How to use this guide
CISSP questions reward sound security leadership judgment: protect the mission, establish governance, understand risk,
respect process and law, and choose a control that is feasible, proportional, and owned. Technical knowledge matters; it is
usually the evidence used to make a better managerial decision.
THE STUDY CONTRACT
The official ISC2 CISSP Certification Exam Outline is the source of truth for scope. This guide maps every published objective
into plain language and adds instructor commentary. Verify current registration, format, policies, and objectives against ISC2
before scheduling.
The eight-domain map
Domain | Weight | Primary question |
1. Security and Risk Management | 16% | Are we governing risk, people, law, and continuity correctly? |
2. Asset Security | 10% | What is the asset, who owns it, and how should it be handled? |
3. Security Architecture and Engineering | 13% | What secure design and technical mechanism fits the requirement? |
4. Communication and Network Security | 13% | How does information flow securely and resiliently? |
5. Identity and Access Management | 13% | Who/what gets access, to what, under which policy? |
6. Security Assessment and Testing | 12% | How do we obtain reliable assurance and report it? |
7. Security Operations | 13% | How do we monitor, respond, recover, and operate safely? |
8. Software Development Security | 10% | How do we build, buy, and operate trustworthy software? |
When the question asks... | Usually prioritize... |
FIRST / BEST / MOST appropriate | The earliest governance, risk, validation, or authorization step that safely resolves the decision. |
Management response | Business alignment, policy, ownership, risk acceptance/escalation, and defensible process. |
Technical containment | Preserve evidence and scope impact; do not destroy evidence or skip authorization. |
Control selection | The objective, the asset classification, the threat, and the least intrusive effective control. |
Legal or privacy issue | Jurisdiction, contractual duties, counsel, and documented evidence handling; do not guess. |
A reliable question-ordering method
Do not turn these into absolute rules. Read constraints in the scenario: a life-safety emergency, confirmed active harm, legal
order, or explicitly delegated authority can change the immediate action.
Study guide - use the official ISC2 outline as the final authority 2CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
CISSP vocabulary and decision anchors
Anchor Meaning to retain
Due care Acting as a prudent organization should to protect assets and meet obligations. Think: reasonable
safeguards and oversight.
Due diligence Investigating, assessing, and validating before and while acting. Think: evidence that care was exercised.
Risk owner The accountable business authority who decides whether residual risk is accepted, transferred, avoided, or
mitigated.
Data owner Classifies data and defines business handling requirements. A custodian implements the owner’s direction.
Policy / standard / procedure /
guideline
Policy says what and why; standard sets mandatory uniform requirements; procedure tells how; guideline is
recommended flexibility.
Preventive / detective /
corrective
Stop; discover; restore or reduce impact. Deterrent, compensating, directive, and recovery are other useful
classifications.
Defense in depth Layer independent controls so a single failure does not produce unacceptable loss.
Least privilege Give only the minimum access, scope, and duration needed to perform an authorized task.
Term | Formula / interpretation |
SLE | Single Loss Expectancy = Asset Value x Exposure Factor. Expected loss from one event. |
ARO | Annualized Rate of Occurrence. Expected frequency per year. |
ALE | Annualized Loss Expectancy = SLE x ARO. Use with judgment; qualitative risk can be better when inputs are uncertain. |
RTO | Recovery Time Objective: maximum acceptable time to restore a process/service after disruption. |
RPO | Recovery Point Objective: maximum tolerable amount of data loss measured in time. |
MTD / MAO | Maximum Tolerable Downtime / Maximum Acceptable Outage: the outer business limit. RTO should be within it. |
Calculation essentials
RECENT-OUTLINE READINESS
The current official outline embeds cloud, containers, serverless, zero trust, SASE, API security, AI/ML, 5G, SDN, and modern
development ecosystems across domains. Learn the enduring security principle first, then apply it to the technology context.
Study guide - use the official ISC2 outline as the final authority 3CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 1 | 16% OF EXAM
Security and Risk Management
Instructor lens: This is the managerial backbone of CISSP. Start with mission, ownership, law, ethics, and risk before selecting
technology.
1.1 Professional ethics
Know the ISC2 Code of Professional Ethics and your organizational code. Protect society, act honorably and honestly, provide
diligent service to principals, and advance the profession. Ethics can require escalation even when it is inconvenient.
EXAM LENS
When legal, business, and technical pressures conflict, choose the action that is lawful, honest, protects the public, and uses
appropriate authority or escalation.
1.2 Security concepts: the five pillars
Confidentiality limits unauthorized disclosure; integrity prevents or detects unauthorized change; availability ensures timely
reliable access; authenticity establishes genuineness; nonrepudiation provides strong evidence that a party performed an
action. Match the control to the harmed property.
Property Typical mechanisms Common confusion
Confidentiality Encryption, access control, need-to-know Encryption does not automatically provide integrity or
availability.
Integrity Hash/MAC, digital signature, change control A hash alone detects change but does not authenticate the
origin.
Availability Redundancy, capacity, backups, DR A backup is not availability until restoration is feasible and
tested.
Authenticity Certificates, MFA, validated identity Authentication proves a claim; authorization decides
permissions.
Nonrepudiation Digital signatures, protected audit trails Shared accounts and weak key control undermine attribution.
1.3 Security governance
Align the security program to business strategy, mission, objectives, organizational processes, roles, and control frameworks.
Governance assigns accountability, directs risk decisions, measures results, and supports acquisition/divestiture and committee
decisions. Know ISO, NIST, COBIT, SABSA, PCI, and FedRAMP as framework examples; do not treat a framework as a control
by itself.
EXAM LENS
The senior answer establishes ownership and risk-based direction before deploying a tool. Due care is acting prudently; due
diligence is investigating and validating prudently.
1.4 Legal, regulatory, and compliance context
Recognize cybercrime/breach duties, licensing and intellectual property, import/export restrictions, transborder data flows,
privacy, contracts, regulations, and industry standards. Requirements vary by jurisdiction and contract; involve qualified counsel
and the privacy/legal function rather than interpreting law alone.
Study guide - use the official ISC2 outline as the final authority 4CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
1.5 Investigation requirements
Different investigations have different rules: administrative (policy/workplace), criminal (law enforcement and high evidentiary
burden), civil (litigation), regulatory, and standards-based. Determine authority, scope, preservation, notice, documentation, and
chain of custody before collecting evidence.
1.6 Policy hierarchy
Develop, document, implement, communicate, and enforce policy, standards, procedures, and guidelines. A policy must be
approved by the right authority, practical, measurable, reviewed, and supported by enforcement and exception management.
EXAM LENS
If a question describes inconsistent actions, the answer is often to establish or enforce a policy/standard, then create procedures
and training - not to buy a product first.
1.7 Business continuity requirements
Use a business impact analysis (BIA) to identify critical processes, impacts over time, dependencies, recovery priorities,
RTO/RPO/MAO, and resource requirements. External dependencies include cloud, suppliers, utilities, people, facilities, and
telecoms. BC sustains the business; DR restores technology.
1.8 Personnel security
Apply screening and hiring practices, agreements, onboarding, transfers, termination, contractor/vendor controls, separation of
duties, acceptable use, and awareness. The highest-risk access changes often occur at joiner-mover-leaver events; ensure rapid,
verified deprovisioning.
1.9 Risk management
Identify assets, threats, vulnerabilities, likelihood, and impact; analyze and prioritize; select treatment; implement and assess
controls; continuously monitor and report. Treatments are avoid, mitigate, transfer, or accept. Risk acceptance belongs to the
authorized risk owner, not the security team.
Analysis type Use Caution
Qualitative Ranks likelihood/impact using categories; fast and
useful where data are weak.
Subjective scales require clear definitions and
calibration.
Quantitative Uses financial estimates, SLE/ARO/ALE; supports
cost-benefit comparisons.
False precision is dangerous if asset values or rates
are speculative.
Hybrid Uses data where credible and qualitative rankings
elsewhere.
Document assumptions and residual risk.
1.10 Threat modeling
Model how a system can be harmed before it is built or changed: identify assets, trust boundaries, actors, attack surfaces, threats,
mitigations, and residual risk. STRIDE is a common mnemonic: spoofing, tampering, repudiation, information disclosure, denial of
service, elevation of privilege.
1.11 Supply chain risk management (SCRM)
Manage supplier and provider risk across acquisition, delivery, operation, and disposal. Consider tampering, counterfeits,
implants, vulnerable dependencies, service concentration, code provenance, contractual SLAs, audit rights, SBOMs, incident
notification, and exit plans.
1.12 Awareness, education, and training
Build role-appropriate, repeated learning that addresses social engineering, phishing, security champions, gamification, emerging
technologies such as AI/blockchain/cryptocurrency, and measured effectiveness. Awareness changes behavior; education builds
knowledge; training builds a specific skill.
DOMAIN 1 RAPID RECALL
Study guide - use the official ISC2 outline as the final authority 5CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Business owns risk; security advises and enables. BIA precedes recovery design. Counsel guides legal interpretation. Policy
directs; procedures execute. A control is justified by risk, not by fashion.
Study guide - use the official ISC2 outline as the final authority 6CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 2 | 10% OF EXAM
Asset Security
Instructor lens: Find the information, establish its business value and owner, protect it throughout its lifecycle, and dispose of it
defensibly.
2.1 Identify and classify information and assets
Build an inventory of tangible and intangible assets: data, systems, software, models, credentials, media, intellectual property,
and cloud resources. Classification reflects business impact if confidentiality, integrity, or availability is compromised. The data
owner assigns classification; labels and handling rules make the classification operational.
2.2 Information and asset handling
Define handling for creation, collection, labeling, storage, transmission, use, sharing, copying, retention, and destruction.
Requirements should follow classification and contractual/regulatory obligations, including approved locations, encryption,
access, and media controls.
2.3 Secure provisioning
Provision assets through controlled acquisition and registration: name an owner/custodian, record the asset, apply baseline
configuration, classification and access requirements, validate supply/source, and establish support/EOL information. Shadow IT
is an asset-management and governance problem as much as a technical one.
2.4 Data lifecycle and roles
Manage data from collection to destruction. Distinguish roles: owner defines classification/use; controller determines
purpose/means of processing; processor processes for the controller; custodian administers protection; data subject is the
person the personal data concerns. Minimize collection, maintain accuracy, control location, retain only as required, and destroy
correctly.
2.5 Retention, EOL, and EOS
Retain information and assets only for a defined legal, business, and operational period. Account for End of Life (vendor no longer
sells) and End of Support (no fixes/support): inventory, assess exposure, migrate, isolate/compensate, and dispose when
justified.
2.6 Data security controls and compliance
Select controls by state (at rest, in transit, in use), classification, processing location, threats, and obligations. Scope and tailor
standards to the system. Use protection approaches such as DRM, DLP, CASB, encryption, tokenization, segmentation, and
logging, but validate effectiveness and fit.
Data state Primary concern Useful controls
At rest Stored copies, media loss, unauthorized reads Encryption, key management, access control,
retention/destruction, backup safeguards.
In transit Interception, tampering, endpoint authenticity TLS/IPsec, mutual authentication, VPN, secure protocols,
integrity protection.
In use Memory, screen, process, privileged misuse Least privilege, isolation, confidential computing where suitable,
session controls, monitoring.
EXAM LENS
If two answers sound technical, ask first: who owns the data and what is its classification? The owner establishes requirements;
the custodian implements them. Deleting a file is not secure sanitization if recoverable remnants remain.
Study guide - use the official ISC2 outline as the final authority 7CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 3 | 13% OF EXAM
Security Architecture and Engineering
Instructor lens: Translate security requirements into resilient architecture. Know why a mechanism works, its assumptions, its
failure modes, and its lifecycle.
3.1 Secure design principles
Use threat modeling, least privilege, defense in depth, secure defaults, fail securely, separation of duties, simplicity, zero
trust/trust-but-verify, privacy by design, shared responsibility, and SASE. Design security in from requirements through retirement;
do not bolt it on at the end.
3.2 Security models
Bell-LaPadula protects confidentiality: no read up, no write down. Biba protects integrity: no read down, no write up. The
Clark-Wilson model focuses on well-formed transactions, separation of duties, and integrity verification. Brewer-Nash (Chinese
Wall) prevents conflict-of-interest access. The star property is part of Bell-LaPadula’s confidentiality control.
3.3 Control selection from requirements
Derive administrative, technical, and physical controls from clear security requirements and risk. Consider effectiveness,
assurance, usability, cost, interoperability, maintenance, and residual risk. Compensating controls address a gap where the
preferred control is infeasible.
3.4 Information system security capabilities
Understand trusted computing concepts and mechanisms: memory protection and process isolation, privilege rings/modes,
TPM/secure boot, encryption/decryption, virtualization boundaries, auditing, and reference-monitor characteristics (always
invoked, tamperproof, small enough to verify).
3.5 Architecture vulnerability assessment
Assess and mitigate vulnerabilities in client/server/database/cryptographic/ICS/cloud/distributed/IoT/microservices/container/serv
erless/embedded/HPC/edge/virtualized systems. Apply the shared responsibility model exactly: cloud providers secure defined
portions of the service; customers remain responsible for identity, data, configuration, and many workload controls.
Architecture Risk focus Security response
Cloud / SaaS Misconfiguration, identity, data residency, opaque
provider layers
Clarify shared responsibility; enforce IAM, contractual
controls, encryption, logs, and configuration governance.
Containers / serverless Image/dependency risk, runtime permissions,
ephemeral observability
Trusted artifacts, minimal images, secrets management,
least privilege, pipeline and runtime controls.
ICS / IoT / embedded Safety, long lifecycles, weak patching, protocol
constraints
Segmentation, allowlisting, monitoring, vendor
coordination, safe change windows.
Microservices / APIs Service-to-service trust, excessive exposure,
secrets
Strong identity, authorization, schema/input validation,
rate limits, observability, segmentation.
3.6 Cryptographic solutions
Select cryptography by security objective, data state, key lifecycle, performance, interoperability, and threat model. Symmetric
crypto is efficient for bulk data; asymmetric crypto supports key exchange/signatures; hashes detect change; MAC/HMAC adds
keyed integrity/authentication; digital signatures provide integrity, origin authentication, and potential nonrepudiation. PKI binds
identity to public keys through certificates and trust chains. Key generation, storage, rotation, escrow/recovery, revocation, and
destruction are as important as the algorithm.
Need Best-fit primitive Remember
Fast confidential bulk data Symmetric encryption (e.g., AES) Protect the key; encryption does not prove sender
identity.
Study guide - use the official ISC2 outline as the final authority 8CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Need Best-fit primitive Remember
Integrity only Cryptographic hash Anyone can recompute an unkeyed hash.
Integrity + shared-key authenticity HMAC / MAC No nonrepudiation because both sides know the
secret.
Integrity + signer evidence Digital signature Private key signs; public key verifies; certificate helps
bind key to identity.
Secure key exchange Asymmetric mechanism / authenticated key
exchange
Authenticate peers to resist MITM.
3.7 Cryptanalytic and implementation attacks
Recognize brute force, ciphertext-only, known-plaintext, frequency analysis, chosen-ciphertext, implementation, side-channel,
fault injection, timing, MITM, pass-the-hash, Kerberos exploitation, and ransomware. Strong algorithms can fail through weak
keys, bad implementations, inadequate validation, exposed secrets, or poor operations.
3.8 Site and facility design
Apply layered physical security: site selection, setbacks, zoning, controlled entry/exit, utility protection, environmental design,
safety, and resilience. Consider how a building and its critical services support the business recovery strategy.
3.9 Facility security controls
Protect wiring closets, data centers, media/evidence storage, restricted/work areas, HVAC, utilities, fire
prevention/detection/suppression, and redundant/backup power. Know fire classes and suppression trade-offs conceptually:
safety, damage, and environmental impact must be considered.
3.10 Information system lifecycle
Manage stakeholder needs, requirements, architecture, development/implementation, integration, verification/validation,
deployment, operations/maintenance, and retirement/disposal. Security gates and acceptance criteria should exist across the
lifecycle, not only at launch.
ARCHITECTURE DECISION RULE
Start with the asset and security requirement. Then model threats and trust boundaries. Finally choose layered controls with a
named owner and an operational plan. A clever control with no lifecycle or monitoring plan is incomplete.
Study guide - use the official ISC2 outline as the final authority 9CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 4 | 13% OF EXAM
Communication and Network Security
Instructor lens: Understand data flow, trust boundaries, protocol layers, segmentation, secure components, and secure channels
- then choose controls that protect both confidentiality and availability.
4.1 Secure network architecture
Apply OSI and TCP/IP concepts, IPv4/IPv6 addressing and delivery modes, secure protocols, multilayer implications, converged
protocols, topology/planes, performance, traffic flows, segmentation, edge/wireless/mobile/CDN/SDN/VPC, and network
observability. Design assumes the network is hostile until identity, authorization, and encrypted communication establish trust.
Layer / concept Why it matters Security cue
OSI L2: Data link Frames, MAC addresses, switching VLANs separate broadcast domains but are not a complete
security boundary.
OSI L3: Network IP routing and addressing Use routing controls, ACLs, segmentation, anti-spoofing,
secure management.
OSI L4: Transport TCP/UDP ports and sessions Stateful filtering and secure service exposure; TCP is
connection-oriented.
OSI L5-L7 Sessions, presentation, application TLS, application authentication/authorization, proxy/WAF,
protocol validation.
Control / data /
management plane
Decision, forwarded traffic, administration Protect management separately; compromise here can
control the whole network.
4.1a Segmentation and traffic flow
Use physical segmentation (in-band/out-of-band/air-gapped), logical segmentation (VLAN, VPN, VRF, virtual domain), and
micro-segmentation (overlays, distributed enforcement, zero trust). North-south traffic enters/leaves a data center or
environment; east-west traffic moves laterally. An air gap reduces paths but is not absolute protection against media, insiders, or
wireless leakage.
4.1b Modern networks
Secure wireless (Wi-Fi/Bluetooth/Zigbee/satellite), cellular 4G/5G, CDN, SDN/SD-WAN/NFV, and VPC services through strong
identity, encryption, segmentation, secure APIs/control plane, configuration management, and monitoring. Observe bandwidth,
latency, jitter, throughput, and signal-to-noise because availability depends on performance and capacity.
4.2 Secure network components
Secure infrastructure operation (redundant power, warranty/support), transmission media (physical protection and signal quality),
NAC, and endpoint controls. Components require hardening, secure administration, patching, logging, redundancy, baselines,
and lifecycle management.
4.3 Secure communication channels
Implement channels according to design for voice/video/collaboration, remote access/administration, data
communications/backhaul/satellite, and third-party connectivity. Authenticate endpoints, encrypt in transit, minimize exposure,
segment partners, manage keys/certificates, monitor, and define contractual responsibility.
Protocol / mechanism Use CISSP-level distinction
TLS Protects many application sessions in
transit
Validate certificate chain/hostname; TLS is not a substitute for
application authorization.
IPsec Protects IP traffic - tunnel or transport mode Tunnel mode encapsulates the original packet; commonly used
for site-to-site/remote VPN designs.
SSH Secure remote administration / tunneling Use strong key management and restrict administrative access.
Study guide - use the official ISC2 outline as the final authority 10CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Protocol / mechanism Use CISSP-level distinction
VPN Encrypted logical connection across an
untrusted network
Provides a channel; endpoint compromise and overbroad access
remain risks.
NAC Admits/restricts endpoints based on
identity/posture
A control point, not an endpoint-security replacement.
EXAM LENS
Network questions often hide a trust-boundary problem. Favor segmentation, authenticated encryption, controlled management
access, least privilege, and monitoring over a single perimeter-only solution.
Study guide - use the official ISC2 outline as the final authority 11CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 5 | 13% OF EXAM
Identity and Access Management (IAM)
Instructor lens: Identity is the control plane for people, services, devices, applications, and facilities. Prove identity, decide
entitlement, enforce it, and remove it on time.
5.1 Control physical and logical access
Control access to information, systems, devices, facilities, applications, and services using authorization, authentication,
accountability, monitoring, and physical safeguards. Converge physical and logical identity only where governance, privacy, and
operational needs support it.
5.2 Identification and authentication strategy
Design for people, devices, and services using groups/roles, AAA, MFA/passwordless approaches, session management,
registration/proofing, federation, credential/vault management, SSO, and just-in-time access. Authentication factors are
something you know, have, are, do, and somewhere you are; two passwords are not MFA because they are the same factor
category.
Term Question it answers Example
Identification Who do you claim to be? Username, device identity, service principal.
Authentication Can you prove that claim? FIDO key plus biometric/local PIN; client certificate.
Authorization What may you do now? Role/attribute/policy grants read access to a dataset.
Accounting What did you do? Protected, reviewed audit trail tied to a unique identity.
5.3 Third-party federation
Federate identity across on-premises, cloud, and hybrid environments. Understand trust, identity proofing, assertion/token
lifecycle, attribute release, availability, logging, vendor risk, deprovisioning, and privacy. Federation reduces password sprawl but
concentrates trust and outage impact.
5.4 Authorization mechanisms
Compare RBAC (job roles), rule-based (system rules), MAC (centrally enforced labels/clearance), DAC (owner discretion),
ABAC (attributes and policy), and risk-based/adaptive access. Policy decision points evaluate policy; policy enforcement points
apply the decision. Use least privilege, need-to-know, separation of duties, and a denial-by-default posture.
Model Strength Watch for
DAC Flexible owner sharing Permission sprawl; owners can grant too broadly.
MAC Strong centralized confidentiality labels Rigidity; users cannot freely change labels/permissions.
RBAC Scales to stable job functions Role explosion when exceptions proliferate.
ABAC Fine-grained, contextual decisions Attribute quality, policy complexity, and explainability.
Risk/adaptive Responds to context/anomaly Should augment governance, not become opaque denial
without support process.
5.5 Provisioning lifecycle
Manage account reviews, provisioning/deprovisioning, role transitions, privileged escalation (such as sudo with auditing), and
service accounts. Automate joiner-mover-leaver workflow where feasible; every high-risk entitlement should have an owner,
approval, duration, logging, and periodic review.
Study guide - use the official ISC2 outline as the final authority 12CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
5.6 Authentication systems
Implement authentication safely: secure enrollment, protect credentials/secrets, resist phishing and replay, use rate
limiting/lockout carefully, manage sessions/tokens, offer recovery without bypassing assurance, and log events. Password vaults
protect shared/admin secrets but require access governance and auditing.
IAM RAPID RECALL
Authentication is not authorization. A group is not automatically a role. Federation is a trust relationship. Service accounts are
identities with access and need lifecycle, ownership, rotation, and monitoring just like human accounts.
Study guide - use the official ISC2 outline as the final authority 13CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 6 | 12% OF EXAM
Security Assessment and Testing
Instructor lens: Assurance is evidence. Scope, authorize, test, interpret results honestly, report risk clearly, and validate
remediation.
6.1 Assessment, test, and audit strategy
Design and validate strategies appropriate to internal, external, third-party, and on-premises/cloud/hybrid environments. Define
objective, scope, rules of engagement, authorization, safety, data handling, test depth, independence, reporting, and follow-up.
Independence improves credibility; it does not remove the need for cooperation.
6.2 Security control testing
Use vulnerability assessment, penetration testing, log review, synthetic transactions/benchmarks, code review/testing,
misuse-case tests, coverage analysis, interface testing, breach attack simulations, and compliance checks. Each answers a
different question; a vulnerability scan does not prove exploitability, and a penetration test does not prove complete assurance.
Activity Primary purpose Boundary
Vulnerability assessment Find known weaknesses/misconfigurations Broad and repeatable; may generate false positives
and does not require exploitation.
Penetration test Demonstrate exploitable paths and impact Needs written rules of engagement, scope, timing,
and safety constraints.
Audit Evaluate conformance/control evidence Focuses on criteria and evidence; auditor
independence matters.
Red / blue / purple exercise Exercise offense, defense, and collaborative
improvement
Measure detection/response learning, not merely
whether a tool alerts.
Breach attack simulation Continuously emulate selected attacker techniques Complements, not replaces, threat modeling and
human review.
6.3 Security process data
Collect technical and administrative evidence: account management, management review/approval, KPIs/KRIs, backup
verification, awareness results, and BC/DR evidence. Data should be accurate, protected, attributable, timely, relevant, and
retained according to requirements.
6.4 Analyze and report
Analyze output in context, distinguish findings from risk, prioritize remediation, manage exceptions with an owner and expiry, and
follow ethical disclosure. A useful report explains scope, method, evidence, impact, likelihood, affected asset, recommendation,
risk rating/assumptions, management response, and re-test result.
6.5 Security audits
Conduct or facilitate internal, external, and third-party audits across on-premises/cloud/hybrid environments. Prepare evidence,
confirm criteria and scope, preserve independence, remediate findings, and track closure. Do not conceal, alter, or selectively
withhold material evidence.
EXAM LENS
Before testing, obtain explicit authorization and define scope and rules of engagement. After testing, protect evidence, report
accurately, obtain accountable remediation or risk acceptance, and verify closure.
Study guide - use the official ISC2 outline as the final authority 14CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 7 | 13% OF EXAM
Security Operations
Instructor lens: Operations turns plans into reliable daily protection: evidence, logs, configuration, incident handling, recovery,
physical controls, and people safety.
7.1 Investigations
Comply with investigation requirements for evidence collection/handling, reporting/documentation, techniques, forensics
tools/TTPs, and artifacts from data, computer, network, and mobile sources. Preserve chain of custody: identify, collect, preserve,
document, transfer, analyze, and present evidence in a defensible manner. Use write blockers and verified copies where
appropriate.
7.2 Logging and monitoring
Operate IDPS, SIEM, continuous monitoring/tuning, egress monitoring, log management, threat intelligence/hunting, and UEBA.
Effective logging needs synchronized time, adequate retention, integrity, relevant sources, meaningful alerts, owners,
documented response, and regular tuning to control noise and blind spots.
7.3 Configuration management
Use controlled provisioning, approved secure baselines, versioned configuration, change records, automation, drift detection,
testing, rollback, and asset linkage. Configuration management makes the known-good state visible and recoverable.
7.4 Foundational operations
Enforce need-to-know/least privilege, separation of duties/responsibilities, privileged account management, job rotation, and
service-level agreements. Job rotation and mandatory vacation can detect fraud; they do not replace access controls or
monitoring.
7.5 Resource protection
Protect media and data at rest/in transit using appropriate classification, storage, transport, inventory, encryption/key protection,
environmental safeguards, retention, sanitization, and destruction. Media management includes both availability and
confidentiality.
7.6 Incident management
Conduct detection, response, mitigation, reporting, recovery, remediation, and lessons learned. Tailor playbooks by incident type
and authority. Preserve evidence and coordinate legal, privacy, HR, leadership, communications, and providers as needed.
Containment should be proportionate and reversible where possible without allowing continued harm.
IR phase Goal Typical outcome
Preparation People, authority, tools, playbooks, contacts,
baselines
Ready team and tested procedures.
Detection / analysis Validate event, scope, severity, and impact Incident classification and decisions based on
evidence.
Containment Limit harm while preserving options/evidence Segmented host, blocked indicator, controlled
account action.
Eradication / recovery Remove cause; restore safely Cleaned systems, rotated credentials, validated
service restoration.
Lessons learned Improve controls, process, and resilience Tracked actions; not just a meeting or blame
exercise.
Study guide - use the official ISC2 outline as the final authority 15CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
7.7 Detection and prevention measures
Operate and maintain firewalls (NGFW/WAF/network), IDS/IPS, allow/deny lists, third-party security services, sandboxing,
honeypots/honeynets, anti-malware, and ML/AI-based tools. Know their limits: prevention can fail, detection needs tuning, and AI
outputs need validation, data governance, and human accountability.
7.8 Patch and vulnerability management
Inventory, discover, prioritize by exploitability and business impact, test, schedule, deploy, verify, document
exceptions/compensating controls, and report residual risk. A CVSS score is an input; active exploitation, exposure, asset
criticality, and available mitigation drive priority.
7.9 Change management
Submit, assess risk/impact, approve, test, schedule, implement, document, verify, and provide rollback/emergency procedures.
Emergency change is an expedited controlled process, not permission to skip accountability.
7.10 Recovery strategies
Use appropriate backup storage (cloud/onsite/offsite), recovery sites (cold/warm/hot), capacity agreements, multiple processing
sites, resilience, HA, QoS, and fault tolerance. Backups need restore tests, isolation/immutability where risk warrants, protection
from the same failure mode, and sufficient RPO/RTO alignment.
Recovery option Readiness Cost / recovery profile
Cold site Facility/infrastructure, little or no live
equipment/data
Lowest cost; longest recovery and setup time.
Warm site Some equipment/connectivity and perhaps
replicated data
Middle cost and recovery time.
Hot site Ready facility/systems with current or near-current
Highest cost; fastest planned recovery.
data
Active-active / multiple sites Concurrent processing and distribution Strong resilience but complexity and
data-consistency design matter.
7.11 Disaster recovery processes
Implement response, personnel coordination, communications, assessment, restoration, training/awareness, and lessons
learned. DR follows business priorities established through BIA and BC planning; technical restoration is not successful until the
business accepts service recovery.
7.12 Test DR plans
Progress from read-through/tabletop, walkthrough, simulation, parallel, to full interruption. Test communications with
stakeholders, status reporting, and regulators as applicable. A full interruption is most realistic and usually carries the most
business risk; select test depth based on risk and authorization.
7.13 Business continuity exercises
Participate in BC planning and exercises that sustain critical operations, people, alternate processes, suppliers, facilities,
communications, and customer commitments. BC and DR must be integrated but are not synonyms.
7.14 Physical security
Implement perimeter and internal controls: deterrence, delay, detection, access control, surveillance, visitor management, guards,
lighting, locks, mantraps, alarms, and response. Layer controls so detection and response can occur before an adversary reaches
critical assets.
7.15 Personnel safety and security
Address travel, training/awareness, insider threat, social-media impact, MFA fatigue, emergency management, and duress. In an
emergency, life safety takes precedence over asset protection; security decisions should account for human welfare and clear
communications.
Study guide - use the official ISC2 outline as the final authority 16CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
OPERATIONS DECISION RULE
Preserve evidence, follow authority, scope the incident, contain proportionately, communicate through the plan, and return to a
known-good state. Never assume a tool alert proves compromise, and never declare recovery without validation.
Study guide - use the official ISC2 outline as the final authority 17CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DOMAIN 8 | 10% OF EXAM
Software Development Security
Instructor lens: Secure software is a lifecycle and supply-chain discipline. Create secure requirements, build and test with
guardrails, measure evidence, and control acquired components.
8.1 Security in the SDLC
Integrate security throughout Agile, Waterfall, DevOps, DevSecOps, SAFe, operation/maintenance, change management, and
integrated product teams. Use maturity models such as CMM and SAMM to improve repeatability. Security work includes
requirements, architecture/threat modeling, secure design, code, review, testing, release, monitoring, and retirement.
8.2 Controls in development ecosystems
Protect programming languages, libraries, tools, IDEs, runtime, CI/CD, configuration management, code repositories, and
application-security testing. Establish secure build provenance, branch protections, code review, least privilege for pipelines,
secrets handling, dependency governance, signed artifacts, separated environments, and logging.
Technique Where it sees risk Key limitation
SAST Source/bytecode before running Can produce false positives; cannot fully see
runtime/configuration behavior.
DAST Running application from outside Finds observable runtime issues; limited code-path
coverage and needs a testable app.
IAST Instrumented app while it runs Can give contextual findings; needs runtime
instrumentation/coverage.
SCA Third-party libraries/dependencies Identifies known component risk; must also manage
version use, reachability, licenses, and remediation.
Manual review Business logic/design and nuanced code Deep but time-intensive; prioritize high-risk paths.
8.3 Effectiveness of software security
Assess through audit/logging of changes, risk analysis and mitigation, coverage/evidence, testing results, remediation, metrics,
and independent review. A passing pipeline is evidence of defined checks, not proof that software is risk-free.
8.4 Acquired software
Assess COTS, open source, third-party, managed services, and SaaS/IaaS/PaaS for security impact. Evaluate supplier security,
support lifecycle, vulnerabilities, licensing, data handling, integrations/APIs, contract/SLA, change notice, audit rights, secure
configuration, exit/portability, and dependency provenance.
8.5 Secure coding guidelines and standards
Apply source-level practices: validate input, encode output, use parameterized queries, strong
authentication/authorization/session handling, safe error handling, memory-safe techniques, secure cryptographic APIs, secrets
management, logging without sensitive leakage, and API security. Understand software-defined security: security logic itself
needs change control, review, testing, and least-privilege execution.
Weakness pattern Safer pattern
Untrusted input used directly Allowlist validation, type/length/range checks, parameterized interfaces, safe parsing.
Authorization checked only in UI Server-side authorization at every protected action/object; deny by default.
Secrets in source/config/logs Central secrets management, rotation, least privilege, redaction, repository scanning.
Dependency assumed trustworthy Inventory/SBOM, SCA, trusted sources, version control, vulnerability and license response.
Security test only before release Automated and manual checks throughout development plus runtime monitoring and
feedback.
Study guide - use the official ISC2 outline as the final authority 18CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
DEVSECOPS EXAM LENS
Move security earlier, automate repeatable checks, protect the pipeline and dependencies, preserve accountable human review
for high-risk decisions, and keep evidence of change and approval.
Study guide - use the official ISC2 outline as the final authority 19CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Cross-domain comparison sheet
Use these distinctions to eliminate attractive but wrong answers. The right control is the one that meets the stated security
objective in the scenario’s time, authority, and business context.
Do not confuse... With... Distinction
BC DR BC sustains critical business operations; DR restores IT capabilities
supporting them.
BIA Risk assessment BIA determines business impact and recovery priorities; risk assessment
analyzes threats/vulnerabilities and treatment.
Due care Due diligence Care is reasonable protective action; diligence is investigation/validation
that supports that action.
Data owner Custodian Owner defines classification/handling; custodian implements and
operates protection.
Authentication Authorization Authentication proves identity; authorization evaluates permission.
IDS IPS IDS detects/alerts; IPS can actively block/prevent, with risk of
false-positive disruption.
Hash Digital signature Hash detects change; signature uses private-key signing/public-key
verification and can support nonrepudiation.
Vulnerability scan Penetration test Scan identifies potential weaknesses; pen test demonstrates selected
exploit paths under authorization.
Hot site High availability A hot site is a recovery-site strategy; HA is design to reduce/prevent
downtime during component failure.
Policy Procedure Policy sets management direction; procedure gives repeatable
implementation steps.
AI and emerging technology checklist
Question Apply across domains
What asset is it? Training data, model weights, prompts, identities, API tokens, compute, logs, outputs, and vendor service
may each need classification and ownership.
What can go wrong? Bias, privacy disclosure, data/model poisoning, adversarial inputs, insecure tools/plugins, supply chain
compromise, excessive agent permissions, hallucinated output, and availability/cost abuse.
What controls fit? Governance and lawful use; data minimization; secure SDLC; vendor due diligence; IAM/least privilege;
input/output controls; logging; human oversight; testing/red teaming; incident and recovery plans.
Who is accountable? Business/risk/data/model owners and authorized leaders - not an opaque automated system.
DON'T MEMORIZE IN ISOLATION
CISSP scenarios cross domains. For example, an exposed cloud database is simultaneously an asset classification,
architecture/configuration, IAM, network, monitoring, vendor, incident-response, and governance problem. Answer from the
decision point the question asks for.
Study guide - use the official ISC2 outline as the final authority 20CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Cycle | What to do | Evidence you are ready |
1. Map | Read each published objective and mark unfamiliar terms. Use the domain weights to allocate time, but do not neglect a weak domain. | You can state what each objective is trying to protect. |
2. Explain | For every table and callout, make a one-sentence explanation and a small workplace example from memory. | You distinguish terms without relying on buzzwords. |
3. Apply | Practice authorized, reputable scenario questions. For each mistake, write the objective, decision point, why the distractor was tempting, and the governing principle. | Your error log becomes smaller and more specific. |
4. Integrate | Practice cross-domain scenarios: cloud change, suspected breach, supplier acquisition, application release, and data-retention problem. | You identify ownership, risk, control, evidence, and recovery implications. |
5. Verify | Before booking or final revision, compare your study map to the current official ISC2 outline and exam information. | No current objective is unaddressed; logistics are confirmed from ISC2. |
Final preparation plan
Use this guide to turn knowledge into retrieval and judgment. The goal is not to memorize an answer key; it is to explain why the
best answer protects the business while following governance and sound security engineering.
A simple exam-reading routine
1. Read the final question sentence first: is it asking for FIRST, BEST, MOST likely, or a technical mechanism? 2. Identify the
asset, security objective, authority, and time horizon. 3. Notice whether the scenario is before an event, during response, or after
discovery. 4. Eliminate choices that skip governance, violate law/ethics, use the wrong owner, or solve a different problem. 5.
Select the most complete answer that fits the stated constraints - then move on.
EXAM-DAY MINDSET
You are the senior security professional, not a tool operator. Protect people and the mission, make a risk-based and defensible
decision, involve the right authority, and preserve the ability to investigate and recover.
Study guide - use the official ISC2 outline as the final authority 21CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024
Scope, sources, and update note
This study guide is an independent instructional work. It summarizes and explains the publicly available CISSP syllabus; it does
not reproduce exam items, promise a result, or replace official ISC2 materials. Exam content and policies may change. Always
confirm the current outline before your exam.
Primary official source
Source How it was used
ISC2 CISSP Certification Exam Outline, effective
April 15, 2024
All eight domain names, weights, published objectives, and current technology
examples were mapped to the domain sections in this guide.
ISC2 CISSP Exam Outline Summary / Exam
Information
Used for current public exam context and the instruction to use the official outline to
target study.
ISC2 Exam Weighting change notice (Nov. 2023) Used only to identify that Domain 1 weight changed to 16% and Domain 8 to 10% in the
April 2024 refresh.
Human-readable links
https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline
Official detailed content outline PDF (ISC2)
ISC2: Changes to CISSP Exam Weighting
Prepared August 2026. The “recent-outline readiness” notes are instructional synthesis based on the current public ISC2 outline
and published cross-domain AI guidance. They are not claims about unreleased or recalled exam content.
End of guide