CISSP Certification Roadmap

Certified Information Systems Security Professional

Gold Standard of Information Security
8
Security Domains
8-12
Weeks Study Time
200+
Practice Questions
60
Flashcards

Certification Overview

Exam Details

  • Exam Code: CISSP
  • Format: Computerized Adaptive Testing (CAT)
  • Questions: 100-150 (CAT), 250 (linear format)
  • Duration: 3 hours (CAT), 6 hours (linear)
  • Passing Score: 700 out of 1000 points
  • Cost: $749 USD
  • Validity: 3 years (with CPE credits)

Prerequisites

  • Experience: 5 years paid full-time security work (or 4 years + degree or cert)
  • Domains: Must have experience in 2+ of the 8 domains
  • Endorsement: Required by (ISC)² member (provided if not known)
  • Background Check: Conducted by (ISC)²
  • Associate Option: Can test first, gain experience later (6 years to complete)

CISSP Value

  • Gold standard certification for security professionals
  • Vendor-neutral, globally recognized
  • Management and strategic focus ("think like a manager")
  • DoD 8140/8570 approved
  • Significant salary premium ($120-180K+)
  • Required for many senior security positions

Exam Approach

  • Think strategically, not tactically
  • Choose "best" answer from all correct options
  • Management perspective (policies > tools)
  • Read carefully for keywords (BEST, MOST, FIRST)
  • Process of elimination
  • No negative marking - answer everything

CISSP 8 Domains

1

Security and Risk Management

15% of exam - Governance, compliance, legal, ethics, risk management

2

Asset Security

10% of exam - Data classification, ownership, privacy, retention

3

Security Architecture and Engineering

13% of exam - Secure design, cryptography, physical security

4

Communication and Network Security

13% of exam - Network architecture, secure components, protocols

5

Identity and Access Management

13% of exam - Authentication, authorization, identity management

6

Security Assessment and Testing

12% of exam - Vulnerability assessments, pen testing, audits

7

Security Operations

13% of exam - Investigations, incident response, BCP/DRP

8

Software Development Security

11% of exam - SDLC security, secure coding, application security

8-Week Study Roadmap

1

Week 1: Security and Risk Management

Core Topics:

  • CIA Triad (Confidentiality, Integrity, Availability)
  • Security governance principles and frameworks (COBIT, ISO 27001)
  • Legal and regulatory compliance (GDPR, HIPAA, SOX, PCI DSS)
  • Professional ethics and (ISC)² Code of Ethics
  • Risk management concepts (quantitative vs qualitative)
  • Risk assessment methodologies (ALE, SLE, ARO)
  • Risk treatment strategies (avoid, mitigate, transfer, accept)
  • Security policies, standards, procedures, guidelines
  • Security awareness training programs
  • Threat modeling (STRIDE, PASTA, DREAD)

Practice:

  • Complete Domain 1 practice questions (30-40 questions)
  • Review flashcards for governance and risk concepts
  • Calculate ALE/SLE/ARO examples
  • Study key regulations (GDPR, HIPAA requirements)
2

Week 2: Asset Security & Information Classification

Core Topics:

  • Data classification levels (public, internal, confidential, restricted)
  • Data ownership, custody, stewardship roles
  • Data states (at rest, in transit, in use)
  • Privacy protection (PII, PHI, data minimization)
  • Data retention and destruction policies
  • Data sanitization methods (overwrite, degauss, crypto erasure)
  • Data Loss Prevention (DLP) systems
  • Data security controls (encryption, access controls)
  • Privacy Impact Assessments (PIA)
  • Scoping and tailoring security controls

Practice:

  • Complete Domain 2 practice questions (20-30 questions)
  • Review data classification scenarios
  • Study GDPR data subject rights
  • Practice identifying appropriate sanitization methods
3

Week 3: Security Architecture and Engineering

Core Topics:

  • Secure design principles (least privilege, defense in depth, fail secure)
  • Security models (Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash)
  • Trusted Computing Base (TCB), security kernel, reference monitor
  • Common Criteria (EAL levels), TCSEC (Orange Book)
  • Cryptography fundamentals (symmetric, asymmetric, hashing)
  • Encryption algorithms (AES, RSA, ECC)
  • Hashing algorithms (SHA-256, bcrypt, deprecated MD5/SHA-1)
  • Digital signatures and certificates
  • PKI infrastructure (CA, RA, CRL, OCSP)
  • Physical security controls (fencing, locks, CCTV, guards)
  • Environmental controls (HVAC, fire suppression, power)

Practice:

  • Complete Domain 3 practice questions (30-35 questions)
  • Memorize security models (Bell-LaPadula, Biba rules)
  • Review cryptographic algorithms and use cases
  • Practice PKI certificate chain scenarios
4

Week 4: Communication and Network Security

Core Topics:

  • OSI model (7 layers) and TCP/IP model (4 layers)
  • Network protocols (TCP, UDP, ICMP, HTTP, DNS, DHCP)
  • Secure network architecture (DMZ, VLANs, subnetting)
  • Network devices (routers, switches, firewalls, IDS/IPS)
  • Secure protocols (TLS/SSL, SSH, IPsec, DNSSEC)
  • VPN technologies (site-to-site, remote access, split tunnel)
  • Wireless security (WEP, WPA, WPA2, WPA3)
  • Network attacks (DoS/DDoS, MITM, spoofing, sniffing)
  • Software-defined networking (SDN)
  • Content distribution networks (CDN)

Practice:

  • Complete Domain 4 practice questions (30-35 questions)
  • Memorize OSI layers and protocols
  • Review firewall rules and DMZ architecture
  • Study IPsec modes (transport vs tunnel)
5

Week 5: Identity and Access Management (IAM)

Core Topics:

  • Identification, authentication, authorization, accounting (IAAA)
  • Authentication factors (Type I-V: knowledge, possession, inherence, location, behavior)
  • Multi-factor authentication (MFA) vs two-factor (2FA)
  • Biometrics (FRR, FAR, CER, Type I/II errors)
  • Access control models (DAC, MAC, RBAC, ABAC, Rule-Based)
  • Single Sign-On (SSO) and federation
  • Protocols (Kerberos, SAML, OAuth 2.0, OpenID Connect)
  • RADIUS and TACACS+ (AAA protocols)
  • Privileged Access Management (PAM)
  • Access provisioning and deprovisioning
  • Access reviews and recertification

Practice:

  • Complete Domain 5 practice questions (30-35 questions)
  • Memorize authentication factors and MFA requirements
  • Review biometric error rates (FRR vs FAR)
  • Study Kerberos authentication flow
  • Practice access control model scenarios
6

Week 6: Security Assessment and Testing

Core Topics:

  • Security testing types (vulnerability scanning, pen testing)
  • Penetration testing (black-box, white-box, gray-box)
  • Vulnerability assessment vs pen testing differences
  • Code review and security testing
  • SAST (Static Application Security Testing)
  • DAST (Dynamic Application Security Testing)
  • Security audits and assessments
  • Log reviews and analysis
  • Synthetic transactions and real user monitoring
  • Test coverage analysis
  • Interface testing (APIs, web services)

Practice:

  • Complete Domain 6 practice questions (25-30 questions)
  • Review SAST vs DAST differences and use cases
  • Study pen testing methodology and phases
  • Practice audit vs assessment scenarios
7

Week 7: Security Operations

Core Topics:

  • Security Operations Center (SOC) functions
  • SIEM (Security Information and Event Management)
  • Incident response lifecycle (NIST: Prepare, Detect, Contain, Eradicate, Recover, Lessons)
  • Incident handling and evidence collection
  • Forensics and chain of custody
  • Disaster recovery planning (DRP)
  • Business continuity planning (BCP)
  • RTO (Recovery Time Objective) vs RPO (Recovery Point Objective)
  • Backup strategies (full, incremental, differential)
  • High availability and fault tolerance
  • Disaster recovery sites (cold, warm, hot)
  • Change and configuration management
  • Patch management
  • Personnel security (hiring, termination, awareness training)

Practice:

  • Complete Domain 7 practice questions (30-35 questions)
  • Memorize incident response phases
  • Review RTO vs RPO calculations
  • Study disaster recovery site types and costs
  • Practice forensic evidence handling scenarios
8

Week 8: Software Development Security & Final Review

Core Topics:

  • Secure SDLC phases
  • Security requirements gathering
  • Threat modeling (STRIDE, PASTA, attack trees)
  • Secure coding practices
  • Input validation and output encoding
  • OWASP Top 10 vulnerabilities
  • SQL injection prevention (parameterized queries)
  • XSS, CSRF, and other web attacks
  • Session management
  • Error handling and logging
  • DevSecOps and CI/CD security
  • Secure code review
  • Database security (normalization, encryption)

Practice:

  • Complete Domain 8 practice questions (25-30 questions)
  • Review all 200 practice questions
  • Complete all 60 flashcards
  • Take full-length practice exams (250 questions)
  • Review weak areas identified in practice exams
  • Memorize key acronyms and formulas

Career Paths with CISSP

Security Manager/Director

$120,000 - $180,000+/year

Lead security teams, develop strategies, manage security programs, implement governance frameworks.

Advance with: CISM CRISC CGEIT

Security Architect

$130,000 - $200,000+/year

Design secure systems, develop security architectures, define security controls, guide technical implementation.

Advance with: CCSP TOGAF CSA CCSK

GRC Analyst/Manager

$100,000 - $160,000/year

Governance, Risk, and Compliance - manage frameworks, conduct risk assessments, ensure regulatory compliance.

Advance with: CRISC CISA ISO 27001 LA

Security Consultant

$120,000 - $200,000+/year

Provide expert security advice, conduct assessments, design solutions, guide organizations on security strategy.

Advance with: CISM PMP CCSP

CISO (Chief Information Security Officer)

$180,000 - $350,000+/year

Executive leadership, strategic planning, board communication, enterprise security vision, budget management.

Advance with: CISM MBA Executive Education

Security Auditor

$95,000 - $150,000/year

Conduct security audits, assess controls, verify compliance, identify gaps, provide recommendations.

Advance with: CISA CIA ISO 27001 LA

Exam Day Strategy

1. Think Like a Manager

CISSP is management-level. Choose answers that prioritize policies, procedures, and strategic thinking over technical implementation. When in doubt, select the option that involves planning, policy, or communication.

2. Choose the "BEST" Answer

Multiple answers may be correct, but one is BEST. Look for keywords: BEST, MOST, FIRST, PRIMARY. Process of elimination helps narrow choices to the optimal answer.

3. Read Carefully

Questions are scenario-based and wordy. Read the entire question and all options before answering. Identify what's being asked (FIRST step, BEST control, PRIMARY concern).

4. Understand CAT

Computerized Adaptive Testing adjusts difficulty based on responses. Don't panic if questions seem hard - it means you're doing well. You can't go back, so answer carefully the first time.

5. Time Management

CAT: 100-150 questions in 3 hours. Linear: 250 questions in 6 hours. Pace yourself (~1-2 minutes per question). Don't dwell - if unsure, make your best guess and move on.

6. Security Models & Frameworks

Memorize key security models (Bell-LaPadula, Biba), frameworks (COBIT, NIST), regulations (GDPR, HIPAA), and formulas (ALE = SLE × ARO).

7. Apply (ISC)² Ethics

Code of Ethics: Protect society, act honorably, provide competent service, advance the profession. Choose ethical answers prioritizing public safety and legal requirements.

8. Common Traps

Avoid choosing technically correct but poor management answers. Beware of absolutes (always, never). Consider context - what's appropriate depends on risk tolerance and business needs.

Key Formulas to Memorize

ALE (Annual Loss Expectancy) = SLE × ARO

SLE (Single Loss Expectancy) = Asset Value × Exposure Factor

ARO (Annual Rate of Occurrence) = Times per year

CER/EER (Crossover/Equal Error Rate) = Where FRR = FAR (lower is better)

Work Factor = Time/effort to break security (higher is better)

Practice & Resources

Our Practice Materials

Official Resources

Study Materials

  • Shon Harris "All-in-One CISSP Exam Guide"
  • Eric Conrad "CISSP Study Guide" (Sybex)
  • Kelly Handerhan CISSP videos (Cybrary)
  • Larry Greenblatt CISSP bootcamp
  • Thor Pedersen CISSP videos (Udemy)

Community & Practice

Recommended Study Approach

  1. Read Official Study Guide: Cover all 8 domains systematically (4-6 weeks)
  2. Watch Video Course: Reinforce concepts visually (2-3 weeks, parallel with reading)
  3. Practice Questions: Complete 1000+ practice questions, review all explanations (3-4 weeks)
  4. Flashcards & Weak Areas: Focus on domains where you score lowest (1-2 weeks)
  5. Full-Length Exams: Take 2-3 timed 250-question exams, aim for consistent 85%+ (final week)
  6. Final Review: Formulas, ethics, key frameworks, security models (2-3 days before)

Total recommended study time: 8-12 weeks with 15-25 hours per week. Adjust based on experience level.

← Back to All Roadmaps Start CISSP Practice