Certified Information Systems Security Professional (CISSP) Study Guide 2026: Syllabus, Exam Topics & Study Plan -Edureify
๐Ÿ“‹ 2026 Edition  ยท  Updated September 2026

Certified Information Systems Security Professional (CISSP) Study Guide 2026

Complete exam coverage for the Certified Information Systems Security Professional (CISSP): syllabus, domains, key topics, study plan and practical exam preparation strategy.

125
Questions
240 min
Duration
700
Passing score
8
Domains
95%
First-attempt pass rate
47K+
Candidates prepared
4.9โ˜…
Average rating
"Passed my Certified Information Systems Security Professional (CISSP) exam on the first try after just 6 weeks of studying with Edureify AI. The domain-level analysis showed me exactly what I was missing."
- Verified Edureify User
Your readiness score - take the free diagnostic to unlock your personalised analysis
-%
Overall readiness (locked)
Security and Risk Management
-
Asset Security
-
Security Architecture and Engineering
-
Communication and Network Security
-
Identity and Access Management (IAM)
-
Security Assessment and Testing
-
Security Operations
-
Software Development Security
-
Run 10-Minute Free Diagnostic โ†’
Exam at a Glance

Certified Information Systems Security Professional (CISSP) Exam Overview

Key facts about the Certified Information Systems Security Professional (CISSP) exam structure, format and scoring.

๐Ÿ†”
cissp
Exam code
๐Ÿ“
125 questions
Total questions
โฑ
240 minutes
Duration
๐ŸŽฏ
700
Passing score
๐Ÿ“‹
8 domains
Exam domains
๐Ÿ†
Certification
Credential type
โ„น๏ธ
Scoring method: The CISSP CAT exam scores candidates on a scale of 0–1000. A minimum score of 700 is required to pass. The exam uses adaptive testing — it ends when the system determines with 95% confidence whether the candidate passes or fails, between 125 and 175 questions.. The exam may include unscored pilot questions - treat every question seriously.
Focus Areas

What should you study for the Certified Information Systems Security Professional (CISSP) exam?

Start with the domains that make up the Certified Information Systems Security Professional (CISSP) exam. Use the detailed syllabus below to work through the individual topics.

โš ๏ธ
Common mistake: Candidates often memorise terminology but struggle with scenario-based questions. Focus on when to use what, not just what exists.
🔐
Security and Risk Management (16%)
Covers security principles, risk management concepts, compliance, professional ethics, and security policies.
🏗
Asset Security (10%)
Covers the classification, ownership, protection, and retention of data and information assets.
Security Architecture and Engineering (13%)
Covers security models, design principles, cryptography, and physical security.
💰
Communication and Network Security (13%)
Covers network architectures, protocols, secure communications, and network attacks and defenses.
🔄
Identity and Access Management (IAM) (13%)
Covers identity management, authentication, authorization, and access control models.
📊
Security Assessment and Testing (12%)
Covers security control testing, vulnerability assessments, penetration testing, and audit reporting.
🌐
Security Operations (13%)
Covers incident management, disaster recovery, business continuity, and security monitoring.
🛡
Software Development Security (10%)
Covers secure software development lifecycle, application security, and code review practices.
Full Syllabus

Certified Information Systems Security Professional (CISSP) Exam Syllabus and Topics

The Certified Information Systems Security Professional (CISSP) exam is divided into 8 domains. Each domain covers specific skills and topics. Expand a domain to see the detailed syllabus.

Security Governance
Security Policies
Standards and Procedures
Due Care and Due Diligence
Security Frameworks
Risk Management
Risk Identification
Risk Assessment
Risk Response
Quantitative vs Qualitative Analysis
Legal and Regulatory Compliance
Data Privacy Laws (GDPR, CCPA)
Intellectual Property
Import/Export Controls
Cybercrimes
Professional Ethics
ISC2 Code of Ethics
Organizational Ethics
Whistleblowing
Ethical Decision Making
~20 questions
16 marks
16% of exam weight
Data Classification
Classification Levels
Data Ownership
Data Stewardship
Privacy Protection
Classification and Handling of AI-Specific Assets (training datasets, pre-trained models, model weights)
Data Retention and Destruction
Retention Policies
Secure Disposal
Data Remanence
Asset Inventory
~13 questions
10 marks
10% of exam weight
Security Design Principles
Defense in Depth
Least Privilege
Separation of Duties
Zero Trust
Security Models
Bell-LaPadula
Biba Model
Clark-Wilson
Brewer-Nash (Chinese Wall)
Cryptographic Concepts
Symmetric Encryption
Asymmetric Encryption
Hashing
PKI and Digital Certificates
Applied Cryptography
TLS/SSL
IPSec
Key Management
Steganography
~16 questions
13 marks
13% of exam weight
Network Models and Protocols
OSI Model
TCP/IP Stack
DNS
HTTPS/TLS
IPv4/IPv6
Secure Network Design
Firewalls
VPNs
Network Segmentation
DMZ
SD-WAN
Network Threats
DDoS
Man-in-the-Middle
Sniffing and Spoofing
DNS Poisoning
~16 questions
13 marks
13% of exam weight
Authentication Mechanisms
MFA
Biometrics
Password Policies
SSO and Federation
Access Control Models
DAC
MAC
RBAC
ABAC
Zero Trust Access
Provisioning and De-provisioning
User Provisioning
Privileged Access Management
Account Reviews
Identity Governance
~16 questions
13 marks
13% of exam weight
Security Testing Techniques
Vulnerability Scanning
Penetration Testing
Red Team/Blue Team
Security Audits
Security Assessment Reporting
Audit Reports
Test Results Analysis
Remediation Planning
Management Review
~15 questions
12 marks
12% of exam weight
Incident Management
Incident Detection
Incident Response Plan
Forensics
Chain of Custody
Business Continuity and Disaster Recovery
BCP Development
DRP
RTO and RPO
Backup Strategies
Security Operations Center (SOC)
SIEM
Log Management
Threat Intelligence
Patch Management
~16 questions
13 marks
13% of exam weight
SDLC Security
Security Requirements
Threat Modeling
Secure Coding Practices
DevSecOps
Application Security
OWASP Top 10
Code Review
Static/Dynamic Analysis
Web Application Firewalls
~13 questions
10 marks
10% of exam weight
๐Ÿ”ฅ 1,247 professionals tested in the last 24 hours

Know if you'll pass Certified Information Systems Security Professional (CISSP) before exam day

Take our 10-minute diagnostic and get a personalised report showing your readiness, weak domains and where to focus next.

Start Free Diagnostic โ†’
100% FreeNo credit cardResults in 10 minutes
Study Plan

Certified Information Systems Security Professional (CISSP) Structured Study Roadmap

Choose a preparation timeline based on how much time you have available. For a plan based on your actual readiness and weak domains, use the personalised Edureify study experience. Get My Training Plan โ†’

Weeks 1-2
Core Services + Highest-Weighted Domain
Deep-dive into the most heavily tested domain. Spend more time here when its exam weight is significantly higher.
Official exam guideDomain 1 completeCore conceptsPractice questions
Week 3
Domain 2 - Hands-on Practice
Focus on scenario-based study and reinforce concepts through practical application where applicable.
Domain 2Scenario walkthroughsHands-on practicePractice questions
Week 4
Domain 3 - Deeper Concepts
Work through complex concepts and decision scenarios.
Domain 3Scenario drillsPractice examReview
Week 5
Remaining Domains + Weak Area Targeting
Identify your weaker domains and spend focused time closing those gaps.
Remaining domainsDiagnosticTargeted reviewStudy notes
Week 6
Full Simulations + Final Preparation
Use timed simulations to test your preparation and review the reasoning behind incorrect answers.
Full mock examsWrong-answer reviewFinal reviewExam logistics
Exam Strategy

Tips to pass Certified Information Systems Security Professional (CISSP) on your first attempt

Practical advice for applying what you know, managing questions and preparing for exam conditions.

🗓
Think like a manager and risk advisor — the CISSP tests decision-making, not just technical knowledge.
🔍
When two answers seem correct, choose the one that addresses risk from the highest organizational level.
Understand all eight domains equally — no single domain can be skipped.
📊
Use memory aids and mnemonics for cryptographic algorithms, access control models, and network protocols.
Recommended Resources

Certified Information Systems Security Professional (CISSP) Study Resources

Use a focused set of resources alongside the study guide rather than trying to study from everything available.

Official
Official Exam Guide
Start with the authoritative exam objectives and blueprint.
Practice Tests
Certified Information Systems Security Professional (CISSP) Practice Test
Practice questions with explanations and domain-level performance analysis.
โ†’ Start free practice test
Mock Exam
Certified Information Systems Security Professional (CISSP) Mock Exam
Timed preparation under realistic exam-style conditions.
โ†’ Take free mock exam
Training
Certified Information Systems Security Professional (CISSP) Certification Training
Structured preparation with personalised learning support and adaptive practice.
โ†’ Certified Information Systems Security Professional (CISSP) certification online training
AI Tutor
Certified Information Systems Security Professional (CISSP) AI Tutor
Get help understanding concepts and work on weak areas with AI-powered learning support.
โ†’ Try Certified Information Systems Security Professional (CISSP) AI tutor
Reference
Certified Information Systems Security Professional (CISSP) Cheat Sheet
Quick-reference summaries for final revision.
โ†’ Get free cheat sheet
Diagnostic
Certified Information Systems Security Professional (CISSP) Readiness Test
Assess your preparation and identify weaker exam domains.
โ†’ Check my readiness
โš ๏ธ
Avoid brain dumps. Sites selling real or stolen exam questions may violate certification-provider rules and can leave candidates studying outdated material.
Reviews

What candidates say after passing

โ˜…โ˜…โ˜…โ˜…โ˜…
I had 12 years of security experience and failed CISSP twice. The problem wasn't knowledge - it was that I kept picking the most secure answer instead of the most risk-appropriate one.Edureify AI's scenarios are specifically designed to break that habit. Third attempt, I cleared it.
Liam F.
Solutions Architect
โ˜…โ˜…โ˜…โ˜…โ˜…
The voice-based practice forced me to articulate my reasoning out loud, not just pick answers. That made a meaningful difference in the exam - I could work through the risk logic verbally instead of pattern-matching to technical solutions.
Dinesh N.
Network Engineer
โ˜…โ˜…โ˜…โ˜…โ˜…
What surprised me was how consistently the correct CISSP answer is the business-aligned option, not the maximum-security option.Edureify AI drilled that distinction until it became instinctive. My manager said I now think about security the way a CISO does.
Carlos M.
Cloud Engineer
โ˜…โ˜…โ˜…โ˜…โ˜…
I studied for 4 months with textbooks and flashcards and still failed. Six weeks withEdureify AI focused exclusively on my weak domains - incident response sequencing and IAM - and I passed. The targeted approach is incomparably more efficient.
Stephanie L.
Data Engineer
FAQ

Frequently asked questions about Certified Information Systems Security Professional (CISSP)

Most candidates with relevant background can structure their preparation over several weeks, depending on their existing knowledge, available study time and exam difficulty. Use the study roadmap above as a starting point and use the readiness diagnostic to identify where you need more preparation.
The guide covers the exam overview, domains, detailed syllabus and topics, study roadmap, exam preparation tips and links to practice, mock, readiness, cheat-sheet, AI Tutor and training resources.
The guide is designed to organize your preparation around the exam syllabus. You should combine it with practice questions and timed simulations so that you can test both your knowledge and your ability to apply it.
Yes. Start with the exam overview and domain breakdown, then work through the detailed topics using the study roadmap. Candidates with less experience may need additional time for foundational concepts.
Take the Edureify readiness diagnostic to assess your preparation and identify the domains where you need to focus more.
Edureify AI can help explain concepts, identify weaker areas from practice performance and support a more personalised preparation process.

Ready to prepare for Certified Information Systems Security Professional (CISSP)?

Find your weak areas and build a more focused preparation plan.

Start My Free Diagnostic โ†’
95% first-attempt pass rate47,000+ candidates4.9โ˜… ratingNo credit card needed
Keep Learning

Related Cybersecurity Certification Study Guides

Explore related certification study guides within this category.