🔐
CISSP
Certified Information Systems Security Professional
Complete Study Guide — All 8 Domains
Domain Weight
1. Security & Risk Management 15%
2. Asset Security 10%
3. Security Architecture & Engineering 13%
4. Communication & Network Security 13%
5. Identity & Access Management (IAM) 13%
6. Security Assessment & Testing 12%
7. Security Operations 13%
8. Software Development Security 11%
ISC2 Certification | Independent Study Resource
,About the CISSP Exam
The CISSP is widely regarded as the gold standard of information security certifications. It validates that
you can design, implement, and manage a best-in-class cybersecurity program. This guide is an original,
independently authored study resource and is not affiliated with ISC2.
Exam Detail Value
Questions 125–175 adaptive (CAT format)
Duration 4 hours
Passing Score 700 out of 1000
Experience Required 5 years in 2+ CISSP domains (or 4 with
qualifying degree)
Exam Format Computerized Adaptive Testing (CAT) —
difficulty adjusts per answer
Validity 3 years (CPE credits required for renewal)
Endorsement Must be endorsed by an ISC2 member within 9
months of passing
🔴 CRITICAL
CISSP exam mindset: Think like a MANAGER, not a technician. When two answers are
technically correct, choose the one that addresses risk, policy, or governance first — not the
one that involves immediate technical action.
, Domain 1: Security & Risk Management (15%)
The largest domain. Focuses on the foundational principles of security, governance frameworks, legal
compliance, and formal risk management processes.
1.1 The CIA Triad
Principle Definition Example Control
Confidentiality Information is accessible only to Encryption, access controls,
authorised individuals. need-to-know
Integrity Data is accurate, complete, and has not Hashing, digital signatures,
been unauthorisedly altered. checksums
Availability Systems and data are accessible to Redundancy, backups, DDoS
authorised users when needed. protection
Extended models add Authenticity (the source is genuine), Non-repudiation (the sender cannot deny
sending), and Privacy (personal data is protected). These appear frequently in CISSP questions.
1.2 Risk Management
Core Risk Terminology
Term Definition
Threat Any potential event that could cause harm (hurricane, hacker,
insider).
Vulnerability A weakness that a threat can exploit (unpatched software, weak
password).
Risk The likelihood that a threat exploits a vulnerability and the resulting
impact. Risk = Threat × Vulnerability × Impact.
Asset Anything of value to the organisation (data, hardware, reputation,
people).
Exposure The degree to which an asset is subject to loss from a threat.
Control / Safeguard A countermeasure that reduces risk (firewall, policy, training).
Quantitative Risk Analysis
Quantitative analysis assigns monetary values to risk, enabling cost-benefit analysis of controls.
Asset Value (AV) = $500,000
Exposure Factor (EF) = 40% (% of asset lost per incident)
Single Loss Expectancy = AV × EF = $500,000 × 0.40 = $200,000
(SLE)
CISSP
Certified Information Systems Security Professional
Complete Study Guide — All 8 Domains
Domain Weight
1. Security & Risk Management 15%
2. Asset Security 10%
3. Security Architecture & Engineering 13%
4. Communication & Network Security 13%
5. Identity & Access Management (IAM) 13%
6. Security Assessment & Testing 12%
7. Security Operations 13%
8. Software Development Security 11%
ISC2 Certification | Independent Study Resource
,About the CISSP Exam
The CISSP is widely regarded as the gold standard of information security certifications. It validates that
you can design, implement, and manage a best-in-class cybersecurity program. This guide is an original,
independently authored study resource and is not affiliated with ISC2.
Exam Detail Value
Questions 125–175 adaptive (CAT format)
Duration 4 hours
Passing Score 700 out of 1000
Experience Required 5 years in 2+ CISSP domains (or 4 with
qualifying degree)
Exam Format Computerized Adaptive Testing (CAT) —
difficulty adjusts per answer
Validity 3 years (CPE credits required for renewal)
Endorsement Must be endorsed by an ISC2 member within 9
months of passing
🔴 CRITICAL
CISSP exam mindset: Think like a MANAGER, not a technician. When two answers are
technically correct, choose the one that addresses risk, policy, or governance first — not the
one that involves immediate technical action.
, Domain 1: Security & Risk Management (15%)
The largest domain. Focuses on the foundational principles of security, governance frameworks, legal
compliance, and formal risk management processes.
1.1 The CIA Triad
Principle Definition Example Control
Confidentiality Information is accessible only to Encryption, access controls,
authorised individuals. need-to-know
Integrity Data is accurate, complete, and has not Hashing, digital signatures,
been unauthorisedly altered. checksums
Availability Systems and data are accessible to Redundancy, backups, DDoS
authorised users when needed. protection
Extended models add Authenticity (the source is genuine), Non-repudiation (the sender cannot deny
sending), and Privacy (personal data is protected). These appear frequently in CISSP questions.
1.2 Risk Management
Core Risk Terminology
Term Definition
Threat Any potential event that could cause harm (hurricane, hacker,
insider).
Vulnerability A weakness that a threat can exploit (unpatched software, weak
password).
Risk The likelihood that a threat exploits a vulnerability and the resulting
impact. Risk = Threat × Vulnerability × Impact.
Asset Anything of value to the organisation (data, hardware, reputation,
people).
Exposure The degree to which an asset is subject to loss from a threat.
Control / Safeguard A countermeasure that reduces risk (firewall, policy, training).
Quantitative Risk Analysis
Quantitative analysis assigns monetary values to risk, enabling cost-benefit analysis of controls.
Asset Value (AV) = $500,000
Exposure Factor (EF) = 40% (% of asset lost per incident)
Single Loss Expectancy = AV × EF = $500,000 × 0.40 = $200,000
(SLE)