CISSP
Certified Information Systems Security Professional
CISSP is a widely recognized, experience-based information security certification covering eight domains. This track emphasizes the broad technical and managerial judgment the exam measures, including connections among governance, architecture, engineering, operations, and software security.
Exam Details
| Detail | CISSP |
|---|---|
| Format | CAT adaptive, 100–150 questions |
| Time | 3 hours |
| Standard Exam Fee (USD; verify regional price) | $749 USD |
| Passing Score | 700 out of 1000 |
| Experience | 5 years of cumulative qualifying experience in at least 2 of the 8 domains. A relevant bachelor’s or master’s degree, or an ISC2-approved credential, can satisfy up to 1 year; qualifying part-time work and internships may count |
| Renewal | 120 CPE credits per 3-year cycle; annual AMF $135 |
Source and Scope Note
Track scope checked August 24, 2026. The reference was the ISC2 CISSP Certification Exam Outline, effective April 15, 2024.
This note records the outline used for the track; it does not mean ISC2 reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.
What You’ll Learn
- Develop the managerial thinking ISC2 expects for security decisions
- Build breadth across all eight CISSP domains without sacrificing depth
- Prepare for the CAT exam format with targeted strategy
- Use domain evidence and a limited Domain 6 objective check to identify study gaps
Domain 1 — Security and Risk Management (16%)
Professional ethics, security governance principles, legal and regulatory compliance, business continuity, risk management concepts, threat modeling, supply chain risk, and security awareness programs.
Section A — Governance and Legal
- 1 Professional Ethics and ISC2 Code Free Free Preview
- 2 Core Security Concepts Full Access
- 3 Security Governance Principles Full Access
- 4 Legal, Regulatory, and Compliance Full Access
- 5 Investigation Types Full Access
- 6 Security Policy Development and Implementation Full Access
- ✓ Section A Review: Governance and Legal Full Access
Section B — Risk and Continuity
- 7 Business Continuity Requirements and BIA Full Access
- 8 Personnel Security Policies Full Access
- 9 Risk Management Concepts and Frameworks Full Access
- 10 Threat Modeling Methodologies Full Access
- 11 Supply Chain Risk Management Full Access
- 12 Security Awareness and Training Programs Full Access
- ✓ Section B Review: Risk and Continuity Full Access
Domain 1 Review
- ★ Capstone Review: SECURITY AND RISK MANAGEMENT Full Access
Domain 2 — Asset Security (10%)
Information and asset classification, handling requirements, secure provisioning, data lifecycle management, asset retention, and data security controls and compliance.
Section A — Classification and Provisioning
- 13 Information and Asset Classification Free Free Preview
- 14 Asset Handling Requirements Full Access
- 15 Secure Asset Provisioning and Inventory Full Access
- ✓ Section A Review: Classification and Provisioning Full Access
Section B — Data Lifecycle and Controls
- 16 Data Lifecycle Management Full Access
- 17 Asset Retention Full Access
- 18 Data Security Controls and Compliance Full Access
- ✓ Section B Review: Data Lifecycle and Controls Full Access
Domain 2 Review
- ★ Capstone Review: ASSET SECURITY Full Access
Domain 3 — Security Architecture and Engineering (13%)
Secure design principles, security models, control selection, system security capabilities, vulnerability mitigation, cryptographic solutions, cryptanalytic attacks, site and facility security, and information system lifecycle.
Section A — Design Principles and Models
- 19 Secure Design Principles Free Free Preview
- 20 Security Models Full Access
- 21 Security Requirements and Control Selection Full Access
- 22 Information System Security Capabilities Full Access
- ✓ Section A Review: Design Principles and Models Full Access
Section B — Vulnerabilities and Cryptography
- 23 Vulnerability Mitigation Full Access
- 24 Cryptographic Solutions and Lifecycle Full Access
- 25 Cryptanalytic Attacks Full Access
- ✓ Section B Review: Vulnerabilities and Cryptography Full Access
Section C — Physical Security and System Lifecycle
- 26 Site and Facility Security Principles Full Access
- 27 Facility Design Controls Full Access
- 28 Information System Lifecycle Management Full Access
- ✓ Section C Review: Physical Security and System Lifecycle Full Access
Domain 3 Review
- ★ Capstone Review: SECURITY ARCHITECTURE AND ENGINEERING Full Access
Domain 4 — Communication and Network Security (13%)
Secure network architecture design, secure network component implementation, and secure communication channels.
Section A — Network Architecture and Security
- 29 Secure Network Architecture Design Free Free Preview
- 30 Secure Network Component Implementation Full Access
- 31 Secure Communication Channel Implementation Full Access
- ✓ Section A Review: Network Architecture and Security Full Access
Domain 4 Review
- ★ Capstone Review: COMMUNICATION AND NETWORK SECURITY Full Access
Domain 5 — Identity and Access Management (13%)
Physical and logical access control, identification and authentication strategy, federated identity, authorization mechanisms, access provisioning lifecycle, and authentication systems.
Section A — Identity and Authentication
- 32 Physical and Logical Access Control Free Free Preview
- 33 Authentication Strategy Design Full Access
- 34 Federated Identity with Third Parties Full Access
- ✓ Section A Review: Identity and Authentication Full Access
Section B — Authorization and Lifecycle
- 35 Authorization Mechanisms Full Access
- 36 Identity and Access Provisioning Lifecycle Full Access
- 37 Authentication Systems Implementation Full Access
- ✓ Section B Review: Authorization and Lifecycle Full Access
Domain 5 Review
- ★ Capstone Review: IDENTITY AND ACCESS MANAGEMENT Full Access
Domain 6 — Security Assessment and Testing (12%)
Assessment and audit strategy design, security control testing, security process data collection, test output analysis and reporting, and security audit facilitation.
Section A — Assessments and Testing
- 38 Assessment and Audit Strategy Design Free Free Preview
- 39 Security Control Testing Methods Full Access
- 40 Security Process Data Collection Full Access
- 41 Test Output Analysis and Reporting Full Access
- 42 Security Audits Facilitation Full Access
- ✓ Section A Review: Assessments and Testing Full Access
Domain 6 Review
- ★ Capstone Review: SECURITY ASSESSMENT AND TESTING Full Access
Domain 7 — Security Operations (13%)
Investigations and evidence handling, logging and monitoring, configuration management, incident management, detection and prevention, patch and vulnerability management, recovery strategies, disaster recovery, business continuity, and physical security.
Section A — Investigations and Monitoring
- 43 Investigation Compliance and Evidence Handling Free Free Preview
- 44 Logging and Monitoring Activities Full Access
- 45 Configuration Management Full Access
- 46 Foundational Security Operations Concepts Full Access
- 47 Resource Protection Full Access
- 48 Incident Management Lifecycle Full Access
- 49 Detection and Preventative Measures Full Access
- ✓ Section A Review: Investigations and Monitoring Full Access
Section B — Recovery and Continuity
- 50 Patch and Vulnerability Management Full Access
- 51 Change Management Full Access
- 52 Recovery Strategies Full Access
- 53 Disaster Recovery Processes Full Access
- 54 Disaster Recovery Plan Testing Full Access
- 55 Business Continuity Planning Full Access
- 56 Physical Security Implementation Full Access
- 57 Personnel Safety and Security Full Access
- ✓ Section B Review: Recovery and Continuity Full Access
Domain 7 Review
- ★ Capstone Review: SECURITY OPERATIONS Full Access
Domain 8 — Software Development Security (10%)
Security integration in the SDLC, security controls in development ecosystems, software security effectiveness assessment, acquired software security impact, and secure coding guidelines and standards.
Section A — Secure Development
- 58 SDLC Security Integration Free Free Preview
- 59 Security Controls in Development Ecosystems Full Access
- 60 Software Security Effectiveness Assessment Full Access
- 61 Acquired Software Security Impact Full Access
- 62 Secure Coding Guidelines and Standards Full Access
- ✓ Section A Review: Secure Development Full Access
Domain 8 Review
- ★ Capstone Review: SOFTWARE DEVELOPMENT SECURITY Full Access
Career Benefits
- Relevant to senior security engineering, architecture, consulting, and leadership roles
- Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
- Covers a broad security body of knowledge used across many industries
- May be requested or valued for senior security architecture, consulting, and leadership roles
How It Compares
CISSP provides broad coverage across eight security domains, while CISM focuses specifically on security-program management. CySA+ V4 (CS0-004) occupies a different part of the path: it concentrates on analyst operations, vulnerability management, incident response, and reporting across four domains. CompTIA recommends approximately four years of relevant hands-on analyst experience for CySA+ but does not impose an experience prerequisite.
Choose CySA+ when you want focused operational-analysis depth; choose CISSP when your qualifying experience and goals span a broader set of technical and managerial domains. CySA+ is neither a prerequisite for CISSP nor a substitute for CISSP’s experience requirement. See the full comparison →
Head-to-head comparisons: CISSP vs CISM · CRISC vs CISSP · Security+ vs CISSP