D320 Acronyms

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/59

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:56 AM on 9/4/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

60 Terms

1
New cards

VMI

Virtual Machine Introspection. An agentless security technique that examines a virtual machine's physical address, network settings, and operating system to ensure its security baseline has not changed.

2
New cards

iSCSI

Internet Small Computer System. A storage networking standard used to link data storage to systems using the Internet Protocol (IP).

3
New cards

CMM

Capability Maturity Model. A development model where the maturity relates to the formality and optimization of processes. When applied to cloud security it would focus on those aspects as they relate to cloud security.

4
New cards

ASHRAE

American Society of Heating, Refrigerating and Air-Conditioning Engineers. An American professional association seeking to advance heating, ventilation, air conditioning, and refrigeration systems design and construction.

5
New cards

NFV

Network Functions Virtualization. The replacement of physical network appliance hardware with virtual machines that run networking functions such as routing and load balancing.

6
New cards

SDN

Software Defined Networking. A networking approach that uses software-based controllers or APIs to communicate with underlying hardware and direct network traffic.

7
New cards

QA

Quality Assurance. Management and inspection activities intended to reduce the possibility of introducing errors or harming the final product.

8
New cards

ONF

Organizational Normative Framework. An organizational framework containing the components, security controls, and best practices used by an organization for application security

9
New cards

ANF

Application Normative Framework. A subset of the ONF created for a specific application that contains the applicable security requirements needed to achieve the application's required level of security and trust.

10
New cards

IAM

Identity and Access Management. The processes and procedures used to create, manage, and destroy digital identities and control their access to resources.

11
New cards

SAML

Security Assertion Markup Language. An XML-based federation standard used to communicate authentication, authorization, entitlement, and attribute information between organizations.

12
New cards

WAFs (What OSI layer? Protects against what types of attacks?)

Web Application Firewalls. Firewalls that protect specific web applications, operate at Layer 7 of the OSI model, and can provide protection against attacks such as DoS and DDoS.

13
New cards

DAM

Database Activity Monitoring. A security technology that protects databases by monitoring for unusual requests or activity and can operate using host-based or network-based methods.

14
New cards

XACML

eXtensible Access Control Markup Language. An XML-based, attribute-based access control policy language used to express security policies and access requests.

15
New cards

APIs

Application Programming Interfaces. Coding components that allow applications to communicate with one another through a defined interface, including web-based interfaces.

16
New cards

RESTful APIs

Representational State Transfer. APIs based on a stateless, client-server architecture that use cacheable communications and provide scalable web services.

17
New cards

SCIM

System for Cross-domain Identity Management. An open standard that defines a schema and RESTful API for managing user and group identity information and performing CRUD operations.

18
New cards

SOAP

Simple Object Access Protocol. A protocol specification for exchanging structured information in web services that can operate over protocols such as HTTP, FTP, and SMTP.

19
New cards

SDK

Software Development Kit. A collection of software development tools packaged together to facilitate application development and API usage.

20
New cards

TLS

Transport Layer Security. A protocol used to provide privacy and secure communications between applications, servers, and clients.

21
New cards

SSL

Secure Socket Layer. An older protocol that served the same purpose as TLS but has been replaced by TLS.

22
New cards

CSRF

Cross-Site Request Forgery. An attack that manipulates a logged-in user's browser into sending a forged HTTP request with the user's cookies, causing a vulnerable application to treat the request as legitimate.

23
New cards

White-Box Testing SAST

Static Application Security Testing. Application security testing that reviews the application's source code to identify vulnerabilities.

24
New cards

Black-Box Testing DAST

Dynamic Application Security Testing. Application security testing performed while the application is running without reviewing its source code, using inputs and observed results to identify vulnerabilities.

25
New cards

TPM

Trusted Platform Module. A specialized computer chip that secures hardware using integrated cryptographic keys and helps authenticate devices and protect against threats such as firmware and ransomware attacks.

26
New cards

RAID

Redundant Array of Independent Disks. A data protection method that distributes data across multiple disks, often using striping and parity to allow data recovery when a drive fails.

27
New cards

SSMS

Secret Sharing Made Short. A bit-splitting method using encryption, an information dispersal algorithm, and secret sharing to split encryption keys, with fragments distributed across different cloud storage services.

28
New cards

CI/CD

Continuous Integration/Continuous Delivery. A software development approach that heavily uses automation to shorten the software delivery pipeline while incorporating administrative and technical controls.

29
New cards

ITSM

IT Service Management. An approach focused on identifying user needs, designing IT services to meet those needs, deploying the services, and continuously improving them.

30
New cards

BC/DR

Business Continuity and Disaster Recovery. Planning and activities designed to maintain critical operations during disruptions and restore operations following a disaster.

31
New cards

MAD (AKA …)

Maximum Allowable Downtime. The maximum amount of time an interruption can stop an organization's operations; also called Maximum Tolerable Downtime (MTD).

32
New cards

MTTR

Mean Time to Repair. The average amount of time required to repair a system or device that is down.

33
New cards

RTO

Recovery Time Objective. The maximum targeted time for recovering operations after a disruption; it must be less than the MAD.

34
New cards

RPO

Recovery Point Objective. The maximum acceptable amount of data loss measured in time following an outage or unplanned event.

35
New cards

RSL %

Recovery Service Level. A measurement used to express the percentage of recovery service achieved or available following a disruption.

36
New cards

ALE

Annual Loss Expectancy. The amount an organization expects to lose annually from a specific type of incident, calculated as ARO × SLE.

37
New cards

ARO

Annual Rate of Occurrence. The expected frequency or rate at which a specific event or incident occurs annually.

38
New cards

SLE

Single Loss Expectancy. The expected amount of damage or loss resulting from one specific security incident.

39
New cards

ECPA

Electronic Communications Privacy Act. U.S. laws that restrict government wiretapping of telephone calls and electronic communications.

40
New cards

GLBA

Gramm-Leach-Bliley Act. U.S. law requiring financial institutions to protect the security and privacy of customer information and allowing customers to opt out of certain information-sharing arrangements.

41
New cards

SOX

Sarbanes-Oxley Act. U.S. legislation designed to improve transparency and accountability in publicly traded corporations and protect shareholders and the public from accounting errors and fraud.

42
New cards

HIPAA

Health Insurance Portability and Accountability Act. U.S. law designed to protect patient health information and records, including electronic protected health information (ePHI).

43
New cards

FERPA

Family Educational Rights and Privacy Act. U.S. law that protects student educational records and generally restricts educational institutions from disclosing student information without authorization.

44
New cards

DMCA

Digital Millennium Copyright Act. U.S. law that protects copyrighted digital content, criminalizes bypassing certain access controls, and provides mechanisms for copyright holders to request removal of infringing content.

45
New cards

CLOUD Act

Clarifying Lawful Overseas Use of Data. U.S. law that allows law enforcement and courts to compel U.S. companies to provide data stored in foreign data centers under applicable legal authority.

46
New cards

GDPR

General Data Protection Regulation. The European Union's comprehensive privacy regulation governing the handling and protection of personal information belonging to EU individuals.

47
New cards

ISMSs

Information Security Management Systems. A holistic framework for managing an organization's information security program, including policies, procedures, standards, and risk management.

48
New cards

KRIs

Key Risk Indicators. Forward-looking metrics used to provide early warning of potential negative impacts or risks to an organization's operations.

49
New cards

KPIs

Key Performance Indicators. Backward-looking metrics used to measure business-critical initiatives, objectives, or goals against defined benchmarks.

50
New cards

RMF

Risk Management Framework. A structured approach for identifying, assessing, managing, and continuously addressing organizational risk.

51
New cards

ENISA

EU Agency for Network and Information Security. The European Union agency responsible for cybersecurity guidance and standards, including identifying major cloud computing security risks.

52
New cards

ISO/IEC 15408-1:2009

Common Criteria Assurance Framework. A framework for providing assurance that security products meet stated security requirements and have been thoroughly evaluated by independent third-party testers.

53
New cards

CSA STAR

Security, Trust, and Assurance Registry. A framework and registry used to evaluate cloud providers and their security controls as part of vendor management and due diligence.

54
New cards

CCM

Cloud Controls Matrix. A framework containing cloud security controls organized into security domains and cross-referenced with other frameworks such as COBIT, ISO, NIST, FedRAMP, and PIPEDA.

55
New cards

CAIQ

Consensus Assessments Initiative Questionnaire. A questionnaire used by cloud providers for self-assessment of their security practices and control groups.

56
New cards

OWASP

Open Web Application Security Project. An international nonprofit organization focused on identifying software vulnerabilities and educating developers about secure software development.

57
New cards

FPE

Format-Preserving Encryption. A technique that encrypts or scrambles data while preserving its original structural format.

58
New cards

DFD

Data Flow Diagrams. Diagrams used in systems and software engineering to establish functional requirements before selecting technology.

59
New cards

PRE

Proxy Re-Encryption. A cryptographic technique that allows a proxy to convert ciphertext encrypted under one key into ciphertext for the same message under another key without revealing the underlying plaintext.

60
New cards

Microsoft SDL

Security Development Lifecycle. Microsoft's secure software development process based on the spiral model, designed to reduce security issues and vulnerabilities while lowering development and maintenance costs. Training, requirements, design, implementation, verification, release, r