CISSP Domains Explained
Dr. Abeer Alshammari · Published 7/29/2026
The CISSP Common Body of Knowledge (CBK) is organized into eight domains. (ISC)² publishes approximate exam weightings, which shift slightly between exam outline revisions -- always check the current official outline before finalizing a study plan.
| Domain | Focus | Approx. weight |
|---|---|---|
| 1. Security and Risk Management | Governance, legal/regulatory, risk management, policy, BCP/DR | ~15% |
| 2. Asset Security | Classifying, owning, and protecting information and assets | ~10% |
| 3. Security Architecture and Engineering | Secure design principles, cryptography, physical security | ~13% |
| 4. Communication and Network Security | Network architecture, protocols, secure communications | ~13% |
| 5. Identity and Access Management (IAM) | Identity lifecycle, authentication, authorization models | ~13% |
| 6. Security Assessment and Testing | Audit strategies, vulnerability assessment, test types | ~12% |
| 7. Security Operations | Incident response, DFIR, logging/monitoring, recovery | ~13% |
| 8. Software Development Security | Secure SDLC, application security controls | ~11% |
Reading the weightings correctly
No single domain dominates the exam -- the highest is around 15%, and most sit between 10-13%. This is intentional: (ISC)² is testing whether you can reason across the whole program, not whether you memorized one heavily weighted section. A study plan that skips a "smaller" domain to over-invest in a favorite one usually backfires.
Candidates who come from a technical background often assume Domain 4 (networking) or Domain 5 (IAM) will be the hard part, and are surprised when Domain 1 questions -- pure governance and risk reasoning -- are what trips them up. The domains you already do at work are rarely the ones that need the most study time; the domains outside your day-to-day are.
Try it yourself
An interactive CyberAbeer experience for this topic is in development.
Coming soon