ISC2 Certified in Cybersecurity (CC) flashcards
133 free flashcards. Tap a card to flip it.
Authentication
Flip cardThe process of verifying the identity of a user, process, or device.
- Confirms 'who you are'
- Typically follows identification
- Uses factors like passwords, biometrics, tokens
Memory trick: Identify, Authenticate, Authorize: 'Who are you, prove it, what can you do?'
Single Sign-On (SSO)
Flip cardAn authentication process that allows a user to access multiple applications with one set of login credentials.
- Improves user experience and productivity.
- Reduces password-related help desk calls.
- Can be implemented using protocols like SAML or OAuth.
Memory trick: Manage identities, sign on once.
Separation of Duties
Flip cardA security principle that divides critical or sensitive tasks among multiple individuals to prevent any single person from having enough control to commit fraud or errors.
- Reduces the risk of insider threat.
- Requires multiple individuals to complete a transaction.
- Often implemented with access controls (e.g., RBAC).
Memory trick: Separate duties, prevent fraud.
Implicit Deny
Flip cardA security principle in access control where if a request (e.g., for access) does not explicitly match an 'allow' rule, it is automatically denied by default.
- Also known as 'deny by default'
- Fundamental for firewall and ACL configurations
- Ensures only explicitly permitted actions are allowed
Memory trick: Implicit Deny: 'If it's not explicitly green, it's red!'
Multi-Factor Authentication (MFA)
Flip cardAn authentication method that requires a user to present two or more distinct authentication factors from different categories (e.g., knowledge, possession, inherence) to verify their identity.
- Significantly improves security against credential theft.
- Common factors: password (knowledge), token/app (possession), fingerprint (inherence).
- Reduces the risk of unauthorized access even if one factor is compromised.
Memory trick: Know it, have it, be it: that's MFA's secret.
Authentication Factors
Flip cardDistinct categories of credentials used to verify a user's identity during authentication.
- There are traditionally three main factors: knowledge, possession, inherence.
- Multi-factor authentication (MFA) combines two or more different factors.
- Stronger authentication uses multiple factors.
Memory trick: Know, Have, Are: the three factors to verify.
Role-Based Access Control (RBAC)
Flip cardAn access control model where permissions are associated with roles, and users are assigned to appropriate roles, thereby inheriting the associated permissions.
- Simplifies access management in large organizations.
- Promotes the principle of least privilege.
- Roles are typically defined by job function or responsibility.
Memory trick: Models define access, roles make it easy.
Identity Governance and Administration (IGA)
Flip cardA framework that manages the entire lifecycle of digital identities and their access rights, ensuring compliance and reducing risk.
- Automates provisioning/deprovisioning
- Includes access reviews and certifications
- Focuses on policy enforcement and compliance
Memory trick: IAM: 'Identify, Authenticate, Authorize, Govern.'
Discretionary Access Control (DAC)
Flip cardAn access control model where the owner of a resource (or an administrator with equivalent privileges) has full control over who can access that resource and what permissions they have.
- Common in many operating systems (e.g., Windows, Unix).
- Access decisions are 'discretionary' to the owner.
- Can be less secure if owners are not careful with permissions.
Memory trick: Models control access, owners decide discretion.
Physical Access Control Types
Flip cardCategories of physical security mechanisms based on their primary function in safeguarding assets.
- Deterrents discourage attacks.
- Detection identifies attacks in progress.
- Delay slows down attackers.
- Correction remedies damage or restores systems.
Memory trick: Deter, Detect, Delay, Correct: the 4 D's of physical security.
Mandatory Access Control (MAC)
Flip cardAn access control model where access decisions are centrally controlled and strictly enforced by the system based on security labels assigned to subjects and objects. Users cannot override these policies.
- Often used in high-security environments (e.g., military, government).
- Based on security classifications (e.g., Top Secret, Secret, Confidential).
- Users cannot grant or deny access, even to their own files.
Memory trick: DAC is 'discretionary' for you; MAC is 'mandatory' for all.
Attribute-Based Access Control (ABAC)
Flip cardAn access control model that grants or denies access based on a dynamic set of attributes associated with the user, resource, and environment.
- Highly granular and flexible
- Uses policies rather than fixed roles/labels
- Context-aware (e.g., time, location, device)
Memory trick: ABAC is like a customizable puzzle, where every piece (attribute) matters.
Need-to-Know
Flip cardAn access control principle stating that an individual should only be granted access to the specific information and resources absolutely required for their assigned duties.
- A refinement of the 'Least Privilege' principle
- Crucial for protecting classified or sensitive data
- Limits exposure of information even to authorized personnel
Memory trick: Need-to-Know: 'If you don't need to know, you won't know.'
Identity and Access Management (IAM)
Flip cardA framework of policies, processes, and technologies that manage digital identities and control access to resources and systems within an organization. It encompasses user provisioning, authentication, authorization, and auditing.
- Centralizes identity management across multiple systems.
- Automates the lifecycle of user access (provisioning/deprovisioning).
- Enhances security, compliance, and operational efficiency.
Memory trick: IAM is the master key for all identities and access.
Least Privilege
Flip cardA security principle requiring that a user or process be given only the minimum set of permissions needed to perform its function.
- Reduces the attack surface.
- Limits potential damage from compromised accounts.
- Fundamental to secure system design.
Memory trick: Principles guide security, less is more.
Physical Access Controls
Flip cardSecurity measures designed to restrict unauthorized access to physical facilities, equipment, and resources. They protect against theft, damage, and unauthorized entry.
- Includes barriers, locks, fences, guards, cameras, and mantraps.
- Focuses on securing tangible assets and locations.
- Essential for protecting data centers, server rooms, and critical infrastructure.
Memory trick: Physical is touch, Logical is thought, Admin is rule.
Identification (Access Control)
Flip cardThe process by which a user or entity claims an identity to a system, typically through a unique identifier like a username.
- It is the first step in the access control process.
- Establishes 'who you say you are'.
- Must precede authentication.
Memory trick: First, say who; then, prove it's you.
Accountability (Access Control)
Flip cardThe principle that ensures that all actions performed on a system can be attributed to a specific individual or entity.
- Relies on strong identification and authentication.
- Enabled by comprehensive logging and auditing.
- Essential for forensics and incident response.
Memory trick: AAA: Assert, Prove, Permit, Trace.
Access Reviews
Flip cardA recurring process of formally reviewing and validating user access rights to ensure they are appropriate, necessary, and compliant with security policies.
- Also known as access certifications or recertifications
- Helps identify orphaned accounts and excessive permissions
- Crucial for maintaining least privilege and compliance
Memory trick: Access Reviews: 'Review to Renew or Remove.'
False Positive (Security)
Flip cardAn alert or indication from a security system that reports a legitimate activity or benign condition as malicious or anomalous.
- Can lead to alert fatigue and wasted resources.
- Often caused by poor calibration or misconfiguration of sensors.
- Requires investigation to distinguish from true threats.
Memory trick: Logs conflict, look for false facts.
Provisioning
Flip cardThe process of creating, maintaining, and managing user accounts and access rights to organizational resources.
- Grants initial access based on role.
- Ensures users have necessary permissions.
- Part of the identity and access management (IAM) lifecycle.
Memory trick: Life's a cycle, access is vital.
Administrative Controls
Flip cardSecurity controls implemented through policies, procedures, guidelines, and training to manage security risks.
- Focus on human behavior and organizational processes
- Examples: security awareness, background checks, incident response plans
- Often complement technical and physical controls
Memory trick: Controls: 'TAP' that security — Technical, Administrative, Physical.
Deprovisioning
Flip cardThe process of revoking or disabling user access to systems and resources when they no longer require it, such as upon termination or role change.
- Crucial for maintaining security after employee turnover.
- Prevents unauthorized access by former personnel.
- Often includes disabling accounts, removing group memberships, and reclaiming physical access cards.
Memory trick: From hiring to firing, access changes are key.
Secure Disposal
Flip cardThe process of permanently removing data from storage media and/or destroying the media itself to prevent unauthorized recovery and ensure compliance with privacy regulations.
- Methods include degaussing, shredding, and overwriting.
- Crucial for protecting sensitive information.
- Ensures compliance with data privacy laws.
Memory trick: Disposal Destroys Data Definitively.
Security Monitoring
Flip cardThe continuous process of observing and analyzing an organization's systems, networks, and data for security-related events, anomalies, and potential threats.
- Provides real-time threat detection.
- Utilizes tools like SIEM and IDS/IPS.
- Crucial for incident response and proactive defense.
Memory trick: Monitoring Makes Malicious Moves Manifest.
Log Management
Flip cardThe process of collecting, storing, processing, and analyzing log data from various systems and applications to support security monitoring, auditing, and incident response.
- Provides an auditable record of activities.
- Essential for incident response and compliance.
- Can identify suspicious activities and security breaches.
Memory trick: Logs Leave Legible Life Lines.
Data Classification
Flip cardThe process of categorizing data based on its sensitivity and value to an organization, which then dictates the security controls applied to it.
- Helps determine appropriate security controls.
- Often involves labels like 'Public', 'Internal', 'Confidential', 'Restricted'.
- Crucial for compliance and risk management.
Memory trick: Classify Data to Clarify Controls.
Volatile Data
Flip cardInformation that exists in a temporary state and is lost when a computer system is powered down or loses power, such as RAM contents, CPU registers, and network connections.
- Must be collected first in forensics
- Includes active processes, open network connections, RAM data
- Contrasts with persistent data (e.g., hard drive contents)
Memory trick: Volatile data vanishes like smoke, collect it fast!
Anomaly Detection
Flip cardThe process of identifying patterns or behaviors in data that are significantly different from the expected or normal patterns, often indicating potential security threats or system issues.
- Identifies deviations from a baseline
- Can detect novel attacks or insider threats
- Requires establishing a 'normal' behavior profile
Memory trick: Monitoring for the 'odd one out' is key to security.
Vulnerability Scanning
Flip cardAn automated process of identifying security weaknesses (vulnerabilities) in a network, system, or application.
- Non-invasive and automated.
- Identifies known vulnerabilities.
- Provides a report of discovered weaknesses.
Memory trick: Scan for cracks before the wall falls.
SIEM (Security Information and Event Management)
Flip cardA security solution that provides real-time analysis of security alerts generated by network hardware and applications. SIEMs combine SIM (Security Information Management) and SEM (Security Event Management) functions.
- Aggregates logs from many sources
- Correlates events to detect patterns and incidents
- Provides alerts and reporting for compliance and threat detection
Memory trick: Logs are data, SIEM makes them smart for security.
Environmental Controls
Flip cardMeasures implemented to manage and maintain suitable environmental conditions (temperature, humidity, power, fire safety) for IT infrastructure.
- Protects hardware from damage.
- Ensures continuous operation.
- Includes HVAC, fire suppression, power conditioning.
Memory trick: Keep the server cool, dry, and fire-free.
Data Handling
Flip cardThe processes and controls implemented to manage and protect data throughout its entire lifecycle, from creation to destruction.
- Encompasses storage, transmission, processing, access.
- Includes encryption, access controls, auditing.
- Guided by data classification and retention policies.
Memory trick: Handle data with care, from start to end.
Patch Management
Flip cardThe systematic process of identifying, acquiring, testing, and installing software patches and updates.
- Mitigates known vulnerabilities
- Improves system stability and performance
- Often automated for efficiency
Memory trick: Patches are like band-aids for software, covering up known wounds (vulnerabilities).
Configuration Management
Flip cardThe process of establishing and maintaining consistency of a system's performance, functional, and physical attributes with its requirements, design, and operational information throughout its life.
- Ensures systems are configured securely and consistently.
- Prevents configuration drift and unauthorized changes.
- Crucial for compliance and auditing.
Memory trick: Consistent Configs Confirm Compliance.
Defense in Depth
Flip cardA cybersecurity strategy that employs multiple layers of security controls (administrative, technical, and physical) to protect information assets, so that if one control fails, others are still in place.
- Also known as 'layered security'
- Provides redundancy and resilience
- Applies to people, technology, and operations
Memory trick: Layers protect like an onion, if one fails, another is there.
Personnel Security
Flip cardMeasures taken to ensure that individuals who have access to an organization's assets are trustworthy and understand their security responsibilities.
- Covers hiring, onboarding, and termination.
- Includes background checks and security awareness.
- Crucial for insider threat prevention.
Memory trick: People are the strongest (or weakest) link.
Penetration Testing
Flip cardA simulated cyber attack against an information system, network, or web application to check for exploitable vulnerabilities.
- Actively attempts to exploit vulnerabilities.
- Goes beyond vulnerability scanning.
- Evaluates the effectiveness of security controls.
Memory trick: Pen Test Probes Potential Pathways.
Change Management
Flip cardA formal process for controlling all proposed changes to systems, services, or configurations, ensuring they are documented, assessed, approved, and tracked.
- Minimizes risks associated with changes.
- Ensures traceability and accountability.
- Critical for system stability and security.
Memory trick: Don't change it, manage it!
Secure Data Disposal
Flip cardThe process of permanently and irrecoverably removing data from storage media to prevent unauthorized access or recovery, adhering to organizational policies and regulatory requirements.
- Methods include degaussing, shredding, cryptographic erasure
- Applies to all media types (hard drives, SSDs, cloud)
- Crucial for compliance and data privacy
Memory trick: When data's life ends, dispose of it securely.
Remote Wipe
Flip cardA security feature that allows an administrator to remotely delete data from a lost, stolen, or decommissioned device.
- Crucial for BYOD security.
- Can be full or selective (corporate data only).
- Prevents unauthorized access to sensitive data.
Memory trick: Lost phone? Zap the data, not the memories.
Security Awareness Training
Flip cardAn ongoing educational program designed to inform and train employees about cybersecurity threats, organizational security policies, and best practices to protect information assets.
- Aims to reduce human error in security
- Covers topics like phishing, social engineering, password hygiene
- Should be mandatory and recurring for all staff
Memory trick: People are the strongest or weakest link.
Third-Party Risk Management
Flip cardThe process of identifying, assessing, and mitigating risks associated with external vendors, suppliers, and partners who have access to an organization's systems, data, or processes.
- Crucial for supply chain security
- Involves due diligence, contract review, and ongoing monitoring
- Aims to protect organizational assets accessed by third parties
Memory trick: Trusting others requires careful checks.
Data Retention
Flip cardThe policies and procedures that govern how long an organization must keep different types of data.
- Driven by legal, regulatory, and business requirements.
- Impacts storage costs and risk exposure.
- Defines the lifespan of data before disposal.
Memory trick: Retain data as long as needed, then shred it.
Biometric Authentication
Flip cardA security process that relies on the unique biological characteristics of an individual to verify their identity.
- Uses unique biological traits (e.g., fingerprint, iris, face).
- Enhances physical and logical access control.
- Provides a strong form of authentication ('something you are').
Memory trick: Your body unlocks the door.
Physical Access Control
Flip cardSecurity measures designed to restrict or permit access to physical locations, resources, or assets based on authentication and authorization.
- Uses mechanisms like locks, keycards, biometrics
- Often combines 'something you have' (card) with 'something you know' (PIN)
- Protects against unauthorized physical entry and theft
Memory trick: Physical security protects the 'stuff' in the building.
Asset Management
Flip cardThe process of tracking and managing an organization's IT assets, including hardware, software, and data, throughout their lifecycle to optimize their use and ensure security.
- Maintains an inventory of all IT assets.
- Supports compliance and resource optimization.
- Crucial for security and financial planning.
Memory trick: Assets Are Always Accounted.
Incident Response: Eradication Phase
Flip cardThe phase of incident response focused on removing the root cause of the incident, eliminating the attacker's presence, and hardening systems to prevent re-infection.
- Follows containment and precedes recovery.
- Involves removing malware, disabling compromised accounts, patching vulnerabilities.
- Crucial to prevent recurrence of the incident.
Memory trick: Eradicate: Eliminate the Evil, make it go away.
Continuous Data Replication (CDR)
Flip cardA backup strategy that captures and replicates every change to data as it occurs, ensuring that the recovery site always has an up-to-date copy of the data, minimizing data loss.
- Achieves near-zero Recovery Point Objective (RPO).
- Often paired with hot sites for rapid Recovery Time Objective (RTO).
- Resource-intensive but critical for high-availability systems.
Memory trick: Replication: Reaching Perfection, Live And Continuously.
High Availability (HA)
Flip cardA characteristic of a system, which aims to ensure an agreed level of operational performance for a higher than normal period, often through redundant components and automatic failover mechanisms.
- Minimizes downtime for critical systems.
- Uses redundancy (hardware, networks, power).
- Often involves automatic failover.
Memory trick: HA: Highly Available, Always Active.
Redundant Systems
Flip cardDuplicate hardware, software, or network components designed to provide continuous service in the event of a primary system failure, ensuring high availability and rapid failover.
- Eliminates single points of failure
- Ensures high availability and fault tolerance
- Critical for meeting low RTOs and MTDs
Memory trick: Redundancy is the key to always be Ready, Even when things go down.
Hot Site
Flip cardA fully equipped and configured offsite data center that can immediately take over operations from a primary site in the event of a disaster, with minimal downtime and data loss.
- Provides the lowest RTO and RPO.
- Most expensive type of alternate site.
- Requires continuous data synchronization.
Memory trick: Hot sites are Ready, Operational, and 'Hot' for action.
Business Continuity Plan (BCP)
Flip cardA comprehensive plan that outlines how an organization will maintain critical business functions and operations during and after a disruptive event, ensuring resilience and recovery.
- Broader than a Disaster Recovery Plan, encompassing all aspects of business operations.
- Focuses on maintaining essential functions, not just IT systems.
- Addresses people, processes, technology, and facilities.
Memory trick: BCP: The 'Big Picture' plan for keeping the Business going.
Incident Management
Flip cardThe process of identifying, analyzing, prioritizing, and resolving security incidents to restore normal service operations as quickly as possible and prevent future occurrences.
- Encompasses detection, containment, eradication, recovery, and post-incident activities.
- Aims to minimize the impact of security incidents.
- Requires a well-defined incident response plan.
Memory trick: Management is the 'big picture' of handling all incidents.
Incident Response: Post-Incident Activity
Flip cardThe final phase of incident response, focused on learning from the incident, documenting findings, and improving policies, procedures, and tools for future incidents.
- Also known as 'Lessons Learned'
- Includes documentation and reporting
- Aims for continuous improvement of IR capabilities
Memory trick: P D C E R P: Prepare, Detect, Contain, Eradicate, Recover, Post-Incident.
Maximum Tolerable Downtime (MTD)
Flip cardThe total amount of time a business process or system can be inoperative before the organization experiences unacceptable consequences or significant damage.
- Absolute upper limit for outage duration
- Determined by Business Impact Analysis (BIA)
- RTO must be less than or equal to MTD
Memory trick: MTD: Max Tolerable Downtime; RTO: Recovery Time Objective.
Synchronous Replication
Flip cardA data replication method where data is written to a primary storage system and simultaneously to a secondary, redundant system. A write operation is not considered complete until it has been confirmed by both systems.
- Provides near-zero Recovery Point Objective (RPO).
- Offers immediate failover capability.
- Requires low-latency network connections between systems.
Memory trick: Sync 'n' Share: Data's always there!
Synchronous Data Replication
Flip cardA method of data replication where data is written to both the primary and secondary storage locations simultaneously, ensuring data consistency and near-zero data loss (RPO) but potentially introducing latency.
- Data written simultaneously to primary and secondary
- Ensures near-zero RPO (virtually no data loss)
- Requires high-bandwidth, low-latency network connections
- Enables rapid failover
Memory trick: Sync for Zero Loss, Async for Speed.
Communication Plan (BC/DR)
Flip cardA documented strategy that outlines how an organization will communicate with internal and external stakeholders during and after a business disruption or disaster.
- Identifies key stakeholders and their communication needs.
- Defines communication methods, channels, and frequency.
- Assigns responsibilities for communication tasks.
Memory trick: Communicate Clearly, Keep Everyone Informed.
Business Impact Analysis (BIA)
Flip cardA systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
- Identifies critical business functions and processes.
- Quantifies the impact of disruptions (financial, operational, reputational).
- Helps determine RTOs and RPOs.
Memory trick: BIA: Business's Impact Assessed, Always.