Last updated:
CISSP glossary
Which CISSP terms should you know, and how should you use them?
Direct answer
A useful CISSP glossary defines security terms in decision context, connects related concepts across domains, and shows how a definition changes the answer to a scenario. Learn distinctions, ownership, sequence, and application rather than memorizing isolated one-line definitions. First, group terms by decisions such as ownership, risk, access, assessment, response, recovery, and development, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
the CISSP glossary: a practical decision framework
| Check | How to use it |
|---|---|
| Objective | Learn distinctions, ownership, sequence, and application rather than memorizing isolated one-line definitions. |
| First move | group terms by decisions such as ownership, risk, access, assessment, response, recovery, and development |
| Common trap | Choosing an option because it contains a familiar term even when the role, qualifier, or sequence does not fit. |
the CISSP glossary in practice
A learner knows the definitions of due care, risk acceptance, and data custodian but assigns all three decisions to the security administrator in a scenario.
The definitions lack role context. Relearn each term with actor, authority, example, counterexample, and adjacent concepts.
What matters most for the CISSP glossary
Learn distinctions, ownership, sequence, and application rather than memorizing isolated one-line definitions.
A useful CISSP glossary defines security terms in decision context, connects related concepts across domains, and shows how a definition changes the answer to a scenario. The useful question is not whether an isolated fact looks familiar, but whether you can apply it under the actor, authority, objective, qualifier, and constraints in the scenario.
How to work on the CISSP glossary
group terms by decisions such as ownership, risk, access, assessment, response, recovery, and development
For the CISSP glossary, separate official facts from CertArc guidance and market observations. Check the named primary source and access date before acting on a volatile fee, policy, format, or product claim.
- Name the actor and the authority that actor holds.
- Underline the qualifier and the required business or security outcome.
- Check sequence, scope, constraints, and residual risk before choosing.
The mistake that distorts the CISSP glossary
Choosing an option because it contains a familiar term even when the role, qualifier, or sequence does not fit.
This error can survive repeated question practice when review stops at the correct letter. Rework the item until you can state the transferable rule without quoting the stem.
How to verify guidance about the CISSP glossary
The definitions lack role context. Relearn each term with actor, authority, example, counterexample, and adjacent concepts.
Retest the CISSP glossary with a changed actor, qualifier, constraint, or domain context. Keep the result only when the same reasoning survives unfamiliar wording and you can explain what evidence would make another option stronger.
- Use an unfamiliar scenario rather than a repeated item.
- Record confidence before opening the explanation.
- Name the evidence that would reverse the decision.
Ownership and custody terms
Ownership terms distinguish who makes a business decision from who implements or operates it.
In CISSP scenarios, the title matters less than the authority described in the stem. Identify who owns the risk or information, who approves use, and who carries out the approved handling.
- Risk owner: the accountable business authority that accepts, rejects, transfers, or directs treatment of risk within delegated authority.
- Data owner: the business role that classifies information and approves access and handling requirements.
- Data custodian: the role that implements storage, protection, backup, and other approved handling controls.
Governance and access terms
Governance terms describe the standard of action and the boundaries placed on access and decisions.
Definitions become useful when you can tell which action demonstrates the term in context and which distractor merely repeats familiar vocabulary.
- Due care: taking the reasonable protective actions expected under the circumstances.
- Due diligence: the ongoing investigation, verification, and monitoring used to understand whether care remains adequate.
- Least privilege: granting only the access needed for an authorized task, for the necessary scope and duration.
Continuity and recovery terms
Recovery terms express different business tolerances and should not be treated as interchangeable timers.
Start with the business impact analysis and approved continuity objectives before selecting recovery architecture or declaring one technical target sufficient.
- BIA: business impact analysis used to identify critical activities, dependencies, consequences, and recovery priorities.
- RTO: recovery time objective, the targeted duration for restoring a service or activity after disruption.
- RPO: recovery point objective, the targeted maximum data-loss interval measured backward from disruption.
Sources and fact check
Source checked: 2026-08-24
- CertArc is an independent exam-preparation platform and is not affiliated with or endorsed by ISC2.
- CertArc uses original practice questions, not live or recalled exam items, and does not reproduce the CISSP CAT algorithm.
- Practice performance is study evidence, not a pass prediction or guarantee.
Frequently asked questions
Which CISSP terms should you know, and how should you use them?
A useful CISSP glossary defines security terms in decision context, connects related concepts across domains, and shows how a definition changes the answer to a scenario. Learn distinctions, ownership, sequence, and application rather than memorizing isolated one-line definitions. First, group terms by decisions such as ownership, risk, access, assessment, response, recovery, and development, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
Which facts about the CISSP glossary can change?
Exam policies, fees, formats, credential requirements, and product capabilities can change. Check the named primary source and access date before acting.
What is official fact versus CertArc guidance for the CISSP glossary?
Official facts come from the cited certification body. CertArc frameworks, examples, product descriptions, and study recommendations are clearly presented as independent guidance.
What is the main source mistake with the CISSP glossary?
Choosing an option because it contains a familiar term even when the role, qualifier, or sequence does not fit. Prefer current first-party evidence and keep unsupported anecdotes separate from verified facts.
How should I use this guide?
Group terms by decisions such as ownership, risk, access, assessment, response, recovery, and development Follow the linked canonical guide when your question needs more detail or a more recent fact check.