CISSP: security, risk, and operations
Prepare for CISSP through eight domains, security decisions, and banking management and operations scenarios.
Objectives and progression
Eight lessons, 50 regular questions, and eight original cases with an internal 32-decision assessment in 50 minutes. First pass through eight domains of the outline effective April 15, 2024, including current guidance integrating AI across those domains. Fictional banking examples connect governance, assets, architecture, networking, IAM, assessment, operations, and software. Independent preparation; this fixed assessment neither reproduces CAT nor estimates an official score.
Audience: Security professionals, APS/L3 teams, architects, and technical managers responsible for services and risk.
Prerequisites: IT experience and security fundamentals. CISSP certification requires experience under ISC2 rules, normally five years across at least two domains with a maximum eligible one-year waiver. Passing the exam without experience may permit the Associate of ISC2 pathway; completing DR grants neither status.
290 estimated study minutes
- Connect controls to objectives, impact, and decision authority.
- Maintain protection and accountability when data changes format or location.
- Design protection for normal conditions and concrete failures.
- Distinguish reaching a resource, protecting a channel, and being allowed to perform an operation.
- Manage access from onboarding through effective revocation.
- Form conclusions matching what was actually tested.
- Coordinate containment and continuity with measurable recovery criteria.
- Integrate security requirements into design, pipeline, and acceptance.
Modules
- Governance, ethics, and risk decisions
- Assets, data, and decommissioning
- Architecture, cryptography, and common failures
- Networks, channels, and access boundaries
- Identity, sessions, and privileges
- Assessment, testing, and evidence limits
- Operations, incidents, and recovery
- Secure software and supply chain
Continue learning
- CompTIA Security+
- CISM — Certified Information Security Manager
- CISA — Certified Information Systems Auditor
- CKS — Certified Kubernetes Security Specialist
- Technical Project Manager
References and version
CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29
- CISSP certification · 2026-09-29
- CISSP exam outline · 2026-09-29
- CISSP experience requirements · 2026-09-29
- Computerized Adaptive Testing · 2026-09-29
- ISC2 Code of Ethics · 2026-09-29
- Cybersecurity Framework 2.0 · 2026-09-29
- Guide for Conducting Risk Assessments · 2026-09-29
- Guidelines for Media Sanitization · 2026-09-29
- Engineering Trustworthy Secure Systems · 2026-09-29
- Recommendation for Key Management · 2026-09-29
- Contingency Planning Guide · 2026-09-29
- Zero Trust Architecture · 2026-09-29
- Authentication and Authenticator Management · 2026-09-29
- Federation and Assertions · 2026-09-29
- Technical Guide to Security Testing and Assessment · 2026-09-29
- Incident Response Recommendations and Considerations · 2026-09-29
- Secure Software Development Framework 1.1 · 2026-09-29
- SSDF publication status · 2026-09-29
- AI Risk Management Framework 1.0 · 2026-09-29
- TLS 1.3 · 2026-09-29
- Shared Responsibility Model · 2026-09-29
- SQL Injection Prevention · 2026-09-29
What you will explore
0 / 8Governance, ethics, and risk decisions
Connect controls to objectives, impact, and decision authority.
Assets, data, and decommissioning
Maintain protection and accountability when data changes format or location.
Architecture, cryptography, and common failures
Design protection for normal conditions and concrete failures.
Networks, channels, and access boundaries
Distinguish reaching a resource, protecting a channel, and being allowed to perform an operation.
Identity, sessions, and privileges
Manage access from onboarding through effective revocation.
Assessment, testing, and evidence limits
Form conclusions matching what was actually tested.
Operations, incidents, and recovery
Coordinate containment and continuity with measurable recovery criteria.
Secure software and supply chain
Integrate security requirements into design, pipeline, and acceptance.