Direct book connectionAccountability
Accountability makes people, roles, services, and organizations answerable for security decisions and actions by assigning ownership and preserving reliable evidence.
Open article →Direct book connectionAlert Triage
Alert triage is the rapid, evidence-based process of validating a security alert, estimating urgency and impact, and deciding the correct next action.
Open article →Direct book connectionAsset Inventory
An asset inventory is an authoritative record of the hardware, software, services, cloud resources, data stores, operational technology, and other components the organization must manage and protect.
Open article →Direct book connectionAttack Paths
An attack path is a sequence of reachable systems, identities, trust relationships, weaknesses, and actions that could let an adversary move from an initial foothold to a valuable objective.
Open article →Direct book connectionAttack Vectors
An attack vector is the route, method, or mechanism an adversary uses to reach a target and attempt an unauthorized action.
Open article →Direct book connectionAuthentication Factors
Authentication factors are independent categories of evidence used to prove control of an identity, commonly something known, possessed, or inherent to the user.
Open article →Direct book connectionBusiness Impact Analysis
A business impact analysis identifies essential activities, dependencies, outage consequences, and recovery priorities so continuity and disaster-recovery plans reflect business needs.
Open article →Direct book connectionComplete Mediation
Complete mediation requires every security-relevant access request to be checked against current authorization rules rather than relying indefinitely on an earlier decision.
Open article →Direct book connectionControl Objectives
A control objective states the security or risk outcome a control or group of controls is intended to achieve, providing a basis for design, implementation, and assessment.
Open article →Direct book connectionData Classification
Data classification assigns meaningful categories to information so protection, access, retention, sharing, monitoring, and disposal can be aligned with risk.
Open article →Direct book connectionData Loss Prevention
Data loss prevention identifies and controls sensitive information as it moves through endpoints, networks, applications, cloud services, and storage locations.
Open article →Direct book connectionData Minimization
Data minimization limits collection, use, sharing, precision, and retention to what is necessary for a defined and legitimate purpose.
Open article →