Release 1.1

CISSP Study Guide System

A searchable, domain-organized reference for reviewing CISSP concepts, decision rules, exam traps, recall prompts, and visual models.

CoverageOrganizationAlignment
Eight CISSP domainsDeduplicated and organized by official domainCISSP exam outline effective April 15, 2024

Current exam map

The domain weights below follow the official CISSP exam outline. Use the official outline as the scope authority and these notes as an independent explanation layer.

DomainWeightGuide
1. Security and Risk Management16%Domain 1 notes
2. Asset Security10%Domain 2 notes
3. Security Architecture and Engineering13%Domain 3 notes
4. Communication and Network Security13%Domain 4 notes
5. Identity and Access Management (IAM)13%Domain 5 notes
6. Security Assessment and Testing12%Domain 6 notes
7. Security Operations13%Domain 7 notes
8. Software Development Security10%Domain 8 notes

Exam format

ItemCurrent detail
DeliveryComputerized Adaptive Testing (CAT), English exam
LengthUp to 3 hours
Items100–150 multiple-choice and advanced innovative items
Passing score700 out of 1,000 points

Verify future changes at: ISC2 CISSP Exam Outline

How the eight domains connect

Decision flowLead domainDownstream use
Govern and prioritize riskD1Sets objectives, policy, risk tolerance, legal, and supplier requirements
Understand and protect informationD2Defines classification, handling, retention, and disposal
Engineer trustworthy systemsD3Turns requirements into architecture, cryptography, and physical/platform controls
Protect communicationsD4Connects systems through segmented, resilient, and encrypted paths
Control subjects and privilegesD5Identifies subjects, authenticates them, and enforces least privilege
Generate assurance evidenceD6Tests whether controls are designed and operating effectively
Operate and recoverD7Monitors, responds, preserves evidence, and restores business capability
Build secure softwareD8Integrates security through code, dependencies, pipelines, and operation

Cross-domain facts worth mastering early

FactPrimary domain
The risk owner accepts residual risk; security advises and provides evidence.D1
The owner classifies and approves; the custodian implements controls.D2
Bell–LaPadula protects confidentiality; Biba protects integrity.D3
ARP resolves IPv4 addresses to MAC addresses and is normally classified at Layer 2 for CISSP.D4
OAuth is authorization; OpenID Connect adds authentication.D5
Assessment identifies potential weaknesses; penetration testing demonstrates exploitability.D6
RTO is downtime; RPO is the data-loss point; RAID is not backup.D7
SAST is static, DAST is runtime, IAST is instrumented runtime, and SCA evaluates components.D6 + D8

Editorial notes

  • Repetition and class logistics were removed.
  • Concepts are organized by their official CISSP domain rather than the order in which they were taught.
  • Shorthand that could lead to an incorrect exam answer was corrected.
  • Volatile trivia is minimized in favor of durable decision rules and concepts.
  • This is an independent study aid, not official ISC2 material.