Experience requirement
Five years of cumulative full-time experience in two or more domains; an eligible degree or credential can waive no more than one year. Part-time work and internships may count.
A management-perspective CISSP system covering all eight domains and 62 objectives through source-linked lessons, decision matrices, scenarios, recall, and fixed-length non-adaptive practice.
Formats: multiple-choice.
Delivery: ISC2 Authorized PPC or Pearson VUE Test Center Select.
The live ISC2 certification page states 100–150 items; the linked April 2024 outline PDF states 125–150. Baitaphish fixed-length practice is not CAT and cannot estimate an ISC2 scaled result.
Five years of cumulative full-time experience in two or more domains; an eligible degree or credential can waive no more than one year. Part-time work and internships may count.
A candidate who passes without the required experience may become an Associate of ISC2 and has six years to earn the required experience.
Make ethical, governance, legal, business-continuity, personnel, risk, threat-model, supply-chain, and awareness decisions from an organizational perspective.
Assign ownership, classify assets and information, define handling, provision securely, manage lifecycle and retention, and select data controls.
Apply secure design, models, system controls, platform capabilities, vulnerability analysis, cryptography, physical security, and lifecycle engineering.
Design secure network architectures, components, protocols, segmentation, wireless, remote access, third-party connectivity, and communication channels.
Control physical and logical access through identity proofing, authentication, federation, authorization, provisioning, review, revocation, and system integration.
Design assessment and audit strategies, test controls safely, collect reliable data, analyze evidence, report risk, and manage independent assurance.
Operate investigations, monitoring, configuration, change, incidents, vulnerability management, recovery, continuity, physical security, and personnel safety.
Integrate security into development methods, environments, testing, acquired software, coding, deployment, operation, and software supply-chain governance.
32 objective-linked items route the 7-, 14-, or 30-day path.
Open diagnostic →Lesson, decision matrix, application, recall, check, and remediation are specified for each day.
Choose a study plan →Each includes prerequisites, cost, procedure, validation, cleanup, objectives, and publication status.
Review applications →Keyboard-operable recall with private mastery tracking.
Study flashcards →Practice choosing controls and patterns from requirements, failure modes, and evidence.
Open cheat sheet →Internal raw-score practice with domain floors and readiness hard gates; never provider score equivalence.
Open practice center →Scores, confidence, answers, and weak objectives remain in browser storage and are not sent to Baitaphish.
AI assisted with curriculum drafting and implementation. Provider facts were rechecked against first-party sources. Questions and application procedures remain separately gated until named technical review and execution validation.
This record says human review did not occur.
Current effective date, live exam overview, and domain names.
Exam format, domain weights, objectives, and experience requirements; states 125–150 items.
Current certification and experience overview; live page states 100–150 items.