ISC2 CISSP
Follow a topic roadmap built from the published exam blueprint, with lessons, practice exercises and practice exams.
Validate your expertise in designing, engineering, and managing holistic organizational security postures with the premier information security leadership certification.
What you'll learn
Every objective CISSP publishes, and what it asks you to be able to do. The percentage is how much of the exam each one is worth.
- Security and Risk Management (16% of the exam)Understand, adhere to, and promote professional ethics. Understand and apply security concepts. Evaluate and apply security governance principles. Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context. Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards). Develop, document, and implement security policy, standards, procedures, and guidelines. And 6 more, each a topic in the course below.
- Asset Security (10% of the exam)Identify and classify information and assets. Establish information and asset handling requirements. Manage data lifecycle. Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support). Determine data security controls and compliance requirements. Provision information and assets securely.
- Security Architecture and Engineering (13% of the exam)Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula). Select and determine cryptographic solutions. Understand methods of cryptanalytic attacks. Research, implement and manage engineering processes using secure design principles. Select controls based upon systems security requirements. Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption). And 4 more, each a topic in the course below.
- Communication and Network Security (13% of the exam)Apply secure design principles in network architectures. Secure network components. Implement secure communication channels according to design.
- Identity and Access Management (IAM) (13% of the exam)Control physical and logical access to assets. Design identification and authentication strategy (e.g., people, devices, and services). Implement authentication systems. Implement and manage authorization mechanisms. Federated identity with a third-party service. Manage the identity and access provisioning lifecycle.
- Security Assessment and Testing (12% of the exam)Design and validate assessment, test, and audit strategies. Conduct security control testing. Collect security process data (e.g., technical and administrative). Analyze test output and generate report. Conduct or facilitate security audits.
- Security Operations (13% of the exam)Apply foundational security operations concepts. Conduct logging and monitoring activities. Perform Configuration Management (CM) (e.g., provisioning, baselining, automation). Understand and participate in change management processes. Apply resource protection. Operate and maintain detection and preventative measures. And 9 more, each a topic in the course below.
- Software Development Security (10% of the exam)Understand and integrate security in the Software Development Life Cycle (SDLC). Define and apply secure coding guidelines and standards. Identify and apply security controls in software development ecosystems. Assess the effectiveness of software security. Assess security impact of acquired software.
The exam at a glance
- Length
- 3 hours
- Cost
- $749
- Validity
- 3 years
- Style
- Multiple choice
Computerized Adaptive Testing (CAT). Based on CISSP. Pass mark is 700 out of 1000 points.
Candidates must have a minimum of five years cumulative full-time experience in two or more of the eight domains of the current CISSP Exam Outline.
Sitting the exam
The part nobody publishes in a syllabus. For CISSP the logistics are study strategy: what you are allowed to read while the clock runs changes how you should practise, and what a second attempt costs changes when you should book.
If you do not pass
- Candidates are given 180 days from the date of purchase to complete both attempts under the Peace of Mind Protection.
Booking it
- The exam code must be scheduled and administered within 365 days of purchase.
What comes with it
- An exam-only purchase includes two attempts in the purchase price.
Read off the official exam page on 10 September 2026. Rules change without notice, so confirm anything you are about to spend money on.
What the exam covers
Straight from the published curriculum. The weights are how much of the exam each area is worth, so they are the honest guide to where your study time should go.
Course content
65 topics
1. Foundational Security Concepts
Core security principles including confidentiality, integrity, availability, and defense in depth
2. Professional Ethics and Security Concepts
- Understand, adhere to, and promote professional ethics
- Understand and apply security concepts
3. Security Governance Principles
- Evaluate and apply security governance principles
4. Legal, Regulatory, and Compliance Issues
- Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
- Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
5. Security Policy, Standards, Procedures, and Guidelines
- Develop, document, and implement security policy, standards, procedures, and guidelines
6. Risk Management Concepts
- Understand and apply risk management concepts
7. Threat Modeling Concepts and Methodologies
- Understand and apply threat modeling concepts and methodologies
8. Supply Chain Risk Management
- Apply Supply Chain Risk Management (SCRM) concepts
9. Information and Asset Identification and Classification
- Identify and classify information and assets
10. Information and Asset Handling Requirements
- Establish information and asset handling requirements
11. Data Lifecycle Management
- Manage data lifecycle
12. Asset Retention and End of Life
- Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
13. Data Security Controls and Compliance Requirements
- Determine data security controls and compliance requirements
14. Secure Provisioning of Information and Assets
- Provision information and assets securely
15. Fundamental Security Models
- Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
16. Cryptographic Fundamentals
Basic cryptographic concepts including symmetric and asymmetric encryption, hashing, and digital signatures
17. Cryptographic Solutions
- Select and determine cryptographic solutions
18. Cryptanalytic Attacks
- Understand methods of cryptanalytic attacks
19. Secure Design Principles and Engineering Processes
- Research, implement and manage engineering processes using secure design principles
20. Systems Security Requirements and Control Selection
- Select controls based upon systems security requirements
21. Security Capabilities of Information Systems
- Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
22. Security Architecture Vulnerability Assessment and Mitigation
- Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
23. Physical Security Principles for Sites and Facilities
- Apply security principles to site and facility design
24. Site and Facility Security Controls
- Design site and facility security controls
25. Information System Lifecycle Management
- Manage the information system lifecycle
26. Network Architecture Fundamentals
OSI model, TCP/IP, network protocols, and basic network components
27. Secure Network Architecture Design
- Apply secure design principles in network architectures
28. Secure Network Components
- Secure network components
29. Secure Communication Channels
- Implement secure communication channels according to design
30. Identity and Access Management Fundamentals
Basic IAM concepts including subjects, objects, and access control models
31. Physical and Logical Access Control
- Control physical and logical access to assets
32. Identification and Authentication Strategy
- Design identification and authentication strategy (e.g., people, devices, and services)
33. Authentication Systems Implementation
- Implement authentication systems
34. Authorization Mechanisms
35. Federated Identity Management
- Federated identity with a third-party service
36. Identity and Access Provisioning Lifecycle
- Manage the identity and access provisioning lifecycle
37. Personnel Security Policies and Procedures
- Contribute to and enforce personnel security policies and procedures
38. Security Awareness, Education, and Training Program
- Establish and maintain a security awareness, education, and training program
39. Software Development Lifecycle Fundamentals
Basic SDLC phases, methodologies, and software development concepts
40. Security in the Software Development Lifecycle
- Understand and integrate security in the Software Development Life Cycle (SDLC)
41. Secure Coding Guidelines and Standards
- Define and apply secure coding guidelines and standards
42. Security Controls in Software Development Ecosystems
- Identify and apply security controls in software development ecosystems
43. Software Security Effectiveness Assessment
- Assess the effectiveness of software security
44. Security Impact of Acquired Software
- Assess security impact of acquired software
45. Foundational Security Operations Concepts
- Apply foundational security operations concepts
46. Logging and Monitoring Activities
- Conduct logging and monitoring activities
47. Configuration Management
- Perform Configuration Management (CM) (e.g., provisioning, baselining, automation)
48. Change Management Processes
- Understand and participate in change management processes
49. Resource Protection
- Apply resource protection
50. Detection and Preventative Measures
- Operate and maintain detection and preventative measures
51. Patch and Vulnerability Management
- Implement and support patch and vulnerability management
52. Incident Management
- Conduct incident management
53. Investigations Compliance
- Understand and comply with investigations
54. Assessment, Test, and Audit Strategies
- Design and validate assessment, test, and audit strategies
55. Security Control Testing
- Conduct security control testing
56. Security Process Data Collection
- Collect security process data (e.g., technical and administrative)
57. Test Output Analysis and Reporting
- Analyze test output and generate report
58. Security Audits
- Conduct or facilitate security audits
59. Business Continuity Requirements
- Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
60. Recovery Strategies
- Implement recovery strategies
61. Disaster Recovery Processes
- Implement Disaster Recovery (DR) processes
62. Disaster Recovery Plan Testing
- Test Disaster Recovery Plans (DRP)
63. Business Continuity Planning and Exercises
- Participate in Business Continuity (BC) planning and exercises
64. Physical Security Operations
- Implement and manage physical security
65. Personnel Safety and Security
- Address personnel safety and security concerns
What to know before you start
- Five years of cumulative, full-time professional experience in two or more of the eight CISSP domains.
- Comprehensive understanding of security and risk management, asset security, and security architecture.
- Advanced knowledge of communication, network security, identity and access management, and security operations.
Other certifications
Frequently asked questions
How much does the CISSP exam cost?
$749. Confirm it on ISC2's page before you book: exam fees change.
How long is the CISSP exam?
3 hours. Computerized Adaptive Testing (CAT).
How many questions are on the CISSP exam?
Computerized Adaptive Testing (CAT). The sitting is 3 hours long. Check the current count with ISC2 before you book.
How long is CISSP valid?
3 years. Check ISC2's recertification route before it lapses.
Is the CISSP exam hands-on?
No. It is a written exam, so the skill it tests is recognising the right design or command rather than executing it under time pressure.
What is on the CISSP exam?
8 domains. The heaviest is Security and Risk Management at 16% of the exam, so it is the one worth over-preparing.
What should I know before starting CISSP?
Five years of cumulative, full-time professional experience in two or more of the eight CISSP domains.. Comprehensive understanding of security and risk management, asset security, and security architecture.. Advanced knowledge of communication, network security, identity and access management, and security operations..
Exam details from ISC2, checked August 2026. Always confirm on their page before booking.
What learners say about Acelro
About Acelro rather than the CISSP exam: what learners made of the gap analysis, the roadmap and the projects.
“The roadmap makes me focus on a learning curve, no matter the length.”
“Acelro has been really great for me, an inspiring experience. I've gained a lot of confidence doing projects I thought were rocket science.”
“The gap analysis maps your actual skills against what the current job market is asking for. Nobody else made it that clear where I stood.”