Free knowledge base

ISC2 CISSP (Certified Information Systems Security Professional) — key terms, tricks & tips

Everything from the course in one searchable place: 391 entries. Use it to review before a practice test or look up a word you forgot.

391 results · showing first 300, refine your search

Key term

CAT Exam

Computerized Adaptive Testing; adjusts question difficulty based on answers.

Getting Started: CISSP Exam Essentials

Key term

Domain Weighting

Percentage of exam questions allocated to a specific knowledge area.

Getting Started: CISSP Exam Essentials

Key term

Linear Exam

Fixed set of questions, allows review, used for non-English CISSP.

Getting Started: CISSP Exam Essentials

Key term

Pre-test Items

Unscored questions used to evaluate for future exams.

Getting Started: CISSP Exam Essentials

Key term

Passing Score

Minimum 700 out of 1000 points required to pass CISSP.

Getting Started: CISSP Exam Essentials

Key term

ISC2

International Information System Security Certification Consortium.

Getting Started: CISSP Exam Essentials

Memory trick

CISSP Exam Structure and Format

Remember the 8 domains with 'SAM Can't See All Secure Software Dev'. (Security & Risk, Asset, Comm & Net, Security Arch & Eng, Identity & Access, Security Assess & Test, Security Ops, Software Dev Security)

Getting Started: CISSP Exam Essentials

Exam tip

CISSP Exam Structure and Format

The CISSP exam for English candidates is 100-150 questions, 3 hours, and uses CAT. For non-English candidates, it is 250 questions, 6 hours, and is linear. The passing score is 700/1000 for all versions.

Getting Started: CISSP Exam Essentials

Common mistake

CISSP Exam Structure and Format

Assuming all questions count towards your score; some are pre-test items.

Getting Started: CISSP Exam Essentials

Common mistake

CISSP Exam Structure and Format

Trying to guess the difficulty of questions to determine if you are doing well; focus on each question individually.

Getting Started: CISSP Exam Essentials

Common mistake

CISSP Exam Structure and Format

Not allocating study time according to domain weighting; this can lead to under-preparation in critical areas.

Getting Started: CISSP Exam Essentials

Key term

CBK

Common Body of Knowledge; the comprehensive framework of topics for the CISSP exam.

Getting Started: CISSP Exam Essentials

Key term

Domain

A major functional area of information security within the CISSP CBK.

Getting Started: CISSP Exam Essentials

Key term

Official Study Guide

The primary textbook published by ISC2 for CISSP exam preparation.

Getting Started: CISSP Exam Essentials

Key term

Practice Tests

Simulated exam questions used to assess knowledge and familiarize with format.

Getting Started: CISSP Exam Essentials

Key term

Study Plan

A structured schedule outlining topics, resources, and timelines for exam preparation.

Getting Started: CISSP Exam Essentials

Key term

Managerial Thinking

An approach to exam questions prioritizing risk, business impact, and policy over technical details.

Getting Started: CISSP Exam Essentials

Memory trick

Effective Study Strategies and Resources for CISSP

To remember key study steps: 'Assess, Plan, Resource, Practice, Review' – APRPR. Like 'April's Pretty Radiant, Right?'

Getting Started: CISSP Exam Essentials

Exam tip

Effective Study Strategies and Resources for CISSP

The exam often tests your ability to apply concepts, not just recall facts. Look for keywords like 'MOST effective,' 'BEST course of action,' or 'FIRST step.' These indicate a need for critical thinking and often a managerial perspective, prioritizing business objectives and risk management.

Getting Started: CISSP Exam Essentials

Common mistake

Effective Study Strategies and Resources for CISSP

Focusing too heavily on technical details without understanding the managerial and risk-based implications.

Getting Started: CISSP Exam Essentials

Common mistake

Effective Study Strategies and Resources for CISSP

Relying on only one study resource, missing out on diverse perspectives and question styles.

Getting Started: CISSP Exam Essentials

Common mistake

Effective Study Strategies and Resources for CISSP

Neglecting weaker domains, assuming strong areas will compensate for deficiencies.

Getting Started: CISSP Exam Essentials

Key term

Confidentiality

Protecting information from unauthorized disclosure.

Foundations of Security & Risk Management

Key term

Integrity

Ensuring information is accurate, complete, and unaltered.

Foundations of Security & Risk Management

Key term

Availability

Ensuring authorized access to information and systems when needed.

Foundations of Security & Risk Management

Key term

Security Governance

Framework for strategic security direction and oversight.

Foundations of Security & Risk Management

Key term

Ethics

Moral principles guiding professional conduct in security.

Foundations of Security & Risk Management

Key term

Non-Repudiation

Assurance that an action or event cannot be denied later.

Foundations of Security & Risk Management

Key term

Authenticity

Verifying the identity of a user or the origin of data.

Foundations of Security & Risk Management

Memory trick

CIA Triad, Security Governance & Ethics

Remember 'CIA' for 'Confidentiality, Integrity, Availability' – the core 'C'omponents 'I'n 'A'ny security system.

Foundations of Security & Risk Management

Exam tip

CIA Triad, Security Governance & Ethics

The exam often tests your ability to identify which part of the CIA triad is violated in a given scenario. For example, a DDoS attack impacts Availability, while unauthorized data viewing impacts Confidentiality.

Foundations of Security & Risk Management

Common mistake

CIA Triad, Security Governance & Ethics

Confusing Integrity with Confidentiality: Integrity is about data accuracy and completeness, not just secrecy.

Foundations of Security & Risk Management

Common mistake

CIA Triad, Security Governance & Ethics

Underestimating the importance of Availability: Downtime can be as damaging as a data breach.

Foundations of Security & Risk Management

Common mistake

CIA Triad, Security Governance & Ethics

Ignoring the role of ethics: Technical skills alone are insufficient without strong moral principles.

Foundations of Security & Risk Management

Key term

Compliance

Adherence to rules, laws, regulations, or standards.

Foundations of Security & Risk Management

Key term

Policy

High-level, mandatory statements of management's intent.

Foundations of Security & Risk Management

Key term

Standard

Mandatory, specific technical or configuration requirements.

Foundations of Security & Risk Management

Key term

Procedure

Detailed, step-by-step instructions for performing a task.

Foundations of Security & Risk Management

Key term

Guideline

Recommendations or best practices; not mandatory.

Foundations of Security & Risk Management

Key term

GDPR

EU regulation for data protection and privacy.

Foundations of Security & Risk Management

Key term

HIPAA

US law protecting health information privacy and security.

Foundations of Security & Risk Management

Key term

Regulatory Framework

Rules established by regulatory bodies in an industry.

Foundations of Security & Risk Management

Memory trick

Compliance, Legal, Regulatory & Policies

P.S.P.G. - Policies Set Procedures and Guidelines. (Remember Standards fit in between Policies and Procedures in detail level).

Foundations of Security & Risk Management

Exam tip

Compliance, Legal, Regulatory & Policies

Memorize the hierarchy: Laws/Regulations > Policies > Standards > Procedures > Guidelines. The exam often tests your ability to distinguish between these levels of documentation and their mandatory nature.

Foundations of Security & Risk Management

Common mistake

Compliance, Legal, Regulatory & Policies

Confusing a guideline (recommendation) with a standard (mandatory specification).

Foundations of Security & Risk Management

Common mistake

Compliance, Legal, Regulatory & Policies

Underestimating the importance of legal counsel in incident response and policy development.

Foundations of Security & Risk Management

Common mistake

Compliance, Legal, Regulatory & Policies

Failing to regularly review and update policies, making them obsolete or ineffective.

Foundations of Security & Risk Management

Key term

Risk

The potential for loss, damage, or destruction of an asset.

Foundations of Security & Risk Management

Key term

Threat

A potential danger that might exploit a vulnerability.

Foundations of Security & Risk Management

Key term

Vulnerability

A weakness that can be exploited by a threat.

Foundations of Security & Risk Management

Key term

Risk Appetite

The amount of risk an organization is willing to accept.

Foundations of Security & Risk Management

Key term

Risk Mitigation

Reducing the likelihood or impact of a risk.

Foundations of Security & Risk Management

Key term

Threat Modeling

Structured approach to identify and address security risks.

Foundations of Security & Risk Management

Key term

Supply Chain Risk

Risks introduced by third-party vendors or partners.

Foundations of Security & Risk Management

Memory trick

Risk Management, Threat Modeling & Supply Chain

To remember the four risk treatment strategies, think of 'A.A.M.T.' - Alligators Always Make Trouble!

Foundations of Security & Risk Management

Exam tip

Risk Management, Threat Modeling & Supply Chain

The CISSP exam frequently tests your understanding of risk treatment strategies. Remember the four main strategies: Accept, Avoid, Mitigate, and Transfer. Be able to differentiate between them and provide examples of each.

Foundations of Security & Risk Management

Common mistake

Risk Management, Threat Modeling & Supply Chain

Confusing a threat with a vulnerability (a threat exploits a vulnerability).

Foundations of Security & Risk Management

Common mistake

Risk Management, Threat Modeling & Supply Chain

Believing all risks must be eliminated (risk management aims for acceptable risk levels).

Foundations of Security & Risk Management

Common mistake

Risk Management, Threat Modeling & Supply Chain

Neglecting supply chain risks, assuming third-party security is always adequate.

Foundations of Security & Risk Management

Key term

Business Continuity (BC)

Maintaining critical business functions during disruptions.

Foundations of Security & Risk Management

Key term

Disaster Recovery (DR)

Restoring IT systems after a major incident.

Foundations of Security & Risk Management

Key term

Recovery Time Objective (RTO)

Max tolerable time for system downtime.

Foundations of Security & Risk Management

Key term

Recovery Point Objective (RPO)

Max tolerable data loss period.

Foundations of Security & Risk Management

Key term

Hot Site

Fully equipped, ready-to-use recovery facility.

Foundations of Security & Risk Management

Key term

Warm Site

Partially equipped recovery facility, needs setup.

Foundations of Security & Risk Management

Key term

Cold Site

Basic infrastructure recovery facility, needs significant setup.

Foundations of Security & Risk Management

Key term

Personnel Security

Managing human risk throughout employment lifecycle.

Foundations of Security & Risk Management

Memory trick

Business Continuity, Disaster Recovery, & Personnel

BC/DR: Business Continues, Disasters Recover. Think of BC as the CEO's concern, DR as the CIO's concern.

Foundations of Security & Risk Management

Exam tip

Business Continuity, Disaster Recovery, & Personnel

On the CISSP exam, distinguish BC from DR by their scope: BC is business-focused, DR is IT-focused. Memorize RTO (time) and RPO (data loss) definitions and their implications for recovery strategies. Understand the phases of personnel security (pre-employment, employment, termination).

Foundations of Security & Risk Management

Common mistake

Business Continuity, Disaster Recovery, & Personnel

Confusing RTO and RPO: RTO is about time, RPO is about data loss. Don't mix them up!

Foundations of Security & Risk Management

Common mistake

Business Continuity, Disaster Recovery, & Personnel

Treating BC and DR as interchangeable: They are distinct plans with different objectives, though related.

Foundations of Security & Risk Management

Common mistake

Business Continuity, Disaster Recovery, & Personnel

Neglecting personnel security after hiring: It's an ongoing process, not just a one-time check.

Foundations of Security & Risk Management

Key term

Information Classification

Categorizing data by sensitivity, value, and criticality.

Protecting Information Assets

Key term

Data Owner

Senior manager accountable for data protection and classification.

Protecting Information Assets

Key term

Data Custodian

Implements and maintains security controls as directed by owner.

Protecting Information Assets

Key term

Data User

Individual who accesses data to perform their job duties.

Protecting Information Assets

Key term

Confidential

Classification for highly sensitive business or personal data.

Protecting Information Assets

Key term

Private

Classification often used for personally identifiable information (PII).

Protecting Information Assets

Key term

Public

Classification for data intended for general public consumption.

Protecting Information Assets

Key term

Data Steward

Ensures data quality, defines data elements, and implements policies.

Protecting Information Assets

Memory trick

Information & Asset Classification and Ownership

O.C.U.S.T. - Owners Classify, Users Store, Custodians Take care. (Okay, the 'U' is a stretch, but it helps remember the roles!)

Protecting Information Assets

Exam tip

Information & Asset Classification and Ownership

The CISSP exam frequently tests your understanding of roles. Remember: the Data Owner is ultimately ACCOUNTABLE for the data, while the Data Custodian is RESPONSIBLE for its technical protection. Look for questions distinguishing between these accountabilities.

Protecting Information Assets

Common mistake

Information & Asset Classification and Ownership

Confusing the Data Owner's accountability with the Data Custodian's responsibility. The owner is the decider, the custodian is the doer.

Protecting Information Assets

Common mistake

Information & Asset Classification and Ownership

Applying a 'one-size-fits-all' security approach without proper classification, leading to either over-spending or under-protecting.

Protecting Information Assets

Common mistake

Information & Asset Classification and Ownership

Failing to regularly review and update data classifications as data value or regulatory requirements change.

Protecting Information Assets

Key term

CCPA/CPRA

California Consumer Privacy Act/California Privacy Rights Act.

Protecting Information Assets

Key term

Privacy by Design

Embedding privacy into systems from the start.

Protecting Information Assets

Key term

Privacy by Default

Highest privacy settings applied automatically.

Protecting Information Assets

Key term

Data Minimization

Collecting only necessary personal data.

Protecting Information Assets

Key term

Data Retention

Policy for how long data is kept.

Protecting Information Assets

Key term

Secure Disposal

Irreversible removal of data from media.

Protecting Information Assets

Memory trick

Protecting Privacy and Data Retention

To remember the core privacy principles: T-P-D-A-S-I-A (Transparency, Purpose, Data Minimization, Accuracy, Storage, Integrity, Accountability). Think 'The Privacy Data Act Saves Individual Assets'!

Protecting Information Assets

Exam tip

Protecting Privacy and Data Retention

The CISSP exam frequently tests on the core principles of GDPR and CCPA/CPRA. Memorize the seven principles of Privacy by Design and understand the difference between 'by design' (proactive integration) and 'by default' (automatic highest privacy settings).

Protecting Information Assets

Common mistake

Protecting Privacy and Data Retention

Confusing privacy (individual's rights over data) with security (protecting data from threats). They are related but distinct.

Protecting Information Assets

Common mistake

Protecting Privacy and Data Retention

Assuming one privacy regulation (e.g., GDPR) applies everywhere; global organizations must comply with multiple, sometimes conflicting, laws.

Protecting Information Assets

Common mistake

Protecting Privacy and Data Retention

Failing to regularly review and update data retention policies, leading to unnecessary data accumulation and increased risk.

Protecting Information Assets

Key term

Administrative Control

Policy-based safeguards like policies, procedures, and training.

Protecting Information Assets

Key term

Technical Control

Hardware or software mechanisms for data and system protection.

Protecting Information Assets

Key term

Physical Control

Tangible measures protecting physical assets and environments.

Protecting Information Assets

Key term

Data at Rest

Data stored on media, requiring encryption and access controls.

Protecting Information Assets

Key term

Data in Transit

Data moving across networks, secured by protocols like TLS.

Protecting Information Assets

Key term

Data in Use

Data actively processed by a CPU or in RAM, challenging to secure.

Protecting Information Assets

Key term

Operational Control

Day-to-day security procedures, like backups and logging.

Protecting Information Assets

Memory trick

Data Security Controls and Handling Requirements

Remember 'ATP' for the main control types: Administrative, Technical, Physical. Then add 'O' for Operational to cover the day-to-day.

Protecting Information Assets

Exam tip

Data Security Controls and Handling Requirements

The exam frequently tests your ability to categorize controls. Be ready to identify whether a given control is administrative, technical, or physical. Keywords like 'policy', 'encryption', 'fence' are strong indicators.

Protecting Information Assets

Common mistake

Data Security Controls and Handling Requirements

Confusing administrative controls with operational controls; administrative defines 'what to do', operational defines 'how to do it' daily.

Protecting Information Assets

Common mistake

Data Security Controls and Handling Requirements

Underestimating the importance of physical controls; a strong firewall is useless if someone can walk away with the server.

Protecting Information Assets

Common mistake

Data Security Controls and Handling Requirements

Forgetting to consider data in use; many focus on data at rest and in transit, but data in memory is also vulnerable.

Protecting Information Assets

Key term

Data in Processing

Data actively being used by a system, application, or user.

Protecting Information Assets

Key term

Data Lifecycle Management

Policy-based approach to managing data from creation to destruction.

Protecting Information Assets

Key term

Data Loss Prevention (DLP)

Systems preventing unauthorized transmission of sensitive data.

Protecting Information Assets

Key term

Encryption

Transforming data to protect confidentiality and integrity.

Protecting Information Assets

Key term

Data Destruction

Secure, irreversible removal of data from storage media.

Protecting Information Assets

Memory trick

Data States and Lifecycle Management

Remember the three states of data with 'R.I.P.': Rest, In Transit, Processing.

Protecting Information Assets

Exam tip

Data States and Lifecycle Management

The exam expects you to differentiate between data states and apply appropriate security controls for each. Keywords to spot include 'encryption at rest,' 'TLS/SSL,' 'access controls,' and 'secure destruction.' Remember that data in processing is often protected by OS and application controls.

Protecting Information Assets

Common mistake

Data States and Lifecycle Management

Confusing data states with data lifecycle phases; they are related but distinct concepts.

Protecting Information Assets

Common mistake

Data States and Lifecycle Management

Assuming encryption alone is sufficient for all data states; access controls and other measures are also vital.

Protecting Information Assets

Common mistake

Data States and Lifecycle Management

Neglecting the secure destruction phase, leading to potential data leakage from discarded media.

Protecting Information Assets

Key term

Trusted Platform Module (TPM)

A secure cryptoprocessor that stores cryptographic keys and measures system integrity.

Designing Secure Systems

Key term

Hardware Root of Trust (HRoT)

An immutable, inherently trusted hardware component that forms the basis of a secure system.

Designing Secure Systems

Key term

Platform Configuration Registers (PCRs)

Registers within a TPM that store cryptographic hashes of system components for integrity checks.

Designing Secure Systems

Key term

Bell-LaPadula Model

A security model focused on confidentiality, preventing unauthorized information flow downwards.

Designing Secure Systems

Key term

Biba Model

A security model focused on integrity, preventing unauthorized information flow upwards.

Designing Secure Systems

Key term

Full Disk Encryption (FDE)

A security feature that encrypts all data on a hard drive, protecting it from unauthorized access.

Designing Secure Systems

Key term

Secure Boot

A process that ensures only trusted software (firmware, OS) can load during system startup.

Designing Secure Systems

Memory trick

Security Models & System Capabilities (TPM, Encryption)

To remember Bell-LaPadula's rules: 'Bell's Confidentiality: No Reading Up, No Writing Down.' Think of a 'bell' ringing to keep secrets contained.

Designing Secure Systems

Exam tip

Security Models & System Capabilities (TPM, Encryption)

The CISSP exam frequently tests the core functions of the TPM, especially its role in providing a hardware root of trust, secure key storage, and integrity measurement using PCRs. Be ready to distinguish between confidentiality (Bell-LaPadula) and integrity (Biba) models.

Designing Secure Systems

Common mistake

Security Models & System Capabilities (TPM, Encryption)

Confusing the Bell-LaPadula (confidentiality) and Biba (integrity) models; remember their primary goals.

Designing Secure Systems

Common mistake

Security Models & System Capabilities (TPM, Encryption)

Underestimating the importance of a hardware root of trust; it's the foundation, not just an add-on.

Designing Secure Systems

Common mistake

Security Models & System Capabilities (TPM, Encryption)

Believing software-only encryption provides the same level of protection as hardware-backed encryption with a TPM.

Designing Secure Systems

Key term

OWASP Top 10

A standard awareness document for web application security.

Designing Secure Systems

Key term

SQL Injection

Attack inserting malicious SQL queries into input fields.

Designing Secure Systems

Key term

Cross-Site Scripting (XSS)

Injecting malicious scripts into web pages viewed by others.

Designing Secure Systems

Key term

Insecure Deserialization

Exploiting deserialization of untrusted data to execute code.

Designing Secure Systems

Key term

Jailbreaking/Rooting

Bypassing mobile OS restrictions to gain elevated access.

Designing Secure Systems

Key term

Firmware

Low-level software embedded in hardware devices.

Designing Secure Systems

Key term

API

Application Programming Interface; defines interactions between software.

Designing Secure Systems

Memory trick

Vulnerabilities in Architectures, Web, Mobile & IoT

For OWASP Top 10, think 'I BROKE SADLY, X-RAYING INSECURE COMPONENTS.' (Injection, Broken Auth, Sensitive Data, XML External Entities, Broken Access, Security Misconfiguration, Cross-Site Scripting, Insecure Deserialization, Using Components with Known Vulnerabilities, Insufficient Logging & Monitoring)

Designing Secure Systems

Exam tip

Vulnerabilities in Architectures, Web, Mobile & IoT

The CISSP exam frequently tests your knowledge of the OWASP Top 10. Memorize the categories and understand the general nature of each vulnerability, not just the names. Also, understand the unique security challenges presented by mobile and IoT devices due to their resource constraints and deployment environments.

Designing Secure Systems

Common mistake

Vulnerabilities in Architectures, Web, Mobile & IoT

Underestimating the impact of architectural flaws, which are often the hardest to remediate.

Designing Secure Systems

Common mistake

Vulnerabilities in Architectures, Web, Mobile & IoT

Focusing solely on code-level vulnerabilities and neglecting configuration or deployment issues.

Designing Secure Systems

Common mistake

Vulnerabilities in Architectures, Web, Mobile & IoT

Assuming mobile or IoT devices are inherently secure due to their small size or limited functionality.

Designing Secure Systems

Key term

Symmetric Key

Single secret key used for both encryption and decryption.

Designing Secure Systems

Key term

Asymmetric Key

Public/private key pair; one encrypts, the other decrypts.

Designing Secure Systems

Key term

Public Key

Freely shared key in an asymmetric pair, used for encryption or signature verification.

Designing Secure Systems

Key term

Private Key

Secret key in an asymmetric pair, used for decryption or digital signing.

Designing Secure Systems

Key term

AES

Advanced Encryption Standard, a widely used symmetric encryption algorithm.

Designing Secure Systems

Key term

RSA

Rivest-Shamir-Adleman, a common asymmetric encryption algorithm.

Designing Secure Systems

Key term

Hybrid Cryptosystem

Combines symmetric and asymmetric methods for efficiency and security.

Designing Secure Systems

Memory trick

Symmetric vs. Asymmetric Cryptography

Symmetric is for SPEED (Single key), Asymmetric is for SECURE EXCHANGE (Two keys).

Designing Secure Systems

Exam tip

Symmetric vs. Asymmetric Cryptography

The CISSP exam frequently tests the *purpose* and *use cases* of symmetric vs. asymmetric cryptography. Remember that asymmetric solves the key distribution problem, while symmetric is faster for bulk data. Keywords to spot: 'bulk encryption' often points to symmetric; 'key exchange' or 'digital signatures' often points to asymmetric.

Designing Secure Systems

Common mistake

Symmetric vs. Asymmetric Cryptography

Confusing the speed and efficiency of symmetric vs. asymmetric algorithms.

Designing Secure Systems

Common mistake

Symmetric vs. Asymmetric Cryptography

Misunderstanding that asymmetric encryption is primarily for key exchange and digital signatures, not bulk data encryption.

Designing Secure Systems

Common mistake

Symmetric vs. Asymmetric Cryptography

Neglecting the importance of key management for both types of cryptography.

Designing Secure Systems

Key term

Privacy by Design (PbD)

Approach embedding privacy into system design and operations.

Designing Secure Systems

Key term

Physical Security

Protecting physical assets from unauthorized access, damage, or theft.

Designing Secure Systems

Key term

Secure Design Pattern

Reusable solution to a common security problem in architecture.

Designing Secure Systems

Key term

Security Anti-Pattern

Common design mistake leading to vulnerabilities.

Designing Secure Systems

Key term

Defense in Depth

Layering multiple security controls to protect assets.

Designing Secure Systems

Key term

Mantraps

Two-door entry system preventing tailgating.

Designing Secure Systems

Memory trick

Site Security & Secure Design Principles

For PbD: 'Proactive Privacy Embedded Fully, End-to-End, Visible, Respectful.'

Designing Secure Systems

Exam tip

Site Security & Secure Design Principles

Memorize the 7 Foundational Principles of Privacy by Design (PbD) and be able to distinguish them from other security principles. Also, understand that the OWASP Top 10 is a list of common risks, not a comprehensive standard.

Designing Secure Systems

Common mistake

Site Security & Secure Design Principles

Assuming physical security is 'someone else's job' and not integrating it into overall security planning.

Designing Secure Systems

Common mistake

Site Security & Secure Design Principles

Treating OWASP Top 10 as a checklist to 'pass' rather than a guide for continuous secure development.

Designing Secure Systems

Common mistake

Site Security & Secure Design Principles

Implementing privacy features as an afterthought or only to meet minimum compliance, rather than embedding them by design.

Designing Secure Systems

Key term

IPsec

Suite of protocols securing IP communications.

Securing Networks and Communications

Key term

Authentication Header (AH)

IPsec protocol for integrity and authentication.

Securing Networks and Communications

Key term

Encapsulating Security Payload (ESP)

IPsec protocol for confidentiality, integrity, authentication.

Securing Networks and Communications

Key term

Tunnel Mode

IPsec mode encrypting entire original IP packet.

Securing Networks and Communications

Key term

Software-Defined Networking (SDN)

Separates network control from data plane.

Securing Networks and Communications

Key term

Security Association (SA)

Defines parameters for secure IPsec communication.

Securing Networks and Communications

Memory trick

Secure Network Architecture & Design (IPsec, SDN)

IPsec: I Protect Secure Encrypted Communications. Remember ESP for Everything (Encryption, Security, Protection) and AH for Authentication Only (no encryption).

Securing Networks and Communications

Exam tip

Secure Network Architecture & Design (IPsec, SDN)

Memorize the core functions of AH (integrity, authentication) versus ESP (confidentiality, integrity, authentication) for IPsec. The exam often tests your understanding of which protocol provides which service. Also, distinguish between Tunnel and Transport modes.

Securing Networks and Communications

Common mistake

Secure Network Architecture & Design (IPsec, SDN)

Confusing IPsec Transport mode with Tunnel mode applications.

Securing Networks and Communications

Common mistake

Secure Network Architecture & Design (IPsec, SDN)

Believing AH provides confidentiality (it does not).

Securing Networks and Communications

Common mistake

Secure Network Architecture & Design (IPsec, SDN)

Underestimating the security benefits of SDN's centralized control.

Securing Networks and Communications

Key term

Router

Device that forwards data packets between computer networks.

Securing Networks and Communications

Key term

Switch

Device that connects devices within a local area network (LAN).

Securing Networks and Communications

Key term

Firewall

Monitors and controls network traffic based on security rules.

Securing Networks and Communications

Key term

IDS/IPS

Detects (IDS) or prevents (IPS) malicious network activity.

Securing Networks and Communications

Key term

WAP

Wireless Access Point; connects wireless devices to a wired network.

Securing Networks and Communications

Key term

Network Segmentation

Dividing a network into smaller, isolated sub-networks.

Securing Networks and Communications

Key term

Hardening

Process of securing a system by reducing its attack surface.

Securing Networks and Communications

Key term

802.1X

IEEE standard for port-based network access control.

Securing Networks and Communications

Memory trick

Secure Network Components and Devices

R-S-F-I-W-S-H: **R**eally **S**ecure **F**irewalls **I**nside **W**ireless **S**egmented **H**omes. (Routers, Switches, Firewalls, IDS/IPS, WAPs, Segmentation, Hardening)

Securing Networks and Communications

Exam tip

Secure Network Components and Devices

The exam will test your understanding of the *purpose* and *placement* of devices like firewalls, IDS/IPS, and WAPs, as well as specific hardening techniques. Keywords to spot include 'least privilege' applied to device access, 'defense in depth' for layered security, and 'single point of failure' avoidance.

Securing Networks and Communications

Common mistake

Secure Network Components and Devices

Leaving default credentials on network devices, creating an easy entry point for attackers.

Securing Networks and Communications

Common mistake

Secure Network Components and Devices

Failing to update firmware and software regularly, leaving devices vulnerable to known exploits.

Securing Networks and Communications

Common mistake

Secure Network Components and Devices

Not segmenting networks, allowing a breach in one area to easily spread throughout the entire infrastructure.

Securing Networks and Communications

Key term

TLS (Transport Layer Security)

Cryptographic protocol for secure communication over a network.

Securing Networks and Communications

Key term

HTTPS (Hypertext Transfer Protocol Secure)

HTTP secured by TLS/SSL for encrypted web communication.

Securing Networks and Communications

Key term

SSH (Secure Shell)

Protocol for secure remote network services over an unsecured network.

Securing Networks and Communications

Key term

S/MIME (Secure/Multipurpose Internet Mail Extensions)

Standard for encrypting and signing email messages.

Securing Networks and Communications

Key term

DNSSEC (Domain Name System Security Extensions)

Adds cryptographic security to the DNS protocol.

Securing Networks and Communications

Key term

SRTP (Secure Real-time Transport Protocol)

Provides encryption and authentication for real-time audio/video.

Securing Networks and Communications

Key term

X.509 Certificate

Digital document used to verify the ownership of a public key.

Securing Networks and Communications

Memory trick

Secure Communication Channels and Protocols

To remember key secure protocols: 'SSH-S-TLS-DNS' - Secure Shell, S/MIME, TLS, DNSSEC. Each protects a different communication aspect!

Securing Networks and Communications

Exam tip

Secure Communication Channels and Protocols

The exam often tests the *purpose* of protocols. For example, if a question asks about securing web traffic, think HTTPS/TLS. If it's about secure remote access, think SSH. Know which layer (transport vs. application) each protocol generally operates at.

Securing Networks and Communications

Common mistake

Secure Communication Channels and Protocols

Confusing the OSI layer where a protocol operates (e.g., thinking SSH is transport layer when it's application layer).

Securing Networks and Communications

Common mistake

Secure Communication Channels and Protocols

Not understanding the difference between FTPS (FTP over SSL/TLS) and SFTP (SSH File Transfer Protocol).

Securing Networks and Communications

Common mistake

Secure Communication Channels and Protocols

Assuming all secure protocols provide the same security services; each has specific strengths and weaknesses.

Securing Networks and Communications

Key term

Denial of Service (DoS)

An attack to make a machine or network resource unavailable to its intended users.

Securing Networks and Communications

Key term

Distributed DoS (DDoS)

A DoS attack launched from numerous compromised systems (botnet).

Securing Networks and Communications

Key term

Man-in-the-Middle (MitM)

An attacker intercepts and potentially alters communication between two parties.

Securing Networks and Communications

Key term

Eavesdropping

Secretly listening to private communication, often via network sniffing.

Securing Networks and Communications

Key term

Botnet

A network of private computers infected with malicious software and controlled as a group.

Securing Networks and Communications

Key term

Packet Sniffer

A tool used to capture and analyze network traffic.

Securing Networks and Communications

Key term

Intrusion Prevention System (IPS)

Monitors network traffic for malicious activity and takes action to prevent it.

Securing Networks and Communications

Memory trick

Understanding and Mitigating Network Attacks

To remember attack types: 'DDoS' is 'Distributed' and 'Disruptive'. 'MitM' is 'Middle' and 'Malicious' interception.

Securing Networks and Communications

Exam tip

Understanding and Mitigating Network Attacks

The CISSP exam frequently tests the distinction between DoS and DDoS (single vs. multiple sources), and the primary defense mechanisms for each. Pay attention to the 'intent' of the attack (e.g., disruption vs. data theft).

Securing Networks and Communications

Common mistake

Understanding and Mitigating Network Attacks

Confusing DoS with DDoS: DoS is from a single source, DDoS from multiple.

Securing Networks and Communications

Common mistake

Understanding and Mitigating Network Attacks

Underestimating the importance of encryption: Many attacks rely on unencrypted traffic.

Securing Networks and Communications

Common mistake

Understanding and Mitigating Network Attacks

Believing a single security tool is sufficient: A layered defense is always necessary.

Securing Networks and Communications

Key term

Physical Access Control

Restricts entry to physical spaces and assets.

Managing Identities and Access

Key term

Logical Access Control

Restricts access to computer systems and data.

Managing Identities and Access

Key term

Least Privilege

Users get minimum access needed for their job.

Managing Identities and Access

Key term

Separation of Duties

Prevents one person from completing critical tasks alone.

Managing Identities and Access

Key term

Multi-Factor Authentication (MFA)

Requires two or more verification methods.

Managing Identities and Access

Key term

Access Control List (ACL)

A list of permissions attached to an object.

Managing Identities and Access

Key term

Role-Based Access Control (RBAC)

Access based on user's role within an organization.

Managing Identities and Access

Memory trick

Physical & Logical Access Controls

P-L-A-N: Physical, Logical, And Network. Remember you need to secure all three layers for complete protection.

Managing Identities and Access

Exam tip

Physical & Logical Access Controls

The CISSP exam frequently tests the integration of physical and logical security. Look for questions that describe a scenario and ask for the *most comprehensive* or *most effective* control, which often implies a combined approach. Memorize that physical controls are 'something you can touch' and logical controls are 'something you can configure'.

Managing Identities and Access

Common mistake

Physical & Logical Access Controls

Assuming strong logical controls compensate for weak physical security, or vice-versa.

Managing Identities and Access

Common mistake

Physical & Logical Access Controls

Failing to regularly review and update both physical and logical access permissions.

Managing Identities and Access

Common mistake

Physical & Logical Access Controls

Implementing controls in isolation without considering their interaction and potential gaps.

Managing Identities and Access

Key term

Identification

Claiming an identity to a system.

Managing Identities and Access

Key term

Authentication

Verifying the claimed identity.

Managing Identities and Access

Key term

Authorization

Determining what an authenticated user can do.

Managing Identities and Access

Key term

Something You Know

An authentication factor like a password or PIN.

Managing Identities and Access

Key term

Something You Have

An authentication factor like a token or smart card.

Managing Identities and Access

Key term

Something You Are

An authentication factor like a fingerprint or retina scan.

Managing Identities and Access

Memory trick

Identification, Authentication & Authorization (IAA)

Remember 'IAA' as 'I Am Allowed' – first, I identify myself, then I prove I am who I say, then I'm allowed to do things.

Managing Identities and Access

Exam tip

Identification, Authentication & Authorization (IAA)

The CISSP exam frequently tests the order and distinction of IAA. Remember: Identify, then Authenticate, then Authorize. Keywords to spot include 'verify identity' (authentication) vs. 'grant permissions' (authorization).

Managing Identities and Access

Common mistake

Identification, Authentication & Authorization (IAA)

Confusing authentication with authorization: Authentication is *who* you are, authorization is *what* you can do.

Managing Identities and Access

Common mistake

Identification, Authentication & Authorization (IAA)

Believing identification alone is sufficient for security: Identification must always be followed by authentication.

Managing Identities and Access

Common mistake

Identification, Authentication & Authorization (IAA)

Underestimating the importance of multi-factor authentication: Single-factor authentication is easily compromised.

Managing Identities and Access

Key term

IDaaS

Cloud-based service offering identity and access management capabilities.

Managing Identities and Access

Key term

SAML

XML standard for exchanging authentication and authorization data.

Managing Identities and Access

Key term

OpenID Connect

Identity layer built on top of the OAuth 2.0 protocol.

Managing Identities and Access

Key term

OAuth

Open standard for access delegation, granting limited access.

Managing Identities and Access

Key term

Credential Stuffing

Using stolen credentials from one breach to try logging into other services.

Managing Identities and Access

Key term

Single Sign-On (SSO)

Allows users to authenticate once and access multiple applications.

Managing Identities and Access

Key term

Federated Identity

Method allowing users to authenticate across multiple, independent systems.

Managing Identities and Access

Memory trick

IDaaS, Third-Party Identity Services & Attacks

To remember the key identity protocols, think: 'SAML is for Security Assertions, OIDC is for OpenID (identity), and OAuth is for Authorization.'

Managing Identities and Access

Exam tip

IDaaS, Third-Party Identity Services & Attacks

The CISSP exam frequently tests your understanding of the benefits and risks of IDaaS and third-party identity providers. Be prepared to identify common protocols like SAML, OIDC, and OAuth, and their specific purposes. Also, know the attack vectors like credential stuffing and phishing, and their countermeasures.

Managing Identities and Access

Common mistake

IDaaS, Third-Party Identity Services & Attacks

Assuming IDaaS automatically solves all identity security problems without proper configuration or due diligence.

Managing Identities and Access

Common mistake

IDaaS, Third-Party Identity Services & Attacks

Neglecting to implement MFA even when using IDaaS or third-party identity services.

Managing Identities and Access

Common mistake

IDaaS, Third-Party Identity Services & Attacks

Failing to conduct regular audits and reviews of third-party identity provider security practices and compliance.

Managing Identities and Access

Key term

Provisioning

Creating user accounts and assigning initial access.

Managing Identities and Access

Key term

Deprovisioning

Revoking access and disabling/deleting user accounts.

Managing Identities and Access

Key term

Reprovisioning

Modifying access rights due to role or status changes.

Managing Identities and Access

Key term

Orphaned Account

An active account no longer linked to an active user.

Managing Identities and Access

Key term

Access Governance

Policies and processes for managing digital identities.

Managing Identities and Access

Key term

IAM

Identity and Access Management; systems for managing identities.

Managing Identities and Access

Memory trick

Identity and Access Provisioning Lifecycle

P-R-R-D: 'People Rarely Remember Details' to recall the stages: Provisioning, Review, Reprovisioning, Deprovisioning.

Managing Identities and Access

Exam tip

Identity and Access Provisioning Lifecycle

The exam often tests your understanding of the 'cradle-to-grave' management of identities. Look for questions about the security implications of neglecting any stage, especially deprovisioning. Remember that automated processes are generally preferred for efficiency and security over manual ones.

Managing Identities and Access

Common mistake

Identity and Access Provisioning Lifecycle

Forgetting to deprovision accounts promptly, leading to security vulnerabilities.

Managing Identities and Access

Common mistake

Identity and Access Provisioning Lifecycle

Granting excessive privileges during provisioning, violating the principle of least privilege.

Managing Identities and Access

Common mistake

Identity and Access Provisioning Lifecycle

Failing to conduct regular access reviews, allowing stale or unnecessary access to persist.

Managing Identities and Access

Key term

Log

A record of events within a system.

Security Operations Fundamentals

Key term

Monitoring

Continuous review of system activities for anomalies.

Security Operations Fundamentals

Key term

SIEM

Security Information and Event Management system.

Security Operations Fundamentals

Key term

SOAR

Security Orchestration, Automation, Response platform.

Security Operations Fundamentals

Key term

IOC

Indicator of Compromise, evidence of a breach.

Security Operations Fundamentals

Key term

Chain of Custody

Documented history of evidence handling.

Security Operations Fundamentals

Key term

Digital Forensics

Scientific process of collecting and analyzing digital evidence.

Security Operations Fundamentals

Key term

Playbook

Predefined automated actions in SOAR.

Security Operations Fundamentals

Memory trick

Investigations, Logging, Monitoring & Concepts

L.M.S.I.F.R. - Logs Make Security Investigations Fun, Right? (Logging, Monitoring, SIEM, Investigations, Forensics, Reporting)

Security Operations Fundamentals

Exam tip

Investigations, Logging, Monitoring & Concepts

For the CISSP exam, memorize the typical phases of an incident response process (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) and understand the distinct roles of SIEM (detection, correlation) vs. SOAR (automation, orchestration).

Security Operations Fundamentals

Common mistake

Investigations, Logging, Monitoring & Concepts

Not retaining logs for a sufficient period, leading to gaps in investigation data.

Security Operations Fundamentals

Common mistake

Investigations, Logging, Monitoring & Concepts

Failing to establish a clear chain of custody for digital evidence, making it inadmissible.

Security Operations Fundamentals

Common mistake

Investigations, Logging, Monitoring & Concepts

Over-relying on automated tools without human oversight, leading to missed threats or false positives.

Security Operations Fundamentals

Key term

Resource Protection

Safeguarding assets to ensure CIA.

Security Operations Fundamentals

Key term

Incident Prevention

Proactive measures to stop security incidents.

Security Operations Fundamentals

Key term

Incident Management

Systematic handling of security incidents.

Security Operations Fundamentals

Key term

Incident Response Plan (IRP)

Documented procedures for incident handling.

Security Operations Fundamentals

Key term

Containment

Limiting an incident's scope and impact.

Security Operations Fundamentals

Key term

Eradication

Removing the root cause of an incident.

Security Operations Fundamentals

Key term

Recovery

Restoring systems to normal operations.

Security Operations Fundamentals

Memory trick

Resource Protection, Incident Management & Prevention

P-D-C-E-R-P: 'Please Don't Cause Every Robot Pain' helps remember Preparation, Detection, Containment, Eradication, Recovery, Post-Incident.

Security Operations Fundamentals

Exam tip

Resource Protection, Incident Management & Prevention

Memorize the phases of the incident management lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident Activity) as they are frequently tested in order and purpose. Look for questions asking about the 'next step' or 'primary goal' of a specific phase.

Security Operations Fundamentals

Common mistake

Resource Protection, Incident Management & Prevention

Confusing incident prevention with incident response; prevention is proactive, response is reactive.

Security Operations Fundamentals

Common mistake

Resource Protection, Incident Management & Prevention

Failing to regularly test the Incident Response Plan (IRP), leading to ineffective response during a real incident.

Security Operations Fundamentals

Common mistake

Resource Protection, Incident Management & Prevention

Neglecting the 'lessons learned' phase, missing opportunities for continuous improvement.

Security Operations Fundamentals

Key term

Patch Management

Systematic process of applying software updates to fix bugs and vulnerabilities.

Security Operations Fundamentals

Key term

Vulnerability Assessment

Process of identifying and quantifying security weaknesses in systems and applications.

Security Operations Fundamentals

Key term

Change Management

Formal process for controlling all changes to IT infrastructure and services.

Security Operations Fundamentals

Key term

Penetration Testing

Authorized simulated attack to exploit vulnerabilities and test security defenses.

Security Operations Fundamentals

Key term

CVE (Common Vulnerabilities and Exposures)

A list of publicly disclosed cybersecurity vulnerabilities.

Security Operations Fundamentals

Key term

Remediation

The act of correcting or fixing a identified security vulnerability.

Security Operations Fundamentals

Key term

Attack Surface

The sum of all points where an unauthorized user can try to enter or extract data from an environment.

Security Operations Fundamentals

Memory trick

Patch, Vulnerability & Change Management

P.V.C. for Security: Patches, Vulnerabilities, Changes. Think of PVC pipes – strong and secure when properly managed!

Security Operations Fundamentals

Exam tip

Patch, Vulnerability & Change Management

The CISSP exam frequently tests the *order* of operations within these processes. Memorize the typical sequence for patch deployment and change management. Also, clearly distinguish between vulnerability scanning (identification) and penetration testing (exploitation/validation).

Security Operations Fundamentals

Common mistake

Patch, Vulnerability & Change Management

Skipping testing of patches in a non-production environment, leading to system outages.

Security Operations Fundamentals

Common mistake

Patch, Vulnerability & Change Management

Confusing vulnerability scanning with penetration testing; one identifies, the other exploits.

Security Operations Fundamentals

Common mistake

Patch, Vulnerability & Change Management

Bypassing the formal change management process for 'quick fixes,' introducing unmanaged risks.

Security Operations Fundamentals

Key term

Business Continuity Plan (BCP)

Plan to maintain business functions during disruption.

Security Operations Fundamentals

Key term

Disaster Recovery Plan (DRP)

Plan to restore IT systems after a disaster.

Security Operations Fundamentals

Key term

Business Impact Analysis (BIA)

Identifies critical functions and impact of their loss.

Security Operations Fundamentals

Memory trick

Recovery, Disaster Recovery, and Business Continuity

RTO is 'Time' (how long till back online), RPO is 'Point' (how much data can be lost).

Security Operations Fundamentals