Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
GIAC (SANS)

GIAC Information Security Professional

The GIAC Information Security Professional (GISP) certification validates a practitioner's understanding of the eight domains of cybersecurity knowledge that form the critical foundation of the CISSP® exam. Designed for security professionals, system and network administrators, and security managers, GISP demonstrates broad security domain fluency and offers a pragmatic alternative to CISSP, signaling expertise validated by a respected provider.

Exam formatProctored exam
Duration240 minutes
DeliveryGIAC
Passing score70%
Free questions429

Content last reviewed 30 July 2026 · Up to date

The certification

What GIAC Information Security Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

3domains
8objectives
81concepts
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The GIAC Information Security Professional (GISP) certification validates a practitioner's understanding of the eight domains of cybersecurity knowledge, as determined by ISC2, that form a critical part of the CISSP® exam. GISP certification holders have demonstrated expertise in security and risk management, asset security, security architecture and engineering, communication and network security, identity and access management (IAM), security assessment and testing, security operations, and software development security.

GISP offers a pragmatic alternative to CISSP, signaling broad security domain fluency validated by a respected provider. It is designed for security professionals who want to understand the concepts covered in the CISSP® exam, including system administrators, security administrators, network administrators, and security managers. Earning GISP demonstrates a solid grasp of the foundational knowledge required to protect modern organizations.

Who it’s for

The GISP certification is for security professionals who want to understand the concepts covered in the CISSP® exam as determined by ISC2. It is particularly suited for system administrators, security administrators, network administrators, and security managers who need a broad understanding of cybersecurity domains without the depth required for CISSP. This certification is ideal for individuals seeking to validate their knowledge across the eight CISSP domains and demonstrate a comprehensive understanding of information security concepts, from risk management to software development security.

Recommended experience

Practical work experience can help ensure that you have mastered the skills necessary for certification. College-level courses or self-paced study through other programs or materials may also meet the needs for mastery. Practical work experience in information security; College-level courses or self-paced study in cybersecurity; Familiarity with the eight CISSP domains

The syllabus

What you’ll learn

Every domain and objective GIAC (SANS) measures, with the weight they carry on the exam.

The official GIAC (SANS) exam outline · checked 30 July 2026 · See the source

Security Management and Risk
  • Security and Risk Management
  • Asset Security
2 objectives · 109 free questions · 23 pages
Security Architecture and Operations
  • Security Architecture and Engineering
  • Security Operations
  • Communication and Network Security
3 objectives · 185 free questions · 38 pages
Access, Testing, and Development
  • Identity and Access Management (IAM)
  • Security Assessment and Testing
  • Software Development Security
3 objectives · 135 free questions · 29 pages
On the day

The exam itself

Everything GIAC (SANS) publishes about sitting it, and nothing we inferred.

Prerequisites

No mandatory prerequisites — this certification has no required predecessor exam or credential.

CertificationGIAC Information Security Professional
Exam formatProctored exam
Duration240 minutes
Questions150 questions
Passing score70%
DeliveryGIAC
LanguagesEnglish
Certification levelProfessional
After you pass

Where this credential goes next

The path GIAC (SANS) lays out, how the credential is kept, and where to book.

Step-by-step path to GIAC Information Security Professional

GIAC Information Security Professional badgeCredential earnedGIAC Information Security Professional Professional level certification
Renewal and maintenance

GIAC certifications must be renewed every four years by earning 36 CPE credits or retaking the exam. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. GIAC (SANS) maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by GIAC (SANS)

Exam registration

Register for the exam through GIAC, GIAC (SANS)’s authorized testing partner.

Schedule your exam

Visit the official GIAC (SANS) certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does GISP relate to the CISSP certification?

GISP validates understanding of the eight domains of cybersecurity knowledge as determined by ISC2, which form a critical part of the CISSP exam. It is a pragmatic alternative to CISSP, signaling broad security domain fluency without the depth required for CISSP.

Is there a hands-on or lab component in the GISP exam?

The GISP exam is a proctored exam with 150 questions. It does not include a hands-on or lab component.

What are the proctoring options for the GISP exam?

All GIAC certification exams are web-based and proctored. You can choose remote proctoring through ProctorU or onsite proctoring through PearsonVUE.

How soon can I retake the GISP exam if I fail?

GIAC does not publish a specific retake policy on the GISP exam page. Refer to your GIAC account or contact GIAC for details on retake waiting periods.

What job roles does the GISP certification map to?

GISP is designed for security professionals, system administrators, security administrators, network administrators, and security managers who want to understand the concepts covered in the CISSP exam.

Can I renew GISP by passing a different GIAC exam?

GIAC certifications can be renewed by retaking the same exam or earning CPE credits. Passing a different GIAC exam may count toward CPE credits, but it does not automatically renew GISP.

Are there regional differences in GISP exam delivery?

GIAC exams are available online and onsite through PearsonVUE, which has test centers worldwide. Regional availability may vary; check the GIAC website for details.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 429 questions, free, no account needed.