CISSP tests broad professional judgment. Prefer answers that establish governance, understand requirements, assess risk, and choose proportionate controls before jumping to a tool.
The outline is interconnected: a software decision can implicate asset classification, identity, architecture, assessment, operations, legal duties, and supplier risk.
Provision resources and manage lifecycle, retention, controls, and compliance
D3 · 13%
Security Architecture and Engineering
Secure design and models
System capabilities and architecture vulnerabilities
Cryptography, facilities, and system lifecycle
D4 · 13%
Communication and Network Security
Secure network design
Secure network components
Secure communication channels
D5 · 13%
Identity and Access Management
Physical and logical access
Identity, authentication, federation, authorization, lifecycle, and authentication systems
D6 · 12%
Security Assessment and Testing
Assessment strategy and control testing
Collect, analyze, and report process data
Internal, external, and third-party audits
D7 · 13%
Security Operations
Investigations, logging, configuration, and operational concepts
Resource protection, incidents, vulnerability and change management
Recovery, continuity, physical security, and personnel safety
D8 · 10%
Software Development Security
Software lifecycle and ecosystem controls
Assess software security effectiveness
Acquired software and secure coding
Use the official numbered objective hierarchy for coverage. The summaries here group objectives for study navigation and do not replace the outline.
Cross-map every scenario to at least two domains so breadth becomes integrated judgment rather than eight isolated memorization lists.
Device-local diagnostic
Mark domains that need review
These selections stay in this browser. They are not an exam score and are never sent to Baitaphish.
No domains currently marked.
Diagnostic
For each domain, explain its governance purpose, one lifecycle, one failure mode, one assessment method, and how it connects to two other domains.
Risk framing
Lifecycle reasoning
Management priority
Control selection
Assessment evidence
Cross-domain integration
Shared foundations
These subjects are maintained once across the certification library; this guide applies them through its own domain lens.
Risk and governance
Translate business context, policy, legal duties, control ownership, and evidence into defensible risk decisions.
Data protection and cryptography
Choose controls for classification, lifecycle, encryption, keys, secrets, privacy, retention, and defensible deletion.
Secure architecture
Reason about trust boundaries, resilience, data flows, network controls, and security tradeoffs before selecting products.
Identity and access
Explain authentication, authorization, federation, lifecycle controls, and least privilege across organizational and cloud boundaries.
Operations and incident response
Connect telemetry, triage, containment, recovery, change, and continuous improvement to measurable outcomes.
Delivery and assurance
Build testing, software lifecycle, deployment, evaluation, audit, and evidence practices into normal delivery work.
Study sequence and reusable assets
Governance and assets
Anchor decisions in ethics, requirements, risk, policy, classification, and lifecycle.
Governance and asset decision cases: Choose the accountable first action and explain why.
Architecture, network, and identity
Connect design principles, trust boundaries, protocols, cryptography, and access models.
Architecture, network, and identity map: Retrieve related concepts without treating domains as silos.
Assessment and operations
Distinguish testing, audit, detection, response, recovery, and continuity responsibilities.
Assessment-to-recovery tabletop: Separate assurance, operations, response, continuity, and recovery roles.
Software and synthesis
Apply lifecycle assurance and supplier decisions in mixed-domain executive scenarios.
Mixed-domain synthesis set: Identify scope, role, priority, and lifecycle stage in ambiguous scenarios.
Common misconceptions
“The most technical control is usually the best answer.”
CISSP questions often prioritize requirements, safety, governance, risk assessment, and accountable process before implementation detail.
“Business continuity and disaster recovery are interchangeable.”
Continuity sustains prioritized business activities; disaster recovery restores technology capabilities that support them.
“Passing the exam immediately grants the CISSP certification.”
ISC2 also requires endorsement and qualifying experience; candidates without it can use the Associate pathway under current rules.
Seven-day experienced review sprint
Experienced cross-domain practitioner who has already completed a baseline and needs one final week.
Day 1 — Diagnostic, ethics, governance, legal duties, risk, and asset lifecycle.
Day 2 — Architecture principles, models, crypto, physical design, and network trust boundaries.
Day 3 — Identity lifecycle, federation, authorization models, and access reviews.
Day 4 — Assessment strategy, test evidence, audit independence, and reporting.
Day 5 — Operations, incident response, recovery, continuity, change, and personnel safety.
Day 6 — Software lifecycle, acquired software, supplier risk, and mixed-domain scenarios.
Day 7 — Timed set, management-level error review, and endorsement/logistics check.
Longer study path
Practitioner with uneven domain exposure using an eight- to twelve-week path.
Map prior experience to the official objective numbers and mark true gaps.
Study foundations in paired domains, producing concept maps and short management explanations.
Use scenario reviews to practice order of operations: understand, govern, assess, design, implement, verify, improve.
Teach one weak topic weekly and correct imprecise terms against official or standards sources.
Complete mixed timed sets and use an error taxonomy: knowledge, scope, priority, actor, or reading error.
Exam logistics
Verify the current exam format, adaptive-testing availability, languages, identification, rescheduling, and pricing directly with ISC2 before booking.
ISC2 currently describes five years of cumulative paid work in two or more CISSP domains, with up to a one-year waiver; an exam passer without the experience may become an Associate of ISC2 and has six years to earn it.
Review the official endorsement process separately from exam preparation. This unofficial guide is not affiliated with or endorsed by ISC2.