ISC2 CISSP (Certified Information Systems Security Professional) flashcards
186 free flashcards. Tap a card to flip it.
Administrative Security Data
Flip cardInformation related to an organization's policies, procedures, standards, guidelines, and training programs that dictate how security is managed and implemented.
- Includes policies, procedures, and standards
- Covers security awareness and training records
- Forms the governance framework for security
Memory trick: Data: Admin for rules, Tech for gear, Ops for daily grind.
Audit Finding Categories
Flip cardClassifications used in security audits to describe identified issues, often relating to policy adherence, control effectiveness, or technical vulnerabilities.
- Policy non-compliance: failure to follow rules
- Control weakness: a control is insufficient or ineffective
- Technical vulnerability: a specific flaw in a system
Memory trick: Audit: Policy breaks, weak controls, or tech flaws.
Black Box Testing
Flip cardA penetration testing methodology where the tester has no prior knowledge of the internal workings of the system being tested, simulating an external attacker.
- Simulates an external attacker
- No internal system knowledge provided to tester
- Focuses on externally exploitable vulnerabilities
Memory trick: Boxes of knowledge, from dark to light.
SAST (Static Application Security Testing)
Flip cardA security testing method that analyzes an application's source code, bytecode, or binary code for vulnerabilities without actually executing the application.
- Analyzes code without execution (static)
- Identifies vulnerabilities early in SDLC
- Good for finding coding errors like buffer overflows, SQL injection
Memory trick: App tests: SAST for code, DAST for running, IAST for both.
Continuous Security Monitoring
Flip cardAn ongoing process of collecting, analyzing, and reporting on security-related data to detect threats, vulnerabilities, and deviations from security policies in real-time or near real-time.
- Provides real-time visibility into security posture
- Detects deviations from baselines promptly
- Supports proactive risk management
Memory trick: Assessments: Snapshots, Deep Dives, or Constant Watches.
Security Policy Compliance
Flip cardThe act of adhering to an organization's internal security policies, standards, and procedures, as well as external regulations and legal requirements.
- Ensures alignment with organizational security posture
- Audits verify compliance status
- Non-compliance indicates a gap in security governance
Memory trick: Audit uncovers Policy breaks, Design flaws, or weak Controls.
CIA Triad (Integrity)
Flip cardIntegrity, part of the CIA Triad, ensures that information is accurate, complete, and protected from unauthorized modification or destruction.
- Protects against unauthorized alteration or deletion
- Ensures data is trustworthy and reliable
- Often maintained through hashing, digital signatures, access controls
Memory trick: CIA: Confidentiality, Integrity, Availability.
Shift-Left Security
Flip cardAn approach to software development that integrates security practices, including testing, earlier into the development lifecycle to find and fix vulnerabilities when they are less costly to address.
- Security activities moved to earlier SDLC phases
- Emphasizes automation and continuous integration
- Reduces cost and effort of vulnerability remediation
Memory trick: Shift Left: Security goes earlier, not later.
Manual Penetration Testing
Flip cardA hands-on, human-driven security test where skilled testers simulate real-world attacks to identify and exploit vulnerabilities that automated tools might miss, particularly in complex or unique environments.
- Human intelligence and adaptability
- Effective for complex business logic and custom applications
- Reduces false positives compared to automated tools
Memory trick: Old apps need human touch, not just robots.
OSSTMM (Open Source Security Testing Methodology Manual)
Flip cardA peer-reviewed methodology for security testing that provides a scientific, repeatable, and metric-based approach to assess operational security, often focusing on the measurable impact of security controls.
- Metric-based and scientific approach
- Covers a wide range of security: physical, human, operational
- Focuses on measurable impact and real-world results
Memory trick: PTES is steps, OWASP for web, OSSTMM for science.
Security Control Validation
Flip cardThe process of testing and evaluating security controls to ensure they are implemented correctly, operating as intended, and achieving their desired security objectives.
- Confirms controls are effective
- Includes testing, simulations, and exercises
- Identifies gaps between design and actual performance
Memory trick: Gaps: Policy, Training, or Unvalidated Controls.
SCADA Security
Flip cardSecuring SCADA (Supervisory Control and Data Acquisition) systems involves unique challenges due to their critical function, real-time operation, legacy components, and high availability demands. Network segmentation, strong access controls, and robust monitoring are key.
- High availability and real-time operations are paramount.
- Patching and reboots can be disruptive and are often avoided.
- Network segmentation and isolation are crucial for protection.
- Often involves legacy systems with known vulnerabilities.
Memory trick: Isolate the heart of the grid.
Change Management Process
Flip cardThe Change Management Process is a formal procedure for managing all changes to an organization's IT environment, ensuring that changes are introduced in a controlled, coordinated, and documented manner to minimize disruption and risk.
- Minimizes risks from changes.
- Includes planning, approval, implementation, and review.
- Crucial for maintaining system stability and security.
Memory trick: Changes need 'Control' to not break things.
Data Loss Prevention (DLP)
Flip cardData Loss Prevention (DLP) is a set of tools and processes designed to ensure that sensitive data is not lost, misused, or accessed by unauthorized users. DLP systems classify and protect sensitive information, preventing its unauthorized disclosure.
- Prevents sensitive data exfiltration.
- Analyzes data in use, in motion, and at rest.
- Uses content inspection, keyword matching, and pattern recognition.
Memory trick: DLP 'Deters Leaking' of sensitive data.
Network Baselining
Flip cardNetwork baselining is the process of measuring and recording the normal performance and behavior of a network over a period of time to establish a reference point for future comparisons and anomaly detection.
- Establishes 'normal' operational patterns.
- Used to detect deviations and anomalies.
- Crucial for effective monitoring and incident detection.
Memory trick: Baseline is the 'base' of what's normal, where anomalies stand out.
Application Logging Importance
Flip cardApplication logging records events and activities specific to a software application, such as user logins, data access, transactions, and errors. These logs are critical for security monitoring, forensic analysis, auditing, and troubleshooting application-specific issues.
- Provides granular detail on internal application events.
- Essential for auditing user actions and data access.
- Crucial for forensic investigations of application breaches.
- Often required for regulatory compliance.
Memory trick: OS is the house, App is the room.
Auditor Independence
Flip cardThe state of being free from relationships or circumstances that could reasonably be expected to compromise an auditor's objectivity, allowing them to form an unbiased opinion.
- Essential for credible and trustworthy audit results.
- Often achieved by reporting to a high-level, impartial body.
- Prevents conflicts of interest and undue influence.
Memory trick: AUDIT PRINCIPLES are INDEPENDENT, OBJECTIVE, and SCOPED for accuracy.
Recovery Point Objective (RPO)
Flip cardRPO is the maximum acceptable amount of data loss, measured in time, that an organization can tolerate during a disruption. It dictates the frequency of backups or data replication.
- Measures data loss in time (e.g., 4 hours of data).
- Determines how frequently data must be backed up.
- A lower RPO means less data loss but typically higher cost.
Memory trick: RTO is for Time, RPO is for Point (data).
Security Information and Event Management (SIEM)
Flip cardA SIEM system provides real-time analysis of security alerts generated by network hardware and applications. It centralizes log management, correlation, and reporting for security events.
- Aggregates logs from various sources.
- Performs real-time correlation and analysis.
- Generates alerts and reports for security incidents.
Memory trick: SIEM is the central brain for all security log data.
Resource Protection
Flip cardResource protection refers to the implementation of controls and measures to safeguard an organization's assets, including data, systems, and facilities, from unauthorized access, use, disclosure, disruption, modification, or destruction.
- Aims to preserve confidentiality, integrity, and availability (CIA).
- Involves technical, administrative, and physical controls.
- Examples include encryption, access controls, backups, and physical security.
Memory trick: Protect the resources, govern the process, manage the risks.
Warm Site
Flip cardA warm site is a type of disaster recovery site that has essential hardware and network connectivity pre-installed, but requires data to be restored from backups and applications to be configured, leading to a recovery time of hours to days.
- Balance of cost and recovery speed.
- Hardware and network in place.
- Requires data and application setup post-disaster.
Memory trick: Hot is 'Ready Now'; Warm is 'Ready Soon'; Cold is 'Start from Scratch'.
Post-Incident Recovery
Flip cardThe final phase of incident response, focusing on restoring systems, conducting forensic analysis, documenting lessons learned, and improving future incident handling.
- Occurs after the immediate threat is contained and eradicated.
- Includes detailed forensic analysis and root cause identification.
- Crucial for continuous improvement of security posture.
Memory trick: INCIDENT RESPONSE is a PREP plan, ID, CONTAIN, ERADICATE, RECOVER, and LESSONS cycle.
Defense-in-Depth
Flip cardDefense-in-depth is a security strategy that employs multiple, overlapping security controls to protect information assets. The failure of one control does not compromise the entire system, providing resilience against various threats, including unknown ones.
- Uses layered security controls (administrative, technical, physical).
- Aims to slow down and complicate attacks, not just block them.
- Improves overall resilience by preventing single points of failure.
Memory trick: Layers of an onion keep threats from the core.
Penetration Test
Flip cardA simulated cyberattack against a computer system, network, or web application to check for exploitable vulnerabilities.
- Involves active exploitation of vulnerabilities.
- Aims to determine the real-world impact of a breach.
- Can be black-box, white-box, or gray-box.
Memory trick: ASSESSMENTS range from passive SCANS to active PEN TESTS, ensuring COMPLIANCE and AUDIT integrity.
Defense-in-Depth (Physical Security)
Flip cardDefense-in-Depth (also known as 'layered security') in physical security involves implementing multiple, independent layers of security controls to protect an asset, such that if one control fails, others remain to provide protection.
- Multiple, overlapping security controls.
- Aims to slow down or deter attackers.
- Reduces reliance on a single point of failure.
Memory trick: Layered Defenses make it a 'Castle' of security.
Significant Deficiency
Flip cardA flaw in an organization's internal control over financial reporting or security that is less severe than a material weakness, yet important enough to merit attention by those responsible for oversight.
- Indicates a breakdown in a control process.
- Less severe than a material weakness, but still serious.
- Requires attention from management and governance.
Memory trick: Auditors find FLAWED CONTROLS, ranging from minor OBSERVATIONS to serious MATERIAL WEAKNESSES.
Auditability
Flip cardAuditability refers to the ability to examine and verify the records, processes, and controls of an organization to ensure compliance, integrity, and accountability.
- Relies heavily on comprehensive logging and record keeping.
- Essential for regulatory compliance and internal governance.
- Allows for reconstruction of events and verification of actions.
Memory trick: CIA Triad + AAA + D (Confidentiality, Integrity, Availability, Authentication, Authorization, Accountability, Non-repudiation, Auditability).
Incident Response - Containment
Flip cardContainment in incident response refers to the actions taken to stop an incident from spreading or causing further damage, thereby limiting its scope and impact.
- Aims to prevent further damage.
- Often involves isolating affected systems or blocking malicious traffic.
- Is a critical phase before eradication and recovery.
Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned.
Maximum Tolerable Downtime (MTD)
Flip cardMTD, also known as Maximum Tolerable Period of Disruption (MTPD), is the maximum amount of time an organization can tolerate a business function or process to be inoperative before suffering unacceptable consequences.
- Defines the absolute limit of downtime for a business function.
- Determined by business impact analysis.
- RTOs must be less than or equal to MTDs.
Memory trick: MTD is the absolute limit.
SOC 2 Type II Report
Flip cardA report on Controls at a Service Organization relevant to Security, Availability, Processing Integrity, Confidentiality, or Privacy, covering the effectiveness of these controls over a specified period.
- Issued by an independent auditor.
- Provides assurance on the effectiveness of controls over time.
- Commonly used for SaaS and cloud service providers.
Memory trick: THIRD-PARTY reports ASSURE TRUST, from SOC for services to ISO for systems.
Recovery Time Objective (RTO)
Flip cardThe Recovery Time Objective (RTO) is the maximum acceptable duration of time that a system, application, or service can be unavailable after a disaster or disruption.
- Measures downtime duration.
- Determined by business impact analysis.
- Target for recovery efforts.
Memory trick: RTO is 'Time' to get back up; RPO is 'Point' of data loss.
Cryptography
Flip cardCryptography is the science of secure communication, focusing on methods to protect information and communications through the use of codes, so that only those for whom the information is intended can read and process it.
- Used for confidentiality, integrity, and non-repudiation.
- Involves encryption, decryption, hashing, and digital signatures.
- Essential for protecting data at rest, in transit, and in use.
Memory trick: CIA ensures data's security, Cryptography is the key.
Vulnerability Prioritization
Flip cardVulnerability prioritization is the process of ranking identified vulnerabilities based on their potential impact, exploitability, and the criticality of the affected assets, to determine the order and urgency of remediation efforts.
- Crucial for efficient resource allocation.
- Considers severity, exploitability, and asset criticality.
- Enables a risk-based approach to remediation.
Memory trick: ID, Assess, Prioritize, Remediate, Verify, Monitor.
Incident Containment
Flip cardIncident containment is the phase of incident response focused on limiting the scope and impact of an ongoing security incident. It prevents further damage and unauthorized access.
- Aims to stop the spread of an incident.
- Can involve technical controls like blocking IPs or isolating systems.
- Should be executed quickly to minimize impact.
Memory trick: PICERL: Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned.
Anomaly Detection
Flip cardAnomaly detection is a technique used to identify events or patterns that do not conform to expected behavior.
- Identifies deviations from a baseline.
- Can detect novel attacks or insider threats.
- Often relies on statistical models, machine learning, or rule-based systems.
Memory trick: Anomalies are the 'odd ones out' in the security data crowd.
Gray Box Testing
Flip cardA penetration testing approach where the tester has some knowledge of the internal structure, design, or implementation of the system being tested, but not full access or complete transparency.
- Combines elements of black box and white box testing.
- More efficient than black box as some reconnaissance is skipped.
- Less comprehensive than white box but more realistic than black box.
Memory trick: PEN TEST BOXES: BLACK is blind, WHITE is open, GRAY is in-between.
Least Privilege
Flip cardA security principle that requires giving an individual the minimum level of access or permissions necessary to perform their job function, and no more.
- Reduces the attack surface and potential damage from compromise.
- Applies to users, processes, and applications.
- Often implemented through role-based access control (RBAC).
Memory trick: SECURITY PRINCIPLES are like a fortress: LEAST privilege, SEPARATION of duties, NEED-TO-KNOW, and ACCOUNTABILITY.
Administrative Controls
Flip cardAdministrative controls are security safeguards implemented through policies, procedures, guidelines, and training to manage how an organization protects its assets.
- Focus on human behavior and organizational processes.
- Examples include access control policies, security awareness training, incident response plans, and hiring procedures.
- Often define the 'what' and 'how' for other control types.
Memory trick: TAP, as in 'Tap into security with Technical, Administrative, and Physical controls!'
Business Impact Analysis (BIA)
Flip cardA BIA is a systematic process to evaluate the potential effects of an interruption to critical business operations. It identifies critical functions, their dependencies, and the financial, operational, and reputational impacts of various outage scenarios.
- Identifies critical business functions and processes.
- Determines the impact of disruptions over time.
- Establishes Maximum Tolerable Downtime (MTD).
- Forms the foundation for recovery strategies and RTO/RPO.
Memory trick: BIA: What hurts most, how bad, how long?
SIEM Correlation Engine
Flip cardA core component of a Security Information and Event Management (SIEM) system responsible for analyzing aggregated log and event data to identify patterns, anomalies, and potential security incidents.
- Connects disparate events to form a coherent picture.
- Uses rules, heuristics, and machine learning for detection.
- Generates alerts for security analysts to investigate.
Memory trick: SIEM has AGGREGATION, CORRELATION, INTEL, and REPORTS for security insight.
Business Continuity Planning (BCP)
Flip cardBusiness Continuity Planning (BCP) is the process of creating systems of prevention and recovery to deal with potential threats to a company. It ensures that critical business functions can continue to operate during and after a disaster.
- Focuses on maintaining business operations.
- Broader than Disaster Recovery (DRP).
- Includes people, processes, physical infrastructure, and IT.
Memory trick: BCP keeps the 'Business' running; DRP recovers 'Data' and systems.
Change Advisory Board (CAB)
Flip cardThe CAB is a group of stakeholders, including IT, security, and business representatives, responsible for reviewing, approving, and prioritizing proposed changes to IT services and infrastructure. Its role is to minimize risk and ensure changes align with business objectives.
- Reviews and approves proposed changes.
- Assesses risks and impacts of changes.
- Ensures changes adhere to organizational policies.
Memory trick: Plan, Request, Assess, Approve, Implement, Review.
Continuous Monitoring
Flip cardThe ongoing, real-time or near real-time assessment of an organization's security posture to identify vulnerabilities, threats, and compliance deviations.
- Detects changes in configuration and security state.
- Crucial for dynamic environments like cloud.
- Involves automated tools and regular reviews.
Memory trick: ASSESSMENT STRATEGIES include MONITORING for ongoing health, VULNERABILITY scans, and POLICY enforcement.
Physical Layered Security
Flip cardPhysical layered security, or defense-in-depth, involves implementing multiple, concentric rings of physical controls to protect assets. Each layer provides a barrier that an intruder must overcome, increasing the time and effort required for unauthorized access and enhancing detection opportunities.
- Uses multiple physical controls (e.g., fences, guards, locks, cameras).
- Each layer adds delay and detection capabilities.
- Protects critical assets by preventing single points of failure.
- Examples include perimeter, building, room, and rack-level controls.
Memory trick: Circles of protection, like an onion.
Network Baslining
Flip cardNetwork baselining is the process of capturing and analyzing network performance and traffic data over a period to establish a 'normal' operational state. This baseline is then used to detect deviations that may indicate performance issues, security incidents, or policy violations.
- Identifies normal traffic patterns and volumes.
- Crucial for anomaly detection and security monitoring.
- Requires data collection over time to account for variations.
- Often involves network flow data (NetFlow, sFlow, IPFIX).
Memory trick: Know what's normal to spot the abnormal.
STRIDE Threat Modeling
Flip cardA threat modeling framework developed by Microsoft that categorizes potential threats into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
- Used to identify threats against systems and applications.
- Helps ensure comprehensive coverage of potential attack vectors.
- Often used early in the Software Development Life Cycle (SDLC).
Memory trick: THREAT MODELING uses STRIDE to categorize, DREAD to rate, and ATT&CK to map attacks.
Data Residency
Flip cardThe legal and regulatory requirement that certain data must be stored within the borders of a specific country or jurisdiction.
- Also known as data sovereignty.
- Driven by national laws and regulations (e.g., GDPR, local privacy laws).
- Impacts cloud computing, backup strategies, and global data transfers.
Memory trick: Privacy protects, residency restricts, purpose limits.
Annualized Loss Expectancy (ALE)
Flip cardThe expected monetary loss from a risk over a one-year period.
- Calculated as SLE x ARO.
- Helps prioritize risks based on financial impact.
- A quantitative risk assessment metric.
Memory trick: Quantify losses, annualize occurrence, expect the total.
Risk Mitigation (Control)
Flip cardImplementing controls to reduce the likelihood or impact of a risk event.
- Often involves technical, administrative, or physical safeguards.
- Aims to lower risk to an acceptable level when avoidance isn't feasible.
- Examples include patching, segmentation, encryption, and training.
Memory trick: AART for risk: Avoid it, Accept it, Reduce it, Transfer it.
Confidentiality
Flip cardThe principle of preventing unauthorized disclosure of information.
- Ensures privacy and secrecy of data.
- Protects against unauthorized access and disclosure.
- Often implemented through encryption, access controls, and data classification.
Memory trick: CIA: Keep secrets, stay whole, always ready to go!
Security Policy
Flip cardA high-level document, typically approved by senior management, that defines an organization's overall security objectives, rules, and acceptable practices. It sets the strategic direction for information security.
- Mandatory and applies to all relevant personnel.
- High-level and technology-independent.
- Serves as the foundation for standards, guidelines, and procedures.
Memory trick: Policies are the 'King' – high-level rules for all.
Pragmatic Risk Management
Flip cardSelecting risk treatment strategies that are practical, feasible, and effective given an organization's specific resources, constraints, and risk appetite.
- Balances security needs with budget, staff, and operational realities.
- Prioritizes actions that deliver the most impact for the least cost/effort.
- Often involves leveraging external services or simpler, robust solutions.
Memory trick: Budget tight, risk high? Focus on vital, outsource smart, protect core.
Supply Chain Security
Flip cardThe process of securing the entire lifecycle of a product or service, from design to disposal, including all third-party components and services.
- Involves managing risks associated with vendors, suppliers, and external partners.
- Focuses on transparency, trust, and continuous monitoring.
- Tools include SBOMs, vendor risk assessments, and contractual agreements.
Memory trick: Vendor Beware: Know your parts, audit their processes, build trust.
Security Policies, Standards, and Procedures
Flip cardHierarchical documentation that defines an organization's security posture, requirements, and implementation steps.
- Policies are high-level statements of intent.
- Standards define mandatory requirements for systems and processes.
- Procedures provide detailed, step-by-step instructions for tasks.
Memory trick: Policies set the path, standards define the goal, procedures show the way.
Risk Management Framework (RMF)
Flip cardA structured approach to integrating security and privacy into the system development life cycle and throughout the entire organization.
- Provides a systematic process for managing security risks.
- Typically includes steps like categorizing, selecting, implementing, assessing, authorizing, and monitoring.
- Aids in ensuring compliance and reducing organizational risk.
Memory trick: Plans for every security scenario, from daily risks to disasters.
Risk Mitigation
Flip cardA risk management strategy that involves taking actions to reduce the likelihood or impact of a risk. This can include implementing security controls, policies, or procedures.
- Reduces the probability or consequence of a risk.
- Often involves implementing security controls (technical, administrative, physical).
- Aims to bring risk to an acceptable level.
Memory trick: A-A-M-T: Avoid, Accept, Mitigate, Transfer – ways to handle risk.
Vendor Risk Assessment
Flip cardThe process of identifying, evaluating, and mitigating potential risks associated with third-party vendors and their services.
- Crucial for supply chain security and compliance.
- Evaluates a vendor's security controls, policies, and financial stability.
- Should be conducted before contract signing and periodically thereafter.
Memory trick: Before you trust, you must assess.
Threat Modeling
Flip cardA structured approach to identify, quantify, and address security risks in a system or application design.
- Proactive security measure, typically done early in SDLC.
- Focuses on 'what can go wrong' from an attacker's view.
- Helps prioritize security efforts and design effective countermeasures.
Memory trick: Find the weaknesses before they find you: Scan, Model, PenTest, Audit.
Stakeholder Engagement
Flip cardThe process by which an organization involves people who may be affected by the decisions it makes or can influence the implementation of its decisions.
- Crucial for successful security programs.
- Ensures all perspectives and requirements are considered.
- Promotes ownership and support for security initiatives.
Memory trick: Govern with ALL hands on deck, from legal to tech.
Jurisdictional Restrictions
Flip cardLegal or regulatory limitations that dictate how data can be collected, stored, processed, or transferred based on the geographic location of the data, the entity, or the individuals involved.
- Crucial consideration for multinational organizations.
- Can impact cloud adoption and data outsourcing decisions.
- Examples include data residency requirements and cross-border data transfer prohibitions.
Memory trick: Privacy with borders, minimize data, design it in, and be safe.