Click Study Flashcards above to open the flashcard hub — hundreds of ISSEP cards you can flip, match, type, or quiz yourself on. Every card is drawn from the five official ISC2 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
ISSEP is one of the 9 ISC2 certifications — explore our ISC2 flashcards to compare and prep across the whole family.
ISSEP Flashcard Study Modes
Flip mode lets you turn cards one at a time and rate what you actually know. Match is a timed game that pairs terms with definitions under pressure. Type shows the definition and asks you to key the term back, so a card like Attack surface has to come from memory. Quiz turns the same 200 cards into multiple choice.

Why Flashcards Work for the ISSEP
Systems Security Engineering Foundations holds 21 cards and carries the heaviest official weight at 24%, so the smallest stack earns the most attention. These cards define the vocabulary the rest of the deck leans on, including IATF, Stakeholder, Protection needs, and Concept stage, plus scope-setting terms such as Tailored trust and CISSP-ISSEP.
Security Planning and Engineering is the largest section at 58 cards and 22% of the exam. The terms run from threat modeling methods like STRIDE and Attack tree to design principles such as Open design and Segmentation, alongside core properties including Integrity and Availability.
Risk Management contributes 48 cards against a 20% weight, and much of it is federal guidance you need to recall by number. Expect FIPS 199 and FIPS 200 for categorization and controls, CNSSI 1253 and Overlay for tailoring, plus foundational terms such as Threat and Impact.
Systems Security Implementation, Verification, and Validation has 32 cards for another 20%. These drill how security is built and proven: Secure SDLC, Assurance case, Evidence, and Penetration testing, with lifecycle markers like Development stage and Production stage and standards such as FIPS 140-3.
Secure Operations, Change Management and Disposal rounds out the deck with 41 cards at 14%. The cards cover sustainment and end-of-life practice, from Hardening and Audit logging to incident terms like Containment and NIST SP 800-61, plus NIST SP 800-34 and NIST SP 800-88 for continuity and media sanitization.
The ISSEP is dense with framework terminology — NIST SP 800-160 systems security engineering, the Risk Management Framework, the system life cycle, and verification and validation.[2] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
ISSEP Flashcards by Domain
The cards are organized by the five official ISC2 domains. The weights are uneven, so lead with the two engineering domains — Systems Security Engineering Foundations and Security Planning & Engineering:[1]
| Domain | Exam weight |
|---|---|
| Systems Security Engineering Foundations | 24% |
| Security Planning & Engineering | 22% |
| Risk Management | 20% |
| Implementation, Verification & Validation | 20% |
| Secure Operations, Change Management & Disposal | 14% |
How to Get the Most Out of These Flashcards
- Start with the foundations. Systems Security Engineering Foundations is only 21 cards but carries 24%, so clearing terms like Protection needs and Trustworthiness early pays off across every other domain.
- Type-drill the publication numbers. Cards such as CNSSI 1253 and FIPS 140-3 are easy to recognize and hard to produce, so Type mode exposes the gap that Flip mode hides.
- Use Match for definition families. The NIST document cards cluster well, so a timed round that mixes NIST SP 800-34, NIST SP 800-61, and NIST SP 800-88 forces precise separation.
- Move to the practice test when Quiz stalls. Once multiple choice stops surprising you in all five domains, shift to the practice test for scenario length and the study guide for depth.
- Keep a rotating cadence. Take one domain per session, split the 58 cards of Security Planning and Engineering across two sittings, and reshuffle older domains into every review.
ISSEP Flashcards FAQ
Hundreds of free CISSP-ISSEP flashcards, organized across all five ISC2 domains — Systems Security Engineering Foundations, Risk Management, Security Planning and Engineering, Systems Security Implementation, Verification and Validation, and Secure Operations, Change Management and Disposal. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions across several days. They're ideal for the ISSEP's dense framework terminology across NIST SP 800-160, the RMF, and the system life cycle.
All five ISC2 domains: Systems Security Engineering Foundations (SSE, trustworthiness, the TCB), Risk Management (the RMF, FIPS 199, the ATO), Security Planning and Engineering (requirements, architecture, resiliency, zero trust), Implementation, Verification and Validation (V&V, testing, assessment), and Secure Operations, Change Management and Disposal.
Lead with the two engineering domains — Systems Security Engineering Foundations (24%) and Security Planning and Engineering (22%) — which are nearly half the exam. Mix the modes: flip to learn, type to test recall, match for speed, and quiz to check yourself before a full practice test.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current ISC2 CISSP-ISSEP exam outline, covering all five scored domains in their official proportions, with definitions grounded in NIST publications.
ISSEP flashcard bank
All 200 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Systems Security Engineering Foundations (21)
- CISSP-ISSEP
Show answerHide answer
Information Systems Security Engineering Professional — an ISC2 advanced concentration for CISSP holders that focuses on engineering security into systems and projects throughout the system life cycle.
- Systems security engineering (SSE)
Show answerHide answer
The disciplined application of engineering principles to design, build, and sustain trustworthy systems that satisfy stakeholder security needs across the entire life cycle (NIST SP 800-160 Vol. 1).
- NIST SP 800-160 Vol. 1
Show answerHide answer
Engineering Trustworthy Secure Systems — the foundational SSE publication that adapts ISO/IEC/IEEE 15288 life-cycle processes to security engineering.
- NIST SP 800-160 Vol. 2
Show answerHide answer
Developing Cyber-Resilient Systems — a Systems Security Engineering Approach, covering anticipate, withstand, recover, and adapt against advanced cyber threats.
- ISO/IEC/IEEE 15288
Show answerHide answer
The international standard defining the system life-cycle processes (agreement, organizational project-enabling, technical management, and technical) that SSE adapts for security.
- Trustworthiness
Show answerHide answer
The degree of confidence that a system meets its requirements, behaves as intended, and is worthy of being relied upon — the central goal of systems security engineering.
- Trust vs. trustworthiness
Show answerHide answer
Trust is a belief or willingness to depend on a system; trustworthiness is the demonstrated, evidence-based property that justifies that trust.
- Protection needs
Show answerHide answer
Stakeholder-driven statements of what must be protected and the consequences of loss; they ground security requirements in asset value rather than arbitrary controls.
- Asset
Show answerHide answer
Anything of value to stakeholders — data, systems, capabilities, or missions — whose loss, corruption, or denial would cause adverse consequences.
- Stakeholder
Show answerHide answer
Any party with a legitimate interest in a system — owners, users, operators, regulators, or the public — whose needs and concerns drive requirements.
- Security concept of operations (Security CONOPS)
Show answerHide answer
A narrative describing how a system's security functions are intended to operate from the user's and operator's perspective.
- Concept of operations (CONOPS)
Show answerHide answer
A user-oriented document describing system characteristics and how stakeholders intend to operate it, used to derive requirements.
- Mission / business function
Show answerHide answer
The organizational objective a system supports; SSE traces protection needs and risk back to mission impact.
- System life cycle
Show answerHide answer
The full span of a system from concept through development, production, utilization, support, and retirement; SSE applies to every stage.
- Concept stage
Show answerHide answer
The earliest life-cycle stage where mission needs, protection needs, and feasibility are explored before requirements are set.
- Information Systems Security Engineer (ISSE)
Show answerHide answer
The engineer who applies SSE processes to define needs, design, and integrate security into a system across its life cycle.
- ISSE process (IATF)
Show answerHide answer
Discover needs, define requirements, design architecture, develop detailed design, implement, and assess effectiveness — the legacy IATF SE-companion model.
- IATF
Show answerHide answer
Information Assurance Technical Framework — historical guidance pairing the ISSE process with the systems engineering process.
- Information assurance (IA)
Show answerHide answer
Measures that protect and defend information and systems by ensuring availability, integrity, authentication, confidentiality, and non-repudiation.
- Holistic protection
Show answerHide answer
Engineering security across people, process, and technology and the full life cycle, rather than relying on isolated technical fixes.
- Tailored trust
Show answerHide answer
Designing the right level of trustworthiness for stakeholder needs and risk — adequate security, justified by assurance evidence.
Risk Management (48)
- Risk Management Framework (RMF)
Show answerHide answer
NIST SP 800-37's seven-step process for managing security and privacy risk: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.
- NIST SP 800-37
Show answerHide answer
Risk Management Framework for Information Systems and Organizations — defines the RMF steps, tasks, and roles for authorizing systems to operate.
- RMF Step 1 — Prepare
Show answerHide answer
Establish context and priorities for managing risk at the organization and system levels before categorization begins (added in Rev. 2).
- RMF Step 2 — Categorize
Show answerHide answer
Determine the system's impact level by categorizing the information and system using FIPS 199 (confidentiality, integrity, availability).
- RMF Step 3 — Select
Show answerHide answer
Choose an appropriate baseline of security controls from NIST SP 800-53 and tailor it to the system and its risk.
- RMF Step 6 — Authorize
Show answerHide answer
A senior official (the authorizing official) accepts the residual risk and grants an Authorization to Operate (ATO).
- Authorization to Operate (ATO)
Show answerHide answer
The formal management decision by an authorizing official to accept residual risk and permit a system to operate.
- Authorizing Official (AO)
Show answerHide answer
The senior executive with authority to formally assume responsibility for operating a system at an acceptable level of risk.
- FIPS 199
Show answerHide answer
Standards for Security Categorization — sets potential impact (low, moderate, high) for confidentiality, integrity, and availability.
- FIPS 200
Show answerHide answer
Minimum Security Requirements for Federal Information and Information Systems — mandates selecting an appropriate SP 800-53 control baseline.
- High-water mark
Show answerHide answer
The FIPS 199 rule that a system's overall categorization equals the highest impact value among its confidentiality, integrity, and availability ratings.
- NIST SP 800-53
Show answerHide answer
Security and Privacy Controls for Information Systems and Organizations — the catalog of controls and control baselines used in RMF Select.
- Control baseline
Show answerHide answer
A predefined set of minimum security controls (low, moderate, or high) selected for a system based on its FIPS 199 categorization.
- Control tailoring
Show answerHide answer
Adjusting a baseline by adding, removing, or refining controls and applying scoping and overlays to fit a specific system and risk.
- Overlay
Show answerHide answer
A specification of controls and tailoring for a community of interest (e.g., privacy, cloud, classified) applied on top of a baseline.
- Common control
Show answerHide answer
A control inherited by multiple systems and managed by a provider, reducing redundant implementation (the basis of control inheritance).
- Hybrid control
Show answerHide answer
A control partly inherited as common and partly implemented system-specifically.
- Risk
Show answerHide answer
A measure of the extent to which an entity is threatened by a potential event, expressed as a function of likelihood and impact.
- Threat
Show answerHide answer
Any circumstance or event with the potential to adversely impact assets through unauthorized access, destruction, disclosure, or denial of service.
- Vulnerability
Show answerHide answer
A weakness in a system, control, or process that could be exploited by a threat source.
- Likelihood
Show answerHide answer
A weighted estimate of the probability that a given threat will exploit a vulnerability, used with impact to determine risk.
- Impact
Show answerHide answer
The magnitude of harm from a loss of confidentiality, integrity, or availability of information or a system.
- NIST SP 800-30
Show answerHide answer
Guide for Conducting Risk Assessments — the methodology for identifying threats, vulnerabilities, likelihood, and impact.
- NIST SP 800-39
Show answerHide answer
Managing Information Security Risk — frames risk management at the organization, mission/business process, and information system tiers.
- Three-tier risk model
Show answerHide answer
SP 800-39's structure: Tier 1 organization, Tier 2 mission/business process, Tier 3 information system — risk flows between tiers.
- Risk frame
Show answerHide answer
The set of assumptions, constraints, tolerances, and priorities that establishes the context for organizational risk decisions.
- Risk tolerance
Show answerHide answer
The level of risk an organization is willing to accept in pursuit of its mission and objectives.
- Risk treatment options
Show answerHide answer
Accept, avoid, mitigate (reduce), or transfer (share) — the choices for responding to an assessed risk.
- Residual risk
Show answerHide answer
The risk remaining after controls are applied; the authorizing official must formally accept it before an ATO.
- Inherent risk
Show answerHide answer
The level of risk present before any controls or mitigations are applied.
- Plan of Action and Milestones (POA&M)
Show answerHide answer
A document that tracks identified weaknesses, planned remediation, resources, and milestones for closing security gaps.
- Authorization package
Show answerHide answer
The SSP, SAR, and POA&M (plus supporting evidence) submitted to the authorizing official for the risk-acceptance decision.
- Risk Management Framework roles
Show answerHide answer
Includes the AO, system owner, common control provider, security control assessor, ISSO, ISSE, and SISO/CISO.
- Adversary (advanced persistent threat)
Show answerHide answer
A capable, well-resourced threat actor that establishes a long-term presence to achieve objectives; a primary driver of cyber-resilient design.
- Cyber kill chain
Show answerHide answer
A model of attack phases (reconnaissance through actions on objectives) used to design controls that disrupt adversaries early.
- MITRE ATT&CK
Show answerHide answer
A knowledge base of adversary tactics and techniques used to inform threat analysis, control selection, and detection engineering.
- Cost-benefit analysis
Show answerHide answer
Comparing the cost of a control against the reduction in expected loss it provides; a control should not cost more than the asset it protects.
- Authorization boundary
Show answerHide answer
All components of an information system to be authorized for operation, excluding separately authorized systems it connects to.
- Supply chain risk management (SCRM)
Show answerHide answer
Managing risks from suppliers, components, and services across the system's supply chain (NIST SP 800-161).
- NIST SP 800-161
Show answerHide answer
Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations (C-SCRM).
- Counterfeit / tampered component
Show answerHide answer
A supply-chain threat where hardware or software is altered or faked; mitigated by provenance, validation, and trusted suppliers.
- Software Bill of Materials (SBOM)
Show answerHide answer
A formal inventory of software components and dependencies used to manage supply-chain and vulnerability risk.
- Acquisition security
Show answerHide answer
Embedding security requirements into procurement and contracts so suppliers deliver trustworthy components and services.
- Trusted foundry / provenance
Show answerHide answer
Sourcing critical components from trusted, verified suppliers and tracking their origin to counter supply-chain tampering.
- FISMA
Show answerHide answer
The Federal Information Security Modernization Act, which mandates risk-based security programs and authorization for federal systems.
- OMB Circular A-130
Show answerHide answer
Federal policy requiring agencies to manage information resources and security risk, including authorization and continuous monitoring.
- Committee on National Security Systems (CNSS)
Show answerHide answer
The body issuing policy and instruction (e.g., CNSSI 1253) for securing national security systems.
- CNSSI 1253
Show answerHide answer
Security Categorization and Control Selection for National Security Systems — the NSS counterpart to FIPS 199/200 and SP 800-53.
Security Planning and Engineering (58)
- Loss
Show answerHide answer
An adverse consequence to asset value from an event; SSE seeks to limit losses to a level acceptable to stakeholders.
- Adequate security
Show answerHide answer
Security commensurate with the risk and magnitude of harm from loss — neither over- nor under-engineered relative to stakeholder protection needs.
- Defense in depth
Show answerHide answer
Layering multiple, diverse, overlapping safeguards so the failure of one control does not result in compromise of the asset.
- Least privilege
Show answerHide answer
Granting each subject only the minimum access and capability needed to perform its function, limiting the impact of compromise or error.
- Separation of duties
Show answerHide answer
Dividing a critical task among multiple parties so no single individual can complete it alone, reducing fraud and error.
- Fail-safe / fail-secure
Show answerHide answer
A design principle ensuring that when a system fails it defaults to a state that protects assets (e.g., denies access) rather than exposing them.
- Economy of mechanism
Show answerHide answer
Keeping the design and implementation of security mechanisms as simple and small as possible so they can be analyzed and verified.
- Complete mediation
Show answerHide answer
Every access to every object is checked against the security policy on each request, with no bypass paths.
- Open design
Show answerHide answer
Security should not depend on the secrecy of the design or mechanism (no security through obscurity); it should depend on protecting keys and credentials.
- Psychological acceptability
Show answerHide answer
Security mechanisms should be easy to use so that users apply them correctly and do not work around them.
- Reference monitor
Show answerHide answer
An abstract machine that mediates all access of subjects to objects; it must be tamperproof, always invoked, and small enough to verify.
- Security kernel
Show answerHide answer
The hardware, firmware, and software that implement the reference monitor concept within the Trusted Computing Base.
- Trusted Computing Base (TCB)
Show answerHide answer
The totality of protection mechanisms — hardware, software, firmware — responsible for enforcing a system's security policy.
- Security architecture
Show answerHide answer
The structure that describes how security controls and components are positioned and related to satisfy the protection needs of a system.
- Enterprise architecture framework
Show answerHide answer
A structured method (e.g., DoDAF, TOGAF, Zachman) for describing an organization's systems; security architecture aligns to and extends it.
- Security requirement
Show answerHide answer
A capability or constraint the system must satisfy to meet stakeholder protection needs; it is verifiable and traceable to a need.
- Functional vs. assurance requirements
Show answerHide answer
Functional requirements state what a security control must do; assurance requirements state the evidence and rigor needed to trust that it does it.
- Requirements traceability
Show answerHide answer
Maintaining links from stakeholder needs to requirements, design, implementation, and test so every control has a justified origin.
- Derived requirement
Show answerHide answer
A requirement that arises from analysis or design decisions rather than directly from a stakeholder, but still traces back to a need.
- System Security Plan (SSP)
Show answerHide answer
The formal document describing a system, its boundary, and the implementation of its selected security controls.
- Confidentiality
Show answerHide answer
Preserving authorized restrictions on access and disclosure so information is not revealed to unauthorized parties.
- Integrity
Show answerHide answer
Guarding against improper modification or destruction of information and ensuring non-repudiation and authenticity.
- Availability
Show answerHide answer
Ensuring timely and reliable access to and use of information and systems by authorized users.
- Authentication
Show answerHide answer
Verifying the identity of a user, process, or device as a prerequisite to granting access to system resources.
- Non-repudiation
Show answerHide answer
Assurance that a party cannot deny having performed an action, achieved through signatures, logging, and timestamps.
- Authorization (access)
Show answerHide answer
Granting an authenticated subject the rights and permissions to access specific resources and perform specific actions.
- Cyber resiliency
Show answerHide answer
The ability to anticipate, withstand, recover from, and adapt to adverse cyber conditions, stresses, attacks, or compromises (SP 800-160 Vol. 2).
- Resiliency goals
Show answerHide answer
Anticipate, Withstand, Recover, Adapt — the four high-level objectives of cyber-resilient systems engineering.
- Resiliency techniques
Show answerHide answer
Approaches such as redundancy, diversity, segmentation, deception, and adaptive response used to achieve cyber resiliency.
- Segmentation
Show answerHide answer
Dividing a system into isolated zones to limit the spread of compromise and contain adversary movement.
- Diversity (resiliency)
Show answerHide answer
Using heterogeneous components so a single vulnerability does not affect all elements of a system.
- Deception (resiliency)
Show answerHide answer
Using misdirection (e.g., decoys, honeypots) to confuse adversaries and reveal their activity.
- Attack surface
Show answerHide answer
The set of points where an attacker can attempt to enter, affect, or extract data from a system; SSE seeks to minimize it.
- Threat modeling
Show answerHide answer
Systematically identifying, enumerating, and prioritizing potential threats against a system during design (e.g., using STRIDE or attack trees).
- STRIDE
Show answerHide answer
A threat taxonomy: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
- Attack tree
Show answerHide answer
A hierarchical diagram modeling how an objective (the root) could be achieved through combinations of attack steps.
- Security control
Show answerHide answer
A safeguard or countermeasure — administrative, technical, or physical — that protects the confidentiality, integrity, and availability of a system.
- Administrative control
Show answerHide answer
A management control such as policy, procedures, training, or personnel security that governs behavior.
- Technical control
Show answerHide answer
A control implemented in hardware, software, or firmware, such as encryption, access control lists, or authentication.
- Physical control
Show answerHide answer
A control that protects facilities and equipment, such as locks, guards, fencing, and environmental safeguards.
- Preventive control
Show answerHide answer
A control that stops an undesirable event before it occurs (e.g., access control, encryption).
- Compensating control
Show answerHide answer
An alternative safeguard used when a primary control is not feasible, providing equivalent protection.
- Cryptographic protection
Show answerHide answer
Using approved algorithms and key management to provide confidentiality, integrity, authentication, and non-repudiation.
- Cryptographic key management
Show answerHide answer
The full life cycle of keys — generation, distribution, storage, rotation, and destruction — governed by NIST SP 800-57.
- Public Key Infrastructure (PKI)
Show answerHide answer
The certificate authorities, certificates, and policies that bind public keys to identities and manage trust.
- Symmetric encryption
Show answerHide answer
Encryption using one shared secret key for both encryption and decryption (e.g., AES); fast but requires secure key distribution.
- Asymmetric encryption
Show answerHide answer
Encryption using a public/private key pair (e.g., RSA, ECC) that solves key exchange and enables digital signatures.
- Digital signature
Show answerHide answer
A hash of data encrypted with the signer's private key, providing integrity, authenticity, and non-repudiation.
- Data at rest / in transit / in use
Show answerHide answer
The three states of data that each require protection — encryption for stored and moving data, and protections such as enclaves for data in processing.
- Zero trust architecture
Show answerHide answer
A model (NIST SP 800-207) that assumes no implicit trust and continuously verifies every access request based on identity, device, and context.
- NIST SP 800-207
Show answerHide answer
Zero Trust Architecture — defines the logical components (policy engine, policy administrator, policy enforcement point) and principles of ZTA.
- Policy Enforcement Point (PEP)
Show answerHide answer
The zero-trust component that enables, monitors, and terminates connections between a subject and a resource per policy.
- Policy Decision Point (PDP)
Show answerHide answer
The zero-trust logic (policy engine plus policy administrator) that decides whether to grant access to a resource.
- Trade-off analysis
Show answerHide answer
Evaluating competing design options against cost, performance, risk, and security to choose a balanced solution.
- Security trade-offs
Show answerHide answer
Balancing security objectives against usability, performance, cost, and mission needs to reach adequate (not maximal) security.
- Security boundary
Show answerHide answer
The defined perimeter of a system that establishes what is inside the authorization and protection scope.
- Privacy engineering
Show answerHide answer
Applying engineering practices to manage privacy risk and protect personally identifiable information across the life cycle (NIST SP 800-53 privacy controls).
- Personally Identifiable Information (PII)
Show answerHide answer
Information that can be used to identify an individual; it requires privacy controls and influences categorization and protection.
Systems Security Implementation, Verification, and Validation (32)
- Security verification
Show answerHide answer
Confirming the system was built correctly — that it meets its specified security requirements ("did we build the system right?").
- Security validation
Show answerHide answer
Confirming the right system was built — that it satisfies stakeholder needs and intended use in the operational environment ("did we build the right system?").
- Verification vs. validation
Show answerHide answer
Verification checks compliance with requirements; validation checks fitness for purpose against stakeholder needs and the real environment.
- Security assurance
Show answerHide answer
Grounds for confidence — evidence and analysis — that a system meets its security objectives and behaves as intended.
- Assurance case
Show answerHide answer
A structured, evidence-backed argument that a system's security claims are satisfied, used to justify a trust decision.
- Evidence
Show answerHide answer
Artifacts produced across the life cycle (analyses, test results, reviews) that support the assurance case for a trust decision.
- Development stage
Show answerHide answer
The life-cycle stage where requirements are realized into an architecture, design, and implementation that is verified.
- Production stage
Show answerHide answer
The life-cycle stage where the system is manufactured or built to its verified design for fielding.
- RMF Step 4 — Implement
Show answerHide answer
Deploy the selected controls and document how they are implemented in the system security plan.
- RMF Step 5 — Assess
Show answerHide answer
Evaluate whether controls are implemented correctly, operating as intended, and producing the desired outcome (per SP 800-53A).
- Security Assessment Report (SAR)
Show answerHide answer
The output of RMF Assess: findings on whether controls are implemented correctly and operating effectively, informing the authorization decision.
- Security control assessor (SCA)
Show answerHide answer
The independent party who conducts the assessment of security controls and produces the SAR.
- FIPS 140-3
Show answerHide answer
Security Requirements for Cryptographic Modules — the standard a module must meet for use in federal systems (validated via CMVP).
- System interconnection
Show answerHide answer
A connection between two or more systems requiring agreements (e.g., ISA) and controls to manage shared risk.
- Interconnection Security Agreement (ISA)
Show answerHide answer
A document specifying the technical and security requirements for connecting two systems and managing the shared risk.
- Memorandum of Understanding (MOU)
Show answerHide answer
A document establishing the terms and responsibilities between organizations that interconnect or share resources.
- Secure SDLC
Show answerHide answer
Integrating security activities into every phase of software development rather than testing for it only at the end (e.g., NIST SP 800-218 SSDF).
- NIST SP 800-218 (SSDF)
Show answerHide answer
Secure Software Development Framework — practices for producing well-secured software across the development life cycle.
- Static application security testing (SAST)
Show answerHide answer
Analyzing source code or binaries without executing them to find vulnerabilities early in development.
- Dynamic application security testing (DAST)
Show answerHide answer
Testing a running application to find vulnerabilities observable at runtime.
- Security test and evaluation (ST&E)
Show answerHide answer
Planned testing to determine whether security controls are implemented correctly and meet requirements before authorization.
- Developmental test and evaluation (DT&E)
Show answerHide answer
Testing during development to verify that the system meets technical and security requirements.
- Operational test and evaluation (OT&E)
Show answerHide answer
Testing in a realistic operational environment to validate the system performs and protects as intended in actual use.
- Penetration testing
Show answerHide answer
Authorized, simulated attacks that actively exploit weaknesses to demonstrate real impact under defined rules of engagement.
- Vulnerability scanning
Show answerHide answer
Automated identification of known weaknesses in a system without exploiting them.
- Independent verification and validation (IV&V)
Show answerHide answer
V&V performed by a party technically and managerially independent of the development team to increase assurance.
- Common Criteria (ISO/IEC 15408)
Show answerHide answer
An international standard for evaluating the security assurance of IT products against protection profiles and security targets.
- Protection Profile (PP)
Show answerHide answer
An implementation-independent set of security requirements for a category of products under Common Criteria evaluation.
- Evaluation Assurance Level (EAL)
Show answerHide answer
A Common Criteria rating (EAL1–EAL7) indicating the depth and rigor of an evaluation, not the strength of the product.
- Security functional requirements vs. security target
Show answerHide answer
The Security Target (ST) states the security claims for a specific product; functional requirements specify what the security functions must do.
- Operational readiness review
Show answerHide answer
An assessment confirming a system and its operators are prepared to securely transition into operations.
- Transition to operations
Show answerHide answer
The controlled handover of a verified, validated system from development into the operational environment with sustained security.
Secure Operations, Change Management and Disposal (41)
- Utilization stage
Show answerHide answer
The life-cycle stage where the system is operated to deliver its intended services; secure operations apply here.
- Support stage
Show answerHide answer
The life-cycle stage providing sustainment — maintenance, logistics, and change management — to keep the system operational and secure.
- Retirement stage
Show answerHide answer
The final life-cycle stage where the system is removed from service and disposed of securely (data sanitization, media destruction).
- RMF Step 7 — Monitor
Show answerHide answer
Continuously track control effectiveness, system changes, and risk through ongoing assessment and reporting.
- Continuous monitoring (ISCM)
Show answerHide answer
Ongoing awareness of security, vulnerabilities, and threats (NIST SP 800-137) supporting risk-based decisions throughout operation.
- NIST SP 800-137
Show answerHide answer
Information Security Continuous Monitoring (ISCM) for Federal Information Systems — defines the strategy and process for ongoing monitoring.
- Ongoing authorization
Show answerHide answer
A time-driven or event-driven continuous authorization approach that replaces periodic reauthorization using continuous monitoring data.
- Reauthorization
Show answerHide answer
Re-running the authorization decision when significant changes or events alter a system's risk posture.
- Information System Security Officer (ISSO)
Show answerHide answer
The individual responsible for ensuring an operational system's security posture is maintained day to day.
- Accountability
Show answerHide answer
The ability to trace actions uniquely to an entity through identification, authentication, authorization, and audit.
- Detective control
Show answerHide answer
A control that identifies and signals an event that has occurred (e.g., IDS, audit logs).
- Corrective control
Show answerHide answer
A control that restores systems to a normal state after an event (e.g., backups, patching).
- Configuration management (CM)
Show answerHide answer
The discipline of identifying, controlling, and documenting a system's configuration items and their changes throughout its life.
- Configuration item (CI)
Show answerHide answer
A component or aggregation of components under configuration management that is treated as a single entity.
- Baseline configuration
Show answerHide answer
A documented, approved set of specifications for a system at a point in time, serving as the basis for change control.
- Change management
Show answerHide answer
The controlled process of requesting, evaluating, approving, testing, and documenting changes to a system to preserve its security posture.
- Change Control Board (CCB)
Show answerHide answer
The body that reviews and approves or rejects proposed changes, assessing their security and operational impact.
- Security impact analysis (SIA)
Show answerHide answer
An analysis of how a proposed change affects the security state of a system before the change is approved and deployed.
- Patch management
Show answerHide answer
The process of acquiring, testing, and deploying updates to remediate vulnerabilities while controlling operational risk.
- Hardening
Show answerHide answer
Reducing a system's attack surface by removing unnecessary services, applying secure configurations, and closing default weaknesses.
- Secure configuration baseline (e.g., STIG)
Show answerHide answer
A standardized, hardened configuration (such as a DISA STIG or CIS Benchmark) applied to reduce vulnerabilities.
- Audit logging
Show answerHide answer
Recording security-relevant events to support detection, accountability, and forensic analysis.
- Security Information and Event Management (SIEM)
Show answerHide answer
A platform that aggregates and correlates logs and events across systems for detection, alerting, and analysis.
- Incident response
Show answerHide answer
The structured process to prepare for, detect, contain, eradicate, recover from, and learn from security incidents (NIST SP 800-61).
- NIST SP 800-61
Show answerHide answer
Computer Security Incident Handling Guide — defines the incident response life cycle and handling practices.
- Containment
Show answerHide answer
Limiting the scope and damage of an incident before eradication and recovery — "stop the bleeding first."
- Contingency planning
Show answerHide answer
Preparing to maintain or restore operations after a disruption (NIST SP 800-34), including backups and alternate sites.
- NIST SP 800-34
Show answerHide answer
Contingency Planning Guide for Federal Information Systems — covers BIA, recovery strategies, and plan testing.
- Business Impact Analysis (BIA)
Show answerHide answer
An analysis that identifies critical functions and sets recovery objectives (MTD, RTO, RPO), driving continuity decisions.
- Recovery Time Objective (RTO)
Show answerHide answer
The targeted time to restore a function after a disruption; it must be shorter than the maximum tolerable downtime.
- Recovery Point Objective (RPO)
Show answerHide answer
The maximum acceptable amount of data loss measured backward in time, which drives backup frequency.
- Maximum Tolerable Downtime (MTD)
Show answerHide answer
The longest a function can be unavailable before unacceptable harm occurs; it bounds the RTO.
- Disaster recovery (DR)
Show answerHide answer
The processes to restore IT systems and data after a disruptive event, a subset of overall continuity planning.
- Backup strategy
Show answerHide answer
The plan for full, incremental, or differential backups and their storage to meet the RPO and support recovery.
- Media sanitization
Show answerHide answer
Removing data from media via clearing, purging, or destruction so it cannot be recovered (NIST SP 800-88).
- NIST SP 800-88
Show answerHide answer
Guidelines for Media Sanitization — defines Clear, Purge, and Destroy levels matched to data confidentiality.
- Data remanence
Show answerHide answer
Residual data remaining on media after deletion or formatting that may be recoverable without proper sanitization.
- Secure disposal
Show answerHide answer
Securely retiring systems and media — sanitizing data, destroying keys, and documenting disposition — at end of life.
- Decommissioning
Show answerHide answer
The orderly removal of a system from service, including data migration, sanitization, and revocation of credentials and authorizations.
- Key destruction (zeroization)
Show answerHide answer
Securely erasing cryptographic keys from memory and storage so they cannot be recovered when a system is retired or compromised.
- Lessons learned
Show answerHide answer
Capturing what worked and what failed after incidents, tests, or projects to improve future engineering and operations.
References
- 1.ISC2. “CISSP-ISSEP Information Systems Security Engineering Professional.” isc2.org. ↑
- 2.National Institute of Standards and Technology. “SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems.” csrc.nist.gov. ↑
- 3.National Institute of Standards and Technology. “SP 800-37 Rev. 2: Risk Management Framework.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
