This pillar of the CIA triad ensures that data is accurate, reliable, and has not been altered by unauthorized parties.
Integrity
This type of encryption uses the exact same key for both encrypting and decrypting data.
Symmetric Encryption
This control category discourages potential attackers by clearly displaying warning signs, banner notices, or policies prior to system entry.
Deterrent control
Armed with basic scripting tools found online, this entry-level threat actor lacks deep technical knowledge and relies on pre-made exploit kits.
Script Kiddie/Unskilled Attacker
This cloud computing service model provides virtualized computing resources over the internet, such as virtual machines and raw storage.
IaaS (Infrastructure as a Service)
This security principle dictates that users and systems should only be given the minimum level of access necessary to perform their job functions.
Least Privilege?
This mathematical operation turns input data of any size into a fixed-size string and is strictly a one-way function.
Hashing
This control category involves deploying physical security guards, door locks, and mantraps to protect hardware infrastructure from intruders.
Physical/Preventative Control
This internal threat actor is motivated by personal grievances, revenge, or financial desperation, using their legitimate organizational access to sabotage systems or steal data.
Insider Threat
This network design technique divides a larger network into smaller, isolated zones to restrict lateral movement.
A holistic security approach that relies on multiple layers of distinct controls to protect organizational assets.
Defense-in-Depth
This cryptographic process adds random, unique data to a password before hashing it to protect against pre-computed rainbow table attacks.
Salting
Automated backup restoration scripts that execute immediately after a ransomware attack are classified as this functional control type.
Technical/Corrective Control
These groups are motivated by political agendas, social causes, or ideology, often launching DDoS attacks or defacing websites.
Hacktivists
A security framework that integrates cloud-based security and networking services into a single, unified edge architecture, heavily favored for remote workforces.
Secure Access Service Edge (SASE)
This modern security framework assumes breach and explicitly verifies every request, operating under the mantra "never trust, always verify."
Zero Trust
In asymmetric cryptography, you use this specific key belonging to the recipient to encrypt a message so only they can read it.
Public Key
An IDS generates an alert based on a signature of known malicious traffic.
Technical/Detective
Highly resourced, stealthy, and persistent groups typically backed by foreign governments to conduct long-term espionage.
APTs
A hardware-based security feature that creates a secure, isolated environment within a CPU to execute code safely.
Secure Enclave or Trusted Execution Environment
This part of Zero Trust Architecture is responsible for inspecting network traffic and allowing or blocking it based on pre-rules defined by the system.
Policy Enforcement Point or PEP
This Certificate Authority is typically used to issue certs to other CAs and often kept offline
Root CA
The control Type AND Category for policies requiring employees to report suspicious behavior or activity on company systems
Managerial and Directive/Preventative/Detective
Operating purely for profit, these organized syndicates often function like corporate enterprises, complete with customer support lines for ransomware victims.
Cybercrime Syndicates (or Organized Crime Groups)
This standard enables authentication protocols for devices wireless devices
802.1x