CISSP asks for two vocabularies at once: the technical language of security engineering and the managerial language of risk, governance and continuity. A lot of exam questions are perfectly answerable — once you decode the acronyms they're wrapped in. This glossary is the decoder: 151 terms in plain English, organized by the domains they belong to, with study tips on the pairs people actually confuse.
It's written for CISSP candidates, and equally for technology executives who want a working cybersecurity vocabulary without a certification course. Educational reference only — see the note at the end of the page.
Browse the glossary
Study these terms with flashcards & exam-style practice questions →See the whole syllabus as a mind map →Track your chapter scores →
Risk, Governance & Continuity (30 terms)
Expected annual financial loss from a risk.
Study tip: ALE = SLE × ARO — memorize it; quantitative-risk questions are free marks.
Estimated number of times an event will occur in one year.
Maintaining essential business operations through a disruption.
Documented approach for continuing critical business functions.
Identifies critical business processes and evaluates the effect of disruption.
Study tip: The BIA comes first — its findings feed RTO, RPO and MTD.
The three classic objectives of information security.
Study tip: Practically every Domain 1 question maps back to one of these three.
ISACA framework for governance and management of enterprise IT, built on six key principles for the governance system.
Study tip: Know the six principles by name — plausible security phrases like “maintaining authenticity and accountability” are NOT among them.
In depth — the steps that get tested
- 1 Provide Stakeholder Value
- 2 Holistic Approach
- 3 Dynamic Governance System
- 4 Governance Distinct from Management
- 5 Tailored to Enterprise Needs
- 6 End-to-End Governance System
The threat-modeling step after modeling itself: breaking an application, system or environment down to understand its logic, internal components and external interactions — identifying five key concepts.
Study tip: The five concepts are structural. “Patch/update versions” and “open- vs closed-source” sound reasonable but are NOT decomposition components.
In depth — the steps that get tested
- Trust boundaries — where the level of trust changes
- Dataflow paths — how data moves between components
- Input points — where external input enters the system
- Privileged operations — actions requiring elevated rights
- Details about security stance and approach — the declared security posture
Restoration of technology and services following a disruptive event.
Study tip: BC keeps the business running; DR restores the technology behind it.
Threat-rating scheme that scores each identified threat by answering five questions: Damage, Reproducibility, Exploitability, Affected users, Discoverability.
Study tip: DREAD does not find threats — it RATES threats you have already found.
In depth — the steps that get tested
- Damage — how bad is the impact?
- Reproducibility — how reliably does the attack work?
- Exploitability — how much effort/skill to launch?
- Affected users — how many people are hit?
- Discoverability — how easily is the flaw found?
Documented procedures for restoring technology and services.
European Union data-protection and privacy regulation.
Organizational management of governance requirements, risk and compliance obligations.
Metric measuring performance against an objective.
Metric indicating changing risk exposure.
Study tip: KPI looks at performance; KRI looks ahead at rising risk.
Longest period a business process can remain unavailable before unacceptable impact occurs.
Study tip: MTD caps RTO: the RTO you commit to must fit inside the MTD.
Expected operating time before a component fails.
Average time required to restore a failed system or service.
Study tip: MTTF is time until failure; MTTR is time to fix it.
US standards organization that publishes widely used cybersecurity frameworks and guidance.
Risk-centric threat-modeling methodology with seven stages — from business objectives through attack simulation to countermeasures weighted by the value of the assets protected.
Study tip: The exam phrase is “risk-centric / countermeasures in relation to asset value” — and know that it has SEVEN stages.
In depth — the steps that get tested
- Stage 1 — Define Objectives (business & security goals)
- Stage 2 — Define Technical Scope (attack surface)
- Stage 3 — Application Decomposition (components, data flows, trust boundaries)
- Stage 4 — Threat Analysis (intel-driven threat identification)
- Stage 5 — Vulnerability & Weakness Analysis
- Stage 6 — Attack Modeling & Simulation
- Stage 7 — Risk & Impact Analysis (countermeasures weighted by asset value)
Security standard protecting payment-card data.
Maximum acceptable amount of data loss, measured in time.
Study tip: “How much data can we lose?” It sizes your backup frequency.
Maximum target time for restoring a service after disruption.
Study tip: “How long can the service be down?” Pair it with RPO.
Business-driven framework for security architecture.
Managing cybersecurity and operational risks introduced by suppliers, products and services.
Agreement defining measurable service expectations.
Expected monetary loss from one occurrence of a risk event.
Study tip: SLE = Asset Value × Exposure Factor.
Dividing sensitive responsibilities among multiple people to reduce fraud and error risk.
Study tip: A classic control against fraud — often the answer when one person holds end-to-end power.
Microsoft's threat-categorization model: every identified threat is classified into one of the six S-T-R-I-D-E categories.
Study tip: The four threat-modeling names in one line: STRIDE categorizes, DREAD rates, PASTA runs a 7-stage risk-centric process, VAST scales threat modeling into Agile.
In depth — the steps that get tested
- Spoofing — attacks authentication
- Tampering — attacks integrity
- Repudiation — attacks non-repudiation
- Information disclosure — attacks confidentiality
- Denial of service — attacks availability
- Elevation of privilege — attacks authorization
Threat-modeling approach designed to integrate into Agile development pipelines and scale across an entire enterprise.
Study tip: “Agile” or “scalable” in the question stem points at VAST.
Remember this — Recovery & quantitative risk
- RTO = how long can the service be unavailable?
- RPO = how much data can be lost?
- SLE = Asset Value × Exposure Factor
- ALE = SLE × ARO
Data & Asset Security (8 terms)
Security policy and enforcement layer between cloud-service users and cloud providers.
Technologies and processes designed to detect and prevent unauthorized disclosure or movement of sensitive information.
Study tip: DLP asks: “can the data leave?” (NAC asks whether the device may enter.)
Controls governing access to and use of protected digital content.
Point at which a product is no longer actively developed.
Point after which the vendor no longer provides normal support or security updates.
Study tip: EOL ends development; EOS ends patches — EOS is the security cliff.
Encryption protecting the contents of an entire storage device.
Individually identifiable health information subject to privacy and security protection.
Information that identifies, or can reasonably identify, an individual.
Cryptography (24 terms)
The functional order in which physical security controls should engage an intruder: Deter → Deny → Detect → Delay → Determine → Decide.
Study tip: Order matters and is tested verbatim — deterrence comes first, decision comes last.
In depth — the steps that get tested
- 1 Deter — discourage the attempt (signage, fencing, lighting)
- 2 Deny — block access (locks, barriers)
- 3 Detect — notice the intrusion (sensors, cameras)
- 4 Delay — slow progress until response arrives
- 5 Determine — assess what is happening
- 6 Decide — choose and execute the response
Widely used symmetric encryption algorithm suitable for fast bulk-data encryption.
Study tip: Symmetric = one shared key = fast bulk encryption.
Trusted entity that issues and signs digital certificates.
Mapping and documenting a facility's physical network cabling infrastructure, from the entrance facility (demarcation point) through distribution to the endpoints.
Study tip: Know the five elements — person traps, fire escapes, UPSs and loading docks are NOT cable-plant elements.
In depth — the steps that get tested
- Entrance facility — where the carrier enters (the demarcation point)
- Equipment room — the main cross-connect and core gear
- Backbone distribution system — links equipment room to telecom rooms between floors
- Telecommunications room — per-floor connection point
- Horizontal distribution system — telecom room out to the wall jacks
Systematic facility-design method that maps the relationships between mission-critical applications, processes and operations and ALL of their supporting elements — power, HVAC, communications, water.
Study tip: Facility-design context is the tell. Risk analysis evaluates threats × consequences; inventory just lists assets — neither maps dependencies.
Reducing crime by shaping the physical environment itself — first-generation CPTED rests on four core strategies: natural access control, natural surveillance, territorial control, and image/milieu.
Study tip: Know the four first-generation strategies; invented-sounding options (“natural training and enrichment”) are classic distractors.
In depth — the steps that get tested
- Natural access control — entrances, fencing, bollards and lighting subtly steer movement
- Natural surveillance — maximize visibility so offenders feel observable
- Territorial control — make the space feel owned by an inclusive, caring community
- Image and milieu — maintenance and surroundings that signal the area is cared for
Published list of certificates revoked before their expiration date.
Study tip: CRL = periodically downloaded list; OCSP = real-time status query.
Request containing the information a CA needs to issue a certificate.
Cryptographic method allowing parties to establish shared key material over an untrusted network.
Study tip: Key agreement, not encryption — it establishes a shared secret.
Multiple different controls arranged in series so that no single control's failure exposes the asset.
Study tip: Study materials cluster these terms with DiD: layering, classifications, zones, realms, compartments, silos, segmentations, lattice structure, protection rings.
Public-key cryptography based on elliptic curves, providing strong security with comparatively small keys.
Study tip: Same strength, smaller keys — think mobile and IoT.
Diffie–Hellman key agreement implemented using elliptic-curve cryptography.
Uses a cryptographic hash plus a secret key to provide message integrity and authenticity.
Study tip: SHA proves integrity; adding the key (HMAC) also proves who sent it.
Dedicated secure hardware for generating, protecting and using cryptographic keys.
Attack in which an adversary intercepts and potentially alters communications between parties.
Protocol used to check whether a certificate has been revoked.
Session-key design ensuring compromise of long-term keys does not expose previously encrypted sessions.
Study tip: Ephemeral session keys: yesterday's traffic stays safe even if today's private key leaks.
Technologies, policies and processes used to manage public/private keys and digital certificates.
Entity that verifies identities before certificate issuance.
Study tip: RA verifies; CA signs. The RA never issues certificates itself.
Layered CPU/OS privilege model: Ring 0 = kernel (most privileged), Rings 1–2 = OS services and drivers, Ring 3 = user applications; inner rings control outer ones.
Study tip: Ring 0 vs Ring 3 is the tested pair — and “protection rings” also appears in the defense-in-depth term cluster.
In depth — the steps that get tested
- Ring 0 — kernel: most privileged
- Rings 1–2 — OS services and device drivers
- Ring 3 — user applications: least privileged
- Inner rings service and control outer rings
Asymmetric cryptographic algorithm used for operations including digital signatures and key-related functions.
Study tip: Asymmetric = key pairs = signatures and key exchange, not bulk data.
Family of cryptographic hash functions used to create fixed-length message digests.
Study tip: Hashing = integrity. One-way; no key; any change alters the digest.
Four types: wet pipe (water always charged), dry pipe (air-filled until triggered), preaction (two-stage trigger — best for computer facilities), and deluge (open heads, high volume).
Study tip: Preaction is the answer for computer rooms: the second trigger prevents accidental water release. Wet, dry and deluge all release on a single trigger.
In depth — the steps that get tested
- Wet pipe — pipes always charged with water; simplest, riskiest near electronics
- Dry pipe — pipes hold pressurized air until a head opens; suits freezing areas
- Preaction — TWO triggers (detector fills pipes, then head releases); computer facilities
- Deluge — open heads flood the area with large volumes; not for electronics
Hardware security component used to protect cryptographic keys and support platform integrity.
Study tip: TPM is built into a platform; an HSM is dedicated key hardware.
Remember this — Encryption
- AES = symmetric = fast bulk encryption
- RSA / ECC = asymmetric = keys, signatures, public-key use
- SHA = hashing = integrity
Communication & Network Security (35 terms)
Self-assigned 169.254.0.0/16 link-local address a host takes when no DHCP server responds.
Study tip: A 169.254 address on a client means “DHCP failed” — and it is not part of RFC 1918.
Resolves IP addresses to MAC addresses on a LAN. ARP poisoning corrupts those mappings — often via unsolicited (gratuitous) replies — to redirect or intercept traffic.
Study tip: Three different layer-2 attacks: ARP poisoning falsifies IP→MAC mappings; MAC spoofing falsifies a device's own hardware address; MAC flooding overloads a switch's CAM table.
The AES-based encryption protocol of WPA2 — counter-mode encryption plus CBC-MAC integrity — replacing WEP and TKIP's weaknesses.
Study tip: Wireless lineage in order: WEP → TKIP (WPA) → CCMP/AES (WPA2) → SAE handshake (WPA3).
Geographically distributed service hosts that replicate and serve content close to users for low latency, high performance and high availability.
Study tip: “Replicas in many data centers worldwide” = CDN — not VPN (tunnels), SDN (control-plane separation) or CCMP (wireless encryption).
PPP authentication where the password never crosses the wire: the client answers a random server challenge with a hash computed from it.
Study tip: PAP = plaintext, CHAP = challenge/response, EAP = extensible framework — the three PPP options in one line.
Automatically supplies network configuration to clients.
Buffer zone positioned between the private network and the internet that hosts publicly accessible services without exposing the internal LAN.
Study tip: Screened subnet = DMZ. The intranet is the private network itself, an extranet serves selected partners only, and a honeypot is a trap — none of them buffer public services.
Resolves human-readable domain names to network information such as IP addresses.
Adds origin authentication and integrity protection to DNS data.
Study tip: DNSSEC signs DNS data — it proves authenticity, not confidentiality.
Authentication FRAMEWORK (one of PPP's three options, alongside PAP and CHAP) that supports 40+ pluggable methods rather than one fixed mechanism.
Study tip: Real methods include LEAP, PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM, EAP-MD5, EAP-POTP. Invented names like “EAP-VPN” are standard distractors.
In depth — the steps that get tested
- Real methods: LEAP, PEAP, EAP-TLS, EAP-TTLS, EAP-FAST, EAP-SIM, EAP-MD5, EAP-POTP
- More than 40 methods are defined — EAP is a framework, not one protocol
- Fakes that appear as distractors: EAP-VPN, EAP-MBL, VEAP
Combined intrusion detection and prevention capability.
Detects suspicious or malicious activity.
Study tip: IDS detects and alerts; IPS sits inline and can block.
Detects suspicious activity and can actively block it.
Suite of protocols for protecting IP communications.
Firewall deployed INSIDE the network to filter traffic between internal zones — the enforcement device behind segmentation and microsegmentation.
Study tip: Perimeter firewalls face the internet; ISFWs face east-west traffic between internal zones (even down to a single high-value host).
Falsifying a device's hardware (MAC) address to impersonate an authorized device — e.g. to bypass port security or MAC filtering.
Study tip: Spoofing impersonates, flooding overloads switch memory, ARP poisoning corrupts neighbours' mappings.
Controls whether users and devices are permitted to connect to a network.
Study tip: NAC asks: “may the device enter?” (DLP asks whether the data may leave.)
Firewall integrating traditional filtering with application awareness, IPS, TLS inspection and other services in one device — often described as unified threat management (UTM).
Study tip: “UTM” in a stem points at NGFW. It guards the network path; EDR guards the endpoint.
Synchronizes system clocks across a network — a dependency for Kerberos authentication and for correlating logs during investigations.
Study tip: Mysterious Kerberos logon failures on some hosts = check clock drift first (tolerance is about five minutes).
Seven-layer conceptual networking model — 1 Physical, 2 Data Link, 3 Network, 4 Transport, 5 Session, 6 Presentation, 7 Application.
Study tip: Know the seven layers in order (“Please Do Not Throw Sausage Pizza Away”) and which protocols and devices live at each.
In depth — the steps that get tested
- Layer 1 Physical — cables, signals, hubs
- Layer 2 Data Link — frames, MAC addresses, switches
- Layer 3 Network — packets, IP, routers
- Layer 4 Transport — TCP/UDP, ports, segmentation
- Layer 5 Session — dialog establishment and teardown
- Layer 6 Presentation — formats, compression, encryption
- Layer 7 Application — HTTP, DNS, SMTP and friends
PPP authentication that transmits usernames and passwords in cleartext — no encryption or protection of logon credentials at all.
Study tip: “No protection for credentials” = PAP, full stop. RADIUS is a AAA service, not the naked protocol.
A logical circuit that always exists and waits for the customer to send data — versus an SVC (switched virtual circuit), built per session and torn down afterwards.
Study tip: “Always exists, waiting for data” = PVC; “created each time it's needed” = SVC. Think dedicated leased line vs dial-up, virtualized.
Mechanisms for managing network performance and traffic priority.
The three private, non-routable IPv4 blocks: 10.0.0.0/8, 172.16.0.0/12 (through 172.31.255.255), and 192.168.0.0/16.
Study tip: The 172.16–172.31 boundary is the tested detail. 169.254.x.x is APIPA link-local — NOT an RFC 1918 range.
In depth — the steps that get tested
- 10.0.0.0 – 10.255.255.255 (10.0.0.0/8)
- 172.16.0.0 – 172.31.255.255 (172.16.0.0/12)
- 192.168.0.0 – 192.168.255.255 (192.168.0.0/16)
- NOT private: 169.254.x.x — that's APIPA link-local
Cloud-delivered architecture combining networking and security capabilities.
Network architecture separating centralized software-based control from packet forwarding.
Study tip: Control plane and data plane are split — the controller is the crown jewel to protect. Access control inside SDNs is commonly ABAC (attribute-based).
Protocol for monitoring and managing network devices.
Study tip: Only SNMPv3 adds real security (authentication and encryption).
Secure protocol for remote system administration and related functions.
Older predecessor to TLS; obsolete versions should not be treated as secure.
Study tip: If an answer offers SSL as the “secure” choice, be suspicious — TLS replaced it.
Core protocol suite underlying IP networks and the Internet; its four-layer model is Link, Internet, Transport, Application.
Study tip: Mapping to OSI: Link ≈ 1–2, Internet ≈ 3, Transport ≈ 4, Application ≈ 5–7.
In depth — the steps that get tested
- Link — OSI layers 1–2
- Internet — OSI layer 3 (IP)
- Transport — OSI layer 4 (TCP/UDP)
- Application — OSI layers 5–7
Cryptographic protocol protecting data in transit.
Logical separation of network devices into distinct broadcast domains.
Protected logical connection across an untrusted network.
Filters and protects HTTP/HTTPS traffic to web applications.
Low-power, short-range IoT communications protocol for sensors and hubs, encrypted with a 128-bit symmetric key.
Study tip: Tells: IoT sensor, metres of range, low power, encryption built in — where plain Bluetooth would be unencrypted.
Remember this — Network vs. Data
- NAC = can the device enter?
- DLP = can the data leave?
Identity & Access Management (20 terms)
Determines who a subject is, what it may do, and records relevant activity.
Makes authorization decisions using attributes of users, resources and context.
Allows resource owners to decide who receives access.
Study tip: Owner decides = DAC; labels and clearances decide = MAC.
Trust arrangement allowing identities to be recognized across security domains — users sign in with their EXISTING (normal) account credentials.
Study tip: In federation questions, the login ID stays the user's normal account; SSO is the resulting capability, not a kind of account.
Processes and technologies controlling identities and their access to resources.
Provides elevated access temporarily, only when required.
Ticket-based network authentication: a Key Distribution Center issues ticket-granting tickets and service tickets, using AES symmetric cryptography.
Study tip: Two exam hooks: clocks must agree within ~5 minutes (drift = logon failures, fix with NTP), and compromising the KRBTGT account lets attackers forge golden tickets.
In depth — the steps that get tested
- KDC — Key Distribution Center (authentication + ticket-granting services)
- TGT — ticket-granting ticket, obtained at logon
- Service tickets — presented to each resource
- Symmetric crypto (AES); passwords never cross the network
- Clock tolerance ~5 minutes — drift breaks authentication (fix: NTP)
- KRBTGT account compromise → forged golden tickets
Protocol used to access and manage directory services.
Centrally enforced access decisions based on classifications and labels. Supports three environment types: hierarchical, compartmentalized, and hybrid.
Study tip: Context matters: MAC can also mean Media Access Control or Message Authentication Code on the exam.
In depth — the steps that get tested
- Hierarchical environment — ordered labels low → high (each level relates to the ones above/below)
- Compartmentalized environment — isolated compartments, no ordering between them
- Hybrid environment — hierarchical levels containing compartments
- These three are the ONLY MAC environments — 'bracketed' and 'centralized' are invented distractors
Authentication requiring factors from more than one factor category.
Study tip: Two passwords is not MFA — factors must come from different categories.
Framework for delegated authorization allowing applications limited access to resources without sharing a user's password.
Study tip: OAuth = authorization (what an app may do), not authentication.
Identity and authentication layer built on OAuth 2.0, carrying identity claims in JSON Web Tokens (JWTs).
Study tip: Token format is a tell: JSON Web Tokens = OIDC; XML assertions = SAML. OIDC adds the “who are you?” answer on top of OAuth.
Controls and monitors highly privileged accounts and credentials.
Reusing a captured NTLM credential hash to authenticate to remote systems without ever knowing the password.
Study tip: Match attack to system: pass the hash = NTLM; pass the ticket and golden ticket = Kerberos; rainbow tables = offline password cracking.
In depth — the steps that get tested
- Pass the hash — reuse an NTLM hash without knowing the password
- Pass the ticket — reuse a captured Kerberos ticket
- Golden ticket — forge TGTs after compromising KRBTGT (Kerberos)
- Rainbow table — offline cracking with precomputed hash tables
AAA protocol widely used for network-access authentication.
Study tip: RADIUS for network access; TACACS+ (separate AAA, fully encrypted payload) for device administration.
Assigns permissions according to organizational roles.
Study tip: Roles decide (RBAC); attributes and context decide (ABAC).
XML-based standard commonly used for federated identity and browser-based enterprise SSO.
Study tip: SAML = enterprise federation and browser SSO.
Standard for automating identity provisioning and deprovisioning.
Allows one authentication event to provide access to multiple related systems.
AAA protocol frequently used for administrative access to network equipment.
Remember this — Federation
- OAuth = authorization
- OIDC = authentication / identity on OAuth
- SAML = enterprise federation / browser SSO
Security Assessment & Testing (11 terms)
Standard identifier assigned to publicly disclosed vulnerabilities.
Framework for expressing vulnerability severity.
Catalog of common software and hardware weakness types.
Study tip: CVE names a specific vulnerability; CWE names the general weakness type behind it.
Tests a running application externally.
Study tip: Dynamic = attack the running app from outside. Black-box.
Analyzes application behavior from within, via instrumentation, while the application executes.
Authorized attempt to exploit vulnerabilities to demonstrate practical impact.
Application-integrated protection operating while software runs.
Analyzes source or compiled code without executing the application.
Study tip: Static = code at rest. White-box, early in the pipeline.
Structured inventory of components contained in a software product.
Identifies third-party and open-source components and associated vulnerabilities or licensing concerns.
Study tip: SCA inspects your dependencies, not your own code.
Process of identifying and evaluating security weaknesses.
Study tip: VA finds weaknesses; a penetration test exploits them to show impact.
Remember this — Application testing
- SAST = analyze code without executing it
- DAST = attack / test the running application
- SCA = inspect dependencies and components
- IAST = analyze from inside while the app executes
Security Operations (11 terms)
Team responsible for coordinating response to cybersecurity incidents.
Endpoint-focused monitoring, detection, investigation and response — the evolution of traditional antivirus, often reporting events to a central or cloud ML analysis engine.
Study tip: Scenario tells: “evolution of antivirus”, “beyond AV/HIDS”, central ML analysis, endpoint focus. NGFW is a network device, WAF filters web traffic, and XSRF is an attack, not a control. (EDR = endpoints; NDR = network; XDR = correlated across layers.)
Architecture intended to minimize service outages and increase resilience.
Observable artifact or behavior suggesting possible compromise.
Study tip: IOC = the artifact left behind; TTP = the adversary's behavior pattern.
Structured process for managing cybersecurity incidents.
Study tip: Know the lifecycle IN ORDER: Detection/Analysis → Containment → Eradication → Recovery → Lessons Learned.
In depth — the steps that get tested
- 1 Detection / Analysis — recognize and triage the incident
- 2 Containment — stop the spread before deeper action
- 3 Eradication / Remediation — remove the adversary and artifacts
- 4 Recovery — restore systems and service
- 5 Lessons Learned — feed improvements back into controls
Detection and investigation based primarily on network telemetry.
Aggregates and correlates logs and security events for monitoring and investigation.
Study tip: SIEM gives visibility; SOAR automates the response on top of it.
Automates and coordinates security-analysis and response workflows.
Patterns describing how adversaries pursue goals and conduct attacks.
Uses behavior patterns to detect anomalous or risky activity involving users and other entities.
Correlates security telemetry and response across multiple security layers.
Remember this — Incident response lifecycle
Software & Cloud Security (12 terms)
Defined interface enabling software systems to communicate.
Automated practices for integrating, testing and releasing software.
Commercially produced software acquired rather than custom developed.
Organization providing cloud computing services.
Cloud model providing computing infrastructure while customers manage the higher software layers.
Study tip: Responsibility shifts to the provider as you move IaaS → PaaS → SaaS.
Nonprofit community producing widely used application-security guidance and tools.
Cloud model providing infrastructure plus a managed application platform and runtime.
Cloud model delivering a complete managed application.
Processes through which software is planned, designed, built, tested, operated and retired.
Study tip: Phases in order: requirements → design → implementation → testing → deployment/operations → retirement.
In depth — the steps that get tested
- Requirements — what must it do (start security HERE)
- Design — architecture and threat modeling
- Implementation — secure coding
- Testing — SAST/DAST, reviews, UAT
- Deployment / Operations — hardening, monitoring, patching
- Retirement — secure decommissioning and data disposal
SDLC in which security activities and controls are intentionally integrated.
Study tip: Security built in, not bolted on — the recurring exam theme.
Five-level software-process maturity model: 1 Initial → 2 Repeatable → 3 Defined → 4 Managed (quantitatively measured) → 5 Optimizing.
Study tip: Know the five levels in order; the trap is Defined (documented org-wide) vs Managed (measured).
In depth — the steps that get tested
- Level 1 Initial — ad hoc, heroics
- Level 2 Repeatable — basic project management discipline
- Level 3 Defined — processes documented organization-wide
- Level 4 Managed — processes quantitatively measured
- Level 5 Optimizing — continuous process improvement
Web attack that tricks an authenticated user's browser into sending unwanted, legitimate-looking requests to a site where the victim is already logged in.
Study tip: Also written CSRF. It is an ATTACK — when a question asks you to pick a defensive control, XSRF is always the distractor.
Further study
The authoritative statement of what the exam covers is the official ISC2 CISSP Certification Exam Outline. Definitions in this glossary are independently written summaries — use the outline to weight your study time across domains.
Independent CISSP study aid. CISSP is a registered trademark of ISC2. This resource is not affiliated with or endorsed by ISC2.