ISC2 · Official Blueprint · Last reviewed May 2026

CISSP Exam Domains & Blueprint

The official ISC2 CISSP exam covers 8 domains. Domain weights tell you exactly how much of the exam each topic represents — and where to invest your study time.

CISSP Domain Weight Summary

#DomainWeightQuestions
1Security and Risk Management
%
2Asset Security
%
3Security Architecture and Engineering
%
4Communication and Network Security
%
5Identity and Access Management
%
6Security Assessment and Testing
%
7Security Operations
%
8Software Development Security
%

Detailed Domain Breakdown

%

Domain 1: Security and Risk Management

Covers the topics, concepts, and applied skills examined under the Security and Risk Management domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

%

Domain 2: Asset Security

Covers the topics, concepts, and applied skills examined under the Asset Security domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

%

Domain 3: Security Architecture and Engineering

Network segmentation, zero trust architecture, cloud security models, virtualisation security, and resilience/redundancy design.

%

Domain 4: Communication and Network Security

Covers the topics, concepts, and applied skills examined under the Communication and Network Security domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

%

Domain 5: Identity and Access Management

Covers the topics, concepts, and applied skills examined under the Identity and Access Management domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

%

Domain 6: Security Assessment and Testing

Covers the topics, concepts, and applied skills examined under the Security Assessment and Testing domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

%

Domain 7: Security Operations

Incident response lifecycle, digital forensics, threat hunting, SIEM/SOAR tools, log analysis, and security automation.

%

Domain 8: Software Development Security

Covers the topics, concepts, and applied skills examined under the Software Development Security domain. Study the official exam objectives and practise questions in this area to build confidence and accuracy before your exam.

How to Use Domain Weights in Your Study Plan

The heaviest domain on the CISSP is "Security and Risk Management" at null%. Start here and return to it regularly.

Allocate study time proportional to domain weight — a 25% domain deserves roughly 25% of your prep hours.

Never skip a low-weight domain. A 10% domain still represents 5–7 exam questions — enough to make the difference between pass and fail.

Use Courseiva domain analytics to track your accuracy per domain automatically. The system routes extra questions to your weak areas.

Practice every CISSP domain

Courseiva tracks your accuracy per domain automatically and routes you toward your weakest areas — no manual configuration needed.

CISSP Concept Guides

Related Exam Domains