Skip to content
Log inRegister

CISSP Domains Explained

Dr. Abeer Alshammari · Published 7/29/2026

BeginnerStudentsProfessionals

The CISSP Common Body of Knowledge (CBK) is organized into eight domains. (ISC)² publishes approximate exam weightings, which shift slightly between exam outline revisions -- always check the current official outline before finalizing a study plan.

DomainFocusApprox. weight
1. Security and Risk ManagementGovernance, legal/regulatory, risk management, policy, BCP/DR~15%
2. Asset SecurityClassifying, owning, and protecting information and assets~10%
3. Security Architecture and EngineeringSecure design principles, cryptography, physical security~13%
4. Communication and Network SecurityNetwork architecture, protocols, secure communications~13%
5. Identity and Access Management (IAM)Identity lifecycle, authentication, authorization models~13%
6. Security Assessment and TestingAudit strategies, vulnerability assessment, test types~12%
7. Security OperationsIncident response, DFIR, logging/monitoring, recovery~13%
8. Software Development SecuritySecure SDLC, application security controls~11%

Reading the weightings correctly

No single domain dominates the exam -- the highest is around 15%, and most sit between 10-13%. This is intentional: (ISC)² is testing whether you can reason across the whole program, not whether you memorized one heavily weighted section. A study plan that skips a "smaller" domain to over-invest in a favorite one usually backfires.

Dr. Abeer Explains

Candidates who come from a technical background often assume Domain 4 (networking) or Domain 5 (IAM) will be the hard part, and are surprised when Domain 1 questions -- pure governance and risk reasoning -- are what trips them up. The domains you already do at work are rarely the ones that need the most study time; the domains outside your day-to-day are.

Try it yourself

An interactive CyberAbeer experience for this topic is in development.

Coming soon
Back to insights