This guide covers all eight domains of the (ISC)² CISSP Common Body of Knowledge, providing a structured curriculum for exam preparation.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
15 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CISSPterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideSecurity Governance and Principles
Objective 1.1 · Understand and apply concepts of confidentiality, integrity, and availability
Security Architecture and Models
Objective 1.2 · Evaluate and apply security governance principles
Asset Security: Classification and Handling
Objective 2.1 · Identify and classify information and assets
Asset Security: Privacy and Data Retention
Objective 2.2 · Determine and maintain information and asset ownership
Cryptography and Its Applications
Objective 3.1 · Understand and apply cryptography concepts
Secure Network Architecture and Components
Objective 3.2 · Implement secure design principles in network architectures
Identity and Access Management (IAM)
Objective 4.1 · Manage identification and authentication of people, devices, and services
Access Control Models and Mechanisms
Objective 4.2 · Integrate identity as a third-party service
Security Assessment and Testing
Objective 5.1 · Design and validate assessment and test strategies
Security Operations Foundations
Objective 6.1 · Understand and support the security operations process
Incident Response and Business Continuity
Objective 6.2 · Manage incident response and business continuity plans
Disaster Recovery Planning
Objective 6.3 · Implement and manage disaster recovery processes
Software Development Security
Objective 7.1 · Understand and integrate security in the software development lifecycle
Physical Security and Environmental Controls
Objective 8.1 · Implement and manage physical security controls
Legal, Regulatory, and Compliance Issues
Objective 8.2 · Understand legal and regulatory issues related to information security
Free CISSP practice questions with full explanations. Test what you learn chapter by chapter.
CISSP Practice Questions