Skip to content

Practical handbook

CISSP Certification Guide

An independent study guide and practice question bundle for the ISC2 CISSP exam: the eight domains, the manager-perspective mindset, and a full practice exam.

An eight-domain emblem wheel of eight exact colored sectors around concentric defense-in-depth rings and a golden core, beneath the title CISSP Certification Guide.

Reading order

Contents

Part 1

Part I - Orientation and Exam Blueprint

2 entries
  1. 01 How to Use This Guide
  2. 02 The CISSP Exam Blueprint and the Eight Domains

Part 2

Part II - Security and Risk Management

5 entries
  1. 03 Governance, Compliance, and Legal Frameworks
  2. 04 Risk Management and Threat Modeling
  3. 05 Business Continuity and Disaster Recovery Planning
  4. 06 Security Policies, Training, and Awareness
  5. 07 Domain 1 Practice Test: Security and Risk Management

Part 3

Part III - Asset Security

4 entries
  1. 08 Asset Inventory, Ownership, and Classification
  2. 09 Privacy and Data Protection
  3. 10 Retention, Handling, and Disposal
  4. 11 Domain 2 Practice Test: Asset Security

Part 4

Part IV - Security Architecture and Engineering

4 entries
  1. 12 Security Design Principles and Architecture Models
  2. 13 Cryptography and Key Management
  3. 14 Secure System Design, Evaluation Models, and Physical Security
  4. 15 Domain 3 Practice Test: Security Architecture and Engineering

Part 5

Part V - Communication and Network Security

3 entries
  1. 16 Network Architectures and Protocols
  2. 17 Secure Communications and Network Attacks
  3. 18 Domain 4 Practice Test: Communication and Network Security

Part 6

Part VI - Identity and Access Management

3 entries
  1. 19 Identity and Access Control Models
  2. 20 Identity and Access Management Implementation
  3. 21 Domain 5 Practice Test: Identity and Access Management

Part 7

Part VII - Security Assessment and Testing

3 entries
  1. 22 Assessment and Testing Strategy
  2. 23 Security Testing Tools and Evidence
  3. 24 Domain 6 Practice Test: Security Assessment and Testing

Part 8

Part VIII - Security Operations

4 entries
  1. 25 Security Operations, Monitoring, and Logging
  2. 26 Incident Response and Investigation
  3. 27 Resilience, Availability, and Physical Operations
  4. 28 Domain 7 Practice Test: Security Operations

Part 9

Part IX - Software Development Security

3 entries
  1. 29 Secure Software Development Lifecycle
  2. 30 Software Security Testing and Secure Coding
  3. 31 Domain 8 Practice Test: Software Development Security

Part 10

Part X - Exam Strategy and Full Practice Exams

4 entries
  1. 32 Exam Strategy and Question Technique
  2. 33 Full Practice Exam I: Questions 1–63
  3. 34 Full Practice Exam II: Questions 64–125
  4. 35 Final Readiness Review