The Certified Information Systems Security Professional (CISSP) exam covers security across an organization rather than inside one product, team, or technical specialty. A candidate may need to recognize a protocol or control, but the stronger answer often depends on who owns the decision, which requirement applies, how risk is evaluated, and what should happen before implementation.
The current ISC2 exam outline took effect April 15, 2024. It contains eight domains and gives the greatest average weight to Security and Risk Management. The breadth means most experienced candidates begin with both strengths and blind spots. A security operations specialist may need more software-development depth. An auditor may need more architecture and cryptography. A network engineer may need more governance, privacy, and personnel-security context.
Use the official outline as the coverage checklist. Use this guide to organize the work, connect nearby concepts, and keep technical facts attached to the decisions they support.
Use the CISSP Quick Review Guides when two models, governance terms, assessment methods, or recovery choices are easy to blur together.
CISSP exam snapshot
The official ISC2 outline describes the English CISSP exam as computerized adaptive testing (CAT):
- Exam time
- 3 hours
- Number of items
- 100 to 150
- Item format
- Multiple choice and advanced item types
- Passing grade
- 700 out of 1000 points
Computerized adaptive testing adjusts item selection based on the candidate's responses while maintaining the domain weighting required by the exam outline. A candidate cannot return to an earlier item after submitting an answer. That makes careful reading important, but repeatedly second-guessing every question can waste time and attention.
Confirm current exam rules with ISC2. Delivery details, policies, and certification requirements can change. Check the official outline and registration guidance before scheduling the exam.
How to use this guide
A productive CISSP study cycle has four parts:
- Map the outline to your experience. Mark each objective as familiar, partly familiar, or unfamiliar. Distinguish direct work experience from topics you have only read about.
- Build the decision context. Learn the business purpose, accountable role, lifecycle stage, and risk consideration around each control or process.
- Practice distinctions. Compare terms that appear reasonable together, such as due care and due diligence, data owner and custodian, business continuity and disaster recovery, or risk appetite and risk tolerance.
- Review the strongest distractor. When you miss a question, identify why the wrong choice looked plausible and which clue made another answer better.
Do not study each domain as an isolated container. Security and Risk Management influences architecture, access control, operations, testing, and software development. Asset classification affects encryption, identity, retention, monitoring, and disposal. Business continuity depends on architecture, suppliers, operations, and tested recovery procedures.
Choose the resource that matches the weakness
| Need | Best starting point | Use it for |
|---|---|---|
| Complete exam organization | Eight-domain roadmap | Identifying the domain and study priority behind a broad weakness. |
| Governance and risk foundation | Domain 1 guide | Ethics, legal duties, policy, continuity, personnel security, risk, supply chains, and awareness. |
| Classification and data lifecycle | Domain 2 guide | Classification, ownership, handling, data roles, retention, sanitization, and protection controls. |
| Network architecture and protected communications | Domain 4 guide | Models, secure protocols, segmentation, network components, monitoring, remote access, and third-party connectivity. |
| Identity, authentication, and access decisions | Domain 5 guide | Identity proofing, authentication, federation, authorization models, provisioning, privileged access, and service accounts. |
| Assessment evidence and control testing | Domain 6 guide | Assessment strategy, vulnerability and penetration testing, process data, metrics, reporting, remediation, exceptions, and audits. |
| Security operations, incident response, and recovery | Domain 7 guide | Investigations, logging, monitoring, configuration, incidents, detection, patching, recovery, continuity, physical security, and personnel safety. |
| Security controls and operations refresher | Security+ study guide | Rebuilding technical vocabulary before applying the broader CISSP perspective. |
| Network foundation | Network+ study guide | Refreshing architecture, segmentation, services, protocols, and operational evidence. |
| Official scope | ISC2 exam outline | Checking every task and subtask that may appear on the exam. |
The CISSP decision lens
CISSP questions commonly present several actions that could help. The task is to choose the action that best fits the stated role, authority, sequence, and risk context.
Use these questions to evaluate the choices:
- What outcome is the organization protecting? Consider people, mission, legal duties, services, data, reputation, and financial stability.
- Who has authority? A security professional may recommend and implement controls, while a business owner or senior leader accepts business risk.
- What requirement governs the decision? Look for policy, law, regulation, contract, standard, risk appetite, or architecture requirements.
- What should happen first? Requirements, classification, assessment, ownership, and approval often precede technical implementation.
- What is the least disruptive action that meets the requirement? A stronger control is not automatically the better control when it prevents the business process from functioning.
- How will the organization know the control works? Favor measurable requirements, documented evidence, testing, monitoring, and review.
- What happens across the lifecycle? Consider acquisition, deployment, operation, change, incident response, recovery, retention, and disposal.
Common perspective shifts
| Scenario clue | Useful perspective |
|---|---|
| A control is technically effective but expensive or disruptive. | Compare the risk reduction with business impact, obligations, alternatives, and risk appetite. |
| A serious finding needs a decision. | Provide the risk owner with clear impact, likelihood, options, and residual risk. |
| A new system is being designed. | Define requirements and trust boundaries early instead of adding controls after deployment. |
| A supplier provides a critical service. | Address due diligence, contract requirements, monitoring, concentration risk, recovery, and exit planning. |
| An incident creates legal or regulatory exposure. | Preserve evidence, follow approved procedures, involve appropriate stakeholders, and respect reporting duties. |
| A policy exists but behavior has not changed. | Check communication, acknowledgement, role-based learning, enforcement, measurement, and leadership support. |
The eight CISSP domains
The domain weights are averages. Computerized adaptive testing still constructs each exam in accordance with the official weighting, but a candidate should not expect questions to arrive in domain order.
| Domain | Weight | Study priority |
|---|---|---|
| 1. Security and Risk Management | 16% | Build the governance, ethics, legal, continuity, personnel, risk, supplier, and awareness foundation used across the exam. |
| 2. Asset Security | 10% | Connect classification and ownership to handling, privacy, retention, protection, and destruction decisions. |
| 3. Security Architecture and Engineering | 13% | Understand secure design principles, models, cryptography, system types, physical design, and lifecycle engineering. |
| 4. Communication and Network Security | 13% | Apply secure architecture, segmentation, protocols, transmission, remote access, and network operations concepts. |
| 5. Identity and Access Management | 13% | Manage identities, authentication, authorization, federation, access models, provisioning, review, and deprovisioning. |
| 6. Security Assessment and Testing | 12% | Choose assessment strategies, collect evidence, test controls, interpret results, report findings, and support audits. |
| 7. Security Operations | 13% | Connect investigations, monitoring, incidents, vulnerability management, change, resilience, recovery, and personnel safety. |
| 8. Software Development Security | 10% | Integrate security into development, acquisition, testing, coding, deployment, maintenance, and software supply chains. |
Domain 1: Security and Risk Management
Domain 1 establishes how security decisions are governed and justified. It covers professional ethics, security principles, organizational governance, legal and regulatory obligations, investigations, policy, business continuity, personnel security, risk management, threat modeling, supply-chain risk, and security learning programs.
Start with the detailed Security and Risk Management guide. The vocabulary in this domain appears throughout the other seven domains, especially ownership, due care, due diligence, risk response, policy hierarchy, resilience, and control assessment.
Domain 2: Asset Security
Asset Security follows information and other assets through classification, ownership, handling, storage, retention, protection, and destruction. Study the roles of owner, controller, custodian, processor, user, and data subject. Connect each role to authority and responsibility rather than memorizing titles without context.
A classification label matters because it drives handling requirements. Those requirements influence access control, encryption, monitoring, backup, retention, transmission, and disposal. Use the detailed Asset Security guide to connect the six official objectives to practical lifecycle decisions.
Domain 3: Security Architecture and Engineering
This domain combines abstract security models with practical engineering decisions. Topics include secure design principles, system security capabilities, architecture weaknesses, cryptography, physical security, and the information-system lifecycle.
Learn what a model or principle protects, which assumption it makes, and where it fits. A name alone is rarely enough. For cryptography, connect algorithm selection to confidentiality, integrity, authentication, nonrepudiation, key management, performance, and lifecycle risk. Use the detailed Security Architecture and Engineering guide to connect all ten official objectives.
Domain 4: Communication and Network Security
Communication and Network Security covers secure network design, traffic flow, segmentation, protocols, transmission media, wireless and mobile networking, remote access, network components, and third-party connectivity.
Technical recognition remains important, but CISSP adds architecture and governance questions. A secure connection must fit the trust boundary, performance need, availability requirement, management model, and monitoring strategy. Use the detailed Communication and Network Security guide to connect all three official objectives.
Domain 5: Identity and Access Management
Identity and Access Management (IAM) covers people, devices, services, credentials, sessions, federation, access-control models, provisioning, review, and removal. Follow the identity lifecycle from registration and proofing through authorization, monitoring, changes, and deprovisioning.
Separate identification, authentication, authorization, and accounting. Then connect each step to governance principles such as least privilege, need to know, separation of duties, and periodic review. Use the detailed Identity and Access Management guide to connect all six official objectives.
Domain 6: Security Assessment and Testing
This domain asks how an organization selects, performs, and evaluates assessments. Study testing strategies, vulnerability assessments, penetration testing, code review, control testing, process data, audits, analysis, remediation, exceptions, and reporting.
The method should match the purpose and authority. An audit, vulnerability assessment, penetration test, and red-team exercise can all reveal weaknesses, but they differ in scope, independence, depth, rules of engagement, and expected output.
Use the detailed Security Assessment and Testing guide to connect the five official objectives to planning, evidence, control testing, reporting, remediation, exceptions, and audits.
Domain 7: Security Operations
Security Operations covers investigations, evidence, logging, monitoring, configuration, privileged access, incident management, protective technologies, vulnerability management, change, backup, recovery, disaster recovery, business continuity, physical security, and personnel safety.
Sequence matters. Preserve life and safety, follow approved response procedures, protect evidence, contain harm, communicate appropriately, recover services, and use lessons learned to improve controls.
Use the detailed Security Operations guide to connect investigations, monitoring, configuration, incident management, patching, recovery, continuity, physical safeguards, personnel safety, and AI-assisted operations.
Domain 8: Software Development Security
Software Development Security integrates security into development and acquisition. Topics include development methodologies, maturity models, coding practices, application testing, dependencies, repositories, continuous integration and delivery, acquired software, managed services, and cloud services.
The most effective security work begins with requirements and design. Testing near release remains necessary, but it cannot replace secure architecture, trusted dependencies, controlled change, and lifecycle ownership.
Use the detailed Software Development Security guide to connect the secure software lifecycle, development methods, repositories, pipelines, application testing, acquired software, supply-chain controls, coding standards, APIs, software-defined security, and AI-assisted development.
A practical CISSP study plan
Use a plan that reflects your own background rather than giving every topic identical time.
Phase 1: Build the map
- Read the complete official outline.
- Mark each objective by confidence and direct experience.
- Identify the two domains with the least practical exposure.
- Note concepts that appear in several domains, such as risk, ownership, lifecycle, least privilege, testing, and resilience.
Phase 2: Strengthen weak domains
For each weak objective, create a short explanation that answers:
- What problem does this concept solve?
- Who owns or approves the decision?
- Which requirement or risk drives it?
- What evidence shows it is working?
- What lifecycle event could change the answer?
Use small scenarios. A paragraph that explains a supplier outage, a privacy requirement, or an access review is more useful than a page of disconnected definitions.
Phase 3: Mix the domains
CISSP scenarios often cross boundaries. Practice following one situation through several domains:
- A cloud service begins with governance and supplier risk.
- Its data requires classification, ownership, and retention.
- Its architecture needs trust boundaries, encryption, and resilience.
- Its users and services require identity controls.
- Its controls need assessment and monitoring.
- Its incidents and changes require operational processes.
- Its integrations and code require software-development security.
Phase 4: Practice decision quality
For every question, state the role and goal before reviewing the answers. After answering, explain why the strongest alternative is weaker. Common reasons include:
- It occurs too early or too late in the process.
- It exceeds the person's authority.
- It solves the technical symptom without addressing the governing requirement.
- It ignores evidence, documentation, legal duties, or business impact.
- It treats risk acceptance as a security-team decision rather than a risk-owner decision.
- It selects a control before requirements and classification are understood.
Review habits that improve retention
Use several forms of recall instead of rereading the same chapter:
- Draw a responsibility map for owners, custodians, users, assessors, risk owners, and leadership.
- Compare two similar terms without looking at notes.
- Explain a control to a technical employee, a business owner, and an executive using different levels of detail.
- Build a lifecycle from acquisition through disposal and place the appropriate security decisions at each stage.
- Review missed questions by clue, not only by topic.
- Revisit weak concepts after several days, then again after several weeks.
A high score in one familiar domain should not hide a serious gap elsewhere. The adaptive exam still draws from all eight domains, and the certification represents broad professional judgment.
Official references
- ISC2 CISSP Certification Exam Outline
- ISC2 CISSP certification page
- ISC2 computerized adaptive testing guidance
- ISC2 ethics guidance
- NIST Cybersecurity Framework 2.0
- NIST Risk Management Framework
The official outline defines exam scope. The additional references provide durable context for governance, risk, ethics, and lifecycle decisions. CertHappens is an independent study resource and is not affiliated with or endorsed by ISC2.