EVIDENCE · NOT SCORES
SIGN IN
← ALL CERTIFICATIONS

ISC2

Certified Information Systems Security Professional

CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONALEXAM CISSPBLUEPRINT CISSP-APRIL-2024

BUILD MY CERTIFICATION PATH

EXAM BLUEPRINT

The published domains and objectives for CISSP. Your missions come from these objectives, and your progress is recorded against them.

  • 16%

    1

    Security and Risk Management

    • 1.1Understand, adhere to, and promote professional ethics
    • 1.2Understand and apply security concepts
    • 1.3Evaluate and apply security governance principles
    • 1.4Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
    • 1.5Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
    • 1.6Develop, document, and implement security policy, standards, procedures, and guidelines
    • 1.7Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
    • 1.8Contribute to and enforce personnel security policies and procedures
    • 1.9Understand and apply risk management concepts
    • 1.10Understand and apply threat modeling concepts and methodologies
    • 1.11Apply Supply Chain Risk Management (SCRM) concepts
    • 1.12Establish and maintain a security awareness, education, and training program
  • 10%

    2

    Asset Security

    • 2.1Identify and classify information and assets
    • 2.2Establish information and asset handling requirements
    • 2.3Provision information and assets securely
    • 2.4Manage data lifecycle
    • 2.5Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
    • 2.6Determine data security controls and compliance requirements
  • 13%

    3

    Security Architecture and Engineering

    • 3.1Research, implement and manage engineering processes using secure design principles
    • 3.2Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
    • 3.3Select controls based upon systems security requirements
    • 3.4Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
    • 3.5Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
    • 3.6Select and determine cryptographic solutions
    • 3.7Understand methods of cryptanalytic attacks
    • 3.8Apply security principles to site and facility design
    • 3.9Design site and facility security controls
    • 3.10Manage the information system lifecycle
  • 13%

    4

    Communication and Network Security

    • 4.1Apply secure design principles in network architectures
    • 4.2Secure network components
    • 4.3Implement secure communication channels according to design
  • 13%

    5

    Identity and Access Management (IAM)

    • 5.1Control physical and logical access to assets
    • 5.2Design identification and authentication strategy (e.g., people, devices, and services)
    • 5.3Federated identity with a third-party service
    • 5.4Implement and manage authorization mechanisms
    • 5.5Manage the identity and access provisioning lifecycle
    • 5.6Implement authentication systems
  • 12%

    6

    Security Assessment and Testing

    • 6.1Design and validate assessment, test, and audit strategies
    • 6.2Conduct security control testing
    • 6.3Collect security process data (e.g., technical and administrative)
    • 6.4Analyze test output and generate report
    • 6.5Conduct or facilitate security audits
  • 13%

    7

    Security Operations

    • 7.1Understand and comply with investigations
    • 7.2Conduct logging and monitoring activities
    • 7.3Perform Configuration Management (CM) (e.g., provisioning, baselining, automation)
    • 7.4Apply foundational security operations concepts
    • 7.5Apply resource protection
    • 7.6Conduct incident management
    • 7.7Operate and maintain detection and preventative measures
    • 7.8Implement and support patch and vulnerability management
    • 7.9Understand and participate in change management processes
    • 7.10Implement recovery strategies
    • 7.11Implement Disaster Recovery (DR) processes
    • 7.12Test Disaster Recovery Plans (DRP)
    • 7.13Participate in Business Continuity (BC) planning and exercises
    • 7.14Implement and manage physical security
    • 7.15Address personnel safety and security concerns
  • 10%

    8

    Software Development Security

    • 8.1Understand and integrate security in the Software Development Life Cycle (SDLC)
    • 8.2Identify and apply security controls in software development ecosystems
    • 8.3Assess the effectiveness of software security
    • 8.4Assess security impact of acquired software
    • 8.5Define and apply secure coding guidelines and standards