Companion-course connectionSystem Categorization and Impact Level
System categorization determines the potential impact of losing confidentiality, integrity, or availability for the information and services a system supports.
Open article →Companion-course connectionCIA Triad
The CIA triad is a foundational model for describing what security is trying to preserve: authorized access, trustworthy information, and dependable service.
Open article →Companion-course connectionCommon, Inherited, and System-Specific Controls
Common controls support multiple systems, inherited controls are received from another provider or environment, and system-specific controls are implemented for one system.
Open article →Companion-course connectionSystem Boundary and Scope
A system boundary identifies the components, data, people, services, interfaces, and dependencies included in a security or privacy assessment.
Open article →Companion-course connectionThreat Applicability Analysis
Threat applicability analysis tests whether an actor, technique, path, precondition, target, and consequence are relevant to a specific system before controls are selected or credited.
Open article →Companion-course connectionAI Audit Finding Follow-Up
AI audit finding follow-up verifies that corrective actions address the root cause, operate as intended, and reduce the stated risk before a finding is closed.
Open article →Companion-course connectionAI Control Monitoring
AI control monitoring observes whether preventive, detective, and corrective controls remain active, correctly configured, sufficiently covered, and effective as systems change.
Open article →Companion-course connectionAI Post-Deployment Monitoring
AI post-deployment monitoring measures whether a released system continues to perform, comply, and behave safely in its actual environment.
Open article →Companion-course connectionCardholder Data Environment
The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.
Open article →Companion-course connectionDigital Signatures and Non-Repudiation
Digital signatures use asymmetric cryptography to support message integrity, signer authentication, and evidence that an action came from a particular key holder.
Open article →Companion-course connectionIncident Closure Criteria
Incident closure criteria define the evidence and approvals required before an event leaves active response and enters monitoring, remediation, or normal operations.
Open article →Companion-course connectionLinux Account Lifecycle
Linux account lifecycle management governs creation, modification, suspension, deletion, home directories, shells, group membership, service identities, and residual access from onboarding through deprovisioning.
Open article →