What is the CISSP exam?
CISSP is the most widely held advanced security certification and is often a listed requirement for security architect, security manager and CISO roles. It is awarded by ISC2 and accredited under ISO/IEC 17024, and it is approved by the US Department of Defense for several information-assurance job categories.
The exam covers eight domains, from security governance and risk management through asset security, architecture and engineering, networks, identity and access management, assessment and testing, operations, and software development security. It is deliberately broad and managerial in tone: the classic advice is to answer as a risk-focused security leader would, not as an engineer.
The English-language exam uses computerised adaptive testing, so the questions you see depend on how you have answered so far. Certification requires the exam plus five years of paid work experience in at least two of the eight domains, an endorsement from an existing ISC2 member, and agreement to the ISC2 code of ethics.
Who sits it
- Experienced security engineers and analysts moving into architecture or management
- Security managers, consultants and auditors who need a recognised leadership credential
- IT professionals with five or more years of experience who want to formalise security expertise
Exam format at a glance
- Questions
- 100–150, delivered adaptively (multiple-choice plus some advanced item types)
- Duration
- 3 hours
- Delivery
- Computer-based, year-round, at Pearson VUE test centres
- Fee (USD)
- About $749
- Passing standard
- Scaled score of 700 out of 1,000
- Experience
- Five years of cumulative paid experience in two or more domains; one year can be waived for a relevant degree or approved credential
- Pass rate
- ISC2 does not publish one
- Exam outline
- Current version effective from April 2024
Exam-body facts last checked September 2026. Fees, dates and formats change; confirm the current details with ISC2 before registering.
Syllabus and topic weights
1.Security and Risk Management16% · 46 lessons · 0 questions · 199 cards16%460199
- Understand, Adhere to, and Promote Professional Ethics
- Understand and Apply Security Concepts
- Evaluate and Apply Security Governance Principles
- Legal, Regulatory, and Compliance Issues in Information Security
- Requirements for Investigation Types
- Security Policy, Standards, Procedures, and Guidelines
- Business Continuity (BC) Requirements
- Personnel Security Policies and Procedures
- Understand and Apply Risk Management Concepts
- Threat Modeling Concepts and Methodologies
- Supply Chain Risk Management (SCRM)
- Security Awareness, Education, and Training Program
2.Asset Security10% · 25 lessons · 0 questions · 98 cards10%25098
- Identify and Classify Information and Assets
- Establish Information and Asset Handling Requirements
- Provision Information and Assets Securely
- Manage Data Lifecycle
- Ensure Appropriate Asset Retention
- Data Security Controls and Compliance Requirements
3.Security Architecture and Engineering13% · 44 lessons · 0 questions · 217 cards13%440217
- Engineering Processes Using Secure Design Principles
- Fundamental Concepts of Security Models
- Select Controls Based on Systems Security Requirements
- Security Capabilities of Information Systems
- Vulnerabilities of Security Architectures, Designs, and Solution Elements
- Select and Determine Cryptographic Solutions
- Methods of Cryptanalytic Attacks
- Apply Security Principles to Site and Facility Design
- Design Site and Facility Security Controls
- Manage the Information System Lifecycle
4.Communication and Network Security13% · 23 lessons · 0 questions · 74 cards13%23074
- Secure Design Principles in Network Architectures
- Secure Network Components
- Implement Secure Communication Channels
5.Identity and Access Management (IAM)13% · 25 lessons · 0 questions · 101 cards13%250101
- Control Physical and Logical Access to Assets
- Design Identification and Authentication Strategy
- Federated Identity with a Third-Party Service
- Implement and Manage Authorization Mechanisms
- Manage the Identity and Access Provisioning Lifecycle
- Implement Authentication Systems
6.Security Assessment and Testing12% · 20 lessons · 0 questions · 80 cards12%20080
- Design and Validate Assessment, Test, and Audit Strategies
- Conduct Security Controls Testing
- Collect Security Process Data
- Analyze Test Output and Generate Report
- Conduct or Facilitate Security Audits
7.Security Operations13% · 64 lessons · 0 questions · 248 cards13%640248
- Understand and Comply with Investigations
- Conduct Logging and Monitoring Activities
- Perform Configuration Management (CM)
- Apply Foundational Security Operations Concepts
- Apply Resource Protection
- Conduct Incident Management
- Operate and Maintain Detection and Preventative Measures
- Implement and Support Patch and Vulnerability Management
- Change Management Processes
- Implement Recovery Strategies
- Implement Disaster Recovery (DR) Processes
- Test Disaster Recovery Plan (DRP)
- Participate in Business Continuity (BC) Planning and Exercises
- Implement and Manage Physical Security
- Address Personnel Safety and Security Concerns
8.Software Development Security10% · 25 lessons · 0 questions · 97 cards10%25097
- Integrate Security in the Software Development Life Cycle (SDLC)
- Security Controls in Software Development Ecosystems
- Assess the Effectiveness of Software Security
- Assess Security Impact of Acquired Software
- Secure Coding Guidelines and Standards
Lesson, question and flashcard counts are StudyOptima's published content for each topic. Expand a topic to see its subtopics.
How to prepare for CISSP
- 1
Study to the exam outline, not to your job. Most candidates are strong in two or three domains and weak in the rest; the adaptive exam will find the gaps.
- 2
Learn the management perspective. When a question offers a technical fix and a governance answer, the governance answer (assess risk, get management approval, follow policy) is usually what ISC2 wants.
- 3
Domain 1 (Security and Risk Management) is the largest and its concepts (risk analysis, legal and regulatory issues, business continuity planning) reappear inside other domains' questions.
- 4
Do not aim to know every technology in depth. Know what each control is for, where it sits in a defence-in-depth model, and its main weaknesses.
- 5
Practise reading questions for the qualifier: 'best', 'first', 'most', 'least'. The adaptive format means you cannot go back, so read each question once, carefully.
Study for CISSP on StudyOptima
272 study lessons
Condensed notes for every topic, organised by learning objective, with read-progress tracking.
1,408 practice questions
Exam-style questions with worked explanations, timed mocks, and re-drills of what you got wrong.
1,114 flashcards
Spaced-repetition review of the definitions and formulas the exam keeps coming back to.
Free lessons to start with
Read these with a free account, no card required.
- The ISC2 Code of Professional EthicsSecurity and Risk Management
- The CIA Triad and the DAD TriadSecurity and Risk Management
- Organizational Codes of EthicsSecurity and Risk Management
- Authenticity, Nonrepudiation, and the Five AAA ElementsSecurity and Risk Management
- Other Ethical Frameworks: RFC 1087, the Ten Commandments, and Fair Information PracticesSecurity and Risk Management
- Protection Mechanisms and Security BoundariesSecurity and Risk Management
Plans and pricing
Paid plans for CISSP are not on sale yet. Create a free account to read the free lessons and answer a daily allowance of practice questions, and we will let you know when full access opens.
Create a free accountCISSP FAQ
What is computerised adaptive testing and how does it affect the exam?
The exam selects each question based on your previous answers and ends once it is confident you are above or below the passing standard, between 100 and 150 questions. You cannot review or change earlier answers.
Can I take the CISSP exam without five years of experience?
Yes. If you pass without the experience you become an Associate of ISC2 and have six years to gain the required experience.
How long is the certification valid?
Three years. Maintaining it requires an annual maintenance fee and 120 continuing professional education credits over the cycle.
What does StudyOptima offer for CISSP?
Study notes across all eight domains and 62 subtopics, flashcards, and a practice bank of more than 1,400 questions written in the managerial style of the real exam, with the first lessons of each domain free.