Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results · Page 2 for “ISC2”. More results are available below.
CC · Security Operations
Data needs protection at every stage. At creation it is classified, for example Public, Internal, Confidential or Restricted, which determines handling rules. In storage it is encrypted at r…
CC · Security Operations
Symmetric encryption uses one shared key for both encryption and decryption, is fast and suits bulk data; AES is the standard. Its weakness is key distribution: every party needs the same se…
CC · Security Operations
Configuration management establishes and maintains a documented baseline for each system type, such as a hardened server image with unnecessary services removed, so every deployment starts s…
CC · Security Operations
Logs record who did what and when across systems, applications and network devices, providing the accountability that access control depends on and the evidence incident responders need. Cen…
CCSP · Cloud governance and cost
Cloud governance connects resource decisions to business ownership, access rules and spending controls. Consistent tags and accounts help identify who should respond to a cost increase or un…
CCSP · Cloud security
Moving a workload to a provider does not remove the need to manage permissions, secrets and sensitive information. Map where data enters, is stored and leaves, then identify the identities a…
CCSP · Privacy engineering
Privacy engineering applies lifecycle controls to application data, telemetry, caches, indexes and exports. Collect only what the feature needs and avoid unnecessary sensitive values in logs…
CGRC · Assurance and evidence
An audit evaluates evidence against defined criteria. A written policy demonstrates intended behavior; it does not prove people followed it. Select records, observations or samples that addr…
CGRC · Technology governance
Technology governance determines priorities, decision rights and oversight so technology supports organizational objectives. Management then plans and performs the work within that direction…
CGRC · Risk assessment and treatment
Risk combines the possibility of an unwanted event with its consequences for an objective. Identify the asset, threat and conditions before choosing a response. Controls may reduce likelihoo…
CISSP · Access governance
Access has a lifecycle: grant it for a justified need, review it when responsibilities change, and remove it when the need ends. Old group memberships and privileged accounts can outlive the…
CISSP · Risk assessment and treatment
Risk combines the possibility of an unwanted event with its consequences for an objective. Identify the asset, threat and conditions before choosing a response. Controls may reduce likelihoo…
CISSP · Security architecture
A trust boundary is where data or actions cross between components with different security assumptions. Map those crossings and require appropriate validation, identity checks and authorizat…
CSSLP · Secure software lifecycle
Security requirements belong alongside functional requirements. Model likely misuse early, use secure implementation patterns, and check changes through review and testing. Track dependencie…
CSSLP · Security architecture
A trust boundary is where data or actions cross between components with different security assumptions. Map those crossings and require appropriate validation, identity checks and authorizat…
CSSLP · Web application security
Browser-side checks improve usability but can be bypassed. The server must validate input and authorize the requested operation on the specific object. Keep data separate from executable que…
ISSAP · Risk assessment and treatment
Risk combines the possibility of an unwanted event with its consequences for an objective. Identify the asset, threat and conditions before choosing a response. Controls may reduce likelihoo…
ISSAP · Secure software lifecycle
Security requirements belong alongside functional requirements. Model likely misuse early, use secure implementation patterns, and check changes through review and testing. Track dependencie…
ISSAP · Security architecture
A trust boundary is where data or actions cross between components with different security assumptions. Map those crossings and require appropriate validation, identity checks and authorizat…
ISSEP · Risk assessment and treatment
Risk combines the possibility of an unwanted event with its consequences for an objective. Identify the asset, threat and conditions before choosing a response. Controls may reduce likelihoo…
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.