Companion-course connectionSecurity Control Categories and Types
Security controls can be grouped by implementation category and by function, helping practitioners select, explain, and evaluate safeguards.
Open article →Companion-course connectionZero Trust Architecture
Zero Trust is an architectural approach that evaluates access requests using identity, device, resource, context, and risk while limiting implicit trust and lateral movement.
Open article →Companion-course connectionDefense in Depth
Defense in depth uses overlapping controls across people, process, technology, and physical environments to reduce the impact of any single weakness.
Open article →Companion-course connectionLeast Privilege
Least privilege reduces avoidable exposure by limiting users, services, applications, and devices to the permissions they actually require.
Open article →Companion-course connectionAuthentication, Authorization, and Accounting
AAA separates three connected functions: verifying identity, deciding allowed actions, and recording activity for accountability and investigation.
Open article →Companion-course connectionDigital Signatures and Non-Repudiation
Digital signatures use asymmetric cryptography to support message integrity, signer authentication, and evidence that an action came from a particular key holder.
Open article →Companion-course connectionMultifactor Authentication
Multifactor authentication strengthens sign-in by requiring independent evidence from different factor categories rather than relying on one credential alone.
Open article →Companion-course connectionSecure Change Management
Secure change management brings planning, review, testing, communication, evidence, and recovery into normal operational change.
Open article →Companion-course connectionCIA Triad
The CIA triad is a foundational model for describing what security is trying to preserve: authorized access, trustworthy information, and dependable service.
Open article →Companion-course connectionCybersecurity Risk Management
Cybersecurity risk management connects assets, threats, vulnerabilities, controls, consequences, uncertainty, priorities, and accountable decisions.
Open article →Companion-course connectionAI Security Governance
AI security governance establishes accountable decisions, controls, evidence, and oversight across the AI lifecycle without treating AI as either ordinary software or an unknowable special case.
Open article →Companion-course connectionCloud Shared Responsibility
Shared responsibility explains how cloud providers and customers divide security duties, while the customer remains accountable for understanding and operating its part of the service.
Open article →