Unofficial study guide · ISC2

Certified Information Systems Security Professional

An unofficial management-level study system aligned to the CISSP outline effective April 15, 2024.

Exam code CISSP · Scope Exam outline effective April 15, 2024 · Reviewed

How to use this guide

CISSP tests broad professional judgment. Prefer answers that establish governance, understand requirements, assess risk, and choose proportionate controls before jumping to a tool.

The outline is interconnected: a software decision can implicate asset classification, identity, architecture, assessment, operations, legal duties, and supplier risk.

Official domain map

D1 · 16%

Security and Risk Management

  • Ethics and security concepts
  • Governance, legal and regulatory requirements
  • Investigations, policy, continuity, personnel, risk, threat modeling, supply chain, and awareness
D2 · 10%

Asset Security

  • Classify and handle information and assets
  • Provision resources and manage lifecycle, retention, controls, and compliance
D3 · 13%

Security Architecture and Engineering

  • Secure design and models
  • System capabilities and architecture vulnerabilities
  • Cryptography, facilities, and system lifecycle
D4 · 13%

Communication and Network Security

  • Secure network design
  • Secure network components
  • Secure communication channels
D5 · 13%

Identity and Access Management

  • Physical and logical access
  • Identity, authentication, federation, authorization, lifecycle, and authentication systems
D6 · 12%

Security Assessment and Testing

  • Assessment strategy and control testing
  • Collect, analyze, and report process data
  • Internal, external, and third-party audits
D7 · 13%

Security Operations

  • Investigations, logging, configuration, and operational concepts
  • Resource protection, incidents, vulnerability and change management
  • Recovery, continuity, physical security, and personnel safety
D8 · 10%

Software Development Security

  • Software lifecycle and ecosystem controls
  • Assess software security effectiveness
  • Acquired software and secure coding

Use the official numbered objective hierarchy for coverage. The summaries here group objectives for study navigation and do not replace the outline.

Cross-map every scenario to at least two domains so breadth becomes integrated judgment rather than eight isolated memorization lists.

Device-local diagnostic

Mark domains that need review

These selections stay in this browser. They are not an exam score and are never sent to Baitaphish.

No domains currently marked.

Diagnostic

For each domain, explain its governance purpose, one lifecycle, one failure mode, one assessment method, and how it connects to two other domains.

  • Risk framing
  • Lifecycle reasoning
  • Management priority
  • Control selection
  • Assessment evidence
  • Cross-domain integration

Shared foundations

These subjects are maintained once across the certification library; this guide applies them through its own domain lens.

Risk and governance

Translate business context, policy, legal duties, control ownership, and evidence into defensible risk decisions.

Data protection and cryptography

Choose controls for classification, lifecycle, encryption, keys, secrets, privacy, retention, and defensible deletion.

Secure architecture

Reason about trust boundaries, resilience, data flows, network controls, and security tradeoffs before selecting products.

Identity and access

Explain authentication, authorization, federation, lifecycle controls, and least privilege across organizational and cloud boundaries.

Operations and incident response

Connect telemetry, triage, containment, recovery, change, and continuous improvement to measurable outcomes.

Delivery and assurance

Build testing, software lifecycle, deployment, evaluation, audit, and evidence practices into normal delivery work.

Study sequence and reusable assets

  1. Governance and assets

    Anchor decisions in ethics, requirements, risk, policy, classification, and lifecycle.

    • Governance and asset decision cases: Choose the accountable first action and explain why.
  2. Architecture, network, and identity

    Connect design principles, trust boundaries, protocols, cryptography, and access models.

    • Architecture, network, and identity map: Retrieve related concepts without treating domains as silos.
  3. Assessment and operations

    Distinguish testing, audit, detection, response, recovery, and continuity responsibilities.

    • Assessment-to-recovery tabletop: Separate assurance, operations, response, continuity, and recovery roles.
  4. Software and synthesis

    Apply lifecycle assurance and supplier decisions in mixed-domain executive scenarios.

    • Mixed-domain synthesis set: Identify scope, role, priority, and lifecycle stage in ambiguous scenarios.

Common misconceptions

The most technical control is usually the best answer.

CISSP questions often prioritize requirements, safety, governance, risk assessment, and accountable process before implementation detail.

Business continuity and disaster recovery are interchangeable.

Continuity sustains prioritized business activities; disaster recovery restores technology capabilities that support them.

Passing the exam immediately grants the CISSP certification.

ISC2 also requires endorsement and qualifying experience; candidates without it can use the Associate pathway under current rules.

Seven-day experienced review sprint

Experienced cross-domain practitioner who has already completed a baseline and needs one final week.

  1. Day 1 — Diagnostic, ethics, governance, legal duties, risk, and asset lifecycle.
  2. Day 2 — Architecture principles, models, crypto, physical design, and network trust boundaries.
  3. Day 3 — Identity lifecycle, federation, authorization models, and access reviews.
  4. Day 4 — Assessment strategy, test evidence, audit independence, and reporting.
  5. Day 5 — Operations, incident response, recovery, continuity, change, and personnel safety.
  6. Day 6 — Software lifecycle, acquired software, supplier risk, and mixed-domain scenarios.
  7. Day 7 — Timed set, management-level error review, and endorsement/logistics check.

Longer study path

Practitioner with uneven domain exposure using an eight- to twelve-week path.

  1. Map prior experience to the official objective numbers and mark true gaps.
  2. Study foundations in paired domains, producing concept maps and short management explanations.
  3. Use scenario reviews to practice order of operations: understand, govern, assess, design, implement, verify, improve.
  4. Teach one weak topic weekly and correct imprecise terms against official or standards sources.
  5. Complete mixed timed sets and use an error taxonomy: knowledge, scope, priority, actor, or reading error.

Exam logistics

  • Verify the current exam format, adaptive-testing availability, languages, identification, rescheduling, and pricing directly with ISC2 before booking.
  • ISC2 currently describes five years of cumulative paid work in two or more CISSP domains, with up to a one-year waiver; an exam passer without the experience may become an Associate of ISC2 and has six years to earn it.
  • Review the official endorsement process separately from exam preparation. This unofficial guide is not affiliated with or endorsed by ISC2.

Official sources