Wednesday, 16 September 2026

Study Guide for CISSP Exam 2026

 How to use this guide

CISSP questions reward sound security leadership judgment: protect the mission, establish governance, understand risk,

respect process and law, and choose a control that is feasible, proportional, and owned. Technical knowledge matters; it is

usually the evidence used to make a better managerial decision.

THE STUDY CONTRACT

The official ISC2 CISSP Certification Exam Outline is the source of truth for scope. This guide maps every published objective

into plain language and adds instructor commentary. Verify current registration, format, policies, and objectives against ISC2

before scheduling.

The eight-domain map

Domain 

Weight 

Primary question

1. Security and Risk Management 

16% 

Are we governing risk, people, law, and continuity correctly?

2. Asset Security 

10% 

What is the asset, who owns it, and how should it be handled?

3. Security Architecture and Engineering 

13% 

What secure design and technical mechanism fits the requirement?

4. Communication and Network Security 

13% 

How does information flow securely and resiliently?

5. Identity and Access Management 

13% 

Who/what gets access, to what, under which policy?

6. Security Assessment and Testing 

12% 

How do we obtain reliable assurance and report it?

7. Security Operations 

13% 

How do we monitor, respond, recover, and operate safely?

8. Software Development Security 

10% 

How do we build, buy, and operate trustworthy software?



When the question asks... 

Usually prioritize...

FIRST / BEST / MOST appropriate 

The earliest governance, risk, validation, or authorization step that safely resolves the decision.

Management response 

Business alignment, policy, ownership, risk acceptance/escalation, and defensible process.

Technical containment 

Preserve evidence and scope impact; do not destroy evidence or skip authorization.

Control selection 

The objective, the asset classification, the threat, and the least intrusive effective control.

Legal or privacy issue 

Jurisdiction, contractual duties, counsel, and documented evidence handling; do not guess.


A reliable question-ordering method

Do not turn these into absolute rules. Read constraints in the scenario: a life-safety emergency, confirmed active harm, legal

order, or explicitly delegated authority can change the immediate action.

Study guide - use the official ISC2 outline as the final authority 2CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

CISSP vocabulary and decision anchors

Anchor Meaning to retain

Due care Acting as a prudent organization should to protect assets and meet obligations. Think: reasonable

safeguards and oversight.

Due diligence Investigating, assessing, and validating before and while acting. Think: evidence that care was exercised.

Risk owner The accountable business authority who decides whether residual risk is accepted, transferred, avoided, or

mitigated.

Data owner Classifies data and defines business handling requirements. A custodian implements the owner’s direction.

Policy / standard / procedure /

guideline

Policy says what and why; standard sets mandatory uniform requirements; procedure tells how; guideline is

recommended flexibility.

Preventive / detective /

corrective

Stop; discover; restore or reduce impact. Deterrent, compensating, directive, and recovery are other useful

classifications.

Defense in depth Layer independent controls so a single failure does not produce unacceptable loss.

Least privilege Give only the minimum access, scope, and duration needed to perform an authorized task.

Term 

Formula / interpretation

SLE 

Single Loss Expectancy = Asset Value x Exposure Factor. Expected loss from one event.

ARO 

Annualized Rate of Occurrence. Expected frequency per year.

ALE 

Annualized Loss Expectancy = SLE x ARO. Use with judgment; qualitative risk can be better when inputs are

uncertain.

RTO 

Recovery Time Objective: maximum acceptable time to restore a process/service after disruption.

RPO 

Recovery Point Objective: maximum tolerable amount of data loss measured in time.

MTD / MAO 

Maximum Tolerable Downtime / Maximum Acceptable Outage: the outer business limit. RTO should be within it.


Calculation essentials

RECENT-OUTLINE READINESS

The current official outline embeds cloud, containers, serverless, zero trust, SASE, API security, AI/ML, 5G, SDN, and modern

development ecosystems across domains. Learn the enduring security principle first, then apply it to the technology context.

Study guide - use the official ISC2 outline as the final authority 3CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 1 | 16% OF EXAM

Security and Risk Management

Instructor lens: This is the managerial backbone of CISSP. Start with mission, ownership, law, ethics, and risk before selecting

technology.

1.1 Professional ethics

Know the ISC2 Code of Professional Ethics and your organizational code. Protect society, act honorably and honestly, provide

diligent service to principals, and advance the profession. Ethics can require escalation even when it is inconvenient.

EXAM LENS

When legal, business, and technical pressures conflict, choose the action that is lawful, honest, protects the public, and uses

appropriate authority or escalation.

1.2 Security concepts: the five pillars

Confidentiality limits unauthorized disclosure; integrity prevents or detects unauthorized change; availability ensures timely

reliable access; authenticity establishes genuineness; nonrepudiation provides strong evidence that a party performed an

action. Match the control to the harmed property.

Property Typical mechanisms Common confusion

Confidentiality Encryption, access control, need-to-know Encryption does not automatically provide integrity or

availability.

Integrity Hash/MAC, digital signature, change control A hash alone detects change but does not authenticate the

origin.

Availability Redundancy, capacity, backups, DR A backup is not availability until restoration is feasible and

tested.

Authenticity Certificates, MFA, validated identity Authentication proves a claim; authorization decides

permissions.

Nonrepudiation Digital signatures, protected audit trails Shared accounts and weak key control undermine attribution.

1.3 Security governance

Align the security program to business strategy, mission, objectives, organizational processes, roles, and control frameworks.

Governance assigns accountability, directs risk decisions, measures results, and supports acquisition/divestiture and committee

decisions. Know ISO, NIST, COBIT, SABSA, PCI, and FedRAMP as framework examples; do not treat a framework as a control

by itself.

EXAM LENS

The senior answer establishes ownership and risk-based direction before deploying a tool. Due care is acting prudently; due

diligence is investigating and validating prudently.

1.4 Legal, regulatory, and compliance context

Recognize cybercrime/breach duties, licensing and intellectual property, import/export restrictions, transborder data flows,

privacy, contracts, regulations, and industry standards. Requirements vary by jurisdiction and contract; involve qualified counsel

and the privacy/legal function rather than interpreting law alone.

Study guide - use the official ISC2 outline as the final authority 4CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

1.5 Investigation requirements

Different investigations have different rules: administrative (policy/workplace), criminal (law enforcement and high evidentiary

burden), civil (litigation), regulatory, and standards-based. Determine authority, scope, preservation, notice, documentation, and

chain of custody before collecting evidence.

1.6 Policy hierarchy

Develop, document, implement, communicate, and enforce policy, standards, procedures, and guidelines. A policy must be

approved by the right authority, practical, measurable, reviewed, and supported by enforcement and exception management.

EXAM LENS

If a question describes inconsistent actions, the answer is often to establish or enforce a policy/standard, then create procedures

and training - not to buy a product first.

1.7 Business continuity requirements

Use a business impact analysis (BIA) to identify critical processes, impacts over time, dependencies, recovery priorities,

RTO/RPO/MAO, and resource requirements. External dependencies include cloud, suppliers, utilities, people, facilities, and

telecoms. BC sustains the business; DR restores technology.

1.8 Personnel security

Apply screening and hiring practices, agreements, onboarding, transfers, termination, contractor/vendor controls, separation of

duties, acceptable use, and awareness. The highest-risk access changes often occur at joiner-mover-leaver events; ensure rapid,

verified deprovisioning.

1.9 Risk management

Identify assets, threats, vulnerabilities, likelihood, and impact; analyze and prioritize; select treatment; implement and assess

controls; continuously monitor and report. Treatments are avoid, mitigate, transfer, or accept. Risk acceptance belongs to the

authorized risk owner, not the security team.

Analysis type Use Caution

Qualitative Ranks likelihood/impact using categories; fast and

useful where data are weak.

Subjective scales require clear definitions and

calibration.

Quantitative Uses financial estimates, SLE/ARO/ALE; supports

cost-benefit comparisons.

False precision is dangerous if asset values or rates

are speculative.

Hybrid Uses data where credible and qualitative rankings

elsewhere.

Document assumptions and residual risk.

1.10 Threat modeling

Model how a system can be harmed before it is built or changed: identify assets, trust boundaries, actors, attack surfaces, threats,

mitigations, and residual risk. STRIDE is a common mnemonic: spoofing, tampering, repudiation, information disclosure, denial of

service, elevation of privilege.

1.11 Supply chain risk management (SCRM)

Manage supplier and provider risk across acquisition, delivery, operation, and disposal. Consider tampering, counterfeits,

implants, vulnerable dependencies, service concentration, code provenance, contractual SLAs, audit rights, SBOMs, incident

notification, and exit plans.

1.12 Awareness, education, and training

Build role-appropriate, repeated learning that addresses social engineering, phishing, security champions, gamification, emerging

technologies such as AI/blockchain/cryptocurrency, and measured effectiveness. Awareness changes behavior; education builds

knowledge; training builds a specific skill.

DOMAIN 1 RAPID RECALL

Study guide - use the official ISC2 outline as the final authority 5CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Business owns risk; security advises and enables. BIA precedes recovery design. Counsel guides legal interpretation. Policy

directs; procedures execute. A control is justified by risk, not by fashion.

Study guide - use the official ISC2 outline as the final authority 6CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 2 | 10% OF EXAM

Asset Security

Instructor lens: Find the information, establish its business value and owner, protect it throughout its lifecycle, and dispose of it

defensibly.

2.1 Identify and classify information and assets

Build an inventory of tangible and intangible assets: data, systems, software, models, credentials, media, intellectual property,

and cloud resources. Classification reflects business impact if confidentiality, integrity, or availability is compromised. The data

owner assigns classification; labels and handling rules make the classification operational.

2.2 Information and asset handling

Define handling for creation, collection, labeling, storage, transmission, use, sharing, copying, retention, and destruction.

Requirements should follow classification and contractual/regulatory obligations, including approved locations, encryption,

access, and media controls.

2.3 Secure provisioning

Provision assets through controlled acquisition and registration: name an owner/custodian, record the asset, apply baseline

configuration, classification and access requirements, validate supply/source, and establish support/EOL information. Shadow IT

is an asset-management and governance problem as much as a technical one.

2.4 Data lifecycle and roles

Manage data from collection to destruction. Distinguish roles: owner defines classification/use; controller determines

purpose/means of processing; processor processes for the controller; custodian administers protection; data subject is the

person the personal data concerns. Minimize collection, maintain accuracy, control location, retain only as required, and destroy

correctly.

2.5 Retention, EOL, and EOS

Retain information and assets only for a defined legal, business, and operational period. Account for End of Life (vendor no longer

sells) and End of Support (no fixes/support): inventory, assess exposure, migrate, isolate/compensate, and dispose when

justified.

2.6 Data security controls and compliance

Select controls by state (at rest, in transit, in use), classification, processing location, threats, and obligations. Scope and tailor

standards to the system. Use protection approaches such as DRM, DLP, CASB, encryption, tokenization, segmentation, and

logging, but validate effectiveness and fit.

Data state Primary concern Useful controls

At rest Stored copies, media loss, unauthorized reads Encryption, key management, access control,

retention/destruction, backup safeguards.

In transit Interception, tampering, endpoint authenticity TLS/IPsec, mutual authentication, VPN, secure protocols,

integrity protection.

In use Memory, screen, process, privileged misuse Least privilege, isolation, confidential computing where suitable,

session controls, monitoring.

EXAM LENS

If two answers sound technical, ask first: who owns the data and what is its classification? The owner establishes requirements;

the custodian implements them. Deleting a file is not secure sanitization if recoverable remnants remain.

Study guide - use the official ISC2 outline as the final authority 7CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 3 | 13% OF EXAM

Security Architecture and Engineering

Instructor lens: Translate security requirements into resilient architecture. Know why a mechanism works, its assumptions, its

failure modes, and its lifecycle.

3.1 Secure design principles

Use threat modeling, least privilege, defense in depth, secure defaults, fail securely, separation of duties, simplicity, zero

trust/trust-but-verify, privacy by design, shared responsibility, and SASE. Design security in from requirements through retirement;

do not bolt it on at the end.

3.2 Security models

Bell-LaPadula protects confidentiality: no read up, no write down. Biba protects integrity: no read down, no write up. The

Clark-Wilson model focuses on well-formed transactions, separation of duties, and integrity verification. Brewer-Nash (Chinese

Wall) prevents conflict-of-interest access. The star property is part of Bell-LaPadula’s confidentiality control.

3.3 Control selection from requirements

Derive administrative, technical, and physical controls from clear security requirements and risk. Consider effectiveness,

assurance, usability, cost, interoperability, maintenance, and residual risk. Compensating controls address a gap where the

preferred control is infeasible.

3.4 Information system security capabilities

Understand trusted computing concepts and mechanisms: memory protection and process isolation, privilege rings/modes,

TPM/secure boot, encryption/decryption, virtualization boundaries, auditing, and reference-monitor characteristics (always

invoked, tamperproof, small enough to verify).

3.5 Architecture vulnerability assessment

Assess and mitigate vulnerabilities in client/server/database/cryptographic/ICS/cloud/distributed/IoT/microservices/container/serv

erless/embedded/HPC/edge/virtualized systems. Apply the shared responsibility model exactly: cloud providers secure defined

portions of the service; customers remain responsible for identity, data, configuration, and many workload controls.

Architecture Risk focus Security response

Cloud / SaaS Misconfiguration, identity, data residency, opaque

provider layers

Clarify shared responsibility; enforce IAM, contractual

controls, encryption, logs, and configuration governance.

Containers / serverless Image/dependency risk, runtime permissions,

ephemeral observability

Trusted artifacts, minimal images, secrets management,

least privilege, pipeline and runtime controls.

ICS / IoT / embedded Safety, long lifecycles, weak patching, protocol

constraints

Segmentation, allowlisting, monitoring, vendor

coordination, safe change windows.

Microservices / APIs Service-to-service trust, excessive exposure,

secrets

Strong identity, authorization, schema/input validation,

rate limits, observability, segmentation.

3.6 Cryptographic solutions

Select cryptography by security objective, data state, key lifecycle, performance, interoperability, and threat model. Symmetric

crypto is efficient for bulk data; asymmetric crypto supports key exchange/signatures; hashes detect change; MAC/HMAC adds

keyed integrity/authentication; digital signatures provide integrity, origin authentication, and potential nonrepudiation. PKI binds

identity to public keys through certificates and trust chains. Key generation, storage, rotation, escrow/recovery, revocation, and

destruction are as important as the algorithm.

Need Best-fit primitive Remember

Fast confidential bulk data Symmetric encryption (e.g., AES) Protect the key; encryption does not prove sender

identity.

Study guide - use the official ISC2 outline as the final authority 8CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Need Best-fit primitive Remember

Integrity only Cryptographic hash Anyone can recompute an unkeyed hash.

Integrity + shared-key authenticity HMAC / MAC No nonrepudiation because both sides know the

secret.

Integrity + signer evidence Digital signature Private key signs; public key verifies; certificate helps

bind key to identity.

Secure key exchange Asymmetric mechanism / authenticated key

exchange

Authenticate peers to resist MITM.

3.7 Cryptanalytic and implementation attacks

Recognize brute force, ciphertext-only, known-plaintext, frequency analysis, chosen-ciphertext, implementation, side-channel,

fault injection, timing, MITM, pass-the-hash, Kerberos exploitation, and ransomware. Strong algorithms can fail through weak

keys, bad implementations, inadequate validation, exposed secrets, or poor operations.

3.8 Site and facility design

Apply layered physical security: site selection, setbacks, zoning, controlled entry/exit, utility protection, environmental design,

safety, and resilience. Consider how a building and its critical services support the business recovery strategy.

3.9 Facility security controls

Protect wiring closets, data centers, media/evidence storage, restricted/work areas, HVAC, utilities, fire

prevention/detection/suppression, and redundant/backup power. Know fire classes and suppression trade-offs conceptually:

safety, damage, and environmental impact must be considered.

3.10 Information system lifecycle

Manage stakeholder needs, requirements, architecture, development/implementation, integration, verification/validation,

deployment, operations/maintenance, and retirement/disposal. Security gates and acceptance criteria should exist across the

lifecycle, not only at launch.

ARCHITECTURE DECISION RULE

Start with the asset and security requirement. Then model threats and trust boundaries. Finally choose layered controls with a

named owner and an operational plan. A clever control with no lifecycle or monitoring plan is incomplete.

Study guide - use the official ISC2 outline as the final authority 9CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 4 | 13% OF EXAM

Communication and Network Security

Instructor lens: Understand data flow, trust boundaries, protocol layers, segmentation, secure components, and secure channels

- then choose controls that protect both confidentiality and availability.

4.1 Secure network architecture

Apply OSI and TCP/IP concepts, IPv4/IPv6 addressing and delivery modes, secure protocols, multilayer implications, converged

protocols, topology/planes, performance, traffic flows, segmentation, edge/wireless/mobile/CDN/SDN/VPC, and network

observability. Design assumes the network is hostile until identity, authorization, and encrypted communication establish trust.

Layer / concept Why it matters Security cue

OSI L2: Data link Frames, MAC addresses, switching VLANs separate broadcast domains but are not a complete

security boundary.

OSI L3: Network IP routing and addressing Use routing controls, ACLs, segmentation, anti-spoofing,

secure management.

OSI L4: Transport TCP/UDP ports and sessions Stateful filtering and secure service exposure; TCP is

connection-oriented.

OSI L5-L7 Sessions, presentation, application TLS, application authentication/authorization, proxy/WAF,

protocol validation.

Control / data /

management plane

Decision, forwarded traffic, administration Protect management separately; compromise here can

control the whole network.

4.1a Segmentation and traffic flow

Use physical segmentation (in-band/out-of-band/air-gapped), logical segmentation (VLAN, VPN, VRF, virtual domain), and

micro-segmentation (overlays, distributed enforcement, zero trust). North-south traffic enters/leaves a data center or

environment; east-west traffic moves laterally. An air gap reduces paths but is not absolute protection against media, insiders, or

wireless leakage.

4.1b Modern networks

Secure wireless (Wi-Fi/Bluetooth/Zigbee/satellite), cellular 4G/5G, CDN, SDN/SD-WAN/NFV, and VPC services through strong

identity, encryption, segmentation, secure APIs/control plane, configuration management, and monitoring. Observe bandwidth,

latency, jitter, throughput, and signal-to-noise because availability depends on performance and capacity.

4.2 Secure network components

Secure infrastructure operation (redundant power, warranty/support), transmission media (physical protection and signal quality),

NAC, and endpoint controls. Components require hardening, secure administration, patching, logging, redundancy, baselines,

and lifecycle management.

4.3 Secure communication channels

Implement channels according to design for voice/video/collaboration, remote access/administration, data

communications/backhaul/satellite, and third-party connectivity. Authenticate endpoints, encrypt in transit, minimize exposure,

segment partners, manage keys/certificates, monitor, and define contractual responsibility.

Protocol / mechanism Use CISSP-level distinction

TLS Protects many application sessions in

transit

Validate certificate chain/hostname; TLS is not a substitute for

application authorization.

IPsec Protects IP traffic - tunnel or transport mode Tunnel mode encapsulates the original packet; commonly used

for site-to-site/remote VPN designs.

SSH Secure remote administration / tunneling Use strong key management and restrict administrative access.

Study guide - use the official ISC2 outline as the final authority 10CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Protocol / mechanism Use CISSP-level distinction

VPN Encrypted logical connection across an

untrusted network

Provides a channel; endpoint compromise and overbroad access

remain risks.

NAC Admits/restricts endpoints based on

identity/posture

A control point, not an endpoint-security replacement.

EXAM LENS

Network questions often hide a trust-boundary problem. Favor segmentation, authenticated encryption, controlled management

access, least privilege, and monitoring over a single perimeter-only solution.

Study guide - use the official ISC2 outline as the final authority 11CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 5 | 13% OF EXAM

Identity and Access Management (IAM)

Instructor lens: Identity is the control plane for people, services, devices, applications, and facilities. Prove identity, decide

entitlement, enforce it, and remove it on time.

5.1 Control physical and logical access

Control access to information, systems, devices, facilities, applications, and services using authorization, authentication,

accountability, monitoring, and physical safeguards. Converge physical and logical identity only where governance, privacy, and

operational needs support it.

5.2 Identification and authentication strategy

Design for people, devices, and services using groups/roles, AAA, MFA/passwordless approaches, session management,

registration/proofing, federation, credential/vault management, SSO, and just-in-time access. Authentication factors are

something you know, have, are, do, and somewhere you are; two passwords are not MFA because they are the same factor

category.

Term Question it answers Example

Identification Who do you claim to be? Username, device identity, service principal.

Authentication Can you prove that claim? FIDO key plus biometric/local PIN; client certificate.

Authorization What may you do now? Role/attribute/policy grants read access to a dataset.

Accounting What did you do? Protected, reviewed audit trail tied to a unique identity.

5.3 Third-party federation

Federate identity across on-premises, cloud, and hybrid environments. Understand trust, identity proofing, assertion/token

lifecycle, attribute release, availability, logging, vendor risk, deprovisioning, and privacy. Federation reduces password sprawl but

concentrates trust and outage impact.

5.4 Authorization mechanisms

Compare RBAC (job roles), rule-based (system rules), MAC (centrally enforced labels/clearance), DAC (owner discretion),

ABAC (attributes and policy), and risk-based/adaptive access. Policy decision points evaluate policy; policy enforcement points

apply the decision. Use least privilege, need-to-know, separation of duties, and a denial-by-default posture.

Model Strength Watch for

DAC Flexible owner sharing Permission sprawl; owners can grant too broadly.

MAC Strong centralized confidentiality labels Rigidity; users cannot freely change labels/permissions.

RBAC Scales to stable job functions Role explosion when exceptions proliferate.

ABAC Fine-grained, contextual decisions Attribute quality, policy complexity, and explainability.

Risk/adaptive Responds to context/anomaly Should augment governance, not become opaque denial

without support process.

5.5 Provisioning lifecycle

Manage account reviews, provisioning/deprovisioning, role transitions, privileged escalation (such as sudo with auditing), and

service accounts. Automate joiner-mover-leaver workflow where feasible; every high-risk entitlement should have an owner,

approval, duration, logging, and periodic review.

Study guide - use the official ISC2 outline as the final authority 12CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

5.6 Authentication systems

Implement authentication safely: secure enrollment, protect credentials/secrets, resist phishing and replay, use rate

limiting/lockout carefully, manage sessions/tokens, offer recovery without bypassing assurance, and log events. Password vaults

protect shared/admin secrets but require access governance and auditing.

IAM RAPID RECALL

Authentication is not authorization. A group is not automatically a role. Federation is a trust relationship. Service accounts are

identities with access and need lifecycle, ownership, rotation, and monitoring just like human accounts.

Study guide - use the official ISC2 outline as the final authority 13CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 6 | 12% OF EXAM

Security Assessment and Testing

Instructor lens: Assurance is evidence. Scope, authorize, test, interpret results honestly, report risk clearly, and validate

remediation.

6.1 Assessment, test, and audit strategy

Design and validate strategies appropriate to internal, external, third-party, and on-premises/cloud/hybrid environments. Define

objective, scope, rules of engagement, authorization, safety, data handling, test depth, independence, reporting, and follow-up.

Independence improves credibility; it does not remove the need for cooperation.

6.2 Security control testing

Use vulnerability assessment, penetration testing, log review, synthetic transactions/benchmarks, code review/testing,

misuse-case tests, coverage analysis, interface testing, breach attack simulations, and compliance checks. Each answers a

different question; a vulnerability scan does not prove exploitability, and a penetration test does not prove complete assurance.

Activity Primary purpose Boundary

Vulnerability assessment Find known weaknesses/misconfigurations Broad and repeatable; may generate false positives

and does not require exploitation.

Penetration test Demonstrate exploitable paths and impact Needs written rules of engagement, scope, timing,

and safety constraints.

Audit Evaluate conformance/control evidence Focuses on criteria and evidence; auditor

independence matters.

Red / blue / purple exercise Exercise offense, defense, and collaborative

improvement

Measure detection/response learning, not merely

whether a tool alerts.

Breach attack simulation Continuously emulate selected attacker techniques Complements, not replaces, threat modeling and

human review.

6.3 Security process data

Collect technical and administrative evidence: account management, management review/approval, KPIs/KRIs, backup

verification, awareness results, and BC/DR evidence. Data should be accurate, protected, attributable, timely, relevant, and

retained according to requirements.

6.4 Analyze and report

Analyze output in context, distinguish findings from risk, prioritize remediation, manage exceptions with an owner and expiry, and

follow ethical disclosure. A useful report explains scope, method, evidence, impact, likelihood, affected asset, recommendation,

risk rating/assumptions, management response, and re-test result.

6.5 Security audits

Conduct or facilitate internal, external, and third-party audits across on-premises/cloud/hybrid environments. Prepare evidence,

confirm criteria and scope, preserve independence, remediate findings, and track closure. Do not conceal, alter, or selectively

withhold material evidence.

EXAM LENS

Before testing, obtain explicit authorization and define scope and rules of engagement. After testing, protect evidence, report

accurately, obtain accountable remediation or risk acceptance, and verify closure.

Study guide - use the official ISC2 outline as the final authority 14CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 7 | 13% OF EXAM

Security Operations

Instructor lens: Operations turns plans into reliable daily protection: evidence, logs, configuration, incident handling, recovery,

physical controls, and people safety.

7.1 Investigations

Comply with investigation requirements for evidence collection/handling, reporting/documentation, techniques, forensics

tools/TTPs, and artifacts from data, computer, network, and mobile sources. Preserve chain of custody: identify, collect, preserve,

document, transfer, analyze, and present evidence in a defensible manner. Use write blockers and verified copies where

appropriate.

7.2 Logging and monitoring

Operate IDPS, SIEM, continuous monitoring/tuning, egress monitoring, log management, threat intelligence/hunting, and UEBA.

Effective logging needs synchronized time, adequate retention, integrity, relevant sources, meaningful alerts, owners,

documented response, and regular tuning to control noise and blind spots.

7.3 Configuration management

Use controlled provisioning, approved secure baselines, versioned configuration, change records, automation, drift detection,

testing, rollback, and asset linkage. Configuration management makes the known-good state visible and recoverable.

7.4 Foundational operations

Enforce need-to-know/least privilege, separation of duties/responsibilities, privileged account management, job rotation, and

service-level agreements. Job rotation and mandatory vacation can detect fraud; they do not replace access controls or

monitoring.

7.5 Resource protection

Protect media and data at rest/in transit using appropriate classification, storage, transport, inventory, encryption/key protection,

environmental safeguards, retention, sanitization, and destruction. Media management includes both availability and

confidentiality.

7.6 Incident management

Conduct detection, response, mitigation, reporting, recovery, remediation, and lessons learned. Tailor playbooks by incident type

and authority. Preserve evidence and coordinate legal, privacy, HR, leadership, communications, and providers as needed.

Containment should be proportionate and reversible where possible without allowing continued harm.

IR phase Goal Typical outcome

Preparation People, authority, tools, playbooks, contacts,

baselines

Ready team and tested procedures.

Detection / analysis Validate event, scope, severity, and impact Incident classification and decisions based on

evidence.

Containment Limit harm while preserving options/evidence Segmented host, blocked indicator, controlled

account action.

Eradication / recovery Remove cause; restore safely Cleaned systems, rotated credentials, validated

service restoration.

Lessons learned Improve controls, process, and resilience Tracked actions; not just a meeting or blame

exercise.

Study guide - use the official ISC2 outline as the final authority 15CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

7.7 Detection and prevention measures

Operate and maintain firewalls (NGFW/WAF/network), IDS/IPS, allow/deny lists, third-party security services, sandboxing,

honeypots/honeynets, anti-malware, and ML/AI-based tools. Know their limits: prevention can fail, detection needs tuning, and AI

outputs need validation, data governance, and human accountability.

7.8 Patch and vulnerability management

Inventory, discover, prioritize by exploitability and business impact, test, schedule, deploy, verify, document

exceptions/compensating controls, and report residual risk. A CVSS score is an input; active exploitation, exposure, asset

criticality, and available mitigation drive priority.

7.9 Change management

Submit, assess risk/impact, approve, test, schedule, implement, document, verify, and provide rollback/emergency procedures.

Emergency change is an expedited controlled process, not permission to skip accountability.

7.10 Recovery strategies

Use appropriate backup storage (cloud/onsite/offsite), recovery sites (cold/warm/hot), capacity agreements, multiple processing

sites, resilience, HA, QoS, and fault tolerance. Backups need restore tests, isolation/immutability where risk warrants, protection

from the same failure mode, and sufficient RPO/RTO alignment.

Recovery option Readiness Cost / recovery profile

Cold site Facility/infrastructure, little or no live

equipment/data

Lowest cost; longest recovery and setup time.

Warm site Some equipment/connectivity and perhaps

replicated data

Middle cost and recovery time.

Hot site Ready facility/systems with current or near-current

Highest cost; fastest planned recovery.

data

Active-active / multiple sites Concurrent processing and distribution Strong resilience but complexity and

data-consistency design matter.

7.11 Disaster recovery processes

Implement response, personnel coordination, communications, assessment, restoration, training/awareness, and lessons

learned. DR follows business priorities established through BIA and BC planning; technical restoration is not successful until the

business accepts service recovery.

7.12 Test DR plans

Progress from read-through/tabletop, walkthrough, simulation, parallel, to full interruption. Test communications with

stakeholders, status reporting, and regulators as applicable. A full interruption is most realistic and usually carries the most

business risk; select test depth based on risk and authorization.

7.13 Business continuity exercises

Participate in BC planning and exercises that sustain critical operations, people, alternate processes, suppliers, facilities,

communications, and customer commitments. BC and DR must be integrated but are not synonyms.

7.14 Physical security

Implement perimeter and internal controls: deterrence, delay, detection, access control, surveillance, visitor management, guards,

lighting, locks, mantraps, alarms, and response. Layer controls so detection and response can occur before an adversary reaches

critical assets.

7.15 Personnel safety and security

Address travel, training/awareness, insider threat, social-media impact, MFA fatigue, emergency management, and duress. In an

emergency, life safety takes precedence over asset protection; security decisions should account for human welfare and clear

communications.

Study guide - use the official ISC2 outline as the final authority 16CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

OPERATIONS DECISION RULE

Preserve evidence, follow authority, scope the incident, contain proportionately, communicate through the plan, and return to a

known-good state. Never assume a tool alert proves compromise, and never declare recovery without validation.

Study guide - use the official ISC2 outline as the final authority 17CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DOMAIN 8 | 10% OF EXAM

Software Development Security

Instructor lens: Secure software is a lifecycle and supply-chain discipline. Create secure requirements, build and test with

guardrails, measure evidence, and control acquired components.

8.1 Security in the SDLC

Integrate security throughout Agile, Waterfall, DevOps, DevSecOps, SAFe, operation/maintenance, change management, and

integrated product teams. Use maturity models such as CMM and SAMM to improve repeatability. Security work includes

requirements, architecture/threat modeling, secure design, code, review, testing, release, monitoring, and retirement.

8.2 Controls in development ecosystems

Protect programming languages, libraries, tools, IDEs, runtime, CI/CD, configuration management, code repositories, and

application-security testing. Establish secure build provenance, branch protections, code review, least privilege for pipelines,

secrets handling, dependency governance, signed artifacts, separated environments, and logging.

Technique Where it sees risk Key limitation

SAST Source/bytecode before running Can produce false positives; cannot fully see

runtime/configuration behavior.

DAST Running application from outside Finds observable runtime issues; limited code-path

coverage and needs a testable app.

IAST Instrumented app while it runs Can give contextual findings; needs runtime

instrumentation/coverage.

SCA Third-party libraries/dependencies Identifies known component risk; must also manage

version use, reachability, licenses, and remediation.

Manual review Business logic/design and nuanced code Deep but time-intensive; prioritize high-risk paths.

8.3 Effectiveness of software security

Assess through audit/logging of changes, risk analysis and mitigation, coverage/evidence, testing results, remediation, metrics,

and independent review. A passing pipeline is evidence of defined checks, not proof that software is risk-free.

8.4 Acquired software

Assess COTS, open source, third-party, managed services, and SaaS/IaaS/PaaS for security impact. Evaluate supplier security,

support lifecycle, vulnerabilities, licensing, data handling, integrations/APIs, contract/SLA, change notice, audit rights, secure

configuration, exit/portability, and dependency provenance.

8.5 Secure coding guidelines and standards

Apply source-level practices: validate input, encode output, use parameterized queries, strong

authentication/authorization/session handling, safe error handling, memory-safe techniques, secure cryptographic APIs, secrets

management, logging without sensitive leakage, and API security. Understand software-defined security: security logic itself

needs change control, review, testing, and least-privilege execution.

Weakness pattern Safer pattern

Untrusted input used directly Allowlist validation, type/length/range checks, parameterized interfaces, safe parsing.

Authorization checked only in UI Server-side authorization at every protected action/object; deny by default.

Secrets in source/config/logs Central secrets management, rotation, least privilege, redaction, repository scanning.

Dependency assumed trustworthy Inventory/SBOM, SCA, trusted sources, version control, vulnerability and license response.

Security test only before release Automated and manual checks throughout development plus runtime monitoring and

feedback.

Study guide - use the official ISC2 outline as the final authority 18CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

DEVSECOPS EXAM LENS

Move security earlier, automate repeatable checks, protect the pipeline and dependencies, preserve accountable human review

for high-risk decisions, and keep evidence of change and approval.

Study guide - use the official ISC2 outline as the final authority 19CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Cross-domain comparison sheet

Use these distinctions to eliminate attractive but wrong answers. The right control is the one that meets the stated security

objective in the scenario’s time, authority, and business context.

Do not confuse... With... Distinction

BC DR BC sustains critical business operations; DR restores IT capabilities

supporting them.

BIA Risk assessment BIA determines business impact and recovery priorities; risk assessment

analyzes threats/vulnerabilities and treatment.

Due care Due diligence Care is reasonable protective action; diligence is investigation/validation

that supports that action.

Data owner Custodian Owner defines classification/handling; custodian implements and

operates protection.

Authentication Authorization Authentication proves identity; authorization evaluates permission.

IDS IPS IDS detects/alerts; IPS can actively block/prevent, with risk of

false-positive disruption.

Hash Digital signature Hash detects change; signature uses private-key signing/public-key

verification and can support nonrepudiation.

Vulnerability scan Penetration test Scan identifies potential weaknesses; pen test demonstrates selected

exploit paths under authorization.

Hot site High availability A hot site is a recovery-site strategy; HA is design to reduce/prevent

downtime during component failure.

Policy Procedure Policy sets management direction; procedure gives repeatable

implementation steps.

AI and emerging technology checklist

Question Apply across domains

What asset is it? Training data, model weights, prompts, identities, API tokens, compute, logs, outputs, and vendor service

may each need classification and ownership.

What can go wrong? Bias, privacy disclosure, data/model poisoning, adversarial inputs, insecure tools/plugins, supply chain

compromise, excessive agent permissions, hallucinated output, and availability/cost abuse.

What controls fit? Governance and lawful use; data minimization; secure SDLC; vendor due diligence; IAM/least privilege;

input/output controls; logging; human oversight; testing/red teaming; incident and recovery plans.

Who is accountable? Business/risk/data/model owners and authorized leaders - not an opaque automated system.

DON'T MEMORIZE IN ISOLATION

CISSP scenarios cross domains. For example, an exposed cloud database is simultaneously an asset classification,

architecture/configuration, IAM, network, monitoring, vendor, incident-response, and governance problem. Answer from the

decision point the question asks for.

Study guide - use the official ISC2 outline as the final authority 20CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Cycle 

What to do 

Evidence you are ready

1. Map 

Read each published objective and mark unfamiliar terms. Use the

domain weights to allocate time, but do not neglect a weak

domain.

You can state what each objective is trying to

protect.

2. Explain 

For every table and callout, make a one-sentence explanation and

a small workplace example from memory.

You distinguish terms without relying on

buzzwords.

3. Apply 

Practice authorized, reputable scenario questions. For each

mistake, write the objective, decision point, why the distractor was

tempting, and the governing principle.

Your error log becomes smaller and more

specific.

4. Integrate 

Practice cross-domain scenarios: cloud change, suspected

breach, supplier acquisition, application release, and

data-retention problem.

You identify ownership, risk, control, evidence,

and recovery implications.

5. Verify 

Before booking or final revision, compare your study map to the

current official ISC2 outline and exam information.

No current objective is unaddressed; logistics are

confirmed from ISC2.


Final preparation plan

Use this guide to turn knowledge into retrieval and judgment. The goal is not to memorize an answer key; it is to explain why the

best answer protects the business while following governance and sound security engineering.

A simple exam-reading routine

1. Read the final question sentence first: is it asking for FIRST, BEST, MOST likely, or a technical mechanism? 2. Identify the

asset, security objective, authority, and time horizon. 3. Notice whether the scenario is before an event, during response, or after

discovery. 4. Eliminate choices that skip governance, violate law/ethics, use the wrong owner, or solve a different problem. 5.

Select the most complete answer that fits the stated constraints - then move on.

EXAM-DAY MINDSET

You are the senior security professional, not a tool operator. Protect people and the mission, make a risk-based and defensible

decision, involve the right authority, and preserve the ability to investigate and recover.

Study guide - use the official ISC2 outline as the final authority 21CISSP MASTER STUDY GUIDE Instructor edition | current outline: Apr 2024

Scope, sources, and update note

This study guide is an independent instructional work. It summarizes and explains the publicly available CISSP syllabus; it does

not reproduce exam items, promise a result, or replace official ISC2 materials. Exam content and policies may change. Always

confirm the current outline before your exam.

Primary official source

Source How it was used

ISC2 CISSP Certification Exam Outline, effective

April 15, 2024

All eight domain names, weights, published objectives, and current technology

examples were mapped to the domain sections in this guide.

ISC2 CISSP Exam Outline Summary / Exam

Information

Used for current public exam context and the instruction to use the official outline to

target study.

ISC2 Exam Weighting change notice (Nov. 2023) Used only to identify that Domain 1 weight changed to 16% and Domain 8 to 10% in the

April 2024 refresh.

Human-readable links

https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline

Official detailed content outline PDF (ISC2)

ISC2: Changes to CISSP Exam Weighting

Prepared August 2026. The “recent-outline readiness” notes are instructional synthesis based on the current public ISC2 outline

and published cross-domain AI guidance. They are not claims about unreleased or recalled exam content.

End of guide

No comments:

Post a Comment

Study Guide for CISSP Exam 2026

  How to use this guide CISSP questions reward sound security leadership judgment : protect the mission, establish governance, understand ri...