TERMS ON FILE
The CISSP Glossary
CISSP exam vocabulary, defined for the candidate: precisely, briefly, and with the exam relevance stated. Listed A to Z, and filterable by CISSP domain.
#
Fourth-generation cellular technology, standardised by 3GPP as Long Term Evolution; where enabled, its encryption protects the radio link to the base station, not traffic end to end.
Fifth-generation cellular technology from 3GPP, commonly described as concealing the subscriber's permanent identity on the air, and introducing network slicing on shared infrastructure.
A
A list attached to an object that names which subjects may access it and which operations each may perform; the common enforcement mechanism behind discretionary access control.
A table with subjects as rows, objects as columns and the permitted rights in each cell; the abstract model from which access control lists and capability tables are both derived.
The approach a system uses to decide who may access what, and who controls those decisions: owner-set (DAC), label-based (MAC), role-based, rule-based, attribute-based or risk-based.
A periodic and event-driven check, usually signed off by the person accountable for the access, that each account and privilege is still needed, with anything unjustified removed.
In OAuth 2.0, the credential a client presents to a resource server to use a protected resource; it represents a granted authorisation, not proof of who the user is.
Disabling an account or authenticator for a period, or until an administrator releases it, after too many consecutive failed logon attempts, to limit online password guessing.
The ability to trace each action on a system to the one individual who performed it, which depends on unique accounts, strong authentication and protected audit records.
The protocol an IPv4 host uses to learn the hardware (MAC) address that belongs to an IP address on its own segment; it has no authentication, which is what ARP spoofing exploits.
Physical segmentation in which a system or network has no wired or wireless connection to any other network; data that must cross it moves on removable media or through people.
A denial-of-service technique that sends small spoofed requests to services whose replies are far larger, so the replies converge on the victim at many times the attacker's own traffic.
The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis.
Irreversibly processing personal data so that no one can be identified from it by any means reasonably likely to be used, which places the result outside the scope of the GDPR.
An addressing method in which several nodes share one address and routing delivers each packet to the nearest of them; widely used for resilient DNS and content delivery.
A firewall that terminates each connection and relays it through a proxy for a specific application protocol, so it can inspect and filter content at OSI layer 7.
A local-network attack in which forged ARP replies bind the attacker's MAC address to another host's IP address, so traffic meant for that host passes through the attacker.
Grouping assets such as systems, devices and facilities by value, sensitivity and criticality, so that the controls, monitoring and recovery priority each receives match its importance.
The maintained record of the assets an organisation holds, tangible and intangible, with each one's owner, location, classification and lifecycle state: the starting point for protecting them.
The individual accountable for an asset across its life: confirming its classification, approving its use and making sure suitable controls are in place, even when others operate it.
Encryption using linked key pairs where what the public key encrypts only the private key can decrypt; slow, so used for key exchange and signatures rather than bulk data.
Access control model that evaluates attributes of the subject, object, action, and environment (time, location, device) against policy for the most granular, context-aware decisions.
Proving a claimed identity by showing possession and control of one or more authenticators bound to that account; it follows identification and comes before authorisation.
NIST SP 800-63's three-step scale for the strength of an authentication process: AAL1 basic, AAL2 two distinct factors, AAL3 phishing-resistant hardware-backed keys.
A category of evidence used to authenticate: something you know, something you have or something you are. MFA requires more than one distinct type, not more than one item.
Three separate access functions: authentication proves identity, authorisation decides what that identity may do, and accounting records what it actually did.
Something a subscriber possesses and controls, such as a password, OTP device or cryptographic key, that is bound to their account and used to prove their identity.
The decision about what an authenticated identity may do: which resources it may reach and which operations it may perform, based on policy rather than on identity alone.
The OAuth 2.0 role that authenticates the resource owner, obtains their authorisation and issues access tokens (and often refresh tokens) to the client.
A self-assigned IPv4 address from 169.254.0.0/16 that a host takes when no DHCP server answers; it reaches only the local link and commonly signals a DHCP failure.
B
The intermediate links that carry traffic from a network's edge, such as cell sites or branch offices, back to its core; also the practice of routing remote traffic through a central site.
The maximum rate at which a link or path can carry data, stated in bits per second; a capacity figure, distinct from throughput, which is the rate actually achieved.
A system deliberately exposed to an untrusted network and hardened to withstand attack, commonly placed in a DMZ to run a public service or act as a controlled point of entry.
A token that grants access to whoever holds it, with no further proof of identity or key possession; OAuth access tokens are commonly used this way, so a stolen one works for the thief.
The confidentiality-only security model behind CISSP Domain 3: No Read Up (Simple Security Property) and No Write Down (Star Property) keep classified data from leaking downward.
The integrity counterpart to Bell-LaPadula: No Read Down and No Write Up stop trusted data from being contaminated by less trustworthy sources. Confidentiality is out of scope.
Authentication by a measured physical or behavioural characteristic, such as a fingerprint, face, iris or typing rhythm: something you are, matched against a threshold rather than exactly.
A Bluetooth attack that exploits firmware flaws in some older devices to use the device's own commands, such as placing calls, sending messages or reading data, without the owner knowing.
Sending unsolicited messages to nearby Bluetooth devices; the message does no harm to the device, but it can lure the user into a harmful response, much as spam or phishing does.
Unauthorised access to data on a Bluetooth device, such as contacts, messages or the device identifier, by forcing a connection through firmware flaws found in some older devices.
An open standard for short-range radio links between personal devices such as phones, headsets and sensors; its security rests on pairing, discoverability settings and firmware quality.
The routing protocol that exchanges reachability between the internet's autonomous systems; announcements a peer does not filter or validate can carry false routes that redirect traffic.
A network of compromised devices, each a bot, that an attacker directs remotely through command-and-control channels to run coordinated activity such as DDoS attacks, spam or credential stuffing.
A highly privileged emergency account kept sealed for use when normal administrative access has failed, with every use alerted, reviewed and followed by a credential change.
A layer 2 device that joins network segments and forwards frames between them by MAC address, separating collision domains while leaving a single broadcast domain.
Delivery of a single frame or packet to every host in a broadcast domain; IPv4 relies on it for ARP and DHCP, while IPv6 has no broadcast and uses multicast for those jobs.
The organisation-wide plan for keeping critical business functions running during and after a disruption. The umbrella programme that disaster recovery sits underneath.
The process that identifies critical business functions and the impact of their disruption over time, producing the recovery metrics (RTO, RPO, MTD) that drive continuity planning.
The senior official accountable for a line of business or a mission, who defines what its supporting systems and data must achieve and weighs their protection against business need.
C
A list bound to a subject that records every object it may access and the rights it holds over each; one row of the access control matrix, and the counterpart to an access control list.
A web page that holds a newly connected device's traffic until the user authenticates, accepts terms or pays; common on guest Wi-Fi, it controls access but does not encrypt the connection.
Media access methods where a device listens before it transmits on a shared medium: CSMA/CD detects collisions on wired Ethernet, CSMA/CA tries to avoid them on wireless networks.
The AES-based data protection protocol from IEEE 802.11i that WPA2 requires: counter mode encrypts each frame and CBC-MAC checks its integrity, replacing the RC4-based TKIP.
A signed record that specific media or records were sanitised or destroyed, stating what was processed, by which method, when and by whom, kept as evidence for audit and chain of custody.
Hardcoding which certificate or public key a client will accept for a service, so a fraudulent certificate from a compromised CA is rejected even though it validates normally.
Documented, unbroken record of who collected, handled, transferred, and stored evidence, with times and locations, proving it was not altered between collection and court.
A PPP authentication protocol (RFC 1994) where the server sends a random challenge and the client returns a hash of it with a shared secret, so the secret never crosses the link.
Formal process taking every change through request, approval, testing, and rollback planning before implementation, so changes are deliberate, documented, and reversible.
The Brewer-Nash model: access rights change dynamically based on what a user has already accessed, blocking conflicts of interest between competing clients' data.
The set of cryptographic algorithms a client and server agree to use for one TLS connection, covering key exchange, authentication, bulk encryption and integrity.
A communication method that sets up a dedicated path between two endpoints before any data flows and holds it, with its capacity reserved, for the whole session.
A firewall or proxy working at the session layer that validates the setup of a connection, then relays its traffic without inspecting the application content inside.
A single statement about a subject, such as its identifier, an attribute, or a token's issuer or expiry, asserted by an issuer and trusted only as far as the issuer and its signature are.
A commercial integrity model built on well-formed transactions and separation of duties: users change data only through certified programs, never directly. Access triple: subject, program, object.
The IP addressing and routing scheme that replaced fixed address classes with prefixes of any length, written as an address, a slash and the number of network bits.
A rule requiring staff to lock away sensitive papers and removable media and to lock their screens whenever they leave their workspace, so unattended information is not open to others.
The least intensive NIST SP 800-88 sanitisation method: overwriting or resetting all user-addressable storage so data resists simple recovery tools, while the media stays fit for reuse.
A threshold of routine errors or events that is tolerated before an activity is recorded as suspicious or an action is triggered, such as a set number of failed logons before lockout.
A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT.
Copper cable with one central conductor inside an insulating layer and a conductive shield, giving better resistance to electromagnetic interference than unshielded twisted pair.
A knowledge-based credential drawn from personal facts or opinions, such as a first pet's name, used for login or account recovery; weak because many answers can be found or guessed.
Alternate facility providing only space, power, and environmental support; hardware and data arrive after the disaster, so activation takes weeks, at the lowest standing cost.
Recovering data such as disk encryption keys from a computer's RAM shortly after power is cut, exploiting the fact that memory contents fade over seconds or minutes rather than at once.
The privacy principle that personal data is collected only as far as needed, by lawful and fair means, and where appropriate with the knowledge or consent of the person it concerns.
The servers and communication channels an attacker uses to send instructions to compromised systems, such as the bots in a botnet, and to receive data back from them.
An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it.
An open interconnect standard built on the PCI Express physical layer that links processors, accelerators and memory devices with cache coherency; the ISC2 outline names it as a converged protocol.
A repository of configuration items (the components that make up IT services) and the relationships between them, used to support change, incident and asset management.
A distributed set of servers that caches and serves content close to users; it can improve performance and availability, and where it terminates TLS the trust boundary moves to the provider.
Access control in which the decision turns on what the requested object contains, such as the values in a database record, as well as on who is asking.
Access control in which the decision depends on the circumstances of the request, such as time, location, device or the sequence of earlier actions, rather than on the data requested.
The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once.
Protocols that carry traffic which once needed its own separate network, such as storage or voice, over a shared network, usually an Ethernet or IP network.
A system that stores, issues and rotates secrets such as passwords, keys and certificates, so people and software no longer keep them in memory, in files or in code.
An automated attack that replays username and password pairs leaked in one breach against other services, succeeding wherever a user has reused the same password.
How essential an asset, system, process or data set is to the organisation, judged by how severely and how quickly its loss would cause harm. It mainly drives availability and recovery decisions.
The point at which a biometric system's false acceptance and false rejection rates are equal, commonly used to compare devices: a lower CER means better accuracy at that point.
Sanitising encrypted data by destroying every copy of the key that protects it, so the ciphertext left on the media or in a cloud service can no longer be decrypted.
A switch forwarding method that starts sending a frame on as soon as it has read the destination address, cutting latency but passing on damaged frames it cannot check.
D
Data held in persistent storage, such as disks, databases, backups, removable media and cloud object stores, as distinct from data moving across a network or being processed in memory.
The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it.
The person or organisation that decides why and how personal data is processed, alone or jointly with others, and so carries primary accountability for that processing under the GDPR.
The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data.
A picture of a system's components, the data moving between them and its trust boundaries, used as the surface a threat model is walked across element by element.
Data moving between systems, sites or users across a network, also called data in motion, and exposed to interception and tampering along the way unless the channel is protected.
Data being actively processed, held in memory, CPU registers or cache, or shown on a screen, where it normally has to be in plaintext for the application or person to work with it.
The stages information passes through from creation or collection to destruction, with security and privacy requirements attached to each stage according to the data's classification.
Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans.
The ongoing work of keeping stored data accurate, current and consistent across its lifecycle, including correction, review of its classification, and removal of stale copies.
Replacing sensitive values with realistic but fictitious or partly hidden ones, either permanently in a copy (static masking) or as data is queried or displayed (dynamic masking).
The principle that personal data collected and kept should be adequate, relevant and limited to what is necessary for the stated purpose, as set out in GDPR Article 5(1)(c).
The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated.
The three functional layers of a network device: the data plane forwards traffic, the control plane decides where it goes, and the management plane configures and monitors.
The binding contract that GDPR Article 28 requires between a controller and a processor, limiting processing to the controller's documented instructions and setting security duties.
A person or organisation that processes personal data on behalf of a controller and on its documented instructions, as defined in GDPR Article 4(8), without deciding the purposes.
The degree to which data is fit for its intended use, commonly judged on dimensions such as accuracy, completeness, consistency, validity, timeliness and uniqueness.
The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed.
The physical or geographic location where data is stored and processed, usually chosen by the organisation for legal, contractual, performance or customer reasons.
Keeping data for a defined period set by legal, regulatory and business requirements, then disposing of it securely, as documented in a retention policy and schedule.
The principle that data is subject to the laws and legal processes of the jurisdiction where it is stored, and sometimes of jurisdictions with authority over whoever holds it.
The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms.
The role responsible for a data set's quality, metadata and business meaning, making sure the data is accurate, well defined and fit for its purpose on behalf of the data owner.
The identified or identifiable natural person whom personal data relates to, as defined in GDPR Article 4(1), holding rights such as access, rectification, erasure and objection.
Anyone who accesses data to perform their job, bound by the acceptable use policy and by the handling requirements that follow from the data's classification.
The authorised removal of a classification once the information's sensitivity has lapsed, so that protection does not stay higher, or last longer, than the information needs.
The controlled retirement of an asset from service: revoking its access and identities, retaining or disposing of its data, sanitising its media, and updating the inventory.
Layering physical, technical, and administrative controls so no single control failure exposes an asset; every layer assumes the layer in front of it can be breached.
Destroying information routinely under a documented, consistently applied retention schedule, so the organisation can show the destruction was normal business practice, not concealment.
Erasing magnetic media by exposing it to a strong magnetic field matched to the media, a physical purge technique under NIST SP 800-88 that has no effect on flash storage or optical discs.
A network segment between an untrusted network and the internal one that holds the systems outsiders must reach, with traffic into the internal network limited to permitted flows.
An attack on availability that stops legitimate users reaching a system or service, by exhausting its resources or by exploiting a flaw that makes it crash.
Disabling or removing an account and revoking the access that went with it, including sessions, tokens and shared credentials, when a person leaves, moves role or no longer needs it.
A practice that makes security a shared responsibility across development and operations by automating security checks into the CI/CD pipeline instead of a bolt-on review at release.
An authentication, authorisation and accounting protocol defined in RFC 6733, commonly described as the successor to RADIUS and used mainly in mobile operator networks.
A password-guessing attack that tries entries from a prepared list of likely passwords, such as common choices, words and leaked values, instead of every possible combination.
Protection that travels with content: the file is encrypted and a policy, checked each time it is opened, controls who may view, edit, print, copy or forward it, even after distribution.
A message hash encrypted with the sender's private key, proving integrity, authenticity, and nonrepudiation to anyone with the matching public key; it provides no confidentiality.
A central, hierarchical store of identities and resources and their attributes, such as users, groups and devices, that systems query to identify, authenticate and authorise.
The IT-focused plan for restoring systems, infrastructure and data after a failure. One component beneath the business continuity plan, not a synonym for it.
Access controlled at the owner's discretion: whoever owns a resource decides who else may use it. Flexible, but permissions can spread in ways no central policy intended.
A denial of service attack launched from many systems at once, commonly a botnet or abused third-party servers, so no single source can be blocked to stop it.
A firewall whose policy is defined centrally but enforced at many points close to the workloads, such as on each host or in the virtual switch, rather than only at the network edge.
The policy layer that tests whether an SPF or DKIM pass aligns with the visible From domain, tells receivers what to do when neither does, and requests reports from them.
An industrial control protocol used mainly by electric and water utilities for SCADA communication, standardised as IEEE 1815 and commonly carried inside TCP/IP.
An attack that plants a forged record in a DNS resolver's cache, so the resolver hands the false answer to every client that asks until the record expires.
An attack that takes control of the settings that decide how names resolve, such as a DNS server, a domain's registrar account or a device's resolver, to redirect traffic.
A protocol that carries DNS queries and answers inside an encrypted HTTPS session, hiding them from observers on the path but also from the organisation's own DNS monitoring.
Extensions that let a resolver verify DNS answers through digital signatures and a chain of trust from the root, giving origin authentication and integrity but no confidentiality.
The internet's distributed naming service, resolving names to addresses. It is unauthenticated by default, which is why DNSSEC signs records and why poisoning and tunnelling remain testable.
A cryptographic signature over an email, verified against a public key in DNS. It proves integrity and which domain signed, provides no confidentiality, and survives a plain forward.
Microsoft's threat-scoring model: Damage, Reproducibility, Exploitability, Affected users, Discoverability, rated on an agreed scale to rank threats a framework such as STRIDE has already found.
A control that requires two or more people to act together, at the same moment, to complete a single sensitive operation, so that no individual can perform it alone.
Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part.
The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action.
Black-box testing that probes a running application from the outside, finding runtime and configuration flaws without source access, but unable to point to the offending line of code.
The protocol that leases IP addresses and settings such as the default gateway and DNS servers to hosts automatically, with no authentication of the server by default.
E
An EAP method in which the client and the authentication server each prove their identity with a digital certificate, giving mutual authentication with no password to steal.
Rules at the network edge that limit which traffic may leave, restricting outbound destinations and services and dropping packets whose source address is not the organisation's own.
Watching traffic that leaves the network for signs of data exfiltration, command-and-control beacons, and policy violations; the outbound counterpart to inbound-facing defences.
Forging the sender identity on a message. SMTP verifies neither the envelope sender nor the visible From, so the three forms differ in whether authentication can address them at all.
The wrapping of data from a higher network layer inside the header, and sometimes trailer, of the layer below as it moves down the stack; decapsulation removes them on arrival.
The vendor milestone after which a product is no longer sold or manufactured; patches and support usually continue until a later End of Support date.
The date a vendor stops issuing security patches, updates and technical help for a product, after which newly found vulnerabilities may stay unfixed while the product keeps running.
Host-based controls on the device itself, such as hardening, a host firewall, anti-malware, host intrusion detection and endpoint detection and response, complementing network controls.
A Wi-Fi mode that encrypts traffic on an open network with no password, using a key exchange at association, but authenticates neither the user nor the access point.
A wireless attack in which a malicious access point impersonates a legitimate network's name so that users connect to it, placing the attacker in the path of their traffic.
An OASIS standard defining an XML policy language for attribute-based authorisation, a request and response format, and a reference architecture of policy decision and enforcement points.
An authentication framework, defined in RFC 3748, that carries many different authentication methods between a device and an authentication server; it is not itself one method.
F
A failure mode where a control defaults to denying access when it loses power or malfunctions, protecting the asset; contrast fail safe, which defaults to protecting people.
The rate at which a biometric system wrongly accepts an impostor, commonly called a Type II error. Of the two biometric errors it is the one that admits the wrong person.
The rate at which a biometric system wrongly refuses a genuine, enrolled user, commonly called a Type I error. It costs convenience and availability rather than admitting an impostor.
Trust between organisations that lets one domain's identities access another's systems, with an identity provider asserting authentication to service providers via SAML, OAuth, or OIDC.
The NIST SP 800-63C-4 measure, from FAL1 to FAL3, of how strongly a federation protects the assertion an identity provider sends to a relying party.
The machine-readable description each federation party exchanges or publishes in advance, giving its identifier, service endpoints and public keys so its messages can be verified.
A converged protocol that carries Fibre Channel storage frames directly inside Ethernet frames, so storage and data traffic share one network, without IP and so without IP routing.
Transmission media that carries data as pulses of light through glass or plastic strands, immune to electromagnetic interference and not radiating the electrical emanations copper does.
Standards for public-key sign-in: the W3C Web Authentication API and the FIDO Alliance's CTAP, which let a browser use an authenticator whose key is bound to one website.
A legacy protocol for transferring files that sends credentials, commands and file contents in cleartext over separate control and data connections; commonly replaced by SFTP or FTPS.
A device or software that enforces a policy on traffic passing between networks or into a host, permitting or blocking it by rules based on addresses, ports, state or content.
A denial-of-service attack that sends UDP packets with the victim's spoofed source address to a broadcast address, so every responding host floods the victim with replies.
Two routes for federation and OAuth messages: the front channel passes through the user's browser, while the back channel runs directly between servers without the user in the path.
The File Transfer Protocol with TLS added to encrypt its control and data connections; not to be confused with SFTP, which is a separate protocol built on SSH.
G
Forging SAML assertions with an identity provider's stolen signing key, so an attacker can sign in to services that trust that key as any user they choose, bypassing the provider's login.
Forging Kerberos TGTs with the stolen KRBTGT password hash, giving an attacker any identity and any group membership in the domain, with a validity period the attacker chooses.
A security model defining eight primitive protection rights: how subjects and objects are securely created and deleted, and how access rights are granted, transferred, and revoked.
Two ways of administering access in bulk: a group collects accounts so permissions can be granted together, while a role is a set of permissions defined by a job function.
H
The rules, set by an asset's classification, for how information and assets are marked, stored, transmitted, accessed, retained and destroyed across their lifecycle.
Reducing a system's attack surface by removing unneeded software and services, closing ports, patching and applying secure settings, to bring it to a defined secure baseline.
A physical device that proves possession during authentication, either by displaying a one-time code or by performing a cryptographic operation with a key stored inside it.
A one-way function condensing any input into a fixed-length digest used to verify integrity; computationally infeasible to reverse, and secure only while collisions stay impractical.
The rule that a system, asset or collection takes the highest classification or impact level of any information it holds, so one confidential file makes a laptop confidential.
A one-time password algorithm, defined in RFC 4226, that computes each code from a shared secret key and a counter that advances every time a code is generated.
A spoofing technique that registers a domain name built from lookalike characters, often from another alphabet, so a fraudulent site or sender address looks legitimate at a glance.
Decoy system with no production value, deployed to attract attackers so their tools and methods can be observed; any interaction with it is suspicious by definition.
Fully equipped alternate facility with hardware, software, and near-real-time data replication in place, able to take over within hours; the fastest and most expensive option.
HTTP carried over TLS, protecting web traffic's confidentiality and integrity in transit and authenticating the server by certificate; it does not prove the site itself is trustworthy.
A layer 1 network device that repeats every signal it receives out of every other port, so all attached hosts share one collision domain and can see each other's traffic.
I
In OpenID Connect, the signed JSON Web Token that tells the client application who the user is and when and how they authenticated at the OpenID provider.
The step in which a subject claims an identity, usually by presenting a username or other unique identifier, before any proof of that claim is checked.
Identity and access management delivered as a cloud service by a third party, commonly covering directory, single sign-on, MFA, federation and account provisioning.
NIST SP 800-63 measure of how rigorously a person's identity was proofed before an account was issued, from IAL1 to IAL3, chosen by the harm a proofing failure would cause.
The step after identity proofing in which a proofed applicant is given an account and has authenticators bound to it, so that later logins can be tied to that identity.
Verifying that a person is who they claim to be before credentials are issued, using evidence such as documents or biometrics; the registration step that authentication later relies on.
The party in a federation that authenticates the user and issues a signed assertion or token about them to relying parties; called the OpenID Provider (OP) in OpenID Connect.
The IEEE standard for port-based network access control: a device (supplicant) must authenticate through the switch or access point (authenticator) to a server before the port opens.
The default rule that any access not explicitly permitted is refused, so a request that matches no allow rule fails rather than succeeds.
A device that impersonates a mobile network's base station so that nearby phones connect to it, exposing subscriber identities and, if it forces an older standard, possibly traffic.
In-band management reaches devices over the production network they serve; out-of-band management uses a separate path that does not depend on that network being healthy.
Managed lifecycle for handling security incidents: detection, response, mitigation, reporting, recovery, remediation, and lessons learned, limiting damage and preventing recurrence.
A converged protocol that carries InfiniBand's remote direct memory access (RDMA) transport over Ethernet, commonly implemented as RDMA over Converged Ethernet (RoCE).
Filtering of traffic entering a network, commonly used at the edge to drop packets whose source addresses cannot legitimately arrive from that direction (anti-spoofing).
An asset with no physical form, such as data, software, intellectual property, trade secrets or reputation, valued by what its loss or disclosure would cost rather than by a price tag.
The IP suite's error-reporting and diagnostic protocol: it carries messages about delivery problems and network status, works at the Network layer, and uses no port numbers.
The protocol IPsec uses to authenticate peers and negotiate security associations, agreeing the algorithms and deriving shared keys through a Diffie-Hellman exchange.
The connectionless Network-layer protocol that carries packets between networks using logical source and destination addresses, with best-effort delivery and no guarantee of arrival.
Monitoring control that inspects network traffic or host activity for signs of attack and raises alerts without blocking; detection is signature-based or anomaly-based.
Layer 3 protocol suite securing IP traffic: AH gives integrity and origin authentication only, ESP adds confidentiality, and tunnel mode wraps the whole original packet for VPNs.
Version 4 of the Internet Protocol (RFC 791), whose 32-bit addresses give a space of about 4.3 billion, now exhausted and stretched by private ranges and address translation.
Version 6 of the Internet Protocol (RFC 8200), with 128-bit addresses written in hexadecimal, no broadcast, and a simpler base header, designed to replace the exhausted IPv4 space.
A converged protocol that carries SCSI storage commands over TCP/IP, letting servers use remote block storage across an ordinary IP network instead of dedicated storage links.
The practice of tracking IT hardware, software and related contracts across their lifecycle, from request and purchase through use and maintenance to retirement and disposal.
J
Variation in packet delay over time, so packets of one stream arrive at uneven intervals; it harms real-time traffic such as voice and video more than bulk data transfer.
A compact, URL-safe token format defined in RFC 7519 that carries claims as JSON, usually signed so the recipient can detect tampering, and widely used for ID and access tokens.
A hardened, closely monitored host that administrators connect to first and from which they reach systems in a protected zone, giving one controlled path for administrative access.
Privilege model granting elevated rights only for the duration of a task and revoking them afterwards, which removes the standing privileges that attackers commonly harvest through credential theft.
Creating a user's account at a relying party automatically the first time a federated identity arrives there, using attributes from the assertion, instead of creating it in advance.
K
An attack where any authenticated domain user requests service tickets for accounts with SPNs, then cracks them offline to recover service account passwords. No admin rights needed.
The ticket-based network authentication protocol tested in CISSP Domain 5: a trusted KDC issues a TGT, then service tickets, using symmetric encryption so passwords never cross the wire.
The trusted third party at the heart of Kerberos, combining the Authentication Service and Ticket Granting Service. In Active Directory every domain controller runs a KDC.
Holding copies of cryptographic keys with a trusted third party so they can be recovered for continuity or produced for lawful access, trading confidentiality risk for availability.
A forward-looking metric that warns risk exposure is approaching an unacceptable level, triggering management action before loss occurs, unlike a KPI, which measures achieved performance.
The built-in Active Directory account whose password hash encrypts and signs every TGT in the domain. Stealing it enables golden tickets; remediation is a careful double password reset.
L
The time data takes to travel from source to destination, measured one way or as a round trip; it is a delay, distinct from bandwidth, which is a measure of capacity.
The legal ground under GDPR Article 6 that permits processing of personal data: consent, contract, legal obligation, vital interests, public task or legitimate interests.
A tunnelling protocol that carries PPP frames across an IP network; it provides no strong encryption of its own, so it is commonly paired with IPsec as L2TP/IPsec for VPNs.
Configuring a system to provide only the functions, ports, protocols, software and services its mission requires, and disabling or removing the rest to reduce the attack surface.
Granting each user, process, or account only the access its task requires, and no more. Limits the damage from mistakes, malware, and compromised credentials alike.
The standard protocol for querying and updating a directory service, defined in RFC 4511; also used to check credentials by binding to the directory as a user.
A device or service that spreads incoming requests across a pool of servers and removes failed ones from rotation, improving availability and capacity for the service behind it.
Access control enforced electronically by hardware or software, such as authentication, permissions, access control lists and network rules, as opposed to physical barriers.
Removing a file's directory entry or pointer and marking its space as free, while the underlying data stays on the media until something else happens to overwrite it.
M
A switch attack that fills the MAC address table with forged source addresses so the switch floods frames out of every port, letting an attacker capture traffic meant for others.
An attack where the adversary secretly relays, and can alter, traffic between two parties who believe they communicate directly; defeated by mutual authentication and certificate validation.
Access decided by the system comparing security labels against clearances, under a policy users cannot override. Not even a file's owner can share it outside policy.
Showing an asset's classification: human-readable markings on documents, screens and media, and machine-readable labels that a system uses to enforce access decisions.
The longest a business process can be unavailable before the damage becomes unacceptable. The outer boundary every other recovery metric must fit inside: RTO plus WRT.
A hardware identifier, 48 bits in its common form, assigned to a network interface and used to deliver frames on a local network segment at the Data Link layer.
Making data on storage media infeasible to recover for a given level of effort, using the Clear, Purge or Destroy methods described in NIST SP 800-88.
An attack in which someone holding a stolen password triggers repeated MFA push prompts until the user approves one, often out of annoyance or after a fake support call.
Applying access policy to small groups of workloads, often a single workload or application, and enforcing it close to the workload rather than only at a network boundary.
Testing that verifies what a system must not allow, inverting use cases into abuse scenarios to prove that invalid, malicious, or out-of-sequence actions are rejected.
Central tooling that enrols phones, tablets and laptops and enforces configuration, encryption, passcode, app and remote-wipe policy on the devices that hold organisational data.
Authentication requiring two or more different factor types (something you know, have, or are); two instances of the same type, such as two passwords, remain single-factor.
One-to-many delivery in which a single transmission reaches only the hosts that have joined a group, rather than one host (unicast) or every host on the segment (broadcast).
A protocol whose functions span several OSI layers, or a suite that nests protocols inside one another; the flexibility also allows covert channels and filter bypass.
A carrier forwarding technique that sends packets along pre-established paths by reading short labels instead of IP addresses; it separates customers' traffic but does not encrypt it.
Both parties verify each other's identity before communicating: the client proves itself to the server and the server proves itself back. A defining property of Kerberos.
N
A very short-range wireless technology, derived from RFID, that lets two devices exchange data when held a few centimetres apart; used for contactless payment, access cards and pairing.
Restricting access to specific information to those with an operational requirement for it, applied after clearance rather than instead of it.
Admission control that authenticates devices and checks their security posture before granting network access, typically via 802.1X, shunting failures to a quarantine VLAN.
Rewriting of IP addresses in packet headers as traffic crosses a boundary device, so hosts on privately addressed networks can reach the internet through public addresses.
Running network functions such as firewalls, routers and load balancers as software on general-purpose servers instead of on dedicated hardware appliances.
A virtual network built on top of an existing physical network by encapsulating its traffic, so separate segments can share one underlying network.
Dividing a network into isolated zones so compromise of one cannot spread laterally; spans physical separation, logical VLANs and firewalls, and workload micro-segmentation.
A 5G capability that runs several logically separate end-to-end networks over the same physical infrastructure, each configured for a different service or customer.
A layer 2 device that forwards frames to the port where the destination MAC address was learned, instead of repeating every frame to every port as a hub does.
The protocol hosts use to synchronise their clocks with reference time sources over a network, which log correlation, Kerberos and certificate checks all depend on.
The arrangement of a network's nodes and links, such as bus, star, ring or mesh, which determines where single points of failure sit and how faults spread.
A firewall that adds application awareness, user identity and integrated intrusion prevention to stateful inspection, so policy can name applications rather than only ports.
NIST's Guidelines for Media Sanitization, which sort sanitisation methods into Clear, Purge and Destroy and help an organisation choose one by media type, sensitivity and destination.
The Biba rule that a subject cannot read data of lower integrity than its own, stopping trusted processes from being corrupted by unreliable input.
The Bell-LaPadula rule that a subject cannot read data classified above their clearance. Confidentiality's ceiling: a Secret clearance never opens a Top Secret file.
The Biba rule that a subject cannot write to a higher integrity level, stopping unreliable processes from injecting bad data into trusted records.
Any access control approach in which a central authority or system policy, not the owner of a resource, decides who may access it; the opposite of discretionary access control.
Assurance that a party cannot credibly deny an action. It needs a secret only that party holds, which is why digital signatures provide it and shared-key MACs cannot.
North-south traffic crosses the boundary of the network being protected; east-west traffic moves between systems inside it. Both labels depend on which boundary is named.
O
Authorisation framework (RFC 6749) that lets a user grant an application limited access to their resources on another service through access tokens, without sharing their password.
In OAuth 2.0, the application that requests access to protected resources on the user's behalf, receiving a limited access token; RFC 6749 classes it as confidential or public.
The defined procedure an OAuth 2.0 client follows to obtain an access token, such as the authorization code or client credentials grant; the implicit grant is now discouraged.
In access control, the passive resource being protected, such as a file, database record, service, device or room, which a subject requests access to.
A code valid for a single authentication, generated by a token or app from a shared secret and a counter or clock; proves possession of the device but is not phishing-resistant.
An authentication layer built on OAuth 2.0 that lets an application verify who the user is, through a signed ID token issued by an OpenID Provider.
An active account that is no longer tied to a current owner, such as a leaver's account left enabled or a service account whose owner has moved on; a standing credential nobody watches.
Seven-layer reference model, physical to application, used to place protocols, devices, and attacks at the layer where they operate; a common framework for classifying them.
Writing new data, such as a fixed pattern of zeros, over the locations that held old data on storage media, so the original contents can no longer be read back by ordinary means.
P
Capturing and reading network traffic as it crosses a medium, used legitimately for troubleshooting and monitoring, and by attackers to collect credentials and data.
A method of data communication that splits messages into packets which share network links and are forwarded independently, instead of reserving a dedicated path per call.
A stateless firewall that allows or denies each packet on its own by matching header fields, such as addresses, ports and protocol, against an ordered rule list.
Authenticating with a stolen password hash instead of the password itself, exploiting NTLM's use of the hash as the credential; no cracking needed, the hash is the secret.
Stealing valid Kerberos tickets from a compromised machine's memory and replaying them from another system, authenticating as the victim without knowing any password or hash.
A passwordless sign-in credential built on FIDO2 and WebAuthn: a key pair bound to one site, with the private key kept on the user's device or synced, unlocked locally by biometric or PIN.
A PPP authentication method in which the client sends its username and password to the server in clear text, with no challenge and no protection against capture or replay.
The rules an organisation sets for choosing, checking, storing and changing passwords. Current NIST guidance favours length and blocklist screening over complexity rules and forced expiry.
An online guessing attack that tries a few common passwords against many accounts, keeping each account below its lockout threshold so per-account defences are not triggered.
A system that stores passwords and other secrets encrypted and releases them only to authorised users or software; enterprise vaults can also check out, log and rotate privileged credentials.
Authentication that removes the password a user types and a server stores, commonly replacing it with a cryptographic key held on a device and unlocked locally by a PIN or biometric.
A direct interconnection between two networks so they can exchange traffic with each other, rather than sending it through a third-party transit provider.
An authorised simulated attack, run under written rules of engagement, that proves whether weaknesses are actually exploitable rather than merely listing them.
Authentication whose protocol keeps secrets and valid outputs away from an impostor site without relying on user vigilance, by binding a cryptographic proof to the real verifier or channel.
Controls that decide who can enter a site, room or cabinet and physically reach an asset, such as locks, badge readers, guards, fences and access control vestibules, with entries logged.
Sanitising media by shredding, disintegrating, pulverising, melting or incinerating it, so data cannot be recovered even in a laboratory and the media cannot be used again.
A denial-of-service attack that sends a malformed, oversized ICMP echo request in fragments, so reassembly overflows a buffer and crashes an unpatched system.
An OAuth 2.0 extension (RFC 7636) that binds an authorization code to the client that requested it, designed so that an intercepted code cannot be redeemed by another party.
A data link layer protocol that frames traffic over a direct link between two nodes and negotiates the link, optional authentication and the network protocols it will carry.
An early VPN protocol that tunnels PPP sessions across an IP network; its usual authentication and encryption pairing has known weaknesses, so it is treated as obsolete.
The component where access policies are written, tested, managed and stored before a policy decision point applies them to requests. It authors the rules; it does not decide requests.
The NIST SP 800-207 zero trust component that carries out the policy engine's decision by commanding enforcement points to open or close the path between a subject and a resource.
The component that evaluates an access request against the applicable policy and attributes and returns a verdict, such as permit or deny. It decides; a separate enforcement point acts on it.
The gatekeeper between a subject and a resource that passes each access request to a decision point and applies the verdict it receives by allowing or refusing the access.
The NIST SP 800-207 zero trust component that makes the final grant, deny or revoke decision on a subject's access to a resource, feeding policy and live signals into a trust algorithm.
An attribute source consulted during an access decision: it returns facts about the subject, resource, action or environment that the policy decision point needs to evaluate a rule.
A form of NAT in which many internal hosts share one public IP address, distinguished by translating each session's source port as well as its address.
Marking each section, paragraph or item of a document with its own classification, so readers can see which parts are sensitive, while the overall banner shows the highest level.
An IPv4 address from the ranges RFC 1918 reserves for internal networks: usable by any organisation, and not routed on the public internet.
Access that piles up over time when a person moves between roles or projects and gains new rights without losing the old, until they hold more than their current job requires.
Gaining rights beyond those currently held: a managed practice when a user runs approved privileged commands under policy with logging, and an attack when the elevation is unauthorised.
The processes and tools that control accounts with elevated rights: vaulting their credentials, granting elevation for a task, recording privileged sessions and reviewing their use.
An account with rights beyond an ordinary user's, able to change security settings, manage other accounts or reach sensitive data, such as administrator, root and many service accounts.
An EAP method that builds a TLS tunnel authenticated by the server's certificate, then runs a second, password-based EAP method inside it to authenticate the user.
A hardware-enforced privilege hierarchy in which privilege increases inward: ring 0 holds the kernel and is most privileged, ring 3 holds user applications and is least privileged.
The unit of data that one layer of a network model exchanges with its peer layer: the layer's own header, and sometimes trailer, wrapped around the data from the layer above.
Creating an account and granting the access that an approved request or defined role specifies, at onboarding or on transfer; the lifecycle stage that deprovisioning later closes.
An intermediary that ends a client's connection and opens its own onward connection, so it can filter, cache, log or hide traffic on behalf of clients or of the servers behind it.
Replacing direct identifiers in personal data with aliases, while the information needed to re-identify people is kept separately and protected. Under GDPR it is still personal data.
The CAs, registration authorities, certificates, and revocation services (CRLs, OCSP) that bind identities to public keys and let strangers trust asymmetric cryptography at scale.
The NIST SP 800-88 sanitisation level that makes data infeasible to recover even with state-of-the-art laboratory techniques, while often leaving the media reusable.
The privacy principle that personal data is collected for specified, explicit and legitimate purposes, and is not later used in ways incompatible with those purposes.
Q
Mechanisms that classify network traffic and give chosen classes, such as voice and video, priority for bandwidth, delay, jitter and loss when links are congested.
R
Identification of tagged objects, badges or people by radio: a reader energises or queries a tag and receives its identifier, often without line of sight or the holder's awareness.
Remote Authentication Dial In User Service: a client-server AAA protocol (RFC 2865) that carries authentication, authorisation and accounting between network access devices and a central server.
The maximum data loss a business can tolerate, measured as a time window backwards from a disruption. RPO drives backup frequency: a one-hour RPO needs backups at least hourly.
The maximum time a business process can be down before recovery must complete. A CISSP Domain 7 metric: RTO plus WRT must fit inside the Maximum Tolerable Downtime (MTD).
The abstract machine that mediates every access by every subject to every object against the security policy. A concept, not a product, defined by three properties.
A denial-of-service technique that sends requests to third-party servers with the victim's address forged as the source, so the servers' replies converge on the victim.
An OAuth 2.0 credential a client presents to the authorization server to get new access tokens without the user signing in again. It goes only to the authorization server, never to resource servers.
The application that accepts an identity provider's assertion or token and grants access on its strength, instead of checking the user's credentials itself. SAML calls it the service provider.
A proprietary protocol from Microsoft that gives a user the graphical desktop of a remote Windows system, a common remote administration tool and a frequent target when exposed.
Policy and technical rules for USB drives, external disks, memory cards and tapes: whether they may be used at all, which devices are approved, how they are encrypted and how they are tracked.
Capturing a valid authentication exchange and retransmitting it later to impersonate the original party. Defeated by timestamps, nonces, and sequence numbers that make each exchange unique.
The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite.
The OAuth 2.0 role for the entity able to grant access to a protected resource. When that entity is a person, RFC 6749 calls it the end-user.
The OAuth 2.0 role for the server hosting protected resources, usually an API, which serves a request only when the access token presented is valid and its scope covers it.
The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision.
The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response.
An access control approach that estimates the risk of each request from its context, then allows it, asks for stronger authentication, or denies it. Also called adaptive access control.
A wireless access point connected to an organisation's network without authorisation, creating an unmanaged wireless way into the wired network that bypasses perimeter controls.
Access control model where permissions attach to roles and users receive roles matching their job function, simplifying administration and limiting privilege creep at scale.
A layer 3 device that forwards packets between separate networks by destination IP address, using a routing table, and separates broadcast domains.
Access control applying one global set of rules to every subject, as in firewall ACLs or time-of-day limits; distinct from role-based access control despite sharing the RBAC initials.
S
Secure/Multipurpose Internet Mail Extensions: a standard (RFC 8551) that signs and encrypts email messages end to end using X.509 certificates issued through a PKI.
A signed XML package of statements that a SAML identity provider issues about a user: that the user authenticated, what attributes the user has, or what the user may access.
Running untrusted code in an isolated environment so its behaviour can be observed and contained without risk to production; the basis of malware detonation and browser isolation.
Data links relayed through satellites that cover a wide area, commonly with high latency, where anything sent unencrypted on a downlink can be received anywhere in its footprint.
The binary decision about whether a baseline control applies to your environment at all. A control for a technology you do not run is scoped out. Applicability, not customisation.
A profile of RTP (RFC 3711) that encrypts and authenticates voice and video media streams and protects them against replay, with keys supplied by a separate exchange.
A protocol (RFC 4251 to RFC 4254) giving an encrypted, integrity-protected channel for remote command-line login, file transfer and tunnelling, replacing Telnet and rlogin.
The deprecated predecessor of TLS, created at Netscape in the 1990s; the IETF has retired both published SSL versions, though the name survives loosely in phrases like SSL certificate.
A control that inspects users' outbound web traffic and enforces policy on it, typically URL filtering, malware scanning and acceptable-use rules, on premises or as a cloud service.
An OASIS XML standard for passing signed authentication and attribute assertions from an identity provider to a service provider, widely used for web single sign-on.
A formal, evidence-based evaluation of controls against a defined standard, performed by internal, external, or third-party auditors whose independence determines its credibility.
A defined minimum set of security controls or configuration settings for a class of systems or data, usually adopted from a published source such as the NIST SP 800-53B baselines.
The level of classified information a subject is trusted to access, which mandatory access control compares with an object's label. A clearance alone does not grant access.
A structured evaluation of whether controls are implemented correctly, operating as intended, and producing the required outcome, evidenced by examining, interviewing and testing.
Centralised platform that aggregates logs from across the estate, normalises them, correlates events from multiple sources in near real time, and raises alerts for investigation.
The hardware, firmware and software inside the trusted computing base that implements the reference monitor concept in running code. The implementation, not the concept.
A classification level, plus any categories or compartments, bound to an object or subject so that mandatory access control can compare it with a clearance and decide access.
The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines.
A drive whose own controller encrypts everything written to it in hardware, with the key held inside the drive, so the data can be sanitised quickly by cryptographic erase.
DNS record listing the servers authorised to send mail for a domain. The receiver checks the connecting IP against the envelope sender's record, so it authenticates the path, not the visible From.
A measure of the harm that would follow if information were disclosed to people not authorised to see it: the main property that classification labels record.
Splitting a critical process across multiple people so no individual can complete it alone, forcing collusion to commit fraud. A core control in Clark-Wilson and Domain 1 alike.
An account used by software rather than a person, which needs a named owner, only the privileges its service requires, a managed credential and a place in access review.
The unique identifier that ties a Kerberos-enabled service to the account that runs it. Accounts with SPNs can be requested as service tickets, which makes them Kerberoasting targets.
The name of a Wi-Fi network, advertised by access points and used by clients to choose which network to join. It identifies the network but provides no security.
Taking over a session that another party has already authenticated, by capturing or predicting its identifiers, so the attacker is treated as the legitimate user.
The signalling protocol (RFC 3261) that sets up, changes and ends voice, video and messaging sessions over IP. It negotiates calls but does not carry the media itself.
Protecting an authenticated session through its life: a random session secret issued at sign-in, carried only over protected channels, and ended on timeout, logout or expiry.
Hardware, software or cloud services used for organisational work without the knowledge or approval of IT or security, and therefore missing from the inventory and its controls.
An attack recovering secrets from an implementation's physical leakage (timing, power draw, emanations, cache behaviour) rather than from any weakness in the algorithm itself.
The strength of a wanted signal compared with background noise, usually in decibels; a low ratio means more errors, retransmissions and lower usable throughput on a link.
Forging a Kerberos service ticket with a stolen service account password hash. Scope is limited to that one service, but the attack never touches the KDC, so it leaves almost no logs.
Fraud in which an attacker gets a mobile carrier to move a victim's phone number to a SIM the attacker controls, then receives the codes sent to it by text message or call.
The protocol (RFC 5321) that sends email from clients to mail servers and relays it between servers. It was designed without sender authentication or encryption.
A protocol for monitoring and configuring network devices: managers query agents for values and agents send alerts. Versions 1 and 2c authenticate only with cleartext community strings.
The password-based key exchange in the IEEE 802.11 standard that WPA3-Personal uses in place of pre-shared key authentication, commonly described as resisting offline guessing.
The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis.
Authenticate once, then access multiple systems without re-entering credentials. Improves usability and centralises control, but a compromised session unlocks everything at once.
The unused remainder of a cluster allocated to a file, between the end of the file's data and the end of the cluster, which can still hold fragments of earlier data.
A card with an embedded chip that stores keys and performs cryptographic operations. Unlocked with a PIN, it combines something you have with something you know.
A denial-of-service attack that sends ICMP echo requests to a network's broadcast address, forging the victim as the source, so every host on that network replies to the victim.
Automated inventory of the third-party and open-source components inside an application, mapping each to known vulnerabilities and licence obligations via a software bill of materials.
The phased process for building and retiring software, from requirements through design, development, testing, operation, and disposal, with security built into every phase from the start.
Architecture separating the control plane from the data plane: a centralised programmable controller sets forwarding policy network-wide, and becomes its highest-value target.
An approach that runs a wide-area network from central policy, steering each application's traffic across several transport links such as MPLS, broadband and cellular.
A remote access VPN setting that sends only traffic for the organisation's networks through the tunnel, while other traffic goes straight to the internet from the device.
Destroying, altering or failing to preserve evidence relevant to litigation that is under way or reasonably expected, including by letting routine deletion continue after a legal hold should apply.
Forging an identifier, such as an IP address, MAC address, DNS answer or email sender, so that a system or person accepts traffic or a message as coming from a trusted source.
A file transfer and file management protocol that runs as a subsystem of SSH, so commands, credentials and file contents all travel inside one encrypted SSH connection.
Deciding which external regulations, standards and frameworks set the security requirements for an organisation's data, such as PCI DSS, ISO/IEC 27001 or NIST SP 800-53.
The Bell-LaPadula rule that a subject cannot write to a lower classification level, stopping cleared users from leaking secrets into documents that lower clearances can read.
A firewall that records each connection in a state table and judges packets in the context of that connection, so replies to permitted sessions pass without separate rules.
White-box testing that analyses source code or bytecode without executing the program, catching code-level flaws early in development but missing runtime and configuration issues.
The GDPR principle in Article 5(1)(e): personal data may be kept in a form that identifies people only for as long as the purpose it was processed for requires.
A switching method in which the switch receives the whole frame and checks it for errors before forwarding it, trading extra latency for not passing on corrupted frames.
Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property.
The active entity in an access request, such as a user, process or device, that seeks to act on an object. The subject makes the request and the object is acted upon.
Dividing an IP address block into smaller networks by lengthening the network prefix, so that each subnet has its own address range and a routed boundary to the others.
A Unix-like system utility that lets a permitted user run specific commands with another account's privileges, usually root, under a written policy that logs each use.
Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates.
Encryption where one shared secret key both encrypts and decrypts: fast enough for bulk data, but burdened by the key distribution problem and n(n-1)/2 keys for n parties.
A denial-of-service attack that sends TCP connection requests and never completes the handshake, filling the target's queue of half-open connections so real clients are refused.
Scripted, pre-built transactions run against live systems to verify functionality, availability, and response times proactively, catching failures before real users hit them.
An IETF standard (RFCs 7643 and 7644) for creating, updating and removing user accounts across domains through a common REST and JSON interface, including deprovisioning.
The role accountable for an IT system or platform that stores or processes data, as distinct from the data owner, who is accountable for the information itself.
T
Discussion-based walkthrough in which the response team talks through a disaster scenario against the plan, validating roles and decisions without touching any production system.
An AAA protocol over TCP that handles authentication, authorisation and accounting as separate exchanges, commonly used to control administrator access to network devices.
Customising how the controls that apply to your environment are implemented: adjusting parameters, adding compensating controls, or refining assumptions to fit organisational reality.
An asset with a physical form, such as a server, laptop, network device, storage medium or facility, which can be counted, tagged and valued by its purchase or replacement cost.
The four-layer model of the internet protocol suite (link, internet, transport and application) that describes how working networks are built and maps onto the seven OSI layers.
A denial-of-service attack that sends IP fragments with overlapping offsets, crashing hosts whose reassembly code mishandles the overlap. The known flaws have long been patched.
A protocol for interactive remote terminal access that sends everything, including usernames and passwords, in cleartext. SSH replaced it for remote administration.
The interim Wi-Fi encryption protocol of WPA, which wrapped WEP's RC4 cipher in per-packet key mixing and an integrity check so existing hardware could be upgraded. Now deprecated.
Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production.
The SYN, SYN-ACK and ACK exchange that opens a TCP connection, in which each side confirms the other can be reached and the two agree their starting sequence numbers.
The rate at which data is actually delivered across a network path in a given time, as distinct from bandwidth, which is the capacity the link could carry in theory.
The KDC component that exchanges a valid TGT for service tickets. Each service ticket is encrypted with the target service account's key, which is the property Kerberoasting exploits.
The Kerberos credential issued at logon that proves a user already authenticated. Presented to the TGS to obtain service tickets without re-entering a password. Forged TGTs are golden tickets.
A one-time code computed from a shared secret and the current time, defined in RFC 6238, that changes at a fixed interval and proves possession of the device holding the secret.
The opening phase of a TLS connection that agrees the protocol version and cipher suite, commonly authenticates the server with its certificate, and derives the session keys.
Replacing a sensitive value, such as a card number, with a meaningless token while the real value is held in a separate secured vault; widely used to reduce PCI DSS scope.
Controlling the rate of outbound network traffic by queuing and delaying packets so flows conform to a set profile, smoothing bursts and protecting priority traffic.
Connection-oriented transport protocol that opens sessions with a handshake and uses sequence numbers, acknowledgements and retransmission to deliver data reliably and in order.
The physical paths that carry network signals: copper and fibre-optic cable, which guide the signal, and radio, microwave and infrared, which send it through the air.
Protocol encrypting sessions above the transport layer: an asymmetric handshake authenticates the server and agrees symmetric session keys; the deprecated predecessor is SSL.
A line on a data flow diagram where the level of trust changes, such as between the public internet and an internal network, and a crossing worth examining first.
An agreement, configured in advance, under which one security domain accepts authentications made by another, as in federation or in trusts between directory domains.
The total combination of hardware, firmware and software responsible for enforcing a system's security policy; if any part of it fails, every protection built on top of it fails.
A hardware-isolated area of a processor where code and data are protected from the rest of the system, including the host operating system: the basis of confidential computing.
A dedicated hardware chip that stores cryptographic keys, measures boot integrity, and seals secrets to a known-good platform state, anchoring full-disk encryption and secure boot.
Copper network cable made of insulated wire pairs twisted together to reduce interference and crosstalk, sold as unshielded (UTP) or shielded (STP) and graded by category.
U
Storage the file system records as free, which can still hold the contents of deleted files until new data happens to be written over those blocks.
Delivery of a packet from one sender to one specific receiver, identified by a single destination address. It is contrasted with broadcast, multicast and anycast.
Connectionless transport protocol that sends datagrams with no handshake, acknowledgement or retransmission, trading reliability for low overhead and low delay.
V
One physical network device, commonly a firewall, run as several separate logical instances, each with its own interfaces, routing, security policy and administration.
Layer 2 logical segmentation that splits one physical switch fabric into isolated broadcast domains via 802.1Q tags; separation without new hardware, subverted by VLAN hopping.
A logically isolated network inside a public cloud, whose address ranges, subnets, routing and filtering rules are defined and configured by the customer.
Encrypted tunnel carrying private traffic across untrusted networks; site-to-site links join whole networks through gateways, remote access serves single users, over IPsec or TLS.
A router feature that keeps several separate routing and forwarding tables on one device, so traffic in one instance has no route into another unless routes are deliberately shared.
An attack that sends traffic from one VLAN into another without passing the layer-3 device meant to control it, by switch spoofing or by double tagging on the native VLAN.
Carrying voice calls as packets over IP networks, with a signalling protocol such as SIP to set up calls and RTP to carry the media, sharing the data network's threats.
A systematic scan that identifies, quantifies, and ranks weaknesses across systems without exploiting them, trading depth for breadth and requiring validation of false positives.
An overlay protocol (RFC 7348) that wraps layer-2 Ethernet frames in UDP packets so isolated segments can stretch across a layer-3 network; it separates traffic but does not encrypt it.
W
Moving through an area with a wireless-capable device to discover, record and map wireless networks, their names, security settings and locations, as reconnaissance.
Alternate facility with hardware and connectivity in place but no current data; backups must be restored on activation, giving recovery in days at a fraction of hot-site cost.
A flash controller technique that spreads writes across memory cells by remapping them, which can leave old copies of data where host-based overwriting may not reach.
A firewall that inspects HTTP and HTTPS traffic to a web application at layer 7 and blocks requests that match attack patterns or break the application's expected behaviour.
A Clark-Wilson concept: data may only be changed by vetted procedures that move it from one consistent state to another, never by direct edits, preserving internal and external consistency.
TCP and UDP port numbers 0 to 1023, assigned by IANA to standard services; a port shows the service expected on a connection, not the traffic actually carried.
Wireless local area networking under the IEEE 802.11 standards; Wi-Fi is the industry certification name, and its security comes from WEP, WPA, WPA2 or WPA3.
The 2003 transitional replacement for WEP, using TKIP so existing hardware could be upgraded by firmware; itself now deprecated in favour of WPA2 and WPA3.
The original IEEE 802.11 wireless encryption, built on RC4 with a short initialisation vector and a static shared key; broken, and not to be used.
The device that connects wireless clients to a wired network: it advertises the network, handles association and enforces the Wi-Fi security mode configured on it.
The time after a system is technically restored spent verifying data, reconciling records, and resuming normal processing. RTO plus WRT must fit inside the MTD.
The Wi-Fi security certification based on IEEE 802.11i, with mandatory AES-based CCMP encryption, offered as Personal (shared passphrase) or Enterprise (IEEE 802.1X).
The Wi-Fi security certification that replaces pre-shared key authentication with SAE in Personal mode and requires protected management frames.
X
The ITU-T series of directory standards defining a hierarchical, distributed directory of named entries, the model on which LDAP and X.509 certificates are built.
Z
A security model granting no implicit trust from network location: every request is authenticated, authorised, and continuously verified, wherever it originates.
Erasing cryptographic keys and other sensitive security parameters, commonly by overwriting them with zeros, to make them unrecoverable from a device or from memory.
A low-power, low-data-rate wireless mesh protocol built on IEEE 802.15.4, commonly used for building, home and industrial sensors; its practical weakness is key handling.
No terms match that filter. Try a shorter word, or choose All domains.