CISSP-2026Hard

CISSP exam guide

Certified Information Systems Security Professional: the benchmark certification for security leadership across eight domains of the ISC2 Common Body of Knowledge.

8
Topics
272
Study lessons
1,408
Practice questions
1,114
Flashcards

What is the CISSP exam?

CISSP is the most widely held advanced security certification and is often a listed requirement for security architect, security manager and CISO roles. It is awarded by ISC2 and accredited under ISO/IEC 17024, and it is approved by the US Department of Defense for several information-assurance job categories.

The exam covers eight domains, from security governance and risk management through asset security, architecture and engineering, networks, identity and access management, assessment and testing, operations, and software development security. It is deliberately broad and managerial in tone: the classic advice is to answer as a risk-focused security leader would, not as an engineer.

The English-language exam uses computerised adaptive testing, so the questions you see depend on how you have answered so far. Certification requires the exam plus five years of paid work experience in at least two of the eight domains, an endorsement from an existing ISC2 member, and agreement to the ISC2 code of ethics.

Who sits it

  • Experienced security engineers and analysts moving into architecture or management
  • Security managers, consultants and auditors who need a recognised leadership credential
  • IT professionals with five or more years of experience who want to formalise security expertise

Exam format at a glance

Questions
100–150, delivered adaptively (multiple-choice plus some advanced item types)
Duration
3 hours
Delivery
Computer-based, year-round, at Pearson VUE test centres
Fee (USD)
About $749
Passing standard
Scaled score of 700 out of 1,000
Experience
Five years of cumulative paid experience in two or more domains; one year can be waived for a relevant degree or approved credential
Pass rate
ISC2 does not publish one
Exam outline
Current version effective from April 2024

Exam-body facts last checked September 2026. Fees, dates and formats change; confirm the current details with ISC2 before registering.

Syllabus and topic weights

  • 1.Security and Risk Management16% · 46 lessons · 0 questions · 199 cards
    1. Understand, Adhere to, and Promote Professional Ethics
    2. Understand and Apply Security Concepts
    3. Evaluate and Apply Security Governance Principles
    4. Legal, Regulatory, and Compliance Issues in Information Security
    5. Requirements for Investigation Types
    6. Security Policy, Standards, Procedures, and Guidelines
    7. Business Continuity (BC) Requirements
    8. Personnel Security Policies and Procedures
    9. Understand and Apply Risk Management Concepts
    10. Threat Modeling Concepts and Methodologies
    11. Supply Chain Risk Management (SCRM)
    12. Security Awareness, Education, and Training Program
  • 2.Asset Security10% · 25 lessons · 0 questions · 98 cards
    1. Identify and Classify Information and Assets
    2. Establish Information and Asset Handling Requirements
    3. Provision Information and Assets Securely
    4. Manage Data Lifecycle
    5. Ensure Appropriate Asset Retention
    6. Data Security Controls and Compliance Requirements
  • 3.Security Architecture and Engineering13% · 44 lessons · 0 questions · 217 cards
    1. Engineering Processes Using Secure Design Principles
    2. Fundamental Concepts of Security Models
    3. Select Controls Based on Systems Security Requirements
    4. Security Capabilities of Information Systems
    5. Vulnerabilities of Security Architectures, Designs, and Solution Elements
    6. Select and Determine Cryptographic Solutions
    7. Methods of Cryptanalytic Attacks
    8. Apply Security Principles to Site and Facility Design
    9. Design Site and Facility Security Controls
    10. Manage the Information System Lifecycle
  • 4.Communication and Network Security13% · 23 lessons · 0 questions · 74 cards
    1. Secure Design Principles in Network Architectures
    2. Secure Network Components
    3. Implement Secure Communication Channels
  • 5.Identity and Access Management (IAM)13% · 25 lessons · 0 questions · 101 cards
    1. Control Physical and Logical Access to Assets
    2. Design Identification and Authentication Strategy
    3. Federated Identity with a Third-Party Service
    4. Implement and Manage Authorization Mechanisms
    5. Manage the Identity and Access Provisioning Lifecycle
    6. Implement Authentication Systems
  • 6.Security Assessment and Testing12% · 20 lessons · 0 questions · 80 cards
    1. Design and Validate Assessment, Test, and Audit Strategies
    2. Conduct Security Controls Testing
    3. Collect Security Process Data
    4. Analyze Test Output and Generate Report
    5. Conduct or Facilitate Security Audits
  • 7.Security Operations13% · 64 lessons · 0 questions · 248 cards
    1. Understand and Comply with Investigations
    2. Conduct Logging and Monitoring Activities
    3. Perform Configuration Management (CM)
    4. Apply Foundational Security Operations Concepts
    5. Apply Resource Protection
    6. Conduct Incident Management
    7. Operate and Maintain Detection and Preventative Measures
    8. Implement and Support Patch and Vulnerability Management
    9. Change Management Processes
    10. Implement Recovery Strategies
    11. Implement Disaster Recovery (DR) Processes
    12. Test Disaster Recovery Plan (DRP)
    13. Participate in Business Continuity (BC) Planning and Exercises
    14. Implement and Manage Physical Security
    15. Address Personnel Safety and Security Concerns
  • 8.Software Development Security10% · 25 lessons · 0 questions · 97 cards
    1. Integrate Security in the Software Development Life Cycle (SDLC)
    2. Security Controls in Software Development Ecosystems
    3. Assess the Effectiveness of Software Security
    4. Assess Security Impact of Acquired Software
    5. Secure Coding Guidelines and Standards

Lesson, question and flashcard counts are StudyOptima's published content for each topic. Expand a topic to see its subtopics.

How to prepare for CISSP

  1. 1

    Study to the exam outline, not to your job. Most candidates are strong in two or three domains and weak in the rest; the adaptive exam will find the gaps.

  2. 2

    Learn the management perspective. When a question offers a technical fix and a governance answer, the governance answer (assess risk, get management approval, follow policy) is usually what ISC2 wants.

  3. 3

    Domain 1 (Security and Risk Management) is the largest and its concepts (risk analysis, legal and regulatory issues, business continuity planning) reappear inside other domains' questions.

  4. 4

    Do not aim to know every technology in depth. Know what each control is for, where it sits in a defence-in-depth model, and its main weaknesses.

  5. 5

    Practise reading questions for the qualifier: 'best', 'first', 'most', 'least'. The adaptive format means you cannot go back, so read each question once, carefully.

Study for CISSP on StudyOptima

272 study lessons

Condensed notes for every topic, organised by learning objective, with read-progress tracking.

1,408 practice questions

Exam-style questions with worked explanations, timed mocks, and re-drills of what you got wrong.

1,114 flashcards

Spaced-repetition review of the definitions and formulas the exam keeps coming back to.

Plans and pricing

Paid plans for CISSP are not on sale yet. Create a free account to read the free lessons and answer a daily allowance of practice questions, and we will let you know when full access opens.

Create a free account

CISSP FAQ

What is computerised adaptive testing and how does it affect the exam?

The exam selects each question based on your previous answers and ends once it is confident you are above or below the passing standard, between 100 and 150 questions. You cannot review or change earlier answers.

Can I take the CISSP exam without five years of experience?

Yes. If you pass without the experience you become an Associate of ISC2 and have six years to gain the required experience.

How long is the certification valid?

Three years. Maintaining it requires an annual maintenance fee and 120 continuing professional education credits over the cycle.

What does StudyOptima offer for CISSP?

Study notes across all eight domains and 62 subtopics, flashcards, and a practice bank of more than 1,400 questions written in the managerial style of the real exam, with the first lessons of each domain free.

Related exams

Start preparing for CISSP today

Free account in 30 seconds. No credit card required.

Create your free account