1. 16% OF THE EXAM

    CISSP Domain 1: Security and Risk Management

    CISSP Domain 1 explained: risk analysis, governance, compliance, business continuity and security policy, with the guides and glossary terms for each.

    7 ARTICLES · 21 TERMS

  2. 10% OF THE EXAM

    CISSP Domain 2: Asset Security

    CISSP Domain 2 explained: data classification, owner and custodian roles, data states, retention, end of life and sanitisation, with guides and glossary terms.

    2 ARTICLES · 7 TERMS

  3. 13% OF THE EXAM

    CISSP Domain 3: Security Architecture and Engineering

    CISSP Domain 3 explained: Bell-LaPadula, Biba, Clark-Wilson and the other models, the trusted computing base, cryptography and secure design, with guides.

    7 ARTICLES · 27 TERMS

  4. 13% OF THE EXAM

    CISSP Domain 4: Communication and Network Security

    CISSP Domain 4 explained: the OSI model, IPsec and TLS, email authentication with SPF, DKIM and DMARC, and network segmentation, with guides and glossary terms.

    3 ARTICLES · 14 TERMS

  5. 13% OF THE EXAM

    CISSP Domain 5: Identity and Access Management

    CISSP Domain 5 explained: authentication, SSO, the access control models, least privilege and need to know, and the Kerberos attack chain, with guides.

    5 ARTICLES · 25 TERMS

  6. 12% OF THE EXAM

    CISSP Domain 6: Security Assessment and Testing

    CISSP Domain 6 explained: assessment, test and audit strategies, vulnerability and penetration testing, SOC reports and control assessment, with guides.

    2 ARTICLES · 7 TERMS

  7. 13% OF THE EXAM

    CISSP Domain 7: Security Operations

    CISSP Domain 7 explained: incident response, logging, chain of custody, change management, RTO, RPO, WRT and MTD, and recovery sites, with guides and terms.

    4 ARTICLES · 17 TERMS

  8. 10% OF THE EXAM

    CISSP Domain 8: Software Development Security

    CISSP Domain 8 explained: the secure development lifecycle, DevSecOps, race conditions such as TOCTOU, and SAST, DAST and SCA testing, with guides and terms.

    2 ARTICLES · 5 TERMS

Weightings are those published in the ISC2 CISSP exam outline effective April 2024. A domain's weighting says how much of the exam it may occupy, not how hard it is, and candidates tend to find the smaller domains are where confusable pairs live.