← All Certifications
ISC2

ISC2 CISSP Certification

CISSP 2026 · 8 domains

Last updated: March 31, 2026

Exam Syllabus & Domains

The ISC2 CISSP certification exam covers the following domains. Focus your training time proportionally to each domain's weight.

Domain 1 16%

Security and Risk Management

  • 1.1 Understand and apply security governance principles
  • 1.2 Determine compliance and regulatory requirements
  • 1.3 Understand legal and regulatory issues in information security
  • 1.4 Understand professional ethics and organizational security policies
CIA TriadRisk AssessmentBCP/DRPCompliance FrameworksSecurity GovernanceEthicsLegal/RegulatoryPersonnel Security
Domain 2 10%

Asset Security

  • 2.1 Identify and classify information and assets
  • 2.2 Establish information and asset handling requirements
  • 2.3 Provision resources securely
  • 2.4 Manage data lifecycle and data security controls
Data ClassificationData OwnershipPrivacy ProtectionData RetentionAsset HandlingData RemanenceDLPLabeling Standards
Domain 3 13%

Security Architecture and Engineering

  • 3.1 Research and implement security design principles
  • 3.2 Understand security models and system architecture concepts
  • 3.3 Select controls based on systems security requirements
  • 3.4 Understand cryptographic concepts and apply them appropriately
Security Models (Bell-LaPadula, Biba)Defense in DepthZero TrustSecure Design PrinciplesCryptographyCloud SecurityIoT SecurityVirtualization
Domain 4 13%

Communication and Network Security

  • 4.1 Implement secure design principles in network architectures
  • 4.2 Secure network components and communication channels
  • 4.3 Design and implement network security controls
  • 4.4 Prevent or mitigate network attacks
OSI ModelTCP/IPNetwork SegmentationVPNFirewallsIDS/IPSWireless SecurityCDN
Domain 5 13%

Identity and Access Management (IAM)

  • 5.1 Control physical and logical access to assets
  • 5.2 Manage identification and authentication of people and devices
  • 5.3 Implement and manage authorization mechanisms
  • 5.4 Manage the identity and access provisioning lifecycle
Access Control Models (MAC, DAC, RBAC)Authentication FactorsSSOFederationIdentity LifecycleProvisioningMFABiometrics
Domain 6 12%

Security Assessment and Testing

  • 6.1 Design and validate assessment, test, and audit strategies
  • 6.2 Conduct security control testing
  • 6.3 Collect security process data and analyze test outputs
  • 6.4 Conduct or facilitate security audits
Vulnerability AssessmentPenetration TestingLog AnalysisSIEMSOC OperationsCode ReviewCompliance AuditingKPIs/KRIs
Domain 7 13%

Security Operations

  • 7.1 Understand and support investigations and forensics
  • 7.2 Conduct logging and monitoring activities
  • 7.3 Perform configuration and change management
  • 7.4 Implement and support patch and vulnerability management
Incident ResponseDigital ForensicsDisaster RecoveryBusiness ContinuityChange ManagementPatch ManagementPhysical SecurityResource Protection
Domain 8 10%

Software Development Security

  • 8.1 Understand security in the software development lifecycle
  • 8.2 Identify and apply security controls in development environments
  • 8.3 Assess the effectiveness of software security
  • 8.4 Assess software acquisition security impact
SDLCOWASP Top 10Code ReviewDevSecOpsDatabase SecurityAPI SecurityMalware AnalysisSoftware Assurance

Where to Focus Your Study Time

Domains with higher weight have more exam questions — allocate your study hours accordingly.

D1 Security and Risk Management
16%
D2 Asset Security
10%
D3 Security Architecture and Engineering
13%
D4 Communication and Network Security
13%
D5 Identity and Access Management (IAM)
13%
D6 Security Assessment and Testing
12%
D7 Security Operations
13%
D8 Software Development Security
10%

Study Tips

Free Study Resources

๐Ÿ“‹

Study Roadmap

Week-by-week study plan with free resources

โœ…

Study Tracker

Track objective completion with progress dashboard

๐Ÿ’ฐ

Cost Calculator

Total cost breakdown and ROI analysis

๐Ÿงช

Practice Quiz

Test your knowledge with free practice questions

Practice Quiz

Test your knowledge before the exam with our free practice quiz.

Take the ISC2 CISSP Practice Quiz

Related Comparisons

Not sure if ISC2 CISSP is the right choice? Compare it with similar certifications:

CISSP vs CISM CISSP vs Security+ CASP+ vs CISSP SSCP vs CISSP CCSP vs CISSP

Get the ISC2 CISSP Study Planner

Fillable PDF with 16-week schedule, domain trackers, flashcard templates, progress tracking, and quick reference sheets. Available in Standard, ADHD-Friendly, Dark Mode, and 4-Format Bundle.

Get the Study Planner — $5.99

Also available as a 4-Format Bundle for $15.99

CyberFolio

Earned your certs? Show employers.

Build a shareable cybersecurity portfolio that highlights your certifications, projects, and skills — free.

Build Your Portfolio →

Free Training Resources

Use these free tools to support your ISC2 CISSP certification training:

Frequently Asked Questions

What is the ISC2 CISSP certification?

The ISC2 CISSP (CISSP 2026) is a professional IT certification that validates your knowledge and skills in the exam domains covered. It is recognized globally by employers and is a valuable credential for career advancement in cybersecurity and IT.

What does the ISC2 CISSP certification syllabus cover?

The ISC2 CISSP exam syllabus covers 8 domains. Each domain is weighted differently, so focus your training on higher-weighted domains first. Review the complete domain breakdown above for objectives and key concepts.

How should I study for ISC2 CISSP?

Create a structured study plan covering all exam domains, use practice tests to identify weak areas, and review key concepts regularly. A fillable study planner can help you organize your training with weekly schedules and progress tracking.

How long does it take to prepare for ISC2 CISSP?

Preparation time varies by experience level. Most candidates spend 8-12 weeks of dedicated training. Using a structured study planner with domain-by-domain breakdown helps ensure you cover all certification objectives efficiently.