Across
- 1. Security Operations Center
- 3. Indicator of Attack showing malicious behavior in progress
- 5. Process of securing systems by reducing vulnerabilities
- 8. Organization behind the ATT&CK Framework
- 9. Meeting the requirements of regulations, frameworks, and standards
- 11. Security platform that automates response to alerts
- 13. Plan of Action and Milestones document used to track remediation efforts
- 15. Organization that publishes SP 800-171 and other security standards
- 18. Security model based on "never trust, always verify"
- 19. Formal evaluation of security controls and compliance
- 22. Cybersecurity Maturity Model Certification framework required for many DoD contractors
- 23. Protection that makes data unreadable without a key
- 25. Process of recording system and security events
Down
- 2. Safeguard implemented to reduce security risk
- 4. Formal review to verify compliance with security requirements
- 6. Process of correcting identified security deficiencies
- 7. Controlled Unclassified Information protected under CMMC and NIST requirements
- 10. Defense regulation requiring cybersecurity protections for contractors
- 12. Notification generated when suspicious activity is detected
- 14. Adversary tactics and techniques framework used by defenders
- 16. Multi-factor authentication requirement for secure access
- 17. Platform that collects and correlates security logs
- 20. System Security Plan documenting how security controls are implemented
- 21. Documentation provided to prove compliance during an assessment
- 24. Indicator of Compromise found during incident investigations
