Certification study notes, exam preparation, roadmaps, and reference material for security and AI-security credentials. This repository is a working study resource — condensed notes written to be understood, not memorized. Each topic is deconstructed to the underlying logic so the reasoning behind a control or concept is visible, not just the definition.
| Certification | Status | Target Domain |
|---|---|---|
| CompTIA Security+ (SY0-701) | Holder | Core security fundamentals |
| CompTIA SecAI+ (CY0-001) | In Progress | AI security, model risk, adversarial ML |
| AWS Certified AI Practitioner (AIF-C01) | In Progress | Cloud AI/ML foundations |
| ISO 27001 Lead Auditor | Planned | ISMS audit and governance |
| CISSP | Planned | Security architecture and management |
Status legend: Holder — credential earned. In Progress — actively studying. Planned — sequenced on the roadmap.
| Folder | Coverage |
|---|---|
| comptia/ | CompTIA Security+ (SY0-701) domain breakdown and study notes |
| soc2/ | SOC 2 Trust Services Criteria, Type I vs Type II, control evidence |
| iso27001/ | ISO/IEC 27001:2022 structure, Annex A controls, ISMS concepts |
| hipaa/ | HIPAA Security Rule safeguards, Privacy Rule, breach notification |
| learning-roadmap.md | Phased study plan across the certification track |
| notes-template.md | Reusable template for capturing study notes |
Each set of notes follows the same principle: start from the smallest causal unit and build up. A control is never presented as a rule to memorize — it is presented as an answer to a question. Why does this exist? What failure does it prevent? What would go wrong without it? When the logic is visible, recall follows naturally because the material is understood rather than stored.
Part of the SwooshJ-SecAI security and AI engineering portfolio.