• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Information Security
    On this page
    lock

    Information Security

    Governance templates and trackers for managing access, data classification, breach response, retention, and security metrics.

    table_chart

    Access Rights & Permissions Matrix

    A structured record mapping roles, systems, and access levels to enforce least privilege and support access audits.

    report

    Data Breach Notification Log

    A chronological record of confirmed breaches, notification decisions, and disclosure timelines used to demonstrate regulatory compliance.

    folder_special

    Data Classification Register

    An inventory of data assets tagged by sensitivity tier to drive proportionate access, handling, and protection controls.

    shield

    Data Loss Prevention (DLP) Incident Log

    A record of detected policy violations and potential data exfiltration events used to track containment and repeat offenders.

    delete_history

    Document Retention & Disposal Tracker

    A schedule mapping record types to required retention periods and disposal methods to limit unnecessary data exposure.

    dashboard

    Security KPI Dashboard

    A curated set of recurring metrics that translate security program activity into indicators leadership and auditors can track over time.

    key

    Asymmetric-Key Cryptography

    A trust-based dual-key cryptographic system built on a mathematically linked public key and private key pair.

    verified_user

    Combined Security Model: Digital Signature + Digital Envelope

    An integrated model combining digital signatures and digital envelopes to secure authentication, integrity, and confidentiality across the …

    database

    Database Encryption Techniques (API, Plug-in, TDE)

    A comparison of the three core database encryption architectures — API, Plug-in, and TDE — used to protect sensitive data at rest.

    sync_alt

    Diffie-Hellman Key Exchange

    The algorithm that solved the key distribution problem by deriving a shared secret over a public channel using the discrete logarithm …

    mail_lock

    Digital Envelope

    The hybrid mechanism that secures encryption-key transmission by encrypting a session key with the recipient's public key.

    history_edu

    Digital Signature

    The core mechanism for integrity and non-repudiation, in which a sender encrypts a document hash with their private key.

    fingerprint

    Hash Function

    The one-way function that fingerprints data by converting an arbitrary-length message into a fixed-length digest.

    functions

    Homomorphic Encryption

    A cryptographic scheme that enables direct computation on encrypted data without ever decrypting it.

    merge_type

    Hybrid Cryptography

    An integrated cryptographic scheme that combines the speed of symmetric-key encryption with the secure key exchange of asymmetric-key …

    verified

    PKI (Public Key Infrastructure)

    The hierarchical chain of trust that certifies the identity, issuance, storage, distribution, and revocation of public keys.

    encrypted

    Post-Quantum Cryptography (PQC)

    Next-generation cryptographic algorithms designed around mathematical problems that remain hard even for quantum computers.

    bolt

    Quantum Security

    An overview of PQC, QKD, and lattice-based cryptography, the technologies that defend against the quantum computing threat.

    vpn_key

    RSA Encryption

    The number-theory-based trust scheme built on the fact that multiplying two primes is easy but factoring the product back out is hard.

    lock_person

    Sign-then-Encrypt

    A scheme that signs the plaintext first, then encrypts the entire package to secure both authentication and confidentiality.

    password

    Symmetric-Key Cryptography

    The core mechanism for high-speed data protection, built on a single secret key shared by sender and receiver.

    security

    CIA Triad

    The three core elements of information security — confidentiality, integrity, and availability — and how they trade off against each other.

    devices

    Endpoint Security

    The host-based security strategy that detects, blocks, and responds to threats once they reach an end-user device, at the front line beyond …

    dns

    Systematic Server Defense Strategy

    A layered defense strategy that hardens servers and applies secure-OS access control to protect confidentiality, integrity, and …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs