Knowledge Graph

Concept Maps

Explore how terms connect across your learning. Click any concept to see its full relationship map.

1801terms
0links
1809topics

Hub Concepts

Most connected terms

shared

36

Assets

Assets are systems, data, accounts, applications, devices, or services that an organization needs to protect.

Authenticity

Authenticity is confidence that data, users, systems, or messages are genuine and not impersonated or altered.

Availability

Availability means systems and information remain reachable and usable when people or services need them.

CIA Triad

The CIA triad is a model for thinking about confidentiality, integrity, and availability.

CIS Benchmarks

Detailed, consensus-developed configuration guides from the Center for Internet Security that specify how to securely configure operating systems, applications, and devices. They turn 'harden this system' into concrete, checkable settings.

Compensating Controls

Compensating controls are alternative safeguards used when the preferred control cannot be implemented exactly as required.

Confidentiality

Confidentiality means information is only accessible to people, systems, or services that are authorized to see it.

Cybersecurity

The practice of protecting systems, networks, and data from digital attack, unauthorized access, and damage, by preserving the confidentiality, integrity, and availability of information. It is the overarching discipline this whole field sits within.

Data at Rest

Data stored on disk, in databases, backups, or other storage systems.

Data Classification

Labeling data based on sensitivity, value, or handling requirements.

Defender

Anyone whose role is to protect systems, networks, and data from attack, spanning SOC analysts, incident responders, detection engineers, and security architects. The defender's perspective frames how security work is approached.

Defense in Depth

Defense in depth uses multiple layers of controls so one failure does not leave an asset fully exposed.

Detection Engineering

The practice of designing, testing, and improving logic that identifies suspicious activity.

Encapsulation

Wrapping data with protocol headers as it moves through network layers.

Frame

The unit of data at the data-link layer of a network, wrapping a packet with addressing (MAC addresses) for delivery across a local network segment. It is the lowest-level container in the common networking models.

Host

In a URL, the part identifying the server to connect to, typically a domain name or IP address. It tells the browser where to send the request and is key context when judging whether a request goes where expected.

HTTP

HTTP is the protocol browsers and applications use to request and transfer web content.

HTTP Method

The verb in an HTTP request, such as GET, POST, PUT, or DELETE, that indicates the action the client wants to perform. Methods carry security meaning, since some change data and access control must account for which are allowed.

Inherence Factor

An authentication factor based on something you are, a biometric trait like a fingerprint, face, or iris, used to verify identity. It is one of the three classic factor categories alongside knowledge and possession.

Integrity

Integrity means information or systems remain accurate, complete, and protected from unauthorized change.

IP Addresses

Numeric labels assigned to devices on a network that identify them and enable routing of traffic to and from them. They are fundamental to networking and a key data point in detection, investigation, and access control.

IPv4

Internet Protocol version 4: the long-dominant IP addressing scheme using 32-bit addresses written as four numbers (like 192.168.1.1). Its limited address space led to NAT and the development of IPv6.

IPv6

Internet Protocol version 6: the newer IP addressing scheme using 128-bit addresses to vastly expand address space beyond IPv4. Defenders must account for it because it is often enabled by default and can create overlooked attack surface.

Knowledge Factor

An authentication factor based on something you know, such as a password, PIN, or answer to a security question, used to verify identity. It is one of the three classic factor categories alongside possession and inherence.

MAC Addresses

Hardware addresses assigned to network interfaces that identify devices on a local network segment, used for delivery at the data-link layer. They are local in scope, unlike IP addresses, which route across networks.

Network

The interconnected systems and the paths between them over which data flows. Understanding what a network is, its devices, protocols, and connections, is foundational to defending it, monitoring it, and reasoning about attacks.

Non-Repudiation

The property that a party cannot credibly deny having performed an action, since cryptographic or audit evidence ties them to it. It supports accountability alongside the CIA triad's other properties.

OSI Model

A conceptual model that organizes network communication into layers.

Packet

The unit of data routed across networks at the network layer, carrying a payload plus addressing (IP) so it can travel from source to destination. Packets are fundamental units defenders inspect and analyze.

Permission Boundaries

A cloud IAM feature that sets the maximum permissions an identity can have, capping effective access even if broader permissions are granted, used to safely delegate administration without risking over-permissioning.

Port

A port is a numbered communication endpoint used by network protocols to identify which service should receive traffic.

Risk Appetite

The amount and type of risk an organization is willing to tolerate.

Risk Assessment

The structured analysis that identifies risks, evaluates their likelihood and impact, and produces input for treatment decisions. Risk assessment is foundational across security governance, analyst work, and GRC.

Risk Identification

The step of finding and naming the risks an organization faces, through workshops, scans, threat modeling, and other sources, so they can then be analyzed and treated rather than missed entirely.

Risk Register

A record of identified risks, owners, ratings, decisions, and follow-up actions.

Threat Intelligence

Information about adversaries, their motivations, capabilities, and behaviors, that defenders consume to make better decisions about detection, response, and investment. Foundational to modern defense.

grc

23

Audit Firm Selection

Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.

Awareness Program Applied

An applied awareness program turns security guidance into practical habits through role-aware training, reminders, reporting paths, and reinforcement.

BC/DR Applied

Putting business continuity and disaster recovery into practice within a real security program: producing the plans, recovery objectives, and tested procedures rather than treating BC/DR as a theoretical document.

Evidence Practices

The end-to-end practices for handling compliance evidence in a security program, how it is collected, organized, validated, and presented, applied as part of building and running a coherent program in the capstone context.

Evidence Repository

A central, organized store where compliance evidence is kept, control proof, logs, policies, and records, so it is preserved, version-tracked, and easy to retrieve for audits and ongoing compliance.

GDPR Compliance Posture

An organization's overall state of GDPR readiness within a security program, how well its policies, controls, data handling, and evidence actually satisfy GDPR, assessed and improved as part of building the program.

GDPR Data Mapping

Building the inventory of personal data flows required for GDPR, what personal data the organization holds, where it comes from, how it is used, and where it goes, as a foundation for the program's GDPR compliance.

Multi-Framework Control Mapping

Mapping the organization's controls to several frameworks at once so each control's evidence can be claimed against every framework it satisfies, the practical core of running multi-framework compliance.

Multi-Framework Efficiency

The gains in cost, effort, and consistency that come from running multiple frameworks as a coherent program with shared controls and evidence, rather than handling each separately, the payoff of a mature multi-framework approach.

Phishing Simulation

Sending controlled, fake phishing emails to staff to measure susceptibility and reinforce training, a security-awareness tool used carefully to build resilience without blaming or demoralizing employees.

Policy Library Structure

How an organization organizes its set of policies, by topic, hierarchy, ownership, and version, so the library is navigable, complete, and maintainable, an essential GRC and capstone-level deliverable.

Policy Lifecycle

The full cycle policies move through, drafting, approval, communication, operation, review, revision, and eventual retirement, ensuring policies are managed deliberately over time rather than written and forgotten.

Risk Assessment Scope

Defining what an assessment covers, which systems, processes, threats, and time horizon, so its findings are bounded, comparable, and meaningful rather than vague.

Security Program Charter

A foundational document establishing a security program's authority, scope, mission, and structure, signed by executive leadership, that authorizes the program and anchors its governance.

Security Program Presentation

Communicating the security program's status, priorities, and asks to executive and board audiences clearly, persuasively, and concisely, a capstone skill that determines whether the program gets support.

Security Program Scope

What the security program covers, business units, systems, geographies, controls, that defines the program's responsibilities and boundaries so they are clear rather than assumed.

Security Training Program

A managed program that designs, delivers, and measures the security training employees receive, across the awareness and GRC capstone perspectives, so training is intentional rather than ad hoc.

SOC 2 Gap Assessment

An internal assessment that compares current controls against SOC 2 Trust Services Criteria to find gaps before an external audit, so they can be remediated in time.

SOC 2 Policy Coverage

Ensuring an organization's policy set covers all areas SOC 2 expects, access control, change management, vendor risk, incident response, so audit evidence about policies is complete.

SOC 2 Policy Requirements

The specific policies SOC 2 expects to see, with content, ownership, and approvals appropriate to the Trust Services Criteria, that organizations meet to satisfy the policy side of SOC 2.

SOC 2 Program Design

The capstone exercise of designing a complete SOC 2 program, scope, controls, policies, evidence, audit plan, that demonstrates a working approach to satisfying SOC 2 end to end.

Threat-Based Identification

Identifying risks by walking specific threats and asking what they could do, surfacing concrete risks tied to plausible adversary behavior rather than starting from generic categories.

TPRM Applied

Applying third-party risk management in practice end to end, vendor inventory, tiering, due diligence, contracts, monitoring, that builds a working TPRM function rather than a paper one.

cloud

13

Account/Subscription Strategy

An account and subscription strategy defines how cloud accounts or subscriptions are separated, governed, and assigned so ownership, billing, and security boundaries stay clear.

Cloud IAM Architecture

The overall design of identity and access in a cloud environment, how accounts, roles, policies, permission boundaries, and organization-wide controls fit together to enforce least privilege and limit blast radius.

Cloud Native vs Lifted

The distinction between workloads built specifically for the cloud (cloud-native) and those moved from on-premises largely unchanged (lift-and-shift). The two have very different security profiles, tooling, and opportunities.

Cloud Security Architect

The role responsible for designing secure cloud environments, setting the patterns, standards, and guardrails, identity, network, logging, account structure, that workloads are built within. It focuses on design and strategy rather than day-to-day operations.

Cloud Security Engineer

The role that implements, automates, and operates security controls in cloud environments, building guardrails, configuring identity and network protections, integrating security into pipelines, and responding to issues. It is hands-on and build-focused.

Cloud Security Lifecycle

The end-to-end stages of securing cloud workloads over time, design, build, deploy, operate, and respond, with security integrated at each stage rather than bolted on at the end.

Cloud Security Maturity

A measure of how advanced and effective an organization's cloud security practices are, from ad-hoc and reactive toward automated, integrated, and proactive. It helps teams gauge where they stand and what to improve next.

Continuous Evidence Collection

Automatically gathering compliance evidence on an ongoing basis, configurations, logs, access reviews, and tickets, as it is generated, so audits draw on a continuously maintained evidence store rather than a last-minute manual scramble.

Engineer-Developer Interface

The working relationship between cloud security engineers and the developers who build on the cloud, defining how security guardrails, feedback, and requirements reach developers without becoming a blocker to their work.

Engineering vs Operations

The distinction between building cloud security capabilities (engineering, automation, guardrails, tooling) and running them day to day (operations, monitoring, response), two complementary modes within the cloud security engineer role.

IAM Roles vs Users (Cloud)

The distinction between cloud users (long-lived identities for people, with standing credentials) and roles (assumable identities granting temporary credentials), a core cloud-IAM concept where roles are preferred to avoid static, leakable keys.

Image Signing

Cryptographically signing container or VM images so their integrity and origin can be verified before deployment, ensuring an image has not been tampered with and came from a trusted source.

Multi-Cloud vs Single-Cloud

The architectural choice between using one cloud provider or several. Multi-cloud avoids lock-in and adds resilience but increases complexity; single-cloud is simpler but ties the organization to one provider.

soc

7

Data-Driven Hunting

A threat-hunting approach that starts from the data itself, applying analytical techniques like frequency analysis, stack counting, and long-tail analysis to large datasets to surface anomalies worth investigating, rather than starting from a known threat.

Detection Documentation

The written record accompanying a detection, what it detects, the logic and data sources it uses, its assumptions, known false positives, and response guidance, so it can be understood, triaged, tuned, and maintained by others.

Detection Lifecycle

The full arc of a detection from idea to retirement, hypothesis, development, testing, deployment, tuning, monitoring, and eventual retirement, framing detection as something maintained over time rather than written once.

Frequency Analysis

A hunting and analysis technique that counts how often values occur in a dataset, so rare occurrences stand out, on the principle that unusual, infrequent activity is more likely to be malicious than common, high-volume activity.

Indicators of Compromise

Observable artifacts that signal a system may be compromised, such as malicious file hashes, IP addresses, domains, or registry keys, used to detect, hunt for, and confirm known threats across an environment.

Long Tail Analysis

An analytic technique that focuses on the rare, infrequent items in a dataset, the 'long tail', on the principle that uncommon activity is more likely to be malicious than the common bulk. Used in hunting and log analysis.

Post-Incident Review

A structured review of what happened, what worked, and what should improve after an incident.

analyst

1