Exam Details
- Exam Code: CISSP
- Format: Computerized Adaptive Testing (CAT)
- Questions: 100-150 (CAT), 250 (linear format)
- Duration: 3 hours (CAT), 6 hours (linear)
- Passing Score: 700 out of 1000 points
- Cost: $749 USD
- Validity: 3 years (with CPE credits)
Prerequisites
- Experience: 5 years paid full-time security work (or 4 years + degree or cert)
- Domains: Must have experience in 2+ of the 8 domains
- Endorsement: Required by (ISC)² member (provided if not known)
- Background Check: Conducted by (ISC)²
- Associate Option: Can test first, gain experience later (6 years to complete)
CISSP Value
- Gold standard certification for security professionals
- Vendor-neutral, globally recognized
- Management and strategic focus ("think like a manager")
- DoD 8140/8570 approved
- Significant salary premium ($120-180K+)
- Required for many senior security positions
Exam Approach
- Think strategically, not tactically
- Choose "best" answer from all correct options
- Management perspective (policies > tools)
- Read carefully for keywords (BEST, MOST, FIRST)
- Process of elimination
- No negative marking - answer everything
CISSP 8 Domains
Security and Risk Management
15% of exam - Governance, compliance, legal, ethics, risk management
Asset Security
10% of exam - Data classification, ownership, privacy, retention
Security Architecture and Engineering
13% of exam - Secure design, cryptography, physical security
Communication and Network Security
13% of exam - Network architecture, secure components, protocols
Identity and Access Management
13% of exam - Authentication, authorization, identity management
Security Assessment and Testing
12% of exam - Vulnerability assessments, pen testing, audits
Security Operations
13% of exam - Investigations, incident response, BCP/DRP
Software Development Security
11% of exam - SDLC security, secure coding, application security