The 8 CISSP Domains Explained (2026)

The CISSP covers eight domains: Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security. Together these eight domains form the ISC2 Common Body of Knowledge (CBK), the shared body of security concepts every certified professional is expected to know. Each domain carries a fixed weight on the exam, and the weights determine roughly how many questions you can expect from each area.

The exam itself is delivered in English as a Computerized Adaptive Test (CAT). It runs 125 to 150 items over a 3 hour window, and you need 700 out of 1000 points to pass. The domains and their current weights below reflect the ISC2 exam outline that took effect on April 15, 2024. If a study source shows Security and Risk Management at 15% or Software Development Security at 11%, it is using the older pre 2024 weights. This page walks through all eight domains in order, what each one covers, and where candidates tend to lose the most points.

Domain 1: Security and Risk Management (16%)

This is the largest domain and it sets the foundation for everything else. It covers security governance, the confidentiality, integrity, and availability triad, legal and regulatory issues, professional ethics, security policies, risk management concepts, threat modeling, and business continuity requirements. Because it is the heaviest weighted domain, strong command of risk terminology and governance frameworks pays off across the whole exam. You can read a fuller breakdown on the Security and Risk Management domain page.

Domain 2: Asset Security (10%)

Domain 2 deals with the information and assets an organization needs to protect. It covers data classification and handling, ownership roles such as data owner and data custodian, privacy protection, data retention, and the full data lifecycle from creation to secure destruction. Expect questions on classification schemes and on matching protection controls to the sensitivity of the data. You can read a fuller breakdown on the Asset Security domain page.

Domain 3: Security Architecture and Engineering (13%)

This domain covers the engineering principles behind secure systems. Topics include security models, secure design principles, cryptography and its practical uses, security capabilities of information systems, and the vulnerabilities found in web, mobile, embedded, and cloud based systems. Cryptography in particular is a heavy sub area, so understanding symmetric and asymmetric methods, hashing, and public key infrastructure matters here. You can read a fuller breakdown on the Security Architecture and Engineering domain page.

Domain 4: Communication and Network Security (13%)

Domain 4 focuses on the design and protection of networks. It covers secure network architecture, the OSI and TCP/IP models, secure protocols, network components, and the controls used to protect data in transit. A working knowledge of how traffic moves across layers, and where each control belongs, is what separates a confident answer from a guess here. You can read a fuller breakdown on the Communication and Network Security domain page.

Domain 5: Identity and Access Management (13%)

IAM covers how identities are created, controlled, and removed. Topics include identification, authentication, and authorization, the access control models such as role based and attribute based access, federated identity, single sign on, and the identity lifecycle. Knowing the differences between the access control models, and when each fits, is a recurring theme in this domain. You can read a fuller breakdown on the Identity and Access Management domain page.

Domain 6: Security Assessment and Testing (12%)

This domain is about verifying that controls actually work. It covers assessment and test strategies, security control testing, vulnerability assessments and penetration testing, log reviews, and how to collect and report security process data. The distinction between assessing, testing, and auditing, along with who performs each, tends to trip up candidates. You can read a fuller breakdown on the Security Assessment and Testing domain page.

Domain 7: Security Operations (13%)

Domain 7 is the day to day running of security. It covers incident response, logging and monitoring, configuration and change management, physical security, disaster recovery, business continuity execution, and investigations. This is a broad, scenario heavy domain, so being comfortable ordering incident response steps and recovery priorities is important. You can read a fuller breakdown on the Security Operations domain page.

Domain 8: Software Development Security (10%)

The final domain applies security to the software development lifecycle. It covers secure coding practices, security in development environments, the effectiveness of software security controls, and the risks introduced by acquired and open source software. Familiarity with common application weaknesses and where security belongs in each phase of development will carry you through most questions here. You can read a fuller breakdown on the Software Development Security domain page.

Which domains carry the most weight, and where do candidates struggle?

By weight, Security and Risk Management (16%) is the clear priority, followed by the four domains tied at 13%: Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, and Security Operations. Asset Security and Software Development Security are the lightest at 10% each. If you are budgeting study time, roughly two thirds of the exam sits in Domains 1, 3, 4, 5, and 7, so that is where the return on effort is highest.

Weight is not the same as difficulty, though. Many candidates find the cryptography content in Domain 3 and the technical detail in Domain 4 the hardest to hold onto, because both reward precise recall. Domain 7 catches people out for a different reason: it is broad and scenario driven, so the challenge is choosing the best action rather than the merely correct one. A common mistake is to over study the two lightest domains because they feel manageable, while under preparing the heavily weighted risk and operations material that appears far more often. The other frequent trap is answering as a hands on engineer rather than as a manager, since the exam usually rewards the governance minded, risk based choice.

Frequently Asked Questions

How many domains are on the CISSP exam?

There are eight domains. They have stayed at eight since the 2015 refresh, though the weights were adjusted in the April 2024 exam outline update.

What is the CISSP Common Body of Knowledge?

The Common Body of Knowledge, or CBK, is the ISC2 framework that defines the full range of security topics a CISSP is expected to know. The eight domains are the top level structure of that CBK.

How is the exam split across the eight domains?

Each domain has a fixed percentage of the exam: Security and Risk Management 16%, Asset Security 10%, Security Architecture and Engineering 13%, Communication and Network Security 13%, Identity and Access Management 13%, Security Assessment and Testing 12%, Security Operations 13%, and Software Development Security 10%. You can see the full delivery details on the CISSP exam format page.

Did the CISSP domain weights change recently?

Yes. The April 2024 exam outline raised Security and Risk Management from 15% to 16% and lowered Software Development Security from 11% to 10%. The names of the eight domains did not change.

Which domain should I study first?

Most candidates start with Domain 1, Security and Risk Management. It is the heaviest weighted domain and it establishes the governance and risk vocabulary that the later, more technical domains build on.

Do I need to master all eight domains to pass?

The CISSP tests breadth, so you cannot skip a domain and rely on the rest. Your five years of paid experience only needs to fall within two or more of the domains, but the exam draws from all eight. See what the CISSP is for how the credential and its experience requirement fit together.

Where to go next

If you are new to the credential, start with what the CISSP is and who it is for, then review the CISSP exam format to understand how the adaptive test scores you across these eight domains. From there, work through each domain page in turn to turn this overview into a real study plan.

✓ Reviewed against official ISC2 sources. The exam facts on this page are checked against ISC2’s official CISSP Exam Outline and other primary sources. Last verified August 2026. certifiedcissp.com is an independent resource and is not affiliated with, endorsed by, or sponsored by ISC2.

author avatar
claude-test claude-test

Leave a Reply

Your email address will not be published. Required fields are marked *