Acronyms are easier to remember when they are attached to a security decision. Use this reference when unfamiliar initials interrupt a guide, practice question, diagram, log, or conversation. Then return to the surrounding material and apply the term in context.

This list covers 45 common ISC2 Certified in Cybersecurity (CC) acronyms and terms drawn from the September 2026 exam outline and the CertHappens CC study guides. The page uses a stable CC address so later outline revisions can update the reference without creating a new URL.

Context decides the meaning. MAC is the clearest CC example: in identity and access management it can mean Mandatory Access Control, while networking material may use MAC for Media Access Control. Read the surrounding scenario before choosing an expansion.

A

AAA
Authentication, Authorization, and Accounting Separates proving an identity, deciding what that identity may do, and recording activity for accountability.
ABAC
Attribute-Based Access Control Makes access decisions from attributes about the subject, resource, action, or environment rather than a role alone.
ATT&CK
Adversarial Tactics, Techniques, and Common Knowledge MITRE knowledge base that organizes observed adversary behavior so defenders can describe and compare techniques consistently.

B

BC
Business Continuity Keeps critical business functions operating at an acceptable level during and after disruption.
BIA
Business Impact Analysis Identifies critical activities, dependencies, and disruption impacts so recovery priorities and requirements can be set.

C

CIA
Confidentiality, Integrity, and Availability Three foundational security properties: prevent unauthorized disclosure, preserve trustworthy information, and maintain timely authorized access.
CTI
Cyber Threat Intelligence Analyzed information about threats that helps defenders prioritize monitoring, prevention, investigation, and response decisions.

D

DAC
Discretionary Access Control Access-control model in which an object owner can grant or remove access, subject to the system's rules.
DAST
Dynamic Application Security Testing Examines a running application for security weaknesses by interacting with it from the outside.
DR
Disaster Recovery Restores technology, data, and supporting services after a disruption so the organization can resume required operations.

E

EOL
End of Life Point after which a product or version is no longer supported as an active lifecycle offering, increasing replacement and security-planning pressure.

G

GRC
Governance, Risk, and Compliance Connects organizational direction, risk decisions, and legal or contractual obligations so cybersecurity work supports business requirements.

I

IaaS
Infrastructure as a Service Cloud service model in which the provider supplies core infrastructure while the customer manages more of the operating-system, application, and data stack.
IAM
Identity and Access Management Processes and technologies that manage identities, authentication, authorization, provisioning, review, and deprovisioning across the identity lifecycle.
ICS
Industrial Control System Technology used to monitor or control physical or industrial processes, where cyber events can affect real-world operations.
IDS
Intrusion Detection System Monitors activity for signs of suspicious or policy-violating behavior and produces alerts for review rather than automatically blocking every event.
IoT
Internet of Things Network-connected embedded devices and sensors that can expand the attack surface because capabilities, support lifecycles, and update options vary widely.
IP
Internet Protocol Network-layer protocol family used to address and route packets between networks.
IPv4
Internet Protocol version 4 Widely deployed IP version that uses 32-bit addresses.
IPv6
Internet Protocol version 6 IP version that uses 128-bit addresses and provides a much larger address space than IPv4.
IR
Incident Response Organized process for preparing for, identifying, containing, handling, recovering from, and learning from security incidents.
IRP
Incident Response Plan Documented roles, priorities, escalation paths, communications, and procedures used to coordinate incident response.
ISO
International Organization for Standardization International standards body whose publications can provide structured guidance and requirements used in governance and security programs.

K

KPI
Key Performance Indicator Measure used to show how effectively an activity, process, or program is performing against an intended result.
KRI
Key Risk Indicator Measure that signals changing risk exposure or conditions that may require attention before loss occurs.

M

MAC
Mandatory Access Control Access-control model in which centrally enforced labels or classifications determine access. In networking, MAC can also mean Media Access Control, so context matters.
MFA
Multi-Factor Authentication Authentication that requires evidence from more than one factor category, reducing reliance on a single credential.

N

NIST
National Institute of Standards and Technology U.S. standards and guidance organization whose cybersecurity publications are commonly used for risk, resilience, zero trust, and incident-response references.

O

OSI
Open Systems Interconnection Seven-layer conceptual networking model used to organize how network functions relate to one another.

P

PaaS
Platform as a Service Cloud service model in which the provider manages more of the platform and runtime so the customer can focus on applications and data.
PoLP
Principle of Least Privilege Limits users, services, and automated identities to the minimum access needed for their authorized tasks.

R

RBAC
Role-Based Access Control Access-control model that assigns permissions to defined roles and then assigns users or identities to those roles.
RPO
Recovery Point Objective Target that describes how much data loss, measured backward in time, an organization can tolerate after disruption.
RTO
Recovery Time Objective Target time for restoring a process, system, or service after disruption.

S

SaaS
Software as a Service Cloud service model in which a provider delivers a complete hosted application while the customer manages its use, identities, configurations, and data responsibilities.
SAST
Static Application Security Testing Analyzes source code, bytecode, or binaries for security weaknesses without exercising the running application.
SIEM
Security Information and Event Management Centralizes and correlates logs and security events so analysts can detect patterns, investigate alerts, and support incident response.
SoD
Separation of Duties Divides incompatible responsibilities among multiple people or roles so one actor cannot complete a sensitive process alone.

T

TCP
Transmission Control Protocol Connection-oriented transport protocol that provides ordered, reliable delivery between applications.
TCP/IP
Transmission Control Protocol/Internet Protocol Protocol suite and networking model that describes how Internet-connected systems communicate across layered functions.
TTP
Tactics, Techniques, and Procedures Term for patterns of adversary goals, methods, and operational behavior used to describe how threats act.

V

VLAN
Virtual Local Area Network Logical Layer 2 segmentation that separates broadcast domains without requiring a separate physical switch for each network.
VPN
Virtual Private Network Creates a protected logical connection across an untrusted or shared network so traffic can travel through a controlled tunnel.

Z

ZT
Zero Trust Security approach that avoids implicit trust based only on network location and instead continually evaluates identity, device, resource, and context.
ZTA
Zero Trust Architecture Architecture that applies zero-trust principles through explicit verification, limited access, segmentation, and continuous evaluation.

Scope follows the ISC2 CC exam outline effective September 1, 2026. Use the official outline as the final authority for exam scope.

ISC2 CC September 2026 Study Guide Follow the five-domain roadmap and continue into the detailed September 2026 domain guides. ISC2 CC September 2026 Practice Test Apply the terminology in randomized practice questions and review detailed explanations. Common Ports and Protocols Reference Review common services, transports, secure alternatives, and protocols without port numbers. ISC2 CC Resource Hub Return to the CC overview, study guide, practice test, and supporting references.