Knowledge Graph
Concept Maps
Explore how terms connect across your learning. Click any concept to see its full relationship map.
Hub Concepts
Most connected termsAccount/Subscription Strategy
An account and subscription strategy defines how cloud accounts or subscriptions are separated, governed, and assigned so ownership, billing, and security boundaries stay clear.
Assets
Assets are systems, data, accounts, applications, devices, or services that an organization needs to protect.
Audit Firm Selection
Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.
Authenticity
Authenticity is confidence that data, users, systems, or messages are genuine and not impersonated or altered.
Availability
Availability means systems and information remain reachable and usable when people or services need them.
Awareness Program Applied
An applied awareness program turns security guidance into practical habits through role-aware training, reminders, reporting paths, and reinforcement.
shared
36Assets
Assets are systems, data, accounts, applications, devices, or services that an organization needs to protect.
Authenticity
Authenticity is confidence that data, users, systems, or messages are genuine and not impersonated or altered.
Availability
Availability means systems and information remain reachable and usable when people or services need them.
CIA Triad
The CIA triad is a model for thinking about confidentiality, integrity, and availability.
CIS Benchmarks
Detailed, consensus-developed configuration guides from the Center for Internet Security that specify how to securely configure operating systems, applications, and devices. They turn 'harden this system' into concrete, checkable settings.
Compensating Controls
Compensating controls are alternative safeguards used when the preferred control cannot be implemented exactly as required.
Confidentiality
Confidentiality means information is only accessible to people, systems, or services that are authorized to see it.
Cybersecurity
The practice of protecting systems, networks, and data from digital attack, unauthorized access, and damage, by preserving the confidentiality, integrity, and availability of information. It is the overarching discipline this whole field sits within.
Data at Rest
Data stored on disk, in databases, backups, or other storage systems.
Data Classification
Labeling data based on sensitivity, value, or handling requirements.
Defender
Anyone whose role is to protect systems, networks, and data from attack, spanning SOC analysts, incident responders, detection engineers, and security architects. The defender's perspective frames how security work is approached.
Defense in Depth
Defense in depth uses multiple layers of controls so one failure does not leave an asset fully exposed.
Detection Engineering
The practice of designing, testing, and improving logic that identifies suspicious activity.
Encapsulation
Wrapping data with protocol headers as it moves through network layers.
Frame
The unit of data at the data-link layer of a network, wrapping a packet with addressing (MAC addresses) for delivery across a local network segment. It is the lowest-level container in the common networking models.
Host
In a URL, the part identifying the server to connect to, typically a domain name or IP address. It tells the browser where to send the request and is key context when judging whether a request goes where expected.
HTTP
HTTP is the protocol browsers and applications use to request and transfer web content.
HTTP Method
The verb in an HTTP request, such as GET, POST, PUT, or DELETE, that indicates the action the client wants to perform. Methods carry security meaning, since some change data and access control must account for which are allowed.
Inherence Factor
An authentication factor based on something you are, a biometric trait like a fingerprint, face, or iris, used to verify identity. It is one of the three classic factor categories alongside knowledge and possession.
Integrity
Integrity means information or systems remain accurate, complete, and protected from unauthorized change.
IP Addresses
Numeric labels assigned to devices on a network that identify them and enable routing of traffic to and from them. They are fundamental to networking and a key data point in detection, investigation, and access control.
IPv4
Internet Protocol version 4: the long-dominant IP addressing scheme using 32-bit addresses written as four numbers (like 192.168.1.1). Its limited address space led to NAT and the development of IPv6.
IPv6
Internet Protocol version 6: the newer IP addressing scheme using 128-bit addresses to vastly expand address space beyond IPv4. Defenders must account for it because it is often enabled by default and can create overlooked attack surface.
Knowledge Factor
An authentication factor based on something you know, such as a password, PIN, or answer to a security question, used to verify identity. It is one of the three classic factor categories alongside possession and inherence.
MAC Addresses
Hardware addresses assigned to network interfaces that identify devices on a local network segment, used for delivery at the data-link layer. They are local in scope, unlike IP addresses, which route across networks.
Network
The interconnected systems and the paths between them over which data flows. Understanding what a network is, its devices, protocols, and connections, is foundational to defending it, monitoring it, and reasoning about attacks.
Non-Repudiation
The property that a party cannot credibly deny having performed an action, since cryptographic or audit evidence ties them to it. It supports accountability alongside the CIA triad's other properties.
OSI Model
A conceptual model that organizes network communication into layers.
Packet
The unit of data routed across networks at the network layer, carrying a payload plus addressing (IP) so it can travel from source to destination. Packets are fundamental units defenders inspect and analyze.
Permission Boundaries
A cloud IAM feature that sets the maximum permissions an identity can have, capping effective access even if broader permissions are granted, used to safely delegate administration without risking over-permissioning.
Port
A port is a numbered communication endpoint used by network protocols to identify which service should receive traffic.
Risk Appetite
The amount and type of risk an organization is willing to tolerate.
Risk Assessment
The structured analysis that identifies risks, evaluates their likelihood and impact, and produces input for treatment decisions. Risk assessment is foundational across security governance, analyst work, and GRC.
Risk Identification
The step of finding and naming the risks an organization faces, through workshops, scans, threat modeling, and other sources, so they can then be analyzed and treated rather than missed entirely.
Risk Register
A record of identified risks, owners, ratings, decisions, and follow-up actions.
Threat Intelligence
Information about adversaries, their motivations, capabilities, and behaviors, that defenders consume to make better decisions about detection, response, and investment. Foundational to modern defense.
grc
23Audit Firm Selection
Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.
Awareness Program Applied
An applied awareness program turns security guidance into practical habits through role-aware training, reminders, reporting paths, and reinforcement.
BC/DR Applied
Putting business continuity and disaster recovery into practice within a real security program: producing the plans, recovery objectives, and tested procedures rather than treating BC/DR as a theoretical document.
Evidence Practices
The end-to-end practices for handling compliance evidence in a security program, how it is collected, organized, validated, and presented, applied as part of building and running a coherent program in the capstone context.
Evidence Repository
A central, organized store where compliance evidence is kept, control proof, logs, policies, and records, so it is preserved, version-tracked, and easy to retrieve for audits and ongoing compliance.
GDPR Compliance Posture
An organization's overall state of GDPR readiness within a security program, how well its policies, controls, data handling, and evidence actually satisfy GDPR, assessed and improved as part of building the program.
GDPR Data Mapping
Building the inventory of personal data flows required for GDPR, what personal data the organization holds, where it comes from, how it is used, and where it goes, as a foundation for the program's GDPR compliance.
Multi-Framework Control Mapping
Mapping the organization's controls to several frameworks at once so each control's evidence can be claimed against every framework it satisfies, the practical core of running multi-framework compliance.
Multi-Framework Efficiency
The gains in cost, effort, and consistency that come from running multiple frameworks as a coherent program with shared controls and evidence, rather than handling each separately, the payoff of a mature multi-framework approach.
Phishing Simulation
Sending controlled, fake phishing emails to staff to measure susceptibility and reinforce training, a security-awareness tool used carefully to build resilience without blaming or demoralizing employees.
Policy Library Structure
How an organization organizes its set of policies, by topic, hierarchy, ownership, and version, so the library is navigable, complete, and maintainable, an essential GRC and capstone-level deliverable.
Policy Lifecycle
The full cycle policies move through, drafting, approval, communication, operation, review, revision, and eventual retirement, ensuring policies are managed deliberately over time rather than written and forgotten.
Risk Assessment Scope
Defining what an assessment covers, which systems, processes, threats, and time horizon, so its findings are bounded, comparable, and meaningful rather than vague.
Security Program Charter
A foundational document establishing a security program's authority, scope, mission, and structure, signed by executive leadership, that authorizes the program and anchors its governance.
Security Program Presentation
Communicating the security program's status, priorities, and asks to executive and board audiences clearly, persuasively, and concisely, a capstone skill that determines whether the program gets support.
Security Program Scope
What the security program covers, business units, systems, geographies, controls, that defines the program's responsibilities and boundaries so they are clear rather than assumed.
Security Training Program
A managed program that designs, delivers, and measures the security training employees receive, across the awareness and GRC capstone perspectives, so training is intentional rather than ad hoc.
SOC 2 Gap Assessment
An internal assessment that compares current controls against SOC 2 Trust Services Criteria to find gaps before an external audit, so they can be remediated in time.
SOC 2 Policy Coverage
Ensuring an organization's policy set covers all areas SOC 2 expects, access control, change management, vendor risk, incident response, so audit evidence about policies is complete.
SOC 2 Policy Requirements
The specific policies SOC 2 expects to see, with content, ownership, and approvals appropriate to the Trust Services Criteria, that organizations meet to satisfy the policy side of SOC 2.
SOC 2 Program Design
The capstone exercise of designing a complete SOC 2 program, scope, controls, policies, evidence, audit plan, that demonstrates a working approach to satisfying SOC 2 end to end.
Threat-Based Identification
Identifying risks by walking specific threats and asking what they could do, surfacing concrete risks tied to plausible adversary behavior rather than starting from generic categories.
TPRM Applied
Applying third-party risk management in practice end to end, vendor inventory, tiering, due diligence, contracts, monitoring, that builds a working TPRM function rather than a paper one.
cloud
13Account/Subscription Strategy
An account and subscription strategy defines how cloud accounts or subscriptions are separated, governed, and assigned so ownership, billing, and security boundaries stay clear.
Cloud IAM Architecture
The overall design of identity and access in a cloud environment, how accounts, roles, policies, permission boundaries, and organization-wide controls fit together to enforce least privilege and limit blast radius.
Cloud Native vs Lifted
The distinction between workloads built specifically for the cloud (cloud-native) and those moved from on-premises largely unchanged (lift-and-shift). The two have very different security profiles, tooling, and opportunities.
Cloud Security Architect
The role responsible for designing secure cloud environments, setting the patterns, standards, and guardrails, identity, network, logging, account structure, that workloads are built within. It focuses on design and strategy rather than day-to-day operations.
Cloud Security Engineer
The role that implements, automates, and operates security controls in cloud environments, building guardrails, configuring identity and network protections, integrating security into pipelines, and responding to issues. It is hands-on and build-focused.
Cloud Security Lifecycle
The end-to-end stages of securing cloud workloads over time, design, build, deploy, operate, and respond, with security integrated at each stage rather than bolted on at the end.
Cloud Security Maturity
A measure of how advanced and effective an organization's cloud security practices are, from ad-hoc and reactive toward automated, integrated, and proactive. It helps teams gauge where they stand and what to improve next.
Continuous Evidence Collection
Automatically gathering compliance evidence on an ongoing basis, configurations, logs, access reviews, and tickets, as it is generated, so audits draw on a continuously maintained evidence store rather than a last-minute manual scramble.
Engineer-Developer Interface
The working relationship between cloud security engineers and the developers who build on the cloud, defining how security guardrails, feedback, and requirements reach developers without becoming a blocker to their work.
Engineering vs Operations
The distinction between building cloud security capabilities (engineering, automation, guardrails, tooling) and running them day to day (operations, monitoring, response), two complementary modes within the cloud security engineer role.
IAM Roles vs Users (Cloud)
The distinction between cloud users (long-lived identities for people, with standing credentials) and roles (assumable identities granting temporary credentials), a core cloud-IAM concept where roles are preferred to avoid static, leakable keys.
Image Signing
Cryptographically signing container or VM images so their integrity and origin can be verified before deployment, ensuring an image has not been tampered with and came from a trusted source.
Multi-Cloud vs Single-Cloud
The architectural choice between using one cloud provider or several. Multi-cloud avoids lock-in and adds resilience but increases complexity; single-cloud is simpler but ties the organization to one provider.
soc
7Data-Driven Hunting
A threat-hunting approach that starts from the data itself, applying analytical techniques like frequency analysis, stack counting, and long-tail analysis to large datasets to surface anomalies worth investigating, rather than starting from a known threat.
Detection Documentation
The written record accompanying a detection, what it detects, the logic and data sources it uses, its assumptions, known false positives, and response guidance, so it can be understood, triaged, tuned, and maintained by others.
Detection Lifecycle
The full arc of a detection from idea to retirement, hypothesis, development, testing, deployment, tuning, monitoring, and eventual retirement, framing detection as something maintained over time rather than written once.
Frequency Analysis
A hunting and analysis technique that counts how often values occur in a dataset, so rare occurrences stand out, on the principle that unusual, infrequent activity is more likely to be malicious than common, high-volume activity.
Indicators of Compromise
Observable artifacts that signal a system may be compromised, such as malicious file hashes, IP addresses, domains, or registry keys, used to detect, hunt for, and confirm known threats across an environment.
Long Tail Analysis
An analytic technique that focuses on the rare, infrequent items in a dataset, the 'long tail', on the principle that uncommon activity is more likely to be malicious than the common bulk. Used in hunting and log analysis.
Post-Incident Review
A structured review of what happened, what worked, and what should improve after an incident.
