The Certified Information Systems Security Professional (CISSP) remains ISC2’s broad professional certification for experienced security practitioners, managers, architects and leaders. The current exam outline has been effective since April 15, 2024 and remains the published CISSP blueprint as of October 2026.
The current CISSP exam uses Computerized Adaptive Testing for all languages, runs for up to three hours, contains 100–150 multiple-choice and advanced item types, and requires 700 out of 1000 points to pass.
Domain 1: Security and Risk Management is 16%
The largest domain covers ethics, CIA/authenticity/nonrepudiation, governance, laws/regulations/privacy, investigation requirements, policies/standards/procedures, business continuity, personnel security, risk management, threat modeling, supply-chain risk and security awareness.
The CISSP perspective is managerial as well as technical: security decisions should align with business objectives and risk tolerance.
Domain 2: Asset Security is 10%
This domain covers information and asset classification, ownership, handling requirements, retention, data security controls and secure lifecycle/disposal considerations.
An Asset Security focus is useful because many controls depend on first knowing what data exists, who owns it and how sensitive it is.
Domain 3: Security Architecture and Engineering is 13%
This area includes secure design principles, security models, control selection, hardware/platform security, cryptography, physical security and vulnerabilities across cloud, distributed, virtualized, IoT, container, serverless, edge and other systems.
Candidates need conceptual depth across architectures rather than product-specific configuration.
Domain 4: Communication and Network Security is 13%
The domain covers secure network architecture, protocols, transmission methods, network components and secure communication channels.
The CISSP should understand segmentation, secure design and protocol risks well enough to choose controls and assess architecture.
Domain 5: Identity and Access Management is 13%
IAM covers physical/logical asset access, identity management, authentication, authorization, identity federation, credential lifecycle and access-control models.
A CISSP IAM model should connect least privilege, separation of duties, lifecycle governance and modern identity patterns.
Domain 6: Security Assessment and Testing is 12%
This domain covers assessment strategies, security testing, process data collection, test outputs and internal/external audits.
A Security Assessment and Testing approach should distinguish vulnerability assessment, penetration testing, control testing, audit and continuous monitoring.
Domain 7: Security Operations is 13%
Security Operations includes investigations, logging/monitoring, provisioning, configuration management, vulnerability/patch management, change management, incident response, business continuity/disaster recovery, physical security and operational resilience.
This domain connects policy and architecture to what security teams actually operate every day.
Domain 8: Software Development Security is 10%
The final domain covers software-development lifecycle security, development ecosystems, application controls, secure coding and software-security assessment.
CISSP candidates are not required to be professional developers, but they should understand how security is built into requirements, design, coding, testing, release and maintenance.
Experience requirements remain part of earning the credential
ISC2 requires five years of cumulative full-time experience in at least two of the eight CISSP domains. An approved degree or credential can waive up to one year; ISC2 updated the qualifying waiver list in April 2026.
Candidates who pass the exam without the required experience can follow the Associate of ISC2 pathway while they build the required experience.
CISSP is a security-leadership knowledge framework
The current exam outline also makes clear that CISSP is not a product certification. Technologies such as cloud, containers, serverless, AI, IoT, industrial control systems, cryptography, and identity services appear as security contexts. The exam is interested in selecting and governing controls, not remembering vendor command syntax.
Professional ethics sits at the beginning of Domain 1 for a reason. ISC2 expects security professionals to protect society, the common good, necessary public trust, and the infrastructure while acting honorably, honestly, justly, responsibly, and legally. Scenario questions can reward the answer that preserves professional duty over organizational convenience.
Governance includes aligning security with organizational mission, strategy, committees, roles, frameworks and due care/due diligence. The CISSP should recognize that security exists to support the business while reducing unacceptable risk; it is not an independent technical objective detached from enterprise priorities.
Legal and privacy content spans cybercrime, licensing and intellectual property, import/export, transborder data flows, privacy laws and contractual requirements. Candidates are not expected to be attorneys, but they should know when legal counsel, regulators, law enforcement or privacy specialists must be involved.
Business continuity begins with business impact analysis and external dependencies. Security professionals should understand maximum tolerable disruption, recovery priorities, dependencies and continuity strategies before selecting technical recovery controls. A backup system is not automatically a complete business-continuity program.
Supply-chain risk is now a visible part of Domain 1. Counterfeit components, tampering, malicious dependencies, supplier concentration, minimum security requirements, monitoring, service levels, silicon roots of trust and software bills of materials can all affect enterprise risk before a product is deployed internally.
Asset Security should be read as a lifecycle. Data and devices are created or acquired, classified, handled, stored, transmitted, retained and eventually destroyed. Ownership and privacy requirements follow the asset across that lifecycle; they do not begin only when encryption is configured.
Domain 3 security architecture covers classic security models such as Bell-LaPadula and Biba as conceptual tools for confidentiality or integrity, plus modern systems such as cloud, microservices, containers, serverless, edge, IoT and industrial environments. Candidates should recognize the security property a model or architecture emphasizes.
Cryptography inside Domain 3 should be understood through purpose: confidentiality, integrity, authenticity, nonrepudiation, key management and trust. The exam can ask about symmetric versus asymmetric uses, hashing, PKI, digital signatures, certificates, algorithms, lifecycle and implementation risk without requiring cryptographic programming.
Physical security remains part of CISSP because information systems depend on facilities, power, environmental controls, personnel access and hardware protection. A secure network cannot compensate for unrestricted access to server rooms or inadequate fire/flood/power resilience.
Communication and Network Security should be studied from architecture inward: network design, segmentation, secure communication, protocols, wireless, remote access and network-device security. The professional answer often reduces trust boundaries and attack surface rather than simply adding one more monitoring product.
IAM is broader than passwords. Identity proofing, account lifecycle, federation, single sign-on, MFA, authorization models, privilege management, service accounts and physical access all contribute. Access should be granted according to business need and removed promptly when the need changes.
Security Assessment and Testing is about evidence and assurance. A vulnerability scan identifies known weaknesses; a penetration test attempts exploitation within rules of engagement; audit evaluates controls/process against criteria; code review and synthetic transactions test other aspects. No single assessment proves “the system is secure.”
Security Operations includes change and configuration management because operational security can be weakened by normal administrative activity. Baselines, patches, vulnerability remediation, log monitoring and incident procedures need controlled change so organizations can distinguish authorized evolution from compromise.
Incident response should be connected with investigations and evidence. Administrative, civil, criminal or regulatory investigations can impose different standards and stakeholders. Chain of custody, integrity, legal hold and appropriate escalation can matter when operational events become formal investigations.
Disaster recovery and business continuity are related but not identical. DR focuses on restoring technology and data; business continuity covers sustaining critical business functions through disruption. CISSP questions often reward the broader business view when the scenario asks what should happen first.
Software Development Security is not only secure coding. It includes integrating security into lifecycle models, requirements, design, development ecosystems, testing, third-party components and change. The CISSP perspective asks how governance and risk controls prevent software weaknesses from entering production repeatedly.
The current CISSP exam uses adaptive testing, meaning the number of items can vary between 100 and 150. Candidates should not attempt to infer performance from question difficulty or exam length. Each item should be answered based on professional judgment, and once an item is submitted in CAT it generally cannot be revisited.
The experience requirement reinforces the nature of the credential. Five years across at least two domains is intended to ensure that successful candidates have seen how security decisions affect organizations in practice. The exam can be passed without all required experience, but the full CISSP designation requires the experience and endorsement process.
For current-scope control, use the official April 15, 2024 exam outline rather than older weightings. The current distribution is 16/10/13/13/13/12/13/10, and Domain 8 was reduced to 10% in the 2024 refresh while Domain 1 increased to 16%.
Security awareness, education, and training closes Domain 1 because people are part of the control environment. Programs should address relevant threats such as phishing and social engineering, include emerging technologies such as AI where appropriate, and measure effectiveness rather than equating completion rates with reduced risk.
The current outline also emphasizes shared responsibility and zero-trust ideas across modern environments. These concepts appear in several domains because security architecture, asset handling, identity, operations, and cloud service models all depend on clearly defined responsibility and continuously validated access.
CISSP candidates should also recognize that domain percentages are average weights, not guarantees that questions will appear in isolated blocks. Adaptive items can combine governance, architecture, IAM, testing, and operations in one scenario. The best preparation therefore connects domains instead of trying to predict a fixed chapter-by-chapter exam order.
For final current-scope review, compare your study source against the official ISC2 outline headings and effective date. If a resource still uses older domain weights or older linear-exam logistics, keep the timeless security concepts but update the exam-specific facts before relying on it for pacing or prioritization.
Within the broader ISC2 certification portfolio, CISSP validates broad technical and managerial competence. The strongest preparation connects governance, assets, architecture, networks, identity, testing, operations and secure development into risk-based decisions rather than eight isolated textbooks.