking to advance heating, ventilation, air conditioning, and refrigeration systems design and construction.
NFV
Network Functions Virtualization. The replacement of physical network appliance hardware with virtual machines that run networking functions such as routing and load balancing.
SDN
Software Defined Networking. A networking approach that uses software-based controllers or APIs to communicate with underlying hardware and direct network traffic.
QA
Quality Assurance. Management and inspection activities intended to reduce the possibility of introducing errors or harming the final product.
ONF
Organizational Normative Framework. An organizational framework containing the components, security controls, and best practices used by an organization for application security
ANF
Application Normative Framework. A subset of the ONF created for a specific application that contains the applicable security requirements needed to achieve the application's required level of security and trust.
IAM
Identity and Access Management. The processes and procedures used to create, manage, and destroy digital identities and control their access to resources.
SAML
Security Assertion Markup Language. An XML-based federation standard used to communicate authentication, authorization, entitlement, and attribute information between organizations.
WAFs (What OSI layer? Protects against what types of attacks?)
Web Application Firewalls. Firewalls that protect specific web applications, operate at Layer 7 of the OSI model, and can provide protection against attacks such as DoS and DDoS.
DAM
Database Activity Monitoring. A security technology that protects databases by monitoring for unusual requests or activity and can operate using host-based or network-based methods.
XACML
eXtensible Access Control Markup Language. An XML-based, attribute-based access control policy language used to express security policies and access requests.
APIs
Application Programming Interfaces. Coding components that allow applications to communicate with one another through a defined interface, including web-based interfaces.
RESTful APIs
Representational State Transfer. APIs based on a stateless, client-server architecture that use cacheable communications and provide scalable web services.
SCIM
System for Cross-domain Identity Management. An open standard that defines a schema and RESTful API for managing user and group identity information and performing CRUD operations.
SOAP
Simple Object Access Protocol. A protocol specification for exchanging structured information in web services that can operate over protocols such as HTTP, FTP, and SMTP.
SDK
Software Development Kit. A collection of software development tools packaged together to facilitate application development and API usage.
TLS
Transport Layer Security. A protocol used to provide privacy and secure communications between applications, servers, and clients.
SSL
Secure Socket Layer. An older protocol that served the same purpose as TLS but has been replaced by TLS.
CSRF
Cross-Site Request Forgery. An attack that manipulates a logged-in user's browser into sending a forged HTTP request with the user's cookies, causing a vulnerable application to treat the request as legitimate.
White-Box Testing SAST
Static Application Security Testing. Application security testing that reviews the application's source code to identify vulnerabilities.
Black-Box Testing DAST
Dynamic Application Security Testing. Application security testing performed while the application is running without reviewing its source code, using inputs and observed results to identify vulnerabilities.
TPM
Trusted Platform Module. A specialized computer chip that secures hardware using integrated cryptographic keys and helps authenticate devices and protect against threats such as firmware and ransomware attacks.
RAID
Redundant Array of Independent Disks. A data protection method that distributes data across multiple disks, often using striping and parity to allow data recovery when a drive fails.
SSMS
Secret Sharing Made Short. A bit-splitting method using encryption, an information dispersal algorithm, and secret sharing to split encryption keys, with fragments distributed across different cloud storage services.
CI/CD
Continuous Integration/Continuous Delivery. A software development approach that heavily uses automation to shorten the software delivery pipeline while incorporating administrative and technical controls.
ITSM
IT Service Management. An approach focused on identifying user needs, designing IT services to meet those needs, deploying the services, and continuously improving them.
BC/DR
Business Continuity and Disaster Recovery. Planning and activities designed to maintain critical operations during disruptions and restore operations following a disaster.
MAD (AKA …)
Maximum Allowable Downtime. The maximum amount of time an interruption can stop an organization's operations; also called Maximum Tolerable Downtime (MTD).
MTTR
Mean Time to Repair. The average amount of time required to repair a system or device that is down.
RTO
Recovery Time Objective. The maximum targeted time for recovering operations after a disruption; it must be less than the MAD.
RPO
Recovery Point Objective. The maximum acceptable amount of data loss measured in time following an outage or unplanned event.
RSL %
Recovery Service Level. A measurement used to express the percentage of recovery service achieved or available following a disruption.
ALE
Annual Loss Expectancy. The amount an organization expects to lose annually from a specific type of incident, calculated as ARO × SLE.
ARO
Annual Rate of Occurrence. The expected frequency or rate at which a specific event or incident occurs annually.
SLE
Single Loss Expectancy. The expected amount of damage or loss resulting from one specific security incident.
ECPA
Electronic Communications Privacy Act. U.S. laws that restrict government wiretapping of telephone calls and electronic communications.
GLBA
Gramm-Leach-Bliley Act. U.S. law requiring financial institutions to protect the security and privacy of customer information and allowing customers to opt out of certain information-sharing arrangements.
SOX
Sarbanes-Oxley Act. U.S. legislation designed to improve transparency and accountability in publicly traded corporations and protect shareholders and the public from accounting errors and fraud.
HIPAA
Health Insurance Portability and Accountability Act. U.S. law designed to protect patient health information and records, including electronic protected health information (ePHI).
FERPA
Family Educational Rights and Privacy Act. U.S. law that protects student educational records and generally restricts educational institutions from disclosing student information without authorization.
DMCA
Digital Millennium Copyright Act. U.S. law that protects copyrighted digital content, criminalizes bypassing certain access controls, and provides mechanisms for copyright holders to request removal of infringing content.
CLOUD Act
Clarifying Lawful Overseas Use of Data. U.S. law that allows law enforcement and courts to compel U.S. companies to provide data stored in foreign data centers under applicable legal authority.
GDPR
General Data Protection Regulation. The European Union's comprehensive privacy regulation governing the handling and protection of personal information belonging to EU individuals.
ISMSs
Information Security Management Systems. A holistic framework for managing an organization's information security program, including policies, procedures, standards, and risk management.
KRIs
Key Risk Indicators. Forward-looking metrics used to provide early warning of potential negative impacts or risks to an organization's operations.
KPIs
Key Performance Indicators. Backward-looking metrics used to measure business-critical initiatives, objectives, or goals against defined benchmarks.
RMF
Risk Management Framework. A structured approach for identifying, assessing, managing, and continuously addressing organizational risk.
ENISA
EU Agency for Network and Information Security. The European Union agency responsible for cybersecurity guidance and standards, including identifying major cloud computing security risks.
ISO/IEC 15408-1:2009
Common Criteria Assurance Framework. A framework for providing assurance that security products meet stated security requirements and have been thoroughly evaluated by independent third-party testers.
CSA STAR
Security, Trust, and Assurance Registry. A framework and registry used to evaluate cloud providers and their security controls as part of vendor management and due diligence.
CCM
Cloud Controls Matrix. A framework containing cloud security controls organized into security domains and cross-referenced with other frameworks such as COBIT, ISO, NIST, FedRAMP, and PIPEDA.
CAIQ
Consensus Assessments Initiative Questionnaire. A questionnaire used by cloud providers for self-assessment of their security practices and control groups.
OWASP
Open Web Application Security Project. An international nonprofit organization focused on identifying software vulnerabilities and educating developers about secure software development.
FPE
Format-Preserving Encryption. A technique that encrypts or scrambles data while preserving its original structural format.
DFD
Data Flow Diagrams. Diagrams used in systems and software engineering to establish functional requirements before selecting technology.
PRE
Proxy Re-Encryption. A cryptographic technique that allows a proxy to convert ciphertext encrypted under one key into ciphertext for the same message under another key without revealing the underlying plaintext.
Microsoft SDL
Security Development Lifecycle. Microsoft's secure software development process based on the spiral model, designed to reduce security issues and vulnerabilities while lowering development and maintenance costs. Training, requirements, design, implementation, verification, release, r