Searching CertSprout…
Searching CertSprout…
A little curiosity goes a long way
Search certifications, learning topics, career paths, public profiles and help across CertSprout.
Showing 20 results for “ISC2”. More results are available below.
CC · Security Principles
Every security control protects at least one of three properties. Confidentiality keeps information from unauthorised eyes; encryption and access controls serve it. Integrity ensures data is…
CC · Security Principles
Authentication proves a claimed identity using one or more factors. Something you know is a password or PIN. Something you have is a token, smart card or phone generating codes. Something yo…
CC · Security Principles
Non-repudiation provides proof that a specific party performed an action, so they cannot later deny it. Digital signatures deliver this: the sender signs with a private key that only they ho…
CC · Security Principles
A vulnerability is a weakness, such as an unpatched server. A threat is a potential cause of harm, such as an attacker or a flood. Risk is the likelihood that a threat exploits a vulnerabili…
CC · Security Principles
Controls are grouped by how they are implemented. Physical controls protect facilities and hardware: locks, guards, fences, cameras, badge readers. Technical (or logical) controls are enforc…
CC · Security Principles
Governance documents form a hierarchy. Policies are high-level statements of management intent that say what must be done and are mandatory; an acceptable use policy is the classic example. …
CC · Security Principles
Certified members agree to four canons, listed in order of precedence for when they conflict. First, protect society, the common good, necessary public trust and confidence, and the infrastr…
CC · Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
Business continuity is the broad discipline of sustaining critical business functions during and after a disruption, covering people, facilities, suppliers and communications. Disaster recov…
CC · Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
Alternate sites let an organisation resume operations when the primary location is unusable. A hot site is fully equipped with hardware, current data and network connectivity, ready within m…
CC · Business Continuity (BC), Disaster Recovery (DR) & Incident Response Concepts
Incident response follows a life cycle. Preparation builds the team, tools, playbooks and communication channels before anything happens. Detection and analysis identifies events, validates …
CC · Access Controls Concepts
Least privilege grants each subject only the permissions required to do their job, limiting damage from mistakes or compromise. Need to know restricts access to specific information even amo…
CC · Access Controls Concepts
Access control models differ in who sets permissions. Discretionary access control lets the resource owner decide who may access it, as with file permissions on a personal workstation; flexi…
CC · Access Controls Concepts
Physical access controls stop unauthorised people reaching equipment. Badge readers and smart cards authenticate entry and create logs. A mantrap, also called an access control vestibule, us…
CC · Access Controls Concepts
Logical access starts with provisioning an account with the right permissions when someone joins. Periodic access reviews confirm the rights are still appropriate, especially after a role ch…
CC · Access Controls Concepts
Defence in depth assumes any single control can fail and layers several so an attacker must defeat all of them. A typical stack includes perimeter firewalls, network segmentation, host firew…
CC · Network Security
The OSI model has seven layers: physical, data link, network, transport, session, presentation, application. The TCP/IP model compresses them to four: network access, internet, transport, ap…
CC · Network Security
Port numbers identify services and appear constantly on the exam. SSH is TCP 22 and encrypts remote administration; Telnet is TCP 23 and sends everything in clear text, so it should be repla…
CC · Network Security
A firewall enforces policy at a boundary by allowing or denying traffic based on addresses, ports, protocols and, in next-generation models, applications and users. An intrusion detection sy…
CC · Network Security
A denial of service attack exhausts a system's resources so legitimate users cannot reach it; a distributed version uses a botnet of many compromised devices, which is far harder to block by…
CC · Network Security
A virtual private network creates an encrypted tunnel across an untrusted network such as the internet, letting remote workers or branch offices reach internal resources securely; IPsec and …
People search uses public names, handles and headlines. Private and unlisted profiles are excluded. Your goals are visible only to you in search.