CCSP - Certified Cloud Security Professional¶
Exam Overview¶
The Certified Cloud Security Professional (CCSP) is a joint certification from ISC2 and the Cloud Security Alliance (CSA). It validates advanced technical and managerial competence in cloud security architecture, design, operations, and service orchestration. CCSP is widely recognized for cloud security architects, cloud security engineers, and cloud-focused CISOs.
CCSP is accredited under ANSI/ISO/IEC 17024 and is approved for several US Department of Defense (DoD) cloud security workforce roles.
Exam Details: - Exam Code: CCSP - Format: Linear, fixed-form - Duration: 3 hours - Number of Questions: 150 - Question Types: Multiple choice - Passing Score: 700 out of 1000 (scaled) - Cost: $599 USD - Languages: English, Japanese, Chinese (Simplified), Korean, German - Delivery: Pearson VUE testing centers - Validity: 3 years (recertification via 90 CPE credits) - Prerequisites: 5 years cumulative paid IT work experience, including 3 years of information security and 1 year in one or more of the 6 CCSP CBK domains. CISSP holders may substitute it for the entire CCSP experience requirement. CCSK holders may substitute CCSK for the 1 year of CCSP-domain experience.
Six CCSP Domains¶
Domain 1: Cloud Concepts, Architecture, and Design (17%)¶
- Cloud computing concepts: definition (NIST SP 800-145), characteristics, service models, deployment models
- Cloud reference architecture
- Security concepts relevant to cloud computing
- Design principles for secure cloud computing
- Trusted Cloud Services and certifications (CSA STAR, ISO 27017/27018, FedRAMP, BSI C5)
Domain 2: Cloud Data Security (20%)¶
- Cloud data lifecycle (Create, Store, Use, Share, Archive, Destroy)
- Cloud data storage architectures
- Data security technologies and strategies
- Data discovery and classification
- Information rights management (IRM) / DRM
- Data retention, deletion, and archiving
- Data event auditability, traceability, accountability
Domain 3: Cloud Platform and Infrastructure Security (17%)¶
- Cloud infrastructure components
- Risk management for cloud infrastructure
- Plan and implement security controls
- Plan disaster recovery and BCP for cloud
- Hypervisor security, container security
- Network security in cloud (SDN, microsegmentation, zero trust)
- Compute, storage, network virtualization
Domain 4: Cloud Application Security (17%)¶
- Training and awareness for application security
- Cloud application architecture
- Cloud SDLC
- Secure application architecture (sandboxing, application virtualization)
- Cryptography in cloud applications
- Identity and access management for cloud apps
- API security
- Verification and validation of cloud applications
Domain 5: Cloud Security Operations (16%)¶
- Implement and build physical and logical infrastructure
- Operate physical and logical infrastructure
- Manage physical and logical infrastructure
- Implement operational controls and standards (ITIL, ISO 20000)
- Support digital forensics
- Manage communication with stakeholders
- Manage security operations (SOC, SIEM, log management, vulnerability management)
Domain 6: Legal, Risk, and Compliance (13%)¶
- Legal requirements and unique risks within the cloud environment
- Privacy issues and jurisdictional differences
- Audit process, methodologies, and required adaptations for a cloud environment
- Implications of cloud to enterprise risk management
- Outsourcing and cloud contract design
- Vendor management
Study Materials¶
Notes¶
- 01 - Cloud Concepts, Architecture, and Design
- 02 - Cloud Data Security
- 03 - Cloud Platform and Infrastructure Security
- 04 - Cloud Application Security
- 05 - Cloud Security Operations
- 06 - Legal, Risk, and Compliance
Study Resources¶
- Fact Sheet - Quick reference
- Practice Plan - 10-week study schedule
- Scenarios - Cloud security scenarios
- Strategy - Exam day tactics
Audience and Career Profile¶
CCSP targets practitioners with significant cloud security responsibility. Common roles:
- Cloud Security Architect
- Cloud Security Engineer
- Cloud Security Consultant
- Cloud Security Manager / CISO with cloud focus
- Enterprise Architect with cloud security responsibility
- Security Analyst working primarily in cloud
- Compliance Officer focused on cloud
Official Resources¶
- CCSP Certification Page: https://www.isc2.org/certifications/ccsp
- CCSP Exam Outline: https://www.isc2.org/certifications/ccsp/ccsp-exam-outline
- CSA Guidance v5: https://cloudsecurityalliance.org/research/guidance (free)
- Cloud Controls Matrix (CCM) v4: https://cloudsecurityalliance.org/research/cloud-controls-matrix (free)
- NIST SP 800-145: Cloud computing definition
- NIST SP 500-291: Cloud Computing Standards Roadmap
- NIST SP 800-144: Guidelines on Security and Privacy in Public Cloud
- NIST SP 800-210: Access Control for Cloud
- ISO/IEC 17788: Cloud computing overview and vocabulary
- ISO/IEC 17789: Cloud computing reference architecture
- ISO/IEC 27017: Code of practice for cloud information security
- ISO/IEC 27018: Code of practice for protection of PII in public clouds
- ISO/IEC 27701: Privacy information management system
Recommended Training¶
Books¶
- (ISC)2 CCSP Official Study Guide, 4th Edition (Sybex) - primary text
- (ISC)2 CCSP Official Practice Tests, 3rd Edition (Sybex)
- CCSP All-in-One Exam Guide (McGraw Hill)
- CSA Security Guidance v5 (free PDF) - foundational reading
Video Courses¶
- Pete Zerger CCSP Exam Cram (free on YouTube)
- Destination Certification CCSP MasterClass
- Mike Chapple CCSP (LinkedIn Learning)
- Kelly Handerhan CCSP (Cybrary)
Practice Tests¶
- Boson ExSim CCSP - high-quality practice
- Sybex Official Practice Tests
- LearnZapp CCSP
- Pocket Prep CCSP
Relationship to Other Certifications¶
| Certification | Relationship to CCSP |
|---|---|
| CISSP | Senior security generalist; CISSP credit waives full CCSP experience |
| CCSK | Foundational cloud security; CCSK credit waives 1 year CCSP-domain experience |
| AWS Security Specialty | AWS-specific, complements CCSP |
| Azure AZ-500 / SC-100 | Azure-specific, complements CCSP |
| Google Professional Cloud Security Engineer | GCP-specific, complements CCSP |
| ISACA CCAK | Cloud auditing focus |
CCSP is vendor-neutral and architectural; provider-specific certs validate hands-on skills with one cloud.
After You Pass¶
- Submit endorsement application within 9 months (ISC2 member endorsement or ISC2 endorsement)
- Pay first Annual Maintenance Fee ($135)
- Earn 90 CPE credits over 3-year cycle (30 CPE/year minimum)
- 60 CPEs must be Group A (security-related)
- Adhere to ISC2 Code of Ethics
Mindset Tip¶
CCSP, like CISSP, rewards judgment over technical depth. Choose the answer that: 1. Addresses the cloud-specific nuance (shared responsibility, multi-tenancy, ephemeral workloads) 2. Reflects the cloud customer's responsibility correctly under the service model (IaaS/PaaS/SaaS) 3. Considers legal and jurisdictional implications 4. Aligns to vendor-neutral best practice (CSA, NIST, ISO), not single-vendor preference
CCSP is more technical than CISSP, but the same "manager-perspective best answer" approach applies.