Independent study system · ISC2

Certified Information Systems Security Professional

A management-perspective CISSP system covering all eight domains and 62 objectives through source-linked lessons, decision matrices, scenarios, recall, and fixed-length non-adaptive practice.

By

Exam code CISSP · April 2024 outline · facts checked
Current exam snapshot

CISSP at a glance

official
Version
April 2024 outline
Effective
2024-04-15
Time
180 minutes
Items
100–150
Scored / unscored
Not disclosed
Passing standard
700 out of 1,000 points

Formats: multiple-choice.

Delivery: ISC2 Authorized PPC or Pearson VUE Test Center Select.

The live ISC2 certification page states 100–150 items; the linked April 2024 outline PDF states 125–150. Baitaphish fixed-length practice is not CAT and cannot estimate an ISC2 scaled result.

Who this system is for

Provider statement · official

Experience requirement

Five years of cumulative full-time experience in two or more domains; an eligible degree or credential can waive no more than one year. Part-time work and internships may count.

Provider statement · official

Associate pathway

A candidate who passes without the required experience may become an Associate of ISC2 and has six years to earn the required experience.

Preparation prerequisites

  • Professional ethics and organizational governance
  • Risk and business continuity
  • Security architecture, networks, and identity
  • Assessment, operations, incident response, and recovery
  • Secure development and supplier risk
  • Ability to choose the best management action, not merely a technically possible action
Foundation-path triggers
  • Cannot distinguish policy, standard, procedure, and guideline
  • Cannot identify the risk owner
  • Cannot distinguish proofing, authentication, and authorization
  • Defaults to technical action before authority, safety, evidence, or business priority
Blueprint coverage

Official domains and objective lessons

62 objectives
D1 · 16%

Security and Risk Management

Make ethical, governance, legal, business-continuity, personnel, risk, threat-model, supply-chain, and awareness decisions from an organizational perspective.

  • 1.1 Professional ethics
  • 1.2 Security concepts
  • 1.3 Security governance
  • 1.4 Legal, regulatory, and compliance issues
  • 1.5 Investigation requirements
  • 1.6 Policies, standards, procedures, and guidelines
  • 1.7 Business continuity requirements
  • 1.8 Personnel security
  • 1.9 Risk management
  • 1.10 Threat modeling
  • 1.11 Supply-chain risk management
  • 1.12 Security awareness, education, and training
Open domain lesson →
D2 · 10%

Asset Security

Assign ownership, classify assets and information, define handling, provision securely, manage lifecycle and retention, and select data controls.

  • 2.1 Identify and classify information and assets
  • 2.2 Establish handling requirements
  • 2.3 Provision information and assets securely
  • 2.4 Manage the data lifecycle
  • 2.5 Ensure appropriate retention
  • 2.6 Determine data controls and compliance
Open domain lesson →
D3 · 13%

Security Architecture and Engineering

Apply secure design, models, system controls, platform capabilities, vulnerability analysis, cryptography, physical security, and lifecycle engineering.

  • 3.1 Secure design principles
  • 3.2 Security models
  • 3.3 Control selection
  • 3.4 Information-system capabilities
  • 3.5 Architecture vulnerabilities
  • 3.6 Cryptographic solutions
  • 3.7 Cryptanalytic attacks
  • 3.8 Site and facility design
  • 3.9 Physical controls
  • 3.10 System lifecycle
Open domain lesson →
D4 · 13%

Communication and Network Security

Design secure network architectures, components, protocols, segmentation, wireless, remote access, third-party connectivity, and communication channels.

  • 4.1 Secure network architecture
  • 4.2 Secure network components
  • 4.3 Secure communication channels
Open domain lesson →
D5 · 13%

Identity and Access Management (IAM)

Control physical and logical access through identity proofing, authentication, federation, authorization, provisioning, review, revocation, and system integration.

  • 5.1 Physical and logical access
  • 5.2 Identification and authentication strategy
  • 5.3 Federated identity
  • 5.4 Authorization
  • 5.5 Identity lifecycle
  • 5.6 Authentication-system implementation
Open domain lesson →
D6 · 12%

Security Assessment and Testing

Design assessment and audit strategies, test controls safely, collect reliable data, analyze evidence, report risk, and manage independent assurance.

  • 6.1 Assessment, test, and audit strategy
  • 6.2 Control testing
  • 6.3 Collect security process data
  • 6.4 Analyze and report results
  • 6.5 Internal and third-party audits
Open domain lesson →
D7 · 13%

Security Operations

Operate investigations, monitoring, configuration, change, incidents, vulnerability management, recovery, continuity, physical security, and personnel safety.

  • 7.1 Investigations
  • 7.2 Logging and monitoring
  • 7.3 Configuration management
  • 7.4 Security operations concepts
  • 7.5 Resource protection
  • 7.6 Incident management
  • 7.7 Detective and preventive measures
  • 7.8 Patch and vulnerability management
  • 7.9 Change management
  • 7.10 Recovery strategies
  • 7.11 Disaster recovery processes
  • 7.12 Disaster recovery testing
  • 7.13 Business continuity planning and exercises
  • 7.14 Physical security
  • 7.15 Personnel safety
Open domain lesson →
D8 · 10%

Software Development Security

Integrate security into development methods, environments, testing, acquired software, coding, deployment, operation, and software supply-chain governance.

  • 8.1 Security in the SDLC
  • 8.2 Development-ecosystem controls
  • 8.3 Software security effectiveness
  • 8.4 Acquired software
  • 8.5 Secure coding
Open domain lesson →

Learn, apply, assess

Diagnose

Route preparation depth

32 objective-linked items route the 7-, 14-, or 30-day path.

Open diagnostic →
Schedule

Every day is actionable

Lesson, decision matrix, application, recall, check, and remediation are specified for each day.

Choose a study plan →
Apply

10 labs or scenarios

Each includes prerequisites, cost, procedure, validation, cleanup, objectives, and publication status.

Review applications →
Recall

124 source-linked cards

Keyboard-operable recall with private mastery tracking.

Study flashcards →
Compare

8 decision matrices

Practice choosing controls and patterns from requirements, failure modes, and evidence.

Open cheat sheet →
Assess

Two fresh mixed sets

Internal raw-score practice with domain floors and readiness hard gates; never provider score equivalence.

Open practice center →

Version and scope notes

  • The current outline took effect April 15, 2024.
  • Domain 1 is weighted 16% and Domain 8 is weighted 10%.
  • ISC2 uses CAT for the listed languages; Baitaphish practice is explicitly fixed-length and non-adaptive.
  • The provider's live page and linked PDF disagree on the lower item-count bound.
Private by design

Progress on this device

0/59lessons
0/10applications
0/124flashcards
0assessment attempts

Scores, confidence, answers, and weak objectives remain in browser storage and are not sent to Baitaphish.

Trust and provenance

Editorial record

AI-assistance disclosure

AI assisted with curriculum drafting and implementation. Provider facts were rechecked against first-party sources. Questions and application procedures remain separately gated until named technical review and execution validation.

This record says human review did not occur.

Sources