Study tracks
CCSP Track
The CCSP (Certified Cloud Security Professional, from ISC2) is the vendor-neutral cloud sibling of the CISSP. It tests cloud concepts, data protection, platform and application security, operations, and the legal and contractual side of using someone else's infrastructure. This track follows the exam outline in effect from 1 August 2026, which added AI and machine-learning subdomains (1.6 and 2.9). Weights below are from ISC2's announcement of that outline.
3 min read
6 sections
verified 2026-10
Last verified2026-10
| Domain | Weight |
|---|---|
| 1. Cloud Concepts, Architecture and Design | 17% |
| 2. Cloud Data Security | 20% |
| 3. Cloud Platform and Infrastructure Security | 17% |
| 4. Cloud Application Security | 16% |
| 5. Cloud Security Operations | 17% |
| 6. Legal, Risk and Compliance | 13% |
TipCCSP questions are vendor-neutral: answer with concepts (customer-managed keys, CASB, crypto-shredding), not product names. The AWS links below are concrete examples, not exam vocabulary.
Domain 1 — Cloud Concepts, Architecture and Design (17%)
- 1.1–1.2 Cloud concepts and reference architecture — NIST characteristics, service and deployment models, roles
- 1.3 Shared responsibility — who owns what in IaaS, PaaS and SaaS
- 1.3 Cryptography and IAM — the security concepts the cloud relies on
- 1.4 Secure cloud design principles — lifecycle, design for failure, identity as perimeter
- 1.4 Business continuity and DR — RTO, RPO, recovery strategies
- 1.5 Evaluating cloud providers — ISO 27017/27018, CSA STAR, SOC 2, FedRAMP
- 1.6 AI and ML in the cloud and the OWASP LLM Top 10
Domain 2 — Cloud Data Security (20%)
- 2.1 Data concepts and the cloud data lifecycle — lifecycle phases, data dispersion, data flows
- 2.2 Storage architectures and their threats
- 2.3 Data security technologies — encryption and key custody, masking, tokenisation, anonymisation, DLP
- 2.3 Key custody in practice (AWS example) — BYOK, HYOK, HSMs
- 2.4–2.5 Data discovery and classification
- 2.6 Information rights management
- 2.7 Retention, deletion, archiving and legal hold — crypto-shredding
- 2.8 Auditability, traceability and accountability
- 2.9 Protecting AI and ML data
Domain 3 — Cloud Platform and Infrastructure Security (17%)
- 3.1 Cloud infrastructure components — hypervisor types, management plane
- 3.2 Secure data-centre design and physical security
- 3.3 Risks specific to cloud infrastructure — VM escape, side channels, management plane
- 3.4 Network, edge and compute controls (AWS example)
- 3.4 Logging and monitoring architecture (AWS example)
- 3.5 Backups, recovery sites and DR testing
Domain 4 — Cloud Application Security (16%)
- 4.1 AppSec deep dive — the common vulnerabilities training should cover
- 4.2–4.3 Secure software development — SDLC models, maturity models
- 4.3 Threat modelling — STRIDE and friends
- 4.4 SAST, DAST and SCA — assurance and validation in the pipeline
- 4.5 Dependency management and OWASP CI/CD Top 10 — verified, trusted software
- 4.6 Cloud application architecture — WAF, DAM, API gateways, CASB, sandboxing
- 4.6 Kubernetes security — orchestration and containers
- 4.7 Authentication deep dive — federation, SSO, OIDC, SAML, MFA
Domain 5 — Cloud Security Operations (17%)
- 5.1–5.2 Building and operating cloud infrastructure — hardening, admin access, clustering, patching
- 5.3 Operational processes (ITIL / ISO 20000-1) and change and patch management
- 5.4 Digital forensics in the cloud and digital forensics
- 5.5 Communication with relevant parties
- 5.6 Security operations, the SIEM pipeline and AWS IR playbooks
Domain 6 — Legal, Risk and Compliance (13%)
- 6.1 Legal requirements and jurisdiction — CLOUD Act, data transfers, eDiscovery
- 6.2 Privacy and GDPR
- 6.3 Audit in the cloud — SOC 1/2/3, scope, gap analysis
- 6.4 Enterprise risk management for cloud and risk management
- 6.5 Outsourcing and cloud contract design — MSA, SOW, SLA, exit
- 6.x NIS2 — EU obligations for cloud and managed service providers