ISC2 / Professional / CISSP
Information Systems Security Professional
Connect technical controls to business risk, assurance and accountable decisions across all eight security domains.
Uses the current April 2024 outline and its published AI guidance. Passing the exam alone does not grant CISSP: experience, endorsement and other credential requirements also apply. Foundation topics are shared with our Security+ path; start with chapters 11–16 for the professional distinctions.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Security Principles and Controls
Protect the right property with the right kind of control.
Threats, Attacks and Indicators
Actor explains intent; evidence identifies the technique.
Cryptography, Certificates and Keys
Encrypt for secrecy; sign for origin; hash for comparison.
Secure Architecture and Network Defences
Reduce exposure; separate trust; inspect the right layer.
Hardening and Vulnerability Management
Inventory, prioritize, fix, verify.
Identity, Authentication and Privileged Access
Who are you, what may you do, and for how long?
Incident Response and Evidence
Contain harm while preserving what explains it.
Monitoring, Automation and Investigation
Correlate signals; constrain automated actions.
Governance, Risk and Assurance
Business owns risk; controls reduce it; evidence checks it.
Data Lifecycle, Privacy and Recovery
Know the owner, keep only what you need, test restoration.
Security Leadership, Ethics and Business Risk
Protect people; understand the business; assign the risk owner.
Security Models, Trusted Computing and Cryptanalysis
Confidentiality keeps secrets; integrity protects trustworthy change.
Network, Facility and Distributed-System Design
Trace every trust boundary, including the physical one.
Identity Assurance and Access Models
Proof the identity, bind the credential, limit the session.
Security Assessment and Assurance
Test the requirement; report the business consequence.
Secure Software Lifecycle and Supply Chains
Build the control into the path that ships code.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
- ISC2 official training ↗ Vendor learning reference
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.