All certifications / Project+ / Cheat sheet
Project+ PK0-005 cheat sheet
Domain 1: Project management concepts (33%)
Exam tips
- Separate the sponsor from the project manager: the sponsor funds, authorizes and approves major changes; the project manager plans and runs the work. Ongoing work is operations, not a project.
- When a question asks what to do first after someone requests a change, the answer is to document it as a formal change request and assess its impact, not to implement it or refuse it.
- Scope creep comes from customers or users bypassing change control; gold plating comes from the team adding unrequested extras. Both are unapproved scope, and both are prevented by a clear baseline and enforced change control.
- A risk is uncertain and in the future; an issue has already happened. Qualitative analysis ranks with scales; quantitative analysis calculates with numbers such as EMV.
- Transfer moves the consequences to someone else but does not eliminate the risk. Contingency reserve is for known unknowns in the baseline; management reserve is for unknown unknowns outside it.
- Synchronous means real time and suits complex or sensitive topics; asynchronous suits routine updates and distributed teams. Deliver bad news through an interactive channel, then confirm in writing.
- High power and high interest means manage closely; high power and low interest means keep satisfied. Do not confuse the stakeholder register (who and how they feel) with the communication plan (what, when and how to send).
- Leveling can change the end date; smoothing never does. In a RACI chart each task has exactly one Accountable person, and Consulted is two-way while Informed is one-way.
- The critical path is the longest path and has zero float. Crashing adds cost; fast-tracking adds risk. Compressing activities that are not on the critical path does not shorten the project.
- The product owner decides what and in what order; the scrum master coaches and removes impediments but does not assign work. Velocity forecasts one team's work and must not be used to compare teams.
- Stable, well-defined requirements and formal sign-offs point to predictive; changing requirements and frequent feedback point to agile. Lean removes waste; Six Sigma reduces variation with DMAIC.
- Collaborating is usually the best long-term technique when time allows; forcing fits emergencies and safety or legal issues; withdrawing only delays the problem. Storming is where conflict appears.
Key terms
- Project
- A temporary endeavor with a defined beginning and end that creates a unique product, service or result.
- Operations
- Ongoing, repetitive work that keeps the business running, such as help desk support and routine patching.
- Program
- A group of related projects managed in a coordinated way to obtain benefits not available from managing them separately.
- Portfolio
- All the projects, programs and related work an organization funds, selected and balanced to meet strategic goals.
- Triple constraint
- The linked limits of scope, time and cost, with quality at the center, where changing one affects the others.
- Sponsor
- The senior person who champions the project, provides funding, signs the charter and approves major changes.
- Project management office (PMO)
- The group that sets project standards, templates and governance across the organization.
- Change control
- The formal process for evaluating and approving or rejecting changes to project baselines.
- Change request
- A formal written proposal to modify scope, schedule, cost or another baseline.
- Change log
- A record of all change requests with their status, decisions and dates.
- Impact assessment
- An analysis of how a proposed change would affect scope, schedule, cost, quality, resources and risk.
- Change control board (CCB)
- The group authorized to approve, reject or defer project change requests.
- Change management plan
- The planning document defining the change process, forms, approval thresholds and board membership.
- Scope creep
- Uncontrolled growth in scope through small additions that bypass change control.
- Gold plating
- Team members adding features or extras the customer did not request.
- Timeline change
- A change to planned dates or durations, such as a delayed delivery or an earlier deadline.
- Resource change
- Adding, removing or replacing people, equipment or other resources on a project.
- Requirements change
- A change to what the product must do, often after stakeholders refine their needs.
- Emergency change
- An urgent change approved through an expedited path to prevent serious harm, documented and reviewed afterward.
- Risk
- An uncertain event or condition that, if it occurs, affects a project objective positively or negatively.
- Issue
- A risk or problem that has actually occurred and must be dealt with now.
- Risk register
- The living document listing each risk with its probability, impact, score, owner, triggers and response.
- Qualitative risk analysis
- Ranking risks by subjective probability and impact ratings to set priorities.
- Quantitative risk analysis
- Numerical analysis of risk effects, such as expected monetary value or Monte Carlo simulation.
- Expected monetary value (EMV)
- Probability multiplied by impact in money, used to compare and size risks.
- Risk trigger
- A warning sign indicating that a risk is about to occur or has occurred.
- Probability and impact matrix
- A grid that combines probability and impact ratings to prioritize risks, often shown as a heat map.
- Avoid
- Changing the plan to eliminate a threat or its cause entirely.
- Mitigate
- Taking action to reduce the probability or impact of a threat.
- Transfer
- Shifting the impact of a threat to a third party, such as through insurance or a contract.
- Escalate
- Handing a risk to someone outside the project who has the authority or scope to manage it.
- Exploit
- Acting to make sure a positive risk definitely occurs.
- Contingency reserve
- Time or money in the baseline for identified, accepted risks (known unknowns), controlled by the project manager.
- Management reserve
- Budget outside the baseline for unidentified risks (unknown unknowns), released with management approval.
- Residual risk
- The risk that remains after a response has been applied.
- Communication plan
- The document that defines who receives what information, when, how, how often and from whom.
- Synchronous communication
- Real-time exchange with participants present at the same time, such as meetings and calls.
- Asynchronous communication
- Communication people read and respond to on their own schedule, such as email and shared documents.
- Push communication
- Information sent to specific recipients, such as emails, memos or reports.
- Pull communication
- Information placed where recipients retrieve it themselves, such as a dashboard or intranet site.
- Communication channels
- The number of possible two-person links, calculated as n x (n - 1) / 2.
- Tailoring
- Adjusting content, detail and channel to fit a particular audience.
- Stakeholder
- Anyone who can affect, be affected by or perceive themselves affected by the project.
- Stakeholder register
- The document listing stakeholders with their roles, interests, influence, attitude and expectations.
- Power/interest grid
- A four-quadrant model used to classify stakeholders and choose an engagement strategy.
- Manage closely
- The strategy for high-power, high-interest stakeholders: involve them actively and communicate often.
- Keep satisfied
- The strategy for high-power, low-interest stakeholders: meet their needs without excessive detail.
- Engagement assessment
- A comparison of each stakeholder's current and desired engagement levels to guide actions.
- Expectation management
- Keeping stakeholders' expectations aligned with the agreed scope, schedule and outcomes.
- Resource leveling
- Adjusting activity dates to resolve over-allocation, which can extend the project end date.
- Resource smoothing
- Adjusting activities only within available float so the end date and critical path do not change.
- Resource histogram
- A bar chart showing resource usage over time, used to spot over-allocation.
- Resource calendar
- A calendar showing when people and physical resources are available to the project.
- RACI chart
- A responsibility matrix marking who is Responsible, Accountable, Consulted and Informed for each task.
- Shared resource
- A person or asset split between the project and other projects or operations.
- Matrix organization
- A structure where staff report to both a functional manager and a project manager.
- Critical path
- The longest sequence of dependent activities, which determines the shortest possible project duration.
- Total float
- How long an activity can be delayed without delaying the project finish date.
- Free float
- How long an activity can be delayed without delaying the early start of its successor.
- Finish-to-start (FS)
- The most common dependency: the successor cannot start until the predecessor finishes.
- Lag
- A required waiting time added between dependent activities.
- Crashing
- Shortening the schedule by adding resources to critical path activities, at extra cost.
- Fast-tracking
- Shortening the schedule by performing sequential activities in parallel, at increased risk.
- Milestone
- A zero-duration marker for a significant point or event in the schedule.
- Product owner
- The person accountable for maximizing value by owning and ordering the product backlog.
- Scrum master
- The servant leader who coaches the team in Scrum, facilitates events and removes impediments.
- Sprint
- A fixed timebox, usually one to four weeks, in which the team produces a usable increment.
- User story
- A short requirement written from a user's view, with acceptance criteria.
- Definition of done
- The shared quality checklist an increment must meet to be considered complete.
- Velocity
- The amount of work, usually in story points, a team completes per sprint, used for forecasting.
- WIP limit
- A cap on how many work items may be in a Kanban column at one time.
- Waterfall (predictive)
- A sequential approach that plans scope, schedule and cost up front and moves through phases in order.
- Hybrid approach
- A mix of predictive and agile practices within one project or program.
- Phase gate
- A review at the end of a phase where approval is required to continue.
- PRINCE2
- A process-based method built on business justification, management by stages and management by exception.
- Lean
- An approach that maximizes customer value by eliminating waste in a process.
- Six Sigma
- A data-driven approach to reducing variation and defects in a process.
- DMAIC
- The Six Sigma cycle: Define, Measure, Analyze, Improve, Control.
- Tuckman model
- A model of team development: forming, storming, norming, performing and adjourning.
- Collaborating
- Conflict resolution by working openly together toward a solution that meets everyone's needs.
- Compromising
- Conflict resolution where each side gives up something to reach agreement.
- Smoothing
- Conflict resolution that emphasizes agreement and downplays differences.
- Forcing
- Conflict resolution by imposing one decision, used for emergencies and non-negotiable issues.
- Withdrawing
- Avoiding or postponing a conflict, which does not resolve it.
- Hygiene factors
- Elements such as pay and working conditions whose absence causes dissatisfaction but which do not motivate on their own.
Domain 2: Project life cycle phases (30%)
Exam tips
- The business case justifies whether to do the project; the charter authorizes it. When comparing options, prefer higher NPV, higher ROI and a shorter payback period.
- An assumption is believed true but unverified and is a potential risk; a constraint is a known limit. The charter is signed by the sponsor, not the project manager, and formally authorizes the project.
- The charter authorizes the project; the kickoff launches it and builds shared understanding. A stakeholder surfacing late with new demands points to incomplete stakeholder identification.
- The WBS decomposes deliverables (nouns), not activities (verbs), and the 100 percent rule means everything in scope is in the WBS. The work package is the lowest level.
- Analogous uses a similar past project; parametric uses a unit rate times quantity; bottom-up sums detailed estimates and is most accurate. PERT is (O + 4M + P) / 6, not divided by 3.
- RFI gathers information, RFP asks for a solution and price, RFQ asks for a price on a defined item. Fixed price puts cost risk on the seller; cost-reimbursable puts it on the buyer.
- The risk management plan describes how risk will be managed; the risk register lists the actual risks. Transition planning covers handover to operations and should begin early, not at go-live.
- QA checks the process and prevents defects; QC checks the product and detects defects. Passing QC is not the same as customer acceptance, which requires formal sign-off against acceptance criteria.
- When a variance appears, the first step is to analyze its cause and options, not to rebaseline or add staff. Corrective fixes the present, preventive protects the future, and anything beyond your authority is escalated with options and a recommendation.
- Lessons learned must be captured before the team is released, and a cancelled project still goes through closing. Contract closure concerns vendors; formal acceptance concerns the customer or sponsor.
Key terms
- Business case
- The document that justifies a proposed project by comparing options, costs, benefits and risks.
- Feasibility study
- An assessment of whether a proposed project is technically, operationally, financially and legally workable.
- Return on investment (ROI)
- Net benefit divided by cost, expressed as a percentage.
- Payback period
- The time needed for savings or benefits to repay the initial investment.
- Net present value (NPV)
- The value today of future cash flows minus the investment; positive NPV is favorable.
- Rough order of magnitude (ROM)
- An early, wide-range estimate used to decide whether to proceed.
- Gap analysis
- A comparison of the current state with the desired future state to identify what must change.
- Project charter
- The document that formally authorizes a project and gives the project manager authority to use resources.
- Assumption
- A factor considered true for planning without proof, which should be logged and validated.
- Constraint
- A known limit the project must work within, such as a deadline, budget or mandated technology.
- Assumption log
- A record of assumptions and constraints, reviewed and validated throughout the project.
- Success criteria
- Measurable conditions that define whether the project has achieved its objectives.
- SMART objectives
- Objectives that are specific, measurable, achievable, relevant and time-bound.
- Kickoff meeting
- The meeting that formally launches the project and aligns the sponsor, team and stakeholders on goals, roles and processes.
- Stakeholder identification
- The ongoing process of finding everyone who affects or is affected by the project.
- Stakeholder register
- The document recording stakeholders with their roles, interests, influence and expectations.
- Project manager authority
- The decision rights granted to the project manager, documented in the charter.
- Functional manager
- The manager of a department who controls staff that may be assigned to the project.
- Least privilege
- Granting each person only the access their role requires.
- Functional requirement
- A statement of what the product must do, such as a feature or function.
- Non-functional requirement
- A quality the product must have, such as performance, availability or security.
- Requirements traceability matrix
- A table linking each requirement to its source, deliverable and test.
- Scope statement
- A detailed description of deliverables, acceptance criteria, exclusions, assumptions and constraints.
- Work breakdown structure (WBS)
- A hierarchical decomposition of the total project scope into deliverables and work packages.
- Work package
- The lowest level of the WBS, small enough to estimate, assign and control.
- WBS dictionary
- A document giving detailed information about each WBS element.
- Scope baseline
- The approved scope statement, WBS and WBS dictionary, changed only through change control.
- Analogous estimating
- Estimating from the actual values of a similar past project; quick but less accurate.
- Parametric estimating
- Estimating by multiplying a unit rate by the quantity of work.
- Bottom-up estimating
- Estimating each work package in detail and summing the results; most accurate and slowest.
- Three-point estimate
- An estimate using optimistic, most likely and pessimistic values to reflect uncertainty.
- PERT estimate
- A weighted three-point estimate calculated as (O + 4M + P) / 6.
- Baseline
- The approved version of scope, schedule or cost used to measure performance, changed only through change control.
- Progressive elaboration
- Refining plans and estimates in more detail as more information becomes available.
- Cost baseline
- The approved, time-phased budget including contingency reserve but excluding management reserve.
- Make-or-buy analysis
- Deciding whether to produce work internally or purchase it from an outside vendor.
- Request for proposal (RFP)
- A solicitation asking vendors to propose a solution and price for a stated need.
- Request for quote (RFQ)
- A solicitation asking vendors for prices on a clearly specified product or service.
- Statement of work (SOW)
- A description of the vendor's deliverables, timeline, standards and acceptance criteria that forms part of the contract.
- Firm fixed price contract
- A contract with a set price for defined scope, where the seller carries the cost risk.
- Time and materials contract
- A contract paying an hourly rate plus materials, usually with a not-to-exceed cap.
- CapEx vs OpEx
- Capital expenses buy long-lived assets; operating expenses are ongoing costs such as subscriptions.
- Project management plan
- The collection of baselines and subsidiary plans describing how the project will be executed, monitored and controlled.
- Quality management plan
- The plan defining quality standards, metrics, responsibilities and QA and QC activities.
- Risk management plan
- The plan defining how risk management will be performed, including scales, categories and roles.
- Transition plan
- The plan for handing the finished product over to operations and support.
- Release plan
- The plan for how and when the product is delivered to users, including rollout approach and rollback.
- Hypercare
- A short period of intensified support immediately after go-live.
- Go/no-go criteria
- Predefined conditions checked before a release to decide whether to proceed.
- Quality assurance (QA)
- Process-focused, preventive activities that confirm the team follows the right standards and procedures.
- Quality control (QC)
- Product-focused, detective activities that inspect and test deliverables to find defects.
- User acceptance testing (UAT)
- Testing by business users to confirm the product meets their needs before sign-off.
- Acceptance criteria
- The agreed conditions a deliverable must meet to be formally accepted.
- Change order
- A formal, approved change to a vendor contract's scope, price or schedule.
- Issue log
- A record of current problems with owners, status and resolution.
- Pareto chart
- A ranked bar chart showing which causes account for most defects.
- Variance
- The difference between what was planned and what actually happened.
- Tolerance
- An agreed threshold of variance that can be accepted before action or escalation is required.
- Corrective action
- An action taken to bring current performance back in line with the plan.
- Preventive action
- An action taken to reduce the chance that a future problem affects the project.
- Escalation path
- The defined route for raising issues beyond the project manager's authority, usually to the sponsor and then the steering committee.
- Formal acceptance
- Written confirmation from the sponsor or customer that the deliverables meet the acceptance criteria.
- Transition to operations
- The handoff of the finished product, documentation and support duties to the operations team.
- Contract closure
- Confirming vendor deliverables, settling claims, paying final invoices and archiving procurement records.
- Lessons learned
- Documented insights about what worked, what did not and what to change on future projects.
- Closure report
- The final project report comparing results with objectives and summarizing performance and outstanding items.
Domain 3: Tools and documentation (19%)
Exam tips
- Timeline with bars, dependencies and milestones is a Gantt chart. Workflow columns with WIP limits is a Kanban board. At-a-glance health for executives is a dashboard, and an audit trail of defects or requests is a ticketing system.
- Time zones and the need for a written record point to asynchronous tools; complex, urgent or sensitive discussions point to real-time tools. Confusion over which document is current is solved by version control in a single shared repository.
- Rank the biggest causes: Pareto. Is the process stable within limits over time: control chart. Are two variables related: scatter diagram. Brainstorm causes by category: fishbone. Distribution of values: histogram.
- On a burndown, actual above ideal means behind. A burnup is best for showing scope changes. Velocity is for forecasting one team's work, never for comparing teams. On a CFD a widening band is a bottleneck.
- Every formula starts with EV. Variances subtract (EV - AC, EV - PV) and indexes divide (EV / AC, EV / PV). A negative variance or an index below 1 is bad. When performance is expected to continue, EAC = BAC / CPI.
- Future uncertainty is the risk register; a current problem is the issue log; a requested modification is the change log; an unproven belief is the assumption log. Who owns a task is the RACI, and every task has exactly one Accountable person.
- Before the meeting comes the agenda; after it, minutes with decisions and action items. Every action item needs one owner and a due date. Executives get summaries or dashboards, not raw logs.
- Confidentiality is an NDA; intent to cooperate without binding terms is an MOU; measurable service targets are an SLA; the work to be performed is a SOW; authorization to buy is a PO; a signed contract amendment is a change order.
- EMV is probability times impact. In a decision tree, add each option's own cost to its expected risk cost and pick the lowest total or the highest value. Delphi means anonymous experts; the five whys and fishbone diagrams mean root cause analysis.
Key terms
- Gantt chart
- A bar chart showing tasks against a calendar, with dependencies and milestones.
- Critical path
- The longest sequence of dependent tasks, which determines the shortest possible project duration.
- Kanban board
- A visual board of cards moving through workflow columns, often with work-in-progress limits.
- Work-in-progress (WIP) limit
- A cap on how many items may be in a workflow stage at once, used to expose bottlenecks.
- Ticketing system
- A tool that logs and tracks requests, incidents or defects with owners, status and history.
- Dashboard
- A one-screen summary of key project indicators, often using red, amber and green status.
- Synchronous (real-time) communication
- Communication where participants interact at the same time, such as a video call.
- Asynchronous communication
- Communication where people contribute at different times, such as email, threads or shared comments.
- Shared workspace
- A central online location where the team stores and works on project documents together.
- Version control
- Tracking changes to a document or file over time so the current version is clear and earlier ones can be restored.
- Revision history
- A table or log recording each version of a document, what changed, who changed it and when.
- Check-in/check-out
- A file-locking feature that stops two people editing the same document at the same time.
- Histogram
- A bar chart showing how frequently values fall into ranges or categories.
- Pareto chart
- A histogram sorted from most to least frequent with a cumulative percentage line, used to prioritize causes.
- Run chart
- A line chart plotting a measure over time to show trends and patterns.
- Control chart
- A run chart with a mean and upper and lower control limits, used to judge whether a process is stable.
- Scatter diagram
- A plot of paired values for two variables showing whether they are correlated.
- Fishbone (Ishikawa) diagram
- A cause-and-effect diagram grouping possible causes of a problem into categories.
- Rule of seven
- Seven or more consecutive points on one side of the mean, suggesting a non-random shift in the process.
- Information radiator
- A highly visible chart or board that shows team status without anyone needing to ask.
- Burndown chart
- A chart of work remaining over time compared with an ideal line down to zero.
- Burnup chart
- A chart of work completed rising toward a separate total-scope line, making scope changes visible.
- Velocity
- The amount of work, usually in story points, a team completes in a sprint.
- Cumulative flow diagram (CFD)
- A stacked-band chart of how many items are in each workflow state over time.
- Lead time
- The elapsed time from when work on an item starts or is requested until it is delivered.
- Planned value (PV)
- The budgeted cost of the work scheduled to be completed by a given date.
- Earned value (EV)
- The budgeted cost of the work actually completed by a given date.
- Actual cost (AC)
- The money actually spent on the work completed by a given date.
- Cost performance index (CPI)
- EV divided by AC; below 1 means over budget.
- Schedule performance index (SPI)
- EV divided by PV; below 1 means behind schedule.
- Estimate at completion (EAC)
- The forecast total cost of the project, often BAC divided by CPI.
- Estimate to complete (ETC)
- The forecast additional cost to finish the remaining work, EAC minus AC.
- Project management plan
- The approved document combining the baselines and subsidiary plans that describe how the project will be run.
- RACI chart
- A responsibility matrix showing who is Responsible, Accountable, Consulted and Informed for each task.
- Risk register
- A log of identified risks with probability, impact, owner, trigger and response.
- Issue log
- A log of current problems with owner, priority, actions, due date and status.
- Change log
- A record of all change requests with their impact, decision and status.
- Assumption log
- A record of assumptions and constraints and whether each has been validated.
- Stakeholder register
- A list of stakeholders with their interests, influence and engagement approach.
- Agenda
- A document sent before a meeting listing its purpose, topics, timings and attendees.
- Meeting minutes
- A written record, sent after a meeting, of attendees, key points, decisions and action items.
- Action item
- A specific task arising from a meeting, assigned to one owner with a due date.
- Status report
- A periodic summary of progress, schedule, budget, risks, issues and upcoming work.
- RAG status
- A red, amber or green indicator showing whether a project or area is on track.
- Executive summary
- A brief, high-level report for senior leaders focused on status, key risks and decisions needed.
- Non-disclosure agreement (NDA)
- A contract that obliges one or both parties to keep shared information confidential.
- Memorandum of understanding (MOU)
- A document recording parties' intent to cooperate, usually not legally binding.
- Statement of work (SOW)
- A document defining the work, deliverables, schedule and acceptance criteria for a vendor.
- Service level agreement (SLA)
- An agreement defining measurable service targets and remedies if they are missed.
- Purchase order (PO)
- The buyer's formal authorization to purchase specified goods or services on stated terms.
- Three-way match
- Checking an invoice against the purchase order and proof of receipt before paying.
- Change order
- A formal, signed amendment to a contract or purchase order changing scope, price or schedule.
- SWOT analysis
- A grid of internal Strengths and Weaknesses and external Opportunities and Threats.
- Cost-benefit analysis
- Comparing an option's total expected costs with its expected benefits to judge if it is worthwhile.
- Weighted scoring model
- A decision matrix that scores options against weighted criteria, often used for vendor selection.
- Expected monetary value (EMV)
- Probability multiplied by impact, used to compare risks and options in money terms.
- Decision tree
- A diagram of a decision's options and their uncertain outcomes, with probabilities and values on each branch.
- Delphi technique
- Gathering anonymous expert opinions over several rounds to reach consensus without group pressure.
- Root cause analysis
- Identifying the underlying cause of a problem so it can be fixed permanently.
Domain 4: Basics of IT and governance (18%)
Exam tips
- When asked what access to give a contractor or team member, choose the narrowest, time-limited, individually named option. Security requirements belong in planning and requirements, not after testing.
- Health records mean PHI and HIPAA. Card numbers mean PCI DSS. Personal data of people in the EU means GDPR, even if the company is elsewhere. Test with masked or synthetic data, never real personal data.
- Infrastructure questions usually test impact: downtime needs a maintenance window and change approval, new systems create dependencies and capacity needs, and hardware lead times belong in the schedule, often on the critical path.
- Least customer management is SaaS; control of the OS is IaaS; deploying your own code without managing servers is PaaS. Cloud shifts spending from CapEx to OpEx, and the customer always remains responsible for its data and access.
- UAT happens in staging or test, never first in production. CI means automated build and test on every commit. Continuous delivery keeps a manual approval; continuous deployment does not. Automated pipelines still follow change management for production.
- Production changes need an RFC, CAB approval, a maintenance window, user notification and a rollback plan with a decision point. During a change freeze, non-urgent project work waits; it must not be relabeled as an emergency.
- Old drives with sensitive data need sanitization or destruction with documentation; reformatting is not enough. New hardware may need more power, cooling and rack space, and those belong in the plan with their own lead times.
- There are three different 'change' ideas: project change control (changes to the plan), operational change management (changes to production through the CAB) and organizational change management (helping people adopt the change). Low adoption points to OCM and training.
- RPO is how much data you can lose, which sets backup frequency. RTO is how long you can be down, which sets restore speed. Untested backups are not reliable, so a restore test belongs before go-live.
Key terms
- CIA triad
- The three core security goals: confidentiality, integrity and availability.
- Least privilege
- Giving users and systems only the minimum access needed, for only as long as needed.
- Access review
- A periodic check that each person's access rights are still appropriate, approved by the system owner.
- Separation of duties
- Splitting sensitive tasks so no single person controls an entire process.
- Multifactor authentication (MFA)
- Authentication that requires two or more different types of proof of identity.
- Security by design
- Building security requirements and testing into a project from the start rather than adding them later.
- Personally identifiable information (PII)
- Information that can identify a specific person, alone or combined with other data.
- Protected health information (PHI)
- Health-related information that is linked to an identifiable individual.
- GDPR
- The EU's General Data Protection Regulation, which governs processing of personal data of people in the EU.
- HIPAA
- A United States law protecting health information held by healthcare organizations and their business associates.
- PCI DSS
- The Payment Card Industry Data Security Standard for organizations that handle cardholder data.
- Data classification
- Labeling data by sensitivity so appropriate security controls are applied.
- Data retention policy
- Rules for how long records must be kept and when they must be securely deleted.
- Server
- A computer, physical or virtual, that provides services such as applications, files or databases to other devices.
- Virtual machine (VM)
- A software-based computer running on a hypervisor, sharing a physical host with other VMs.
- Endpoint
- A device people use directly, such as a laptop, desktop, phone or printer.
- Storage area network (SAN)
- A dedicated network that provides high-performance block storage to servers.
- Lead time
- The time between ordering something and receiving it, which must be built into the schedule.
- End of life (EOL)
- The point at which a vendor stops supporting a product, often forcing an upgrade or replacement.
- Infrastructure as a service (IaaS)
- A cloud model where the provider supplies compute, storage and networking and the customer manages the OS and above.
- Platform as a service (PaaS)
- A cloud model where the provider manages the infrastructure, OS and runtime, and the customer deploys code and manages data.
- Software as a service (SaaS)
- A cloud model where the provider runs the whole application and the customer configures it and manages users and data.
- Shared responsibility model
- The division of security and management duties between the cloud provider and the customer.
- Hybrid cloud
- A combination of on-premises or private resources with public cloud services that work together.
- Multicloud
- Using cloud services from more than one provider.
- CapEx vs OpEx
- Capital expenditure is upfront investment in assets; operating expenditure is ongoing spending such as subscriptions.
- Software development life cycle (SDLC)
- The structured phases software goes through, from planning and requirements to deployment and maintenance.
- Continuous integration (CI)
- Frequently merging code into a shared repository, with automated builds and tests on each merge.
- Continuous delivery
- Keeping every tested change ready to release, with a manual approval before production.
- Continuous deployment
- Automatically releasing every change that passes the pipeline to production.
- Staging environment
- A pre-production environment that mirrors production for final testing and validation.
- Release management
- Planning, scheduling and controlling the deployment of software releases into production.
- DevSecOps
- Integrating automated security practices into the DevOps pipeline.
- Change advisory board (CAB)
- The group that reviews and approves or rejects significant changes to the production environment.
- Request for change (RFC)
- A formal request describing a proposed production change, its risk, plan and rollback.
- Standard change
- A low-risk, repeatable change that is pre-approved and follows a documented procedure.
- Emergency change
- An urgent change handled through an expedited approval process, documented afterward.
- Maintenance window
- An agreed period when changes may be made with the least impact on the business.
- Change freeze
- A period when non-emergency changes are not allowed, such as during peak business times.
- Rollback (backout) plan
- The documented steps and decision criteria for restoring the previous state if a change fails.
- Uninterruptible power supply (UPS)
- A battery-backed device that keeps equipment running through short power outages and allows clean shutdowns.
- Power distribution unit (PDU)
- A device in a rack that distributes electrical power to the equipment.
- Access control vestibule
- A secured entry with two doors that lets only one authorized person through at a time.
- Asset inventory
- A record of hardware and software assets with location, owner, serial number, warranty and license details.
- Media sanitization
- Removing data from storage media so it cannot be recovered, by overwriting, degaussing or destruction.
- Certificate of destruction
- A document confirming that media or equipment was securely destroyed, used as audit evidence.
- Governance
- The framework of rules, roles and decision processes that directs and controls projects.
- Project management office (PMO)
- A group that sets standards and supports, controls or directly manages projects.
- Phase gate review
- A formal checkpoint at the end of a phase where a governance body decides whether the project continues.
- Organizational change management (OCM)
- Managing the people side of change so users understand, accept and adopt it.
- Super user (champion)
- A trained user in a department who helps colleagues adopt a new system.
- ADKAR
- A change model of Awareness, Desire, Knowledge, Ability and Reinforcement.
- Recovery time objective (RTO)
- The maximum acceptable time a system can be unavailable before it must be restored.
- Recovery point objective (RPO)
- The maximum acceptable data loss measured in time, which sets how often data must be backed up or replicated.
- Business impact analysis (BIA)
- An analysis of critical business processes and the impact of losing them over time.
- Incremental backup
- A backup of changes since the last backup of any type.
- Differential backup
- A backup of all changes since the last full backup.
- Hot site
- A fully equipped recovery site that can take over almost immediately.
- Tabletop exercise
- A discussion-based walk-through of how the team would respond to a disaster scenario.
Study Project+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Project+ study planLessons, quizzes, exam simulations and hands-on labs.