PassYourCISSP
← All CISSP resources

Certification basics · 6 min read

What is the CISSP certification?

The Certified Information Systems Security Professional (CISSP) certification, administered by ISC2, is one of the most recognised credentials in information security. This guide explains what it is, who it targets and what it certifies.

A vendor-neutral security certification

The CISSP is a vendor-neutral certification: it does not test a specific product or technology, but a broad and deep body of security knowledge spanning architecture, engineering, risk, governance and operations.

It is designed for experienced practitioners: security managers, security architects, consultants, auditors, CISOs and engineers who take decisions that materially affect the security posture of an organisation.

Who it is for

The certification targets professionals with at least five years of cumulative paid work experience in two or more of the eight CISSP domains. One year of that requirement can be waived with a four-year college degree or an approved credential.

Candidates who pass the exam but do not yet meet the experience requirement become Associates of ISC2 and have up to six years to earn the required experience.

What the exam certifies

Passing the CISSP demonstrates that you can design, implement and manage a best-in-class cybersecurity programme. The exam tests judgement at the level of a risk advisor, not only recall of technical facts.

The certification must then be maintained with Continuing Professional Education (CPE) credits and an Annual Maintenance Fee, showing a sustained commitment to the profession.

PassYour is an independent study aid. CISSP is a certification mark of ISC2.