CISSP domains · 7 min read
The 8 CISSP Domains Explained
Understand what each CISSP domain covers and how to organise your preparation around the official exam outline.
The CISSP exam spans eight domains. Knowing their boundaries helps you build a study plan and recognise cross-domain questions.
From governance to software security
The domains cover security and risk management, asset security, architecture and engineering, communications and network security, identity and access management, security assessment and testing, security operations, and software development security.
These areas overlap in real organisations. For example, identity decisions affect operations, architecture and risk, so practice should eventually mix domains.
How to prioritise domains
Start with the domains where your professional experience is weakest, while giving extra revision time to domains with greater exam weight. Use questions to identify gaps instead of relying only on reading progress.
A domain checklist is useful, but mastery means being able to select the safest business-aligned action in a scenario.
PassYour is an independent study aid. CISSP is a certification mark of ISC2.