1/35
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Risk Appetite/Tolerance
The amount of risk an organization is willing to accept, as determined by senior management.
Secrets Manager
Like a password manager for organizational/IT use. It manages passwords for applications/systems.
OWASP 3 Requirements for “break‐glass” Secrets Backup Environments
Ensuring automated backups are in place and executed regularly.
Frequently testing the restore procedures.
Encrypting backups and placing them on secure, monitored storage.
Common Criteria EAL Levels
EAL = Evaluation and Assurance Levels
EAL1: Functionally Tested EAL2: Structurally Tested EAL3: Methodically tested and checked EAL4: Methodically designed, tested, and reviewed | EAL5: Semi-formally designed and tested EAL6: Semi-formally verified design and tested EAL7: Formally verified design and tested |
CSA
Cloud Security and Alliance. Provides a set of vendor‐neutral design patterns for cloud security.
CSA STAR
Cloud Security and Alliance - Security, Trust, and Assurance Registry. A framework and registry used to evaluate cloud providers and their security controls as part of vendor management and due diligence.
Risk Profiles
A comprehensive analysis of the possible risks facing an organization, including operational, geographic, legal, and public perception risks.
Physical Controls
Controls that physically restrict or protect access to assets and reduce the impact of physical events, such as locks, fences, guards, and fire suppression.
Technical Controls
Logical controls that enhance the confidentiality, integrity, and availability of information, such as encryption, ACLs, audit trails, and logs.
Administrative Controls
Security processes and activities such as background checks, log reviews, mandatory vacations, policies, procedures, and business process design.
ISO 31000:2018
An international standard focused on designing, implementing, and reviewing risk management processes and practices.
NIST SP 800-37
A NIST methodology for managing organizational risk in a holistic, comprehensive, and continuous manner.
ENISA
Europe Network and Information Security Agency. EU counterpart to NIST. Standard and model developed in EU. Responsible for producing Cloud Computing: Benefits, Risks, and Recommendations for Information Security. Identifies top eight security risks based on likelihood and impact
COBIT
A framework for the governance and management of enterprise IT.
ISO/IEC 31010:2009
An international standard providing techniques and guidance for risk assessment and risk management.
Risk Management Metrics
A numerical scale used to rate risk severity: 5 is Critical, 4 is High, 3 is Moderate, 2 is Low, and 1 is Minimal.
ISO/IEC 15408-1:2009
Common Criteria Assurance Framework. Provide assurances for security claims by vendors. Assurance for security products customers purchase have been thoroughly tested by 3 rd party testers and meets requirements.
ISO 28000:2007
An international standard addressing security management and controls within supply chains.
CSA STAR Program – Open Certification Framework
A cloud security assurance program with three levels:
Level One self-assessment
Level Two third-party attestation
Level Three continuous monitoring by a certified third party.
PKI
A framework of programs, procedures, communication protocols, and public-key cryptography that enables secure communication among diverse users and systems.
Cross-Certification Model
A federation model in which every participating organization reviews and approves every other organization, making the model difficult to scale.
Management Plane
The logical infrastructure and technology used by administrators to remotely manage cloud resources, such as launching virtual machines and configuring virtual networks.
Information Commissioner
An official responsible for enforcing UK GDPR and providing advice and assistance concerning the handling of personal information.
NIS Directive (EU 2016/1148)
The first EU-wide cybersecurity legislation, requiring covered organizations to notify competent authorities or CSIRTs about certain security incidents.
NIST 800-145
The NIST publication that defines cloud computing as convenient, on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or provider interaction.
NIST 800-146
A NIST document describing cloud computing benefits, open issues, major cloud technologies, and guidelines for evaluating cloud opportunities and risks.
Functional Requirements
Performance aspects of a device, process, or employee that are necessary for accomplishing a business task.
Nonfunctional Requirements
Desired or expected aspects of a device, process, or employee that are not necessary for accomplishing the business task.
Eucalyptus
Software used to build AWS-compatible private or hybrid cloud computing environments with multitenancy.
ISO/IEC 17788
An international standard providing an overview of cloud computing along with cloud computing terms and definitions.
NIST 500-292
A NIST document addressing the adoption of cloud computing by the U.S. federal government.
Metastructure
Protocols and mechanisms that provide an interface between the infrastructure layer and other cloud layers, connecting management and configuration technologies.
Software-Defined Infrastructure
Computing infrastructure that is controlled entirely through software with little or no direct human intervention.
Chaos Engineering
A testing method that deliberately introduces failures and faulty conditions into systems to verify resilience.
Differential Backup
A backup containing all data that has changed since the last full backup; each differential becomes larger until another full backup is performed.
Incremental Backup
A backup containing only data that has changed since the most recent backup; it uses less storage but can require more time to restore because multiple backups may be r