CISSPSeptember 30, 202624 min read

CISSP Glossary: 55 Key Terms Explained (2026)

The 55 CISSP terms that decide scenario questions, from due care vs due diligence to Bell-LaPadula vs Biba and RTO vs RPO, each with a plain definition and the exam cue that signals it.

  • 55Terms defined
  • 60+Acronyms
  • 100-150Questions
  • 3 hoursTime
  • 700 / 1000Pass mark
CISSP glossary of key terms across the eight ISC2 domains

How to use this glossary

CISSP questions rarely ask you to recite a definition. They describe a situation and ask what the security professional should do first, best or most - and the right answer usually hinges on one word: owner vs custodian, due care vs due diligence, RTO vs RPO. If those terms are fuzzy, two answers look equally right. This glossary covers the vocabulary that separates them, written from the risk-focused, manager-level viewpoint the exam rewards.

The terms are mapped to the current ISC2 CISSP exam outline, effective 15 April 2024, which raised Domain 1 to 16% and cut Domain 8 to 10%. As of September 2026 ISC2 has not announced a newer CISSP outline; the April 2026 change was to the experience-waiver credential list, not the exam content. The exam uses Computerized Adaptive Testing: 100-150 items in 3 hours, 700 out of 1000 to pass.

Every term below is tagged with the exam domain it belongs to. This is where the vocabulary load sits across the CISSP blueprint:

  • D1Security and Risk Management16%13 terms
  • D2Asset Security10%5 terms
  • D3Security Architecture and Engineering13%11 terms
  • D4Communication and Network Security13%4 terms
  • D5Identity and Access Management (IAM)13%10 terms
  • D6Security Assessment and Testing12%4 terms
  • D7Security Operations13%5 terms
  • D8Software Development Security10%3 terms

Each card has three layers: a plain-English definition, an On the exam line describing how questions use the term, and — where one exists — the term it is most often confused with. Click that link to jump straight to the rival definition.

The A–Z glossary

ABACAttribute-Based Access ControlD5

An access model that evaluates attributes of the subject, the object, the action and the environment - department, data label, time of day, location - against policy rules to reach a fine-grained allow or deny decision.

On the examCue: access must depend on several conditions at once, such as role plus device plus location. Roles alone cannot express that, so RBAC is the distractor.

Don’t confuse with RBAC

ALEAnnualized Loss ExpectancyD1

The expected yearly cost of a specific risk, calculated as SLE x ARO. It gives management a dollar figure to compare against the annual cost of a proposed safeguard.

On the examExpect a short calculation, then the manager decision: a control is justified when the ALE reduction it delivers exceeds its annual cost. Never spend more protecting an asset than it is worth.

Don’t confuse with SLE

AROAnnualized Rate of OccurrenceD1

How many times per year a given threat is expected to materialize. A flood once every 50 years has an ARO of 0.02; an event expected four times a year has an ARO of 4.

On the examQuestions state frequency in plain words - once every ten years - and you convert it to 0.1 before multiplying. Mixing ARO with exposure factor is the classic slip.

Don’t confuse with ALE

Asymmetric EncryptionD3

Cryptography using a mathematically linked key pair: what one key encrypts only the other can decrypt. It enables key exchange, digital signatures and non-repudiation, but it is far slower than symmetric encryption.

On the examKnow whose key does what: encrypt with the recipient's public key for confidentiality, sign with the sender's private key for non-repudiation. Scenarios needing both speed and scale use hybrid encryption.

Don’t confuse with Symmetric Encryption

AuthenticationD5

Verifying that a claimed identity is genuine, using something you know, have or are. It follows identification (the claim) and comes before authorization (what you may do).

On the examWatch the sequence identification, authentication, authorization, accountability. A user proving who they are with a token and PIN is authentication; deciding which files they open is not.

Don’t confuse with Authorization

AuthorizationD5

Granting or denying an authenticated subject's access to specific objects and actions, based on policy, the access model in use and the principle of least privilege.

On the examScenario describes a verified user reaching data they should not see - that is an authorization failure, and the fix is permissions or access review, not stronger login factors.

Don’t confuse with Authentication

BCPBusiness Continuity PlanD1

The organization-wide plan for keeping critical business functions running during and after a disruption. It is driven by the business impact analysis and owned by senior management, not IT.

On the examBCP is strategic and business-wide; DRP is the IT recovery piece within it. When asked what comes first in continuity planning, the answer is usually project scope and the BIA.

Don’t confuse with DRP

Bell-LaPadulaD3

A formal state-machine security model built to protect confidentiality in multilevel systems. Its rules: no read up (simple security property) and no write down (star property).

On the examAny question about preventing disclosure of classified data points here. Memorize the direction: a Secret user cannot read Top Secret or write down to Unclassified.

Don’t confuse with Biba

BIABusiness Impact AnalysisD1

An analysis that identifies critical business processes, the impact of losing them over time, and the resources they depend on. It produces the MTD, RTO and RPO values that shape recovery strategy.

On the examBIA precedes strategy selection. If a question asks how to decide which systems to recover first or how much downtime is tolerable, the BIA is the answer.

BibaD3

A security model focused on integrity rather than secrecy. Its rules are the inverse of Bell-LaPadula: no read down (simple integrity) and no write up (star integrity).

On the examCue words are integrity, contamination or untrusted input corrupting trusted data. If the scenario is about secrecy instead, the answer flips to Bell-LaPadula.

Don’t confuse with Bell-LaPadula

Brewer-NashD3

Also called the Chinese Wall model. Access rights change dynamically based on what a user has already accessed, preventing conflicts of interest between competing clients' data.

On the examCue: a consultant or analyst serves competing firms. Once they open Company A's files, Company B's become off-limits - that dynamic restriction is Brewer-Nash.

CERCrossover Error RateD5

The point at which a biometric system's false rejection rate (Type I) equals its false acceptance rate (Type II). Also called the equal error rate, it is the standard figure for comparing biometric accuracy.

On the examLower CER means a more accurate device. Remember Type II (false accept) is the security failure; Type I (false reject) is the usability annoyance.

Chain of CustodyD7

The documented, unbroken record of who collected, handled, transferred and stored evidence, and when. It proves evidence was not altered, which keeps it admissible in legal proceedings.

On the examAny gap in handling makes evidence questionable. When asked what matters most once evidence is collected, choose documenting custody, and work from forensic copies rather than originals.

Change ManagementD7

A formal process for requesting, reviewing, approving, testing, implementing and documenting changes to systems, so that changes do not introduce unintended outages or security weaknesses.

On the examScenario: an admin makes a quick fix directly in production and something breaks. The best answer routes the change through approval and testing, even when the fix itself works.

Clark-WilsonD3

An integrity model for commercial systems. Users reach data only through well-formed transactions via the access triple of subject, program and object, with separation of duties and auditing enforced.

On the examCue: users must never modify data directly, only through a controlled application. Terms like CDI, TP and IVP in the question are Clark-Wilson signatures.

Don’t confuse with Biba

Cryptographic ErasureD2

Sanitizing data by securely destroying the encryption keys that protect it, leaving the remaining ciphertext unreadable. Often called crypto-shredding, it suits media you cannot physically control.

On the examCue: sensitive data lives in a cloud or SaaS provider and you cannot degauss or shred their drives. Destroying the keys is the realistic sanitization answer.

Don’t confuse with Data Remanence

DACDiscretionary Access ControlD5

An access model in which the owner of an object decides who can access it, typically through access control lists. It is flexible but hard to manage centrally and vulnerable to misuse by owners.

On the examCue phrase: the data owner or creator grants permissions at their discretion. File shares where users set their own sharing rights are DAC.

Don’t confuse with MAC

DASTDynamic Application Security TestingD8

Testing a running application from the outside by sending crafted inputs and observing responses, without access to source code. It finds runtime issues such as injection and misconfiguration.

On the examCue: the application is deployed or in staging and testers have no source code. DAST finds issues late in the lifecycle, so fixing them costs more.

Don’t confuse with SAST

Data CustodianD2

The role, usually IT or operations staff, that implements and maintains the protections the owner specifies: backups, access provisioning, patching and day-to-day safeguarding of the data.

On the examCustodians do the work but do not decide. If the question asks who performs backups or applies the controls, choose custodian; who classifies or approves is the owner.

Don’t confuse with Data Owner

Data OwnerD2

The senior business person accountable for a data set. They classify it, decide who may access it and approve the level of protection it receives, even if others handle it daily.

On the examAccountability sits with the owner, usually a business manager rather than IT. Questions asking who determines classification or approves access expect data owner.

Don’t confuse with Data Custodian

Data RemanenceD2

Residual data that remains on storage media after deletion or formatting, which can often be recovered with forensic tools. Sanitization methods exist specifically to defeat it.

On the examDeleting files or quick-formatting is never the correct disposal answer. Match the method to media and sensitivity: clear, purge or destroy - and remember degaussing does not work on SSDs.

Don’t confuse with Cryptographic Erasure

Defense in DepthD3

Layering multiple independent administrative, technical and physical controls so that the failure of one control does not expose the asset. Each layer slows or detects an attacker who bypasses the previous one.

On the examWhen one control fails in the scenario, the best answer adds a complementary layer rather than replacing the failed control with a stronger single one.

Don’t confuse with Zero Trust

Digital SignatureD3

A hash of a message encrypted with the sender's private key. Verifying it with the sender's public key proves integrity, authenticity of origin and non-repudiation, but it does not provide confidentiality.

On the examIf a scenario needs proof the sender cannot deny sending, choose a digital signature. A MAC or HMAC gives integrity but not non-repudiation because the key is shared.

DRPDisaster Recovery PlanD7

The technical plan for restoring IT systems, data and facilities after a disruptive event, typically at an alternate site. It is a component of the broader business continuity effort.

On the examDRP focuses on getting IT back; BCP keeps the business running. Remember people safety always comes first, and plans must be tested - a walkthrough before a full interruption test.

Don’t confuse with BCP

Due CareD1

Doing what a reasonable, prudent person would do to protect assets - actually implementing and operating the controls. It is the action side of corporate security responsibility.

On the examCue: applying patches, enforcing the policy, running the controls. If the question says the company acted to protect data, that is due care. Negligence is its absence.

Don’t confuse with Due Diligence

Due DiligenceD1

The research, investigation and ongoing verification that informs and checks security decisions - assessing risks, vetting vendors and confirming controls work. It is the knowing side that precedes and supports due care.

On the examCue: evaluating a vendor before signing, auditing controls, researching risk. Memory hook: due diligence is do detect, due care is do correct.

Don’t confuse with Due Care

IPsecInternet Protocol SecurityD4

A suite of protocols that secures IP traffic at the network layer. AH provides integrity and origin authentication, ESP adds confidentiality, and IKE negotiates keys. It runs in transport or tunnel mode.

On the examTunnel mode encrypts the whole original packet, typical for site-to-site VPNs; transport mode protects only the payload. If confidentiality is required, AH alone is the wrong answer.

Don’t confuse with TLS

JIT AccessJust-in-Time AccessD5

Granting elevated privileges only when they are needed and only for a limited time, then revoking them automatically. It shrinks the window in which privileged accounts can be abused.

On the examNamed in the 2024 outline. Cue: admins hold standing privileged access they use rarely. The best answer removes standing privilege in favor of approved, time-bound elevation.

Don’t confuse with Least Privilege

KerberosD5

A ticket-based authentication protocol using symmetric keys and a trusted Key Distribution Center, made up of an Authentication Service and a Ticket Granting Service, to provide single sign-on inside a network.

On the examKnow the weaknesses: the KDC is a single point of failure and clocks must be synchronized or tickets fail. A ticket-granting ticket is issued once, then exchanged for service tickets.

Don’t confuse with SAML

Least PrivilegeD7

Giving each user, process or system only the minimum access rights required for its job, for the minimum time needed. It limits the damage any compromised account or insider can do.

On the examOften the right answer when a scenario shows privilege creep after job changes. The fix is periodic access review and removing rights no longer needed.

Don’t confuse with Separation of Duties

MACMandatory Access ControlD5

An access model where the system enforces access by comparing subjects' clearances to objects' classification labels. Users, even owners, cannot change those permissions themselves.

On the examCue words: labels, clearances, classification, military or government. If users cannot override access decisions, it is MAC. Do not confuse with a message authentication code.

Don’t confuse with DAC

MicrosegmentationD4

Dividing a network into very small zones, down to individual workloads, with policy enforced on east-west traffic between them. It limits lateral movement once an attacker gets inside.

On the examListed in the 2024 outline. Cue: an attacker compromised one server and moved sideways across a flat data center network. Microsegmentation, a zero trust building block, contains that spread.

MTDMaximum Tolerable DowntimeD1

The longest a business process can be unavailable before the organization suffers unacceptable or irrecoverable harm. It is set by business owners during the BIA and caps every recovery target.

On the examThe RTO must always be shorter than the MTD, leaving time to verify systems. If a proposed recovery takes longer than the MTD, the strategy fails regardless of cost.

Don’t confuse with RTO

OSI ModelOpen Systems Interconnection ModelD4

A seven-layer reference model for network communication: Physical, Data Link, Network, Transport, Session, Presentation and Application. It is used to place protocols, devices and attacks at the right layer.

On the examExpect layer placement: switches at 2, routers and IPsec at 3, TCP and UDP at 4. Encapsulation adds headers going down the stack; decapsulation strips them going up.

Penetration TestingD6

An authorized, simulated attack in which testers actively exploit vulnerabilities to show real-world impact. It is goal-driven, can disrupt systems, and requires written senior management approval and agreed rules of engagement.

On the examThe first step is always written authorization from senior management. Testing without it is illegal regardless of intent - watch for answers that skip permission.

Don’t confuse with Vulnerability Assessment

PolyinstantiationD8

Keeping multiple versions of the same data record at different classification levels, so lower-cleared users see a cover version and cannot infer the existence of classified information.

On the examCue: preventing inference in a multilevel database. If lower-level users could deduce secrets from a record being hidden or locked, polyinstantiation is the countermeasure.

Quantitative Risk AnalysisD1

Risk assessment that assigns monetary values to assets, losses and frequencies - asset value, exposure factor, SLE, ARO, ALE - to produce figures for cost-benefit decisions.

On the examIt supports objective cost-benefit comparison but depends on reliable data. Qualitative analysis ranks risks by scenario and judgment; many questions expect a combination of both.

RBACRole-Based Access ControlD5

An access model that assigns permissions to job roles and places users into roles, rather than granting rights to individuals. It simplifies administration where staff turnover is high.

On the examCue: many users share the same job functions, or turnover is high. Moving a user between roles is the clean fix for accumulated permissions.

Don’t confuse with ABAC

Reference MonitorD3

An abstract concept describing a component that mediates every access by subjects to objects. It must be tamperproof, always invoked and small enough to be verified.

On the examReference monitor is the concept; the security kernel is its implementation inside the TCB. Questions often test that relationship rather than the definition.

Don’t confuse with TCB

Residual RiskD1

The risk that remains after safeguards are applied. Senior management must formally accept it; it can be reduced but never removed completely.

On the examTotal risk minus the effect of controls equals residual risk. Accepting residual risk is a senior management decision - never the security team's alone.

RPORecovery Point ObjectiveD1

The maximum acceptable amount of data loss, measured back in time from the incident to the last usable copy. It drives backup and replication frequency.

On the examRPO is about data, looking backward. An RPO of one hour means backups or replication at least hourly. If the question mentions data loss tolerance, pick RPO.

Don’t confuse with RTO

RTORecovery Time ObjectiveD1

The target time within which a system or process must be restored after a disruption. It must be shorter than the MTD and drives the choice of recovery site and technology.

On the examRTO is about time, looking forward. A four-hour RTO rules out a cold site. If the question mentions how quickly service must return, pick RTO.

Don’t confuse with RPO

SAMLSecurity Assertion Markup LanguageD5

An XML-based standard for exchanging authentication and authorization assertions between an identity provider and a service provider, enabling federated single sign-on across organizations.

On the examCue: browser-based single sign-on to partner or SaaS applications using a corporate identity. The IdP authenticates; the service provider trusts the signed assertion.

SASTStatic Application Security TestingD8

Analyzing source code, bytecode or binaries without executing them to find flaws such as injection, hard-coded secrets and unsafe functions. It can run early in development.

On the examCue: find flaws as early as possible in the SDLC, or developers have source code access. Earlier detection is cheaper, so SAST often beats DAST for shift-left questions.

Don’t confuse with DAST

Scoping and TailoringD2

Scoping selects which controls from a baseline apply to a given system; tailoring modifies those controls to fit the organization's mission and environment, including compensating controls.

On the examBaselines are a starting point, not a mandate. If a baseline control does not fit, the answer is to scope or tailor it with documented justification.

Separation of DutiesD7

Splitting a critical task among two or more people so no single person can complete it alone, reducing fraud and error. Collusion would be required to abuse it.

On the examCue: the same person creates vendors and approves payments, or develops and deploys code. Job rotation and mandatory vacations help detect what separation of duties prevents.

Don’t confuse with Least Privilege

SLESingle Loss ExpectancyD1

The expected monetary loss from one occurrence of a risk, calculated as asset value x exposure factor. The exposure factor is the percentage of the asset lost in one event.

On the examExample: a $200,000 asset with a 25% exposure factor gives an SLE of $50,000. Questions then multiply by ARO to reach ALE.

Don’t confuse with ALE

SOC 2 ReportSystem and Organization Controls 2D6

An independent auditor's report on a service organization's controls relevant to security, availability, processing integrity, confidentiality and privacy. Type I covers design at a point in time; Type II covers operating effectiveness over a period.

On the examCue: you must assure a cloud or outsourcing provider's controls without auditing them yourself. Type II is stronger assurance than Type I because it tests controls over time.

Symmetric EncryptionD3

Encryption using one shared secret key for both encryption and decryption, as in AES. It is fast and suited to bulk data, but key distribution and scale are its weak points.

On the examKnow the key math: n users need n(n-1)/2 symmetric keys but only 2n asymmetric keys. Symmetric provides confidentiality, never non-repudiation.

Don’t confuse with Asymmetric Encryption

Synthetic TransactionD6

A scripted, simulated user transaction run against a system on a schedule to verify availability, performance and functionality before real users are affected.

On the examSynthetic monitoring is proactive; real user monitoring passively observes actual traffic. If the goal is to detect a failed checkout before customers notice, choose synthetic transactions.

TCBTrusted Computing BaseD3

The total combination of hardware, firmware and software protection mechanisms responsible for enforcing a system's security policy. The security perimeter separates it from the rest of the system.

On the examAnything inside the TCB must be trusted, so keep it small. Questions pair it with the security kernel and the reference monitor concept it implements.

Don’t confuse with Reference Monitor

Threat ModelingD1

A structured process for identifying potential threats to a system, ranking them and planning mitigations, ideally during design. Common methods include STRIDE, PASTA and attack trees.

On the examBest done early in design, when changes are cheapest. Know the STRIDE letters: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

TLSTransport Layer SecurityD4

The protocol that secures application traffic, such as HTTPS, between client and server using certificates for authentication, asymmetric key exchange and symmetric session encryption. It replaced the deprecated SSL.

On the examTLS protects specific application sessions; IPsec protects all IP traffic between hosts or networks. Any answer recommending SSL or early TLS versions is wrong.

Don’t confuse with IPsec

Vulnerability AssessmentD6

A systematic process of identifying, quantifying and prioritizing weaknesses in systems, usually with automated scanners, without exploiting them. It aims for breadth of coverage.

On the examIt finds and ranks weaknesses; it does not prove exploitability. If a scenario must show whether an attacker could actually get in, that is a penetration test.

Don’t confuse with Penetration Testing

Zero TrustD3

A security model that removes implicit trust based on network location. Every access request is authenticated, authorized and continuously evaluated, with least privilege and segmentation applied.

On the examCue: never trust, always verify, or remote users and cloud apps make the perimeter meaningless. Zero trust is listed under secure design principles in the 2024 outline.

Don’t confuse with Defense in Depth

Terms the exam loves to confuse

These six pairs account for a large share of CISSP questions where two answers both look correct. Learn the single clue that decides each one.

Due CareTaking reasonable action to protect assets: implementing, operating and maintaining the controls a prudent organization would put in place.

Due DiligenceInvestigating and verifying so decisions are informed: assessing risk, vetting third parties and confirming the controls actually work.

The tellDoing or implementing points to due care; researching, assessing or checking points to due diligence. Diligence informs, care acts.

Bell-LaPadulaConfidentiality model: no read up and no write down, so classified information cannot flow to lower levels.

BibaIntegrity model: no read down and no write up, so untrusted data cannot contaminate higher-integrity data.

The tellSecrecy, disclosure or clearance levels means Bell-LaPadula. Integrity, corruption or trustworthiness of data means Biba. The rules are mirror images.

RTOHow quickly a system must be running again after a disruption. It is a time target that drives recovery site choice.

RPOHow much data, measured in time, can be lost. It is a data-loss target that drives backup and replication frequency.

The tellDowntime or restoration speed means RTO. Data loss or the age of the last good backup means RPO.

Vulnerability AssessmentFinds and prioritizes weaknesses, mostly with automated scanning, without exploiting them. Broad coverage with low disruption.

Penetration TestingActively exploits weaknesses to prove real impact, within approved rules of engagement. Deeper, narrower and riskier.

The tellIf the question asks whether an attacker could actually breach or pivot, choose penetration testing. If it asks what weaknesses exist, choose assessment.

Data OwnerAccountable business manager who classifies the data, approves access and sets the required level of protection.

Data CustodianOperational role that implements the owner's decisions: runs backups, applies controls and maintains the systems.

The tellDeciding, classifying or approving means owner. Performing, maintaining or implementing means custodian. Accountability never moves to the custodian.

DACAccess set at the owner's discretion, usually via ACLs. Flexible, decentralized and dependent on owners making good choices.

MACAccess enforced by the system using labels and clearances. Users cannot change it, even for data they created.

The tellIf users or owners can grant access themselves, it is DAC. Labels, clearances and non-overridable rules mean MAC.

Acronym quick-scan

ISC2 does not attach an official acronym list to the CISSP exam outline, so this list collects the abbreviations that appear most in the outline and in exam-style questions.

  • AAAAuthentication, Authorization, and Accounting
  • ABACAttribute-Based Access Control
  • ACLAccess Control List
  • AESAdvanced Encryption Standard
  • AHAuthentication Header
  • ALEAnnualized Loss Expectancy
  • AROAnnualized Rate of Occurrence
  • AVAsset Value
  • BCPBusiness Continuity Plan
  • BIABusiness Impact Analysis
  • CACertificate Authority
  • CASBCloud Access Security Broker
  • CDIConstrained Data Item
  • CERCrossover Error Rate
  • CIAConfidentiality, Integrity, and Availability
  • CRLCertificate Revocation List
  • CVECommon Vulnerabilities and Exposures
  • CVSSCommon Vulnerability Scoring System
  • DACDiscretionary Access Control
  • DASTDynamic Application Security Testing
  • DLPData Loss Prevention
  • DRPDisaster Recovery Plan
  • EFExposure Factor
  • ESPEncapsulating Security Payload
  • FARFalse Acceptance Rate
  • FRRFalse Rejection Rate
  • GDPRGeneral Data Protection Regulation
  • HMACHash-based Message Authentication Code
  • IaaSInfrastructure as a Service
  • IAMIdentity and Access Management
  • IdPIdentity Provider
  • IDSIntrusion Detection System
  • IKEInternet Key Exchange
  • IPSIntrusion Prevention System
  • IPsecInternet Protocol Security
  • IVPIntegrity Verification Procedure
  • JITJust-in-Time
  • KDCKey Distribution Center
  • KPIKey Performance Indicator
  • KRIKey Risk Indicator
  • MACMandatory Access Control
  • MFAMulti-Factor Authentication
  • MTDMaximum Tolerable Downtime
  • MTTRMean Time to Repair
  • NACNetwork Access Control
  • OCSPOnline Certificate Status Protocol
  • OIDCOpenID Connect
  • OSIOpen Systems Interconnection
  • PAMPrivileged Access Management
  • PASTAProcess for Attack Simulation and Threat Analysis
  • PIIPersonally Identifiable Information
  • PKIPublic Key Infrastructure
  • RBACRole-Based Access Control
  • RPORecovery Point Objective
  • RTORecovery Time Objective
  • SAMLSecurity Assertion Markup Language
  • SASESecure Access Service Edge
  • SASTStatic Application Security Testing
  • SCASoftware Composition Analysis
  • SDLCSoftware Development Life Cycle
  • SDNSoftware-Defined Networking
  • SIEMSecurity Information and Event Management
  • SLAService Level Agreement
  • SLESingle Loss Expectancy
  • SOARSecurity Orchestration, Automation, and Response
  • SOCSystem and Organization Controls
  • SSOSingle Sign-On
  • STRIDESpoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege
  • TCBTrusted Computing Base
  • TGTTicket-Granting Ticket
  • TLSTransport Layer Security
  • TPTransformation Procedure
  • TPMTrusted Platform Module
  • WRTWork Recovery Time

How to make the terms stick

CISSP rewards judgment more than recall, so study the vocabulary the way the exam uses it.

  1. Learn terms by who and whenFor each term, note which role owns it (owner, custodian, senior management, auditor) and where it sits in a process such as BIA before strategy. Most CISSP distractors are the right idea at the wrong step or role.
  2. Drill the confused pairs aloudTake the six pairs above and say the one-line tell for each until it is automatic. Then add your own pairs from missed questions, such as symmetric vs asymmetric or IPsec vs TLS, and review them every few days.
  3. Answer as a manager, then explainWork adaptive practice questions and, for every item, name the term the question hinges on and why each wrong option fails. Pick the answer that manages risk for the business, not the most technical fix.

Knowing the word is not the same as answering the question

Knowing a definition is not the same as spotting it inside a four-sentence scenario. Practice questions test these terms in context, the way the CAT exam does.

App StoreGoogle PlayFree practice testCISSP exam page

FAQ

Is there an official CISSP acronym list?

No. Unlike some vendors, ISC2 does not publish a numbered acronym list with the CISSP exam outline. The outline lists the eight domains and their subdomains, so the vocabulary you need comes from those topics. Focus on acronyms tied to decisions, such as RTO, RPO, MTD, ALE and the access control models, rather than memorizing every protocol abbreviation.

Is the CISSP exam outline changing in 2026 or 2027?

The current outline took effect on 15 April 2024 and, as of September 2026, ISC2 has not announced a replacement. ISC2 refreshes outlines through a job task analysis roughly every three years, so check the official outline page before you book. The April 2026 change affected only the credentials that can waive one year of required experience.

Do I need to calculate ALE on the CISSP exam?

You should be able to. Questions may give an asset value, exposure factor and frequency and expect SLE equals asset value times exposure factor, then ALE equals SLE times ARO. The arithmetic is simple; the real test is the follow-up decision, such as whether a safeguard costs more per year than the loss it prevents.

What does think like a manager mean for CISSP vocabulary?

It means reading each term through business risk and accountability rather than technical detail. Senior management accepts residual risk, data owners classify data, and custodians implement controls. When two answers are technically valid, the better one usually follows process, protects people first, and aligns with policy and business objectives.

Sources

Scope and domain names on this page come from ISC2’s published exam objectives; definitions are ours, written for exam prep:

Checked September 30, 2026. Exam objectives are revised on the vendor’s schedule — if a term here is not in the current objectives, the objectives win.