StudyToCert

All certifications / CISSP / Cheat sheet

CISSP 2024 outline cheat sheet

Every exam tip and key term from the free CISSP lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Security & risk management (16%)

Exam tips

Key terms

ISC2 Code of Ethics
The preamble and four canons that every ISC2-certified member agrees to follow as a condition of certification.
Canon
One of the four ranked principles of the code; when two conflict, the higher-ranked canon takes priority.
Principal
The party you serve professionally, such as an employer, client or customer.
Conflict of interest
A situation where personal gain or divided loyalty could influence, or appear to influence, professional judgment.
Code of conduct
An organization's own written statement of expected behavior, values and consequences for violations.
Ethics hotline
A confidential or anonymous channel for staff to report suspected misconduct without fear of retaliation.
Tone at the top
The ethical climate set by senior leadership through its own behavior and enforcement.
Confidentiality
Assurance that information is disclosed only to authorized people, processes and devices.
Integrity
Assurance that data and systems are protected from unauthorized or accidental change, and that changes can be detected.
Availability
Assurance that authorized users have timely and reliable access to information and systems.
Authenticity
The property of being verifiably genuine, coming from the claimed source and unaltered.
Non-repudiation
Assurance that a party cannot credibly deny having performed an action, usually provided by digital signatures and logging.
DAD triad
Disclosure, alteration and destruction: the attacker-focused opposites of confidentiality, integrity and availability.
Parkerian hexad
A model that extends the CIA triad with possession or control, authenticity and utility.
Security governance
The leadership structures, responsibilities and processes that direct and oversee an organization's security program.
Strategic plan
A long-term plan, often three to five years, that aligns security with the organization's mission and goals.
Tactical plan
A mid-term plan, around one year, that turns strategy into specific projects and initiatives.
Due care
Acting as a reasonable, prudent person would by implementing and maintaining appropriate controls.
Due diligence
The research, assessment and ongoing verification needed to know what controls are appropriate and whether they work.
Chief information security officer (CISO)
The executive who leads the security program and advises senior management on risk.
Security steering committee
A group of business and technical leaders that sets security priorities and resolves conflicts.
Criminal law
Law addressing offenses against society, prosecuted by the government and punishable by fines or imprisonment.
Civil law
Law governing disputes between private parties, typically resolved through monetary damages or court orders.
GDPR
The European Union's General Data Protection Regulation, which governs processing of personal data about people in the EU.
Copyright
Protection for original works of expression, such as software code, that arises automatically when the work is created.
Patent
Time-limited protection for a novel, useful and non-obvious invention, granted in exchange for public disclosure.
Trade secret
Valuable confidential business information protected for as long as the owner takes reasonable steps to keep it secret.
Transborder data flow
The transfer of data, especially personal data, across national borders, often restricted by privacy and localization laws.
Administrative investigation
An internal inquiry into policy violations or operational issues, leading to discipline or process changes.
Criminal investigation
An inquiry by law enforcement into alleged crimes, requiring proof beyond a reasonable doubt.
Civil investigation
Fact-finding to support a lawsuit between parties, judged on the preponderance of the evidence.
Regulatory investigation
An inquiry by a government agency or authorized body into possible violations of regulations.
Chain of custody
Documentation of who collected, handled and stored evidence, when and how, from collection to court.
Legal hold
An instruction to preserve all information relevant to anticipated or current litigation, suspending normal deletion.
eDiscovery
The process of identifying, preserving, collecting, reviewing and producing electronically stored information for legal matters.
Policy
A high-level, mandatory statement of management intent approved by senior leadership.
Standard
A mandatory, specific requirement, such as a technology or configuration, that makes a policy measurable.
Baseline
A mandatory minimum security configuration for a type of system that may be exceeded but not undercut.
Procedure
Detailed, mandatory step-by-step instructions for performing a specific task.
Guideline
An optional recommendation or best practice that allows discretion.
Policy exception
A formally requested, risk-assessed, approved and time-limited deviation from a policy or standard.
Business continuity planning (BCP)
The process of keeping critical business functions operating during and after a disruption.
Business impact analysis (BIA)
An analysis that identifies critical processes, their dependencies and the impact of their loss over time.
Maximum tolerable downtime (MTD)
The longest a process can be unavailable before the damage becomes unacceptable.
Recovery time objective (RTO)
The target time to restore a process or system after a disruption, which must be less than the MTD.
Recovery point objective (RPO)
The maximum acceptable amount of data loss, measured as time since the last good copy.
Work recovery time (WRT)
The time needed after systems are restored to verify data and resume normal operations.
Hot site
A fully equipped alternate site with current data that can take over almost immediately.
Background screening
Verification of a candidate's identity, history and suitability, proportional to the sensitivity of the role.
Non-disclosure agreement (NDA)
A contract obliging a person to keep specified information confidential, often beyond employment.
Separation of duties
Splitting a critical task among multiple people so no one person can complete it alone.
Job rotation
Moving staff between roles periodically to deter fraud and spread knowledge.
Mandatory vacation
Requiring employees to take time off so others perform their duties and irregularities surface.
Privilege creep
The gradual accumulation of access rights beyond what a user's current role requires.
Service-level agreement (SLA)
A contract defining measurable service commitments, such as availability and response times.
Risk
The likelihood that a threat exploits a vulnerability, combined with the impact on an asset.
Single loss expectancy (SLE)
The expected monetary loss from one occurrence of a risk, calculated as asset value times exposure factor.
Annualized rate of occurrence (ARO)
The estimated number of times a risk event occurs in a year.
Annualized loss expectancy (ALE)
The expected yearly loss from a risk, calculated as SLE times ARO.
Residual risk
The risk that remains after safeguards have been applied.
Risk transfer
Shifting the financial impact of a risk to another party, such as through insurance or contracts.
Delphi technique
A qualitative method that gathers anonymous expert opinions over several rounds to reach consensus.
Threat modeling
A structured process for identifying, prioritizing and addressing threats to a system, ideally during design.
Trust boundary
A point in a system where data or execution passes between components with different levels of trust.
STRIDE
A threat categorization model: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.
PASTA
The Process for Attack Simulation and Threat Analysis, a seven-stage, risk-centric threat modeling method.
Supply chain risk management (SCRM)
Identifying and reducing risks introduced by suppliers, components, services and their own suppliers.
Software bill of materials (SBOM)
An inventory of the components and dependencies that make up a piece of software.
Fourth-party risk
Risk arising from the suppliers and subcontractors of your own direct suppliers.
Security awareness
Activities that keep security top of mind and influence everyday behavior across the whole workforce.
Security training
Instruction that teaches specific skills people need to perform their jobs securely.
Security education
In-depth learning that builds understanding of principles so people can handle new situations.
Phishing simulation
A controlled, fake phishing campaign used to teach and measure how staff respond to suspicious messages.
Security champion
A staff member within a team who promotes good security practice and acts as a link to the security function.
Report rate
The proportion of staff who report a suspicious message, a key behavior metric for awareness programs.

Domain 2: Asset security (10%)

Exam tips

Key terms

Asset inventory
A maintained record of the information and assets an organization holds, with owners and locations.
Classification
Assigning information a sensitivity or criticality level that determines its required protections.
Data owner
The senior business person accountable for a data set, including deciding its classification.
Declassification
Formally lowering or removing a classification when information no longer needs its original protection.
Categorization
Rating a system by the potential impact of losing confidentiality, integrity or availability.
Personally identifiable information (PII)
Information that can identify an individual directly or when combined with other data.
Labeling
Attaching a classification indicator to media or systems, such as a physical label on a drive or tape.
Marking
Displaying the classification within the information itself, such as headers, footers or banners.
Metadata label
A classification stored electronically with a file or record so systems can enforce handling rules.
Handling requirements
Rules that specify how information of each classification is stored, transmitted, used and destroyed.
Mandatory access control (MAC)
An access control model where the system enforces access based on labels and clearances, not owner discretion.
Clean desk policy
A rule requiring sensitive materials to be secured and desks cleared when unattended.
Configuration management database (CMDB)
A repository of assets and their configurations, relationships and owners.
Shadow IT
Technology used or deployed without the knowledge or approval of the IT or security function.
Secure provisioning
Deploying resources in an approved, hardened and recorded state from the start.
Infrastructure as code (IaC)
Defining infrastructure in version-controlled templates so builds are repeatable and reviewable.
Configuration drift
Gradual divergence of a system's actual configuration from its approved baseline.
Data life cycle
The phases data passes through: create, store, use, share, archive and destroy.
Data minimization
Collecting and keeping only the data needed for a specific, legitimate purpose.
Archive
Long-term storage of data no longer in active use, kept to meet retention requirements.
Masking
Hiding part of a sensitive value, such as showing only the last four digits, so users see only what they need.
Legal hold
A requirement to preserve relevant data for litigation or investigation, overriding normal destruction.
Cryptographic erasure
Destroying data by securely deleting the encryption keys that protect it, leaving only unreadable ciphertext.
Data custodian
The person or team, often IT, that implements and operates the protections the owner specifies.
Data steward
The role responsible for data quality, definitions, metadata and proper business use.
Data controller
The entity that determines the purposes and means of processing personal data.
Data processor
An entity that processes personal data on behalf of, and on the instructions of, a controller.
Data subject
The identifiable individual to whom personal data relates.
Data protection officer (DPO)
An independent role that advises on and monitors compliance with data protection law.
Collection limitation
The principle of collecting only the personal data needed for a specific, legitimate purpose by fair and lawful means.
Purpose limitation
Using personal data only for the purposes for which it was collected, unless a new lawful basis exists.
Data sovereignty
The concept that data is subject to the laws of the country where it is located.
Data localization
Legal requirements that certain data be stored or processed within a specific country or region.
Data quality
The principle that personal data should be accurate, complete and kept up to date.
Pseudonymization
Replacing direct identifiers with substitutes so data cannot be attributed to a person without additional, separately held information.
Retention policy
A policy defining how long each category of data is kept and how it is disposed of.
Retention schedule
A list of record types with their retention periods, owners and disposition methods.
Spoliation
The destruction or alteration of evidence that should have been preserved, which can bring legal penalties.
End-of-life (EOL)
The point at which a vendor stops selling or developing a product.
End-of-support (EOS)
The point after which a vendor no longer provides patches, updates or technical support.
Compensating control
An alternative control that reduces risk when the primary control is not feasible.
Data remanence
Residual data that remains on media after attempts to erase or remove it.
Clearing
Logical sanitization of user-addressable storage that protects against simple, non-invasive recovery.
Purging
Sanitization that makes recovery infeasible even with advanced laboratory techniques.
Destruction
Physically rendering media unusable and data unrecoverable, such as by shredding or incineration.
Degaussing
Erasing magnetic media with a strong magnetic field; ineffective on SSDs, flash and optical media.
Cryptographic erase
Sanitizing encrypted media by securely destroying every copy of its encryption keys.
Wear leveling
An SSD technique that spreads writes across cells, which can leave old data in areas overwriting cannot reach.
Data at rest
Data stored on media such as disks, databases, backups or cloud storage.
Data in transit
Data moving across a network between systems or locations.
Data in use
Data being actively processed in memory or viewed by a user.
Transport Layer Security (TLS)
A protocol that encrypts and authenticates application traffic such as web and API connections.
Tokenization
Replacing a sensitive value with a random token that maps to the original only through a secure vault.
Confidential computing
Processing data inside hardware-protected enclaves so it stays protected even from the host operating system.
Data loss prevention (DLP)
Tools that discover, monitor and control the movement of sensitive data.
Standards selection
Choosing which frameworks, baselines and standards apply based on obligations, contracts and business goals.
Scoping
Determining which controls in a baseline apply to a given system or environment.
Tailoring
Adjusting applicable controls, parameters and compensating measures to fit the organization's needs.
Digital rights management (DRM)
Technology that enforces usage restrictions on content wherever it goes, using encryption and licensing.
Cloud access security broker (CASB)
A policy enforcement point between users and cloud services that provides visibility, data protection and threat detection.

Domain 3: Security architecture & engineering (13%)

Exam tips

Key terms

Least privilege
Granting only the minimum access needed to perform a function, for only as long as needed.
Defense in depth
Using multiple, diverse, independent layers of controls so the failure of one does not expose the asset.
Secure defaults
Shipping and deploying systems in their most secure reasonable configuration.
Fail securely
Designing components so that failures leave the system in a secure state, such as denying access.
Zero trust
An architecture that grants no implicit trust based on network location and verifies every request.
Privacy by design
Embedding privacy into systems from the outset, with privacy as the default setting.
Secure access service edge (SASE)
A cloud-delivered model combining SD-WAN with security services such as ZTNA, CASB and secure web gateway.
Bell-LaPadula
A confidentiality model enforcing no read up (simple security) and no write down (star property).
Biba
An integrity model enforcing no read down (simple integrity) and no write up (star integrity).
Clark-Wilson
A commercial integrity model using well-formed transactions, access triples and separation of duties.
Brewer-Nash
The Chinese Wall model, which dynamically blocks access that would create a conflict of interest.
Transformation procedure (TP)
In Clark-Wilson, a certified program that is the only way to modify constrained data items.
Noninterference model
A model requiring that high-level actions cannot affect what lower-level subjects observe, limiting covert channels.
Lattice-based access control
Ordering security levels so each subject and object has a place, forming the basis of mandatory access control.
Common Criteria
An international framework (ISO/IEC 15408) for independently evaluating the security of IT products.
Target of evaluation (TOE)
The specific product or system being evaluated under Common Criteria.
Protection profile (PP)
An implementation-independent set of security requirements for a category of products, usually written by customers or governments.
Security target (ST)
A vendor's document describing the security properties and evaluated configuration of its product.
Evaluation assurance level (EAL)
A rating from EAL1 to EAL7 describing how rigorously a product was evaluated.
Authorization (accreditation)
Management's formal decision to accept residual risk and allow a system to operate.
Compensating control
An alternative control used when a primary control is not feasible, providing similar risk reduction.
Trusted Platform Module (TPM)
A secure cryptoprocessor bound to one device that stores keys and records boot measurements.
Hardware security module (HSM)
A tamper-resistant device that securely generates, stores and uses keys for many applications.
Root of trust
A trusted hardware or firmware component on which the security of the rest of the system depends.
Address space layout randomization (ASLR)
Randomizing memory locations of code and data to make memory corruption attacks harder to exploit.
Data execution prevention (DEP)
Marking memory regions as non-executable so data injected there cannot run as code.
Trusted computing base (TCB)
The combination of hardware, firmware and software components that enforce a system's security policy.
Reference monitor
An abstract component that mediates all access; it must be tamperproof, always invoked and verifiable.
Aggregation
Combining individually low-sensitivity data items to reveal more sensitive information.
Inference
Deducing sensitive information from data a user is authorized to access.
Polyinstantiation
Maintaining multiple versions of a record at different classification levels to prevent inference.
Shared responsibility model
The division of security duties between a cloud provider and its customer, varying by service model.
ICS/OT
Industrial control systems and operational technology that monitor and control physical processes.
VM escape
A compromise in which code in a virtual machine breaks isolation to reach the hypervisor or other guests.
Serverless
A cloud model where the provider runs functions on demand and the customer manages code, permissions and data.
Symmetric encryption
Encryption using one shared secret key for both encryption and decryption.
Asymmetric encryption
Encryption using a mathematically related public and private key pair.
Hash function
A one-way function that produces a fixed-length digest from input of any size.
Digital signature
A hash of a message encrypted with the signer's private key, providing integrity, authenticity and non-repudiation.
Public key infrastructure (PKI)
The roles, policies and systems that issue, manage and revoke digital certificates.
Online Certificate Status Protocol (OCSP)
A protocol for checking the revocation status of an individual certificate in real time.
Split knowledge and dual control
Controls ensuring no single person knows or can use a whole critical key alone.
Brute force attack
Trying every possible key or password until the correct one is found, defeated by large key spaces, slow hashing and lockout.
Rainbow table
A precomputed set of hash chains used to reverse unsalted password hashes quickly, made useless by unique salts.
Birthday attack
An attack that exploits the relative ease of finding any two inputs with the same hash value.
Side-channel attack
An attack that extracts secrets from physical behavior such as timing, power use or emissions rather than from the algorithm.
On-path attack
An attacker positioned between two parties to intercept or modify their traffic, also called man-in-the-middle.
Pass the hash
Authenticating with a stolen password hash instead of the password, possible with protocols such as NTLM.
Double extortion
A ransomware tactic that both encrypts data and threatens to publish stolen copies of it.
CPTED
Crime Prevention Through Environmental Design, using layout, lighting and landscaping to discourage crime.
Natural surveillance
The CPTED strategy of arranging spaces so activity is easily visible to others.
Territorial reinforcement
The CPTED strategy of using physical cues to show a space is owned and cared for.
Access control vestibule
A small space between two doors that admits one person at a time, also called a mantrap.
Tailgating
Following an authorized person through a controlled entrance without their knowledge.
Piggybacking
Entering a controlled area with an authorized person's consent but without your own authorization.
Deter, detect, delay, respond
The layered physical security sequence in which each barrier buys time for a response.
Brownout
A prolonged period of low voltage on the power supply.
Sag
A momentary drop in voltage.
Surge
A prolonged period of high voltage, compared with a spike, which is momentary.
Uninterruptible power supply (UPS)
Battery-backed equipment that keeps systems running through short outages and allows clean shutdown or transfer.
Pre-action sprinkler
A system that fills pipes only after detection and releases water only when a head also opens, reducing accidental discharge.
Clean agent
A gaseous fire suppressant that extinguishes fire without leaving residue or damaging electronics.
Positive pressurization
Keeping air pressure higher inside a room so air flows out, not in, when doors open.
Stakeholder requirements
The needs of everyone with an interest in a system, including security and privacy needs, captured before design.
Requirements analysis
Refining stakeholder needs into specific, testable system requirements.
Verification
Confirming the system was built correctly according to its specified requirements.
Validation
Confirming the system meets stakeholders' actual needs in its intended environment.
Authorization to operate
A formal management decision to accept residual risk and allow a system into production.
Operations and maintenance
The typically longest lifecycle phase, covering patching, monitoring, change control and reassessment.
Retirement
The planned end of a system's life, including data archiving, media sanitization and removal of access.

Domain 4: Communication & network security (13%)

Exam tips

Key terms

OSI model
A seven-layer reference model describing network communication from physical transmission to application services.
Encapsulation
Each layer adding its own header to data as it moves down the stack, removed in reverse at the receiver.
Three-way handshake
The SYN, SYN-ACK, ACK exchange TCP uses to establish a connection.
Frame
The layer 2 unit of data, addressed with MAC addresses.
Packet
The layer 3 unit of data, addressed with IP addresses.
Stateful inspection
Firewall filtering that tracks connection state, a primarily layer 4 capability.
Web application firewall (WAF)
A layer 7 control that inspects HTTP traffic for attacks such as injection.
NAT
Network address translation, mapping private internal addresses to public ones; it hides addressing but is not a firewall.
SLAAC
Stateless address autoconfiguration, the IPv6 method by which hosts assign their own addresses from router advertisements.
Forward secrecy
A property of key exchange ensuring that compromise of a long-term key does not expose past session keys.
Authentication Header (AH)
The IPsec protocol that provides integrity and origin authentication without encryption.
Encapsulating Security Payload (ESP)
The IPsec protocol that provides confidentiality as well as integrity and authentication.
Security association (SA)
A one-way IPsec agreement on keys and algorithms, negotiated by IKE.
SNMPv3
The version of SNMP that adds authentication, integrity and encryption.
Converged protocol
A protocol that carries specialized traffic such as storage or voice over standard IP or Ethernet networks.
iSCSI
A protocol that transports SCSI storage commands over TCP/IP networks.
FCoE
Fibre Channel over Ethernet, which carries Fibre Channel frames directly in Ethernet at layer 2 and is not IP-routable.
LUN masking
Storage-side access control that limits which hosts can see which logical storage units.
Zoning
Fabric-level control of which storage devices and hosts can communicate.
RDMA
Remote direct memory access, letting one system access another's memory without involving its processor.
SRTP
Secure Real-time Transport Protocol, which encrypts and authenticates voice and video media streams.
Micro-segmentation
Applying security policy to individual workloads so each can talk only to explicitly permitted peers.
Control plane
The part of networking that decides where traffic should go.
Data plane
The part of networking that forwards traffic according to control plane decisions.
SDN controller
The centralized component that programs network devices in a software-defined network.
VXLAN
An overlay that carries layer 2 frames inside UDP across layer 3 networks with a 24-bit segment ID.
Virtual private cloud (VPC)
A logically isolated customer network within a public cloud.
Software-defined perimeter (SDP)
An architecture that keeps applications hidden until a user and device authenticate and are authorized.
WPA3
The current Wi-Fi security generation, using SAE for personal networks and requiring protected management frames.
SAE
Simultaneous Authentication of Equals, a handshake that resists offline dictionary attacks and provides forward secrecy.
802.1X
Port-based network access control that authenticates users or devices, typically with RADIUS and EAP.
EAP-TLS
An EAP method using certificates on both client and server, the strongest common enterprise Wi-Fi option.
Evil twin
A malicious access point that impersonates a legitimate network to capture traffic or credentials.
Rogue access point
An unauthorized access point connected to an organization's network.
Bluesnarfing
Unauthorized access to data on a Bluetooth device.
Content distribution network (CDN)
A distributed set of edge servers that cache and serve content close to users.
Edge server
A CDN server near users that serves cached content and often applies security controls.
Origin server
The authoritative server that holds the original content a CDN caches.
North-south traffic
Traffic flowing between a data center or cloud environment and the outside world.
East-west traffic
Traffic flowing laterally between systems inside a data center or cloud environment.
Cache poisoning
Causing a cache to store and serve malicious or incorrect content.
Mutual TLS
TLS in which both client and server present certificates, often used to authenticate service-to-service traffic.
Stateful inspection firewall
A firewall that tracks connection state and permits return traffic only for established sessions.
Next-generation firewall (NGFW)
A firewall combining stateful inspection with application awareness, user identity and intrusion prevention.
IDS vs IPS
An IDS detects and alerts on suspicious activity, while an IPS sits inline and can block it.
Anomaly-based detection
Detection that flags deviations from a learned baseline, able to catch new attacks but prone to false positives.
Network access control (NAC)
Controls that authenticate devices and check their posture before and during network access.
Reverse proxy
An intermediary in front of servers that receives client requests and forwards them, often adding load balancing and TLS termination.
Endpoint detection and response (EDR)
Endpoint software that records activity and supports detection, investigation and response.
Toll fraud
Unauthorized use of an organization's phone system to place calls at its expense.
Split tunneling
A VPN configuration that sends only corporate traffic through the tunnel and other traffic directly to the internet.
Zero trust network access (ZTNA)
Remote access that grants authenticated users access to specific applications rather than the whole network.
TACACS+
A AAA protocol that runs over TCP, encrypts the full payload and separates authentication, authorization and accounting.
Interconnection security agreement (ISA)
A document that specifies the technical and security requirements for connecting two organizations' systems.
DMARC
An email policy mechanism that builds on SPF and DKIM to tell receivers how to handle unauthenticated mail from a domain.
DDoS
Distributed denial of service, an availability attack launched from many sources at once.
SYN flood
A protocol attack that sends many TCP connection requests without completing the handshake, exhausting state tables.
Amplification attack
Sending small spoofed requests to services that reply with much larger responses to the victim.
Ingress and egress filtering
Dropping inbound packets with internal source addresses and outbound packets with non-internal sources to reduce spoofing.
DNSSEC
Extensions that sign DNS records so resolvers can verify authenticity and integrity, without encrypting them.
HSTS
HTTP Strict Transport Security, a header that tells browsers to connect to a site only over HTTPS.
DNS tunneling
Hiding data or command traffic inside DNS queries and responses.
Observability
Collecting telemetry rich enough to answer unanticipated questions about system behavior.
Flow data
Summaries such as NetFlow or IPFIX that record endpoints, ports, timing and volume of conversations without full content.
Syslog
A standard for sending event messages from devices to a central collector.
Baseline
A measured picture of normal behavior against which deviations are detected.
NTP
Network Time Protocol, used to synchronize clocks so events can be correlated.
Capacity management
Trending and forecasting resource use so services stay available.
Out-of-band management
Administering devices over a separate network isolated from production traffic.

Domain 5: Identity & access management (13%)

Exam tips

Key terms

Subject
An active entity, such as a user, process or device, that requests access to an object.
Object
A passive resource, such as a file, system or room, that a subject accesses.
Least privilege
Granting only the minimum access needed to perform an assigned task.
Need to know
Restricting access to information required for a specific duty, regardless of clearance level.
Compensating control
An alternative control used when the primary control is not feasible, providing comparable protection.
Detective control
A control that identifies that an event has occurred, such as log review or a monitored camera.
Default deny
A policy that blocks all access not explicitly permitted.
Identification
Claiming an identity, for example by entering a username or presenting a badge.
Authentication
Proving a claimed identity with one or more factors.
Authorization
Determining what an authenticated subject is permitted to do.
Accountability
Tracing actions to a unique individual through identification and auditing.
Multifactor authentication (MFA)
Authentication using factors from two or more different categories.
FIDO2
A passwordless standard combining WebAuthn and CTAP that uses per-site key pairs and is phishing-resistant.
Passkey
A FIDO credential that can be synchronized across a user's devices and replaces a password.
Identity proofing
Verifying that a person is who they claim to be before issuing credentials.
Registration
Creating an identity record and account in a system.
Role
A collection of permissions representing a job function, assigned to users who perform it.
Role explosion
An unmanageable proliferation of narrowly defined roles.
AAA
Authentication, authorization and accounting, often centralized with RADIUS or TACACS+.
Session fixation
An attack in which a victim is made to use a session ID the attacker already knows, prevented by regenerating IDs at login.
Absolute session timeout
A maximum session lifetime after which reauthentication is required regardless of activity.
Identity provider (IdP)
The system that authenticates users and issues signed identity assertions or tokens.
Service provider (SP)
The application that relies on the IdP's assertion to grant access, called a relying party in OIDC.
SAML assertion
A signed XML statement from an IdP about a user's identity and attributes.
OAuth 2.0
An authorization framework for granting applications delegated, scoped access without sharing passwords.
Access token
A credential issued under OAuth that a client presents to an API to exercise granted scopes.
OpenID Connect (OIDC)
An authentication layer built on OAuth 2.0 that issues a signed ID token.
ID token
A signed JWT in OIDC that tells the relying party who the user is and who issued the token.
Credential
Anything a subject uses to prove identity, such as a password, key, token or certificate.
Password vault
A system that stores credentials encrypted and controls and logs their use.
Secrets manager
A service that supplies machine credentials to applications at runtime and rotates them.
Hardware security module (HSM)
Tamper-resistant hardware that generates, stores and uses cryptographic keys.
Single sign-on (SSO)
Authenticating once to gain access to multiple systems through tickets or tokens.
Password synchronization
Keeping the same password on multiple systems, which the user still enters separately on each.
Step-up authentication
Requiring additional authentication before a higher-risk action or application.
Privileged access management (PAM)
Processes and tools that discover, vault, limit and monitor privileged accounts.
Standing privilege
Elevated rights that remain assigned at all times whether or not they are in use.
Just-in-time (JIT) access
Granting elevated rights only when needed, for a limited time, and removing them automatically.
Just-enough administration
Limiting elevation to the specific commands or resources a task requires.
Session brokering
Connecting users to privileged systems through a proxy so they never see the underlying credential.
Privileged access workstation
A hardened device used only for administrative tasks.
Break-glass account
A tightly controlled emergency account used when normal access mechanisms fail.
Discretionary access control (DAC)
A model in which object owners decide who may access their objects, typically via ACLs.
Mandatory access control (MAC)
A model in which the system enforces access based on labels and clearances that users cannot change.
Role-based access control
A non-discretionary model that grants permissions through roles representing job functions.
Rule-based access control
A model that applies global rules, such as time or address conditions, to all subjects.
Attribute-based access control (ABAC)
A model that evaluates policies combining subject, object, action and environment attributes.
Risk-based access control
Adaptive authorization that adjusts decisions based on a real-time risk score.
Security label
A classification and compartment marking used by MAC to make access decisions.
Joiner, mover, leaver (JML)
The lifecycle stages of hiring, transfer and departure that drive access changes.
Provisioning
Creating accounts and granting approved access to a new or changed identity.
Deprovisioning
Disabling or removing access when it is no longer needed.
Privilege creep
Gradual accumulation of excess access as people change roles without old rights being removed.
Access review (recertification)
A periodic check by managers or owners that each person's access is still appropriate.
Orphaned account
An account with no current owner, such as one belonging to a departed employee.
Authoritative source
The system of record, often HR, that triggers identity lifecycle changes.
Key distribution center (KDC)
The trusted Kerberos authority that contains the authentication service and ticket-granting service.
Ticket-granting ticket (TGT)
A Kerberos ticket issued at login and used to obtain service tickets without re-entering credentials.
Service ticket
A Kerberos ticket that authenticates a user to a specific service.
Golden ticket
A forged TGT created with a stolen KDC signing key, granting broad access.
RADIUS
A UDP-based AAA protocol for network access that encrypts only the password field.
TACACS+
A TCP-based AAA protocol that encrypts the full payload and separates authentication, authorization and accounting.
Time skew
Clock difference between systems, which can cause Kerberos authentication to fail.
Password spraying
Trying a few common passwords across many accounts to avoid lockout thresholds.
Credential stuffing
Replaying username and password pairs leaked from other breaches against new sites.
False rejection rate (FRR)
The Type I error rate at which legitimate users are wrongly denied.
False acceptance rate (FAR)
The Type II error rate at which impostors are wrongly accepted.
Crossover error rate (CER)
The point where FAR equals FRR, used to compare biometric accuracy; lower is better.
Liveness detection
Techniques that confirm a biometric sample comes from a live person rather than a fake.
Biometric template
The stored mathematical representation of enrolled biometric features.

Domain 6: Security assessment & testing (12%)

Exam tips

Key terms

Security test
A procedure that verifies whether a specific control works as intended.
Security assessment
A broad review of a system or environment to identify risks and weaknesses.
Audit
A formal, independent evaluation against defined criteria that results in an opinion or attestation.
Internal audit
Assessment by the organization's own staff, ideally reporting independently to the audit committee.
External audit
An audit performed by an outside firm engaged by the organization.
Third-party audit
An audit performed by or on behalf of another party, such as a customer or regulator.
SOC report
A System and Organization Controls report in which an independent auditor attests to a service organization's controls.
Vulnerability assessment
Identifying and prioritizing known weaknesses, usually with automated scanning.
Penetration test
An authorized attempt to exploit weaknesses to demonstrate real impact.
Credentialed scan
A scan that logs in to systems to inspect software and configuration more accurately.
False negative
A real vulnerability that a test fails to detect.
Rules of engagement (RoE)
The written agreement defining a test's scope, methods, timing, contacts and data handling.
Black-box test
A zero-knowledge test in which testers start with little or no information about the target.
White-box test
A full-knowledge test in which testers receive documentation, code and credentials.
Log review
Examining event records to identify policy violations, errors and signs of attack.
SIEM
Security information and event management, a platform that centralizes and correlates logs and alerts.
Clipping level
A threshold of activity below which events are not flagged, used to reduce noise.
Statistical sampling
Selecting records randomly so that conclusions about the whole set can be drawn.
Synthetic transaction
A scripted, scheduled simulation of user activity used to verify function, performance and security behavior.
Real user monitoring (RUM)
Passive observation of the experience of actual users.
Breach and attack simulation (BAS)
Automated, continuous safe execution of attacker techniques to validate prevention and detection.
Static application security testing (SAST)
Analysis of source code, bytecode or binaries for vulnerabilities without running the program.
Dynamic application security testing (DAST)
Testing a running application from the outside by sending requests and analyzing responses.
Fuzzing
Supplying large volumes of malformed or random input to a running program to trigger crashes and errors that reveal flaws.
Misuse case
A scenario describing how an attacker or careless user could abuse a feature, used to design negative tests.
Test coverage analysis
Measurement of how much code, such as statements or branches, was exercised by tests.
Interface testing
Testing the connection points between components, such as APIs and user interfaces, for input handling, authorization and error handling.
Fagan inspection
A formal, structured code review process with defined roles and stages.
Compliance
Conformity with a defined set of requirements from laws, regulations, contracts, frameworks or internal policy.
Configuration compliance scan
An automated comparison of a system's settings against an approved baseline or benchmark.
Security Content Automation Protocol (SCAP)
A NIST suite of specifications that standardizes how security checks, configurations and results are expressed.
Cloud security posture management (CSPM)
Tools that continuously check cloud accounts and resources against security and compliance policy.
Control matrix
A mapping of each requirement to the control that satisfies it, its owner and the evidence that proves it.
Compensating control
An alternative control that reduces risk when a required control cannot be implemented as specified.
Key performance indicator (KPI)
A metric showing how well a process or control is performing against a defined goal.
Key risk indicator (KRI)
A forward-looking metric that warns when risk is rising toward or beyond the organization's appetite.
Orphaned account
An account whose owner has left or can no longer be identified, but which remains active.
Management review
Documented oversight by leadership of security metrics, risks, findings and decisions.
Test restore
Recovering data from backup to confirm it is complete, usable and restorable within the required time.
Recovery time objective (RTO)
The target time within which a system or function must be restored after disruption.
False positive
A finding that reports a vulnerability or problem that does not actually exist.
Common Vulnerability Scoring System (CVSS)
A standard for rating the technical severity of vulnerabilities on a numeric scale.
Executive summary
The part of a report that states overall risk, key findings and needed decisions in business language.
Exception
A formal, documented, time-limited approval to operate without meeting a requirement, usually with compensating controls.
Remediation
The action taken to fix a finding, verified by retesting.
Risk register
A record of identified risks, their owners, ratings, treatments and accepted exceptions.
SOC 1
An attestation report on a service organization's controls relevant to customers' internal control over financial reporting.
SOC 2
A detailed, restricted-use attestation report on controls for security, availability, processing integrity, confidentiality and privacy.
SOC 3
A general-use summary report on the same Trust Services Criteria as SOC 2, without detailed test results.
Type I report
An opinion on the design of controls at a specific point in time.
Type II report
An opinion on the design and operating effectiveness of controls over a period of time.
Trust Services Criteria
The AICPA criteria of security, availability, processing integrity, confidentiality and privacy used in SOC 2 and SOC 3.
Complementary user entity controls (CUECs)
Controls the customer must operate for the service provider's controls to be effective.
Shared responsibility model
The division of security duties between a cloud provider and its customer, which shifts across IaaS, PaaS and SaaS.
Third-party attestation
An independent auditor's report or certification, such as SOC 2 or ISO/IEC 27001, that customers rely on instead of auditing a provider themselves.
Right-to-audit clause
A contract term defining the customer's right to audit or receive evidence of a provider's controls.
Data residency
The requirement or practice of storing and processing data in specific geographic locations or jurisdictions.
Cloud Controls Matrix (CCM)
A Cloud Security Alliance framework of cloud security controls used to assess and compare providers.

Domain 7: Security operations (13%)

Exam tips

Key terms

Chain of custody
The documented record of every person who handled evidence, when, and for what purpose, from collection to presentation.
Order of volatility
The practice of collecting the most short-lived data, such as memory, before more persistent data such as disk contents.
Write blocker
A hardware or software device that allows reading from storage media while preventing any writes to it.
Forensic image
A bit-for-bit copy of storage media, verified by hash, used for analysis instead of the original.
Best evidence rule
A legal principle that prefers original documents over copies as evidence.
Enticement
Offering an opportunity to someone already inclined to commit an offense, which is generally legal, unlike entrapment.
Security information and event management (SIEM)
A system that collects, normalizes, stores and correlates logs from many sources to detect security events.
Security orchestration, automation and response (SOAR)
A platform that runs automated playbooks across security tools to speed and standardize response.
User and entity behavior analytics (UEBA)
Analytics that baseline normal behavior of users and devices and flag anomalies.
Continuous monitoring
Ongoing observation of controls, configurations and threats to support risk-based decisions.
Indicator of compromise (IOC)
An observable artifact, such as a file hash or malicious domain, that suggests a system has been compromised.
Threat hunting
A proactive, hypothesis-driven search for attackers who have evaded existing detections.
Alert fatigue
Desensitization of analysts caused by excessive, often false, alerts, leading to missed real incidents.
Configuration management (CM)
The process of establishing and maintaining systems in a known, approved and secure state.
Configuration item (CI)
A component tracked under configuration management, such as a server, application or setting.
Configuration management database (CMDB)
A repository of configuration items, their attributes and their relationships.
Baseline
The approved minimum secure configuration for a type of system, also used as a reference to detect drift.
Golden image
A hardened, approved system image used to provision new systems consistently.
Configuration drift
Divergence of a system's actual configuration from its approved baseline.
Immutable infrastructure
An approach in which running systems are replaced from updated images rather than modified in place.
Need to know
Restricting access to specific information to people whose current duties require it.
Least privilege
Granting only the minimum rights and permissions, for the minimum time, needed to perform a function.
Separation of duties
Dividing a sensitive task among multiple people so no single person can complete it alone.
Collusion
Two or more people cooperating to bypass controls such as separation of duties.
Job rotation
Periodically moving staff between roles to cross-train and to help detect fraud.
Privilege creep
The gradual accumulation of access rights as a person changes roles without old rights being removed.
Service level agreement (SLA)
A formal agreement defining the level of service a provider commits to and the remedies if targets are missed.
Data remanence
Residual data that remains on media after deletion or formatting and may be recoverable.
Clearing
Sanitization using logical techniques such as overwriting, protecting against simple non-invasive recovery.
Purging
Sanitization using stronger methods, such as cryptographic erase or degaussing, that protect against laboratory recovery.
Destruction
Physically rendering media unusable through shredding, disintegration, pulverizing or incineration.
Degaussing
Erasing magnetic media with a strong magnetic field; it does not work on SSDs or optical media.
3-2-1 backup rule
Keeping at least three copies of data on two types of media with one copy offsite.
Immutable backup
A backup copy that cannot be modified or deleted for a set period, protecting it from ransomware.
Event
Any observable occurrence in a system or network.
Incident
An event or series of events that actually or potentially harms confidentiality, integrity or availability, or violates policy.
Triage
Rapid assessment of an incident to determine its validity, severity and priority.
Containment (mitigation)
Actions that limit the spread and impact of an incident, such as isolating hosts or disabling accounts.
Recovery
Restoring affected systems and data to normal operation.
Remediation
Fixing the root cause so the incident cannot recur the same way.
Lessons learned
A post-incident review that identifies improvements to controls, plans and training.
Stateful inspection firewall
A firewall that tracks connection state and allows return traffic for established sessions.
Intrusion detection system (IDS)
A passive, detective control that monitors activity and alerts on suspected attacks.
Intrusion prevention system (IPS)
An inline, preventive control that can block traffic it identifies as malicious.
Allow list
A list of explicitly approved items, with everything else denied by default.
Sandbox
An isolated environment for safely running and observing suspicious code.
Honeypot
A decoy system with no legitimate use, so any interaction signals suspicious activity.
Endpoint detection and response (EDR)
Endpoint software that records activity, detects attacker techniques and supports response actions.
Vulnerability management
The continuous cycle of discovering, prioritizing, remediating and verifying weaknesses.
Authenticated scan
A vulnerability scan that logs in to systems to see installed software and settings, giving more accurate results.
Patch management
The process of acquiring, testing, approving, deploying and verifying software updates.
Zero-day vulnerability
A flaw that is exploited before a vendor fix is available.
Change advisory board (CAB)
The group that reviews and approves or rejects significant changes.
Emergency change
A change implemented quickly to address an urgent issue, documented and reviewed after the fact.
Rollback plan
Documented steps to return a system to its previous state if a change fails.
Recovery time objective (RTO)
The target time within which a function or system must be restored after disruption.
Recovery point objective (RPO)
The maximum acceptable amount of data loss, measured as time since the last good copy.
Maximum tolerable downtime (MTD)
The longest a function can be unavailable before the organization suffers unacceptable harm.
Incremental backup
A backup of data changed since the last backup of any type, which clears the archive bit.
Differential backup
A backup of data changed since the last full backup, which does not clear the archive bit.
Hot site
A fully equipped alternate site with current data that can take over within hours or less.
Remote journaling
Frequently transmitting transaction logs offsite so a database can be restored by replaying them.
Disaster recovery plan (DRP)
The documented procedures for restoring IT systems and data after a disruptive event.
Read-through (checklist) test
Individual review of the plan to confirm it is accurate, complete and current.
Walkthrough (tabletop) test
A group discussion of a disaster scenario, stepping through the plan to find gaps.
Simulation test
A more detailed scenario exercise that may practice procedures without moving production.
Parallel test
Bringing up systems at the recovery site and processing data while the primary site continues production.
Full-interruption test
Shutting down the primary site and moving operations entirely to the recovery site.
Salvage team
The team responsible for assessing and restoring the primary site after a disaster.
Business continuity planning (BCP)
Planning to keep critical business functions operating during and after a disruption.
Crime prevention through environmental design (CPTED)
Using building and landscape design, such as lighting and sight lines, to deter crime.
Mantrap (access control vestibule)
A small space with two interlocking doors that allows only one authorized person through at a time.
Fail-safe
A design in which a failure leaves a system in a state that protects people, such as doors unlocking on power loss.
Fail-secure
A design in which a failure leaves a system locked or closed to protect assets.
Duress code
A covert signal, such as a special PIN, that lets a person under threat alert security while appearing to comply.
Occupant emergency plan
A plan describing how building occupants evacuate or shelter during an emergency.

Domain 8: Software development security (10%)

Exam tips

Key terms

Software development lifecycle (SDLC)
The structured process for planning, building, testing, deploying, operating and retiring software.
Waterfall
A sequential development model in which each phase is completed before the next begins.
Spiral model
An iterative model that repeats planning, risk analysis, engineering and evaluation in each loop.
Agile
An iterative approach that delivers working software in short sprints and adapts to change.
DevSecOps
Integrating security practices and automation into DevOps as a shared responsibility.
Shift left
Moving security activities earlier in the development lifecycle.
Definition of done
The agreed criteria, which can include security checks, that work must meet to be considered complete.
Capability Maturity Model (CMM)
A five-level model describing process maturity from initial to optimizing.
Capability Maturity Model Integration (CMMI)
The successor to CMM that integrates process improvement across disciplines.
Software Assurance Maturity Model (SAMM)
An open OWASP framework for assessing and improving software security practices across five business functions.
Building Security In Maturity Model (BSIMM)
A descriptive model reporting the software security activities organizations actually perform.
Optimizing level
The highest CMM level, focused on continuous process improvement.
Regression testing
Testing after a change to confirm that previously working functions still work.
Integrated product team (IPT)
A cross-functional team that includes all disciplines needed to deliver a product, including security.
Security champion
A team member with extra security training who acts as the team's first point of contact for security.
Software supply chain
All the components, tools, services and people involved in producing and delivering software.
Software bill of materials (SBOM)
An inventory of the components and dependencies that make up a piece of software.
Threat modeling
A structured analysis of how a system could be attacked and which controls are needed.
Development ecosystem
The people, tools, infrastructure and suppliers used to build and deliver software.
Memory-safe language
A language that prevents or manages memory errors such as buffer overflows by design.
Software composition analysis (SCA)
Tooling that identifies third-party components and their known vulnerabilities and licenses.
Dependency confusion
An attack in which a public package with the same name as an internal one is fetched by the build instead.
Branch protection
Repository rules that require reviews or checks before changes are merged into important branches.
Secrets manager
A service that stores and issues credentials and keys securely instead of embedding them in code.
Continuous integration and continuous delivery (CI/CD)
Automated pipelines that build, test and deploy code changes.
Artifact signing
Digitally signing build outputs so their origin and integrity can be verified before deployment.
Static application security testing (SAST)
White-box analysis of source code, bytecode or binaries without running the program.
Dynamic application security testing (DAST)
Black-box testing of a running application by sending requests and analyzing responses.
Interactive application security testing (IAST)
Instrumentation inside a running application that observes execution during testing to confirm vulnerabilities.
Runtime application self-protection (RASP)
Instrumentation in a production application that detects and blocks attacks from within.
Transitive dependency
A component your application depends on indirectly, through another dependency.
Source and sink
In data-flow analysis, the point where untrusted input enters and the sensitive operation it may reach.
Process audit
A review of whether required development and security practices were actually followed, often by sampling.
Security log
A record of security-relevant events capturing who, what, when, where and outcome.
Log injection
Inserting crafted input into logs to forge entries or mislead analysis, prevented by encoding logged input.
STRIDE
A threat classification: spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege.
Residual risk
The risk that remains after controls are applied, which must be formally accepted by an owner.
Vulnerability density
The number of vulnerabilities relative to the size of the codebase or application, used to compare and trend quality.
Commercial off-the-shelf (COTS)
Software bought from a vendor for general use, typically without access to source code.
Source code escrow
An arrangement in which a third party holds a vendor's source code for release to the customer under agreed conditions, such as vendor failure.
Shared responsibility model
The division of security duties between a cloud provider and customer, varying across IaaS, PaaS and SaaS.
Infrastructure as a service (IaaS)
A cloud model providing virtual compute, storage and networks, with the customer managing operating systems and above.
Platform as a service (PaaS)
A cloud model providing a managed platform and runtime on which the customer deploys its code.
Software as a service (SaaS)
A cloud model providing a complete application, with the customer managing data, users and configuration.
Due diligence
The investigation and assessment performed before and during a relationship to understand and manage its risks.
Common Weakness Enumeration (CWE)
A catalog of software and hardware weakness types, including a list of the most dangerous.
Input validation
Checking that input matches expected type, length, format and range, ideally against an allow list on the server.
Output encoding
Converting data so it is treated as data, not code, in the context where it is displayed or used.
Parameterized query
A database query in which user input is passed separately from the SQL text, preventing injection.
Broken object-level authorization (BOLA)
An API flaw in which the server returns objects without checking that the caller may access them.
Maintenance hook
An undocumented entry point left in code that bypasses normal security controls.
Fail securely
Designing errors to deny access by default and reveal minimal information.
Software-defined networking (SDN)
An architecture that separates the network control plane from the data plane so traffic is managed centrally through software.
Control plane
The layer that makes decisions about policy and traffic flow.
Data plane
The layer that forwards traffic according to the control plane's instructions.
Micro-segmentation
Fine-grained security policy between individual workloads to limit lateral movement.
Policy as code
Security and compliance rules written in machine-readable form so they can be versioned and tested automatically.
Software-defined perimeter (SDP)
An approach that hides services until users and devices are authenticated and authorized, creating per-session access.
Injection
A flaw where untrusted input is interpreted as part of a command or query.
Cross-site scripting (XSS)
A flaw that lets attacker-supplied script run in a victim's browser in the context of a trusted site.
Cross-site request forgery (CSRF)
An attack that makes an authenticated user's browser send an unwanted request to a trusting site.
Buffer overflow
Writing more data into a memory buffer than it can hold, overwriting adjacent memory.
Time-of-check to time-of-use (TOCTOU)
A race condition where a condition changes between being checked and being used.
Insecure deserialization
Rebuilding objects from untrusted serialized data in a way that allows manipulation or code execution.
Content Security Policy (CSP)
A browser security header that restricts where scripts and other content may load from, limiting XSS impact.
Study CISSP for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the CISSP study plan