Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Certified Information Systems Security Professional

The Certified Information Systems Security Professional (CISSP) certification validates your ability to design, implement, and manage a best-in-class cybersecurity program. It is for experienced security practitioners, managers, and executives who lead organizational security strategy and operations. Earning CISSP proves your expertise across eight security domains and grants you ISC2 membership with access to exclusive resources and a global community of cybersecurity leaders.

Exam formatMultiple choice and advanced item types
Duration180 minutes
DeliveryPearson VUE
Passing score700 out of 1000
Free questions1773

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Information Systems Security Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

8domains
62objectives
452concepts
US $50exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Certified Information Systems Security Professional (CISSP) is the world's premier cybersecurity certification, recognized globally as a benchmark for security leadership. It validates an information security professional's deep technical and managerial knowledge and experience to effectively design, engineer, and manage the overall security posture of an organization. CISSP covers eight comprehensive domains, from security and risk management to software development security, ensuring relevance across all disciplines in the field.

Earning the CISSP demonstrates that you have what it takes to lead an organization's information security program. It proves your expertise in designing, implementing, and managing best-in-class cybersecurity programs, and it opens doors to advanced career opportunities and higher earning potential. As an ISC2 member, you join a community of cybersecurity leaders and gain access to exclusive resources, educational tools, and peer-to-peer networking opportunities.

Who it’s for

The CISSP is ideal for experienced security practitioners, managers, and executives who are responsible for leading an organization's information security program. It is designed for professionals who need to prove their knowledge across a wide array of security practices and principles, including those in positions such as Chief Information Security Officer, Chief Information Officer, Director of Security, IT Director/Manager, Security Systems Engineer, Security Analyst, Security Manager, Security Auditor, Security Architect, Security Consultant, and Network Architect. If you are a seasoned cybersecurity professional looking to validate your expertise, advance your career, and gain the support of a community of leaders, the CISSP is the credential for you.

Recommended experience

A minimum of five years of cumulative, full-time experience in two or more of the eight CISSP domains is required. A post-secondary degree in computer science, IT, or a related field, or an approved credential, may waive up to one year of experience. Experience in security and risk management; Experience in asset security; Experience in security architecture and engineering; Experience in communication and network security; Experience in identity and access management; Experience in security assessment and testing; Experience in security operations; Experience in software development security

The syllabus

What you’ll learn

Every domain and objective ISC2 measures, with the weight they carry on the exam.

The official ISC2 exam outline · checked 30 July 2026 · See the source

Security and Risk Management
  • 1.1 - Understand, adhere to, and promote professional ethics
  • 1.2 - Understand and apply security concepts
  • 1.3 - Evaluate and apply security governance principles
  • 1.4 - Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context
  • 1.5 - Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
  • 1.6 - Develop, document, and implement security policy, standards, procedures, and guidelines
  • 1.7 - Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
  • 1.8 - Contribute to and enforce personnel security policies and procedures
  • 1.9 - Understand and apply risk management concepts
  • 1.10 - Understand and apply threat modeling concepts and methodologies
  • 1.11 - Apply Supply Chain Risk Management (SCRM) concepts
  • 1.12 - Establish and maintain a security awareness, education, and training program
12 objectives · 343 free questions · 74 pages
Asset Security
  • 2.1 - Identify and classify information and assets
  • 2.2 - Establish information and asset handling requirements
  • 2.3 - Provision information and assets securely
  • 2.4 - Manage data lifecycle
  • 2.5 - Ensure appropriate asset retention (e.g., End of Life (EOL), End of Support)
  • 2.6 - Determine data security controls and compliance requirements
6 objectives · 146 free questions · 31 pages
Security Architecture and Engineering
  • 3.1 - Research, implement and manage engineering processes using secure design principles
  • 3.2 - Understand the fundamental concepts of security models (e.g., Biba, Star Model, Bell-LaPadula)
  • 3.3 - Select controls based upon systems security requirements
  • 3.4 - Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
  • 3.5 - Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
  • 3.6 - Select and determine cryptographic solutions
  • 3.7 - Understand methods of cryptanalytic attacks
  • 3.8 - Apply security principles to site and facility design
  • 3.9 - Design site and facility security controls
  • 3.10 - Manage the information system lifecycle
10 objectives · 307 free questions · 64 pages
Communication and Network Security
  • 4.1 - Apply secure design principles in network architectures
  • 4.2 - Secure network components
  • 4.3 - Implement secure communication channels according to design
3 objectives · 101 free questions · 22 pages
Identity and Access Management (IAM)
  • 5.1 - Control physical and logical access to assets
  • 5.2 - Design identification and authentication strategy (e.g., people, devices, and services)
  • 5.3 - Federated identity with a third-party service
  • 5.4 - Implement and manage authorization mechanisms
  • 5.5 - Manage the identity and access provisioning lifecycle
  • 5.6 - Implement authentication systems
6 objectives · 159 free questions · 34 pages
Security Assessment and Testing
  • 6.1 - Design and validate assessment, test, and audit strategies
  • 6.2 - Conduct security control testing
  • 6.3 - Collect security process data (e.g., technical and administrative)
  • 6.4 - Analyze test output and generate report
  • 6.5 - Conduct or facilitate security audits
5 objectives · 132 free questions · 28 pages
Security Operations
  • 7.1 - Understand and comply with investigations
  • 7.2 - Conduct logging and monitoring activities
  • 7.3 - Perform Configuration Management (CM) (e.g., provisioning, baselining, automation)
  • 7.4 - Apply foundational security operations concepts
  • 7.5 - Apply resource protection
  • 7.6 - Conduct incident management
  • 7.7 - Operate and maintain detection and preventative measures
  • 7.8 - Implement and support patch and vulnerability management
  • 7.9 - Understand and participate in change management processes
  • 7.10 - Implement recovery strategies
  • 7.11 - Implement Disaster Recovery (DR) processes
  • 7.12 - Test Disaster Recovery Plans (DRP)
  • 7.13 - Participate in Business Continuity (BC) planning and exercises
  • 7.14 - Implement and manage physical security
  • 7.15 - Address personnel safety and security concerns
15 objectives · 433 free questions · 92 pages
Software Development Security
  • 8.1 - Understand and integrate security in the Software Development Life Cycle (SDLC)
  • 8.2 - Identify and apply security controls in software development ecosystems
  • 8.3 - Assess the effectiveness of software security
  • 8.4 - Assess security impact of acquired software
  • 8.5 - Define and apply secure coding guidelines and standards
5 objectives · 152 free questions · 33 pages
On the day

The exam itself

Everything ISC2 publishes about sitting it, and nothing we inferred.

Prerequisites

Minimum of five years of cumulative, full-time experience in two or more of the eight CISSP domains.

CertificationCertified Information Systems Security Professional
Exam formatMultiple choice and advanced item types
Duration180 minutes
Questions100–150 questions
Passing score700 out of 1000
DeliveryPearson VUE
LanguagesChinese, English, German, Japanese, Spanish
PricingUS $50
Certification levelProfessional
After you pass

Where this credential goes next

The path ISC2 lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Information Systems Security Professional

PrerequisiteMinimum of five years of cumulative, full-time experience in two or more of the eight CISSP domains.
Certified Information Systems Security Professional badgeCredential earnedCertified Information Systems Security Professional Professional level certification
Renewal and maintenance

CISSP certification is valid for three years. To maintain the credential, you must earn continuing professional education (CPE) credits and pay an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISC2

Exam registration

Register for the exam through Pearson VUE, ISC2’s authorized testing partner.

Schedule your exam

Visit the official ISC2 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the CISSP relate to the Certified in Cybersecurity (CC) and SSCP certifications?

CC is an entry-level certification for those new to cybersecurity, while SSCP is for hands-on security professionals with at least one year of experience. CISSP is the advanced credential for experienced practitioners and leaders. Earning CC or SSCP can help build foundational knowledge and prepare for the CISSP.

Do I need to earn a lower-level ISC2 certification before taking the CISSP?

No, the CISSP can be taken directly. However, you must meet the required work experience in at least two of the eight domains. If you lack the experience, you can pass the exam and become an Associate of ISC2, then earn the required experience within six years.

Is the CISSP exam available in languages other than English?

Yes, the CISSP exam is available in Chinese, English, German, Japanese, and Spanish. Chinese language exams are only offered during specific appointment windows: March 1-31, June 1-30, September 1-30, and December 1-31.

What is the retake policy for the CISSP exam?

ISC2 exam retake policies are detailed in the exam policies and procedures. Generally, if you fail an exam, you must wait a specified period before retaking it. For Peace of Mind Protection purchases, there is a 30-day waiting period between attempts.

Can I purchase exam vouchers or get discounts for the CISSP exam?

ISC2 offers a Peace of Mind Protection option that includes two exam attempts at a lower cost than two single exams. This can be purchased with the exam or as part of training bundles. Discounts may be available through ISC2 membership or other promotions.

Is there a hands-on or lab component in the CISSP exam?

No, the CISSP exam is a Computerized Adaptive Test (CAT) consisting of multiple choice and advanced item types. There is no hands-on lab component.

How soon will I receive my CISSP exam results?

You will receive a preliminary pass/fail result at the test center immediately after completing the exam. Official results and score reports are typically available within a few weeks.

What job roles does the CISSP certification map to?

The CISSP is ideal for experienced security practitioners, managers, and executives, including roles such as Chief Information Security Officer, Chief Information Officer, Director of Security, IT Director/Manager, Security Systems Engineer, Security Analyst, Security Manager, Security Auditor, Security Architect, Security Consultant, and Network Architect.

Can I recertify by passing a different ISC2 exam?

Yes, earning an advanced ISC2 certification, such as ISSAP, ISSEP, or ISSMP, may help you meet CPE requirements and demonstrate continued expertise, but it does not automatically renew the CISSP. You must still earn CPE credits and pay the AMF.

Are there regional differences in CISSP exam delivery?

Yes, the CISSP exam is delivered at ISC2 Authorized PPC and PVTC Select Pearson VUE Testing Centers. Chinese language exams are only available during specific appointment windows, and availability may vary by region.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 1773 questions, free, no account needed.