certslothcertsloth
← All certifications

ISC2 / Professional / CISSP

Information Systems Security Professional

Connect technical controls to business risk, assurance and accountable decisions across all eight security domains.

16 focused topics80 recall promptsReviewed 2026-10-10

Uses the current April 2024 outline and its published AI guidance. Passing the exam alone does not grant CISSP: experience, endorsement and other credential requirements also apply. Foundation topics are shared with our Security+ path; start with chapters 11–16 for the professional distinctions.

THE REVISION PATH

Your topics, in order.

Read. Recall. Explain the alternative.

01

Security Principles and Controls

Protect the right property with the right kind of control.

2 min ↗
02

Threats, Attacks and Indicators

Actor explains intent; evidence identifies the technique.

3 min ↗
03

Cryptography, Certificates and Keys

Encrypt for secrecy; sign for origin; hash for comparison.

2 min ↗
04

Secure Architecture and Network Defences

Reduce exposure; separate trust; inspect the right layer.

2 min ↗
05

Hardening and Vulnerability Management

Inventory, prioritize, fix, verify.

2 min ↗
06

Identity, Authentication and Privileged Access

Who are you, what may you do, and for how long?

2 min ↗
07

Incident Response and Evidence

Contain harm while preserving what explains it.

2 min ↗
08

Monitoring, Automation and Investigation

Correlate signals; constrain automated actions.

2 min ↗
09

Governance, Risk and Assurance

Business owns risk; controls reduce it; evidence checks it.

2 min ↗
10

Data Lifecycle, Privacy and Recovery

Know the owner, keep only what you need, test restoration.

2 min ↗
11

Security Leadership, Ethics and Business Risk

Protect people; understand the business; assign the risk owner.

3 min ↗
12

Security Models, Trusted Computing and Cryptanalysis

Confidentiality keeps secrets; integrity protects trustworthy change.

2 min ↗
13

Network, Facility and Distributed-System Design

Trace every trust boundary, including the physical one.

2 min ↗
14

Identity Assurance and Access Models

Proof the identity, bind the credential, limit the session.

2 min ↗
15

Security Assessment and Assurance

Test the requirement; report the business consequence.

2 min ↗
16

Secure Software Lifecycle and Supply Chains

Build the control into the path that ships code.

3 min ↗

How this guide is organised

Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.

Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.

Search across every published topic.