ISC2 CISSP Study Guide: Eight Domains, Exam Format, and Study Plan
Prepare for ISC2 CISSP with the current eight-domain outline, exam weights, experience requirements, CAT format, and a practical study plan.
The ISC2 Certified Information Systems Security Professional (CISSP) is a broad information security certification for experienced professionals who design, manage, or assess organizational security. The exam spans governance, risk, architecture, networks, identity, testing, operations, and software development security. Preparation calls for technical understanding and the ability to reason about business risk and management responsibility.
This guide follows the current official CISSP exam outline, effective April 15, 2024. Confirm that your study materials match this version.
Who is this exam for?
CISSP suits professionals with information security or IT experience who want to demonstrate judgment across multiple security domains. Related roles include security engineers, analysts, architects, auditors, consultants, managers, and leaders. Because the exam covers a wide range and includes scenario-based questions, memorizing terms without practical context is rarely enough.
Experience requirements and exam format
To earn the CISSP, candidates generally need five years of cumulative, full-time paid work experience in at least two of the eight current domains. A qualifying post-secondary degree in computer science, IT, or a related field, or an additional credential on ISC2’s approved list, may waive up to one year; waivers cannot exceed one year in total. Review ISC2’s current experience requirements for eligibility details. Candidates who pass before meeting the experience requirement may apply as an Associate of ISC2 and have six years to complete it. Certification also requires ISC2 endorsement and agreement to its professional ethics requirements.
The exam uses Computerized Adaptive Testing (CAT), lasts up to 3 hours, and contains 100–150 items, including multiple-choice and advanced item types. The passing score is 700 out of 1,000. Exam languages include Chinese, English, German, Japanese, and Spanish; Chinese appointments are available only during select windows. Confirm the official exam outline and scheduling information before booking.
Eight domains and exam weights
| Domain | Main topics | Weight |
|---|---|---|
| 1. Security and Risk Management | Governance, policy, ethics, law, risk, business continuity | 16% |
| 2. Asset Security | Data classification, asset handling, retention, and protection | 10% |
| 3. Security Architecture and Engineering | Security models, cryptography, system design, engineering controls | 13% |
| 4. Communication and Network Security | Network architecture, protocols, segmentation, communications protection | 13% |
| 5. Identity and Access Management (IAM) | Identity lifecycle, authentication, authorization, access control | 13% |
| 6. Security Assessment and Testing | Security testing, audits, vulnerability assessment, control validation | 12% |
| 7. Security Operations | Incident response, investigations, recovery, change, operational controls | 13% |
| 8. Software Development Security | Secure development lifecycle, code security, software supply chain | 10% |
Domain 1 has the largest weight, but the other domains remain essential. They connect: asset classification informs access and encryption requirements, while architecture choices affect operations, testing, and incident response.
How to study the eight domains
1. Security and Risk Management
Connect security objectives to the organization’s mission and business goals. Study governance roles, policies and standards, professional ethics, legal and privacy requirements, and risk identification, analysis, treatment, and monitoring. Also cover threat modeling, third-party and supply-chain risk, awareness programs, and business continuity analysis.
Scenario questions often ask for an action that fits the organization’s risk appetite, legal duties, and business priorities. Identify the decision maker, who accepts the risk, and whether a mandatory requirement applies.
2. Asset Security
Learn how to identify and classify information and assets, then set handling requirements. Classification should influence access, storage, transmission, retention, and destruction. Study data lifecycle, privacy and ownership responsibilities, asset inventories, and data handling processes.
For data protection questions, first determine sensitivity, ownership, purpose, and lifecycle stage. Then choose controls that fit the classification instead of applying a technology without context.
3. Security Architecture and Engineering
Review secure design principles, trust boundaries, defense in depth, isolation, and security models. Understand how cryptography supports confidentiality, integrity, authentication, and nonrepudiation. Be ready to assess weaknesses across operating systems, databases, cloud services, virtualization, containers, IoT, and distributed systems.
Practice deriving architectural controls from requirements and threats instead of memorizing product names. For design questions, start with the security objective, impact of failure, trust boundaries, and how the control can be validated.
4. Communication and Network Security
Understand how network architectures and protocols move data, and how segmentation, boundary protection, remote access, and secure protocols reduce risk. Review the roles of common network devices and controls, and use data flows and trust boundaries to decide where protections belong.
For network scenarios, map the communicating parties, path, and boundaries before selecting filtering, encryption, monitoring, or isolation. Controls should fit communication needs without granting unnecessary access.
5. Identity and Access Management (IAM)
Distinguish identification, authentication, authorization, and accountability. Study identity lifecycle, access reviews, least privilege, separation of duties, privileged access, multifactor authentication, and federated identity. Understand access control models in relation to data sensitivity and organizational roles.
For an access question, identify who is accessing which resource, what action is needed, and the business reason. Consider when access should be granted, reviewed, and revoked. Successful authentication does not automatically authorize every action.
6. Security Assessment and Testing
Understand the goals and boundaries of control assessments, vulnerability assessments, penetration tests, audits, and compliance verification. Testing requires authorization, a defined scope, evidence handling, result analysis, and remediation tracking. Results should support risk decisions, not just produce a report.
Distinguish verifying whether controls work as designed, finding technical weaknesses, and independently auditing requirements. Select a method based on the objective, authorized scope, impact tolerance, and evidence needed.
7. Security Operations
Cover day-to-day controls, change management, configuration and patching, log monitoring, incident response, digital forensics, disaster recovery, and personnel security. Incident handling commonly includes preparation, detection and analysis, containment, eradication, recovery, and lessons learned. Preserve evidence integrity and follow escalation procedures.
Business continuity, disaster recovery, and incident response work together but address different problems. In a scenario, reduce harm, preserve evidence, follow responsibilities and procedures, then restore services.
8. Software Development Security
Build security into requirements, design, development, testing, deployment, and maintenance. Study threat modeling, secure coding, code review, dependency and third-party component management, and the purpose of static, dynamic, and interactive application security testing.
Consider the software supply chain, build environment, repositories, and release process. Security testing is not a one-time check before launch; remediation, change review, and production feedback are part of ongoing software security.
Concepts that are easy to confuse
- Risk owner and control operator: The person who accepts or treats risk may not be the person who configures the control each day.
- Authentication and authorization: Authentication establishes identity; authorization determines permitted access.
- Business continuity and disaster recovery: Continuity keeps critical business functions operating; disaster recovery restores systems and data.
- Vulnerability assessment and penetration testing: An assessment identifies and prioritizes weaknesses; a test validates exploitability and impact within an authorized scope.
- Policy, standard, procedure, and guideline: A policy sets direction; a standard defines a mandatory baseline; a procedure gives steps; a guideline offers recommended practices.
- Management judgment and technical detail: First choose an action that meets business goals, reduces overall risk, and complies with requirements; then consider implementation.
Eight-week study plan
| Week | Focus | Suggested outcome |
|---|---|---|
| 1 | Security and risk management | Analyze scenarios using business goals, ownership, and risk appetite |
| 2 | Asset security and data lifecycle | Set handling, protection, and disposal requirements from classification |
| 3 | Security architecture and engineering | Derive architecture controls from threats and security objectives |
| 4 | Communication and network security | Identify boundaries and protections along a communication path |
| 5 | IAM and access control | Distinguish identity, authentication, authorization, and accountability |
| 6 | Security assessment and testing | Select an assessment method and explain its limits |
| 7 | Security operations and software development security | Handle incidents and integrate security into the SDLC |
| 8 | Integrated scenarios and weak-domain review | Analyze risk, ownership, and control priorities across domains |
Each week, combine outline-based study, active recall, and scenario practice. For missed questions, record the reasoning and the trap, especially roles, business impact, authorization scope, and risk priority. Do not just memorize answer letters.
Exam readiness checklist
- Explain all eight domains and weights using materials aligned with the April 2024 outline.
- Choose priorities based on business goals, risk appetite, legal duties, and responsibility.
- Connect asset classification, access control, architecture, and operations in scenarios.
- Distinguish the purpose and limits of assessments, audits, vulnerability reviews, and penetration tests.
- Handle incidents in a sound order while protecting evidence and supporting recovery.
- Verify experience, waiver eligibility, and appointment details against current ISC2 requirements.
What to practice next
CISSP scenarios often cross several domains. Identify the business objective, risk, owner, and constraints first; then choose the best next action. Afterward, explain why the other options do not fit the scenario. Start CISSP practice