CISSP is one connected program. Domain 1 sets policy and acceptable risk. Domain 2 names what you protect. Domains 3, 4, 5, and 8 build and grant the controls. Domain 6 proves they work. Domain 7 runs, detects, and recovers — then feeds lessons back to Domain 1. On the item, think manager: policy before product. After a miss, run PACES before you restudy a chapter.
1. Why the map beats a dump
2 a.m. ransomware is on a file server. The engineer instinct is wipe and rebuild. The exam stem says FIRST. The manager move is contain, assess scope, and protect evidence — then eradicate. Same night, same facts, two brains.
That is the whole CISSP problem. Candidates fail by treating the Common Body of Knowledge as eight flash-card piles. The April 15, 2024 ISC2 CISSP exam outline lists eight domains because they are the rooms of one job: design, engineer, and manage the organization’s security posture.
ISC2 states the credential tests deep technical and managerial knowledge. Computerized Adaptive Testing (CAT) does not walk domain 1, then 2, then 3. Items are selected to the outline weights. If you cannot connect rooms, a hard item feels random.
Deep-dives live on the Domain 1–8 lessons. Here you learn the wiring: manager mindset, PACES, and how a ticket travels across domains. Do not memorize every outline bullet on this page.
2. Mental model: one program, eight rooms
Pre-train three words. Policy is the management statement of direction. Control is a safeguard you select after risk. Evidence is what Domain 6 and Domain 7 produce so Domain 1 can update residual risk.
Read the program left to right, then back. Domain 1 decides what “enough security” means. Domain 2 classifies the thing you are protecting. Design, network, identity, and software (3, 4, 5, 8) implement that decision. Assessment proves it. Operations lives it. Lessons learned return to risk.
Read clockwise from D1. Operations is not the end — it is the sensor that updates risk.
Policy sets the target. Assets name the thing. Design, network, identity, and software build the path. Testing proves it. Operations lives it and sends the residual-risk number back upstairs.
3. Manager mindset + PACES
ISC2’s own description is the mindset: you design, engineer, and manage the posture. On FIRST / BEST items the engineer brain grabs a product. The manager brain asks who owns the decision, what risk is acceptable, and which control type fits — preventive, detective, or corrective — after the assessment.
| Stem word | Manager move | Engineer trap |
|---|---|---|
| FIRST | Risk assessment, policy, or the next process step in the outline | Install, configure, or wipe |
| BEST | Most complete risk-based answer that still enables the business | The most technical or most expensive control |
| Access dispute | Data owner classifies and approves; security implements | CISO or admin decides the label |
| People at risk | Safety and availability can outrank confidentiality (site, OT, emergency) | Always lock it down |
| New vendor / AI / SaaS | Domain 1 supply-chain and risk concepts before a pilot | Connect the API and “harden later” |
PACES is a Techclick item-analysis loop, not an ISC2 domain. Use it after every miss. It is how you force the manager lens onto four options.
| Letter | Means | Ask yourself |
|---|---|---|
| P Possibility | Read every interpretation of the stem | Is FIRST asking for process order, not the “best tool”? |
| A Alternatives | Eliminate before you fall in love | Which two options are the same layer of thinking? |
| C Consequences | Business and people impact | Did I pick a tech fix that ignores residual risk or safety? |
| E Evidence | Outline language, not war-story habit | Which domain task actually owns this? |
| S Selection | Name the failure pattern | Engineer brain? Experience shortcut? Red-herring protocol? |
“In my SOC we just isolate and reimage.” Real shops do that under a playbook. The exam still wants the outline order: investigations and incident management have evidence handling, then detection / response / mitigation / recovery / lessons learned. Your shop’s skip is not the scoring key.
4. How the eight domains connect
One job sentence each. Official names and average weights are from the April 2024 outline. This is the wiring diagram, not the CBK dump.
| Domain | Weight | Job in the program | Feeds / fed by |
|---|---|---|---|
| 1. Security and Risk Management | 16% | Ethics, CIA + authenticity + nonrepudiation, governance, legal/privacy, policy stack, BIA, personnel security, risk, threat modeling, supply-chain risk, awareness | Sets the target every other domain implements |
| 2. Asset Security | 10% | Classify, handle, provision, lifecycle roles (owner / custodian / processor), retention, data states, DLP / DRM / CASB as protection methods | Needs D1 policy; tells D3–D5–D8 what to protect |
| 3. Security Architecture and Engineering | 13% | Secure design principles, models, system capabilities, crypto, site/facility, information-system lifecycle | Turns D1/D2 requirements into a buildable design |
| 4. Communication and Network Security | 13% | Secure architecture (OSI/TCP-IP, segmentation, ZT/micro-seg, SDN/VPC), harden components, secure channels | Carries D2 assets along a D3 design |
| 5. Identity and Access Management (IAM) | 13% | Physical/logical access, IAAA, federation, authorization models, provisioning lifecycle, auth systems | Enforces D1 policy on D2 assets |
| 6. Security Assessment and Testing | 12% | Assessment strategy, control testing, process data, reports, audits (internal / external / third-party) | Proves D3–D5–D8 controls; evidence returns to D1 |
| 7. Security Operations | 13% | Investigations, logging/monitoring, CM, IR, patch, change, DR/BC, physical and personnel safety | Runs the program; lessons update D1 residual risk |
| 8. Software Development Security | 10% | Security in the SDLC, ecosystem controls (SAST/DAST/SCA/IAST), acquired software, secure coding | Builds what D3 designed; D6 tests it; D7 runs it |
ISC2’s outline page also states AI security is interwoven across all eight domains, not a ninth domain. Same loop: govern the model (D1), classify training data and weights (D2), design and isolate the system (D3/D4), identity for agents (D5), red-team the model (D6), monitor drift and abuse (D7), secure the SDLC and libraries (D8).
Upstream rooms
D1 and D2. If these are missing, every later control is decoration. FIRST items live here more than candidates expect.
Build rooms
D3, D4, D5, D8. Pick these when the stem already has policy and classification and now asks how to implement.
Proof room
D6. Scan lists weakness. Pen test proves exploitability. Audit attests over a period. Do not mix those three.
Live room
D7. Contain before eradicate. Chain of custody if it may become evidence. DR tests are not the same as backups existing.
5. Decision flow: who owns FIRST
Flowchart first. Use this when the stem is a messy workplace story.
Diamond = decision. Always ask what input is missing before you pick a build-domain control.
6. How to choose the first move
Compare stems the way CAT will mix them. Same company, different missing room.
| Situation | First domain | Manager first move | Not first |
|---|---|---|---|
| New KYC vendor will see customer PII | D1 | Supply-chain risk + contractual / regulatory requirements | Buy a CASB and “onboard Friday” |
| PII found in an unnamed US bucket | D2 | Classify, assign owner, set handling and location rules | Turn on random encryption |
| App design review, labels already set | D3 | Secure design principles (least privilege, fail securely, privacy by design) | Write IR playbooks first |
| Malware on a laptop, flat VLAN | D4 then D7 | Contain now; design micro-segmentation / ZT so blast radius shrinks | Rewrite the security policy from scratch tonight |
| Contractor still has standing admin | D5 | Deprovision + lifecycle / JIT; owner already decided the role | New SIEM use-case as the only fix |
| Buyer wants proof controls operated | D6 | Assessment / audit strategy that matches who must attest | A self-made vuln-scan PDF |
| Ransomware note on a file server | D7 | Incident management: detect, contain, then recover; preserve artifacts | Reformat as step one |
| CVE in a library, 40 services | D8 | Inventory / SCA / acquired-software impact, then patch via change | Full-interruption DR test first |
Official average weights: D1 16%; D3, D4, D5, D7 13% each; D6 12%; D2 and D8 10% each. Budget hours to the loop, not only to D1. CAT is compensatory — strong rooms can offset a weak one, but they are not a license to skip D8.
7. Item runbook: Side A / B / C
Treat every scored item like a change ticket. Primary source for facts: the current CISSP Certification Exam Outline.
Side A — Read the stem (external facts)
-
Circle the verb
FIRST, BEST, PRIMARY, MOST cost-effective, IMMEDIATELY, NOT. FIRST almost always wants process order from the outline, not your favorite tool.
-
Name the asset and the role
Who is speaking — owner, custodian, processor, CISO, engineer? Domain 2 roles decide who is allowed to choose the label. Domain 1 decides ethics if public safety is in the stem.
-
Mark what is already done
If the stem says “policy is approved” or “data is classified Restricted,” do not rewind to write policy. Move to the next room in the loop.
Side B — PACES (your analysis)
-
P and A
Write one sentence for each option in manager language. Strike any option that installs a product before risk, or that skips a required lifecycle step (for example eradicate before contain when evidence still matters).
-
C and E
Consequences: people, residual risk, business enablement. Evidence: which outline task number could you point to? If you cannot point to a domain task, you are guessing from a vendor blog.
-
S
Name the pattern: engineer brain, experience shortcut, or red-herring protocol. Then commit. CAT does not allow review.
Side C — Prove the pick
-
Say the connecting sentence
“D2 already classified it, so the first remaining gap is D5 deprovision” — or whatever the loop says. If you cannot say the sentence, you picked a silo.
-
After a miss, PACES before reread
Only then open the matching domain lesson. Do not reread all eight.
D1 decide risk + write policy D2 name + classify the asset D3 design · D4 carry · D5 grant · D8 build D6 prove · D7 run and recover · back to D1 PACES after every miss
8. CAT runtime path
Official CAT facts from ISC2 — not forum lore.
| Fact | Official value | What you do with it |
|---|---|---|
| Format | CAT only · multiple choice + advanced items | No linear form. No going back after you confirm. |
| Length / time | 100–150 items · 3 hours · breaks count against the clock | Answer at least 100 operational+pretest mix; do not stall 5 minutes on item 12. |
| Pretest | 25 unscored items inside the exam | You cannot see which. Treat every item as scored. |
| Pass mark | 700 out of 1000 scaled | You do not get a numeric score on the printout. |
| Stop rules | 95% confidence after 100 · or max length · or time | Stop at 100 can be pass or fail. Extra items mean the engine needs more data. |
| Content order | Not in domain sections; weights still apply | The map matters more than “I studied D4 today.” |
| Scoring | Compensatory across domains | You need overall proficiency, not “above” in every room. |
Experience, also official: five years cumulative full-time in two or more of the eight current domains. A qualifying degree or one credential on the ISC2 approved list may waive one year only. Full-time is defined as at least 35 hours/week for four weeks per month accrued. Part-time (20–34 hours) converts at 1040 hours = 6 months and 2080 hours = 12 months. Internships can count with letterhead documentation. Pass without the time and you may become an Associate of ISC2 and have six years to earn the experience.
Map your jobs to two or more outline domains by task, not by job title. “Firewall admin” can be D4 + D7. “IAM engineer” can be D5 + D1 policy. Write the domain numbers before you apply — ISC2 will ask for them.
9. Traps + proof checklist
| Failure | What it looks like | Fix |
|---|---|---|
| Silo study | You can recite D5 models and still pick “install DLP” on a FIRST vendor item | Redraw the loop. Ask which input is missing. |
| Engineer brain | Best tool wins | PACES letter C. Policy and risk assessment sit in D1 for a reason. |
| Shop shortcut | “We reimage first” | Outline order: investigations + IR phases. Evidence can matter. |
| Weight worship | Skip D2 and D8 because they are 10% | CAT still samples them. Software and assets are how other rooms fail in production. |
| AI as a ninth domain | Wait for a dedicated AI chapter | Official stance: AI tasks are woven through all eight rooms. |
| CAT panic | Hard item = I am failing | Official design: next item is aimed near 50% for you. |
| Invented numbers | Forum weights, fake passing percentages | Use only the published average weights and 700/1000. |
- You can draw the eight-room loop from memory and point to official weights.
- You can PACES a missed FIRST item in under two minutes.
- You can route the eight situations in the choose table without opening notes.
- You can state CAT length, pretest count, no-review rule, and experience waiver from ISC2 pages.
- You know AI is across the outline, not a bonus domain.
Knowledge check
Six judgment items. Map, mindset, PACES, CAT. Check answers when you finish.
Sources
- ISC2 — CISSP Certification Exam Outline (effective 15 April 2024): eight domains, average weights, exam length, item range, 700/1000, CAT, experience summary, AI woven across domains, PDF outline link.
- ISC2 — CISSP Exam Outline April 2024 (English PDF)
- ISC2 — Computerized Adaptive Testing: 100–150 items, 25 pretest, no review, compensatory scoring, stop rules, ~50% targeting.
- ISC2 — CISSP Experience Requirements: five years in two or more domains, one-year waiver, Associate of ISC2 (six years), full-time / part-time hour rules.
- ISC2 — CISSP certification overview
Related: Domain 1 · Domain 2 · Domain 3 · Domain 4 · Domain 5 · Domain 6 · Domain 7 · Domain 8