Security fundamentals
The foundational concepts every other term on this page builds on.
16 terms
The small set of concepts — risk, control, least privilege, defense in depth — that every other term on this page assumes you already know.
Showing 16 of 16
AAA (AAA)
Proving who you are, deciding what you can do, and logging what you did.
Asset
Anything worth protecting — data, a system, a device, or a reputation.
Attack surface
Every point an attacker could try to get in through.
CIA triad (CIA)
The three goals of security: keep data private, unaltered, and available when needed.
Control (preventive, detective, corrective)
A safeguard that reduces risk — preventive, detective, or corrective.
Defense in depth
Layer multiple controls so one failure doesn't leave you fully exposed.
Exploit
The specific technique used to take advantage of a vulnerability.
Least privilege
Give people and systems only the access they actually need — nothing more.
Non-repudiation
Proof strong enough that someone can't credibly deny an action.
Residual risk
The risk still left over after controls have been applied.
Risk
The chance a threat exploits a weakness and causes harm.
Security posture
An organization's overall readiness against cyber risk right now.
Separation of duties
Splitting a sensitive task across more than one person to prevent abuse.
Threat
Anything that could cause harm by exploiting a weakness.
Vulnerability
A weakness a threat could take advantage of.
Zero trust
Never trust a user or device by default — verify every request, every time.
No terms match your search.