Reference
Look it up in seconds
The acronyms, ports, and terminology you'll be expected to know — all searchable in one place.
- AAAAuthentication, Authorization, and Accounting
- ACLAccess Control List
- AESAdvanced Encryption Standard — Symmetric block cipher (128/192/256-bit keys)
- AES-256Advanced Encryption Standard 256-bit — AES using a 256-bit key
- AHAuthentication Header — IPSec component providing integrity/authentication
- AIArtificial Intelligence
- AISAutomated Indicator Sharing — CISA program for sharing cyber threat indicators
- ALEAnnualized Loss Expectancy — ALE = SLE x ARO
- APAccess Point
- APIApplication Programming Interface
- APTAdvanced Persistent Threat
- AROAnnualized Rate of Occurrence
- ARPAddress Resolution Protocol — Maps IP addresses to MAC addresses
- ASLRAddress Space Layout Randomization
- AUPAcceptable Use Policy
- BASHBourne Again Shell — Common Unix/Linux command shell and scripting language
- BCPBusiness Continuity Planning
- BGPBorder Gateway Protocol — Internet routing protocol between autonomous systems
- BIABusiness Impact Analysis
- BIOSBasic Input/Output System — Legacy firmware; largely superseded by UEFI
- BPABusiness Partners Agreement
- BPDUBridge Protocol Data Unit — STP messages; BPDU Guard protects switch ports
- BYODBring Your Own Device
- CACertificate Authority
- CAPTCHACompletely Automated Public Turing Test to Tell Computers and Humans Apart
- CARCorrective Action Report
- CASBCloud Access Security Broker
- CBCCipher Block Chaining — Block cipher mode of operation
- CCMPCounter Mode Cipher Block Chaining Message Authentication Code Protocol — Encryption protocol used by WPA2
- CCTVClosed-Circuit Television — Physical security surveillance
- CERTComputer Emergency Response Team
- CFBCipher Feedback — Block cipher mode of operation
- CHAPChallenge Handshake Authentication Protocol
- CIAConfidentiality, Integrity, and Availability — The core security triad
- CIOChief Information Officer
- CIRTComputer Incident Response Team
- CMSContent Management System
- COOPContinuity of Operations Planning
- COPECorporate-Owned, Personally Enabled — Mobile deployment model
- CRCCyclic Redundancy Check — Error-detection checksum (not cryptographically secure)
- CRLCertificate Revocation List
- CSOChief Security Officer
- CSPCloud Service Provider
- CSRCertificate Signing Request
- CSRFCross-Site Request Forgery
- CSUChannel Service Unit — Often paired with DSU (CSU/DSU) for WAN connections
- CTMCounter Mode — Block cipher mode of operation (CTR)
- CTOChief Technology Officer
- CVECommon Vulnerabilities and Exposures
- CVSSCommon Vulnerability Scoring System
- DACDiscretionary Access Control
- DBADatabase Administrator
- DDoSDistributed Denial of Service
- DEPData Execution Prevention
- DESData Encryption Standard — Symmetric block cipher; insecure 56-bit key. CompTIA's appendix prints 'Digital Encryption Standard', but DES = Data Encryption Standard.
- DHCPDynamic Host Configuration Protocol
- DKIMDomainKeys Identified Mail
- DLLDynamic Link Library — Windows shared library; target of DLL injection
- DLPData Loss Prevention
- DMARCDomain-based Message Authentication, Reporting, and Conformance
- DNATDestination Network Address Translation
- DNSDomain Name System
- DNSSECDomain Name System Security Extensions
- DoSDenial of Service
- DPOData Protection Officer — Role required under GDPR (CompTIA lists it as Data Privacy Officer)
- DRPDisaster Recovery Plan
- EAPExtensible Authentication Protocol
- ECBElectronic Codebook — Block cipher mode; insecure for repeating data
- ECCElliptic Curve Cryptography
- ECDHEElliptic Curve Diffie-Hellman Ephemeral — Key exchange providing perfect forward secrecy
- ECDSAElliptic Curve Digital Signature Algorithm
- EDREndpoint Detection and Response
- EFSEncrypting File System — Windows file-level encryption
- ERPEnterprise Resource Planning
- ESPEncapsulating Security Payload — IPSec component providing confidentiality
- FACLFile System Access Control List
- FDEFull Disk Encryption
- FIMFile Integrity Monitoring
- FPGAField Programmable Gate Array — Reconfigurable hardware chip
- FRRFalse Rejection Rate — Biometric Type I error
- FTPFile Transfer Protocol
- FTPSFile Transfer Protocol Secure — FTP over SSL/TLS
- GCMGalois/Counter Mode — Authenticated block cipher mode
- GDPRGeneral Data Protection Regulation
- GPGGNU Privacy Guard — Open-source OpenPGP implementation (CompTIA lists this as GPG, not GnuPG)
- GPOGroup Policy Object
- GPSGlobal Positioning System
- GPUGraphics Processing Unit — Often used for password cracking/hashing
- GREGeneric Routing Encapsulation — Tunneling protocol
- HAHigh Availability
- HIDSHost-based Intrusion Detection System
- HIPSHost-based Intrusion Prevention System
- HMACHash-based Message Authentication Code
- HOTPHMAC-based One-Time Password — Counter-based OTP
- HSMHardware Security Module
- HTTPHypertext Transfer Protocol
- HTTPSHypertext Transfer Protocol Secure
- HVACHeating, Ventilation, and Air Conditioning — Environmental control; a physical/OT security concern
- IaaSInfrastructure as a Service
- IaCInfrastructure as Code
- IAMIdentity and Access Management
- ICSIndustrial Control System
- IDFIntermediate Distribution Frame — Wiring closet connecting to the MDF
- IdPIdentity Provider — Issues assertions in federated SSO (SAML/OAuth)
- IDSIntrusion Detection System
- IKEInternet Key Exchange — Negotiates IPSec security associations
- IMInstant Messaging
- IMAPInternet Message Access Protocol
- IoCIndicators of Compromise — Artifacts suggesting a breach
- IoTInternet of Things
- IPSIntrusion Prevention System
- IPSecInternet Protocol Security
- IRIncident Response
- IRPIncident Response Plan
- ISOInternational Organization for Standardization
- ISPInternet Service Provider
- ISSOInformation Systems Security Officer
- IVInitialization Vector
- KDCKey Distribution Center — Kerberos component that issues tickets
- L2TPLayer 2 Tunneling Protocol
- LDAPLightweight Directory Access Protocol
- LDAPSLightweight Directory Access Protocol over SSL
- MaaSMonitoring as a Service
- MACMandatory Access Control — Access control model based on classifications/labels
- MACMedia Access Control — Hardware address of a network interface
- MACMessage Authentication Code — Cryptographic integrity/authenticity check
- MDFMain Distribution Frame — Primary wiring/cabling distribution point (NOT a multifunction device - that is MFD/MFP)
- MDMMobile Device Management
- MFAMultifactor Authentication
- MFDMultifunction Device — Combined printer/scanner/fax/copier
- MFPMultifunction Printer
- MLMachine Learning
- MMSMultimedia Messaging Service
- MOAMemorandum of Agreement
- MOUMemorandum of Understanding
- MPLSMultiprotocol Label Switching — WAN technology using labels to forward traffic
- MSAMaster Service Agreement
- MSCHAPMicrosoft Challenge Handshake Authentication Protocol
- MSPManaged Service Provider
- MSSPManaged Security Service Provider
- MTBFMean Time Between Failures
- MTTFMean Time to Failure — Expected lifetime of a non-repairable asset
- MTTRMean Time to Repair
- MTUMaximum Transmission Unit — Largest packet size on a network link
- NACNetwork Access Control
- NATNetwork Address Translation
- NDANon-Disclosure Agreement
- NFCNear Field Communication — Short-range wireless used for contactless payments
- NGFWNext-Generation Firewall
- NIDSNetwork-based Intrusion Detection System
- NIPSNetwork-based Intrusion Prevention System
- NISTNational Institute of Standards and Technology
- NTPNetwork Time Protocol
- OAuthOpen Authorization
- OCSPOnline Certificate Status Protocol
- OIDObject Identifier — Unique identifier used in certificates and SNMP MIBs
- OSOperating System
- OSINTOpen-Source Intelligence
- OSPFOpen Shortest Path First — Link-state interior routing protocol
- OTOperational Technology — Hardware/software controlling physical processes (ICS/SCADA)
- OTAOver-the-Air — Wireless updates/provisioning, e.g., for mobile devices
- OWASPOpen Worldwide Application Security Project
- P12PKCS #12 — Binary format (.p12/.pfx) bundling a private key with its certificate
- PaaSPlatform as a Service
- PACProxy Auto-Configuration — Also Protected Access Credential in EAP-FAST
- PAMPrivileged Access Management
- PAPPassword Authentication Protocol
- PATPort Address Translation — NAT overload mapping many hosts to one IP via ports
- PBKDF2Password-Based Key Derivation Function 2
- PCAPPacket Capture — Captured network traffic file format
- PCI DSSPayment Card Industry Data Security Standard
- PDUPower Distribution Unit — Also Protocol Data Unit in networking
- PEAPProtected Extensible Authentication Protocol — EAP wrapped in a TLS tunnel
- PEDPersonal Electronic Device
- PEMPrivacy Enhanced Mail — Base64 ASCII certificate/key format (.pem)
- PFSPerfect Forward Secrecy — Session keys not compromised if long-term key is exposed
- PGPPretty Good Privacy — Email/file encryption using a web of trust
- PHIProtected Health Information — Regulated under HIPAA (CompTIA lists it as Personal Health Information)
- PIIPersonally Identifiable Information
- PKIPublic Key Infrastructure
- POPPost Office Protocol
- POTSPlain Old Telephone Service — Traditional analog phone lines
- PPPPoint-to-Point Protocol — Layer 2 protocol for direct connections
- PPTPPoint-to-Point Tunneling Protocol
- PUPPotentially Unwanted Program
- RARecovery Agent — Can decrypt/recover encrypted data or keys (also Registration Authority in PKI)
- RADIUSRemote Authentication Dial-In User Service — Auth ports UDP 1812/1813
- RAIDRedundant Array of Independent Disks — Disk redundancy/performance (levels 0, 1, 5, 6, 10)
- RASRemote Access Server
- RATRemote Access Trojan — Malware giving an attacker remote control
- RBACRole-Based Access Control
- RDPRemote Desktop Protocol — TCP 3389
- RFIDRadio Frequency Identification — Used in badges, asset tags; susceptible to cloning/skimming
- RPORecovery Point Objective — Maximum acceptable data loss (time)
- RSARivest, Shamir, Adleman — Widely used asymmetric encryption/signature algorithm
- RTBHRemotely Triggered Black Hole — DDoS mitigation that drops traffic to a target
- RTORecovery Time Objective — Target time to restore after an outage
- RTOSReal-Time Operating System — Used in embedded/ICS systems
- RTPReal-time Transport Protocol — Carries voice/video; secured by SRTP
- S/MIMESecure/Multipurpose Internet Mail Extensions
- SaaSSoftware as a Service
- SAESimultaneous Authentication of Equals — WPA3 handshake replacing the WPA2 PSK 4-way handshake
- SAMLSecurity Assertion Markup Language
- SANSubject Alternative Name — Certificate field listing additional names/domains (also Storage Area Network)
- SASESecure Access Service Edge
- SCADASupervisory Control and Data Acquisition
- SCAPSecurity Content Automation Protocol
- SCEPSimple Certificate Enrollment Protocol — Automated certificate issuance, common for devices/MDM
- SD-WANSoftware-Defined Wide Area Network
- SDKSoftware Development Kit
- SDLCSoftware Development Life Cycle
- SDLMSoftware Development Lifecycle Methodology
- SDNSoftware-Defined Networking — Separates control plane from data plane
- SEDSelf-Encrypting Drive — Hardware-based full-disk encryption
- SEHStructured Exception Handler — Windows error handling; target of SEH overwrite exploits
- SELinuxSecurity-Enhanced Linux
- SFTPSSH File Transfer Protocol — File transfer over SSH (TCP 22)
- SHASecure Hash Algorithm
- SHTTPSecure Hypertext Transfer Protocol — Legacy/obsolete; distinct from HTTPS
- SIEMSecurity Information and Event Management
- SIMSubscriber Identity Module — Target of SIM-swapping/cloning attacks
- SLAService-Level Agreement
- SLESingle Loss Expectancy — SLE = asset value x exposure factor
- SMSShort Message Service — Text messaging; weak as an MFA channel
- SMTPSimple Mail Transfer Protocol
- SMTPSSimple Mail Transfer Protocol Secure — SMTP over TLS
- SNMPSimple Network Management Protocol
- SOAPSimple Object Access Protocol — XML-based web services messaging protocol
- SOARSecurity Orchestration, Automation, and Response
- SOCSecurity Operations Center
- SOWStatement of Work
- SPFSender Policy Framework
- SPIMSpam over Instant Messaging — CompTIA lists this as Spam over Internet Messaging
- SQLStructured Query Language
- SQLiSQL Injection — Injection attack against database queries
- SRTPSecure Real-time Transport Protocol — Encrypted RTP for VoIP/video
- SSDSolid State Drive
- SSHSecure Shell — TCP 22
- SSLSecure Sockets Layer — Deprecated; superseded by TLS
- SSOSingle Sign-On
- STIXStructured Threat Information eXpression — Standard format for cyber threat intelligence; pairs with TAXII (CompTIA lists it as eXchange)
- SWGSecure Web Gateway
- TACACS+Terminal Access Controller Access Control System Plus — Auth port TCP 49
- TAXIITrusted Automated eXchange of Indicator Information — Transport protocol for sharing STIX threat intel
- TCPTransmission Control Protocol
- TGTTicket-Granting Ticket — Issued by the Kerberos KDC
- TKIPTemporal Key Integrity Protocol — Legacy WPA encryption; deprecated in favor of CCMP/AES
- TLSTransport Layer Security
- TOCTime-of-Check — TOC/TOU describes a race-condition vulnerability
- TOTPTime-based One-Time Password
- TOUTime-of-Use — The use half of a TOC/TOU race condition
- TPMTrusted Platform Module
- TSIGTransaction Signature — Authenticates DNS updates/zone transfers
- TTPTactics, Techniques, and Procedures — Behavioral description of threat actors (e.g., MITRE ATT&CK)
- UATUser Acceptance Testing
- UAVUnmanned Aerial Vehicle — Drone
- UDPUser Datagram Protocol
- UEBAUser and Entity Behavior Analytics
- UEFIUnified Extensible Firmware Interface
- UEMUnified Endpoint Management — Manages mobile and traditional endpoints centrally
- UPSUninterruptible Power Supply
- URIUniform Resource Identifier
- URLUniform Resource Locator
- USBUniversal Serial Bus
- USB OTGUSB On-the-Go — Lets a mobile device act as a USB host
- UTMUnified Threat Management
- UTPUnshielded Twisted Pair — Common copper network cabling
- VBAVisual Basic for Applications — Office macro language; common malware delivery vector
- VDEVirtual Desktop Environment
- VDIVirtual Desktop Infrastructure — Hosts user desktops on centralized servers
- VLANVirtual Local Area Network
- VLSMVariable Length Subnet Mask
- VMVirtual Machine
- VoIPVoice over Internet Protocol
- VPCVirtual Private Cloud — Isolated cloud network segment
- VPNVirtual Private Network
- VTCVideo Teleconferencing
- WAFWeb Application Firewall
- WAPWireless Access Point
- WEPWired Equivalent Privacy — Obsolete, insecure Wi-Fi encryption
- WIDSWireless Intrusion Detection System
- WIPSWireless Intrusion Prevention System
- WOWork Order
- WPAWi-Fi Protected Access
- WPSWi-Fi Protected Setup
- WTLSWireless Transport Layer Security — TLS variant for the WAP wireless stack
- XDRExtended Detection and Response
- XMLExtensible Markup Language
- XORExclusive OR — Bitwise operation fundamental to many ciphers
- XSRFCross-Site Request Forgery — Alternate abbreviation for CSRF
- XSSCross-Site Scripting