Foundations & Risk
- Cybersecurity
- The people, processes, and technologies used to protect computers, networks, services, and data from unauthorized access, damage, or disruption.
- CIA triad
- A basic security model built around confidentiality, integrity, and availability: keeping information private, correct, and accessible when needed.
- Asset
- Anything an organization values and may need to protect, such as data, devices, software, services, people, or facilities.
- Threat
- A circumstance or actor with the potential to cause harm by exploiting a weakness or disrupting an asset.
- Threat actor
- A person or group that may attempt harmful activity against systems or information, whether for profit, influence, espionage, or another motive.
- Vulnerability
- A weakness in software, hardware, configuration, or a process that could be used to cause harm or gain unauthorized access.
- Risk
- The possibility of loss or harm, considered in terms of how likely a threat is to affect an asset and how serious the impact could be.
- Attack surface
- The set of places where an attacker could try to enter, interact with, or affect a system, including exposed services, accounts, devices, and people.
- Security control
- A safeguard or measure—such as a policy, process, or technical mechanism—used to reduce security risk.
Identity & Access
- Authentication
- Checking evidence to establish that a user, device, or service is the identity it claims to be.
- Authorization
- Determining what an authenticated identity is permitted to see or do.
- Multi-factor authentication (MFA)
- Authentication that requires evidence from at least two different factor categories, such as something you know, have, or are.
- Least privilege
- Giving each user, device, or service only the permissions it needs, for only as long as it needs them.
- Access control
- The rules and mechanisms that decide who or what may access a resource and which actions are allowed.
- Role-based access control (RBAC)
- An access-control approach where permissions are assigned to roles, and users receive permissions through their assigned roles.
- Single sign-on (SSO)
- A sign-in arrangement that lets a user authenticate once with a trusted identity provider and access multiple connected services.
- Identity and access management (IAM)
- The policies and systems used to create, verify, manage, and remove identities and control their access to resources.
- Zero trust
- A security approach that does not grant trust solely because of network location; access is evaluated using identity, context, and policy.
Networks & Endpoints
- Network segmentation
- Dividing a network into smaller, controlled zones so access between them can be limited and a compromise is less likely to spread.
- Firewall
- A device or software control that permits or blocks network traffic according to configured rules.
- Intrusion detection system (IDS)
- A system that monitors activity for signs of suspicious or prohibited behavior and raises alerts; it typically does not block traffic by itself.
- Virtual private network (VPN)
- A technology that creates an authenticated, protected connection across a network that is not fully trusted; it does not by itself make a device or service safe.
- Domain Name System (DNS)
- The naming system that helps devices find internet services by translating domain names, such as example.com, into network addresses.
- Transport Layer Security (TLS)
- A protocol used to protect data in transit and help authenticate a server, commonly used for HTTPS connections.
- Endpoint
- A device that connects to or participates in a network, such as a laptop, phone, server, or workstation.
- Endpoint detection and response (EDR)
- Security technology that collects endpoint activity to help detect suspicious behavior, investigate it, and take response actions.
- Secure configuration
- Setting up systems with security in mind, including removing unnecessary services, changing unsafe defaults, and limiting access.
Vulnerabilities & Attacks
- Malware
- Software or code intentionally designed to perform harmful or unauthorized actions, such as stealing information or disrupting systems.
- Ransomware
- Malicious software or an attack that blocks access to data or systems—often by encrypting data—and demands payment or another concession.
- Phishing
- A deceptive message or website designed to trick someone into revealing information, opening a harmful file, or taking an unsafe action.
- Social engineering
- Manipulating people into disclosing information or performing actions that weaken security, often by using urgency, authority, or trust.
- Exploit
- A method, code, or sequence of actions that takes advantage of a vulnerability to cause an unintended effect.
- Zero-day vulnerability
- A vulnerability that is unknown to, or lacks an available fix from, the responsible vendor or defender; the term's use can vary by context.
- Patch
- A software update that corrects defects or security weaknesses, or otherwise changes a product; applying patches helps reduce exposure to known issues.
- SQL injection
- A web-application flaw where untrusted input is handled as part of a database command, potentially allowing an attacker to read or alter data.
- Supply-chain attack
- An attack that compromises a target by abusing a supplier, software dependency, service provider, or distribution process connected to it.
Detection & Response
- Security log
- A time-stamped record of system or user activity that can help explain what happened and support detection or investigation.
- Security information and event management (SIEM)
- A system that collects and correlates security events from multiple sources to help analysts find suspicious patterns and investigate alerts.
- Security alert
- A notification that activity may match a security rule or indicate a possible threat; an alert needs assessment and is not automatically proof of an incident.
- Security incident
- An event, or series of events, that has compromised or threatens the confidentiality, integrity, or availability of systems or information.
- Incident response
- The coordinated process for preparing for, identifying, analyzing, containing, and recovering from security incidents, then improving from what was learned.
- Triage
- The initial assessment and prioritization of alerts or incidents to determine what needs investigation first and what response is appropriate.
- Containment
- Actions taken to limit an incident's spread or impact while investigation and remediation continue.
- Recovery
- Restoring affected systems and services to normal operation in a controlled way and checking that they remain secure.
- Threat hunting
- A proactive search through available data and systems for signs of malicious activity that automated alerts may have missed.
Cryptography & Data Protection
- Cryptography
- The use of mathematical techniques to protect information or verify its origin, including encryption, hashing, and digital signatures.
- Encryption
- Transforming readable data into a protected form using a key so that it cannot be understood without the appropriate decryption capability.
- Hashing
- Applying a one-way function to data to produce a fixed-size digest, often used to check integrity or safely verify stored passwords when done with a suitable password-hashing method.
- Digital signature
- A cryptographic proof, created with a private key and checked with a corresponding public key, that can help verify a message's origin and detect changes.
- Digital certificate
- A digitally signed document that binds an identity or named subject to a public key, with details that allow relying systems to validate it.
- Data classification
- Labeling information by sensitivity or importance so appropriate handling and protection requirements can be applied.
- Backup
- A separate, recoverable copy of data or system information, maintained so it can be restored after loss, damage, or an attack.
Governance & Resilience
- Security policy
- An organization's documented rules and expectations for protecting systems and information and assigning security responsibilities.
- Risk assessment
- A structured process for identifying assets, threats, vulnerabilities, and possible impacts so risks can be compared and addressed.
- Security awareness
- Helping people recognize security responsibilities and common risks, and know how to report or avoid unsafe activity.
- Vulnerability management
- The ongoing work of finding, prioritizing, addressing, and tracking vulnerabilities across an organization's systems.
- Penetration testing
- An authorized, scoped test that safely simulates selected attacker techniques to find and validate weaknesses in systems or processes.
- Red team
- A group that conducts authorized, realistic adversary simulations to test how well an organization can prevent, detect, and respond to attacks.
- Security framework
- A structured set of guidance, outcomes, or controls that helps an organization organize and improve its security program.
- Business continuity
- The plans and capabilities that help an organization continue delivering important services during disruption and restore normal operations afterward.