Study tracks
CISSP Track
The CISSP (Certified Information Systems Security Professional, from ISC2) tests breadth and judgement across eight domains. The exam rewards thinking like a risk-aware manager: when two answers are technically right, the expected one usually protects people first, then follows policy and then reduces business risk. The weights below are from the outline in effect since 15 April 2024; check ISC2's current outline before booking.
4 min read
8 sections
verified 2026-10
Last verified2026-10
| Domain | Weight |
|---|---|
| 1. Security and Risk Management | 16% |
| 2. Asset Security | 10% |
| 3. Security Architecture and Engineering | 13% |
| 4. Communication and Network Security | 13% |
| 5. Identity and Access Management | 13% |
| 6. Security Assessment and Testing | 12% |
| 7. Security Operations | 13% |
| 8. Software Development Security | 10% |
TipThe managerial domains (1, 2, 3 and 6) reward a different mindset from the technical ones: when in doubt, choose the answer that protects people, follows policy and is decided by the accountable owner.
Domain 1 — Security and Risk Management (16%)
- Compliance frameworks — NIST CSF, ISO 27001, SOC 2 and how they relate
- GDPR, HIPAA and PCI-DSS — legal and regulatory drivers
- Threat modelling — STRIDE and attack trees
- Concepts over tools — reasoning from principles, which is how the exam is written
- Ethics, accountability and the document stack — ISC2 canons, due care vs due diligence, policy → guideline, roles
- Risk management — SLE, ALE, risk responses, supply-chain risk, awareness
- Business impact analysis and recovery objectives — RTO, RPO, MTD
Domain 2 — Asset Security (10%)
- GDPR principles and data-subject rights — why data must be classified and minimised
- KMS and S3 security — protecting data at rest in practice
- Asset security — classification, data states, lifecycle
- Sanitisation, scoping, tailoring and DLP
Domain 3 — Security Architecture and Engineering (13%)
- Cryptography — symmetric, asymmetric, hashing, signatures, PKI, the quantum question
- TLS end to end — certificates, chains, revocation
- Linux security fundamentals — Secure Boot, TPM, mandatory access control
- Memory corruption — and the mitigations architecture adds against it
- System design foundations — designing systems that stay secure at scale
- Formal security models and Common Criteria
- Secure design principles
- Physical and facility security and embedded, IoT and industrial systems
Domain 4 — Communication and Network Security (13%)
- TCP/IP deep dive — the OSI and TCP/IP models, transport, routing
- DNS deep dive — DNSSEC, DoH/DoT, tunnelling
- HTTP/HTTPS deep dive
- What happens when you type a URL — every layer in one flow
- VPC security — segmentation and filtering in the cloud
- Wireless security and IPsec and VPNs
- NAC and segmentation and converged protocols
Domain 5 — Identity and Access Management (13%)
- Authentication deep dive — passwords, OAuth, OIDC, SAML, Kerberos, MFA, sessions
- AWS IAM deep dive — least privilege and role-based access in practice
- Active Directory — the enterprise directory and its attack paths
- Identity threat detection
- Access control models and the identity lifecycle — DAC/MAC/RBAC/ABAC, joiner–mover–leaver, FAR/FRR/CER
Domain 6 — Security Assessment and Testing (12%)
- Detection engineering — testing whether controls actually fire
- SAST, DAST and SCA
- SOC 2 Type I versus Type II — what an audit actually attests
- Security assessment and testing — pen-test types, audits, fuzzing, synthetic transactions, KPIs and KRIs
Domain 7 — Security Operations (13%)
- IR psychology and NIST SP 800-61 — the incident lifecycle
- Digital forensics — evidence collection and chain of custody
- Detection engineering, the SIEM pipeline and threat hunting
- Phishing triage and reports and postmortems
- Change, configuration and patch management
- Backup strategies and recovery sites
- Testing the DR plan — read-through to full interruption
- Investigations and evidence — investigation types, admissibility, personnel safety
Domain 8 — Software Development Security (10%)
- AppSec deep dive — OWASP Top 10 and secure coding failures
- OWASP Top 10 CI/CD risks and GitHub security
- Dependency management — the software supply chain
- OWASP LLM Top 10 — AI features as a new class of software risk
- Secure software development — SDLC and maturity models, acquired software, database security