ข้ามไปยังเนื้อหา

CISSP Guide — สารบัญและคู่มือใช้งาน

ชุด CISSP Guide นี้เป็นคู่มือทบทวนเนื้อหา CISSP ทั้ง 8 Domains ภาษาไทยผสมศัพท์เทคนิคอังกฤษ โดยเน้นการเชื่อม governance, risk, data, architecture, network, identity, evidence, operations และ software lifecycle เข้าด้วยกัน มากกว่าการจำ control หรือผลิตภัณฑ์เป็นรายการแยกส่วน

คู่มือนี้เหมาะกับผู้เตรียมสอบ CISSP, ผู้ทำงาน security ที่ต้องการทบทวนภาพรวมข้ามสายงาน, security manager/architect/engineer/assessor และผู้ที่ต้องอธิบายเหตุผลของ control ด้วย business requirement และ risk เนื้อหาเขียนจากมุมมองแบบ manager และ risk-based decision: owner กำหนด requirement, ผู้เชี่ยวชาญออกแบบหรือนำ control ไปใช้, assessor ตรวจ evidence และผู้มี authority ตัดสิน residual risk

คู่มือนี้เป็นเอกสารช่วยเรียน ไม่ใช่ exam outline หรือมาตรฐานทางการ ฉบับข้อสอบ น้ำหนัก เนื้อหา มาตรฐาน และแนวทางอ้างอิงอาจเปลี่ยนได้ ควรตรวจ CISSP Exam Outline และแหล่งทางการฉบับปัจจุบันก่อนสอบหรือก่อนนำไปใช้จริง

น้ำหนักด้านล่างถอดตามที่ระบุไว้ในแต่ละบท ใช้เพื่อช่วยจัดสรรเวลาอ่าน ไม่ควรตีความเป็นจำนวนข้อที่ผู้สอบทุกคนจะพบอย่างตายตัว

Domainน้ำหนักข้อสอบหัวข้อสำคัญโดยสรุป
Domain 1: Security and Risk Management16%CIA, ethics, governance, legal/compliance, policy hierarchy, risk management, BIA/BCP/DRP, personnel และ supply-chain risk
Domain 2: Asset Security10%Asset/data classification, ownership, privacy, data lifecycle/states, retention, inventory, media sanitization และ data protection controls
Domain 3: Security Architecture and Engineering13%Secure design principles, security models, trusted computing, cryptography/key lifecycle, cloud/platform, physical security, OT/ICS/IoT และ resilience
Domain 4: Communication and Network Security13%OSI/TCP/IP, data flow, segmentation, firewall/IDS/IPS, secure protocols, VPN, wireless, SDN/NFV, cloud/hybrid networking และ Zero Trust
Domain 5: Identity and Access Management13%Identity lifecycle, identity proofing, AuthN/AuthZ, MFA, access models, SSO/federation, provisioning, PAM และ service/workload identity
Domain 6: Security Assessment and Testing12%Audit/assessment strategy, control testing, evidence, vulnerability assessment, penetration testing, logging/SIEM evidence, application testing, metrics และ retest
Domain 7: Security Operations13%Monitoring/detection, incident response, investigations/forensics, configuration/change/patch, vulnerability operations, backup/recovery, DR/BC และ personnel safety
Domain 8: Software Development Security10%Secure SDLC, threat modeling, secure coding, AppSec testing, DevSecOps/CI-CD, database/API security, software supply chain, release/deployment และ production feedback

ไม่มีลำดับเดียวที่บังคับสำหรับทุกคน ลำดับต่อไปนี้เป็นเส้นทางแนะนำเพื่อให้เห็นเหตุผลก่อน implementation และเห็นหลักฐานก่อนตัดสิน risk:

  1. วางฐานการตัดสินใจ: อ่าน Domain 1 เพื่อเข้าใจ governance, risk, authority และ continuity แล้วอ่าน Domain 2 เพื่อรู้ว่า asset/data ใดต้องปกป้อง ใครเป็น owner และมี handling requirement อะไร
  2. แปลง requirement เป็น control: อ่าน Domain 3, Domain 4 และ Domain 5 เพื่อเชื่อม architecture, communication path และ subject/access decision
  3. พิสูจน์และเดินระบบ: อ่าน Domain 6 เพื่อสร้าง evidence แล้วอ่าน Domain 7 เพื่อดำเนิน เฝ้าระวัง ตอบสนอง และกู้คืน
  4. ปิด feedback loop: อ่าน Domain 8 เพื่อฝัง requirement/control/evidence ลง Secure SDLC และนำ finding หรือ incident กลับไปแก้ที่ต้นเหตุ

ถ้ามีประสบการณ์เฉพาะทางอยู่แล้ว สามารถเริ่มจาก Domain ที่ใกล้งานที่สุดแล้วไล่ cross-reference ย้อนกลับได้ เช่น network engineer อาจเริ่ม Domain 4, developer เริ่ม Domain 8 หรือ auditor เริ่ม Domain 6 แต่ควรกลับมาอ่าน Domain 1–2 เพื่อให้ technical decision ผูกกับ business risk และ ownership

วิธีอ่านแต่ละบทให้ได้ผล:

  • รอบแรกอ่านหัวข้อ ภาพรวม, แนวคิดหลัก และ Exam Tips เพื่อสร้าง mental model
  • รอบสองเจาะหัวข้อย่อย พร้อมถามทุก control ว่า “requirement มาจากใคร ลด risk ใด และต้องมี evidence อะไร”
  • รอบสามฝึก scenario ข้าม Domain โดยแยกคำถามว่าโจทย์ถาม governance, process, design, implementation, operation หรือ assurance
  • เมื่อทบทวนผิด ให้กลับไปแก้ความสัมพันธ์ระหว่างคำ ไม่จำเพียงตัวเลือก เช่น AuthN ไม่เท่ากับ AuthZ, backup ไม่เท่ากับ recovery และ compliance ไม่เท่ากับ security
หัวข้อแกนจุดเริ่มและการเชื่อมต่อข้าม Domainผลลัพธ์ที่ต้องย้อนกลับ
RiskDomain 1 กำหนด objective, appetite/tolerance, owner และ authority; Domains 2–5 แปลง risk เป็น protection requirement และ controlDomains 6–8 ส่ง evidence, incident, defect และ residual risk กลับให้ผู้มี authority ตัดสิน
DataDomain 2 กำหนด classification, ownership, lifecycle, state, retention และ privacy requirementArchitecture, network, IAM, logging, testing และ Secure SDLC ต้องตาม data ไปทุกตำแหน่งและทุกช่วง lifecycle
ArchitectureDomain 3 แปลง stakeholder need เป็น trust boundary, security service, defense in depth, cryptography และ resilienceDomain 6 ตรวจ assurance; Domain 7 รักษา design intent ระหว่าง operation/change; Domain 8 ทำให้ software สอดคล้องกับ architecture
NetworkDomain 4 ควบคุม data flow, segmentation, peer authentication, secure channel และ telemetryDomain 5 ให้ identity/context, Domain 6 ทดสอบ path/control, Domain 7 monitor/contain และ Domain 8 ป้องกัน API/CI-CD/workload flow
IAMDomain 5 เชื่อม identity, authenticator, entitlement, policy decision และ lifecycleDomain 6 ตรวจ provisioning/AuthZ/PAM; Domain 7 revoke/monitor; Domain 8 บังคับ AuthN/AuthZ และ service identity ใน application/pipeline
TestingDomain 6 เปรียบเทียบ requirement กับ actual evidence และแยก design, implementation, operating effectivenessFinding ต้องมี owner, remediation/exception, retest และส่ง residual risk ไปยัง decision maker
OperationsDomain 7 เปลี่ยน control เป็น baseline, telemetry, detection, response, recovery และ lessons learnedOperational evidence ย้อนกลับไปปรับ risk, architecture, test strategy, runbook และ software requirement
Secure developmentDomain 8 ฝัง security ใน requirement, design, code, dependency, build, release, operation และ retirementProduction feedback ต้องกลายเป็น root-cause fix, regression test, pipeline control และ risk decision ไม่จบที่ patch หรือ alert

ภาพรวมทั้งชุดอ่านเป็นวงจรได้ดังนี้:

flowchart LR d1["Domain 1: requirement, governance และ risk"] d25["Domains 2–5: asset และ data requirement, design และ control"] d6["Domain 6: evidence, assessment และ retest"] d7["Domain 7: operations, incident response และ recovery"] d8["Domain 8: Secure SDLC และ development feedback"] d1 --> d25 --> d6 --> d7 --> d8 d8 -->|"feedback ไปยัง requirement, control และ residual-risk decision"| d1

Glossary นี้คัดและสังเคราะห์เฉพาะคำที่ใช้เชื่อมหลายบท โดยใช้คำแปล canonical เดียวกับเนื้อหา คำที่ต้องการรายละเอียด เงื่อนไข หรือข้อยกเว้นให้เปิด Domain หลักจากลิงก์ในชื่อคำศัพท์

คำศัพท์/คำย่อความหมาย canonical แบบย่อ
CIA TriadConfidentiality = การรักษาความลับ, Integrity = ความถูกต้องครบถ้วน, Availability = ความพร้อมใช้
Governance / ManagementGovernance ประเมิน กำหนดทิศทาง และกำกับติดตาม; Management วางแผน สร้าง ดำเนินงาน และติดตามตามทิศทางนั้น
Risk / Threat / VulnerabilityRisk คือผลของความไม่แน่นอนต่อวัตถุประสงค์; Threat คือสิ่งหรือเหตุการณ์ที่อาจก่อผลเสีย; Vulnerability คือจุดอ่อนที่อาจถูกใช้ประโยชน์
Inherent risk / Residual riskRisk ก่อนพิจารณาผลของ controls / risk ที่เหลือหลังใช้ controls
Risk appetite / Risk toleranceระดับ risk โดยรวมที่องค์กรเต็มใจรับ / ขอบเขตการเบี่ยงเบนที่ยอมรับได้ในบริบทที่เฉพาะขึ้น
Risk ownerผู้มี accountability ในการตัดสินใจและติดตาม risk ภายใน authority ที่กำหนด
Control / Control objective / Compensating controlมาตรการที่ปรับ risk / ผลลัพธ์ด้านการควบคุมที่ต้องการ / control ทดแทนเมื่อใช้ control หลักไม่ได้และลด risk ได้ตามระดับที่ยอมรับ
Accountability / Responsibilityความรับผิดรับชอบต่อผลซึ่งโอนออกทั้งหมดไม่ได้ / หน้าที่ดำเนินงานที่มอบหมายได้
Due care / Due diligenceใช้ความระมัดระวังและมาตรการที่สมเหตุสมผล / ตรวจต่อเนื่องว่าการตัดสินใจและ controls เหมาะสมและทำงานจริง
Policy / Standard / Baseline / Procedure / Guidelineข้อกำหนดระดับสูง / ข้อกำหนดเฉพาะที่บังคับ / ระดับขั้นต่ำที่อนุมัติ / ขั้นตอนปฏิบัติ / คำแนะนำที่เปิดให้ใช้ดุลยพินิจ
BIA / BCP / DRPวิเคราะห์ผลกระทบและ recovery requirement / รักษา critical business functions / กู้คืน IT, infrastructure, application และ data
MTD / RTO / RPO / WRTระยะหยุดสูงสุดที่ยอมรับ / เป้าหมายเวลากู้ capability / จุดข้อมูลย้อนหลังที่ต้องกู้ได้ / เวลาทำให้งานพร้อมหลังระบบกลับมา
SLE / ARO / ALEความเสียหายคาดหมายต่อเหตุการณ์ / ความถี่คาดหมายต่อปี / ความเสียหายคาดหมายต่อปี โดย ALE = SLE × ARO
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Asset / Information assetสิ่งที่มีคุณค่าต่อองค์กร / ข้อมูลหรือทรัพยากรเกี่ยวกับข้อมูลที่มีคุณค่าต่อธุรกิจ
Data classification / Asset classificationจัดตามความไว คุณค่า ผลกระทบ และ obligation / จัดตาม criticality, value หรือ protection requirement
Data owner / Data custodianBusiness role ที่กำหนด classification, access, handling และ retention / ผู้เก็บดูแลและนำ operational/technical controls ไปใช้ตาม requirement
Data controller / Data processor / Data subjectผู้กำหนดวัตถุประสงค์และวิธีการหลักของ personal data processing / ผู้ประมวลผลแทน controller / บุคคลที่ข้อมูลนั้นเกี่ยวข้อง
Data lifecycleช่วงสร้างหรือเก็บรวบรวม จัดเก็บ ใช้ ส่งต่อ เก็บรักษา และทำลายข้อมูล
Data at rest / in transit / in useข้อมูลใน storage / กำลังส่งผ่าน network / กำลังประมวลผลหรืออยู่ใน memory
Retention schedule / Legal holdตารางชนิด record ระยะเก็บ trigger และ disposition / คำสั่งระงับการทำลายข้อมูลใน scope
Data remanence / Media sanitizationข้อมูลตกค้างที่อาจกู้ได้ / กระบวนการทำให้เข้าถึง target data ไม่ได้ภายใต้ระดับ effort ที่กำหนด
Clear / Purge / DestroySanitization กันการกู้แบบง่ายและมักใช้สื่อต่อได้ / กันเทคนิคห้องปฏิบัติการสมัยใหม่และอาจใช้ต่อได้ / ทำให้กู้และใช้สื่อต่อไม่ได้
Cryptographic eraseการ sanitize key ที่จำเป็นเพื่อทำให้ ciphertext ของ target data เข้าถึงไม่ได้
Masking / Tokenization / Pseudonymization / Anonymizationซ่อนค่าจริง / แทนด้วย token ที่มี mapping / แทนตัวระบุแต่ยังเชื่อมกลับได้ / มุ่งทำให้ระบุตัวบุคคลไม่ได้อย่างสมเหตุสมผล
DLP / DRM / CASBตรวจหรือจำกัดการเคลื่อนย้ายข้อมูล / จำกัดการใช้ content หลังแจกจ่าย / รวม visibility และ policy enforcement สำหรับ cloud use
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Security architecture / Security engineeringโครงสร้างองค์ประกอบ ความสัมพันธ์ และ security services ที่ตอบ requirement / กระบวนการวิศวกรรมเพื่อสร้างและรักษาระบบตาม requirement
Trust boundary / Attack surfaceจุดที่ trust หรือ authority เปลี่ยน / จุดทั้งหมดที่ attacker อาจโต้ตอบหรือส่งผลต่อระบบ
Assuranceหลักฐานที่สร้างความเชื่อมั่นว่า control ถูกต้องและทำงานตามที่อ้าง
Defense in depth / Fail securelyControls หลายชั้นต่างชนิด / failure ไม่เปิดสิทธิเกินหรือสร้างอันตรายโดยไม่จำเป็น โดยไม่เท่ากับ fail closed เสมอ
TCB / Reference monitor / Security kernelส่วนที่ร่วมบังคับ security policy / กลไกแนวคิดที่ตรวจ access ทุกครั้งและ bypass ไม่ได้ / ส่วนแกนที่ implement reference monitor
Root of trust / TPM / HSMจุดเริ่มของ trust chain / platform component สำหรับ key, measurement, attestation / อุปกรณ์หรือบริการเฉพาะสำหรับ cryptographic keys
Bell-LaPadula / Biba / Clark-WilsonConfidentiality: no read up/no write down / Integrity: no read down/no write up / Commercial integrity ผ่าน well-formed transactions และ SoD
Symmetric encryption / Asymmetric cryptographyใช้ shared secret / ใช้ public-private key pair ตามหน้าที่ของ algorithm
Cryptographic hash / MAC / Digital signatureOne-way digest ไม่มี secret / shared-secret integrity และ origin authentication / private key สร้าง signature และ public key ตรวจ
PKIPolicy, roles, processes และ technology สำหรับจัดการ public-key trust
Salt / Nonceค่าสุ่มไม่ซ้ำต่อ credential ก่อน password hashing / ค่าที่ใช้ครั้งเดียวตาม requirement ของ cryptographic construction
Cryptoperiod / Forward secrecy / Cryptographic agilityช่วงที่ key ใช้ได้ / long-term key รั่วภายหลังไม่เปิด session key เก่าโดยอัตโนมัติ / เปลี่ยน algorithm, parameter, certificate และ key อย่างควบคุม
OT / ICS / SCADAระบบที่ตรวจหรือเปลี่ยน physical environment / ระบบควบคุม industrial process / supervisory control และ data acquisition ของสถานีที่มักกระจายพื้นที่
Verification / Validationตรวจว่าตรง specification / ตรวจว่าตอบ stakeholder needs และ use case
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
OSI model / TCP/IP modelแบบจำลองการสื่อสาร 7 ชั้น / แบบจำลอง Application, Transport, Internet และ Link/Network access โดยประมาณ
Data flowเส้นทางและเงื่อนไขที่ data เคลื่อนระหว่าง source, destination, intermediary และ trust boundary
Segmentation / Microsegmentationแบ่ง network และบังคับ flow ระหว่างส่วน / policy ละเอียดระดับ workload, application หรือ identity
DMZZone คั่นกลางสำหรับ service ที่ติดต่อระหว่าง network ต่าง trust level
Data plane / Control plane / Management planeส่วน forward traffic / ส่วนสร้าง routing-forwarding decision / ส่วน configure, monitor และ administer
Stateful firewall / Proxy / WAFติดตาม connection state / ยุติและสร้าง connection อีกฝั่ง / บังคับ policy กับ HTTP/application traffic
IDS / IPSตรวจและ alert / ตรวจและสามารถ block หรือเปลี่ยน traffic ได้
TLS / mTLSปกป้อง application communication; mTLS ให้ทั้งสองฝั่งแสดง certificate แต่ยังต้องมี AuthZ
VPN / IPsecLogical protected channel ผ่าน untrusted network / protocol suite ปกป้อง IP communication
NAC / 802.1XPolicy control สำหรับ network admission / framework ควบคุมการเข้าถึง wired/wireless port ผ่าน EAP
SDN / NFVแยก control plane จาก data plane เชิงตรรกะ / ทำ network function เป็น software บน virtualized infrastructure
ZTA / SASEไม่ให้ implicit trust จาก location / รวม WAN กับ cloud-delivered security capabilities โดยยังต้องประเมิน implementation
Flow log / Blast radiusMetadata ของ network flow / ขอบเขตที่ incident หรือ failure แพร่ผลกระทบได้
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Identity / Account / Entitlementตัวแทน subject ในบริบทหนึ่ง / record ที่ผูก identity, credential และ state / สิทธิใช้ resource หรือ action
Identification / Identity proofingการอ้าง identity / การเชื่อม digital identity กับบุคคลหรือ entity ตาม assurance ที่ต้องการ
Authentication (AuthN) / Authorization (AuthZ)พิสูจน์การควบคุม authenticator / ตัดสินว่า subject ทำ action ใดกับ object ได้
Accountingการบันทึกกิจกรรมและการใช้ resource; สนับสนุนแต่ไม่เท่ากับ accountability
MFAAuthentication ที่ใช้ factor ต่างประเภทอย่างน้อยสองประเภท
SSO / FederationAuthenticate ครั้งเดียวแล้วใช้หลาย application / RP ยอมรับ assertion หรือ token จาก IdP ต่าง administrative domain
DAC / MAC / RBAC / ABACOwner มอบสิทธิ / authority กลางบังคับ label-policy / permission ผูก role / ตัดสินด้วย attributes เทียบ policy
PDP / PEPจุดประเมิน policy / จุด intercept request และบังคับผลตัดสิน
Least privilege / Need-to-know / SoDสิทธิขั้นต่ำ / เหตุผลทางงานในการเข้าถึงข้อมูล / แยกหน้าที่ขัดกัน
PAM / JIT / JEAควบคุม privileged access / ให้สิทธิแบบ time-bound / จำกัดคำสั่งหรือ resource เท่าที่จำเป็น
Provisioning / Deprovisioningสร้างหรือปรับ identity-account-credential-entitlement / ถอน account, credential, session และ entitlement
Break-glass account / Service accountIdentity ฉุกเฉินเมื่อ normal path ใช้ไม่ได้ / non-human account ของ process หรือ service
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Audit / Security assessment / Security testตรวจ evidence เทียบ criteria / ใช้ examine-interview-test ประเมิน control และ risk / กระตุ้นหรือสังเกต actual เทียบ expected result
Criteria / EvidenceRequirement ที่ใช้ตัดสิน / ข้อมูลหรือ artifact ที่สนับสนุน conclusion
Design adequacy / Operating effectivenessแบบ control เหมาะกับ objective / control ทำงานตามแบบสม่ำเสมอตลอดช่วงที่ประเมิน
Sampling / Coverage analysisเลือกส่วนของ population ด้วยวิธีที่อธิบายได้ / วัดพื้นที่ requirement, asset, code หรือ technique ที่ถูกทดสอบ
Vulnerability assessment / Penetration testingค้นหา validate และจัดลำดับ weakness โดยไม่จำเป็นต้อง exploit / controlled exploit เพื่อยืนยัน path และ impact
Rules of Engagement (ROE)ข้อตกลง authorization, scope, technique, safety, stop condition และ communication ของ test
Red team / Blue team / Purple teamจำลอง adversary / ป้องกันและตอบสนอง / ร่วมกันปรับ control และ detection
Black-box / Gray-box / White-boxระดับ knowledge/access ภายในน้อย / บางส่วน / มาก ไม่ใช่ team color
False positive / False negativeรายงานปัญหาที่ไม่จริง / มีปัญหาจริงแต่ไม่พบ
KPI / KRIตัวชี้วัด performance เทียบ objective / ตัวชี้วัดที่ส่งสัญญาณระดับหรือแนวโน้ม risk
Retestทดสอบซ้ำเพื่อยืนยัน remediation และตรวจผลข้างเคียง
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Security operations / SOCการดำเนิน control และตอบสนอง security risk ในงานประจำ / capability เฝ้าระวัง วิเคราะห์ และประสาน response
Event / Alert / Security incident / Problemสิ่งที่สังเกตได้ / event-pattern ที่ถูกยกให้ตรวจ / เหตุที่ละเมิดหรือคุกคาม security objective / สาเหตุหรือ potential cause ของ incident
Containment / Eradication / Remediationจำกัด scope-impact / กำจัด malicious artifact และ persistence / แก้ weakness หรือ control gap
Chain of custody / Digital forensicsบันทึกการครอบครองและเปลี่ยนแปลง evidence / ระบุ เก็บ ตรวจ และวิเคราะห์ digital artifact อย่างควบคุม
Log management / SIEM / UEBALifecycle ของ log / platform รวม ค้นหา correlate และวิเคราะห์ security event / analytic หา deviation ของ user หรือ entity
Threat huntingค้นหาเชิง hypothesis ใน telemetry เพื่อหาภัยที่ detection ปกติอาจพลาด
Configuration baseline / Configuration driftConfiguration ที่อนุมัติเป็นจุดอ้างอิง / state ที่เบี่ยงจาก baseline หรือ intended state
Change management / Patch managementประเมิน อนุญาต ดำเนิน สื่อสาร และทบทวน change / ระบุ จัดลำดับ จัดหา ทดสอบ ติดตั้ง และยืนยัน patch
Backup / Restore / Recoveryสำเนาเพื่อกู้ข้อมูลหรือ configuration / นำสำเนากลับมา / คืน system-service ถึง capability ที่กำหนด
HA / Failover / Failbackลด interruption / ย้ายไป alternate component-site / ย้ายกลับหลัง reconcile และพร้อมใช้งาน
Runbook / Playbookขั้นตอน operational ที่ทำซ้ำได้ / แนวทางสถานการณ์ที่มี trigger, decision point และ action
Tabletop / Parallel test / Full interruptionอภิปรายตาม scenario / ทดสอบ recovery ขนาน production / หยุดหรือย้าย production จริงภายใต้ authorization
คำศัพท์/คำย่อความหมาย canonical แบบย่อ
Secure SDLCฝัง security requirement, control, evidence และ feedback ตลอด software lifecycle
Shift left / Shift rightทำ security activity ให้เร็วขึ้น / ใช้ runtime-production evidence และ feedback
Threat modeling / Abuse-misuse caseวิเคราะห์ asset, data flow, trust boundary, threat และ mitigation / สถานการณ์การใช้ระบบในทางไม่พึงประสงค์
Input validation / Output encoding / Parameterized queryตรวจ input ตามรูปแบบที่อนุญาต / แปลงอักขระตาม output context / แยกโครงคำสั่งจากค่าข้อมูล
SAST / DAST / IAST / SCAวิเคราะห์ code โดยไม่รัน / ทดสอบ application ที่รันผ่าน interface / วิเคราะห์ด้วย runtime instrumentation / inventory component-dependency และจับคู่ vulnerability-license
Fuzz testing / Regression testส่ง input ผิดรูปแบบหรือไม่คาดคิดหา failure / ยืนยันว่า change ไม่ทำให้ behavior เดิมหรือที่แก้แล้วเสีย
DevSecOpsฝัง security responsibility, control และ feedback ใน DevOps workflow ไม่ใช่ชื่อทีม หรือ tool เดียว
Continuous Delivery / Continuous DeploymentArtifact พร้อม promote แต่อาจรอ production approval / deploy change ที่ผ่าน gate ไป production อัตโนมัติ
SCM / Software-defined securityควบคุม version-baseline-change-status ของ software items / แสดง policy-control เป็น code หรือ configuration ที่ version และ test ได้
SBOM / ProvenanceInventory ของ software components / ข้อมูลแหล่งที่มาและกระบวนการสร้าง artifact
BOLA / SSRFAPI ขาด object-level authorization / server ถูกชักให้ request ไป destination ที่ attacker มีอิทธิพล
Security gate / Risk-based exceptionจุดตัดสินจาก criteria และ evidence / ข้อยกเว้นที่มี rationale, owner, approval, mitigation และ expiry

ข้อสอบมักมีหลายตัวเลือกที่ “ทำได้” แต่ถามว่าข้อใดควรทำก่อนหรือเหมาะที่สุด ให้เริ่มจากคำบอกลำดับและมุมมองของผู้ตัดสินใจ

  • FIRST / NEXT: หา prerequisite ก่อน เช่น human safety, authority, scope, requirement, owner, assessment หรือ incident activation คำตอบเชิงเทคนิคอาจถูกแต่ยังไม่ใช่ลำดับแรก
  • BEST / MOST / PRIMARY: เลือกคำตอบที่แก้ root cause, สอดคล้อง business objective และ risk, ครอบคลุม lifecycle และสร้างผลที่ตรวจสอบได้ มากกว่าคำตอบที่เพียงติดตั้ง control จุดเดียว
  • Manager และ risk-based decision: Security team วิเคราะห์ ออกแบบ ทดสอบ และแนะนำ แต่ Data/System/Risk owner หรือผู้มี delegated authority เป็นผู้อนุมัติ requirement, exception และ residual risk ตามขอบเขตอำนาจ
  • ชีวิตและความปลอดภัยมาก่อน: ใน incident, forensic, facility, OT หรือ disaster scenario ให้ human safety มาก่อน evidence, asset และ uptime
  • แยก objective จาก technology: CIA, privacy, accountability, least privilege และ resilience เป็นผลลัพธ์ที่ต้องการ ส่วน encryption, firewall, MFA, SIEM หรือ scanner เป็นกลไกที่ต้องเลือกตาม context
  • Compliance เป็น baseline ไม่ใช่ปลายทาง: Audit หรือ certification เป็น evidence ใน scope และช่วงเวลาหนึ่ง ไม่พิสูจน์ว่าไม่มี risk หรือไม่มี vulnerability

ใช้สายคิดร่วมทั้งแปด Domain ดังนี้:

requirement
→ control
→ evidence / telemetry
→ decision / action
→ validation
→ residual risk
  1. Requirement: ใครเป็น owner ต้องปกป้อง objective/data/process ใด และมี obligation หรือ acceptance criteria อะไร
  2. Control: Architecture, process และ technology ใดลด likelihood/impact โดยไม่สร้าง safety หรือ business risk ที่ไม่ยอมรับ
  3. Evidence/telemetry: จะพิสูจน์ design, implementation และ operating effectiveness จาก artifact, test, log หรือ transaction ใด
  4. Decision/action: ใครมี authority และควร contain, remediate, recover, approve exception หรือยกระดับเมื่อใด
  5. Validation: ตรวจว่าการแก้ไขหรือ recovery ตรง specification และตอบ stakeholder need จริง รวม retest และ negative/failure path
  6. Residual risk: หลัง control และการตรวจผล ยังเหลือ risk อะไร ใครรับได้ภายใน authority และต้อง monitor/review เมื่อใด

เมื่อคำตอบข้ามหลาย Domain ให้เลือกทางที่ปิดวงจรนี้ได้ครบ ตัวอย่าง “ติดตั้ง control แล้ว” ยังไม่จบจนมี evidence ว่าทำงาน, มี action ต่อ finding, ผ่าน validation และส่ง residual risk ให้ผู้มี authority ตัดสินใจ