Security and compliance foundationsUnit 1 of 1
Foundations34 minIn reviewreview

Security and compliance foundations

Learn the language of assets, threats, risk, controls, shared responsibility, defense in depth, Zero Trust and GRC.

What you will learn

Learn the language of assets, threats, risk, controls, shared responsibility, defense in depth, Zero Trust and GRC.

Know this first
  • Network foundations
  • Computer
Start this unit
Last verifiedReview every 90 days
On this page

Name the system before selecting a control

An asset has value. A threat can cause harm. A vulnerability is a weakness that may be exploited. Risk describes uncertainty and potential effect on an objective or asset. A control modifies that risk by preventing, detecting, responding to or recovering from an event.

These terms are related but not interchangeable. A firewall is a control, not a threat. A missing patch can be a vulnerability, not automatically evidence that exploitation occurred.

Defense in depth does not mean risk zeroMicrosoft Learn · SC-900
  1. Governance and people
  2. Physical and identity controls
  3. Network and platform controls
  4. Application and data controls
  5. Asset + residual risk

Shared responsibility changes with the service model

Moving to a cloud service does not transfer every responsibility to the provider. The provider secures defined parts of the cloud service; the customer still owns responsibilities such as identities, access decisions, data classification and configuration to an extent that depends on IaaS, PaaS or SaaS.

Defense in depth and Zero Trust

Defense in depth uses multiple controls so one failure is not the only barrier. More layers do not automatically mean better security: each layer needs a purpose, owner and observable operating state.

Microsoft states three Zero Trust principles: verify explicitly, use least-privilege access, and assume breach. Zero Trust is a model for access and risk decisions, not a product name and not a claim that nobody is ever trusted.

Encryption, hashing and GRC

Encryption is designed to make data unreadable without the required key and is reversible with that key. A cryptographic hash is a one-way digest used for purposes such as integrity comparison; it is not encryption.

Governance sets direction and accountability. Risk management identifies, evaluates and treats uncertainty. Compliance evaluates obligations and evidence. A system can be compliant with a requirement and still carry material risk outside that requirement.

Next stepUse the canonical security hub

Review the visual, original practice question and official SC-900 mapping.