GRC Careers

HomeResources

Professional Library

Cybersecurity Reference Library

Original, professional reference sheets on the concepts, attacks, tools, and standards that define modern cybersecurity, and the careers built on them.

Foundations

CS-001 Cybersecurity CS-002 The CIA Triad CS-003 Defense in Depth CS-004 Zero Trust CS-005 Attack Surface CS-006 Threat Actors CS-007 The Cyber Kill Chain CS-008 MITRE ATT&CK CS-009 Core Security Principles CS-010 Cyber Hygiene

Malware

CS-011 Computer Viruses CS-012 Trojans CS-013 Worms CS-014 Ransomware CS-015 Spyware CS-016 Adware CS-017 Rootkits CS-018 Botnets CS-019 Cryptominers CS-020 Mobile Malware CS-021 Fileless Malware

Passwords & Authentication

CS-022 Passwords CS-023 Passphrases CS-024 Password Managers CS-025 Multi-Factor Authentication (MFA) CS-026 Passkeys CS-027 Credential Stuffing CS-028 Password Spraying CS-029 Brute Force Attacks CS-030 Rainbow Tables CS-031 Account Lockout

Email Security

CS-032 Phishing CS-033 Spear Phishing CS-034 Whaling CS-035 Business Email Compromise (BEC) CS-036 Smishing CS-037 Vishing CS-038 QR Code Phishing (Quishing) CS-039 Malicious Attachments

Network

CS-040 The OSI Model CS-041 TCP/IP CS-042 Ports & Protocols CS-043 Firewalls CS-044 DNS Security CS-045 VPNs CS-046 NAT CS-047 Intrusion Detection Systems (IDS) CS-048 Intrusion Prevention Systems (IPS) CS-049 Proxy Servers CS-050 Wireless Security

Network Tools

CS-051 Nmap CS-052 Wireshark CS-053 Netcat CS-054 tcpdump CS-055 Traceroute CS-056 Ping & ICMP

Application Security

CS-057 OWASP Top 10 CS-058 SQL Injection CS-059 Cross-Site Scripting (XSS) CS-060 Cross-Site Request Forgery (CSRF) CS-061 Server-Side Request Forgery (SSRF) CS-062 Authentication CS-063 Authorization CS-064 Secrets Management CS-065 Secure Coding

API Security

CS-066 REST API Security CS-067 JSON Web Tokens (JWT) CS-068 OAuth 2.0 CS-069 OpenID Connect CS-070 API Rate Limiting CS-071 API Gateways CS-072 GraphQL Security

Endpoint Security

CS-073 Windows Security CS-074 Linux Security CS-075 macOS Security CS-076 Android Security CS-077 iPhone / iOS Security CS-078 USB Security CS-079 BitLocker CS-080 FileVault

Vulnerability & Operations

CS-081 Patch Management CS-082 Vulnerability Scanning CS-083 CVE CS-084 CVSS CS-085 Risk Ratings CS-086 SIEM CS-087 The Security Operations Center (SOC) CS-088 Threat Hunting

Threat Intelligence

CS-089 Indicators of Compromise (IOCs) CS-090 Indicators of Attack (IOAs) CS-091 Threat Feeds CS-092 OSINT

Incident Response

CS-093 Incident Response: Preparation CS-094 Incident Response: Identification CS-095 Incident Response: Containment CS-096 Incident Response: Eradication CS-097 Incident Response: Recovery CS-098 Incident Response: Lessons Learned

Digital Forensics

CS-099 Digital Evidence CS-100 Chain of Custody CS-101 Memory Forensics CS-102 Disk Imaging CS-103 Log Analysis

Compliance & Frameworks

CS-104 NIST Cybersecurity Framework (CSF) CS-105 CIS Controls CS-106 ISO/IEC 27001 CS-107 SOC 2 CS-108 HIPAA CS-109 PCI DSS CS-110 GDPR

AI Security

CS-111 Prompt Injection CS-112 Model Poisoning CS-113 Shadow AI CS-114 AI Hallucinations CS-115 Secure AI Adoption CS-116 OWASP Top 10 for LLM Applications
Download the complete library
Print-ready PDFs and PNGs of every sheet, packaged for study and team training.
Coming soon on Gumroad