Quick References

AI Governance
HITRUST
HIPPA
Vendor
SOC2_Type2
Application Threat Modeling
PCIDSS Quick Notes
System Design - Basie Flow
System Design - Cache
System Design - Load Balancing
System Design - Multi Cluster
Vendor Management - Apple

Knowledge Domains

12 areas covered
🔐
Standard

ISO 27001

International standard for establishing, implementing, and continually improving an Information Security Management System (ISMS) to protect organisational assets.

🤖
Emerging Tech

AI / ML

Artificial Intelligence and Machine Learning concepts, model lifecycle management, bias detection, explainability, and the compliance implications of automated decision-making.

📋
Discipline

GRC

Integrated approach to Governance, Risk management, and Compliance — aligning IT strategy with business objectives while managing uncertainty and regulatory obligations.

⚖️
Methodology

Risk Assessment

Structured processes for identifying, analysing, and evaluating threats and vulnerabilities. Covers qualitative and quantitative methods, risk registers, and treatment strategies.

🏛️
Governance

AI Governance

Frameworks and policies ensuring AI systems are trustworthy, transparent, and accountable. Covers EU AI Act, NIST AI RMF, responsible AI principles, and ethical oversight.

🏥
Regulation

HIPAA

Health Insurance Portability and Accountability Act — safeguarding Protected Health Information (PHI) through Privacy, Security, and Breach Notification Rules for covered entities.

🇪🇺
Regulation

GDPR

General Data Protection Regulation governing personal data collection, processing, and rights of EU/EEA data subjects. Includes DPIA requirements, DPO roles, and cross-border transfers.

🛡️
Framework

HITRUST CSF

Common Security Framework harmonising HIPAA, NIST, ISO 27001, and PCI-DSS controls into a certifiable, risk-based framework widely adopted in healthcare and financial services.

🤝
Operations

Vendor Management

Third-party risk lifecycle covering due diligence, contract controls, ongoing monitoring, and offboarding. Includes SLA governance, sub-processor oversight, and fourth-party risk.

💳
Standard

PCI-DSS

Payment Card Industry Data Security Standard protecting cardholder data. Covers network segmentation, encryption, access control, and v4.0 requirements including payment page integrity.

☁️
Infrastructure

Cloud Security

Controls and architectures securing cloud environments (AWS, Azure, GCP). Includes shared responsibility models, CSPM, infrastructure-as-code security, and CIS Benchmarks.