CISSP Study Guide System
A searchable, domain-organized reference for reviewing CISSP concepts, decision rules, exam traps, recall prompts, and visual models.
| Coverage | Organization | Alignment |
|---|---|---|
| Eight CISSP domains | Deduplicated and organized by official domain | CISSP exam outline effective April 15, 2024 |
Current exam map
The domain weights below follow the official CISSP exam outline. Use the official outline as the scope authority and these notes as an independent explanation layer.
| Domain | Weight | Guide |
|---|---|---|
| 1. Security and Risk Management | 16% | Domain 1 notes |
| 2. Asset Security | 10% | Domain 2 notes |
| 3. Security Architecture and Engineering | 13% | Domain 3 notes |
| 4. Communication and Network Security | 13% | Domain 4 notes |
| 5. Identity and Access Management (IAM) | 13% | Domain 5 notes |
| 6. Security Assessment and Testing | 12% | Domain 6 notes |
| 7. Security Operations | 13% | Domain 7 notes |
| 8. Software Development Security | 10% | Domain 8 notes |
Exam format
| Item | Current detail |
|---|---|
| Delivery | Computerized Adaptive Testing (CAT), English exam |
| Length | Up to 3 hours |
| Items | 100–150 multiple-choice and advanced innovative items |
| Passing score | 700 out of 1,000 points |
Verify future changes at: ISC2 CISSP Exam Outline
How the eight domains connect
| Decision flow | Lead domain | Downstream use |
|---|---|---|
| Govern and prioritize risk | D1 | Sets objectives, policy, risk tolerance, legal, and supplier requirements |
| Understand and protect information | D2 | Defines classification, handling, retention, and disposal |
| Engineer trustworthy systems | D3 | Turns requirements into architecture, cryptography, and physical/platform controls |
| Protect communications | D4 | Connects systems through segmented, resilient, and encrypted paths |
| Control subjects and privileges | D5 | Identifies subjects, authenticates them, and enforces least privilege |
| Generate assurance evidence | D6 | Tests whether controls are designed and operating effectively |
| Operate and recover | D7 | Monitors, responds, preserves evidence, and restores business capability |
| Build secure software | D8 | Integrates security through code, dependencies, pipelines, and operation |
Cross-domain facts worth mastering early
| Fact | Primary domain |
|---|---|
| The risk owner accepts residual risk; security advises and provides evidence. | D1 |
| The owner classifies and approves; the custodian implements controls. | D2 |
| Bell–LaPadula protects confidentiality; Biba protects integrity. | D3 |
| ARP resolves IPv4 addresses to MAC addresses and is normally classified at Layer 2 for CISSP. | D4 |
| OAuth is authorization; OpenID Connect adds authentication. | D5 |
| Assessment identifies potential weaknesses; penetration testing demonstrates exploitability. | D6 |
| RTO is downtime; RPO is the data-loss point; RAID is not backup. | D7 |
| SAST is static, DAST is runtime, IAST is instrumented runtime, and SCA evaluates components. | D6 + D8 |
Editorial notes
- Repetition and class logistics were removed.
- Concepts are organized by their official CISSP domain rather than the order in which they were taught.
- Shorthand that could lead to an incorrect exam answer was corrected.
- Volatile trivia is minimized in favor of durable decision rules and concepts.
- This is an independent study aid, not official ISC2 material.