Jaded Security

TECHNICAL · 2011-09-15The 8 CISSP Domains Explained – What You Actually Need to Know

– Boris Sverdlik

Nobody passes the CISSP on their first attempt by just reading the official study guide cover to cover. There is too much material, and a lot of it reads like it was written by a committee – because it was. What you need is a clear mental model of what each domain covers and how they connect to actual security work.

Here is the breakdown of all 8 CISSP domains. I am going to tell you what each one is actually about, what trips people up, and where to focus your study time.

Domain 1: Security and Risk Management

This is the foundation domain and it is the biggest chunk of the exam. It covers security governance, compliance, legal and regulatory issues, professional ethics, and risk management frameworks.

The core concept is understanding how organizations make decisions about risk. You need to know the difference between risk avoidance, risk mitigation, risk transference, and risk acceptance – and when each is appropriate. You also need to understand quantitative risk analysis (ALE = ARO x SLE) and qualitative risk analysis (high/medium/low matrices).

Business continuity planning starts here too. Know BIA (Business Impact Analysis), RPO, RTO, and MTD. Know the difference between a disaster recovery plan and a business continuity plan.

Study tip: Do not just memorize formulas. Understand why an organization would choose one risk response over another. The exam tests judgment, not recall.

Domain 2: Asset Security

Asset security covers data classification, ownership, privacy protection, data retention, and secure handling of information throughout its lifecycle.

The key concepts are data classification levels (government: Top Secret, Secret, Confidential, Unclassified; private sector: Confidential, Private, Sensitive, Public) and the roles of data owner, data custodian, and data steward. The data owner is a senior manager who determines the classification. The custodian implements the security controls. Do not confuse these.

Data remanence is a favorite exam topic. Know the difference between clearing, purging, and destroying storage media. Know that overwriting is clearing, degaussing is purging, and physical destruction is destruction. Know that SSDs require different sanitization than spinning disks because of wear leveling.

Domain 3: Security Architecture and Engineering

This domain covers security models, evaluation criteria, cryptography fundamentals, and physical security. It is the most technically dense domain.

You need to know the formal security models: Bell-LaPadula (confidentiality – no read up, no write down), Biba (integrity – no read down, no write up), Clark-Wilson (integrity through well-formed transactions and separation of duties), and Brewer-Nash (Chinese Wall – prevents conflicts of interest).

Cryptography is heavily tested. Understand symmetric vs. asymmetric encryption, know the common algorithms (AES, RSA, ECC, Diffie-Hellman), understand hashing (SHA-256, SHA-3), and know how digital signatures work (hash then encrypt with private key). Know the difference between block ciphers and stream ciphers, and understand cipher modes (ECB, CBC, CTR, GCM).

Study tip: If cryptography is not your background, spend extra time here. You cannot fake your way through the crypto questions.

Domain 4: Communication and Network Security

Network security covers the OSI model, TCP/IP, network protocols, network attacks, and secure network design. If you have a networking background, this domain will feel comfortable. If you do not, it requires serious study.

Know the OSI model cold – not just the layer names but what protocols operate at each layer and what security controls apply. Know TCP/IP thoroughly: the three-way handshake, how DNS works, how ARP works, and how each can be attacked.

Understand network segmentation, VLANs, firewalls (stateless vs. stateful vs. application layer), IDS/IPS (signature-based vs. anomaly-based), and VPN technologies (IPsec, SSL/TLS). Know the difference between transport mode and tunnel mode in IPsec.

Wireless security is tested: know WEP (broken), WPA (better but has weaknesses), WPA2 (current standard using AES-CCMP), and WPA3 (latest). Know the attacks against each.

Domain 5: Identity and Access Management (IAM)

IAM covers identification, authentication, authorization, and accountability. This is where you learn about access control models and authentication mechanisms.

Know the access control models: DAC (discretionary – owner sets permissions), MAC (mandatory – system enforces labels), RBAC (role-based – access based on job function), and ABAC (attribute-based – access based on attributes of subject, object, and environment).

Authentication factors: something you know (password), something you have (smart card, token), something you are (biometrics). Multi-factor means two or more different categories. Two passwords is not multi-factor.

Understand single sign-on (SSO) technologies: Kerberos (know the ticket-granting process), SAML, OAuth, and OpenID Connect. Know federated identity management and how trust relationships work between organizations.

Study tip: Kerberos questions are almost guaranteed. Know the components (KDC, TGT, service ticket) and the authentication flow.

Domain 6: Security Assessment and Testing

This domain covers vulnerability assessments, penetration testing, security audits, and software testing techniques.

Know the difference between a vulnerability assessment (identify weaknesses) and a penetration test (attempt exploitation). Know the types of penetration tests: black box (no prior knowledge), white box (full knowledge), and gray box (partial knowledge).

Understand log reviews, code reviews, and security metrics. Know the OWASP Top 10 web application vulnerabilities. Understand static analysis (SAST) and dynamic analysis (DAST) for application security testing.

SOC 1, SOC 2, and SOC 3 reports come up here. SOC 1 is about financial controls. SOC 2 is about security, availability, processing integrity, confidentiality, and privacy – it is the one security professionals care about. Type I is a point-in-time assessment; Type II covers a period of time (usually 6-12 months).

Domain 7: Security Operations

Security operations covers incident management, disaster recovery, physical security operations, change management, and forensics.

Incident response phases: preparation, detection/analysis, containment, eradication, recovery, lessons learned. Know this sequence. Know the difference between containment strategies (short-term containment like isolating a system vs. long-term containment like patching while maintaining evidence).

Digital forensics principles: order of volatility (collect most volatile evidence first – registers, cache, RAM, disk, remote logs), chain of custody, evidence integrity (hashing), and the difference between a forensic image and a backup.

Disaster recovery is tested heavily. Know hot sites (fully operational, switchover in hours), warm sites (partially equipped, days to activate), cold sites (empty facility, weeks to activate). Know RAID levels and their trade-offs. Know backup types: full, incremental (backs up changes since last backup of any type), and differential (backs up changes since last full backup).

Study tip: The incident response and DR questions are scenario-based. Practice applying the frameworks to specific situations rather than just memorizing steps.

Domain 8: Software Development Security

This domain covers secure software development practices, application vulnerabilities, and database security.

Know the SDLC phases and where security activities fit in each phase. Know common application vulnerabilities: buffer overflows, SQL injection, cross-site scripting, cross-site request forgery. Know the OWASP Top 10.

Understand database security concepts: inference attacks, aggregation attacks, polyinstantiation, views for access control. Know the difference between relational databases, object-oriented databases, and NoSQL databases from a security perspective.

Software development models: Waterfall, Agile, Spiral, DevOps/DevSecOps. Know where security testing fits in each model. Know what a maturity model is (CMM/CMMI levels).

Study tip: This domain has a lot of overlap with Domain 3 (security models) and Domain 6 (testing). If you study those well, Domain 8 will feel manageable.

How to Actually Pass

The CISSP is not a technical exam. It is a management and decision-making exam that requires technical knowledge. The questions test whether you can think like a security manager, not whether you can configure a firewall.

Read one primary source (the official study guide or Shon Harris) and one secondary source (practice exams, video courses). Do at least 1,000 practice questions. Review every wrong answer until you understand why the “correct” answer is correct from ISC2’s perspective, even if you disagree.

The exam is adaptive now. You get 100-150 questions in 3 hours. Do not panic if the questions seem hard – that means the adaptive engine thinks you are doing well.

Good luck. The CISSP is worth having, despite everything I have said about ISC2 over the years.


Jaded Security