CISSP asks for two vocabularies at once: the technical language of security engineering and the managerial language of risk, governance and continuity. A lot of exam questions are perfectly answerable — once you decode the acronyms they're wrapped in. This glossary is the decoder: 151 terms in plain English, organized by the domains they belong to, with study tips on the pairs people actually confuse.

It's written for CISSP candidates, and equally for technology executives who want a working cybersecurity vocabulary without a certification course. Educational reference only — see the note at the end of the page.

Browse the glossary

Study these terms with flashcards & exam-style practice questions →See the whole syllabus as a mind map →Track your chapter scores →

Risk, Governance & Continuity (30 terms)

ALEAnnualized Loss ExpectancyCore

Expected annual financial loss from a risk.

Study tip: ALE = SLE × ARO — memorize it; quantitative-risk questions are free marks.

AROAnnualized Rate of OccurrenceCore

Estimated number of times an event will occur in one year.

BCBusiness ContinuityCore

Maintaining essential business operations through a disruption.

BCPBusiness Continuity PlanCore

Documented approach for continuing critical business functions.

BIABusiness Impact AnalysisCore

Identifies critical business processes and evaluates the effect of disruption.

Study tip: The BIA comes first — its findings feed RTO, RPO and MTD.

CIAConfidentiality, Integrity, AvailabilityCore

The three classic objectives of information security.

Study tip: Practically every Domain 1 question maps back to one of these three.

COBITControl Objectives for Information and Related TechnologiesExtended

ISACA framework for governance and management of enterprise IT, built on six key principles for the governance system.

Study tip: Know the six principles by name — plausible security phrases like “maintaining authenticity and accountability” are NOT among them.

In depth — the steps that get tested
  • 1 Provide Stakeholder Value
  • 2 Holistic Approach
  • 3 Dynamic Governance System
  • 4 Governance Distinct from Management
  • 5 Tailored to Enterprise Needs
  • 6 End-to-End Governance System
DecompositionReduction Analysis (Decomposing the System)Extended

The threat-modeling step after modeling itself: breaking an application, system or environment down to understand its logic, internal components and external interactions — identifying five key concepts.

Study tip: The five concepts are structural. “Patch/update versions” and “open- vs closed-source” sound reasonable but are NOT decomposition components.

In depth — the steps that get tested
  • Trust boundaries — where the level of trust changes
  • Dataflow paths — how data moves between components
  • Input points — where external input enters the system
  • Privileged operations — actions requiring elevated rights
  • Details about security stance and approach — the declared security posture
DRDisaster RecoveryCore

Restoration of technology and services following a disruptive event.

Study tip: BC keeps the business running; DR restores the technology behind it.

DREADDamage, Reproducibility, Exploitability, Affected users, DiscoverabilityExtended

Threat-rating scheme that scores each identified threat by answering five questions: Damage, Reproducibility, Exploitability, Affected users, Discoverability.

Study tip: DREAD does not find threats — it RATES threats you have already found.

In depth — the steps that get tested
  • Damage — how bad is the impact?
  • Reproducibility — how reliably does the attack work?
  • Exploitability — how much effort/skill to launch?
  • Affected users — how many people are hit?
  • Discoverability — how easily is the flaw found?
DRPDisaster Recovery PlanCore

Documented procedures for restoring technology and services.

GDPRGeneral Data Protection RegulationCore

European Union data-protection and privacy regulation.

GRCGovernance, Risk and ComplianceExtended

Organizational management of governance requirements, risk and compliance obligations.

KPIKey Performance IndicatorExtended

Metric measuring performance against an objective.

KRIKey Risk IndicatorExtended

Metric indicating changing risk exposure.

Study tip: KPI looks at performance; KRI looks ahead at rising risk.

MTDMaximum Tolerable DowntimeCore

Longest period a business process can remain unavailable before unacceptable impact occurs.

Study tip: MTD caps RTO: the RTO you commit to must fit inside the MTD.

MTTFMean Time To FailureExtended

Expected operating time before a component fails.

MTTRMean Time To Repair (or Recover)Core

Average time required to restore a failed system or service.

Study tip: MTTF is time until failure; MTTR is time to fix it.

NISTNational Institute of Standards and TechnologyCore

US standards organization that publishes widely used cybersecurity frameworks and guidance.

PASTAProcess for Attack Simulation and Threat AnalysisExtended

Risk-centric threat-modeling methodology with seven stages — from business objectives through attack simulation to countermeasures weighted by the value of the assets protected.

Study tip: The exam phrase is “risk-centric / countermeasures in relation to asset value” — and know that it has SEVEN stages.

In depth — the steps that get tested
  • Stage 1 — Define Objectives (business & security goals)
  • Stage 2 — Define Technical Scope (attack surface)
  • Stage 3 — Application Decomposition (components, data flows, trust boundaries)
  • Stage 4 — Threat Analysis (intel-driven threat identification)
  • Stage 5 — Vulnerability & Weakness Analysis
  • Stage 6 — Attack Modeling & Simulation
  • Stage 7 — Risk & Impact Analysis (countermeasures weighted by asset value)
PCI DSSPayment Card Industry Data Security StandardExtended

Security standard protecting payment-card data.

RPORecovery Point ObjectiveCore

Maximum acceptable amount of data loss, measured in time.

Study tip: “How much data can we lose?” It sizes your backup frequency.

RTORecovery Time ObjectiveCore

Maximum target time for restoring a service after disruption.

Study tip: “How long can the service be down?” Pair it with RPO.

SABSASherwood Applied Business Security ArchitectureExtended

Business-driven framework for security architecture.

SCRMSupply Chain Risk ManagementExtended

Managing cybersecurity and operational risks introduced by suppliers, products and services.

SLAService Level AgreementCore

Agreement defining measurable service expectations.

SLESingle Loss ExpectancyCore

Expected monetary loss from one occurrence of a risk event.

Study tip: SLE = Asset Value × Exposure Factor.

SoDSeparation (Segregation) of DutiesCore

Dividing sensitive responsibilities among multiple people to reduce fraud and error risk.

Study tip: A classic control against fraud — often the answer when one person holds end-to-end power.

STRIDESpoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilegeCore

Microsoft's threat-categorization model: every identified threat is classified into one of the six S-T-R-I-D-E categories.

Study tip: The four threat-modeling names in one line: STRIDE categorizes, DREAD rates, PASTA runs a 7-stage risk-centric process, VAST scales threat modeling into Agile.

In depth — the steps that get tested
  • Spoofing — attacks authentication
  • Tampering — attacks integrity
  • Repudiation — attacks non-repudiation
  • Information disclosure — attacks confidentiality
  • Denial of service — attacks availability
  • Elevation of privilege — attacks authorization
VASTVisual, Agile and Simple ThreatExtended

Threat-modeling approach designed to integrate into Agile development pipelines and scale across an entire enterprise.

Study tip: “Agile” or “scalable” in the question stem points at VAST.

Remember this — Recovery & quantitative risk

  • RTO = how long can the service be unavailable?
  • RPO = how much data can be lost?
  • SLE = Asset Value × Exposure Factor
  • ALE = SLE × ARO

Data & Asset Security (8 terms)

CASBCloud Access Security BrokerExtended

Security policy and enforcement layer between cloud-service users and cloud providers.

DLPData Loss PreventionCore

Technologies and processes designed to detect and prevent unauthorized disclosure or movement of sensitive information.

Study tip: DLP asks: “can the data leave?” (NAC asks whether the device may enter.)

DRMDigital Rights ManagementExtended

Controls governing access to and use of protected digital content.

EOLEnd of LifeExtended

Point at which a product is no longer actively developed.

EOSEnd of SupportExtended

Point after which the vendor no longer provides normal support or security updates.

Study tip: EOL ends development; EOS ends patches — EOS is the security cliff.

FDEFull Disk EncryptionCore

Encryption protecting the contents of an entire storage device.

PHIProtected Health InformationCore

Individually identifiable health information subject to privacy and security protection.

PIIPersonally Identifiable InformationCore

Information that identifies, or can reasonably identify, an individual.

Cryptography (24 terms)

6 DsPhysical Security Control OrderExtended

The functional order in which physical security controls should engage an intruder: Deter → Deny → Detect → Delay → Determine → Decide.

Study tip: Order matters and is tested verbatim — deterrence comes first, decision comes last.

In depth — the steps that get tested
  • 1 Deter — discourage the attempt (signage, fencing, lighting)
  • 2 Deny — block access (locks, barriers)
  • 3 Detect — notice the intrusion (sensors, cameras)
  • 4 Delay — slow progress until response arrives
  • 5 Determine — assess what is happening
  • 6 Decide — choose and execute the response
AESAdvanced Encryption StandardCore

Widely used symmetric encryption algorithm suitable for fast bulk-data encryption.

Study tip: Symmetric = one shared key = fast bulk encryption.

CACertificate AuthorityCore

Trusted entity that issues and signs digital certificates.

Cable plantCable Plant ManagementExtended

Mapping and documenting a facility's physical network cabling infrastructure, from the entrance facility (demarcation point) through distribution to the endpoints.

Study tip: Know the five elements — person traps, fire escapes, UPSs and loading docks are NOT cable-plant elements.

In depth — the steps that get tested
  • Entrance facility — where the carrier enters (the demarcation point)
  • Equipment room — the main cross-connect and core gear
  • Backbone distribution system — links equipment room to telecom rooms between floors
  • Telecommunications room — per-floor connection point
  • Horizontal distribution system — telecom room out to the wall jacks
CPACritical Path AnalysisExtended

Systematic facility-design method that maps the relationships between mission-critical applications, processes and operations and ALL of their supporting elements — power, HVAC, communications, water.

Study tip: Facility-design context is the tell. Risk analysis evaluates threats × consequences; inventory just lists assets — neither maps dependencies.

CPTEDCrime Prevention Through Environmental DesignCore

Reducing crime by shaping the physical environment itself — first-generation CPTED rests on four core strategies: natural access control, natural surveillance, territorial control, and image/milieu.

Study tip: Know the four first-generation strategies; invented-sounding options (“natural training and enrichment”) are classic distractors.

In depth — the steps that get tested
  • Natural access control — entrances, fencing, bollards and lighting subtly steer movement
  • Natural surveillance — maximize visibility so offenders feel observable
  • Territorial control — make the space feel owned by an inclusive, caring community
  • Image and milieu — maintenance and surroundings that signal the area is cared for
CRLCertificate Revocation ListCore

Published list of certificates revoked before their expiration date.

Study tip: CRL = periodically downloaded list; OCSP = real-time status query.

CSRCertificate Signing RequestExtended

Request containing the information a CA needs to issue a certificate.

DHDiffie–HellmanCore

Cryptographic method allowing parties to establish shared key material over an untrusted network.

Study tip: Key agreement, not encryption — it establishes a shared secret.

DiDDefense in DepthCore

Multiple different controls arranged in series so that no single control's failure exposes the asset.

Study tip: Study materials cluster these terms with DiD: layering, classifications, zones, realms, compartments, silos, segmentations, lattice structure, protection rings.

ECCElliptic Curve CryptographyCore

Public-key cryptography based on elliptic curves, providing strong security with comparatively small keys.

Study tip: Same strength, smaller keys — think mobile and IoT.

ECDHElliptic Curve Diffie–HellmanExtended

Diffie–Hellman key agreement implemented using elliptic-curve cryptography.

HMACHash-based Message Authentication CodeCore

Uses a cryptographic hash plus a secret key to provide message integrity and authenticity.

Study tip: SHA proves integrity; adding the key (HMAC) also proves who sent it.

HSMHardware Security ModuleCore

Dedicated secure hardware for generating, protecting and using cryptographic keys.

MITMMan-in-the-MiddleCore

Attack in which an adversary intercepts and potentially alters communications between parties.

OCSPOnline Certificate Status ProtocolCore

Protocol used to check whether a certificate has been revoked.

PFSPerfect Forward SecrecyExtended

Session-key design ensuring compromise of long-term keys does not expose previously encrypted sessions.

Study tip: Ephemeral session keys: yesterday's traffic stays safe even if today's private key leaks.

PKIPublic Key InfrastructureCore

Technologies, policies and processes used to manage public/private keys and digital certificates.

RARegistration AuthorityExtended

Entity that verifies identities before certificate issuance.

Study tip: RA verifies; CA signs. The RA never issues certificates itself.

RingsProtection Ring ModelExtended

Layered CPU/OS privilege model: Ring 0 = kernel (most privileged), Rings 1–2 = OS services and drivers, Ring 3 = user applications; inner rings control outer ones.

Study tip: Ring 0 vs Ring 3 is the tested pair — and “protection rings” also appears in the defense-in-depth term cluster.

In depth — the steps that get tested
  • Ring 0 — kernel: most privileged
  • Rings 1–2 — OS services and device drivers
  • Ring 3 — user applications: least privileged
  • Inner rings service and control outer rings
RSARivest–Shamir–AdlemanCore

Asymmetric cryptographic algorithm used for operations including digital signatures and key-related functions.

Study tip: Asymmetric = key pairs = signatures and key exchange, not bulk data.

SHASecure Hash AlgorithmCore

Family of cryptographic hash functions used to create fixed-length message digests.

Study tip: Hashing = integrity. One-way; no key; any change alters the digest.

SprinklersWater-Based Fire Suppression SystemsCore

Four types: wet pipe (water always charged), dry pipe (air-filled until triggered), preaction (two-stage trigger — best for computer facilities), and deluge (open heads, high volume).

Study tip: Preaction is the answer for computer rooms: the second trigger prevents accidental water release. Wet, dry and deluge all release on a single trigger.

In depth — the steps that get tested
  • Wet pipe — pipes always charged with water; simplest, riskiest near electronics
  • Dry pipe — pipes hold pressurized air until a head opens; suits freezing areas
  • Preaction — TWO triggers (detector fills pipes, then head releases); computer facilities
  • Deluge — open heads flood the area with large volumes; not for electronics
TPMTrusted Platform ModuleCore

Hardware security component used to protect cryptographic keys and support platform integrity.

Study tip: TPM is built into a platform; an HSM is dedicated key hardware.

Remember this — Encryption

  • AES = symmetric = fast bulk encryption
  • RSA / ECC = asymmetric = keys, signatures, public-key use
  • SHA = hashing = integrity

Communication & Network Security (35 terms)

APIPAAutomatic Private IP AddressingExtended

Self-assigned 169.254.0.0/16 link-local address a host takes when no DHCP server responds.

Study tip: A 169.254 address on a client means “DHCP failed” — and it is not part of RFC 1918.

ARPAddress Resolution ProtocolCore

Resolves IP addresses to MAC addresses on a LAN. ARP poisoning corrupts those mappings — often via unsolicited (gratuitous) replies — to redirect or intercept traffic.

Study tip: Three different layer-2 attacks: ARP poisoning falsifies IP→MAC mappings; MAC spoofing falsifies a device's own hardware address; MAC flooding overloads a switch's CAM table.

CCMPCounter Mode with CBC-MAC ProtocolExtended

The AES-based encryption protocol of WPA2 — counter-mode encryption plus CBC-MAC integrity — replacing WEP and TKIP's weaknesses.

Study tip: Wireless lineage in order: WEP → TKIP (WPA) → CCMP/AES (WPA2) → SAE handshake (WPA3).

CDNContent Delivery NetworkExtended

Geographically distributed service hosts that replicate and serve content close to users for low latency, high performance and high availability.

Study tip: “Replicas in many data centers worldwide” = CDN — not VPN (tunnels), SDN (control-plane separation) or CCMP (wireless encryption).

CHAPChallenge Handshake Authentication ProtocolCore

PPP authentication where the password never crosses the wire: the client answers a random server challenge with a hash computed from it.

Study tip: PAP = plaintext, CHAP = challenge/response, EAP = extensible framework — the three PPP options in one line.

DHCPDynamic Host Configuration ProtocolExtended

Automatically supplies network configuration to clients.

DMZDemilitarized Zone (Screened Subnet)Core

Buffer zone positioned between the private network and the internet that hosts publicly accessible services without exposing the internal LAN.

Study tip: Screened subnet = DMZ. The intranet is the private network itself, an extranet serves selected partners only, and a honeypot is a trap — none of them buffer public services.

DNSDomain Name SystemCore

Resolves human-readable domain names to network information such as IP addresses.

DNSSECDomain Name System Security ExtensionsExtended

Adds origin authentication and integrity protection to DNS data.

Study tip: DNSSEC signs DNS data — it proves authenticity, not confidentiality.

EAPExtensible Authentication ProtocolCore

Authentication FRAMEWORK (one of PPP's three options, alongside PAP and CHAP) that supports 40+ pluggable methods rather than one fixed mechanism.

Study tip: Real methods include LEAP, PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM, EAP-MD5, EAP-POTP. Invented names like “EAP-VPN” are standard distractors.

In depth — the steps that get tested
  • Real methods: LEAP, PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM, EAP-MD5, EAP-POTP
  • More than 40 methods are defined — EAP is a framework, not one protocol
  • Fakes that appear as distractors: EAP-VPN, EAP-MBL, VEAP
IDPSIntrusion Detection and Prevention SystemExtended

Combined intrusion detection and prevention capability.

IDSIntrusion Detection SystemCore

Detects suspicious or malicious activity.

Study tip: IDS detects and alerts; IPS sits inline and can block.

IPSIntrusion Prevention SystemCore

Detects suspicious activity and can actively block it.

IPSecInternet Protocol SecurityCore

Suite of protocols for protecting IP communications.

ISFWInternal Segmentation FirewallExtended

Firewall deployed INSIDE the network to filter traffic between internal zones — the enforcement device behind segmentation and microsegmentation.

Study tip: Perimeter firewalls face the internet; ISFWs face east-west traffic between internal zones (even down to a single high-value host).

MAC spoofingMAC Address SpoofingExtended

Falsifying a device's hardware (MAC) address to impersonate an authorized device — e.g. to bypass port security or MAC filtering.

Study tip: Spoofing impersonates, flooding overloads switch memory, ARP poisoning corrupts neighbours' mappings.

NACNetwork Access ControlCore

Controls whether users and devices are permitted to connect to a network.

Study tip: NAC asks: “may the device enter?” (DLP asks whether the data may leave.)

NGFWNext-Generation FirewallExtended

Firewall integrating traditional filtering with application awareness, IPS, TLS inspection and other services in one device — often described as unified threat management (UTM).

Study tip: “UTM” in a stem points at NGFW. It guards the network path; EDR guards the endpoint.

NTPNetwork Time ProtocolExtended

Synchronizes system clocks across a network — a dependency for Kerberos authentication and for correlating logs during investigations.

Study tip: Mysterious Kerberos logon failures on some hosts = check clock drift first (tolerance is about five minutes).

OSIOpen Systems InterconnectionCore

Seven-layer conceptual networking model — 1 Physical, 2 Data Link, 3 Network, 4 Transport, 5 Session, 6 Presentation, 7 Application.

Study tip: Know the seven layers in order (“Please Do Not Throw Sausage Pizza Away”) and which protocols and devices live at each.

In depth — the steps that get tested
  • Layer 1 Physical — cables, signals, hubs
  • Layer 2 Data Link — frames, MAC addresses, switches
  • Layer 3 Network — packets, IP, routers
  • Layer 4 Transport — TCP/UDP, ports, segmentation
  • Layer 5 Session — dialog establishment and teardown
  • Layer 6 Presentation — formats, compression, encryption
  • Layer 7 Application — HTTP, DNS, SMTP and friends
PAPPassword Authentication ProtocolCore

PPP authentication that transmits usernames and passwords in cleartext — no encryption or protection of logon credentials at all.

Study tip: “No protection for credentials” = PAP, full stop. RADIUS is a AAA service, not the naked protocol.

PVCPermanent Virtual CircuitExtended

A logical circuit that always exists and waits for the customer to send data — versus an SVC (switched virtual circuit), built per session and torn down afterwards.

Study tip: “Always exists, waiting for data” = PVC; “created each time it's needed” = SVC. Think dedicated leased line vs dial-up, virtualized.

QoSQuality of ServiceExtended

Mechanisms for managing network performance and traffic priority.

RFC 1918Private IPv4 Address RangesCore

The three private, non-routable IPv4 blocks: 10.0.0.0/8, 172.16.0.0/12 (through 172.31.255.255), and 192.168.0.0/16.

Study tip: The 172.16–172.31 boundary is the tested detail. 169.254.x.x is APIPA link-local — NOT an RFC 1918 range.

In depth — the steps that get tested
  • 10.0.0.0 – 10.255.255.255 (10.0.0.0/8)
  • 172.16.0.0 – 172.31.255.255 (172.16.0.0/12)
  • 192.168.0.0 – 192.168.255.255 (192.168.0.0/16)
  • NOT private: 169.254.x.x — that's APIPA link-local
SASESecure Access Service EdgeExtended

Cloud-delivered architecture combining networking and security capabilities.

SDNSoftware Defined NetworkingExtended

Network architecture separating centralized software-based control from packet forwarding.

Study tip: Control plane and data plane are split — the controller is the crown jewel to protect. Access control inside SDNs is commonly ABAC (attribute-based).

SNMPSimple Network Management ProtocolExtended

Protocol for monitoring and managing network devices.

Study tip: Only SNMPv3 adds real security (authentication and encryption).

SSHSecure ShellCore

Secure protocol for remote system administration and related functions.

SSLSecure Sockets LayerCore

Older predecessor to TLS; obsolete versions should not be treated as secure.

Study tip: If an answer offers SSL as the “secure” choice, be suspicious — TLS replaced it.

TCP/IPTransmission Control Protocol / Internet ProtocolCore

Core protocol suite underlying IP networks and the Internet; its four-layer model is Link, Internet, Transport, Application.

Study tip: Mapping to OSI: Link ≈ 1–2, Internet ≈ 3, Transport ≈ 4, Application ≈ 5–7.

In depth — the steps that get tested
  • Link — OSI layers 1–2
  • Internet — OSI layer 3 (IP)
  • Transport — OSI layer 4 (TCP/UDP)
  • Application — OSI layers 5–7
TLSTransport Layer SecurityCore

Cryptographic protocol protecting data in transit.

VLANVirtual Local Area NetworkCore

Logical separation of network devices into distinct broadcast domains.

VPNVirtual Private NetworkCore

Protected logical connection across an untrusted network.

WAFWeb Application FirewallCore

Filters and protects HTTP/HTTPS traffic to web applications.

ZigbeeZigbee (IEEE 802.15.4)Extended

Low-power, short-range IoT communications protocol for sensors and hubs, encrypted with a 128-bit symmetric key.

Study tip: Tells: IoT sensor, metres of range, low power, encryption built in — where plain Bluetooth would be unencrypted.

Remember this — Network vs. Data

  • NAC = can the device enter?
  • DLP = can the data leave?

Identity & Access Management (20 terms)

AAAAuthentication, Authorization and AccountingCore

Determines who a subject is, what it may do, and records relevant activity.

ABACAttribute-Based Access ControlCore

Makes authorization decisions using attributes of users, resources and context.

DACDiscretionary Access ControlCore

Allows resource owners to decide who receives access.

Study tip: Owner decides = DAC; labels and clearances decide = MAC.

FIMFederated Identity ManagementExtended

Trust arrangement allowing identities to be recognized across security domains — users sign in with their EXISTING (normal) account credentials.

Study tip: In federation questions, the login ID stays the user's normal account; SSO is the resulting capability, not a kind of account.

IAMIdentity and Access ManagementCore

Processes and technologies controlling identities and their access to resources.

JITJust-In-Time AccessExtended

Provides elevated access temporarily, only when required.

KerberosKerberos Authentication ProtocolCore

Ticket-based network authentication: a Key Distribution Center issues ticket-granting tickets and service tickets, using AES symmetric cryptography.

Study tip: Two exam hooks: clocks must agree within ~5 minutes (drift = logon failures, fix with NTP), and compromising the KRBTGT account lets attackers forge golden tickets.

In depth — the steps that get tested
  • KDC — Key Distribution Center (authentication + ticket-granting services)
  • TGT — ticket-granting ticket, obtained at logon
  • Service tickets — presented to each resource
  • Symmetric crypto (AES); passwords never cross the network
  • Clock tolerance ~5 minutes — drift breaks authentication (fix: NTP)
  • KRBTGT account compromise → forged golden tickets
LDAPLightweight Directory Access ProtocolCore

Protocol used to access and manage directory services.

MACMandatory Access ControlCore

Centrally enforced access decisions based on classifications and labels. Supports three environment types: hierarchical, compartmentalized, and hybrid.

Study tip: Context matters: MAC can also mean Media Access Control or Message Authentication Code on the exam.

In depth — the steps that get tested
  • Hierarchical environment — ordered labels low → high (each level relates to the ones above/below)
  • Compartmentalized environment — isolated compartments, no ordering between them
  • Hybrid environment — hierarchical levels containing compartments
  • These three are the ONLY MAC environments — 'bracketed' and 'centralized' are invented distractors
MFAMulti-Factor AuthenticationCore

Authentication requiring factors from more than one factor category.

Study tip: Two passwords is not MFA — factors must come from different categories.

OAuthOpen AuthorizationCore

Framework for delegated authorization allowing applications limited access to resources without sharing a user's password.

Study tip: OAuth = authorization (what an app may do), not authentication.

OIDCOpenID ConnectCore

Identity and authentication layer built on OAuth 2.0, carrying identity claims in JSON Web Tokens (JWTs).

Study tip: Token format is a tell: JSON Web Tokens = OIDC; XML assertions = SAML. OIDC adds the “who are you?” answer on top of OAuth.

PAMPrivileged Access ManagementCore

Controls and monitors highly privileged accounts and credentials.

PtHPass the HashExtended

Reusing a captured NTLM credential hash to authenticate to remote systems without ever knowing the password.

Study tip: Match attack to system: pass the hash = NTLM; pass the ticket and golden ticket = Kerberos; rainbow tables = offline password cracking.

In depth — the steps that get tested
  • Pass the hash — reuse an NTLM hash without knowing the password
  • Pass the ticket — reuse a captured Kerberos ticket
  • Golden ticket — forge TGTs after compromising KRBTGT (Kerberos)
  • Rainbow table — offline cracking with precomputed hash tables
RADIUSRemote Authentication Dial-In User ServiceCore

AAA protocol widely used for network-access authentication.

Study tip: RADIUS for network access; TACACS+ (separate AAA, fully encrypted payload) for device administration.

RBACRole-Based Access ControlCore

Assigns permissions according to organizational roles.

Study tip: Roles decide (RBAC); attributes and context decide (ABAC).

SAMLSecurity Assertion Markup LanguageCore

XML-based standard commonly used for federated identity and browser-based enterprise SSO.

Study tip: SAML = enterprise federation and browser SSO.

SCIMSystem for Cross-domain Identity ManagementExtended

Standard for automating identity provisioning and deprovisioning.

SSOSingle Sign-OnCore

Allows one authentication event to provide access to multiple related systems.

TACACS+Terminal Access Controller Access-Control System PlusCore

AAA protocol frequently used for administrative access to network equipment.

Remember this — Federation

  • OAuth = authorization
  • OIDC = authentication / identity on OAuth
  • SAML = enterprise federation / browser SSO

Security Assessment & Testing (11 terms)

CVECommon Vulnerabilities and ExposuresCore

Standard identifier assigned to publicly disclosed vulnerabilities.

CVSSCommon Vulnerability Scoring SystemCore

Framework for expressing vulnerability severity.

CWECommon Weakness EnumerationExtended

Catalog of common software and hardware weakness types.

Study tip: CVE names a specific vulnerability; CWE names the general weakness type behind it.

DASTDynamic Application Security TestingCore

Tests a running application externally.

Study tip: Dynamic = attack the running app from outside. Black-box.

IASTInteractive Application Security TestingExtended

Analyzes application behavior from within, via instrumentation, while the application executes.

PTPenetration TestCore

Authorized attempt to exploit vulnerabilities to demonstrate practical impact.

RASPRuntime Application Self-ProtectionExtended

Application-integrated protection operating while software runs.

SASTStatic Application Security TestingCore

Analyzes source or compiled code without executing the application.

Study tip: Static = code at rest. White-box, early in the pipeline.

SBOMSoftware Bill of MaterialsExtended

Structured inventory of components contained in a software product.

SCASoftware Composition AnalysisExtended

Identifies third-party and open-source components and associated vulnerabilities or licensing concerns.

Study tip: SCA inspects your dependencies, not your own code.

VAVulnerability AssessmentCore

Process of identifying and evaluating security weaknesses.

Study tip: VA finds weaknesses; a penetration test exploits them to show impact.

Remember this — Application testing

  • SAST = analyze code without executing it
  • DAST = attack / test the running application
  • SCA = inspect dependencies and components
  • IAST = analyze from inside while the app executes

Security Operations (11 terms)

CSIRTComputer Security Incident Response TeamCore

Team responsible for coordinating response to cybersecurity incidents.

EDREndpoint Detection and ResponseCore

Endpoint-focused monitoring, detection, investigation and response — the evolution of traditional antivirus, often reporting events to a central or cloud ML analysis engine.

Study tip: Scenario tells: “evolution of antivirus”, “beyond AV/HIDS”, central ML analysis, endpoint focus. NGFW is a network device, WAF filters web traffic, and XSRF is an attack, not a control. (EDR = endpoints; NDR = network; XDR = correlated across layers.)

HAHigh AvailabilityExtended

Architecture intended to minimize service outages and increase resilience.

IOCIndicator of CompromiseCore

Observable artifact or behavior suggesting possible compromise.

Study tip: IOC = the artifact left behind; TTP = the adversary's behavior pattern.

IRIncident ResponseCore

Structured process for managing cybersecurity incidents.

Study tip: Know the lifecycle IN ORDER: Detection/Analysis → Containment → Eradication → Recovery → Lessons Learned.

In depth — the steps that get tested
  • 1 Detection / Analysis — recognize and triage the incident
  • 2 Containment — stop the spread before deeper action
  • 3 Eradication / Remediation — remove the adversary and artifacts
  • 4 Recovery — restore systems and service
  • 5 Lessons Learned — feed improvements back into controls
NDRNetwork Detection and ResponseExtended

Detection and investigation based primarily on network telemetry.

SIEMSecurity Information and Event ManagementCore

Aggregates and correlates logs and security events for monitoring and investigation.

Study tip: SIEM gives visibility; SOAR automates the response on top of it.

SOARSecurity Orchestration, Automation and ResponseExtended

Automates and coordinates security-analysis and response workflows.

TTPTactics, Techniques and ProceduresCore

Patterns describing how adversaries pursue goals and conduct attacks.

UEBAUser and Entity Behavior AnalyticsExtended

Uses behavior patterns to detect anomalous or risky activity involving users and other entities.

XDRExtended Detection and ResponseExtended

Correlates security telemetry and response across multiple security layers.

Remember this — Incident response lifecycle

Detection / AnalysisContainmentEradicationRecoveryLessons Learned

Software & Cloud Security (12 terms)

APIApplication Programming InterfaceExtended

Defined interface enabling software systems to communicate.

CI/CDContinuous Integration / Continuous Delivery (Deployment)Core

Automated practices for integrating, testing and releasing software.

COTSCommercial Off-The-ShelfExtended

Commercially produced software acquired rather than custom developed.

CSPCloud Service ProviderExtended

Organization providing cloud computing services.

IaaSInfrastructure as a ServiceCore

Cloud model providing computing infrastructure while customers manage the higher software layers.

Study tip: Responsibility shifts to the provider as you move IaaS → PaaS → SaaS.

OWASPOpen Worldwide Application Security ProjectCore

Nonprofit community producing widely used application-security guidance and tools.

PaaSPlatform as a ServiceCore

Cloud model providing infrastructure plus a managed application platform and runtime.

SaaSSoftware as a ServiceCore

Cloud model delivering a complete managed application.

SDLCSoftware Development Life CycleCore

Processes through which software is planned, designed, built, tested, operated and retired.

Study tip: Phases in order: requirements → design → implementation → testing → deployment/operations → retirement.

In depth — the steps that get tested
  • Requirements — what must it do (start security HERE)
  • Design — architecture and threat modeling
  • Implementation — secure coding
  • Testing — SAST/DAST, reviews, UAT
  • Deployment / Operations — hardening, monitoring, patching
  • Retirement — secure decommissioning and data disposal
SSDLCSecure Software Development Life CycleCore

SDLC in which security activities and controls are intentionally integrated.

Study tip: Security built in, not bolted on — the recurring exam theme.

SW-CMMSoftware Capability Maturity ModelExtended

Five-level software-process maturity model: 1 Initial → 2 Repeatable → 3 Defined → 4 Managed (quantitatively measured) → 5 Optimizing.

Study tip: Know the five levels in order; the trap is Defined (documented org-wide) vs Managed (measured).

In depth — the steps that get tested
  • Level 1 Initial — ad hoc, heroics
  • Level 2 Repeatable — basic project management discipline
  • Level 3 Defined — processes documented organization-wide
  • Level 4 Managed — processes quantitatively measured
  • Level 5 Optimizing — continuous process improvement
XSRFCross-Site Request Forgery (CSRF)Extended

Web attack that tricks an authenticated user's browser into sending unwanted, legitimate-looking requests to a site where the victim is already logged in.

Study tip: Also written CSRF. It is an ATTACK — when a question asks you to pick a defensive control, XSRF is always the distractor.

Further study

The authoritative statement of what the exam covers is the official ISC2 CISSP Certification Exam Outline. Definitions in this glossary are independently written summaries — use the outline to weight your study time across domains.

Independent CISSP study aid. CISSP is a registered trademark of ISC2. This resource is not affiliated with or endorsed by ISC2.