Skip to content

CISSP - Certified Information Systems Security Professional

Exam Overview

The Certified Information Systems Security Professional (CISSP) is ISC2's flagship certification and one of the most respected credentials in information security. It validates the ability to design, implement, and manage a best-in-class cybersecurity program. CISSP is widely required for senior security roles such as CISO, security architect, security manager, and security consultant.

CISSP is accredited under ANSI/ISO/IEC Standard 17024 and approved for US Department of Defense roles under directive 8140 (formerly 8570). It is regularly cited as a baseline requirement by federal agencies, defense contractors, and large enterprises.

Exam Details: - Exam Code: CISSP - Format (English): Computerized Adaptive Testing (CAT) - Format (other languages): Linear, fixed-form - Duration (CAT): 3 hours - Duration (linear): 6 hours - Number of Questions (CAT): 100 to 150 - Number of Questions (linear): 250 - Question Types: Multiple choice and advanced innovative questions (drag-and-drop, hotspot) - Passing Score: 700 out of 1000 (scaled) - Cost: $749 USD - Languages: English (CAT); Chinese, German, Japanese, Korean, Spanish, French, Brazilian Portuguese (linear) - Delivery: Pearson VUE testing centers worldwide - Validity: 3 years (recertification via 120 CPE credits) - Prerequisites: 5 years cumulative paid work experience in 2 or more of the 8 CBK domains. A 4-year college degree or approved credential waives 1 year. Candidates without experience pass the exam to become Associate of ISC2.

Eight CISSP Domains (2024 Refresh)

Domain 1: Security and Risk Management (16%)

  • Professional ethics and ISC2 Code of Ethics
  • Security concepts: CIA, authenticity, non-repudiation, privacy
  • Security governance principles
  • Compliance and legal/regulatory requirements
  • Investigation types and standards
  • Documentation: policies, standards, procedures, guidelines
  • Business continuity (BC) requirements
  • Personnel security policies and procedures
  • Risk management concepts and frameworks
  • Threat modeling
  • Supply chain risk management (SCRM)
  • Security awareness, education, training

Domain 2: Asset Security (10%)

  • Information and asset classification
  • Information and asset handling requirements
  • Provisioning resources securely
  • Data lifecycle management
  • Asset retention (EOL, EOS)
  • Data security controls and compliance
  • Data states: at rest, in transit, in use
  • Data roles: owner, steward, custodian, user
  • Privacy protection and data localization

Domain 3: Security Architecture and Engineering (13%)

  • Engineering processes using secure design principles
  • Security model fundamentals (Bell-LaPadula, Biba, Clark-Wilson)
  • System security capabilities
  • Security architecture vulnerabilities (client/server, IoT, ICS, cloud)
  • Cryptographic solutions
  • Cryptanalytic attacks
  • Physical security
  • Site and facility design

Domain 4: Communication and Network Security (13%)

  • Secure design principles for network architectures
  • OSI and TCP/IP models
  • IP networking, IPv4/IPv6
  • Secure protocols
  • Implications of multilayer protocols
  • Converged protocols (FCoE, iSCSI, VoIP, MPLS)
  • Wireless networks (Wi-Fi, Bluetooth, cellular, Zigbee)
  • Cellular/mobile networks
  • Content distribution networks
  • Network components security
  • Secure communication channels

Domain 5: Identity and Access Management (IAM) (13%)

  • Control physical and logical access to assets
  • Identification, authentication, authorization
  • Federated identity (SAML, OAuth, OIDC)
  • Credential management systems
  • Single sign-on (SSO)
  • Just-in-Time (JIT) provisioning
  • Identity as a Service (IDaaS)
  • Authorization mechanisms (RBAC, ABAC, MAC, DAC, RuBAC, risk-based)
  • Identity and access provisioning lifecycle
  • Account access review
  • Privileged access management (PAM)

Domain 6: Security Assessment and Testing (12%)

  • Assessment, test, audit strategies
  • Security control testing
  • Vulnerability assessments
  • Penetration testing
  • Log reviews
  • Synthetic transactions
  • Code review and testing
  • Misuse case testing
  • Test coverage analysis
  • Interface testing
  • Breach attack simulations
  • Compliance checks
  • Collect security process data
  • Internal vs external audits

Domain 7: Security Operations (13%)

  • Investigation requirements (administrative, criminal, civil, regulatory)
  • Logging and monitoring
  • Configuration management (CM)
  • Change management
  • Patch and vulnerability management
  • Foundational security operations concepts
  • Resource protection
  • Incident management lifecycle (NIST IR)
  • Detective and preventive measures (IDS/IPS, allowlists, sandboxing, honeypots)
  • Disaster recovery (DR) processes
  • BCP/DR testing
  • Personnel safety and security
  • Physical security

Domain 8: Software Development Security (10%)

  • Security in the software development lifecycle (SDLC)
  • Secure coding practices
  • Software development methodologies (Agile, Waterfall, DevOps, DevSecOps)
  • Maturity models (CMMI, BSIMM, SAMM)
  • Operation and maintenance
  • Change management in software
  • Integrated product team
  • Security controls in development environments
  • Effectiveness of software security
  • Acquired software security (COTS, OSS, SaaS)
  • Define and apply secure coding guidelines and standards

Study Materials

Notes

Study Resources

Audience and Career Profile

CISSP is targeted at experienced security professionals, typically with 5+ years of practical work in two or more domains. Common roles:

  • Chief Information Security Officer (CISO)
  • Security Director / VP of Security
  • Security Manager
  • Security Architect
  • Security Engineer / Senior Security Engineer
  • Security Consultant
  • Security Auditor
  • IT Director with security responsibility
  • Network/Systems Architect with security focus

Official Resources

  • CISSP Certification Page: https://www.isc2.org/certifications/cissp
  • CISSP Exam Outline: https://www.isc2.org/certifications/cissp/cissp-exam-outline (always download the latest)
  • Official ISC2 CISSP CBK Reference (book): Sybex/Wiley
  • Official ISC2 CISSP Study Guide (book): Sybex by Mike Chapple, James Stewart, Darril Gibson
  • Official ISC2 CISSP Practice Tests (book): Sybex
  • Self-paced training: ISC2 official course (~$1,300)
  • Instructor-led training: ISC2 authorized providers

Books

  1. (ISC)2 CISSP Official Study Guide, 10th Edition (Sybex) by Chapple, Stewart, Gibson - the gold standard
  2. (ISC)2 CISSP Official Practice Tests, 4th Edition (Sybex) by Chapple, Seidl
  3. CISSP All-in-One Exam Guide, 9th Edition (McGraw Hill) by Shon Harris, Fernando Maymi
  4. Eleventh Hour CISSP, 3rd Edition by Eric Conrad - excellent final-week review
  5. CISSP Officially Sucks by Luke Ahmed - mindset and tricky-question approach

Video Courses

  1. Destination Certification CISSP MasterClass (Pete Zerger, Rob Witcher) - widely considered the strongest video resource
  2. Pete Zerger's CISSP Exam Cram (free on YouTube)
  3. Kelly Handerhan's CISSP (Cybrary) - classic mindset training
  4. Inside Cloud and Security CISSP playlist (free on YouTube)
  5. Mike Chapple's CISSP (LinkedIn Learning)

Practice Tests

  1. ISC2 official practice exams via Pearson VUE
  2. Boson ExSim CISSP - widely recommended for difficulty calibration
  3. Pocket Prep CISSP
  4. LearnZapp CISSP Official ISC2 app
  5. Sybex test bank (with the official study guide)

Communities

  • r/cissp on Reddit (very active, full of recently-passed wisdom)
  • TechExams CISSP forum
  • ISC2 Community
  • Discord servers focused on CISSP study groups

After You Pass

  • Submit endorsement application within 9 months
  • Endorser must be an ISC2 certified member in good standing
  • Pay first Annual Maintenance Fee ($135)
  • Begin earning 120 CPE credits over the 3-year cycle (40 CPE per year minimum)
  • Adhere to ISC2 Code of Ethics

Mindset Tip

The CISSP exam tests the mindset of a security manager, not a hands-on engineer. When choosing between answers, ask: 1. Which protects life, then assets, then reputation? 2. Which addresses root cause vs symptom? 3. Which is the manager's first action (not the technician's)? 4. Which is the most strategic, not the most tactical?

This perspective is the single biggest determinant of exam success for technically strong candidates.