# Learn Security Management > CISSP exam preparation from Learn Security Management: in-depth guides to the concepts candidates are expected to know, realistic practice questions, and a CISSP-only glossary, written by a certified practitioner. UK-based. Articles and definitions are written to be quotable: the first paragraph of every glossary entry is a self-contained answer. The glossary is CISSP exam vocabulary only. ## Articles - [Business Impact Analysis Explained: The BIA Process and Outputs for CISSP](https://www.learnsecuritymanagement.com/cissp-business-impact-analysis): How a business impact analysis finds critical functions, measures impact over time, maps dependencies, and produces the recovery priorities strategy must meet. - [Business Continuity Planning Explained: The BCP Lifecycle and Testing for CISSP](https://www.learnsecuritymanagement.com/cissp-business-continuity-planning): The five phases of the BCP lifecycle, how BCP differs from DRP, who is accountable for the programme, and the six testing methods in order of disruption. - [Quantitative Risk Formulas: SLE, ARO and ALE](https://www.learnsecuritymanagement.com/cissp-quantitative-risk-assessment-formulas): The five quantitative risk formulas in the order they run, worked end to end from asset value to a funded decision, plus where the method breaks down. - [SPF, DKIM and DMARC: Complete Guide for CISSP](https://www.learnsecuritymanagement.com/cissp-spf-dkim-dmarc-email-authentication): Email authentication for the CISSP: what SPF, DKIM and DMARC each check, why forwarding breaks SPF, and how alignment ties a pass to the visible From. - [TOCTOU Explained: Time of Check Time of Use Race Conditions for CISSP](https://www.learnsecuritymanagement.com/cissp-toctou-time-of-check-time-of-use): How a TOCTOU race condition turns a passed security check into an exploit, why symbolic links make it dangerous, and how to close the window. - [Data Security Roles: Owner, Custodian, Controller and Processor for CISSP](https://www.learnsecuritymanagement.com/cissp-data-security-roles): What each data security role does, how owner differs from custodian and controller from processor, and why accountability never transfers with the work. - [SOC Reports Explained: SOC 1, SOC 2 and SOC 3 for CISSP](https://www.learnsecuritymanagement.com/cissp-soc-reports): What SOC 1, SOC 2 and SOC 3 cover, how Type 1 differs from Type 2, and how the CISSP exam approaches third party assurance and vendor risk. - [Disaster Recovery Sites: Hot, Warm, Cold and Cloud](https://www.learnsecuritymanagement.com/cissp-insight-disaster-recovery-sites): Hot, warm, cold and cloud recovery sites compared. The BIA sets the RTO, and the RTO picks the site. A CISSP insight with a manager mindset. - [Due Diligence vs Due Care: What Is the Difference?](https://www.learnsecuritymanagement.com/cissp-insight-due-diligence-vs-due-care): Due diligence is finding out. Due care is acting on what you found. A CISSP insight on the prudent person rule and the evidence that proves both. - [Fail Safe vs Fail Secure: What Is the Difference?](https://www.learnsecuritymanagement.com/cissp-insight-fail-safe-vs-fail-secure): Fail safe defaults to open and protects people. Fail secure defaults to locked and protects assets. A CISSP insight on matching the default to the risk. - [IPsec AH vs ESP: What Is the Difference?](https://www.learnsecuritymanagement.com/cissp-insight-ipsec-ah-vs-esp): AH authenticates but never encrypts and breaks through NAT. ESP encrypts, authenticates and traverses NAT. A CISSP insight on the IPsec protocol choice. - [What Is SAST? Static Application Security Testing](https://www.learnsecuritymanagement.com/cissp-insight-sast-static-application-security-testing): SAST reads source code without running it, catching flaws at the cheapest point in the SDLC. A CISSP insight on its strengths, blind spots and CI/CD role. - [Silver Ticket Attack: Forging Tickets Past the KDC](https://www.learnsecuritymanagement.com/cissp-silver-ticket-attacks): How a stolen service account hash forges a service ticket that never reaches the KDC, why that keeps it out of domain logs, and how to catch it. - [Bell-LaPadula: No Read Up, No Write Down (CISSP)](https://www.learnsecuritymanagement.com/cissp-bell-lapadula-model): The Bell-LaPadula rules in plain terms: no read up, no write down, and why a subject may write above its clearance but never read there. - [Biba Model: No Read Down, No Write Up (CISSP)](https://www.learnsecuritymanagement.com/cissp-biba-integrity-model): The Biba rules in plain terms: no read down, no write up, and why integrity inverts the Bell-LaPadula directions it is confused with. - [Chinese Wall Model (Brewer-Nash) Explained](https://www.learnsecuritymanagement.com/cissp-brewer-nash-model): How the Chinese Wall model stops consultant conflicts of interest: conflict classes, access that narrows as you read, and dynamic separation of duties. - [Clark-Wilson Model: The Access Triple Explained](https://www.learnsecuritymanagement.com/cissp-clark-wilson-model): How Clark-Wilson protects commercial integrity: the access triple, well-formed transactions, separation of duties, and how it differs from Biba. - [Graham-Denning: The Eight Protection Rules](https://www.learnsecuritymanagement.com/cissp-graham-denning-model): The eight Graham-Denning operations for creating and deleting subjects and objects and transferring access rights, and where Harrison-Ruzzo-Ullman extends them. - [Certificate Pinning: What Should You Pin First?](https://www.learnsecuritymanagement.com/cissp-insight-certificate-pinning-targets): The foundational certificate pinning decision: choosing between certificate fingerprints, public key hashes and chain elements. A CISSP exam insight. - [What Is the Difference Between Scoping and Tailoring?](https://www.learnsecuritymanagement.com/cissp-insight-scoping-vs-tailoring): Scoping makes binary yes or no calls on whether a control applies. Tailoring customises how it is implemented. A CISSP insight with a manager mindset. - [RPO, RTO, WRT and MTD on One Recovery Timeline](https://www.learnsecuritymanagement.com/cissp-rpo-rto-wrt-mtd-disaster-recovery-metrics): How RPO, RTO, WRT and MTD sit on a single outage timeline, and why MTD is the ceiling the other three have to fit inside. - [Kerberoasting: Cracking Service Passwords Offline](https://www.learnsecuritymanagement.com/cissp-kerberoasting-attacks): How any domain user can request a service ticket for an SPN and crack the service account password offline, and why long managed passwords stop it. - [Golden Ticket Attack: Forging a TGT from krbtgt](https://www.learnsecuritymanagement.com/cissp-golden-ticket-attacks): How a stolen krbtgt hash lets an attacker forge any Kerberos TGT, why no domain controller checks it, and why krbtgt must be reset twice. - [Kerberos: The Six-Step Ticket Flow Explained](https://www.learnsecuritymanagement.com/cissp-kerberos-authentication): How Kerberos issues a TGT and then service tickets across six messages, what the AS, TGS and KDC each do, and why clock drift breaks logon. ## Glossary - [Annualized Loss Expectancy (ALE)](https://www.learnsecuritymanagement.com/glossary/annualized-loss-expectancy): The expected yearly cost of a risk: Single Loss Expectancy multiplied by Annualized Rate of Occurrence (ALE = SLE x ARO), the figure that justifies control spending in quantitative analysis. - [Asymmetric encryption](https://www.learnsecuritymanagement.com/glossary/asymmetric-encryption): Encryption using linked key pairs where what the public key encrypts only the private key can decrypt; slow, so used for key exchange and signatures rather than bulk data. - [Attribute-Based Access Control (ABAC)](https://www.learnsecuritymanagement.com/glossary/attribute-based-access-control): Access control model that evaluates attributes of the subject, object, action, and environment (time, location, device) against policy for the most granular, context-aware decisions. - [Bell-LaPadula model](https://www.learnsecuritymanagement.com/glossary/bell-lapadula-model): The confidentiality-only security model behind CISSP Domain 3: No Read Up (Simple Security Property) and No Write Down (Star Property) keep classified data from leaking downward. - [Biba model](https://www.learnsecuritymanagement.com/glossary/biba-model): The integrity counterpart to Bell-LaPadula: No Read Down and No Write Up stop trusted data from being contaminated by less trustworthy sources. Confidentiality is out of scope. - [Business Continuity Plan (BCP)](https://www.learnsecuritymanagement.com/glossary/business-continuity-plan): The organisation-wide plan for keeping critical business functions running during and after a disruption. The umbrella programme that disaster recovery sits underneath. - [Business Impact Analysis (BIA)](https://www.learnsecuritymanagement.com/glossary/business-impact-analysis): The process that identifies critical business functions and the impact of their disruption over time, producing the recovery metrics (RTO, RPO, MTD) that drive continuity planning. - [Certificate pinning](https://www.learnsecuritymanagement.com/glossary/certificate-pinning): Hardcoding which certificate or public key a client will accept for a service, so a fraudulent certificate from a compromised CA is rejected even though it validates normally. - [Chain of custody](https://www.learnsecuritymanagement.com/glossary/chain-of-custody): Documented, unbroken record of who collected, handled, transferred, and stored evidence, with times and locations, proving it was not altered between collection and court. - [Change management](https://www.learnsecuritymanagement.com/glossary/change-management): Formal process taking every change through request, approval, testing, and rollback planning before implementation, so changes are deliberate, documented, and reversible. - [Chinese Wall Model (Brewer-Nash)](https://www.learnsecuritymanagement.com/glossary/brewer-nash-model): The Brewer-Nash model: access rights change dynamically based on what a user has already accessed, blocking conflicts of interest between competing clients' data. - [Clark-Wilson model](https://www.learnsecuritymanagement.com/glossary/clark-wilson-model): A commercial integrity model built on well-formed transactions and separation of duties: users change data only through certified programs, never directly. Access triple: subject, program, object. - [Cloud Access Security Broker (CASB)](https://www.learnsecuritymanagement.com/glossary/cloud-access-security-broker): A policy enforcement point between users and cloud services that delivers visibility, compliance, data security, and threat protection, including discovery of shadow IT. - [Cold site](https://www.learnsecuritymanagement.com/glossary/cold-site): Alternate facility providing only space, power, and environmental support; hardware and data arrive after the disaster, so activation takes weeks, at the lowest standing cost. - [Compensating control](https://www.learnsecuritymanagement.com/glossary/compensating-control): An alternative control adopted when the primary control is impractical or too costly. It must meet the intent and rigour of the original requirement, not merely gesture at it. - [Control types](https://www.learnsecuritymanagement.com/glossary/control-types): The classification of security controls by the function they perform: preventive, detective, corrective, deterrent, recovery, and directive. One control can serve several functions at once. - [Data classification](https://www.learnsecuritymanagement.com/glossary/data-classification): The process of assigning sensitivity labels to information so that handling, storage, and access requirements follow from the label, and controls are selected to match it. - [Data custodian](https://www.learnsecuritymanagement.com/glossary/data-custodian): The technical role that implements data protection on the owner's behalf: backups, access permissions, patching, and secure storage. Responsible for the work, never accountable for the data. - [Data Loss Prevention (DLP)](https://www.learnsecuritymanagement.com/glossary/data-loss-prevention): Content-inspection technology that identifies sensitive data and enforces policy to stop it leaving the organisation, deployed at the network edge, on endpoints, or as discovery scans. - [Data owner](https://www.learnsecuritymanagement.com/glossary/data-owner): The senior business role accountable for a data set: the owner classifies the data, approves access, and sets protection requirements, and that accountability cannot be delegated. - [Data remanence](https://www.learnsecuritymanagement.com/glossary/data-remanence): The residual data that remains on storage media after deletion or formatting, recoverable until the media is properly cleared, purged, or destroyed. - [Data states](https://www.learnsecuritymanagement.com/glossary/data-states): The three conditions data occupies (at rest in storage, in transit across networks, in use during processing), each demanding its own distinct protection mechanisms. - [Defense in depth](https://www.learnsecuritymanagement.com/glossary/defense-in-depth): Layering physical, technical, and administrative controls so no single control failure exposes an asset; every layer assumes the layer in front of it can be breached. - [DevSecOps](https://www.learnsecuritymanagement.com/glossary/devsecops): A practice that makes security a shared responsibility across development and operations by automating security checks into the CI/CD pipeline instead of a bolt-on review at release. - [Digital signature](https://www.learnsecuritymanagement.com/glossary/digital-signature): A message hash encrypted with the sender's private key, proving integrity, authenticity, and nonrepudiation to anyone with the matching public key; it provides no confidentiality. - [Disaster Recovery Plan (DRP)](https://www.learnsecuritymanagement.com/glossary/disaster-recovery-plan): The IT-focused plan for restoring systems, infrastructure and data after a failure. One component beneath the business continuity plan, not a synonym for it. - [Discretionary Access Control (DAC)](https://www.learnsecuritymanagement.com/glossary/discretionary-access-control): Access controlled at the owner's discretion: whoever owns a resource decides who else may use it. Flexible, but permissions can spread in ways no central policy intended. - [DMARC](https://www.learnsecuritymanagement.com/glossary/dmarc): The policy layer that tests whether an SPF or DKIM pass aligns with the visible From domain, tells receivers what to do when neither does, and requests reports from them. - [Domain Name System (DNS)](https://www.learnsecuritymanagement.com/glossary/dns): The internet's distributed naming service, resolving names to addresses. It is unauthenticated by default, which is why DNSSEC signs records and why poisoning and tunnelling remain testable. - [DomainKeys Identified Mail (DKIM)](https://www.learnsecuritymanagement.com/glossary/dkim): A cryptographic signature over an email, verified against a public key in DNS. It proves integrity and which domain signed, provides no confidentiality, and survives a plain forward. - [Due care](https://www.learnsecuritymanagement.com/glossary/due-care): Doing what a reasonable, prudent person would do to protect the organisation's interests. The ongoing act of implementing and maintaining reasonable safeguards. The do part. - [Due diligence](https://www.learnsecuritymanagement.com/glossary/due-diligence): The investigation and ongoing assessment that informs prudent decisions: researching risks, vetting vendors, verifying controls. The homework that precedes due care's action. - [Dynamic Application Security Testing (DAST)](https://www.learnsecuritymanagement.com/glossary/dynamic-application-security-testing): Black-box testing that probes a running application from the outside, finding runtime and configuration flaws without source access, but unable to point to the offending line of code. - [Egress monitoring](https://www.learnsecuritymanagement.com/glossary/egress-monitoring): Watching traffic that leaves the network for signs of data exfiltration, command-and-control beacons, and policy violations; the outbound counterpart to inbound-facing defences. - [Email spoofing](https://www.learnsecuritymanagement.com/glossary/email-spoofing): Forging the sender identity on a message. SMTP verifies neither the envelope sender nor the visible From, so the three forms differ in whether authentication can address them at all. - [Fail secure](https://www.learnsecuritymanagement.com/glossary/fail-secure): A failure mode where a control defaults to denying access when it loses power or malfunctions, protecting the asset; contrast fail safe, which defaults to protecting people. - [Federated identity](https://www.learnsecuritymanagement.com/glossary/federated-identity): Trust between organisations that lets one domain's identities access another's systems, with an identity provider asserting authentication to service providers via SAML, OAuth, or OIDC. - [Golden ticket attack](https://www.learnsecuritymanagement.com/glossary/golden-ticket-attack): Forging Kerberos TGTs with the stolen KRBTGT password hash, giving an attacker any identity and any group membership in the domain, with a validity period the attacker chooses. - [Graham-Denning model](https://www.learnsecuritymanagement.com/glossary/graham-denning-model): A security model defining eight primitive protection rights: how subjects and objects are securely created and deleted, and how access rights are granted, transferred, and revoked. - [Hashing](https://www.learnsecuritymanagement.com/glossary/hashing): A one-way function condensing any input into a fixed-length digest used to verify integrity; computationally infeasible to reverse, and secure only while collisions stay impractical. - [Honeypot](https://www.learnsecuritymanagement.com/glossary/honeypot): Decoy system with no production value, deployed to attract attackers so their tools and methods can be observed; any interaction with it is suspicious by definition. - [Hot site](https://www.learnsecuritymanagement.com/glossary/hot-site): Fully equipped alternate facility with hardware, software, and near-real-time data replication in place, able to take over within hours; the fastest and most expensive option. - [Identity proofing](https://www.learnsecuritymanagement.com/glossary/identity-proofing): Verifying that a person is who they claim to be before credentials are issued, using evidence such as documents or biometrics; the registration step that authentication later relies on. - [Incident management](https://www.learnsecuritymanagement.com/glossary/incident-management): Managed lifecycle for handling security incidents: detection, response, mitigation, reporting, recovery, remediation, and lessons learned, limiting damage and preventing recurrence. - [Intrusion Detection System (IDS)](https://www.learnsecuritymanagement.com/glossary/intrusion-detection-system): Monitoring control that inspects network traffic or host activity for signs of attack and raises alerts without blocking; detection is signature-based or anomaly-based. - [IPsec](https://www.learnsecuritymanagement.com/glossary/ipsec): Layer 3 protocol suite securing IP traffic: AH gives integrity and origin authentication only, ESP adds confidentiality, and tunnel mode wraps the whole original packet for VPNs. - [Just-in-Time (JIT) access](https://www.learnsecuritymanagement.com/glossary/just-in-time-access): Privilege model granting elevated rights only for the duration of a task and revoking them afterwards, eliminating the standing privileges that attackers harvest through credential theft. - [Kerberoasting](https://www.learnsecuritymanagement.com/glossary/kerberoasting): An attack where any authenticated domain user requests service tickets for accounts with SPNs, then cracks them offline to recover service account passwords. No admin rights needed. - [Kerberos](https://www.learnsecuritymanagement.com/glossary/kerberos): The ticket-based network authentication protocol tested in CISSP Domain 5: a trusted KDC issues a TGT, then service tickets, using symmetric encryption so passwords never cross the wire. - [Key Distribution Center (KDC)](https://www.learnsecuritymanagement.com/glossary/key-distribution-center): The trusted third party at the heart of Kerberos, combining the Authentication Service and Ticket Granting Service. In Active Directory every domain controller runs a KDC. - [Key escrow](https://www.learnsecuritymanagement.com/glossary/key-escrow): Holding copies of cryptographic keys with a trusted third party so they can be recovered for continuity or produced for lawful access, trading confidentiality risk for availability. - [Key Risk Indicator (KRI)](https://www.learnsecuritymanagement.com/glossary/key-risk-indicator): A forward-looking metric that warns risk exposure is approaching an unacceptable level, triggering management action before loss occurs, unlike a KPI, which measures achieved performance. - [KRBTGT account](https://www.learnsecuritymanagement.com/glossary/krbtgt-account): The built-in Active Directory account whose password hash encrypts and signs every TGT in the domain. Stealing it enables golden tickets; remediation is a careful double password reset. - [Least privilege](https://www.learnsecuritymanagement.com/glossary/least-privilege): Granting each user, process, or account only the access its task requires, and no more. Limits the damage from mistakes, malware, and compromised credentials alike. - [Man-in-the-Middle (MITM) attack](https://www.learnsecuritymanagement.com/glossary/man-in-the-middle-attack): An attack where the adversary secretly relays, and can alter, traffic between two parties who believe they communicate directly; defeated by mutual authentication and certificate validation. - [Mandatory Access Control (MAC)](https://www.learnsecuritymanagement.com/glossary/mandatory-access-control): Access decided by the system comparing security labels against clearances, under a policy users cannot override. Not even a file's owner can share it outside policy. - [Maximum Tolerable Downtime (MTD)](https://www.learnsecuritymanagement.com/glossary/mtd): The longest a business process can be unavailable before the damage becomes unacceptable. The outer boundary every other recovery metric must fit inside: RTO plus WRT. - [Misuse case testing](https://www.learnsecuritymanagement.com/glossary/misuse-case-testing): Testing that verifies what a system must not allow, inverting use cases into abuse scenarios to prove that invalid, malicious, or out-of-sequence actions are rejected. - [Multi-Factor Authentication (MFA)](https://www.learnsecuritymanagement.com/glossary/multi-factor-authentication): Authentication requiring two or more different factor types (something you know, have, or are); two instances of the same type, such as two passwords, remain single-factor. - [Mutual authentication](https://www.learnsecuritymanagement.com/glossary/mutual-authentication): Both parties verify each other's identity before communicating: the client proves itself to the server and the server proves itself back. A defining property of Kerberos. - [Network Access Control (NAC)](https://www.learnsecuritymanagement.com/glossary/network-access-control): Admission control that authenticates devices and checks their security posture before granting network access, typically via 802.1X, shunting failures to a quarantine VLAN. - [Network segmentation](https://www.learnsecuritymanagement.com/glossary/network-segmentation): Dividing a network into isolated zones so compromise of one cannot spread laterally; spans physical separation, logical VLANs and firewalls, and workload micro-segmentation. - [No Read Down (Simple Integrity Property)](https://www.learnsecuritymanagement.com/glossary/no-read-down): The Biba rule that a subject cannot read data of lower integrity than its own, stopping trusted processes from being corrupted by unreliable input. - [No Read Up (Simple Security Property)](https://www.learnsecuritymanagement.com/glossary/no-read-up): The Bell-LaPadula rule that a subject cannot read data classified above their clearance. Confidentiality's ceiling: a Secret clearance never opens a Top Secret file. - [No Write Up (Star Integrity Property)](https://www.learnsecuritymanagement.com/glossary/no-write-up): The Biba rule that a subject cannot write to a higher integrity level, stopping unreliable processes from injecting bad data into trusted records. - [Non-repudiation](https://www.learnsecuritymanagement.com/glossary/non-repudiation): Assurance that a party cannot credibly deny an action. It needs a secret only that party holds, which is why digital signatures provide it and shared-key MACs cannot. - [OSI model](https://www.learnsecuritymanagement.com/glossary/osi-model): Seven-layer reference model, physical to application, used to place every protocol, device, and attack at the layer where it operates; the exam's favourite classification framework. - [Pass-the-hash](https://www.learnsecuritymanagement.com/glossary/pass-the-hash): Authenticating with a stolen password hash instead of the password itself, exploiting NTLM's use of the hash as the credential; no cracking needed, the hash is the secret. - [Pass-the-ticket](https://www.learnsecuritymanagement.com/glossary/pass-the-ticket): Stealing valid Kerberos tickets from a compromised machine's memory and replaying them from another system, authenticating as the victim without knowing any password or hash. - [Penetration testing](https://www.learnsecuritymanagement.com/glossary/penetration-testing): An authorised simulated attack, run under written rules of engagement, that proves whether weaknesses are actually exploitable rather than merely listing them. - [Protection rings](https://www.learnsecuritymanagement.com/glossary/protection-rings): A hardware-enforced privilege hierarchy in which privilege increases inward: ring 0 holds the kernel and is most privileged, ring 3 holds user applications and is least privileged. - [Public Key Infrastructure (PKI)](https://www.learnsecuritymanagement.com/glossary/public-key-infrastructure): The CAs, registration authorities, certificates, and revocation services (CRLs, OCSP) that bind identities to public keys and let strangers trust asymmetric cryptography at scale. - [Recovery Point Objective (RPO)](https://www.learnsecuritymanagement.com/glossary/rpo): The maximum data loss a business can tolerate, measured as a time window backwards from a disruption. RPO drives backup frequency: a one-hour RPO needs backups at least hourly. - [Recovery Time Objective (RTO)](https://www.learnsecuritymanagement.com/glossary/rto): The maximum time a business process can be down before recovery must complete. A CISSP Domain 7 metric: RTO plus WRT must fit inside the Maximum Tolerable Downtime (MTD). - [Reference monitor](https://www.learnsecuritymanagement.com/glossary/reference-monitor): The abstract machine that mediates every access by every subject to every object against the security policy. A concept, not a product, defined by three properties. - [Replay attack](https://www.learnsecuritymanagement.com/glossary/replay-attack): Capturing a valid authentication exchange and retransmitting it later to impersonate the original party. Defeated by timestamps, nonces, and sequence numbers that make each exchange unique. - [Residual risk](https://www.learnsecuritymanagement.com/glossary/residual-risk): The risk that remains after controls are applied. It can never reach zero, so leadership must formally accept whatever remains within the organisation's risk appetite. - [Risk appetite](https://www.learnsecuritymanagement.com/glossary/risk-appetite): The amount and type of risk leadership is willing to accept in pursuit of organisational objectives, set at board level and cascaded down as the boundary for every risk decision. - [Risk treatment](https://www.learnsecuritymanagement.com/glossary/risk-treatment): The decision on how to respond to an identified risk using one of four options: avoid it, transfer it, mitigate it, or accept it. Every identified risk gets exactly one deliberate response. - [Role-Based Access Control (RBAC)](https://www.learnsecuritymanagement.com/glossary/role-based-access-control): Access control model where permissions attach to roles and users receive roles matching their job function, simplifying administration and limiting privilege creep at scale. - [Rule-based access control](https://www.learnsecuritymanagement.com/glossary/rule-based-access-control): Access control applying one global set of rules to every subject, as in firewall ACLs or time-of-day limits; distinct from role-based access control despite sharing the RBAC initials. - [Sandboxing](https://www.learnsecuritymanagement.com/glossary/sandboxing): Running untrusted code in an isolated environment so its behaviour can be observed and contained without risk to production; the basis of malware detonation and browser isolation. - [Scoping](https://www.learnsecuritymanagement.com/glossary/scoping): The binary decision about whether a baseline control applies to your environment at all. A control for a technology you do not run is scoped out. Applicability, not customisation. - [Security audit](https://www.learnsecuritymanagement.com/glossary/security-audit): A formal, evidence-based evaluation of controls against a defined standard, performed by internal, external, or third-party auditors whose independence determines its credibility. - [Security Information and Event Management (SIEM)](https://www.learnsecuritymanagement.com/glossary/siem): Centralised platform that aggregates logs from across the estate, normalises them, correlates events from multiple sources in near real time, and raises alerts for investigation. - [Security kernel](https://www.learnsecuritymanagement.com/glossary/security-kernel): The hardware, firmware and software inside the trusted computing base that implements the reference monitor concept in running code. The implementation, not the concept. - [Security policy](https://www.learnsecuritymanagement.com/glossary/security-policy): The top of the governance document hierarchy: a mandatory, high-level statement of management intent, implemented through standards and procedures and advised by guidelines. - [Sender Policy Framework (SPF)](https://www.learnsecuritymanagement.com/glossary/spf): DNS record listing the servers authorised to send mail for a domain. The receiver checks the connecting IP against the envelope sender's record, so it authenticates the path, not the visible From. - [Separation of duties](https://www.learnsecuritymanagement.com/glossary/separation-of-duties): Splitting a critical process across multiple people so no individual can complete it alone, forcing collusion to commit fraud. A core control in Clark-Wilson and Domain 1 alike. - [Service Principal Name (SPN)](https://www.learnsecuritymanagement.com/glossary/service-principal-name): The unique identifier that ties a Kerberos-enabled service to the account that runs it. Accounts with SPNs can be requested as service tickets, which makes them Kerberoasting targets. - [Side-channel attack](https://www.learnsecuritymanagement.com/glossary/side-channel-attack): An attack recovering secrets from an implementation's physical leakage (timing, power draw, emanations, cache behaviour) rather than from any weakness in the algorithm itself. - [Silver ticket attack](https://www.learnsecuritymanagement.com/glossary/silver-ticket-attack): Forging a Kerberos service ticket with a stolen service account password hash. Scope is limited to that one service, but the attack never touches the KDC, so it leaves almost no logs. - [Single Loss Expectancy (SLE)](https://www.learnsecuritymanagement.com/glossary/single-loss-expectancy): The monetary loss from one occurrence of a risk event: asset value multiplied by exposure factor (SLE = AV x EF), the per-incident building block of quantitative risk analysis. - [Single Sign-On (SSO)](https://www.learnsecuritymanagement.com/glossary/single-sign-on): Authenticate once, then access multiple systems without re-entering credentials. Improves usability and centralises control, but a compromised session unlocks everything at once. - [Software Composition Analysis (SCA)](https://www.learnsecuritymanagement.com/glossary/software-composition-analysis): Automated inventory of the third-party and open-source components inside an application, mapping each to known vulnerabilities and licence obligations via a software bill of materials. - [Software Development Life Cycle (SDLC)](https://www.learnsecuritymanagement.com/glossary/sdlc): The phased process for building and retiring software, from requirements through design, development, testing, operation, and disposal, with security built into every phase from the start. - [Software-Defined Networking (SDN)](https://www.learnsecuritymanagement.com/glossary/software-defined-networking): Architecture separating the control plane from the data plane: a centralised programmable controller sets forwarding policy network-wide, and becomes its highest-value target. - [Star Property (No Write Down)](https://www.learnsecuritymanagement.com/glossary/no-write-down): The Bell-LaPadula rule that a subject cannot write to a lower classification level, stopping cleared users from leaking secrets into documents that lower clearances can read. - [Static Application Security Testing (SAST)](https://www.learnsecuritymanagement.com/glossary/static-application-security-testing): White-box testing that analyses source code or bytecode without executing the program, catching code-level flaws early in development but missing runtime and configuration issues. - [STRIDE](https://www.learnsecuritymanagement.com/glossary/stride): Microsoft's threat categorisation model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege, each violating one security property. - [Supply Chain Risk Management (SCRM)](https://www.learnsecuritymanagement.com/glossary/supply-chain-risk-management): Identifying and reducing the risks inherited from suppliers, vendors, and service providers: tampered hardware, counterfeit components, malicious implants, and compromised updates. - [Symmetric encryption](https://www.learnsecuritymanagement.com/glossary/symmetric-encryption): Encryption where one shared secret key both encrypts and decrypts: fast enough for bulk data, but burdened by the key distribution problem and n(n-1)/2 keys for n parties. - [Synthetic transactions](https://www.learnsecuritymanagement.com/glossary/synthetic-transactions): Scripted, pre-built transactions run against live systems to verify functionality, availability, and response times proactively, catching failures before real users hit them. - [Tabletop exercise](https://www.learnsecuritymanagement.com/glossary/tabletop-exercise): Discussion-based walkthrough in which the response team talks through a disaster scenario against the plan, validating roles and decisions without touching any production system. - [Tailoring](https://www.learnsecuritymanagement.com/glossary/tailoring): Customising how the controls that apply to your environment are implemented: adjusting parameters, adding compensating controls, or refining assumptions to fit organisational reality. - [Threat modeling](https://www.learnsecuritymanagement.com/glossary/threat-modeling): Systematic identification and rating of the threats a system faces, performed during design so weaknesses are engineered out before deployment rather than discovered in production. - [Ticket Granting Service (TGS)](https://www.learnsecuritymanagement.com/glossary/ticket-granting-service): The KDC component that exchanges a valid TGT for service tickets. Each service ticket is encrypted with the target service account's key, which is the property Kerberoasting exploits. - [Ticket Granting Ticket (TGT)](https://www.learnsecuritymanagement.com/glossary/ticket-granting-ticket): The Kerberos credential issued at logon that proves a user already authenticated. Presented to the TGS to obtain service tickets without re-entering a password. Forged TGTs are golden tickets. - [Transport Layer Security (TLS)](https://www.learnsecuritymanagement.com/glossary/tls): Protocol encrypting sessions above the transport layer: an asymmetric handshake authenticates the server and agrees symmetric session keys; the deprecated predecessor is SSL. - [Trusted Computing Base (TCB)](https://www.learnsecuritymanagement.com/glossary/trusted-computing-base): The total combination of hardware, firmware and software responsible for enforcing a system's security policy; if any part of it fails, every protection built on top of it fails. - [Trusted Platform Module (TPM)](https://www.learnsecuritymanagement.com/glossary/trusted-platform-module): A dedicated hardware chip that stores cryptographic keys, measures boot integrity, and seals secrets to a known-good platform state, anchoring full-disk encryption and secure boot. - [Virtual Local Area Network (VLAN)](https://www.learnsecuritymanagement.com/glossary/vlan): Layer 2 logical segmentation that splits one physical switch fabric into isolated broadcast domains via 802.1Q tags; separation without new hardware, subverted by VLAN hopping. - [Virtual Private Network (VPN)](https://www.learnsecuritymanagement.com/glossary/vpn): Encrypted tunnel carrying private traffic across untrusted networks; site-to-site links join whole networks through gateways, remote access serves single users, over IPsec or TLS. - [Vulnerability assessment](https://www.learnsecuritymanagement.com/glossary/vulnerability-assessment): A systematic scan that identifies, quantifies, and ranks weaknesses across systems without exploiting them, trading depth for breadth and requiring validation of false positives. - [Warm site](https://www.learnsecuritymanagement.com/glossary/warm-site): Alternate facility with hardware and connectivity in place but no current data; backups must be restored on activation, giving recovery in days at a fraction of hot-site cost. - [Well-formed transaction](https://www.learnsecuritymanagement.com/glossary/well-formed-transaction): A Clark-Wilson concept: data may only be changed by vetted procedures that move it from one consistent state to another, never by direct edits, preserving internal and external consistency. - [Work Recovery Time (WRT)](https://www.learnsecuritymanagement.com/glossary/wrt): The time after a system is technically restored spent verifying data, reconciling records, and resuming normal processing. RTO plus WRT must fit inside the MTD. - [Zero trust](https://www.learnsecuritymanagement.com/glossary/zero-trust): A security model granting no implicit trust from network location: every request is authenticated, authorised, and continuously verified, wherever it originates. ## Topics - [Identity & Access Management](https://www.learnsecuritymanagement.com/topics/identity-access-management): Proving who someone is, then deciding what they may reach: authentication, single sign-on, and the access control models. Kerberos goes deepest, with the attack chain built on it (golden tickets, silver tickets, Kerberoasting). CISSP Domain 5. - [Security Architecture](https://www.learnsecuritymanagement.com/topics/security-architecture): How a system is designed to be secure before anything is bolted on: the formal models that decide who may read and write what, the cryptography underneath, and the principles that hold when real systems get messy. CISSP Domain 3. - [Business Continuity](https://www.learnsecuritymanagement.com/topics/business-continuity): Planning for the day the system is gone: how long you can be down, how much data you can afford to lose, and where you fail over to. Impact analysis, recovery sites, and the metrics that all sit on one timeline. CISSP Domains 1 and 7. - [Exam Strategy](https://www.learnsecuritymanagement.com/topics/exam-strategy): How to think like a manager on exam day: reading a scenario for what it is really asking, spotting the distractors, and holding the fine distinctions that decide close questions. Scoping against tailoring, due care against due diligence. - [Risk Management & Governance](https://www.learnsecuritymanagement.com/topics/risk-management): Putting a number on risk, then deciding what to do about it: quantification, treatment and appetite, control types, and threat modeling. Plus the data governance vocabulary that decides classification questions. CISSP Domains 1 and 2. - [Network Security](https://www.learnsecuritymanagement.com/topics/network-security): How networks are secured and attacked: the OSI model layer by layer, the protocols that encrypt traffic in transit, and segmentation from VLANs up to micro-segmentation, so that one breach cannot reach everything. CISSP Domain 4. - [Security Operations](https://www.learnsecuritymanagement.com/topics/security-operations): Running security day to day: watching what is happening now, testing your own defences before somebody else does, and handling it properly when something goes wrong, from incident response to chain of custody. CISSP Domains 6 and 7. - [Software Development Security](https://www.learnsecuritymanagement.com/topics/software-security): Building security into software rather than bolting it on afterwards: where security fits in the development life cycle, what DevSecOps changes, and the testing that finds flaws in your code and in your dependencies. CISSP Domain 8. ## Optional - [Full content of every page](https://www.learnsecuritymanagement.com/llms-full.txt)