Security Notes
Study tracks

CISSP Track

The CISSP (Certified Information Systems Security Professional, from ISC2) tests breadth and judgement across eight domains. The exam rewards thinking like a risk-aware manager: when two answers are technically right, the expected one usually protects people first, then follows policy and then reduces business risk. The weights below are from the outline in effect since 15 April 2024; check ISC2's current outline before booking.

4 min read 8 sections verified 2026-10

Last verified2026-10

DomainWeight
1. Security and Risk Management16%
2. Asset Security10%
3. Security Architecture and Engineering13%
4. Communication and Network Security13%
5. Identity and Access Management13%
6. Security Assessment and Testing12%
7. Security Operations13%
8. Software Development Security10%
Tip

The managerial domains (1, 2, 3 and 6) reward a different mindset from the technical ones: when in doubt, choose the answer that protects people, follows policy and is decided by the accountable owner.

Domain 1 — Security and Risk Management (16%)

Domain 2 — Asset Security (10%)

Domain 3 — Security Architecture and Engineering (13%)

Domain 4 — Communication and Network Security (13%)

Domain 5 — Identity and Access Management (13%)

Domain 6 — Security Assessment and Testing (12%)

Domain 7 — Security Operations (13%)

Domain 8 — Software Development Security (10%)