AppSec Deck

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/92

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:27 PM on 6/15/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

93 Terms

1
New cards

performance testing

evaluate Web application, speed, stability and scalability varying under loads and network conditions

2
New cards

compatibility testing

Is designed to verify that a web application can function correctly across different web, browsers or operating systems, regardless of the device or platform used to access the application

3
New cards

security testing

Identifies the applications, vulnerabilities, weaknesses, and security flaws and ensures. The data is secure from unauthorized access.

4
New cards

comprehensive testing

GAT covers functional usability, accessibility, localization, and compatibility testing

5
New cards

GAT

Global app testing

6
New cards

functional testing

Examines core features

7
New cards

non-functional testing

Assesses performance, security, and usability

8
New cards

unit testing

Design to help mitigate the risks of code changes

9
New cards

integration testing

Involves combining individual software modules and testing them as a group to verify their harmonist and intended functionality

10
New cards

System testing

Validates a complete integrated web application to verify that it meets all specified criteria

11
New cards

regression testing

Aims to identify issues in previously tested code or configuration after changes or modifications

12
New cards

acceptance testing

Evaluates invalidates the web applications functionality from an end users perspective

13
New cards

UI testing

Check whether the web applications user interface works as intended, and is visually appealing to end user

14
New cards

Usability testing

Involves customer feedback observing how they’re interrupt and navigate web applications and identifying usability issues

15
New cards

threat model

A systematic proactive cyber security practice for identifying potential threats, vulnerabilities, and risks in software systems and business processes to inform mitigation strategies and improve security posture

16
New cards

AST

Application security tools

17
New cards

DAST

Dynamic application security testing

18
New cards

OWASP TOP 10 2021

This is the standard for anything cyber security

19
New cards

Broken access control

restrictions on what authorize users are allowed to do are often not properly enforced attackers can exploit these flaws to access unauthorized functionality and or data such as access to other users account view, sensitive files, modify other users, data, change, assets, rights, etc

20
New cards

cryptographic failures

Failure to sufficiently protect data and transit or rest from exposure to unauthorized individuals. This can include poor usage of encryption or lack of it all together.

21
New cards

injection

Injection flaws, such as SQL, NoSQL, OS, And Elda injections occur when Untrust data is sent to an interpreter as part of a command query the attackers hostile data can trick the interpreter into executing unintended command or accessing data without proper authorization

22
New cards

insecure design

Failing to build security into the application early in the process through Threat modeling and secure design patterns, and principles

23
New cards

security mitigation

Security misconfiguration is commonly a result of insecure, default, configurations, incomplete or ad hoc configurations open cloud storage misconfigured HTTP headers and verb error messages containing sensitive information

24
New cards

vulnerable and outdated components

Components, such as libraries, framework and other software modules run with some privileges as the application if a vulnerable component is exploited, such as an attack can facilitate serious data loss, or server takeover

25
New cards

identification and authentication factors

Application functions related to authentication in session management are often implemented incorrectly, allowing the attackers to compromise password, keys, or session, tokens, or other implementation flaws to assume other users, identities, temporarily or permanently

26
New cards

software and data integrity, failures

Code infrastructures that does not properly protect against integrity failures like using plug-ins from

27
New cards

insufficient Logging and monitoring

Insufficient, logging and monitoring coupled with missing or ineffective integration with incident response allows attackers to further attack systems, maintain persistence, pivot to more systems, and temper or destroy data

28
New cards

server side request forging

SSRF occurs when an application fetches resources without validating the destination URL, this can be taken advantage of by attacker who is able to enter destination of their choosing

29
New cards

Security

according to Fischer And Green security implies a stable, relatively predictable environment in which an individual group may pursue its ends without disruption or harm and without fear of disturbance or injury

30
New cards

cyber security

The practice of protecting networks devices and data from unauthorized access or criminal use and ensuring the confidentiality, integrity, and availability of information

31
New cards

vulnerability

Is any weakness and acid that makes it susceptible to an attack or failure?

32
New cards

attack

Is an intentional action that can reduce the value of assets

33
New cards

Failure and errors

Unintentional actions that can reduce the value of an asset

34
New cards

threats

Attacks, failures and errors or actions that we collectively referred to his threats

35
New cards

finding your security goals

determine what assets we want to protect

Learn how the assets Works and interact with other things

Determine how our assets values reduced directly/indirect

36
New cards

CIA Triad

Confidentiality, integrity, and availability

37
New cards

Confidentiality

Ensures that sensitive information is accessible to authorize individuals

38
New cards

integrity

ensures the data is accurate and unaltered, safeguarding it from unauthorized modifications or corruptions

39
New cards

availability

Ensures that the data and services are accessible to authorize users when needed

40
New cards

when we protect something valuable, that’s protecting its _____?

Confidentiality

41
New cards

when it’s something that produces value, it’s _____?

Integrity

42
New cards

when we protect some thing that Provides access to value its _____?

Availability

43
New cards

The protection of info in a computer system

Economy of mechanism, Fail-safe default, Complete mediation, Open design, Separation of privilege, Least privilege, Least common mechanism, Psychological acceptability

44
New cards

TTPs

techniques, tactics, and process

45
New cards

economy of mechanism

Keeping it simple complexity is enemy of security

46
New cards

Fail-Safe default

Fail and error scenarios should fall back to most secure option

47
New cards

complete mediation

Check every access to a resource for authority

48
New cards

Open design

There is no security through security

49
New cards

separation of privilege

Two keys are red present to access key info

50
New cards

least privilege

access to do your job and no more

51
New cards

least common mechanism

Reducing the shared components in the system

52
New cards

psychological Acceptability

Systems need to be designed so people expected behavior provides security. Security is hard. People will find another way.

53
New cards

Secure software development framework

A set of fundamental sound secure software development practices based on established documents from organizations such as the BSA, OWASP ISO, POI, BSIMM, and safe code

It provides a common language for describing secured development practices, which can be used to foster communications for procurement processes, and other management activities

54
New cards

PO: Prepare the organization

Ensure readiness at both the organizational project levels for secure software development

55
New cards

PS: Protect the software

Secure all software components from tampering and unauthorized access

56
New cards

PW: Produce well sourced software

Develop software with minimal security vulnerabilities

57
New cards

RV: Respond to vulnerabilities

identifying address vulnerabilities in release software

58
New cards

customizing practices

The SSDF provides the starting point to organizations can customize and evolve over the time to fit their unique needs rather than serving as a rigid checklist

59
New cards

automating security

Consider auto mobility when implementing SSDF practices, especially for Scaling practices across large or complex environments

60
New cards

CSF

The NIST cyber security framework helps organizations to better understand and improve their management of cyber security risks

The CSF 2.0 is suitable for both initiating and changing cyber security programs

<p>The NIST cyber security framework helps organizations to better understand and improve their management of cyber security risks</p><p></p><p>The CSF 2.0 is suitable for both initiating and changing cyber security programs</p>
61
New cards

6 characteristics of CSF

governance, identify, protect, detect, respond, recover

62
New cards

identify

Develop an understanding of the organization system

63
New cards

Protect

Implement safeguards to ensure delivery of critical services

64
New cards

detect

Implement activities to identify the occurrence of a cyber security event

65
New cards

respond

Implement activities to take action regarding a detective cyber security incident

66
New cards

Recover

Implement activities to restore any capabilities or services that would impair due to a cyber security incident

67
New cards

adoption of the six functions

Organization start by integrating the six core functions of the CSF 2.0 into their cyber security programs

68
New cards

guidance utilization

Utilizing the resources in overview guide that helps organizations understand the rules and responsibilities associated with each function, serving as implementation blueprint

69
New cards

Setting specific outcomes

Organizations use these outcomes as benchmarks to gauge their progress and effectiveness in imagining cyber security risks

70
New cards

supplementary resources

To achieve the detailed outcomes organizations referred to as additional NIST resources that explains specific actions needed to realize these outcomes by adopting best practices

71
New cards

assessment and prioritization

Organizations assess their current cyber security practices against the CSF 2.0 standards to identify gaps and areas of improvement

72
New cards

internal and external communication

The CSF 2.0 used as a two for fostering better communication among internal teams (IT, security, operations, executive leadership, and with external partners)

73
New cards

integration with risk management

Organizations integrate the CSF 2.0 into their broader risk management strategies to ensure that cyber security risks are considered alongside other business risks

74
New cards

risk management framework (RMF)

The NIST RMF provides a process that integrates security privacy and cyber supply chain risk management activities into the system development lifecycle

75
New cards

why NIST RMF?

Evolving technology and edge computing increase the complexity of the interconnected systems

Hayton, security and privacy risks accompany this increased complex

NIST develop the RMF to address these challenges

The RMF is essential for protecting the integrity of systems and data across both public and private sectors

Ensure resilience and trustworthiness throughout the SDLC

76
New cards

The increasing cyber security threat landscape and National imperatives

Complexity and attack surface, supply chain, risk, defense, science board report, executive orders, and policies

77
New cards

complexity and attack surface

The risk in complexity of hardware software and systems participating in critical infrastructure increase vulnerability to attacks

78
New cards

Supply chain risk

Adversaries exploit supply chains to compromise systems the need for robust supply chain, risk management (SCRM)

79
New cards

defense science board report

Highlight the urgent need for improved cyber deterrence, and proactive risk management

80
New cards

executive orders, and policies

EO 13800 mandates federal agencies to ensure Bus risk management practices while office of management and budget (OMB)

81
New cards

7 stages of the RMF

Prepare, categorize, select, implement, assess, authorize, monitor

82
New cards

prepare

Identify rules, risk strategy, risk tolerance, and develop organizational risk assessment and continues monitoring

83
New cards

Categorize

Document system characteristics and classifies security impact

84
New cards

select

Choose, Taylor, and documents, security controls, establish continuous monitoring, and review security plans

85
New cards

Implement

Apply the chain controls. Update, security and privacy plans.

86
New cards

assess

Evaluate control, effectiveness and address deficiencies. Update security plans based on assessments.

87
New cards

authorize

Senior officials decide on risk acceptance. Provide authorization packages and risk mitigation.

88
New cards

Monitor

Maintain ongoing awareness of security posture. Use continues monitoring, inform risk management decisions.

89
New cards

NIST risk management framework (RMF)

Enhance security awareness: engineers are more aware of security risks and responsibilities

Structure development process: follows a systematic approach to risk assessment and management

Compliance requirements: insures adherence to organizational and regulatory security standards

90
New cards

NIST cyber security framework (CSF)

Holistic security integration: integrates security practices into daily development activities

Proactive threat mitigation: focuses on identifying and mitigating potential threats easily in the development cycle

Continuous improvement: encourages ongoing assessment and improvement of security measures

91
New cards

NIST secure software development framework (SDF)

Secure coding practices: emphasizes secure, coding standards and practices

Secure testing: incorporates, regular security, testing, and vulnerability assessments

documentation and transparency: insures, detailed documentation of security measures and decisions

92
New cards

what the CSA does

Promoting best practices, education, search, certification, consulting program guidance and roadmap, user certifications, meta-framework of cloud specifics, security controls, and collaborations

93
New cards

Best practices for 14 domains

  1. Cloud, computing concept and architectures

  1. governance and enterprise risk management,

  2. legal issues, contracts, and electronic discovery

  3. Compliance and audit management

  4. Information governance

  5. Management plan and business continuity

  6. Infrastructure security

  7. Virtualization and containers

  8. Incident response

  9. Application security

  10. Data security and encryption

  11. Identity, entitlement, and access management

  12. Security as a service

  13. related cloud technologies