ISC2 CISSP (Certified Information Systems Security Professional) flashcards
186 free flashcards. Tap a card to flip it.
Cross-Site Scripting (XSS)
Flip cardA web security vulnerability that enables attackers to inject client-side scripts into web pages viewed by other users.
- Occurs when an application embeds untrusted input into its output without proper sanitization.
- Can lead to session hijacking, defacement, or redirection.
- Mitigated by input validation and output encoding.
Memory trick: Injection is Input's Enemy.
Insecure Design (OWASP)
Flip cardA category of web application vulnerabilities that focuses on design flaws related to missing or ineffective control design.
- Often stems from a lack of threat modeling or secure design patterns.
- Not about implementation bugs, but about fundamental architectural weaknesses.
- Can lead to a wide range of vulnerabilities if the underlying design is flawed.
Memory trick: OWASP: The 'O'utstanding 'W'atchdog 'A'lerting 'S'ecurity 'P'rofessionals.
Digital Signatures
Flip cardA mathematical scheme for demonstrating the authenticity of digital messages or documents.
- Provides integrity (message not altered).
- Provides authenticity (verifies sender's identity).
- Provides non-repudiation (sender cannot deny sending).
- Uses asymmetric cryptography (sender's private key for signing, public key for verification).
Memory trick: Signatures Confirm Sender's Sincerity.
Secure Updates
Flip cardA security principle emphasizing that software and firmware updates must be delivered and installed securely, ensuring authenticity and integrity.
- Updates should be cryptographically signed by a trusted entity.
- Updates should be delivered over encrypted channels.
- Prevents tampering and installation of malicious code.
Memory trick: Updates Must Be Signed for Security.
Physical Access Controls
Flip cardMechanisms designed to restrict physical access to sensitive areas, equipment, or data.
- Can include locks, fences, mantraps, biometric readers, and security guards.
- Implemented in layers (defense in depth) from perimeter to internal assets.
- Crucial for protecting hardware, data storage, and critical infrastructure.
Memory trick: Layered security for data centers: from fence to rack.
Hardware Security Module (HSM)
Flip cardA physical computing device that safeguards and manages digital keys, performs encryption and decryption functions, and provides a hardware root of trust.
- Offers a high level of security due to its tamper-resistant and tamper-evident design.
- Used for protecting cryptographic keys, digital signatures, and certificate authorities.
- Complies with industry standards like FIPS 140-2 for cryptographic modules.
Memory trick: HSM: The 'H'ardened 'S'ecurity 'M'achine for your most 'M'portant keys.
Clark-Wilson Security Model
Flip cardAn integrity model designed for commercial environments, focusing on well-formed transactions and separation of duties to maintain data integrity.
- Ensures data transitions from one valid state to another.
- Uses Integrity Verification Procedures (IVPs) and Transformation Procedures (TPs).
- Emphasizes separation of duties and auditing for integrity.
Memory trick: Clark-Wilson: Commercial Integrity, Clear Transactions.
Hashing
Flip cardA cryptographic process that transforms input data into a fixed-size string of characters, known as a hash value or message digest.
- One-way function; computationally infeasible to reverse.
- Used for integrity checks and password storage.
- Collision resistance is a crucial property.
Memory trick: Hashes Hide Secrets, Signatures Show Trust, Asymmetric keys Share, Symmetric keys Shield.
Fault Tolerance
Flip cardThe ability of a system to continue performing its intended function without interruption in the event of a component failure.
- Achieved through redundancy (e.g., redundant power supplies, servers, network paths).
- Ensures high availability and business continuity.
- Often involves automatic failover mechanisms.
Memory trick: Fault tolerance: when one part fails, the system doesn't.
Secure Coding Guidelines
Flip cardA set of best practices and rules for writing software code that minimizes security vulnerabilities.
- Aims to prevent common flaws like injection, XSS, and broken authentication.
- Often based on industry standards like OWASP Top 10.
- Integral part of a secure software development lifecycle (SSDLC).
Memory trick: Web apps need strong code, just like a knight needs strong armor.
Trusted Platform Module (TPM)
Flip cardA secure cryptoprocessor that stores cryptographic keys, measures boot integrity, and provides other hardware-based security functions.
- Provides a hardware root of trust for platforms.
- Used for secure boot, disk encryption (e.g., BitLocker), and digital rights management.
- Protects against software attacks by ensuring system integrity from boot-up.
Memory trick: For embedded systems, TPM is the guardian of the boot.
Privacy by Design (PbD)
Flip cardA framework for embedding privacy principles into the design and operation of information technologies, networked infrastructure, and business practices.
- Developed by Ann Cavoukian in the 1990s.
- Emphasizes proactive rather than reactive privacy measures.
- One of the seven foundational principles is 'Privacy Embedded into Design'.
Memory trick: Design for Privacy, not as an afterthought.
Symmetric Cryptography
Flip cardA type of encryption where the same secret key is used for both encryption and decryption.
- Faster and more efficient than asymmetric cryptography.
- Requires secure key exchange out-of-band.
- Commonly used for bulk data encryption.
Memory trick: Symmetric is Swift for Small Systems.
Attribute-Based Access Control (ABAC)
Flip cardAn authorization model that grants or denies access to objects based on the attributes of the subject, object, action, and environment.
- Highly flexible and granular access control.
- Decisions are dynamic and context-aware.
- Scales well for complex policies and many resources/users.
Memory trick: ABAC Adapts to All Attributes and Contexts.
Insecure Data Storage (Mobile)
Flip cardA mobile application vulnerability where sensitive information is stored in an unencrypted or otherwise unprotected manner on the device's file system.
- Can include databases, configuration files, logs, and user inputs.
- Mitigated by encrypting sensitive data at rest.
- Often results from developers' oversight or misunderstanding of device storage.
Memory trick: Mobile Storage is Sensitive, Encrypt It!
Input Validation & Sanitization
Flip cardThe process of ensuring user-supplied data conforms to expected formats and removing or encoding potentially malicious characters.
- Crucial for preventing injection attacks (SQL, XSS, OS Command).
- Validation checks if input is legitimate, sanitization makes it safe.
- Must be performed on all untrusted input, both client-side and server-side.
Memory trick: Clean your input, or your app will get sick!
Bell-LaPadula Model
Flip cardA state machine model focused on enforcing confidentiality by preventing unauthorized access to classified information.
- Developed for military systems.
- Emphasizes 'no read-up' and 'no write-down' rules.
- Primarily concerned with preventing information disclosure.
Memory trick: Bell-LaPadula Locks Down Confidentiality.
Secure Enclave/Element
Flip cardA dedicated, isolated hardware subsystem within a mobile device or SoC (System on a Chip) for processing sensitive data and cryptographic keys.
- Provides a hardware root of trust, isolated from the main processor and OS.
- Used for biometric authentication, payment processing, and cryptographic key management.
- Protects sensitive operations even if the main OS is compromised.
Memory trick: For mobile keys, the Enclave is the unbreachable vault.
Remote Attestation (TPM)
Flip cardA TPM capability that allows a remote entity to cryptographically verify the integrity of a system's hardware and software configuration.
- Uses Platform Configuration Registers (PCRs) to store measurements of boot components.
- A trusted third party can verify these measurements to confirm system integrity.
- Helps detect rootkits or unauthorized modifications to the OS or applications.
Memory trick: Attestation Assures All is Authentic.
Discretionary Access Control (DAC)
Flip cardDAC allows the owner or creator of a resource to define and control access permissions for that resource.
- Subject (owner) determines access.
- Flexible but can lead to inconsistent security policies.
- Common in many operating systems (e.g., NTFS permissions).
Memory trick: DAC: Discretionary, Owner's Call.
Principle of Least Privilege
Flip cardThe principle of least privilege dictates that a subject should be granted only the minimum necessary rights or permissions to perform its duties.
- Reduces the attack surface and potential damage from compromise.
- Applies to users, processes, and applications.
- A fundamental security best practice.
Memory trick: SLAN: Separation, Least, Accountability, Need.
Certificate-Based Authentication
Flip cardA method of authenticating users or devices using digital certificates, which rely on public key cryptography to verify identity.
- Uses public/private key pairs.
- Private key is typically hardware-protected (e.g., smart card).
- Resistant to replay attacks and robust against phishing.
Memory trick: Keys, Biometrics, Certificates: The Strongest Security Gates
IDaaS Security - Confidentiality & Integrity
Flip cardEnsuring confidentiality and integrity in IDaaS requires robust controls to protect identity data both at rest and in transit, especially during authentication and authorization.
- Data in transit: TLS/SSL encryption is critical.
- Data at rest: Database encryption, access controls.
- Focus on secure communication between client and IDaaS.
Memory trick: Encrypt All Traffic, Always.
OAuth 2.0 / OpenID Connect (OIDC)
Flip cardOAuth 2.0 is an authorization framework for delegated access. OpenID Connect is an identity layer built on top of OAuth 2.0, providing authentication.
- OAuth: Authorization for APIs and service-to-service.
- OIDC: Adds identity verification to OAuth.
- Widely used for modern web, mobile, and microservice architectures.
Memory trick: OAuth/OIDC for API Bots' Access Control
MAC with ABAC Enhancement
Flip cardCombining Mandatory Access Control's label-based enforcement with Attribute-Based Access Control's dynamic, contextual rules for highly granular and secure access decisions.
- MAC enforces strict 'need-to-know' based on classification.
- ABAC adds flexibility with attributes like time, location, device, MFA status.
- Used in high-security environments (e.g., military, intelligence).
Memory trick: MAC-ABAC: Mandatory Attributes Control All.
Brute-Force Attack
Flip cardA brute-force attack is a trial-and-error method used to obtain information such as a user password or personal identification number (PIN).
- Involves systematically trying all possible combinations.
- Can be dictionary attacks (common passwords) or credential stuffing.
- Mitigated by strong passwords, account lockout, MFA, CAPTCHA.
Memory trick: Brute: Brutal, Repeated Guesses.
Identity as a Service (IDaaS)
Flip cardA cloud-based offering that provides identity and access management (IAM) capabilities as a service, including authentication, authorization, and user management.
- Delivered as a cloud service.
- Supports single sign-on (SSO).
- Manages identities across on-premise and multiple cloud applications.
Memory trick: IDaaS Connects On-Prem to Clouds with Ease
Authentication Factor - Something You Do
Flip cardThe 'something you do' authentication factor refers to unique actions or behaviors performed by a user, such as specific gestures, keystroke dynamics, or physical interactions.
- Represents unique user behavior.
- Often used in conjunction with other factors (e.g., possession).
- Examples: specific gestures, typing rhythm, touching a token.
Memory trick: KISS: Know, Inhere, Show, Sit, Step.
SAML (Security Assertion Markup Language)
Flip cardAn open standard for exchanging authentication and authorization data between an identity provider and a service provider, enabling single sign-on (SSO).
- XML-based protocol.
- Facilitates federated identity.
- Supports web-based authentication.
Memory trick: Seamless Access Links Global Domains
SCIM (System for Cross-domain Identity Management)
Flip cardAn open standard for automating the exchange of user identity information between identity domains or IT systems.
- Streamlines user provisioning and deprovisioning.
- Reduces manual administration.
- Often used in hybrid and multi-cloud environments.
Memory trick: SCIM Simplifies Cloud Identity Management
Deprovisioning (Revocation)
Flip cardThe process of removing a user's access rights and accounts from systems and applications when they are no longer authorized.
- Crucial for security hygiene.
- Often triggered by termination or role change.
- Prevents unauthorized access by former personnel.
Memory trick: PACE: Provision, Access, Certify, Exit
Authentication Factors
Flip cardCategories of evidence used to verify a user's identity during authentication.
- Something You Know (password, PIN)
- Something You Have (token, smart card, phone)
- Something You Are (biometrics)
- Something You Do (behavioral biometrics, gestures)
Memory trick: KISS: Know, In-possession, Self, Skill.
Security Assertion Markup Language (SAML)
Flip cardSAML is an XML-based open standard for exchanging authentication and authorization data between an identity provider and a service provider.
- Enables Single Sign-On (SSO).
- Uses XML for assertions.
- Commonly used for federated identity management.
Memory trick: SAML Makes Life Simple (SSO).
OpenID Connect (OIDC)
Flip cardOpenID Connect (OIDC) is an authentication layer on top of OAuth 2.0, enabling clients to verify the identity of the end-user and obtain basic profile information.
- Provides an identity layer over OAuth 2.0.
- Uses JSON Web Tokens (JWTs) for identity assertions.
- Commonly used for consumer-facing and federated web/mobile SSO.
Memory trick: OIDC: Open Identity, Clear Connection.
Third-Party Identity Services Security
Flip cardSecuring identity data and access when using external cloud or managed identity providers, requiring both contractual and technical controls.
- Requires due diligence on vendor security practices.
- Contractual agreements (SLAs) are critical.
- Technical controls like encryption are essential.
Memory trick: Contractual SLAs and Encryption Secure Cloud Data
Authentication Factor: Something You Have
Flip cardA category of authentication factors that relies on a physical item or device that only the legitimate user possesses.
- Examples: Smart cards, USB tokens, mobile phones (for OTP apps).
- Used in multi-factor authentication.
- Adds a layer of security beyond passwords.
Memory trick: Know, Have, Are, Do, Where: The Five Factors
Principle of Least Privilege (PoLP)
Flip cardA security principle that requires giving users and processes only the minimum necessary permissions to perform their legitimate functions.
- Reduces attack surface.
- Limits potential damage from compromise.
- Applies to users, applications, and systems.
Memory trick: Least Privilege is Key for Minimum Access
Third-Party Identity Services Risks
Flip cardRelying on external Identity as a Service (IDaaS) or social login providers introduces dependency risks, particularly around their security posture and availability.
- IdP compromise can lead to widespread account takeovers.
- IdP outages cause service unavailability for your users.
- Loss of direct control over authentication mechanisms and data.
Memory trick: Trusting Others: Their Problems Become Yours.
System for Cross-domain Identity Management (SCIM)
Flip cardSCIM is an open standard designed to automate the exchange of user identity information between identity providers and service providers, simplifying user provisioning and de-provisioning.
- Automates user lifecycle management (create, update, delete).
- Uses RESTful APIs and JSON for data exchange.
- Reduces administrative overhead and improves security consistency.
Memory trick: SCIM: Syncing Cross-Identity Management.
Identity and Access Provisioning Lifecycle - Review
Flip cardThe Review phase involves periodically evaluating existing user access rights and account statuses to ensure they remain appropriate, necessary, and compliant with policies.
- Ensures 'least privilege' and 'need-to-know' are maintained.
- Identifies dormant or unauthorized access.
- Often involves managers or data owners attesting to access validity.
Memory trick: PRRM: People Regularly Review Rights.
Input Whitelisting
Flip cardAn input validation strategy that explicitly defines and allows only known-good, safe input values, characters, or patterns, rejecting everything else by default.
- Positive security model (allow-by-default)
- More secure than blacklisting
- Harder to bypass, robust against unknown attacks
Memory trick: Whitelist your inputs, keep the bad ones out, no nasty surprises, no security doubt.
Trusted Computing Base (TCB)
Flip cardThe set of all protection mechanisms within a computer system (hardware, firmware, software) that are responsible for enforcing the security policy. It must be trustworthy and correct.
- Enforces security policy
- Smallest possible set of components
- Its correctness is paramount for system security
Memory trick: TCB: Tiny Core, Big Security. Less trusted code, more reliability.
Patch Authenticity & Integrity
Flip cardThe process of verifying that a software patch originates from a legitimate source and has not been altered or corrupted since its release.
- Prevents supply chain attacks
- Often uses digital signatures (authenticity)
- Checksums/hashes verify integrity
Memory trick: Patch 'em up quick, but verify first, or a new vulnerability might burst!
Software Composition Analysis (SCA)
Flip cardA tool or process that identifies open-source and third-party components in an application, along with their licenses, known vulnerabilities, and potential security risks.
- Manages open-source software (OSS) risks
- Identifies licensing compliance issues
- Detects known vulnerabilities in OSS components
Memory trick: Component analysis, licenses and flaws, SCA knows all the legal laws.
Output Encoding (Escaping)
Flip cardThe process of converting untrusted data into a safe format for display within a specific context (e.g., HTML, JavaScript), preventing it from being interpreted as active code.
- Crucial for preventing Cross-Site Scripting (XSS).
- Must be applied based on the context of where the data is rendered.
- Different encoding schemes exist for different output contexts (HTML, URL, JavaScript, etc.).
Memory trick: To stop XSS, encode what you show, validate what you know.
Data at Rest Encryption
Flip cardThe process of encrypting data that is stored on a persistent storage medium (e.g., hard drive, mobile device, cloud storage) to protect it from unauthorized access.
- Protects data even if storage device is stolen/compromised
- Requires effective key management
- Applies to local files, databases, backups
Memory trick: Local data's safe, if encrypted it's kept, from prying eyes, secrets well-slept.
Secure by Design
Flip cardAn approach to software development that ensures security considerations are integrated into every phase of the development lifecycle, from initial design to deployment and maintenance.
- Security built-in, not bolted-on
- Proactive rather than reactive
- Focuses on architecture, principles, and practices
Memory trick: Build security in, from the ground up, then vulnerabilities won't fill your cup.
Formal Methods
Flip cardTechniques based on mathematical logic and discrete mathematics used to specify, design, and verify hardware and software systems to ensure their correctness and adherence to requirements.
- Uses mathematical proof for correctness
- High assurance systems (e.g., aerospace, nuclear)
- Can be complex and resource-intensive
Memory trick: Formal methods, mathematically sound, defects are proven not to be found.
Vulnerability Management
Flip cardThe process of identifying, evaluating, treating, and reporting on security vulnerabilities in systems and software.
- Involves continuous scanning and assessment.
- Prioritizes vulnerabilities based on risk.
- Includes patching, configuration changes, or other mitigations.
Memory trick: Critical bugs demand immediate action, not just a patch-up plan.
Effective Vulnerability Risk
Flip cardThe actual security risk posed by a vulnerability is determined by its presence, criticality, and the extent to which the vulnerable component's functionality is actively used or exposed by the system.
- Risk = Likelihood x Impact
- Usage context is key for impact and likelihood
- A dormant vulnerability has low effective risk
Memory trick: Context is king for risk's true sight, if not used, then danger's light.
Shift Left Security
Flip cardThe practice of integrating security activities and considerations earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively, reducing cost and effort.
- Moves security from end-of-cycle to beginning
- Reduces cost of fixing vulnerabilities
- Requires automation and developer involvement
Memory trick: Shift left, test early, errors you'll flee.
Fuzzing
Flip cardAn automated software testing technique that involves injecting malformed, unexpected, or random data into a program's inputs to discover software defects and security vulnerabilities.
- Tests application robustness to bad input
- Can uncover buffer overflows, crashes, memory leaks
- Effective for parsing engines, network protocols
Memory trick: Fuzzing's the game, bad data's its aim, finding crashes before they proclaim.
Service Mesh (with mTLS)
Flip cardA dedicated infrastructure layer that handles service-to-service communication, providing features like traffic management, observability, and security (often via mutual TLS) in microservices architectures.
- Provides mutual authentication and encryption for inter-service calls.
- Offloads communication security from individual applications.
- Enhances observability and policy enforcement for microservices.
Memory trick: Decoupled services need a mesh to tightly secure their chatter.
Secure Memory Management
Flip cardPractices to protect sensitive data stored in application memory, including proper allocation, deallocation, and overwriting of data when no longer needed.
- Prevents sensitive data from lingering in memory after use.
- Mitigates risks like memory dumps, buffer over-reads, and use-after-free.
- Involves zeroing out or overwriting memory regions containing secrets.
Memory trick: Memory leaks are like forgotten secrets; wipe them clean.
Runtime Application Self-Protection (RASP)
Flip cardA security technology that is integrated into an application or its runtime environment to detect and block attacks in real-time from within the application itself.
- Protects applications during execution
- Detects and blocks attacks from within
- Provides real-time visibility and defense
Memory trick: RASP protects the app while it runs, blocking attacks before they're done.
Acquired Software Security Assessment
Flip cardThe process of independently evaluating the security of third-party or off-the-shelf software before acquisition or deployment.
- Goes beyond vendor claims and documentation.
- Often involves penetration testing, vulnerability scanning, or code review.
- Crucial for understanding residual risk from external software.
Memory trick: Don't just trust the box, independently test the locks.
Static Application Security Testing (SAST)
Flip cardA white-box testing methodology that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without actually executing the application.
- Identifies vulnerabilities early in SDLC (Shift Left)
- Scans code for known patterns and weaknesses
- Does not require a running application
Memory trick: Static scans catch code flaws fast, before they're cast.
Security Champion
Flip cardA developer or team member who acts as a security advocate and expert within their development team, bridging the gap between security and development.
- Provides immediate security guidance.
- Promotes secure coding practices.
- Facilitates communication with the central security team.
Memory trick: Agile security thrives with champions, not just gatekeepers.
Trusted Execution Environment (TEE)
Flip cardA secure area of a main processor that provides hardware-backed isolation from the rest of the system, guaranteeing the confidentiality and integrity of code and data loaded within it.
- Protects against software attacks from the OS/hypervisor.
- Ensures integrity and confidentiality of critical computations.
- Examples include Intel SGX, ARM TrustZone.
Memory trick: To truly trust execution, isolate it in a TEE.
DFD Data Flow
Flip cardIn Data Flow Diagrams (DFDs), a 'Data Flow' depicts the movement of information between processes, data stores, and external entities. It is represented by an arrow.
- Shows data in motion
- Represents communication channels
- Critical for identifying interception/tampering threats
Memory trick: Data flows are highways for threats, where interception sets its nets.