Security & Compliance
This cluster provides a comprehensive perspective on security and compliance topics that are crucial for organizations.
- Knowledge domains
- /Thematic areas
- /Segments
- /Building blocks
Audit
Systematic, independent evaluation of processes, systems and compliance to identify risks and ensure quality.
Assurance
Concept for ensuring quality, reliability and compliance across the software lifecycle.
Compliance
Compliance refers to adherence to laws, regulations, and internal policies by organizations.
Access Control
Access control involves security mechanisms to regulate and monitor access to systems and data.
Authentication
A process for verifying the identity of a user.
Authorization
Authorization is a critical process to ensure that users have access to specific resources.
Identity Management
Concept for centralized management of digital identities, authentication and authorization across systems.
Data Protection Impact Assessment (DPIA)
The Data Protection Impact Assessment (DPIA) is an essential process for evaluating the impacts of data processing activities on individuals' privacy.
Data Protection
Protection of personal and sensitive data through organizational, technical and legal measures.
Privacy
Core principles and measures for protecting personal data that guide technical and organizational decisions.
Vulnerability Management
Continuous process for identifying, assessing and remediating security vulnerabilities in IT systems.
Secure Software Development Lifecycle (SSDLC)
Concept for systematically integrating security across all phases of the software lifecycle.
Security Operations
Security Operations orchestrates detection, analysis and response to security incidents to ensure the confidentiality, integrity and availability of systems.
Defense in Depth
Layered security principle that reduces risk through overlapping controls.
Security Architecture
A concept for the structural design of security capabilities in IT landscapes that defines principles, patterns and interfaces for protection measures.
Security Controls
Security controls are defined technical and organizational measures to reduce security risks and ensure confidentiality, integrity and availability. They form the foundation for compliance, operational security and incident response.
Risk Assessment
A systematic approach to identifying, assessing, and prioritizing risks.
Threat Modeling
A structured method for identifying and assessing potential threats and vulnerabilities in a system.
Risk Management
Risk management involves identifying, analyzing, and responding to risks in a project or organization.