T Techclick ← All lessons
ISC2 · CISSP · Interactive lesson

Map all 8 CISSP domains as one program

The exam is not eight silos. It is one security program: decide acceptable risk, name the assets, design and grant access, prove the controls, then operate and recover. Think like a manager. PACES the item before you click.

18 min read · L2 primary · Quiz at end

⚡ Quick Answer

Map all 8 CISSP domains as one security program. Manager mindset, PACES item analysis, and how the domains connect. Official ISC2 April 2024 exam outline only.

After this page you can

Quick answer

CISSP is one connected program. Domain 1 sets policy and acceptable risk. Domain 2 names what you protect. Domains 3, 4, 5, and 8 build and grant the controls. Domain 6 proves they work. Domain 7 runs, detects, and recovers — then feeds lessons back to Domain 1. On the item, think manager: policy before product. After a miss, run PACES before you restudy a chapter.

1. Why the map beats a dump

2 a.m. ransomware is on a file server. The engineer instinct is wipe and rebuild. The exam stem says FIRST. The manager move is contain, assess scope, and protect evidence — then eradicate. Same night, same facts, two brains.

That is the whole CISSP problem. Candidates fail by treating the Common Body of Knowledge as eight flash-card piles. The April 15, 2024 ISC2 CISSP exam outline lists eight domains because they are the rooms of one job: design, engineer, and manage the organization’s security posture.

Hero · one program, eight rooms
Teaches: eight CISSP domains sit around one manager program, not eight silos
Notice the loop, not a list. Policy and assets sit upstream of design, identity, software, proof, and operations.

ISC2 states the credential tests deep technical and managerial knowledge. Computerized Adaptive Testing (CAT) does not walk domain 1, then 2, then 3. Items are selected to the outline weights. If you cannot connect rooms, a hard item feels random.

This page is the map

Deep-dives live on the Domain 1–8 lessons. Here you learn the wiring: manager mindset, PACES, and how a ticket travels across domains. Do not memorize every outline bullet on this page.

2. Mental model: one program, eight rooms

Pre-train three words. Policy is the management statement of direction. Control is a safeguard you select after risk. Evidence is what Domain 6 and Domain 7 produce so Domain 1 can update residual risk.

Read the program left to right, then back. Domain 1 decides what “enough security” means. Domain 2 classifies the thing you are protecting. Design, network, identity, and software (3, 4, 5, 8) implement that decision. Assessment proves it. Operations lives it. Lessons learned return to risk.

Flow 1 · the domain loop
Decide → protect → prove → operate → update risk D1 Risk + policy Acceptable risk · 16% D2 Assets Classify · handle · 10% Build the controls D3 Design 13% · D4 Network 13% D5 IAM 13% · D8 Software 10% D6 Prove Test · audit · 12% D7 Operate Detect · recover · 13% Lessons → D1 Update residual risk Weights are official average weights from the April 2024 outline — not study-hour guesses CAT still samples all eight rooms. A 10% domain can still fail you if you treat it as optional.

Read clockwise from D1. Operations is not the end — it is the sensor that updates risk.

Say this out loud

Policy sets the target. Assets name the thing. Design, network, identity, and software build the path. Testing proves it. Operations lives it and sends the residual-risk number back upstairs.

3. Manager mindset + PACES

ISC2’s own description is the mindset: you design, engineer, and manage the posture. On FIRST / BEST items the engineer brain grabs a product. The manager brain asks who owns the decision, what risk is acceptable, and which control type fits — preventive, detective, or corrective — after the assessment.

Visual · Path A tool vs Path B governance
Teaches: FIRST items split engineer-tool path from manager-policy path
Path A buys a control. Path B writes or applies policy and finishes a risk assessment first. The exam almost always wants Path B on FIRST.
Stem wordManager moveEngineer trap
FIRSTRisk assessment, policy, or the next process step in the outlineInstall, configure, or wipe
BESTMost complete risk-based answer that still enables the businessThe most technical or most expensive control
Access disputeData owner classifies and approves; security implementsCISO or admin decides the label
People at riskSafety and availability can outrank confidentiality (site, OT, emergency)Always lock it down
New vendor / AI / SaaSDomain 1 supply-chain and risk concepts before a pilotConnect the API and “harden later”

PACES is a Techclick item-analysis loop, not an ISC2 domain. Use it after every miss. It is how you force the manager lens onto four options.

Visual · PACES sequence
Teaches: five PACES checks left to right before you restudy a chapter
Do not open a 400-page chapter after a miss. Walk P → A → C → E → S first. The failure is usually C or E, not a missing port number.
LetterMeansAsk yourself
P PossibilityRead every interpretation of the stemIs FIRST asking for process order, not the “best tool”?
A AlternativesEliminate before you fall in loveWhich two options are the same layer of thinking?
C ConsequencesBusiness and people impactDid I pick a tech fix that ignores residual risk or safety?
E EvidenceOutline language, not war-story habitWhich domain task actually owns this?
S SelectionName the failure patternEngineer brain? Experience shortcut? Red-herring protocol?
Unsafe shortcut

“In my SOC we just isolate and reimage.” Real shops do that under a playbook. The exam still wants the outline order: investigations and incident management have evidence handling, then detection / response / mitigation / recovery / lessons learned. Your shop’s skip is not the scoring key.

4. How the eight domains connect

One job sentence each. Official names and average weights are from the April 2024 outline. This is the wiring diagram, not the CBK dump.

DomainWeightJob in the programFeeds / fed by
1. Security and Risk Management16%Ethics, CIA + authenticity + nonrepudiation, governance, legal/privacy, policy stack, BIA, personnel security, risk, threat modeling, supply-chain risk, awarenessSets the target every other domain implements
2. Asset Security10%Classify, handle, provision, lifecycle roles (owner / custodian / processor), retention, data states, DLP / DRM / CASB as protection methodsNeeds D1 policy; tells D3–D5–D8 what to protect
3. Security Architecture and Engineering13%Secure design principles, models, system capabilities, crypto, site/facility, information-system lifecycleTurns D1/D2 requirements into a buildable design
4. Communication and Network Security13%Secure architecture (OSI/TCP-IP, segmentation, ZT/micro-seg, SDN/VPC), harden components, secure channelsCarries D2 assets along a D3 design
5. Identity and Access Management (IAM)13%Physical/logical access, IAAA, federation, authorization models, provisioning lifecycle, auth systemsEnforces D1 policy on D2 assets
6. Security Assessment and Testing12%Assessment strategy, control testing, process data, reports, audits (internal / external / third-party)Proves D3–D5–D8 controls; evidence returns to D1
7. Security Operations13%Investigations, logging/monitoring, CM, IR, patch, change, DR/BC, physical and personnel safetyRuns the program; lessons update D1 residual risk
8. Software Development Security10%Security in the SDLC, ecosystem controls (SAST/DAST/SCA/IAST), acquired software, secure codingBuilds what D3 designed; D6 tests it; D7 runs it

ISC2’s outline page also states AI security is interwoven across all eight domains, not a ninth domain. Same loop: govern the model (D1), classify training data and weights (D2), design and isolate the system (D3/D4), identity for agents (D5), red-team the model (D6), monitor drift and abuse (D7), secure the SDLC and libraries (D8).

Upstream rooms

D1 and D2. If these are missing, every later control is decoration. FIRST items live here more than candidates expect.

Build rooms

D3, D4, D5, D8. Pick these when the stem already has policy and classification and now asks how to implement.

Proof room

D6. Scan lists weakness. Pen test proves exploitability. Audit attests over a period. Do not mix those three.

Live room

D7. Contain before eradicate. Chain of custody if it may become evidence. DR tests are not the same as backups existing.

5. Decision flow: who owns FIRST

Flowchart first. Use this when the stem is a messy workplace story.

Flow 2 · route the FIRST move
Start: what is missing in the story? Is anyone hurt or still bleeding? YES D7 + people safety Contain · stabilize · 7.15 NO Policy / risk done? If NO → D1 first RA · policy · SCRM Asset classified? If NO → D2 Build it → D3 / D8 Move it → D4 Who may → D5 Prove it → D6 Diamond = missing input, not “favorite domain” If policy is absent, a perfect ZTNA design is the wrong FIRST answer.

Diamond = decision. Always ask what input is missing before you pick a build-domain control.

6. How to choose the first move

Compare stems the way CAT will mix them. Same company, different missing room.

SituationFirst domainManager first moveNot first
New KYC vendor will see customer PIID1Supply-chain risk + contractual / regulatory requirementsBuy a CASB and “onboard Friday”
PII found in an unnamed US bucketD2Classify, assign owner, set handling and location rulesTurn on random encryption
App design review, labels already setD3Secure design principles (least privilege, fail securely, privacy by design)Write IR playbooks first
Malware on a laptop, flat VLAND4 then D7Contain now; design micro-segmentation / ZT so blast radius shrinksRewrite the security policy from scratch tonight
Contractor still has standing adminD5Deprovision + lifecycle / JIT; owner already decided the roleNew SIEM use-case as the only fix
Buyer wants proof controls operatedD6Assessment / audit strategy that matches who must attestA self-made vuln-scan PDF
Ransomware note on a file serverD7Incident management: detect, contain, then recover; preserve artifactsReformat as step one
CVE in a library, 40 servicesD8Inventory / SCA / acquired-software impact, then patch via changeFull-interruption DR test first
Study time vs weight

Official average weights: D1 16%; D3, D4, D5, D7 13% each; D6 12%; D2 and D8 10% each. Budget hours to the loop, not only to D1. CAT is compensatory — strong rooms can offset a weak one, but they are not a license to skip D8.

7. Item runbook: Side A / B / C

Treat every scored item like a change ticket. Primary source for facts: the current CISSP Certification Exam Outline.

Side A — Read the stem (external facts)

  1. Circle the verb

    FIRST, BEST, PRIMARY, MOST cost-effective, IMMEDIATELY, NOT. FIRST almost always wants process order from the outline, not your favorite tool.

  2. Name the asset and the role

    Who is speaking — owner, custodian, processor, CISO, engineer? Domain 2 roles decide who is allowed to choose the label. Domain 1 decides ethics if public safety is in the stem.

  3. Mark what is already done

    If the stem says “policy is approved” or “data is classified Restricted,” do not rewind to write policy. Move to the next room in the loop.

Side B — PACES (your analysis)

  1. P and A

    Write one sentence for each option in manager language. Strike any option that installs a product before risk, or that skips a required lifecycle step (for example eradicate before contain when evidence still matters).

  2. C and E

    Consequences: people, residual risk, business enablement. Evidence: which outline task number could you point to? If you cannot point to a domain task, you are guessing from a vendor blog.

  3. S

    Name the pattern: engineer brain, experience shortcut, or red-herring protocol. Then commit. CAT does not allow review.

Side C — Prove the pick

  1. Say the connecting sentence

    “D2 already classified it, so the first remaining gap is D5 deprovision” — or whatever the loop says. If you cannot say the sentence, you picked a silo.

  2. After a miss, PACES before reread

    Only then open the matching domain lesson. Do not reread all eight.

Whiteboard card (say it, do not memorize a dump)
D1 decide risk + write policy
D2 name + classify the asset
D3 design  ·  D4 carry  ·  D5 grant  ·  D8 build
D6 prove  ·  D7 run and recover  ·  back to D1
PACES after every miss

8. CAT runtime path

Official CAT facts from ISC2 — not forum lore.

Visual · proof and exam-day calm
Teaches: proof is calm verification, not panic at a hard item
CAT targets items you have about a 50% chance of answering. Feeling that every item is hard is the design, not a fail signal.
FactOfficial valueWhat you do with it
FormatCAT only · multiple choice + advanced itemsNo linear form. No going back after you confirm.
Length / time100–150 items · 3 hours · breaks count against the clockAnswer at least 100 operational+pretest mix; do not stall 5 minutes on item 12.
Pretest25 unscored items inside the examYou cannot see which. Treat every item as scored.
Pass mark700 out of 1000 scaledYou do not get a numeric score on the printout.
Stop rules95% confidence after 100 · or max length · or timeStop at 100 can be pass or fail. Extra items mean the engine needs more data.
Content orderNot in domain sections; weights still applyThe map matters more than “I studied D4 today.”
ScoringCompensatory across domainsYou need overall proficiency, not “above” in every room.

Experience, also official: five years cumulative full-time in two or more of the eight current domains. A qualifying degree or one credential on the ISC2 approved list may waive one year only. Full-time is defined as at least 35 hours/week for four weeks per month accrued. Part-time (20–34 hours) converts at 1040 hours = 6 months and 2080 hours = 12 months. Internships can count with letterhead documentation. Pass without the time and you may become an Associate of ISC2 and have six years to earn the experience.

Eligibility proof

Map your jobs to two or more outline domains by task, not by job title. “Firewall admin” can be D4 + D7. “IAM engineer” can be D5 + D1 policy. Write the domain numbers before you apply — ISC2 will ask for them.

9. Traps + proof checklist

FailureWhat it looks likeFix
Silo studyYou can recite D5 models and still pick “install DLP” on a FIRST vendor itemRedraw the loop. Ask which input is missing.
Engineer brainBest tool winsPACES letter C. Policy and risk assessment sit in D1 for a reason.
Shop shortcut“We reimage first”Outline order: investigations + IR phases. Evidence can matter.
Weight worshipSkip D2 and D8 because they are 10%CAT still samples them. Software and assets are how other rooms fail in production.
AI as a ninth domainWait for a dedicated AI chapterOfficial stance: AI tasks are woven through all eight rooms.
CAT panicHard item = I am failingOfficial design: next item is aimed near 50% for you.
Invented numbersForum weights, fake passing percentagesUse only the published average weights and 700/1000.
Pilot checklist — you are ready for domain deep-dives when

Knowledge check

Six judgment items. Map, mindset, PACES, CAT. Check answers when you finish.

Q1

Procurement wants to connect a new AI vendor to customer records next sprint. The stem asks what the security professional should do FIRST. What is the manager pick?

Correct: b. FIRST + new vendor / AI is Domain 1: risk, governance, and supply-chain concepts. Pilot and tools come after the acceptable-risk decision. Re-read manager mindset and the choose table.
Q2

A ransomware note appears on a file server. An engineer starts a rebuild from gold images. What should have been FIRST in the Domain 7 incident path?

Correct: b. Domain 7 incident management is detect → respond / mitigate → recover, with investigations requiring evidence handling. Wipe-first destroys both containment options and artifacts. Re-read the decision flow and traps.
Q3

Business and security disagree on whether a customer table is Internal or Restricted. Who decides the classification?

Correct: c. Domain 2 data roles: owners set classification and handling; custodians implement. Domain 1 does not steal the owner’s decision. Re-read how domains connect.
Q4

You missed a FIRST item by choosing “deploy a CASB this week.” Which PACES letter failed first?

Correct: c. Consequences asks whether you thought impact and process, not a product. E is the opposite of “forbid the outline” — evidence is the outline. Re-read PACES.
Q5

A payments API will store PAN. The data owner has just classified it Restricted. What is the next connecting move across the map?

Correct: a. D2 just finished. Next rooms implement handling and controls under existing D1 risk appetite — D3/D5/D8, then D6 proves, D7 runs. Re-read the domain loop.
Q6

On CAT every item feels hard. You cannot review the last answer. What does ISC2’s CAT design say that feeling means?

Correct: b. Official CAT FAQ: after each answer the next item is chosen so you have roughly a 50% chance. No review. Skipping risks the run-out-of-time fail if you never reach the minimum item count. Re-read CAT runtime.

Sources

Related: Domain 1 · Domain 2 · Domain 3 · Domain 4 · Domain 5 · Domain 6 · Domain 7 · Domain 8