EVIDENCE · NOT SCORES
SIGN IN← ALL CERTIFICATIONS
ISC2
Certified Information Systems Security Professional
CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONALEXAM CISSPBLUEPRINT CISSP-APRIL-2024
EXAM BLUEPRINT
The published domains and objectives for CISSP. Your missions come from these objectives, and your progress is recorded against them.
16%
1
Security and Risk Management
- 1.1Understand, adhere to, and promote professional ethics
- 1.2Understand and apply security concepts
- 1.3Evaluate and apply security governance principles
- 1.4Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
- 1.5Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
- 1.6Develop, document, and implement security policy, standards, procedures, and guidelines
- 1.7Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
- 1.8Contribute to and enforce personnel security policies and procedures
- 1.9Understand and apply risk management concepts
- 1.10Understand and apply threat modeling concepts and methodologies
- 1.11Apply Supply Chain Risk Management (SCRM) concepts
- 1.12Establish and maintain a security awareness, education, and training program
10%
2
Asset Security
- 2.1Identify and classify information and assets
- 2.2Establish information and asset handling requirements
- 2.3Provision information and assets securely
- 2.4Manage data lifecycle
- 2.5Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
- 2.6Determine data security controls and compliance requirements
13%
3
Security Architecture and Engineering
- 3.1Research, implement and manage engineering processes using secure design principles
- 3.2Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
- 3.3Select controls based upon systems security requirements
- 3.4Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
- 3.5Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
- 3.6Select and determine cryptographic solutions
- 3.7Understand methods of cryptanalytic attacks
- 3.8Apply security principles to site and facility design
- 3.9Design site and facility security controls
- 3.10Manage the information system lifecycle
13%
4
Communication and Network Security
- 4.1Apply secure design principles in network architectures
- 4.2Secure network components
- 4.3Implement secure communication channels according to design
13%
5
Identity and Access Management (IAM)
- 5.1Control physical and logical access to assets
- 5.2Design identification and authentication strategy (e.g., people, devices, and services)
- 5.3Federated identity with a third-party service
- 5.4Implement and manage authorization mechanisms
- 5.5Manage the identity and access provisioning lifecycle
- 5.6Implement authentication systems
12%
6
Security Assessment and Testing
- 6.1Design and validate assessment, test, and audit strategies
- 6.2Conduct security control testing
- 6.3Collect security process data (e.g., technical and administrative)
- 6.4Analyze test output and generate report
- 6.5Conduct or facilitate security audits
13%
7
Security Operations
- 7.1Understand and comply with investigations
- 7.2Conduct logging and monitoring activities
- 7.3Perform Configuration Management (CM) (e.g., provisioning, baselining, automation)
- 7.4Apply foundational security operations concepts
- 7.5Apply resource protection
- 7.6Conduct incident management
- 7.7Operate and maintain detection and preventative measures
- 7.8Implement and support patch and vulnerability management
- 7.9Understand and participate in change management processes
- 7.10Implement recovery strategies
- 7.11Implement Disaster Recovery (DR) processes
- 7.12Test Disaster Recovery Plans (DRP)
- 7.13Participate in Business Continuity (BC) planning and exercises
- 7.14Implement and manage physical security
- 7.15Address personnel safety and security concerns
10%
8
Software Development Security
- 8.1Understand and integrate security in the Software Development Life Cycle (SDLC)
- 8.2Identify and apply security controls in software development ecosystems
- 8.3Assess the effectiveness of software security
- 8.4Assess security impact of acquired software
- 8.5Define and apply secure coding guidelines and standards