G. GORDON GRITTY
  • Home
  • About Me
  • Shows
GGGP ISC Punk Rock CPA Study Deck

GGGP ISC Punk Rock CPA Study Deck

Contextual analogical pattern learning for ISC: trigger words, decision rules, Becker traps, and GGGP examples.

Question Decoder Trigger Words Decision Rules GGGP Memory Aid

Core Method

Study flow: Question Decoder → Core Distinction → Trigger Words → Job → Becker Trap → GGGP Memory Aid.
Learning Tool Job Example
Question Decoder Translate the stem into plain English. “Restore within 8 hours” = “How long to recover?” = RTO.
Core Distinction Identify what Becker is separating. Data model vs. schema = blueprint vs. implementation.
Trigger Words Spot the exam clue quickly. filter • criteria • condition = WHERE.
GGGP Memory Aid Make the concept concrete and memorable. GGGP ticketing site must be back online within 8 hours = RTO.

SQL Master Table

Mnemonic: Some Friends Join Weird Gigs, Hoping Others Listen.
Mnemonic SQL Clause ISC Trigger Words Job GGGP Memory Aid
Some SELECT columns • attributes • display • output Choose what columns to show. Show Order ID, Customer, and Total Sale.
Friends FROM table • source • dataset Choose which table the data comes from. Pull the data from the Orders table.
Join JOIN combine • relate • foreign key • multiple tables Combine related tables. Combine Orders with Customers so GGGP can see customer names.
Weird WHERE filter • criteria • condition • only records where Filter individual rows before grouping. Show only merch orders over $1,000.
Gigs GROUP BY group • summarize • aggregate • SUM • COUNT • AVG Group rows before calculating summaries. Show total merch sales by city.
Hoping HAVING filter groups • aggregate condition • after GROUP BY Filter summarized groups. Show only cities where merch sales exceed $10,000.
Others ORDER BY sort • ascending • descending • rank Sort final results. Sort cities from highest to lowest merch sales.
Listen LIMIT top • first • maximum rows • return only Return only a certain number of rows. Show only the Top 10 GGGP customers.

Database Normalization Decision Rules

Core question: Who actually knows the information?

1NF

one value • atomic • no repeating groups
Eliminate multiple values in one cell.
One merch item per row. Do not put “shirt, sticker, cassette” in one cell.
Decision rule: Is there more than one value in a cell?

2NF

composite key • partial dependency • whole key
Every non-key attribute depends on the whole composite primary key.
Order_ID + Product_ID identifies a sale, but Product_Name only depends on Product_ID.
Decision rule: Is the PK composite, and does only part of it know the answer?

3NF

non-key → non-key • transitive dependency
Eliminate indirect dependency through another non-key attribute.
Supplier_Phone belongs with Supplier, not with each Product SKU.
Decision rule: Does another non-PK column already know the answer?

Risk Assessment Formula Flow

Formula ISC Trigger Words Job GGGP Memory Aid
EF = Loss ÷ AV percentage loss • damage percentage • portion lost Find the percentage of the asset lost in one incident. GGGP van worth $20,000 has $5,000 damage → EF = 25%.
SLE = AV × EF single loss • one incident • one event Calculate dollar loss from one event. One van accident costs GGGP $5,000.
ALE = SLE × ARO annual loss • per year • expected yearly loss Calculate expected annual loss. $5,000 loss twice per year = $10,000 ALE.

Recovery Metrics

RTO

restore • downtime • recover system • maximum time
How long can it take to recover?
GGGP ticketing website must be back online within 8 hours.
Trap: SLA is the container; RTO is the metric inside it.

RPO

data loss • rollback • restore point • acceptable loss
How much data can be lost?
GGGP can lose at most 30 minutes of ticket sales.

MTTR

average repair time • historical metric • repair performance
Measure average time to repair after incidents.
GGGP website outages historically take 2.5 hours to repair.

AST

availability • uptime • agreed operating time • SLA
Define the agreed time a service should be available.
The host promises GGGP 99.9% uptime.

CIS Controls Cheat Sheet

CIS Control ISC Trigger Words Job GGGP Memory Aid
1. Enterprise Assetsasset inventory • hardware • devicesKnow what assets exist.GGGP lists every laptop, mixer, camera, and merch tablet.
2. Software Assetssoftware inventory • authorized software • unauthorized softwareKnow what software exists.GGGP tracks approved apps on tour laptops.
3. Data Protectionclassification • encryption • sensitive data • handlingProtect data based on sensitivity.GGGP encrypts fan email lists and payroll files.
4. Secure Configurationbaseline • hardening • default settings • configurationSet secure baseline configurations.Every GGGP laptop starts with the same secure setup.
5. Account Managementcreate account • disable account • lifecycle • accountsManage whether accounts exist.New volunteer gets an account; former volunteer is disabled.
6. Access Control Managementcredentials • privileges • permissions • authorization • least privilegeManage what accounts can access.Merch volunteer cannot access payroll or banking.
7. Vulnerability Managementscan • patch • vulnerabilities • remediationFind and fix weaknesses.GGGP scans its ticketing website weekly.
8. Audit Log Managementlogs • audit trail • monitoring • eventsRecord and review activity.GGGP reviews login logs after suspicious activity.
9. Email & Browser Protectionsemail • browser • phishing • web protectionProtect users from email/web threats.GGGP blocks dangerous links in emails.
10. Malware Defensesmalware • virus • ransomware • malicious code • antivirusPrevent and detect malicious code.GGGP installs antivirus on merch laptops.
11. Data Recoverybackup • restore • recovery • trusted stateRestore systems and data.GGGP restores accounting after ransomware.
12. Network Infrastructurerouters • switches • firewalls • network devicesManage network infrastructure securely.GGGP secures the venue Wi-Fi router.
13. Network Monitoring & DefenseIDS • IPS • monitor traffic • detect attacksMonitor and defend the network.GGGP watches for attacks on its website.
14. Security Awarenesstraining • phishing • awareness • workforceTrain people to reduce risk.GGGP teaches volunteers how to spot phishing.
15. Service Provider Managementvendors • third parties • CSPs • supplier riskManage third-party risk.GGGP reviews its online ticket vendor.
16. Application Software SecuritySDLC • secure coding • code review • application lifecycleBuild and maintain secure software.GGGP securely develops its ticketing site.
17. Incident Responseincident response • containment • response planPrepare for and respond to incidents.GGGP activates a response plan after a website hack.
18. Penetration Testingpen test • simulated attack • ethical hackingValidate defenses through testing.GGGP hires ethical hackers before launch.

Data Governance & Data Life Cycle

Capture

ETL • collect • import • acquire • active • passive
Bring data into the organization.
GGGP imports ticket sales from a vendor.

Synthesis

analyze • combine • summarize • insights
Turn data into information.
GGGP combines ticket and merch data to find profit by city.

Publication

share • distribute • report • dashboard
Share information.
GGGP publishes a monthly tour sales dashboard.

Purge

delete • archive • destroy • retention
Remove data after retention or legal need ends.
GGGP deletes expired customer records.

External Data Complexity

copyright • integrity • safety
Assess whether external data can be legally, safely, and reliably used.
GGGP checks whether a venue list is licensed, accurate, and safe to import.
Trap: format is handled later during data preparation.

Privacy Disclosure

cookies • disclosure • consent • promotions • transparency
Use data responsibly while still achieving business objectives.
GGGP tells fans it uses cookies and ticket history to recommend shows and merch.

Frameworks & Concepts

COSO Internal Control

internal control • operations • reporting • compliance • organization-wide
Provide consistent internal control across business areas.
GGGP creates controls for merch, cash, expenses, approvals, and reporting.

COSO ERM Performance

identify risk • assess risk • prioritize risk • respond
Evaluate and prioritize risks affecting objectives.
GGGP ranks tour risks: van breakdown, low sales, venue cancellation.

Data Model

conceptual • blueprint • high-level • relationships • design
Design how data relates before implementation.
GGGP sketches Customers → Orders → Products on a whiteboard.

Database Schema

implementation • tables • columns • constraints • database engine
Implement the design in a database.
GGGP creates SQL tables with primary keys and foreign keys.

Baseline Configuration

original state • benchmark • approved configuration • compare changes
Serve as approved reference point for changes.
GGGP saves website Version 1.0 before future updates.

ERP

integrated system • shared database • cross-department • exception handling
Integrate processes and speed exception handling.
A merch sale updates inventory, accounting, and management reports.

Quiz Mode

GGGP ISC Punk Rock CPA Study Deck. Private study page now; public punk CPA rescue mission later.

Proudly powered by Weebly
  • Home
  • About Me
  • Shows