🛡 Security+ 1.1–1.4 — Summarized Notes


1.1 — Fundamental Security Concepts 🔴 HIGH

CIA Triad

The CIA Triad is the foundation of information security.

Concept

Meaning

Think

Confidentiality

Only authorized subjects can access information

Who can see it?

Integrity

Information cannot be modified without authorization

Can I trust it?

Availability

Authorized users can access information when needed

Can I get to it?

🧠 Memory trick: CIA = Keep it Secret, Correct, and Available

Non-repudiation 🔴

Non-repudiation prevents someone from denying that they performed an action.

Examples:

  • Sending a message

  • Modifying data

  • Deleting information

Think: "You can't say you didn't do it."


2. InfoSec Roles 🟡

Know the basic responsibilities:

  • CSO — Senior security leader

  • CIO — IT leadership, compliance, overall information systems

  • CTO — Technology leadership and aligning IT with business goals

  • ISSO — Maintains the day-to-day security posture of a system

  • SOC — Continuously monitors and defends systems/networks

  • CIRT/CSIRT — Responds to security incidents

SOC vs. CIRT 🔴

SOC = Detect/Monitor

CIRT = Respond

🧠 Think:

SOC sees the fire → CIRT responds to the fire.


3. AAA + Identification 🔴 HIGH

Access control uses AAA:

Identification

"Who are you?"

Usually a username/account name.

Authentication

"Prove it."

You provide credentials/factors such as a password.

Authorization

"What are you allowed to do?"

Determines permissions to:

  • Files

  • Applications

  • Databases

  • Networks

  • Servers

  • Printers

Accounting

"What did you do?"

Records access and activity, including successful and unsuccessful attempts.

Also called auditing.

🧠 Easy sequence:

Identification → Authentication → Authorization → Accounting

Who are you? → Prove it → What can you do? → What did you do?

⚠ Exam trap: Authentication does not determine what you're allowed to access. That's authorization.

Also remember that devices can be subjects, not just people. A laptop may need to authenticate before joining a secured Wi-Fi network.


4. Security Posture & Gap Analysis 🔴

Security Posture

An organization's overall cybersecurity strength and ability to:

  • Prevent threats

  • Detect threats

  • Correct threats

Security Framework

A framework provides organized:

  • Best practices

  • Guidelines

  • Standards

It helps an organization understand its current security status and determine where it needs to improve.

Gap Analysis

Gap analysis = Current state vs. Desired state

It identifies the difference between an organization's current security posture and its desired security goals.

🧠 Think:

"Where am I now?" → "Where do I need to be?" → "What's the gap?"

⚠ Exam trap: A framework helps an organization work toward compliance, but using a framework alone does not automatically make an organization compliant.


5. Zero Trust 🔴 HIGH

Core idea

Never implicitly trust anything.

Zero Trust assumes:

  • Users may be compromised

  • Devices may be compromised

  • Internal networks aren't automatically safe

  • A breach is always possible

Therefore, users, devices, applications, and connections are continuously evaluated and authorized.

Key Zero Trust concepts

Least privilege

Give a subject only the access they actually need.

Adaptive authentication

Access decisions consider context such as:

  • Who is requesting?

  • Where are they coming from?

  • What are they requesting?

  • What is the risk?

Threat scope reduction

Reduce the attack surface by limiting:

  • Points of access

  • Threat vectors

  • Available resources

Policy-driven access control

Access decisions are enforced using policies and rules.


6. Zero Trust Components 🟡/🔴

Policy Engine

Makes the access decision.

Allow, deny, or revoke access.

It can use information such as:

  • Policies

  • Logs

  • Threat intelligence

  • Compliance information

  • SIEM data

Policy Administrator

Carries out the decision.

It communicates with the enforcement point and can establish or terminate sessions.

Policy Enforcement Point (PEP)

Controls the actual connection.

It establishes, monitors, and terminates connections between the subject and resource.

🧠 Memory trick:

Engine = Decide

Administrator = Tell

PEP = Enforce


7. Control Plane vs. Data Plane 🟡

Control Plane

Decides how traffic should move.

Responsible for things such as:

  • Routing

  • Routing protocols

  • NAT tables

  • Network topology

  • Policies/rules

Data Plane

Actually moves the traffic.

🧠 Control = Think

Data = Do

⚠ Don't confuse this with physical network components. These are logical concepts describing network processes.


8. Deception Technologies 🔴

Deception technologies use decoys to attract attackers and gather intelligence.

Honeypot

One decoy system/resource.

Designed to look attractive to attackers.

Honeynet

Multiple interconnected honeypots.

Simulates a network.

Honeyfile

Fake file.

Made to look like it contains sensitive information.

Useful for detecting data theft.

Honeytoken

Fake resource that triggers an alert when accessed.

Could be:

  • User account

  • API key

  • Access token

  • Document

  • Database record

🧠 Memory trick:

Pot = one

Net = network

File = file

Token = credential/resource


9. Security Control Categories 🔴 HIGH

There are 4 categories based on how the control is deployed.

Technical

Implemented using:

  • Hardware

  • Software

  • Firmware

Examples:

  • Firewall

  • Encryption

  • Antivirus

  • ACL

Managerial

Management oversight.

Examples:

  • Security evaluations

  • Risk identification

  • Control effectiveness reviews

Operational

People are primarily responsible for implementing/managing it.

Examples:

  • Security guards

  • Security awareness training

Physical

Protects physical areas/assets.

Examples:

  • Locks

  • Cameras

  • Fences

  • Alarms

  • Lighting

🧠 Memory trick:

Technical = Technology

Managerial = Management

Operational = People

Physical = Physical environment


10. Security Control Types 🔴 HIGH

There are 6 functional types.

Preventative

Stops the incident before it happens.

Examples:

  • Firewall

  • ACL

  • Encryption

  • Antivirus

  • System hardening

Deterrent

Discourages someone from attacking.

Examples:

  • Warning signs

  • Security awareness

  • Policies

  • Visible security controls

Detective

Detects an attack/incident.

Examples:

  • Audit logs

  • IDS

Corrective

Fixes/reduces damage after an incident.

Examples:

  • Backups/recovery

  • Disaster recovery

  • Patch management

Compensating

Alternative control when the primary control isn't viable.

Example:

Primary control can't reasonably be implemented → use another control that provides equivalent or greater protection.

Directive

Tells/guides people what they should do.

Examples:

  • Policies

  • Training

  • SOPs

  • Regulations


🔥 Control Types — Quick Recognition

If the question says...

Think...

Stop/prevent

Preventative

Discourage

Deterrent

Detect/identify

Detective

Fix/recover

Corrective

Alternative/substitute

Compensating

Guide/direct employees

Directive

⚠ Big exam trap:

Category ≠ Type

For example:

A firewall is a technical control and usually preventative.

One describes how it's implemented; the other describes what it does.


11. Physical Security 🔴/🟡

Physical security protects:

  • Buildings

  • Servers

  • Networking equipment

  • Cabling

  • Infrastructure

  • Other physical assets

It can also enforce AAA.

Common physical controls

Bollards

  • Prevent vehicles from entering protected areas.

Mantrap / Access Control Vestibule

  • Two interlocking doors.

  • First door must close before second opens.

  • Helps prevent unauthorized physical entry.

Access badge

  • Physical authentication credential.

  • Can use RFID, NFC, QR codes, or magnetic stripe.

Fencing

  • Prevents or restricts physical access.

Lighting

  • Improves visibility and can deter intrusion.

Video surveillance

  • Monitors/records physical activity.

  • Can provide evidence.

Security guards

  • Deter and respond to physical threats.


12. Security Sensors 🟡

Motion

Detects movement.

Audio/noise

Detects sound or vibration.

Example: breaking glass

Circuit

Detects an open/closed state.

Example: door or window

PIR — Passive Infrared

Detects heat energy emitted by objects.

Pressure

Detects weight/pressure.

Example: floor mat.

Microwave

Uses microwave signals to detect movement.

Ultrasonic

Uses ultrasonic sound waves to detect movement.


13. Change Management 🔴 HIGH

Change management = controlled process for making changes while minimizing disruption and security risk.

Examples:

  • Software updates

  • OS/firmware upgrades

  • Security control installation

  • Hardware upgrades

  • Network configuration changes

  • Cloud migrations


Change Management Process

Know the important concepts:

Change Request / RFC

Formally proposes what needs to change.

Impact Analysis

Determines how the change could affect:

  • Users

  • Business processes

  • Systems

  • Security

  • Downtime

CAB — Change Advisory Board

Reviews complex/high-risk changes and helps:

  • Assess

  • Prioritize

  • Authorize

  • Schedule

Test Environment

Test the change before deploying it fully.

Backout Plan 🔴

Defines how to return to the previous/original state if the change fails.

🧠 Exam clue:

"The update caused problems. How do we restore the previous configuration?"

Backout plan.


14. Other Change Management Concepts 🟡

SOP

Standard Operating Procedure

Detailed step-by-step instructions for performing a task consistently.

Maintenance Window

Scheduled period when maintenance/change can occur with minimal business disruption.

Downtime

Period when a system or business process is unavailable.

Legacy Application

Older software that may be:

  • Outdated

  • Specialized

  • Unsupported

  • Business-critical

Legacy applications require careful research before making changes.

Dependency

One application/service relies on another.

Example:

Application A requires Service B to work.

If B goes down, A may also stop working.


15. Allow Lists vs. Deny Lists 🟡

Allow List

Only approved items are allowed.

More restrictive.

Deny List

Specified items are blocked.

Everything not on the list is generally allowed.

🧠 Memory trick:

Allow = "Only these."
Deny = "Not these."


⭐ What I'd Focus on First

If you were studying this chapter tonight, I'd prioritize:

🔴 Must Know

  1. CIA Triad

  2. Non-repudiation

  3. Identification vs Authentication vs Authorization vs Accounting

  4. Security posture + gap analysis

  5. Zero Trust

  6. Policy Engine / Administrator / PEP

  7. Honeypot / Honeynet / Honeyfile / Honeytoken

  8. 4 security control categories

  9. 6 security control types

  10. Preventative / Detective / Corrective / Compensating

  11. Change request / impact analysis / CAB / backout plan

  12. Allow list vs deny list

🟡 Know Well

  • InfoSec roles

  • Control plane vs data plane

  • Physical security controls

  • Security sensors

  • SOP

  • Maintenance windows

  • Legacy applications

  • Dependencies

The big picture of this chapter is basically:

CIA → AAA → Zero Trust → Security Controls → Physical Security → Change Management