The Certified Information Systems Security Professional (CISSP) exam covers security across an organization rather than inside one product, team, or technical specialty. A candidate may need to recognize a protocol or control, but the stronger answer often depends on who owns the decision, which requirement applies, how risk is evaluated, and what should happen before implementation.

The current ISC2 exam outline took effect April 15, 2024. It contains eight domains and gives the greatest average weight to Security and Risk Management. The breadth means most experienced candidates begin with both strengths and blind spots. A security operations specialist may need more software-development depth. An auditor may need more architecture and cryptography. A network engineer may need more governance, privacy, and personnel-security context.

Use the official outline as the coverage checklist. Use this guide to organize the work, connect nearby concepts, and keep technical facts attached to the decisions they support.

Use the CISSP Quick Review Guides when two models, governance terms, assessment methods, or recovery choices are easy to blur together.

CISSP exam snapshot

The official ISC2 outline describes the English CISSP exam as computerized adaptive testing (CAT):

Exam time
3 hours
Number of items
100 to 150
Item format
Multiple choice and advanced item types
Passing grade
700 out of 1000 points

Computerized adaptive testing adjusts item selection based on the candidate's responses while maintaining the domain weighting required by the exam outline. A candidate cannot return to an earlier item after submitting an answer. That makes careful reading important, but repeatedly second-guessing every question can waste time and attention.

Confirm current exam rules with ISC2. Delivery details, policies, and certification requirements can change. Check the official outline and registration guidance before scheduling the exam.

How to use this guide

A productive CISSP study cycle has four parts:

  1. Map the outline to your experience. Mark each objective as familiar, partly familiar, or unfamiliar. Distinguish direct work experience from topics you have only read about.
  2. Build the decision context. Learn the business purpose, accountable role, lifecycle stage, and risk consideration around each control or process.
  3. Practice distinctions. Compare terms that appear reasonable together, such as due care and due diligence, data owner and custodian, business continuity and disaster recovery, or risk appetite and risk tolerance.
  4. Review the strongest distractor. When you miss a question, identify why the wrong choice looked plausible and which clue made another answer better.

Do not study each domain as an isolated container. Security and Risk Management influences architecture, access control, operations, testing, and software development. Asset classification affects encryption, identity, retention, monitoring, and disposal. Business continuity depends on architecture, suppliers, operations, and tested recovery procedures.

Choose the resource that matches the weakness

Need Best starting point Use it for
Complete exam organization Eight-domain roadmap Identifying the domain and study priority behind a broad weakness.
Governance and risk foundation Domain 1 guide Ethics, legal duties, policy, continuity, personnel security, risk, supply chains, and awareness.
Classification and data lifecycle Domain 2 guide Classification, ownership, handling, data roles, retention, sanitization, and protection controls.
Network architecture and protected communications Domain 4 guide Models, secure protocols, segmentation, network components, monitoring, remote access, and third-party connectivity.
Identity, authentication, and access decisions Domain 5 guide Identity proofing, authentication, federation, authorization models, provisioning, privileged access, and service accounts.
Assessment evidence and control testing Domain 6 guide Assessment strategy, vulnerability and penetration testing, process data, metrics, reporting, remediation, exceptions, and audits.
Security operations, incident response, and recovery Domain 7 guide Investigations, logging, monitoring, configuration, incidents, detection, patching, recovery, continuity, physical security, and personnel safety.
Security controls and operations refresher Security+ study guide Rebuilding technical vocabulary before applying the broader CISSP perspective.
Network foundation Network+ study guide Refreshing architecture, segmentation, services, protocols, and operational evidence.
Official scope ISC2 exam outline Checking every task and subtask that may appear on the exam.

The CISSP decision lens

CISSP questions commonly present several actions that could help. The task is to choose the action that best fits the stated role, authority, sequence, and risk context.

Use these questions to evaluate the choices:

  1. What outcome is the organization protecting? Consider people, mission, legal duties, services, data, reputation, and financial stability.
  2. Who has authority? A security professional may recommend and implement controls, while a business owner or senior leader accepts business risk.
  3. What requirement governs the decision? Look for policy, law, regulation, contract, standard, risk appetite, or architecture requirements.
  4. What should happen first? Requirements, classification, assessment, ownership, and approval often precede technical implementation.
  5. What is the least disruptive action that meets the requirement? A stronger control is not automatically the better control when it prevents the business process from functioning.
  6. How will the organization know the control works? Favor measurable requirements, documented evidence, testing, monitoring, and review.
  7. What happens across the lifecycle? Consider acquisition, deployment, operation, change, incident response, recovery, retention, and disposal.

Common perspective shifts

Scenario clueUseful perspective
A control is technically effective but expensive or disruptive.Compare the risk reduction with business impact, obligations, alternatives, and risk appetite.
A serious finding needs a decision.Provide the risk owner with clear impact, likelihood, options, and residual risk.
A new system is being designed.Define requirements and trust boundaries early instead of adding controls after deployment.
A supplier provides a critical service.Address due diligence, contract requirements, monitoring, concentration risk, recovery, and exit planning.
An incident creates legal or regulatory exposure.Preserve evidence, follow approved procedures, involve appropriate stakeholders, and respect reporting duties.
A policy exists but behavior has not changed.Check communication, acknowledgement, role-based learning, enforcement, measurement, and leadership support.

The eight CISSP domains

The domain weights are averages. Computerized adaptive testing still constructs each exam in accordance with the official weighting, but a candidate should not expect questions to arrive in domain order.

Domain Weight Study priority
1. Security and Risk Management 16% Build the governance, ethics, legal, continuity, personnel, risk, supplier, and awareness foundation used across the exam.
2. Asset Security 10% Connect classification and ownership to handling, privacy, retention, protection, and destruction decisions.
3. Security Architecture and Engineering 13% Understand secure design principles, models, cryptography, system types, physical design, and lifecycle engineering.
4. Communication and Network Security 13% Apply secure architecture, segmentation, protocols, transmission, remote access, and network operations concepts.
5. Identity and Access Management 13% Manage identities, authentication, authorization, federation, access models, provisioning, review, and deprovisioning.
6. Security Assessment and Testing 12% Choose assessment strategies, collect evidence, test controls, interpret results, report findings, and support audits.
7. Security Operations 13% Connect investigations, monitoring, incidents, vulnerability management, change, resilience, recovery, and personnel safety.
8. Software Development Security 10% Integrate security into development, acquisition, testing, coding, deployment, maintenance, and software supply chains.

Domain 1: Security and Risk Management

Domain 1 establishes how security decisions are governed and justified. It covers professional ethics, security principles, organizational governance, legal and regulatory obligations, investigations, policy, business continuity, personnel security, risk management, threat modeling, supply-chain risk, and security learning programs.

Start with the detailed Security and Risk Management guide. The vocabulary in this domain appears throughout the other seven domains, especially ownership, due care, due diligence, risk response, policy hierarchy, resilience, and control assessment.

Domain 2: Asset Security

Asset Security follows information and other assets through classification, ownership, handling, storage, retention, protection, and destruction. Study the roles of owner, controller, custodian, processor, user, and data subject. Connect each role to authority and responsibility rather than memorizing titles without context.

A classification label matters because it drives handling requirements. Those requirements influence access control, encryption, monitoring, backup, retention, transmission, and disposal. Use the detailed Asset Security guide to connect the six official objectives to practical lifecycle decisions.

Domain 3: Security Architecture and Engineering

This domain combines abstract security models with practical engineering decisions. Topics include secure design principles, system security capabilities, architecture weaknesses, cryptography, physical security, and the information-system lifecycle.

Learn what a model or principle protects, which assumption it makes, and where it fits. A name alone is rarely enough. For cryptography, connect algorithm selection to confidentiality, integrity, authentication, nonrepudiation, key management, performance, and lifecycle risk. Use the detailed Security Architecture and Engineering guide to connect all ten official objectives.

Domain 4: Communication and Network Security

Communication and Network Security covers secure network design, traffic flow, segmentation, protocols, transmission media, wireless and mobile networking, remote access, network components, and third-party connectivity.

Technical recognition remains important, but CISSP adds architecture and governance questions. A secure connection must fit the trust boundary, performance need, availability requirement, management model, and monitoring strategy. Use the detailed Communication and Network Security guide to connect all three official objectives.

Domain 5: Identity and Access Management

Identity and Access Management (IAM) covers people, devices, services, credentials, sessions, federation, access-control models, provisioning, review, and removal. Follow the identity lifecycle from registration and proofing through authorization, monitoring, changes, and deprovisioning.

Separate identification, authentication, authorization, and accounting. Then connect each step to governance principles such as least privilege, need to know, separation of duties, and periodic review. Use the detailed Identity and Access Management guide to connect all six official objectives.

Domain 6: Security Assessment and Testing

This domain asks how an organization selects, performs, and evaluates assessments. Study testing strategies, vulnerability assessments, penetration testing, code review, control testing, process data, audits, analysis, remediation, exceptions, and reporting.

The method should match the purpose and authority. An audit, vulnerability assessment, penetration test, and red-team exercise can all reveal weaknesses, but they differ in scope, independence, depth, rules of engagement, and expected output.

Use the detailed Security Assessment and Testing guide to connect the five official objectives to planning, evidence, control testing, reporting, remediation, exceptions, and audits.

Domain 7: Security Operations

Security Operations covers investigations, evidence, logging, monitoring, configuration, privileged access, incident management, protective technologies, vulnerability management, change, backup, recovery, disaster recovery, business continuity, physical security, and personnel safety.

Sequence matters. Preserve life and safety, follow approved response procedures, protect evidence, contain harm, communicate appropriately, recover services, and use lessons learned to improve controls.

Use the detailed Security Operations guide to connect investigations, monitoring, configuration, incident management, patching, recovery, continuity, physical safeguards, personnel safety, and AI-assisted operations.

Domain 8: Software Development Security

Software Development Security integrates security into development and acquisition. Topics include development methodologies, maturity models, coding practices, application testing, dependencies, repositories, continuous integration and delivery, acquired software, managed services, and cloud services.

The most effective security work begins with requirements and design. Testing near release remains necessary, but it cannot replace secure architecture, trusted dependencies, controlled change, and lifecycle ownership.

Use the detailed Software Development Security guide to connect the secure software lifecycle, development methods, repositories, pipelines, application testing, acquired software, supply-chain controls, coding standards, APIs, software-defined security, and AI-assisted development.

A practical CISSP study plan

Use a plan that reflects your own background rather than giving every topic identical time.

Phase 1: Build the map

  • Read the complete official outline.
  • Mark each objective by confidence and direct experience.
  • Identify the two domains with the least practical exposure.
  • Note concepts that appear in several domains, such as risk, ownership, lifecycle, least privilege, testing, and resilience.

Phase 2: Strengthen weak domains

For each weak objective, create a short explanation that answers:

  • What problem does this concept solve?
  • Who owns or approves the decision?
  • Which requirement or risk drives it?
  • What evidence shows it is working?
  • What lifecycle event could change the answer?

Use small scenarios. A paragraph that explains a supplier outage, a privacy requirement, or an access review is more useful than a page of disconnected definitions.

Phase 3: Mix the domains

CISSP scenarios often cross boundaries. Practice following one situation through several domains:

  • A cloud service begins with governance and supplier risk.
  • Its data requires classification, ownership, and retention.
  • Its architecture needs trust boundaries, encryption, and resilience.
  • Its users and services require identity controls.
  • Its controls need assessment and monitoring.
  • Its incidents and changes require operational processes.
  • Its integrations and code require software-development security.

Phase 4: Practice decision quality

For every question, state the role and goal before reviewing the answers. After answering, explain why the strongest alternative is weaker. Common reasons include:

  • It occurs too early or too late in the process.
  • It exceeds the person's authority.
  • It solves the technical symptom without addressing the governing requirement.
  • It ignores evidence, documentation, legal duties, or business impact.
  • It treats risk acceptance as a security-team decision rather than a risk-owner decision.
  • It selects a control before requirements and classification are understood.

Review habits that improve retention

Use several forms of recall instead of rereading the same chapter:

  • Draw a responsibility map for owners, custodians, users, assessors, risk owners, and leadership.
  • Compare two similar terms without looking at notes.
  • Explain a control to a technical employee, a business owner, and an executive using different levels of detail.
  • Build a lifecycle from acquisition through disposal and place the appropriate security decisions at each stage.
  • Review missed questions by clue, not only by topic.
  • Revisit weak concepts after several days, then again after several weeks.

A high score in one familiar domain should not hide a serious gap elsewhere. The adaptive exam still draws from all eight domains, and the certification represents broad professional judgment.

Official references

The official outline defines exam scope. The additional references provide durable context for governance, risk, ethics, and lifecycle decisions. CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.

CISSP Certification Overview Review the exam format, experience path, maintenance requirements, and candidate perspective. CISSP Quick Review Guides Compare governance and risk, security models, assessment methods, incident decisions, and recovery choices. Domain 1: Security and Risk Management Build the ethics, governance, legal, continuity, personnel, risk, supply-chain, and awareness foundation. Domain 2: Asset Security Follow information and other assets through classification, handling, ownership, retention, protection, and destruction. Domain 3: Security Architecture and Engineering Connect secure design principles, models, system capabilities, cryptography, facilities, and lifecycle engineering. Domain 4: Communication and Network Security Connect network models, segmentation, secure protocols, infrastructure, monitoring, and protected communication channels. Domain 5: Identity and Access Management Follow identity proofing, authentication, authorization, federation, provisioning, privileged access, and account removal. Domain 6: Security Assessment and Testing Plan assessments, test controls, evaluate evidence, report findings, and follow remediation, exceptions, and audits. Domain 7: Security Operations Operate investigations, monitoring, incident response, configuration, patching, recovery, continuity, physical safeguards, and personnel safety. Domain 8: Software Development Security Build security into software planning, development, testing, acquisition, delivery, operation, change, and retirement. Security+ SY0-701 Study Guide Refresh security controls, architecture, operations, threats, and governance concepts at the foundational level. Network+ N10-009 Study Guide Review network architecture, services, security, and operations used across several CISSP domains.