Lesson 1 - Fundamental Security Concepts Flashcards
CIA
Confidentiality, Integrity, Authorization
NIST
National Institute of Standards and Technology
- Develops computer security standards used by US federal agencies and publishes cybersecurity best practice guides and research.
CSF
Cybersecurity Framework
- Standards, best practices, and guidelines for effective security risk management. Some frameworks are general in nature, while others are specific to industry or technology types.
IAM
Identity and Access Management
- A security process that provides identification, authentication, and authorization mechanisms for users, computers, and other entities to work with organizational assets like networks, operating systems, and applications.
AAA
Authentication, Authorization and Accounting
- A security concept where a centralized platform verifies subject identification, ensures the subject is assigned relevant permissions, and then logs these actions to create an audit trail.
ACL
Access Control List
- The collection of access control entries (ACEs) that determines which subjects (user accounts, host IP addresses, and so on) are allowed or denied access to the object and the privileges given (read-only, read/write, and so on).
CIO
Chief Information Officer
- A company officer with the primary responsibility for management of information technology assets and procedures.
CTO
Chief Technology Officer
- A company officer with the primary role of making effective use of new and emerging computing platforms and innovations.
CSO
Chief Security Officer
- Typically the job title of the person with overall responsibility for information assurance and systems security.
CISO
Chief Information Security Officer
ISSO
Information Systems Security Officer
- Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.
NICE
National Initiative for Cybersecurity Education
SOC
Security Operations Center
- The location where security professionals monitor and protect critical information assets in an organization.
DevOps
Development and Operations
- A combination of software development and systems operations, and refers to the practice of integrating one discipline with the other.
CIRT
Computer Incident Response Team
- Team with responsibility for incident response. The CSIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).