Skip to content

Blank-Page Reconstructions A–J

Draw each from memory before checking the skeleton.

A — Four A’s + Entitlement

Prompt: Authentication, Authorization, Access, Entitlement, Audit; define each and show relationships.
Minimum correct skeleton: Authentication (who) → Authorization (what may do) → Access (actual use), with Entitlement = total data exposed by the grant; Audit independently reviews evidence/compliance. Correct Authentication does not guarantee correct Authorization.

B — Restriction Model

Prompt: Confidentiality left; Regulation right; origin, access logic, aggregation rule, example.
Skeleton: Confidentiality = internal need-to-know, hierarchical, one highest level. Regulation = external allowed-to-know, additive categories. Final entitlement/protection must satisfy both.

C — Activity Flow

Prompt: rebuild Identify Requirements → Policy → Standards → Risk → Controls → Monitoring/Audit/Compliance.
Skeleton: Identify Requirements → Policy → Standards → Risk Assessment → Controls/Role Design → Manage/Monitor → Independent Audit/Compliance → Improvement.

D — Risk Discriminator

Prompt: Vulnerability / Threat / Risk with example and deciding clue.
Skeleton: weakness → possible adverse action/event → likelihood × impact/cost. Example: unpatched function → attacker may exploit → assessed probability/damage → prioritized control.

E — Masking Decision Tree

Prompt: Persistent vs Dynamic; In-flight vs In-place; use case each.
Skeleton: permanently alter stored target? yes → Persistent; while moving → In-flight; same location → In-place. Preserve source truth but hide at access/display → Dynamic.

F — Privilege-Abuse Map

Prompt: Excessive privilege / legitimate abuse / elevation / service account / shared account.
Skeleton: Excessive = too much granted; Legitimate abuse = right access, wrong use; Elevation = rights increased through exploit; Service = non-human process ID; Shared = generic human ID.

G — Policy-to-Proof Chain

Prompt: Policy → Standard → Control → Audit Trail → Independent Audit → Improvement.
Skeleton: intent → measurable rule → enforcement/procedure → evidence → independent assessment → findings/remediation.

H — Role-Access Design

Prompt: Role Grid vs Role Hierarchy and CRUD/CRUDE.
Skeleton: data/classification/function → Grid → CRUD permissions; people/workgroups → Hierarchy → inherited/restricted roles. RACI = accountability, not data operations.

I — Outsourcing / Cloud Governance

Prompt: accountability, architecture, custody, SLA, RACI/CRUD, right-to-audit, monitoring.
Skeleton: organization retains accountability → classify/architect → contract/SLA → custody → explicit RACI/CRUD → audit rights → monitoring/reporting/evidence → vendor operates controls.

J — Metrics Map

Prompt: five metric groups with one example each.
Skeleton: Architecture/Controls → Baseline → Implementation | Awareness | Protection | Incident | Confidential Data Proliferation → findings/decisions → improvement.

← Rapid Recall Key · Classification Drill →