1/99
A comprehensive vocabulary set of 100 flashcards reviewing cybersecurity fundamentals, control types, data management, supply chain risks, governance, frameworks, risk quantitative metrics, and emerging AI security concepts based on lecture notes.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Primary Strategic Objectives (CyberSecurity)
The four key business objectives achieved by cybersecurity: protecting information assets, individual privacy, legal position, and public image.
Confidentiality
Ensures that only authorized individuals are allowed access to sensitive information with legitimate purposes.
Integrity
Ensures that only authorized modifications are made to information or systems.
Availability
Ensures that information and systems are ready to meet the needs of legitimate users at the time those users request them.
C-I-A Triad
The core security goals consisting of Confidentiality, Integrity, and Availability.
D-A-D
The three breaches of cybersecurity: Disclosure (confidentiality), Alteration (integrity), and Destruction (availability).
Disclosure
The exposure of sensitive information to unauthorized individuals (data loss), representing a violation of confidentiality.
Alteration
The unauthorized modification of information, representing a violation of integrity.
Destruction
The disruption of an authorized user's legitimate access to information, representing a violation of availability.
Managerial Controls
Security controls that give oversight of the system.
Operational Controls
Security controls that depend on a person for implementation.
Technical Controls
Security controls implemented in information technology, such as operating systems, software, and security appliances.
Preventive Control
A security control that stops crime in the first place by physically or logically restricting unauthorized access before an attack occurs.
Detective Control
A security control operating during an attack that identifies and records any attempted or successful intrusion.
Corrective and Recovery Control
A security control operating after an attack that responds to and fixes an incident and may also prevent its reoccurrence.
Deterrent Control
A security control operating before an attack that attempts to discourage individuals from committing a security breach.
Physical Control
A security control usually considered an operational control by NIST and CompTIA that operates during physical events.
Compensating Control
Alternative controls used when a primary prescribed control is not feasible.
OECD Principles of Privacy
Core privacy principles: Collection Limitation, Data Quality, Purpose Specification, Use Limitation, Security Safeguards, Openness, Individual Participation, and Accountability.
Personally Identifiable Information (PII)
Personal information that can be used to personally identify an individual, usually comprising two or more pieces of personal data.
Electronic Health Records (EHR)
Digital patient health records categorized under healthcare PII.
Protected Health Information (PHI)
Healthcare-specific PII subject to specialized health privacy regulations.
Data at Rest
Data stored in persistent storage media, protected using encryption and access control lists.
Data in Transit
Data transmitted over a network, protected using transport encryption such as TLS or IPSec.
Data in Use
Data present in volatile memory, such as system RAM or CPU registers and cache.
Data Exfiltration
Deliberately moving sensitive data from inside an organization to outside an organization's perimeter without permission.
Steganography
A method of hiding data within other data to conceal information during transfer.
Data Loss Prevention (DLP)
Safeguards comprising hardware and software elements designed to prevent sensitive data from falling into unauthorized hands.
De-identification
The process of removing personal information from shared datasets.
Anonymization
The process of modifying data to remove or obscure PII, making it impossible to identify individuals from a dataset.
Tokenization
A database deidentification method that replaces field values with random tokens linked to a separate vault source.
Data Masking
Whole or partial redaction of strings using format-preserving masks, which is irreversible.
Content Aware DLP Technologies
Inspection technologies used to classify information content across Network, Host/Endpoint, Cloud-based, and Discovery states.
Media Handling Controls
Physical and logical safeguards including marking, handling, storing, declassifying, and disposing of media containing sensitive data.
Pulping
A paper disposal method that recycles paper into pulp.
Platter Destruction
The most secure hard drive disposal method involving physical shredding or pulverizing of drive platters.
Degaussing
A demagnetizing technique that renders magnetic media unusable, but does not work on SSD or flash storage.
Secure Erasing
A sanitization technique that wipes an entire drive (effective for SSDs) while keeping the drive reusable.
Wiping / Erasure
A disposal technique of rewriting storage positions with binary 1's and 0's to sanitize reusable media.
NIST SP800-88
NIST publication titled Guidelines for Media Sanitization.
Governance
Board of Directors function that evaluates stakeholder needs, directs prioritization, and monitors performance against objectives.
Management
Executive Management function (e.g., CEO, COO) that plans, builds, runs, and monitors operational activities.
COBIT 5
A framework separating enterprise Governance (Evaluate, Direct, Monitor) from Management (Plan, Build, Run, Monitor).
Governance, Risk, and Compliance (GRC)
An integrated enterprise approach combining executive oversight mechanisms, risk tolerance setting, and regulatory compliance monitoring.
Risk Management
Process by which an organization sets risk appetite, identifies potential risks and impacts, and prioritizes mitigation based on business objectives.
Compliance
Process that records and monitors controls needed to ensure that policies, standards, procedures, and legal requirements are adhered to.
Executive Management Role
Role holding ultimate responsibility for information security, forming steering oversight committees, and assigning ownership.
Information Security Officer
Role responsible for protecting enterprise information assets and facilitating the overall information security program.
Data Owner
Role bearing primary responsibility for determining data classification levels, assigning safeguards, and maintaining data accuracy/integrity.
Custodians (Technology Providers)
Role responsible for assisting with information security implementation and providing secure IT infrastructure for applications.
IT Auditors
Independent evaluators assessing the appropriateness and adequacy of security controls based on compliance and risk.
RACI Matrix
Responsibility Assignment Matrix specifying roles as Responsible, Accountable, Consulted, or Informed for project tasks.
CyberSecurity Policy
Document defining management's guidance and mandatory requirements for implementing information security.
Master Service Agreement (MSA)
Contract establishing the foundation for long-term business relationships by defining future engagement terms and obligations.
Service Level Agreement (SLA)
Legally binding contract defining service behavior, operational expectations, and measurable quality standards.
Operating Level Agreement (OLA)
An internal organizational document detailing relationships between internal departments supporting business activities.
Statement of Work (SOW)
An agreement between a client and service provider defining exact project scope, deliverables, and exclusions.
Memorandum of Understanding (MOU)
A non-binding document outlining participant responsibilities in an agreement between two organizations.
Interconnection Security Agreement (ISA)
Document describing technical interconnection requirements, data sensitivity, and data flow when sharing information between organizations (NIST SP800-47).
Interoperability Agreement (IA)
Agreement between organizations (commonly subsidiary companies) to work together to facilitate mutual data exchange.
Business Partnership Agreement (BPA)
Written agreement detailing business partner relationships, profit/loss shares, obligations, and partner exit conditions.
Reciprocal Agreement (RA)
Agreement where two organizations with similar tech infrastructures act as disaster recovery alternate sites for each other.
Non-Disclosure Agreement (NDA)
Contract promising to protect confidential secret information disclosed during business or employment relationships.
Configuration Management
Discipline ensuring that all hardware, software, and IT assets owned by an organization are known, controlled, and tracked.
Configuration Management Database (CMDB)
Centralized database detailing records of all IT assets, software versions, configurations, and interrelationships.
IT Asset Inventory
Inventory of physical/virtual assets (hardware, software, licenses) used primarily for asset tracking, compliance, and financial management.
Change Control
Process ensuring that all IT modifications are approved, documented, tested, and accepted.
Software Supply Chain Attack
Attempt to exploit weaknesses in software development stages (source code, build process, update server) to plant malware.
Software Bill of Materials (SBOM)
Comprehensive inventory list of all application software components and dependencies used in software supply chain tracking.
CISA
Cybersecurity & Infrastructure Security Agency, part of Homeland Security providing security guidance and alerts.
Risk
A function of the likelihood of a threat exploiting a vulnerability and the resulting impact severity on the organization.
Asset
Any resource of value to an organization.
Threat
A potential danger (accidental trigger or intentional exploit) to an asset if a threat-agent takes advantage of a vulnerability.
Threat-Agent
Anything or anyone (actor, vector, natural disaster) that has the potential to cause a threat.
Vulnerability
A flaw or weakness in an asset or security system.
Exposure
An opportunity for a threat to cause loss due to an unresolved vulnerability.
Exploit / Event
An instance of loss experienced or execution of an attack targeting a vulnerability.
Safeguard
Technical or non-technical risk mitigation mechanism or countermeasure.
Passive Man-Made Threat
Threat involving gathering or intercepting information without interacting directly with target systems, leaving no trace.
Active Man-Made Threat
Threat involving direct interaction with target systems, typically leaving a trail or trace of activity.
Script Kiddies
Unskilled threat actors who use existing computer scripts or code without deep expertise or significant funding.
Hacktivist
Threat actor launching attacks to support an activist movement or further a social/political cause.
Malicious Insider
An employee or authorized user with legitimate access who abuses privileges out of greed, revenge, or coercion.
Nation-State Actors
Highly organized and funded threat actors sponsored by a government entity for political or strategic objectives.
Black Hat
An unauthorized hacker performing malicious criminal activities.
White Hat
An authorized security professional (ethical hacker) working within the law to protect organizations.
Gray Hat
A semi-authorized hacker who may violate ethical standards or laws without malicious intent.
Total Risk (Inherent Risk)
Risk existing before security safeguards are applied, calculated as Total Risk=Threats×Vulnerability×Asset Value.
Residual Risk
The risk remaining after security safeguards and mitigations have been applied.
Accepted Risk
Choice made by an organization to tolerate risk without implementing additional security safeguards.
Single Loss Expectancy (SLE)
Monetary loss expected from a single realized threat, calculated as SLE=Asset Value (AV)×Exposure Factor (EF).
Exposure Factor (EF)
The percentage of loss a realized threat could cause to a specific asset.
Annualized Rate of Occurrence (ARO)
The estimated frequency or number of times a specific threat takes place during a single year.
Annualized Loss Expectancy (ALE)
Estimated annual loss from a risk, calculated as ALE=SLE×ARO.
Qualitative Risk Analysis
Subjective risk assessment assigning non-monetary ratings (e.g., Low, Medium, High) based on subject matter expert input.
Risk Register
Central repository/worksheet detailing identified risks, risk owners, likelihood, impact, scores, and mitigation steps.
NIST Risk Management Framework (RMF)
A 6-step lifecycle process defined in NIST SP 800-37: Categorize, Select, Implement, Assess, Authorize, and Monitor.
Business Impact Analysis (BIA)
Initial BC/DR process identifying critical business assets, evaluating downtime operational impact, and establishing recovery priorities.
Maximum Tolerable Downtime (MTD)
Estimated maximum duration a system can remain inoperable before impact on an organization becomes severe.
Recovery Time Objective (RTO)
Maximum acceptable period of time that a business process or IT system can be unavailable during a disaster.