Career Employer

Your FREE CISSP Flashcards 2026 – 350+ Cards

Realistic, CISSP exam-style flashcards across all 8 ISC2 domains — flip, match, type, and quiz yourself.

How well do you know them?

To find us again, just search “Career Employer CISSP”

By

Click Study Flashcards above to open the flashcard hub — hundreds of CISSP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the eight official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.

CISSP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.

CISSP Flashcard Study Modes

Flip mode turns cards at your own pace, Match times you pairing terms with their definitions, Type shows a definition and asks you to produce the term yourself — SOAR, for example — and Quiz builds multiple-choice items from the same 355 cards. Use Flip on unfamiliar domains first, then let Type and Quiz confirm that recall holds without the prompt in front of you.

Free CISSP flashcards from Career Employer — active recall for the Certified Information Systems Security Professional exam

Why Flashcards Work for the CISSP

Security & Risk Management is the largest block at 81 cards and 16% of the exam, so start there. The cards drill governance and legal vocabulary alongside risk math, mixing regulations such as SOX, GDPR, and GLBA with availability metrics like MTBF and MTTR, plus threat-rating terms including DREAD and foundations like Asset and Risk.

Security Architecture & Engineering carries 48 cards at 13%, heavy on cryptography: AES, RSA, and ECC for algorithms, then Hashing, Salt, and HMAC for integrity work, with SHA-256 and TEMPEST covering implementation detail. Communication & Network Security matches that 13% across 40 cards on segmentation and secure transport, from DMZ, VLAN, and NAC on the design side to TLS, SSH, and IPsec on the protocol side, with WEP as the cautionary card.

Identity & Access Management, also 13%, brings 40 cards on authentication protocols and administrative control: AAA, SAML, and Kerberos, then Kerberos KDC and OAuth 2.0, with personnel controls such as Need to know and Job rotation. Security Operations adds 40 more at the same weight for detection and recovery — SIEM, SOAR, and CSIRT, plus site cards including Hot site and Warm site.

Security Assessment & Testing holds 31 cards at 12%, covering vulnerability scoring and audit evidence: CVE and CVSS, techniques such as Fuzzing and Code review, and reporting cards including SOC 1 report and SOC 2 report. Asset Security has 35 cards at 10% for classification and sanitization, from PII and PHI through Clearing, Purging, and Degaussing. Software Development Security closes with 40 cards, also 10%, on pipeline and maturity vocabulary: CI/CD, DevOps, and DevSecOps, maturity models like BSIMM and OWASP SAMM, and cards such as Injection and Shift left.

The CISSP is dense with terminology — risk formulas, security models, cryptography, access control, and operations frameworks.[3] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.

CISSP Flashcards by Domain

The cards are organized by the eight official ISC2 domains. The weights are fairly even, so cover them all — but start with the largest, Security & Risk Management:[1]

CISSP flashcards by domain and weight
DomainExam weight
Security & Risk Management16%
Security Architecture & Engineering13%
Communication & Network Security13%
Identity & Access Management13%
Security Operations13%
Security Assessment & Testing12%
Asset Security10%
Software Development Security10%

How to Get the Most Out of These Flashcards

  • Start with risk. Security & Risk Management is 81 cards and 16% of the exam, the biggest return on early effort, so get SOX, GDPR, and DREAD solid before touching cryptography.
  • Type-drill the look-alikes. Terms that blur under pressure, such as MTBF and MTTR or Clearing against Purging, reward typing the exact word instead of recognizing it in a list.
  • Match the acronyms. Short cryptography and network fronts like AES, HMAC, and IPsec pair quickly, so Match builds the recall speed that the exam’s longer scenario wording assumes you already have.
  • Move to the practice test. Once Quiz scores hold steady across all eight domains, switch to the practice test for scenario phrasing, then return to Flip on the cards you missed.
  • Keep a rotating cadence. With 355 cards, work one domain per session and re-Flip the previous session’s set first, so Asset Security and Security Assessment & Testing never go stale.

CISSP Flashcards FAQ

Hundreds of free CISSP flashcards, organized across all eight ISC2 domains — Security & Risk Management, Asset Security, Security Architecture & Engineering, Communication & Network Security, Identity & Access Management, Security Assessment & Testing, Security Operations, and Software Development Security. They're free with no account required.

CISSP flashcard bank

All 355 cards, by topic

A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.

Security & Risk Management (81)

CIA triad
Show answer

Confidentiality, Integrity, Availability — the three core goals of information security.

Confidentiality
Show answer

Preventing unauthorized disclosure of data; protected by encryption and access controls.

Integrity
Show answer

Ensuring data is accurate and unaltered except by authorized parties; protected by hashing and digital signatures.

Availability
Show answer

Ensuring authorized users have timely, reliable access to systems and data.

DAD triad
Show answer

Disclosure, Alteration, Destruction — the opposite of CIA; names the threats to each goal.

Authenticity
Show answer

Assurance that data, a transaction, or a message is genuine and from its claimed source.

Non-repudiation
Show answer

Assurance that a party cannot deny an action; achieved via digital signatures and logging.

Defense in depth
Show answer

Layering multiple, overlapping controls so that if one fails, others still protect the asset.

Security governance
Show answer

The framework of policies, roles, and oversight by which senior management directs and controls security.

Due diligence
Show answer

Doing the research and developing the plans and policies needed to protect the organization.

Due care
Show answer

Acting on due diligence — implementing and maintaining reasonable controls (the prudent person rule).

Prudent person rule
Show answer

Acting with the care a reasonable, prudent person would in similar circumstances; reduces negligence liability.

Policy
Show answer

A high-level management statement of intent and goals; mandatory and broad.

Standard
Show answer

A mandatory, specific requirement that supports a policy (e.g., 'use AES-256').

Procedure
Show answer

Detailed, mandatory step-by-step instructions for a task.

Baseline
Show answer

A minimum required level of security that systems must meet.

Guideline
Show answer

A recommended, discretionary (optional) best practice.

Risk
Show answer

The likelihood that a threat exploits a vulnerability, and the resulting impact on an asset.

Threat
Show answer

Any potential event or actor that could harm an asset by exploiting a vulnerability.

Threat agent / actor
Show answer

The entity (person, group, or process) that carries out a threat.

Vulnerability
Show answer

A weakness in a system, process, or control that a threat can exploit.

Exposure
Show answer

An instance of being susceptible to loss from a threat exploiting a vulnerability.

Asset
Show answer

Anything of value to the organization — data, systems, people, facilities, or reputation.

Asset value (AV)
Show answer

The monetary worth assigned to an asset, used in quantitative risk analysis.

Exposure factor (EF)
Show answer

The percentage of an asset's value lost if a specific risk event occurs.

Single Loss Expectancy (SLE)
Show answer

Expected loss from one occurrence: SLE = Asset Value × Exposure Factor.

Annualized Rate of Occurrence (ARO)
Show answer

The expected number of times a risk event occurs in one year.

Annualized Loss Expectancy (ALE)
Show answer

Expected yearly cost of a risk: ALE = SLE × ARO.

SLE formula
Show answer

SLE = AV × EF (Asset Value times Exposure Factor).

ALE formula
Show answer

ALE = SLE × ARO (Single Loss Expectancy times Annualized Rate of Occurrence).

Qualitative risk analysis
Show answer

Subjective ranking of risk (high/medium/low) using scenarios and judgment — fast, not dollar-based.

Quantitative risk analysis
Show answer

Objective, dollar-based risk analysis using AV, EF, SLE, ARO, and ALE.

Residual risk
Show answer

The risk that remains after controls are applied; senior management formally accepts it.

Total risk
Show answer

The risk before any controls are applied (threats × vulnerabilities × asset value).

Risk mitigation
Show answer

Reducing risk to an acceptable level by implementing controls.

Risk transference
Show answer

Shifting the financial impact of a risk to a third party, such as insurance.

Risk avoidance
Show answer

Eliminating a risk by ceasing the activity that creates it.

Risk acceptance
Show answer

A documented, management-approved decision to tolerate a risk.

Risk deterrence
Show answer

Discouraging a threat actor from acting (e.g., warnings, visible controls).

Control cost rule
Show answer

A countermeasure should never cost more than the asset (or the ALE reduction) it provides.

Safeguard / countermeasure
Show answer

A control that reduces the likelihood or impact of a risk.

Administrative controls
Show answer

Policies, procedures, training, and personnel practices (management controls).

Technical / logical controls
Show answer

Hardware and software controls such as firewalls, encryption, and access control.

Physical controls
Show answer

Controls that protect facilities and equipment (locks, fences, guards, cameras).

Preventive control
Show answer

A control that stops an incident before it happens (e.g., a lock, MFA).

Detective control
Show answer

A control that identifies an incident in progress or after it (e.g., logs, IDS, cameras).

Corrective control
Show answer

A control that restores systems after an incident (e.g., backups, patches).

Deterrent control
Show answer

A control that discourages a threat (e.g., warning signs, visible cameras).

Compensating control
Show answer

An alternative control used when the primary one isn't feasible.

Threat modeling
Show answer

Systematically identifying and prioritizing threats to a system during design.

STRIDE
Show answer

Threat model: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.

DREAD
Show answer

A risk-rating model: Damage, Reproducibility, Exploitability, Affected users, Discoverability.

Security control frameworks
Show answer

Structured sets of controls — e.g., NIST SP 800-53, ISO/IEC 27001/27002, COBIT.

ISO/IEC 27001
Show answer

International standard for an Information Security Management System (ISMS).

ISO/IEC 27002
Show answer

Code of practice giving guidance on information security controls.

NIST Cybersecurity Framework
Show answer

A framework of five functions: Identify, Protect, Detect, Respond, Recover.

ISC2 Code of Ethics — Canon 1
Show answer

Protect society, the common good, necessary public trust, and the infrastructure.

ISC2 Code of Ethics — Canon 2
Show answer

Act honorably, honestly, justly, responsibly, and legally.

ISC2 Code of Ethics — Canon 3
Show answer

Provide diligent and competent service to principals.

ISC2 Code of Ethics — Canon 4
Show answer

Advance and protect the profession.

Code of Ethics canon order
Show answer

Canons are applied in order; when they conflict, the earlier (society) outranks the later (profession).

GDPR
Show answer

EU General Data Protection Regulation — protects personal data of EU residents; heavy fines for noncompliance.

HIPAA
Show answer

U.S. law protecting the privacy and security of health information (PHI).

GLBA
Show answer

Gramm-Leach-Bliley Act — requires financial institutions to protect customers' personal financial data.

SOX
Show answer

Sarbanes-Oxley Act — requires accurate financial reporting and internal controls for public companies.

PCI DSS
Show answer

Payment Card Industry Data Security Standard — protects cardholder data (industry standard, not law).

Intellectual property — patent
Show answer

Grants exclusive rights to an invention for a limited time (about 20 years).

Intellectual property — trademark
Show answer

Protects words, symbols, or logos identifying goods/services.

Intellectual property — copyright
Show answer

Protects original works of authorship (software, writing, art).

Trade secret
Show answer

Confidential business information that gives a competitive edge, protected as long as it's kept secret.

Business continuity plan (BCP)
Show answer

A plan to keep critical business functions operating during and after a disruption.

Disaster recovery (DR)
Show answer

Processes and procedures to restore IT systems and operations after a disaster.

Business Impact Analysis (BIA)
Show answer

Identifies critical functions and sets recovery objectives (MTD, RTO, RPO) — the heart of continuity planning.

Maximum Tolerable Downtime (MTD)
Show answer

The longest a function can be unavailable before unacceptable harm; drives the RTO.

Recovery Time Objective (RTO)
Show answer

The target time to restore a function after a disruption; must be less than the MTD.

Recovery Point Objective (RPO)
Show answer

The maximum acceptable amount of data loss, measured backward in time; drives backup frequency.

Work Recovery Time (WRT)
Show answer

Time to verify systems and data after recovery before resuming normal operations.

MTBF
Show answer

Mean Time Between Failures — the average time a repairable component runs before failing.

MTTR
Show answer

Mean Time To Repair — the average time to restore a failed component.

Critical business functions
Show answer

The functions an organization must perform to survive; identified by the BIA.

Senior management role in BCP
Show answer

Senior management must champion, fund, and ultimately own the BCP.

Asset Security (35)

Data classification
Show answer

Labeling data by sensitivity so the right level of protection is applied.

Government classification levels
Show answer

Top Secret, Secret, Confidential, Unclassified (high to low sensitivity).

Commercial classification levels
Show answer

Common scheme: Confidential, Private, Sensitive, Public.

Data owner
Show answer

The senior business manager accountable for data; assigns classification and protection requirements.

Data custodian
Show answer

Implements and maintains the controls protecting data day to day — usually IT.

Data controller
Show answer

Under privacy law, the entity that decides why and how personal data is processed.

Data processor
Show answer

A party that processes personal data on behalf of, and on the instructions of, the controller.

System owner
Show answer

The person responsible for a system's operation and security throughout its lifecycle.

Data steward
Show answer

Responsible for data quality, definitions, and appropriate use within a business area.

Data user
Show answer

An end user who accesses data to perform their job, following handling rules.

Data states
Show answer

At rest (stored), in transit (moving), and in use (being processed in memory).

Data at rest
Show answer

Stored data — protect with full-disk and database encryption.

Data in transit
Show answer

Moving data — protect with TLS, IPsec, or VPNs.

Data in use
Show answer

Data being processed in memory — hardest to protect (e.g., secure enclaves).

Data lifecycle
Show answer

Create, store, use, share, archive, and destroy — each stage needs appropriate protection.

Data remanence
Show answer

Residual data left on media after deletion or formatting that may be recoverable.

Clearing
Show answer

Overwriting media so data can't be recovered by normal means; suitable for internal reuse.

Purging
Show answer

Stronger sanitization (degaussing or multiple overwrites) to allow external release of media.

Destruction
Show answer

Physically destroying media (shred, pulverize, incinerate) for the most sensitive data.

Degaussing
Show answer

Using a strong magnetic field to erase data from magnetic media; does not work on SSDs.

NIST SP 800-88
Show answer

Guidelines for media sanitization defining Clear, Purge, and Destroy levels.

Data Loss Prevention (DLP)
Show answer

Technology that detects and blocks unauthorized exfiltration of sensitive data.

Scoping
Show answer

Selecting only the security controls from a baseline that apply to a given system.

Tailoring
Show answer

Adjusting a baseline of controls to fit an organization's specific needs.

Data retention policy
Show answer

Defines how long data must be kept and when it must be securely destroyed.

PII
Show answer

Personally Identifiable Information — data that can identify a specific individual.

PHI
Show answer

Protected Health Information — individually identifiable health data under HIPAA.

Data anonymization
Show answer

Removing identifiers so data can no longer be linked to an individual.

Pseudonymization
Show answer

Replacing identifying fields with pseudonyms so re-identification needs separate, protected data.

Tokenization
Show answer

Replacing sensitive data with a non-sensitive token, with the real value stored securely elsewhere.

Data masking
Show answer

Hiding parts of data (e.g., showing only the last 4 digits) to limit exposure.

Labeling vs. marking
Show answer

Labeling = machine-readable classification; marking = human-readable classification on documents.

Information lifecycle protection
Show answer

Applying classification, handling, and disposal rules to data from creation to destruction.

Asset inventory
Show answer

A maintained record of all assets and their owners — the basis for protecting them.

Data sovereignty
Show answer

Data is subject to the laws of the country in which it is physically stored.

Security Architecture & Engineering (48)

Security model
Show answer

A formal statement of rules that a system enforces to meet a security policy.

Bell-LaPadula model
Show answer

Confidentiality model: no read up (Simple Security) and no write down (*-Property).

Bell-LaPadula simple security property
Show answer

No read up — a subject can't read data above its clearance.

Bell-LaPadula star property
Show answer

No write down — a subject can't write data to a lower level.

Biba model
Show answer

Integrity model: no read down (Simple Integrity) and no write up (*-Integrity).

Biba simple integrity axiom
Show answer

No read down — a subject can't read data of lower integrity.

Biba star integrity axiom
Show answer

No write up — a subject can't write to a higher integrity level.

Clark-Wilson model
Show answer

Integrity model using well-formed transactions and separation of duties (the access triple).

Brewer-Nash (Chinese Wall)
Show answer

Confidentiality model that changes access dynamically to prevent conflicts of interest.

Take-Grant model
Show answer

A model describing how rights can be passed (taken or granted) between subjects.

Reference monitor
Show answer

The abstract concept that mediates ALL access between subjects and objects.

Security kernel
Show answer

The hardware/software that implements the reference monitor concept.

Trusted Computing Base (TCB)
Show answer

All hardware, software, and firmware that enforces a system's security policy.

Security perimeter
Show answer

The boundary separating the TCB from the rest of the system.

Common Criteria
Show answer

An international standard for evaluating product security, rated by EAL (1-7).

Evaluation Assurance Level (EAL)
Show answer

A Common Criteria rating from EAL1 (lowest) to EAL7 (highest) assurance.

Protection rings
Show answer

Hierarchical privilege levels (Ring 0 = kernel, outer rings = user) isolating processes.

Trusted Platform Module (TPM)
Show answer

A hardware chip that securely stores keys and supports measured boot and disk encryption.

Cryptography
Show answer

The science of protecting information using encryption, hashing, and related techniques.

Plaintext / ciphertext
Show answer

Plaintext is readable data; ciphertext is the encrypted, unreadable form.

Symmetric encryption
Show answer

One shared secret key for encrypting and decrypting; fast but key distribution is hard.

Asymmetric encryption
Show answer

A public/private key pair; slower but solves key exchange and enables signatures.

AES
Show answer

Advanced Encryption Standard — the dominant symmetric block cipher (128/192/256-bit keys).

DES / 3DES
Show answer

Older symmetric ciphers; DES (56-bit) is broken, 3DES is deprecated.

RSA
Show answer

A widely used asymmetric algorithm based on the difficulty of factoring large numbers.

ECC
Show answer

Elliptic Curve Cryptography — asymmetric crypto giving strong security with smaller keys.

Diffie-Hellman
Show answer

A key-exchange algorithm that lets two parties derive a shared secret over an insecure channel.

Hashing
Show answer

A one-way function producing a fixed-length digest used to verify integrity (e.g., SHA-256).

SHA-256
Show answer

A secure hashing algorithm producing a 256-bit digest; used for integrity and signatures.

MD5 / SHA-1
Show answer

Older hash functions now considered insecure (collision attacks) — avoid for security.

Digital signature
Show answer

A hash of a message encrypted with the sender's PRIVATE key — gives integrity, authenticity, non-repudiation.

Encrypt for confidentiality
Show answer

Encrypt with the RECIPIENT's public key; only their private key can decrypt.

Sign for authenticity
Show answer

Sign with YOUR private key; anyone can verify with your public key.

Public Key Infrastructure (PKI)
Show answer

The framework of certificate authorities, certificates, and policies that manages public keys.

Certificate Authority (CA)
Show answer

A trusted entity that issues and signs digital certificates binding a key to an identity.

Digital certificate (X.509)
Show answer

A signed document binding a public key to an identity, issued by a CA.

Hybrid cryptography
Show answer

Using asymmetric encryption to exchange a fast symmetric session key (e.g., TLS).

Salt
Show answer

Random data added to a password before hashing to defeat precomputed (rainbow) attacks.

HMAC
Show answer

A keyed hash providing integrity and authenticity of a message.

Key escrow
Show answer

Storing a copy of cryptographic keys with a trusted third party for recovery.

Perfect forward secrecy
Show answer

Session keys that, if compromised, don't expose past or future sessions.

Block vs. stream cipher
Show answer

Block ciphers encrypt fixed-size blocks (AES); stream ciphers encrypt bit/byte by byte (RC4).

Kerckhoffs's principle
Show answer

A cryptosystem should be secure even if everything but the key is public.

Physical security — CPTED
Show answer

Crime Prevention Through Environmental Design — using layout to deter crime.

Mantrap / access control vestibule
Show answer

A two-door entry that allows only one person at a time, preventing tailgating.

Fire suppression — water vs. gas
Show answer

Water (sprinklers) for general areas; clean-agent gas for equipment rooms to avoid damage.

Faraday cage
Show answer

An enclosure that blocks electromagnetic signals (and emanations like TEMPEST).

TEMPEST
Show answer

Standards to prevent data leakage via electromagnetic emanations from equipment.

Communication & Network Security (40)

OSI model
Show answer

A seven-layer model: Physical, Data Link, Network, Transport, Session, Presentation, Application.

OSI Layer 1 — Physical
Show answer

Cables, signals, and hubs; transmits raw bits.

OSI Layer 2 — Data Link
Show answer

MAC addresses and switches; frames on the local network.

OSI Layer 3 — Network
Show answer

IP addressing and routing; routers and IPsec operate here.

OSI Layer 4 — Transport
Show answer

End-to-end delivery; TCP and UDP, port numbers.

OSI Layer 5 — Session
Show answer

Establishes, manages, and tears down sessions.

OSI Layer 6 — Presentation
Show answer

Data translation, encoding, and encryption formatting.

OSI Layer 7 — Application
Show answer

User-facing protocols: HTTP, DNS, SMTP.

TCP/IP model
Show answer

A four-layer model: Link, Internet, Transport, Application — maps onto OSI.

TCP vs. UDP
Show answer

TCP is connection-oriented and reliable (handshake); UDP is connectionless and fast.

TCP three-way handshake
Show answer

SYN, SYN-ACK, ACK — establishes a reliable TCP connection.

Switch (Layer 2)
Show answer

Forwards frames using MAC addresses within a local network.

Router (Layer 3)
Show answer

Forwards packets between networks using IP addresses.

Firewall
Show answer

A device or software that filters traffic between networks based on rules.

Stateful firewall
Show answer

Tracks the state of connections and allows return traffic for established sessions.

Packet-filtering firewall
Show answer

Filters traffic by IP, port, and protocol without tracking connection state.

Next-generation firewall (NGFW)
Show answer

Adds application awareness, IPS, and deep packet inspection to a firewall.

Proxy server
Show answer

An intermediary that forwards requests on behalf of clients, hiding internal hosts.

DMZ
Show answer

A screened subnet between the internet and the internal network for public-facing servers.

VLAN
Show answer

A logical network segment that isolates traffic at Layer 2 for security and performance.

Network segmentation
Show answer

Dividing a network into zones to limit lateral movement and contain breaches.

VPN
Show answer

An encrypted tunnel that protects traffic over an untrusted network.

IPsec
Show answer

A Layer 3 protocol suite that secures IP traffic; used for VPNs (AH and ESP).

IPsec AH vs. ESP
Show answer

AH provides integrity/authentication; ESP provides confidentiality (encryption) plus integrity.

TLS
Show answer

Transport Layer Security — encrypts application traffic (HTTPS); successor to SSL.

SSH
Show answer

Secure Shell — encrypted remote administration; replaces Telnet.

Insecure legacy protocols
Show answer

Telnet, FTP, HTTP, SNMPv1/2, and WEP transmit data in the clear — avoid them.

WPA2 / WPA3
Show answer

Wi-Fi security protocols; WPA3 is the current standard with stronger encryption.

WEP
Show answer

An obsolete, broken Wi-Fi security protocol — never use it.

IDS vs. IPS
Show answer

An IDS detects and alerts on attacks; an IPS detects and actively blocks them.

NAC
Show answer

Network Access Control — enforces policy (e.g., patch state) before allowing a device on the network.

DDoS attack
Show answer

Distributed Denial of Service — overwhelming a target with traffic from many sources.

Man-in-the-middle (MITM)
Show answer

An attacker intercepts and possibly alters communication between two parties.

ARP spoofing
Show answer

Forging ARP replies to associate the attacker's MAC with another host's IP.

DNS poisoning
Show answer

Corrupting DNS records to redirect users to malicious sites.

Software-Defined Networking (SDN)
Show answer

Decoupling network control from forwarding, managed centrally by software.

Network access — 802.1X
Show answer

A port-based network access control standard requiring authentication before access.

Converged protocols
Show answer

Carrying multiple traffic types over one network (e.g., VoIP, FCoE) — security implications.

Zero Trust
Show answer

A model that trusts no one by default; verifies every request regardless of network location.

Microsegmentation
Show answer

Fine-grained segmentation down to individual workloads, a key Zero Trust technique.

Identity & Access Management (40)

Identification
Show answer

A subject claiming an identity (e.g., a username) — the first step of access control.

Authentication
Show answer

Proving a claimed identity with a credential (knowledge, possession, or inherence).

Authorization
Show answer

Determining what an authenticated identity is permitted to access and do.

Accountability
Show answer

Tying actions back to a specific identity through logging and auditing.

AAA
Show answer

Authentication, Authorization, and Accounting — the pillars of access control.

Type 1 factor — something you know
Show answer

Knowledge factor: password, PIN, or passphrase.

Type 2 factor — something you have
Show answer

Possession factor: smart card, hardware token, or phone.

Type 3 factor — something you are
Show answer

Inherence (biometric) factor: fingerprint, iris, or face.

Multi-factor authentication (MFA)
Show answer

Using two or more factors from DIFFERENT categories — know, have, are.

Why two passwords isn't MFA
Show answer

Two of the same factor type (password + security question) is still single-factor.

Biometric — FAR
Show answer

False Acceptance Rate — wrongly accepting an unauthorized person (a security failure).

Biometric — FRR
Show answer

False Rejection Rate — wrongly rejecting an authorized person (a usability failure).

Biometric — CER
Show answer

Crossover Error Rate — where FAR equals FRR; lower CER means a better biometric system.

Least privilege
Show answer

Granting users and processes only the minimum access needed — and nothing more.

Need to know
Show answer

Limiting access to the specific information required to perform a task.

Separation of duties
Show answer

Splitting a sensitive task so no single person controls it end to end.

Job rotation
Show answer

Periodically moving staff between roles to detect fraud and reduce dependence.

Mandatory vacation
Show answer

Requiring time off so fraud that depends on continuous presence is exposed.

Discretionary access control (DAC)
Show answer

The data owner decides who gets access (file permissions, ACLs).

Mandatory access control (MAC)
Show answer

The system enforces access from labels and clearances; rigid and high-security.

Role-based access control (RBAC)
Show answer

Access granted by job role rather than the individual; scales in enterprises.

Attribute-based access control (ABAC)
Show answer

Access decided by attributes and policy (user, resource, time, location) — most granular.

Rule-based access control
Show answer

Global rules applied to everyone (e.g., a firewall ruleset, time-of-day limits).

Access Control List (ACL)
Show answer

A list specifying which subjects may access an object and with what rights.

Capability table
Show answer

A list of the objects a specific subject is allowed to access (subject-centric).

Single sign-on (SSO)
Show answer

One authentication grants access to multiple systems.

Kerberos
Show answer

A symmetric-key SSO protocol using tickets and a Key Distribution Center (KDC).

Kerberos KDC
Show answer

Key Distribution Center — issues tickets; comprises the Authentication Server and TGS.

Kerberos TGT
Show answer

Ticket-Granting Ticket — proves a user authenticated, used to request service tickets.

SAML
Show answer

Security Assertion Markup Language — XML standard for web SSO and federation.

OAuth 2.0
Show answer

An authorization framework that lets apps access resources without sharing passwords.

OpenID Connect (OIDC)
Show answer

An authentication layer on top of OAuth 2.0 for federated login.

Federation
Show answer

Linking identity across organizations so one set of credentials works across trusted domains.

Identity provider (IdP)
Show answer

The system that authenticates users and asserts identity to service providers.

Provisioning / deprovisioning
Show answer

Creating and removing user access; timely deprovisioning prevents orphan accounts.

Privileged Access Management (PAM)
Show answer

Controlling, monitoring, and securing accounts with elevated rights.

Identity proofing
Show answer

Verifying that a person is who they claim before issuing credentials.

Session management
Show answer

Securely creating, maintaining, and terminating sessions (timeouts, tokens).

Just-in-time (JIT) access
Show answer

Granting elevated access only when needed and for a limited time.

Account lockout
Show answer

Disabling an account after repeated failed logins to slow brute-force attacks.

Security Assessment & Testing (31)

Security assessment
Show answer

A broad review of a system's controls and risk posture against requirements.

Security audit
Show answer

An independent, systematic evaluation of controls against a standard or policy.

Vulnerability scan
Show answer

An automated check that identifies known weaknesses without exploiting them.

Penetration test
Show answer

An authorized, simulated attack that actively exploits weaknesses to show real impact.

Scan vs. pen test
Show answer

A scan finds the holes; a pen test proves what an attacker could do with them.

Black-box test
Show answer

The tester has no prior knowledge of the target (simulates an outside attacker).

White-box test
Show answer

The tester has full knowledge of the target (architecture, source, credentials).

Gray-box test
Show answer

The tester has partial knowledge of the target.

Rules of engagement
Show answer

The written scope, limits, and authorization for a penetration test.

Static application security testing (SAST)
Show answer

Analyzing source code for flaws without running it.

Dynamic application security testing (DAST)
Show answer

Testing a running application from the outside for vulnerabilities.

Code review
Show answer

Examining source code (manually or with tools) to find security and quality flaws.

Fuzzing
Show answer

Feeding malformed or random input to find crashes and security flaws.

Misuse case testing
Show answer

Testing how a system behaves under intentional misuse or attack scenarios.

Test coverage analysis
Show answer

Measuring how much of the code or requirements the tests exercise.

Synthetic transactions
Show answer

Scripted, simulated user interactions used to test and monitor systems.

Log review
Show answer

Examining logs to detect anomalies, policy violations, and incidents.

SOC 1 report
Show answer

An attestation on controls relevant to financial reporting.

SOC 2 report
Show answer

An attestation on controls for security, availability, processing integrity, confidentiality, privacy.

SOC 3 report
Show answer

A general-use, public summary version of a SOC 2 report.

SOC Type I vs. Type II
Show answer

Type I = controls at a point in time; Type II = controls' operating effectiveness over a period.

KPI vs. KRI
Show answer

KPI measures performance toward a goal; KRI measures risk exposure (an early warning).

Vulnerability management lifecycle
Show answer

Discover, prioritize, remediate, and verify vulnerabilities continuously.

CVSS
Show answer

Common Vulnerability Scoring System — a 0-10 severity score for vulnerabilities.

CVE
Show answer

Common Vulnerabilities and Exposures — a standardized identifier for a known vulnerability.

Internal vs. external testing
Show answer

Internal simulates an insider/compromised host; external simulates an internet attacker.

Account management review
Show answer

Periodically reviewing accounts and entitlements to enforce least privilege.

Disaster recovery testing
Show answer

Checklist, tabletop, simulation, parallel, and full-interruption tests of recovery plans.

Tabletop exercise
Show answer

A discussion-based walkthrough of a plan with no system disruption.

Parallel test
Show answer

Bringing recovery systems online alongside production to verify they work, without cutover.

Full-interruption test
Show answer

Shutting down production to fully exercise recovery — most realistic, most risky.

Security Operations (40)

Security operations
Show answer

The day-to-day work of running, monitoring, and defending security controls.

Incident
Show answer

An event that actually or potentially harms the confidentiality, integrity, or availability of assets.

Event vs. incident
Show answer

An event is any observable occurrence; an incident is an event that causes or threatens harm.

Incident response — Detection
Show answer

Identify and confirm that an incident has occurred.

Incident response — Response
Show answer

Contain the incident to limit damage.

Incident response — Mitigation
Show answer

Reduce the impact and stop the spread.

Incident response — Reporting
Show answer

Notify stakeholders and required authorities.

Incident response — Recovery
Show answer

Restore systems to normal operation.

Incident response — Remediation
Show answer

Fix the root cause so the incident can't recur.

Incident response — Lessons Learned
Show answer

Review the response and improve the plan and controls.

Containment
Show answer

Limiting the scope and damage of an incident before eradication and recovery.

NIST SP 800-61
Show answer

Incident handling guide: Preparation; Detection & Analysis; Containment, Eradication & Recovery; Post-Incident.

CSIRT
Show answer

Computer Security Incident Response Team — the group that handles incidents.

SIEM
Show answer

Security Information and Event Management — aggregates and correlates logs for detection and analysis.

SOAR
Show answer

Security Orchestration, Automation, and Response — automates incident handling workflows.

Logging and monitoring
Show answer

Recording events and watching them to detect, investigate, and prove activity.

Clipping level
Show answer

A threshold of activity that, when exceeded, triggers an alert (e.g., failed logins).

Egress monitoring
Show answer

Watching outbound traffic to detect data exfiltration.

Change management
Show answer

A controlled process for requesting, evaluating, approving, and documenting system changes.

Configuration management
Show answer

Maintaining known-good, documented configurations and baselines for systems.

Patch management
Show answer

Identifying, testing, and deploying software updates to fix vulnerabilities.

Backup — full
Show answer

Backs up all selected data; fastest to restore, slowest to back up.

Backup — incremental
Show answer

Backs up changes since the last backup of any type; fast backup, slow restore.

Backup — differential
Show answer

Backs up changes since the last full backup; slower backup, faster restore.

3-2-1 backup rule
Show answer

Keep 3 copies, on 2 media types, with 1 copy offsite.

RAID
Show answer

Redundant Array of Independent Disks — combines disks for redundancy and/or performance.

RAID 1 / RAID 5
Show answer

RAID 1 mirrors disks; RAID 5 stripes with parity, tolerating one disk failure.

Hot site
Show answer

A fully equipped alternate site with near-real-time failover; fastest, most expensive.

Warm site
Show answer

An alternate site with hardware and connectivity; data restored on demand; moderate cost.

Cold site
Show answer

An alternate site with power and space only; cheapest, slowest to bring online.

Redundant site
Show answer

A fully mirrored, always-on duplicate of the primary site (highest cost).

Evidence — chain of custody
Show answer

Documentation of who handled evidence and when, preserving its integrity.

Best evidence rule
Show answer

Original documents/evidence are preferred over copies in legal proceedings.

Real / documentary / testimonial evidence
Show answer

Physical objects; written records; witness statements — types of evidence.

Forensics — order of volatility
Show answer

Collect the most volatile data first (CPU/RAM) before disk and archives.

eDiscovery
Show answer

The process of identifying and producing electronic data for legal proceedings.

Service Level Agreement (SLA)
Show answer

A contract defining the expected level of service and remedies.

Honeypot
Show answer

A decoy system designed to attract and study attackers.

Whitelisting / allow-listing
Show answer

Permitting only approved applications or addresses; everything else is blocked.

Sandboxing
Show answer

Running untrusted code in an isolated environment to contain harm.

Software Development Security (40)

Software Development Lifecycle (SDLC)
Show answer

The phased process of building software: requirements, design, build, test, deploy, maintain.

Secure SDLC
Show answer

Building security into every phase of development rather than testing for it at the end.

Shift left
Show answer

Moving security activities earlier in development, where flaws are cheaper to fix.

Waterfall model
Show answer

A sequential, phase-by-phase development model; rigid, suits stable requirements.

Agile model
Show answer

Iterative development in short sprints; flexible and delivers frequently.

DevOps
Show answer

Integrating development and operations for continuous, automated delivery.

DevSecOps
Show answer

Embedding automated security testing throughout DevOps CI/CD pipelines.

Spiral model
Show answer

An iterative model with heavy risk analysis in each cycle.

CI/CD
Show answer

Continuous Integration / Continuous Delivery — automated build, test, and deployment pipelines.

Threat modeling in design
Show answer

Identifying threats early (e.g., STRIDE) so the design mitigates them.

Capability Maturity Model (CMM/CMMI)
Show answer

A model rating process maturity from initial to optimizing.

BSIMM
Show answer

Building Security In Maturity Model — measures a software security program against peers.

OWASP SAMM
Show answer

Software Assurance Maturity Model — a framework to assess and improve secure development.

OWASP Top 10
Show answer

A community list of the most critical web application security risks.

Broken access control
Show answer

The #1 OWASP risk — users acting outside their intended permissions.

Injection
Show answer

Untrusted input is interpreted as a command or query (e.g., SQL injection).

SQL injection
Show answer

Inserting malicious SQL via unvalidated input to read or alter a database.

Cross-site scripting (XSS)
Show answer

Injecting malicious scripts into web pages viewed by other users.

Cross-site request forgery (CSRF)
Show answer

Tricking a logged-in user's browser into making unwanted requests.

Input validation
Show answer

Checking and sanitizing all input — the primary defense against injection attacks.

Parameterized queries
Show answer

Using prepared statements with bound parameters to prevent SQL injection.

Output encoding
Show answer

Encoding data before rendering it to prevent XSS.

Buffer overflow
Show answer

Writing past a buffer's bounds to corrupt memory or execute code; prevented by bounds checking.

Race condition (TOCTOU)
Show answer

Time-of-check to time-of-use — a flaw exploiting the gap between checking and using a resource.

Inference
Show answer

Deducing sensitive information from data you are allowed to see.

Aggregation
Show answer

Combining individually harmless pieces of data into sensitive information.

Polyinstantiation
Show answer

Storing different data at different classification levels to prevent inference.

Database — ACID
Show answer

Atomicity, Consistency, Isolation, Durability — properties of reliable transactions.

Database normalization
Show answer

Organizing data to reduce redundancy and improve integrity.

Stored procedure
Show answer

Precompiled SQL stored in the database; can reduce injection risk and centralize logic.

Code repository security
Show answer

Protecting source control with access control, signing, and secret scanning.

Software supply chain risk
Show answer

Vulnerabilities introduced through third-party libraries and dependencies.

Software Composition Analysis (SCA)
Show answer

Scanning dependencies for known vulnerabilities and license issues.

Sandboxing untrusted code
Show answer

Isolating code (e.g., applets, plugins) so it can't harm the host.

Secure coding standards
Show answer

Documented rules (e.g., OWASP, CERT) for writing safe code.

Maintenance hooks / backdoors
Show answer

Hidden developer access that must be removed before release.

Object-oriented security
Show answer

Encapsulation, inheritance, and polymorphism affect how data is protected in code.

API security
Show answer

Protecting APIs with authentication, authorization, rate limiting, and input validation.

Regression testing
Show answer

Re-running tests after changes to ensure new code didn't break existing functionality.

Code signing
Show answer

Digitally signing software so users can verify its source and integrity.

References

  1. 1.ISC2. “CISSP Certification Exam Outline (effective April 15, 2024).” isc2.org. ↑
  2. 2.ISC2. “CISSP — Certified Information Systems Security Professional.” isc2.org. ↑
  3. 3.National Institute of Standards and Technology. “SP 800-53 Rev. 5: Security and Privacy Controls.” csrc.nist.gov. ↑
Career Employer

Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.

Follow Us:

All Posts

Career Employer’s Editorial Process

Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.