ISC2 CISSP Course Syllabus
The Certified Information Systems Security Professional (CISSP) is the gold standard of cybersecurity certifications. This syllabus covers the 8 core domains of information security required to successfully pass the CISSP exam, transitioning candidates from a technical mindset to a strategic managerial framework.
Overview
- Certification: Certified Information Systems Security Professional (CISSP)
- Authority: ISC2 (International Information System Security Certification Consortium)
- Exam Duration: 3 hours (Computerized Adaptive Testing)
- Questions: 100–150 multiple-choice & advanced innovative items
- Passing Score: 700/1000
Target Audience & Prerequisites
Who Should Attend? This course is designed for experienced security managers, directors, network architects, and security consultants aiming to validate their strategic and operational leadership skills.
Prerequisites: To fully qualify for the CISSP designation, ISC2 requires a minimum of 5 years of cumulative, paid work experience in at least two of the eight domains listed above. (A 1-year waiver is available for individuals holding a relevant 4-year degree or approved regional certifications).
For students looking for an in-depth video walkthrough of these core concepts before starting, checking out this comprehensive CISSP Certification Full Course will provide an excellent foundational overview of what to expect in each module.
Accreditation & Recognition
- ANSI Accredited under ISO/IEC Standard 17024
- Approved by U.S. Department of Defence (DoDM 8140.03)
- Recognized globally as the premier cybersecurity certification
Course Overview & Exam Weights
Domain | Weight | Key Topics |
1. Security and Risk Management | 16% | Governance, compliance, ethics, risk analysis, security policies, legal/regulatory issues |
2. Asset Security | 10% | Data classification, ownership, privacy protection, secure handling/storage |
3. Security Architecture and Engineering | 13% | Secure design principles, cryptography, physical security, system architecture |
4. Communication and Network Security | 13% | Secure network design, protocols, firewalls, VPNs, intrusion detection |
5. Identity and Access Management (IAM) | 13% | Authentication, authorization, identity lifecycle, access control models |
6. Security Assessment and Testing | 12% | Security audits, penetration testing, vulnerability assessments, reporting |
7. Security Operations | 13% | Incident response, disaster recovery, logging/monitoring, investigations |
8. Software Development Security | 7% | Secure coding practices, SDLC, application security, DevSecOps |
Detailed Domain Breakdown
Domain 1: Security and Risk Management
- Core Security Principles: Confidentiality, Integrity, and Availability (CIA triad); Authenticity and Non-repudiation.
- Security Governance: Alignment of security strategy with business goals, organizational roles, and frameworks (NIST, ISO, COBIT).
- Legal & Compliance: Cybercrimes, data privacy regulations (GDPR, CCPA), intellectual property laws, and import/export controls.
- Personnel Security: Onboarding, termination, background screening, and vendor/contractor controls.
- Risk Management: Threat modelling, risk analysis (quantitative and qualitative), risk response, and Supply Chain Risk Management (SCRM).
- Security Awareness: Developing, implementing, and evaluating security training programs (including modern trends like AI and blockchain).
Domain 2: Asset Security
- Information & Asset Classification: Customizing and managing data and asset classification policies.
- Privacy Protection: Compliance with privacy acts and managing data controllers, processors, and subjects.
- Asset Lifecycle Management: Data collection, maintenance, retention, and secure destruction (handling data remanence).
- Data Security Controls: Implementing data states protection (Data at Rest, Data in Transit, Data in Use).
Domain 3: Security Architecture and Engineering
- Secure Design Principles: Utilizing engineering processes and security models (e.g., Bell-LaPadula, Biba).
- System Vulnerabilities: Identifying and mitigating vulnerabilities in web-based, mobile, embedded/IoT, and cloud systems (IaaS, PaaS, SaaS).
- Cryptographic Solutions: Symmetric/asymmetric encryption, PKI, digital signatures, cryptanalytic attacks, and quantum-resistant algorithms.
- Physical Security: Site design, facility location, server rooms, fire suppression, and HVAC controls.
Domain 4: Communication and Network Security
- Secure Network Architectures: IP networking, OSI and TCP/IP models, routing protocols, and wireless security.
- Secure Network Components: Firewalls, IDS/IPS, proxies, and content filters.
- Secure Communication Channels: VPNs, TLS/SSL, remote access protocols, and virtualization network controls.
Domain 5: Identity and Access Management (IAM)
- Access Control Systems: Physical and logical access controls, identification, and authentication (MFA, Biometrics).
- Identity Management: Identity as a Service (IDaaS), federated identity (SAML, OAuth, OIDC), and third-party identity providers.
- Authorization Mechanisms: Role-Based (RBAC), Attribute-Based (ABAC), and Discretionary/Mandatory Access Controls (DAC/MAC).
- Provisioning Lifecycle: Managing the onboarding, modification, and termination of user access.
Domain 6: Security Assessment and Testing
- Assessment Strategies: Vulnerability assessments, penetration testing, and log reviews.
- Security Control Testing: Code reviews, static and dynamic analysis (SAST/DAST), and synthetic transactions.
- Testing Outputs: Collecting security process data, analyzing reports, and remediating identified deficiencies.
- Audits: Internal and external compliance audits.
Domain 7: Security Operations
- Investigations: Digital forensics, evidence collection, and e-discovery.
- Incident Management: Incident response lifecycles (Detection, Response, Mitigation, Reporting, Recovery, and Lessons Learned).
- Operational Resilience: Disaster Recovery (DR) and Business Continuity (BC) activation, patching, change management, and backup management.
- Resource Protection: Physical security for computing resources, media protection, and personnel safety.
Domain 8: Software Development Security
- Software Development Lifecycle (SDLC): Integrating security into development methodologies (DevSecOps, Agile, Waterfall).
- Security Controls in Dev Environments: Configuration management, source code security, and application security testing.
- Software Security Effectiveness: Auditing commercial-off-the-shelf (COTS) software, open-source vulnerabilities, and utilizing Software Bills of Materials (SBOM).