← Home
ISC2 · Full exam outline

CISSP

Certified Information Systems Security Professional

Security managers, directors, CISOsCore certification
1Security and Risk Management16%
1.1Understand, adhere to, and promote professional ethics
1.2Understand and apply security concepts
1.3Evaluate and apply security governance principles
1.4Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
1.5Understand requirements for investigation types
1.6Develop, document, and implement security policy, standards, procedures, and guidelines
1.7Identify, analyze, assess, prioritize, and implement business continuity (BC) requirements
1.8Contribute to and enforce personnel security policies and procedures
1.9Understand and apply risk management concepts
1.10Understand and apply threat modeling concepts and methodologies
1.11Apply supply chain risk management (SCRM) concepts
1.12Establish and maintain a security awareness, education, and training program
2Asset Security10%
2.1Identify and classify information and assets
2.2Establish information and asset handling requirements
2.3Provision information and assets securely
2.4Manage data lifecycle
2.5Ensure appropriate asset retention
2.6Determine data security controls and compliance requirements
3Security Architecture and Engineering13%
3.1Research, implement, and manage engineering processes using secure design principles
3.2Understand the fundamental concepts of security models
3.3Select controls based upon systems security requirements
3.4Understand security capabilities of information systems
3.5Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
3.6Select and determine cryptographic solutions
3.7Apply security principles to site and facility design
4Communication and Network Security13%
4.1Apply secure design principles in network architectures
4.2Secure network components
4.3Implement secure communication channels according to design
5Identity and Access Management (IAM)13%
5.1Control physical and logical access to assets
5.2Design identification and authentication strategy
5.3Federated identity with a third-party service
5.4Implement and manage authorization mechanisms
5.5Manage the identity and access provisioning lifecycle
6Security Assessment and Testing12%
6.1Design and validate assessment, test, and audit strategies
6.2Conduct security control testing
6.3Collect security process data
6.4Analyze test output and generate report
6.5Conduct or facilitate security audits
7Security Operations13%
7.1Understand and comply with investigations
7.2Conduct logging and monitoring activities
7.3Conduct incident management
7.4Implement recovery strategies
7.5Implement disaster recovery (DR) processes and test plans
8Software Development Security10%
8.1Understand and integrate security in the software development life cycle (SDLC)
8.2Identify and apply security controls in software development ecosystems
8.3Assess the effectiveness of software security
8.4Define and apply secure coding guidelines and standards
Weights are the certification body’s published values and are checked against each outline revision.