Knowledge Graph
Concept Maps
Explore how terms connect across your learning. Click any concept to see its full relationship map.
grc
33Asset-Based Identification
A risk identification approach that starts from the organization's important assets, such as systems, data, and services, and asks what threatens each one. It anchors risk discovery in what actually matters to protect.
Audit Categories
The major kinds of audit, such as financial, operational, compliance, and IT or cybersecurity audits, each with a different objective and scope. Knowing the category sets expectations for what an audit will and will not cover.
Audit Discipline
The body of professional rigor that defines good auditing: systematic methodology, evidence-based conclusions, objectivity, and adherence to standards. It is what makes audit results credible and repeatable.
Audit Ethics
The ethical obligations that govern auditors, including objectivity, integrity, confidentiality, and avoiding conflicts of interest. Because others rely on audit conclusions, ethical lapses undermine the entire value of the work.
Audit Firm Selection
Audit firm selection is the process of choosing an independent assessment partner based on scope, expertise, independence, and the compliance framework being assessed.
Audit Independence
The auditor's freedom from influence or conflicts that could bias their conclusions, in both fact and appearance. Without independence, an audit's assurance is worthless because its objectivity cannot be trusted.
Audit Profession
The field of auditing as a recognized professional discipline, with its own standards, ethics, certifications, and career structure. Membership implies adhering to shared expectations of competence and integrity.
Audit Quality
How well an audit achieves its purpose: conclusions that are accurate, well-evidenced, and relevant, reached through sound methodology and objectivity. Poor quality erodes the trust that makes audit useful.
Audit Standards
The formal frameworks that define how audits must be conducted, such as the IIA Standards for internal audit or ISACA's standards for IT audit. They set expectations for independence, evidence, documentation, and reporting.
Audit Universe
The complete set of areas, processes, and systems that could potentially be audited in an organization. It is the master list from which a risk-based audit plan selects what to audit and when.
Auditor Skills
The competencies an effective auditor needs, combining technical knowledge and methodology with communication, skepticism, and judgment. They determine how reliably an auditor can find and explain real issues.
Awareness Program Applied
An applied awareness program turns security guidance into practical habits through role-aware training, reminders, reporting paths, and reinforcement.
BC/DR Applied
Putting business continuity and disaster recovery into practice within a real security program: producing the plans, recovery objectives, and tested procedures rather than treating BC/DR as a theoretical document.
Comprehensive Identification
A thorough approach to finding risks that combines multiple techniques, asset-based, scenario-based, threat-based, and external sources, so the organization surfaces a complete picture of its risks rather than missing whole categories.
Evidence Practices
The end-to-end practices for handling compliance evidence in a security program, how it is collected, organized, validated, and presented, applied as part of building and running a coherent program in the capstone context.
GDPR Compliance Posture
An organization's overall state of GDPR readiness within a security program, how well its policies, controls, data handling, and evidence actually satisfy GDPR, assessed and improved as part of building the program.
GDPR Data Mapping
Building the inventory of personal data flows required for GDPR, what personal data the organization holds, where it comes from, how it is used, and where it goes, as a foundation for the program's GDPR compliance.
Multi-Framework Control Mapping
Mapping the organization's controls to several frameworks at once so each control's evidence can be claimed against every framework it satisfies, the practical core of running multi-framework compliance.
Multi-Framework Efficiency
The gains in cost, effort, and consistency that come from running multiple frameworks as a coherent program with shared controls and evidence, rather than handling each separately, the payoff of a mature multi-framework approach.
Phishing Simulation
Sending controlled, fake phishing emails to staff to measure susceptibility and reinforce training, a security-awareness tool used carefully to build resilience without blaming or demoralizing employees.
Policy Library Structure
How an organization organizes its set of policies, by topic, hierarchy, ownership, and version, so the library is navigable, complete, and maintainable, an essential GRC and capstone-level deliverable.
Policy Lifecycle
The full cycle policies move through, drafting, approval, communication, operation, review, revision, and eventual retirement, ensuring policies are managed deliberately over time rather than written and forgotten.
Risk Assessment Scope
Defining what an assessment covers, which systems, processes, threats, and time horizon, so its findings are bounded, comparable, and meaningful rather than vague.
Security Program Charter
A foundational document establishing a security program's authority, scope, mission, and structure, signed by executive leadership, that authorizes the program and anchors its governance.
Security Program Presentation
Communicating the security program's status, priorities, and asks to executive and board audiences clearly, persuasively, and concisely, a capstone skill that determines whether the program gets support.
Security Program Scope
What the security program covers, business units, systems, geographies, controls, that defines the program's responsibilities and boundaries so they are clear rather than assumed.
Security Training Program
A managed program that designs, delivers, and measures the security training employees receive, across the awareness and GRC capstone perspectives, so training is intentional rather than ad hoc.
SOC 2 Gap Assessment
An internal assessment that compares current controls against SOC 2 Trust Services Criteria to find gaps before an external audit, so they can be remediated in time.
SOC 2 Policy Coverage
Ensuring an organization's policy set covers all areas SOC 2 expects, access control, change management, vendor risk, incident response, so audit evidence about policies is complete.
SOC 2 Policy Requirements
The specific policies SOC 2 expects to see, with content, ownership, and approvals appropriate to the Trust Services Criteria, that organizations meet to satisfy the policy side of SOC 2.
SOC 2 Program Design
The capstone exercise of designing a complete SOC 2 program, scope, controls, policies, evidence, audit plan, that demonstrates a working approach to satisfying SOC 2 end to end.
Threat-Based Identification
Identifying risks by walking specific threats and asking what they could do, surfacing concrete risks tied to plausible adversary behavior rather than starting from generic categories.
TPRM Applied
Applying third-party risk management in practice end to end, vendor inventory, tiering, due diligence, contracts, monitoring, that builds a working TPRM function rather than a paper one.
cloud
32Account/Subscription Strategy
An account and subscription strategy defines how cloud accounts or subscriptions are separated, governed, and assigned so ownership, billing, and security boundaries stay clear.
Admission Control
A gatekeeping step that checks whether a workload, image, or change is allowed to run before it is admitted into an environment, blocking anything that fails policy such as an unsigned container image or one with critical vulnerabilities.
Admission Controllers
Kubernetes components that intercept requests to the cluster's API server and can validate or modify them before objects are created, letting security teams enforce policy such as blocking privileged pods or requiring trusted images.
API Gateway Security
Securing the API gateway, the entry point that sits in front of backend services and APIs, by enforcing authentication, authorization, rate limiting, and input checks centrally so individual services do not each have to.
Cloud Compliance Landscape
The overall set of regulations, standards, and certification schemes that apply to cloud-hosted systems, such as FedRAMP, ISO 27001/27017, SOC 2, GDPR, and HIPAA, and how they interact under the shared-responsibility model.
Cloud Compliance Tools
Software that helps manage cloud compliance by mapping controls to frameworks, collecting evidence automatically, monitoring for drift, and producing audit-ready reports. They make multi-framework compliance feasible at cloud scale and speed.
Cloud IAM Architecture
The overall design of identity and access in a cloud environment, how accounts, roles, policies, permission boundaries, and organization-wide controls fit together to enforce least privilege and limit blast radius.
Cloud Native Computing Foundation
The open-source organization (CNCF) that hosts and governs many foundational cloud-native projects, including Kubernetes. It stewards the ecosystem of container, orchestration, and cloud-native tooling that modern infrastructure is built on.
Cloud Native vs Lifted
The distinction between workloads built specifically for the cloud (cloud-native) and those moved from on-premises largely unchanged (lift-and-shift). The two have very different security profiles, tooling, and opportunities.
Cloud Provider Compliance
The certifications and attestations a cloud provider holds for its own infrastructure and services, such as SOC 2, ISO 27001, or FedRAMP authorizations, which customers can rely on for the provider's share of the shared-responsibility model.
Cloud Security Architect
The role responsible for designing secure cloud environments, setting the patterns, standards, and guardrails, identity, network, logging, account structure, that workloads are built within. It focuses on design and strategy rather than day-to-day operations.
Cloud Security Engineer
The role that implements, automates, and operates security controls in cloud environments, building guardrails, configuring identity and network protections, integrating security into pipelines, and responding to issues. It is hands-on and build-focused.
Cloud Security Lifecycle
The end-to-end stages of securing cloud workloads over time, design, build, deploy, operate, and respond, with security integrated at each stage rather than bolted on at the end.
Cloud Security Maturity
A measure of how advanced and effective an organization's cloud security practices are, from ad-hoc and reactive toward automated, integrated, and proactive. It helps teams gauge where they stand and what to improve next.
Cloud VM Lifecycle
The stages a cloud virtual machine passes through, from a hardened base image, through provisioning and configuration, to running, patching, and decommissioning, with security applied at each stage to keep workloads protected over time.
Cloud-Native Architecture
The structural design of cloud-native systems, microservices, containers, orchestration, declarative infrastructure, and automated delivery, that emphasizes loosely coupled, independently deployable, elastically scaled components.
Cloud-Native Security Model
The overall approach to securing cloud-native systems, layering identity-based access, network policy and segmentation, admission control, supply-chain security, runtime protection, and observability across the orchestrated, containerized stack.
Compliance vs Security
The distinction between meeting a framework's requirements (compliance) and actually being protected against attack (security). An organization can be fully compliant yet insecure, and secure yet not formally compliant; the two overlap but are not the same.
Conditional Access (Cloud)
Conditional access as implemented and operated by a cloud security engineer, the policies in a cloud identity platform that gate access to cloud resources based on risk, device, location, and identity signals.
Container Compliance
Ensuring container images and running containers meet security and configuration standards, scanned for vulnerabilities, built from approved bases, signed, and configured to benchmarks, so they satisfy both internal policy and external requirements.
Container Registry Security
Protecting the container registry through access control, image signing and verification, vulnerability scanning of stored images, and provenance checks, so only trusted, clean images can be stored and deployed.
Container Runtime Protection
Securing containers while they are running by monitoring their behavior and blocking malicious activity in real time, such as detecting and stopping a container escape, unexpected process execution, or anomalous network connection.
Container Security Lifecycle
The stages of securing a container over its life, build (hardened, scanned, signed images), ship (secure registry), and run (admission control and runtime protection), with security applied at each stage rather than only at the end.
Continuous Evidence Collection
Automatically gathering compliance evidence on an ongoing basis, configurations, logs, access reviews, and tickets, as it is generated, so audits draw on a continuously maintained evidence store rather than a last-minute manual scramble.
Engineer-Developer Interface
The working relationship between cloud security engineers and the developers who build on the cloud, defining how security guardrails, feedback, and requirements reach developers without becoming a blocker to their work.
Engineering vs Operations
The distinction between building cloud security capabilities (engineering, automation, guardrails, tooling) and running them day to day (operations, monitoring, response), two complementary modes within the cloud security engineer role.
IAM Roles vs Users (Cloud)
The distinction between cloud users (long-lived identities for people, with standing credentials) and roles (assumable identities granting temporary credentials), a core cloud-IAM concept where roles are preferred to avoid static, leakable keys.
Image Signing
Cryptographically signing container or VM images so their integrity and origin can be verified before deployment, ensuring an image has not been tampered with and came from a trusted source.
Multi-Cloud vs Single-Cloud
The architectural choice between using one cloud provider or several. Multi-cloud avoids lock-in and adds resilience but increases complexity; single-cloud is simpler but ties the organization to one provider.
Service Control Policies (SCPs)
Organization-level policies in cloud (AWS-style) that set the maximum permissions any account in scope can have, used as guardrails to enforce limits across many accounts at once.
Service Mesh Security
The security capabilities and concerns of a service mesh, mTLS, identity, authorization, observability, plus protecting the mesh itself, treated as a coherent security-architecture topic.
Trust Policy
In AWS IAM, the policy attached to a role that defines who can assume it, distinct from the permissions policy that defines what the role can do. Misconfigured trust policies are a major cloud security issue.
soc
14Activation Decisions
The judgment calls about whether and when to formally declare an incident and stand up the response process, including who has authority to activate and what thresholds trigger it.
Analyst Shifts
How SOC analyst coverage is scheduled across hours and days, such as rotating shifts or follow-the-sun staffing, to keep monitoring running while managing fatigue and handoffs between analysts.
Analyst Specialization
The way SOC analysts develop deeper expertise in particular areas, such as malware analysis, cloud, identity, or detection engineering, instead of all analysts handling everything at the same level.
Burnout
The exhaustion, cynicism, and reduced effectiveness that affect security analysts after prolonged stress, high alert volume, and relentless pace. It is a serious operational risk because it degrades detection quality and drives staff turnover.
Career Arc IR
The typical career progression in incident response, from junior responder through senior responder and incident commander toward leadership, and the skills and mindset shifts each stage requires.
Career Ladders
Defined progression paths for security analysts, laying out the levels (such as Tier 1 to Tier 3 and into specialties or leadership) and the skills and responsibilities expected at each. They give analysts a clear way to grow.
Data-Driven Hunting
A threat-hunting approach that starts from the data itself, applying analytical techniques like frequency analysis, stack counting, and long-tail analysis to large datasets to surface anomalies worth investigating, rather than starting from a known threat.
Detection Documentation
The written record accompanying a detection, what it detects, the logic and data sources it uses, its assumptions, known false positives, and response guidance, so it can be understood, triaged, tuned, and maintained by others.
Detection Lifecycle
The full arc of a detection from idea to retirement, hypothesis, development, testing, deployment, tuning, monitoring, and eventual retirement, framing detection as something maintained over time rather than written once.
Frequency Analysis
A hunting and analysis technique that counts how often values occur in a dataset, so rare occurrences stand out, on the principle that unusual, infrequent activity is more likely to be malicious than common, high-volume activity.
Indicators of Compromise
Observable artifacts that signal a system may be compromised, such as malicious file hashes, IP addresses, domains, or registry keys, used to detect, hunt for, and confirm known threats across an environment.
Long Tail Analysis
An analytic technique that focuses on the rare, infrequent items in a dataset, the 'long tail', on the principle that uncommon activity is more likely to be malicious than the common bulk. Used in hunting and log analysis.
Post-Incident Review
A structured review of what happened, what worked, and what should improve after an incident.
Stack Counting
A hunting and analytics technique that counts how often each value of a field occurs to surface rare items, on the premise that unusual values often indicate threats worth investigating.
