Domains · 8 min read
The eight CISSP domains explained
The CISSP Common Body of Knowledge is organised into eight domains. Knowing the weight of each domain lets you allocate your study time where it counts most.
Domain weights
Security and Risk Management carries the highest weight at 16%, followed by Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security.
The weights tell you where the exam spends its questions, but every domain must be mastered: the adaptive engine can drill into your weakest area.
How to study the domains
Treat the domains as a cycle rather than a list: risk management informs architecture, architecture constrains operations, operations feeds assessment results back into risk.
Many candidates find domains 1 and 7 conceptually easy but tricky in exam questions, because they are written from a manager's perspective rather than an engineer's.
PassYour is an independent study aid. CISSP is a certification mark of ISC2.