Basic Security Concepts
Cryptography
Controls
Threat Actors
Security Architecture
100

This pillar of the CIA triad ensures that data is accurate, reliable, and has not been altered by unauthorized parties.

Integrity

100

This type of encryption uses the exact same key for both encrypting and decrypting data.

Symmetric Encryption

100

This control category discourages potential attackers by clearly displaying warning signs, banner notices, or policies prior to system entry.

Deterrent control

100

Armed with basic scripting tools found online, this entry-level threat actor lacks deep technical knowledge and relies on pre-made exploit kits.

Script Kiddie/Unskilled Attacker

100

This cloud computing service model provides virtualized computing resources over the internet, such as virtual machines and raw storage.

IaaS (Infrastructure as a Service)

200

This security principle dictates that users and systems should only be given the minimum level of access necessary to perform their job functions.

Least Privilege?

200

This mathematical operation turns input data of any size into a fixed-size string and is strictly a one-way function.

Hashing

200

This control category involves deploying physical security guards, door locks, and mantraps to protect hardware infrastructure from intruders.

Physical/Preventative Control

200

This internal threat actor is motivated by personal grievances, revenge, or financial desperation, using their legitimate organizational access to sabotage systems or steal data.

Insider Threat

200

This network design technique divides a larger network into smaller, isolated zones to restrict lateral movement.

Network Segmentation
300

A holistic security approach that relies on multiple layers of distinct controls to protect organizational assets.

Defense-in-Depth

300

This cryptographic process adds random, unique data to a password before hashing it to protect against pre-computed rainbow table attacks.

Salting

300

Automated backup restoration scripts that execute immediately after a ransomware attack are classified as this functional control type.

Technical/Corrective Control

300

 These groups are motivated by political agendas, social causes, or ideology, often launching DDoS attacks or defacing websites.

Hacktivists

300

A security framework that integrates cloud-based security and networking services into a single, unified edge architecture, heavily favored for remote workforces.

Secure Access Service Edge (SASE)

400

This modern security framework assumes breach and explicitly verifies every request, operating under the mantra "never trust, always verify."

Zero Trust

400

In asymmetric cryptography, you use this specific key belonging to the recipient to encrypt a message so only they can read it.

Public Key

400

An IDS generates an alert based on a signature of known malicious traffic.

Technical/Detective

400

Highly resourced, stealthy, and persistent groups typically backed by foreign governments to conduct long-term espionage.

APTs

400

A hardware-based security feature that creates a secure, isolated environment within a CPU to execute code safely.

Secure Enclave or Trusted Execution Environment

500

This part of Zero Trust Architecture is responsible for inspecting network traffic and allowing or blocking it based on pre-rules defined by the system.

Policy Enforcement Point or PEP

500

This Certificate Authority is typically used to issue certs to other CAs and often kept offline

Root CA

500

The control Type AND Category for policies requiring employees to report suspicious behavior or activity on company systems

Managerial and Directive/Preventative/Detective

500

Operating purely for profit, these organized syndicates often function like corporate enterprises, complete with customer support lines for ransomware victims.

 Cybercrime Syndicates (or Organized Crime Groups)

500

This standard enables authentication protocols for devices wireless devices

802.1x