CISSP Glossary: The 40 Terms You Must Know
A plain-English CISSP glossary of the 40 most tested terms - from ALE, BCP and COBIT to TPM, X.509 and zero trust - grouped by domain.
CISSP glossary · 10 min read · updated 2026-09-05
The CISSP speaks a management-level dialect of security: risk and governance vocabulary layered over technical depth. These forty terms are the ones the exam leans on most heavily.
Risk, governance and assets
Asset - anything of value to the organisation: data, systems, people, reputation. Vulnerability - a weakness; Threat - a potential danger that could exploit it; Risk - the probability times impact of that exploitation, and the only one of the three you manage directly. Residual risk - what remains after controls; the board, not the analyst, accepts it. ALE, SLE and ARO - annualized loss expectancy = single loss expectancy x annual rate of occurrence, the exam's recurring calculation.
BIA - business impact analysis, the study identifying critical processes, their RTO and RPO, feeding BCP and DRP. BCP/DRP - business continuity planning and disaster recovery planning, strategy versus technical execution. Control types - preventive, detective, corrective, deterrent, recovery, compensating, directive: know all seven by heart and classify examples fast. Gap analysis - current state versus framework target. Exposure factor - the percentage of an asset lost in one incident, feeding the SLE.
Architecture, crypto and networks
TPM - trusted platform module, hardware root of trust for keys and boot integrity. HSM - dedicated hardware for cryptographic operations at scale. X.509 - the certificate standard underpinning PKI: CA, RA, CRL and OCSP. Kerberos - ticket-based authentication protocol at the heart of Active Directory. Salting and key stretching - defeating rainbow tables for stored passwords. Bell-LaPadula - confidentiality model (no read up, no write down); Biba - integrity (no read down, no write up); Clark-Wilson - well-formed transactions; Brewer-Nash - conflict of interest.
SASE - secure access service edge, converging network and security as cloud service. SD-WAN and micro-segmentation - modern edge and internal segmentation. Zero trust - continuous verification replacing perimeter trust. Data states - at rest, in transit, in use; each has its own crypto answer. Data classification - public, internal, confidential, restricted: drives every control decision downstream.
Operations, IAM and software security
SOC - security operations centre. SIEM - centralised log correlation and alerting. DLP - data loss prevention. IAM - identity and access management: provisioning, review, deprovisioning. IAAA - identification, authentication, authorisation, accountability, the access lifecycle. Least privilege and need to know - the two principles every access question bends toward. Separation of duties - no single person controls a full sensitive workflow.
SDLC security - security requirements, threat modelling (STRIDE), code review, SAST and DAST woven into development. Change management - the control that prevents unreviewed changes from becoming incidents. Forensic terms - order of volatility, chain of custody, legal hold. CPTED - crime prevention through environmental design, the physical security vocabulary the exam occasionally tests.
Frequently asked questions
- How many terms should I memorise for the CISSP?
- The (ISC)2 official outline references hundreds, but roughly 40-60 anchor terms generate most scenario questions. Learn each as a definition in your own words plus the decision rule it implies - CISSP asks what a manager would do, not what an acronym expands to.
- Do I need to memorise security models for the CISSP?
- Yes: Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash, plus state machine models appear in domain 3 questions. Know the rule each enforces (no read up/write down for confidentiality, no read down/write up for integrity) and the situation each fits.
- Where can I drill CISSP terms with real questions?
- The PassYour CISSP track includes the full question bank with explanations mapped to the eight domains, structured lessons per domain and timed mock exams - and the free online CISSP quiz covers the most common terms to start.
Keep reading for CISSP
PassYour is an independent study aid and is not affiliated with, endorsed by or sponsored by ISC2, CompTIA or Microsoft.
