Skip to main content

ISC2 exam preparation

ISC2 CISSP

Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises and practice exams.

Validate your expertise in designing, engineering, and managing holistic organizational security postures with the premier information security leadership certification.

Lessons, quizzes and hands-on practice across every CISSP objective, added to your roadmap. Free account.
Not ready to start? Tell us you want it and nothing else changes.

What you'll learn

Every objective CISSP publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.

  • Security and Risk Management (16% of the exam)Understand, adhere to, and promote professional ethics. Understand and apply security concepts. Evaluate and apply security governance principles. Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context. Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards). Develop, document, and implement security policy, standards, procedures, and guidelines. And 6 more, each a topic in the course below.
  • Asset Security (10% of the exam)Identify and classify information and assets. Establish information and asset handling requirements. Manage data lifecycle. Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support). Determine data security controls and compliance requirements. Provision information and assets securely.
  • Security Architecture and Engineering (13% of the exam)Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula). Select and determine cryptographic solutions. Understand methods of cryptanalytic attacks. Research, implement and manage engineering processes using secure design principles. Select controls based upon systems security requirements. Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption). And 4 more, each a topic in the course below.
  • Communication and Network Security (13% of the exam)Apply secure design principles in network architectures. Secure network components. Implement secure communication channels according to design.
  • Identity and Access Management (IAM) (13% of the exam)Control physical and logical access to assets. Design identification and authentication strategy (e.g., people, devices, and services). Implement authentication systems. Implement and manage authorization mechanisms. Federated identity with a third-party service. Manage the identity and access provisioning lifecycle.
  • Security Assessment and Testing (12% of the exam)Design and validate assessment, test, and audit strategies. Conduct security control testing. Collect security process data (e.g., technical and administrative). Analyze test output and generate report. Conduct or facilitate security audits.
  • Security Operations (13% of the exam)Apply foundational security operations concepts. Conduct logging and monitoring activities. Perform Configuration Management (CM) (e.g., provisioning, baselining, automation). Understand and participate in change management processes. Apply resource protection. Operate and maintain detection and preventative measures. And 9 more, each a topic in the course below.
  • Software Development Security (10% of the exam)Understand and integrate security in the Software Development Life Cycle (SDLC). Define and apply secure coding guidelines and standards. Identify and apply security controls in software development ecosystems. Assess the effectiveness of software security. Assess security impact of acquired software.

The exam at a glance

Length
3 hours
Cost
$749
Validity
3 years
Style
Multiple choice

Computerized Adaptive Testing (CAT). Based on CISSP. Pass mark is 700 out of 1000 points.

Candidates must have a minimum of five years cumulative full-time experience in two or more of the eight domains of the current CISSP Exam Outline.

Sitting the exam

The part nobody publishes in a syllabus. For CISSP the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.

If you do not pass

  • Candidates are given 180 days from the date of purchase to complete both attempts under the Peace of Mind Protection.

Booking it

  • The exam code must be scheduled and administered within 365 days of purchase.

What comes with it

  • An exam-only purchase includes two attempts in the purchase price.

Read off the official exam page on 10 September 2026. Rules change without notice, so confirm anything you are about to spend money on.

What the exam covers

Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.

Security and Risk Management16%
Asset Security10%
Security Architecture and Engineering13%
Communication and Network Security13%
Identity and Access Management (IAM)13%
Security Assessment and Testing12%
Security Operations13%
Software Development Security10%

Course content

65 topics

Core security principles including confidentiality, integrity, availability, and defense in depth

  • Understand, adhere to, and promote professional ethics
  • Understand and apply security concepts
  • Evaluate and apply security governance principles
  • Develop, document, and implement security policy, standards, procedures, and guidelines
  • Understand and apply risk management concepts
  • Understand and apply threat modeling concepts and methodologies
  • Apply Supply Chain Risk Management (SCRM) concepts
  • Identify and classify information and assets
  • Establish information and asset handling requirements
  • Manage data lifecycle
  • Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
  • Determine data security controls and compliance requirements
  • Provision information and assets securely
  • Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)

Basic cryptographic concepts including symmetric and asymmetric encryption, hashing, and digital signatures

  • Select and determine cryptographic solutions
  • Understand methods of cryptanalytic attacks
  • Research, implement and manage engineering processes using secure design principles
  • Select controls based upon systems security requirements
  • Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
  • Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
  • Apply security principles to site and facility design
  • Design site and facility security controls
  • Manage the information system lifecycle

OSI model, TCP/IP, network protocols, and basic network components

  • Apply secure design principles in network architectures
  • Secure network components
  • Implement secure communication channels according to design

Basic IAM concepts including subjects, objects, and access control models

  • Control physical and logical access to assets
  • Design identification and authentication strategy (e.g., people, devices, and services)
  • Implement authentication systems
  • Implement and manage authorization mechanisms
  • Federated identity with a third-party service
  • Manage the identity and access provisioning lifecycle
  • Contribute to and enforce personnel security policies and procedures
  • Establish and maintain a security awareness, education, and training program

Basic SDLC phases, methodologies, and software development concepts

  • Understand and integrate security in the Software Development Life Cycle (SDLC)
  • Define and apply secure coding guidelines and standards
  • Identify and apply security controls in software development ecosystems
  • Assess the effectiveness of software security
  • Assess security impact of acquired software
  • Apply foundational security operations concepts
  • Conduct logging and monitoring activities
  • Perform Configuration Management (CM) (e.g., provisioning, baselining, automation)
  • Understand and participate in change management processes
  • Apply resource protection
  • Operate and maintain detection and preventative measures
  • Implement and support patch and vulnerability management
  • Conduct incident management
  • Understand and comply with investigations
  • Design and validate assessment, test, and audit strategies
  • Conduct security control testing
  • Collect security process data (e.g., technical and administrative)
  • Analyze test output and generate report
  • Conduct or facilitate security audits
  • Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
  • Implement recovery strategies
  • Implement Disaster Recovery (DR) processes
  • Test Disaster Recovery Plans (DRP)
  • Participate in Business Continuity (BC) planning and exercises
  • Implement and manage physical security
  • Address personnel safety and security concerns

What to know before you start

  • Five years of cumulative, full-time professional experience in two or more of the eight CISSP domains.
  • Comprehensive understanding of security and risk management, asset security, and security architecture.
  • Advanced knowledge of communication, network security, identity and access management, and security operations.

Other certifications

Frequently asked questions

How much does the CISSP exam cost?

$749. Confirm it on ISC2's page before you book: exam fees change.

How long is the CISSP exam?

3 hours. Computerized Adaptive Testing (CAT).

How many questions are on the CISSP exam?

Computerized Adaptive Testing (CAT). The sitting is 3 hours long. Check the current count with ISC2 before you book.

How long is CISSP valid?

3 years. Check ISC2's recertification route before it lapses.

Is the CISSP exam hands-on?

No. It is a written exam, so the skill it tests is recognising the right design or command rather than executing it under time pressure.

What is on the CISSP exam?

8 domains. The heaviest is Security and Risk Management at 16% of the exam, so it is the one worth over-preparing.

What should I know before starting CISSP?

Five years of cumulative, full-time professional experience in two or more of the eight CISSP domains.. Comprehensive understanding of security and risk management, asset security, and security architecture.. Advanced knowledge of communication, network security, identity and access management, and security operations..

Exam details from ISC2, checked August 2026. Always confirm on their page before booking.

What learners say about Acelro

About Acelro rather than the CISSP exam: what learners made of the gap analysis, the roadmap and the projects.

The roadmap makes me focus on a learning curve, no matter the length.
Daniel O., Career path navigation
Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.
Stephanie E., Learner
The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.
Cebuka B., Career changer

Not sure you are ready for CISSP yet? Check where your skills stand in under a minute, no sign-up required.