CISSP Complete Study Guide: 8 Domains Explained
The gold-standard security management cert. 8 domains, 100–150 questions, and a mindset most technical candidates get wrong. Complete 90-day plan from a certified holder.
CISSP is the cert every security manager wants on the wall. And in the Middle East it's a legal shortcut - most UAE and KSA government cybersecurity postings list CISSP as a hard requirement. But it's also the most misunderstood exam in security. Technical candidates fail it not because they don't know the material, but because they answer like engineers instead of managers. Here's how to think about CISSP correctly and pass in 90 days.
§The 8 CISSP domains
| Domain | Weight | Focus |
|---|---|---|
| Security & Risk Management | 16% | Governance, compliance, risk, BCP |
| Asset Security | 10% | Classification, ownership, retention |
| Security Architecture & Engineering | 13% | Secure design, cryptography, physical |
| Communication & Network Security | 13% | Secure networks, secure comms |
| Identity & Access Management | 13% | IAM lifecycle, provisioning, SSO |
| Security Assessment & Testing | 12% | Audits, testing, metrics |
| Security Operations | 13% | IR, forensics, DR, patch mgmt |
| Software Development Security | 10% | Secure SDLC, code review, DevSecOps |
§The exam format that trips technical people
English exams use Computer Adaptive Testing (CAT): 100–150 questions in 3 hours. The engine adjusts difficulty as you answer. You can't skip or return to questions. Pass mark: 700/1000, but nobody sees a score - you either 'provisionally passed' or 'did not pass' at the end.
The killer trap: think like a manager, not an engineer. If a question asks 'what should you do first when you discover unauthorized access,' the technical answer is 'contain the breach.' The CISSP answer is 'notify management and initiate the incident response plan.' Process before action. Documentation before heroics. Every question.
§The 90-day plan
- Weeks 1–3: Security & Risk Management + Asset Security. Learn to think in risk terms - quantitative vs qualitative, ALE = SLE × ARO
- Weeks 4–6: Security Architecture + Cryptography. Deep on Bell-LaPadula, Biba, Clark-Wilson models; symmetric, asymmetric, hashing
- Weeks 7–8: Communication & Network Security. OSI, protocols, secure design at architecture level (not troubleshooting)
- Weeks 9–10: IAM + Assessment & Testing. Identity lifecycle, SAML, OAuth, penetration testing methodology
- Weeks 11–12: Security Operations + Software Security. IR lifecycle, forensics, DR, secure SDLC
- Week 13: Practice CAT-style exams daily. Focus on read-and-decide speed.
§The CISSP manager mindset
The exam is written for someone who has already been a director of security. If you're a hands-on engineer, you have to actively translate. Rules of thumb:
- Safety of life > business continuity > data > property
- Policy before technology. Always.
- Escalate before acting on anything you don't own
- Least privilege, separation of duties, need-to-know - invoked in >20% of answers
- When in doubt, pick the most administrative-sounding answer
§Endorsement - the step people forget
Passing the exam doesn't make you a CISSP. You need 5 years of full-time paid work in 2+ of the 8 domains. Waivers up to 1 year for degrees or approved certs (Security+, CCSP, CISM, CEH, etc.). After passing, you have 9 months to submit an endorsement application. An existing CISSP endorses you (or ISC² endorses you for a fee). Miss the window and you retake the exam.
§Salary - where CISSP pays off
| Location | Post-CISSP salary range |
|---|---|
| Dhaka, Bangladesh | BDT 200k–450k/mo |
| Dubai, UAE | AED 30k–55k/mo |
| Riyadh, KSA | SAR 35k–65k/mo |
| Remote (US clients) | USD 10k–18k/mo |
This is where CISSP earns its price tag. In Dhaka, a CISSP holder at a bank or telco makes 2–3x what a Security+/CEH-only candidate makes. In the Gulf, CISSP-holding CISOs command AED 55–90k/mo packages.
"The single biggest reason people fail CISSP is answering 'what would you do' from a technician's perspective. Every answer has to sound like a director defending it to auditors. Once that clicks, the exam becomes easy."
§Best resources
- Official (ISC)² CISSP CBK Reference - the definitive text, dry but complete
- Sybex CISSP Official Study Guide (10th edition) - the readable option
- Destination CISSP by Rob Witcher - free YouTube MindMap videos, gold standard for review
- Boson CISSP practice tests - the closest to real exam difficulty
- Pete Zerger's 'CISSP Exam Cram' YouTube playlist - free, sharp, saves time
§FAQ
How much does CISSP cost?
USD 749 exam fee, plus USD 125 annual maintenance fee once certified.
Do I need 5 years of experience before taking the exam?
No. Pass first, become an 'Associate of (ISC)²' for up to 6 years while earning the experience, then get endorsed.
Is CISSP worth it in Bangladesh?
Yes if you're targeting director+ security roles at banks, telcos, or MNC subsidiaries. Overkill for junior analyst roles.
Can I self-study for CISSP?
Yes, but expect 250–400 hours. Boot camps are USD 3–5k and worth it only if your employer pays.
Certified practitioner and lead curriculum architect at KNScert. Writes about cert strategy, exam tactics, and the real-world skills employers actually pay for.
Stop reading. Start passing.
Verified Q&A, hands-on simulators, and expert workbooks - updated monthly to match the live exam.
Discussion(0)
More from the Journal
Palo AltoPalo Alto PCNSA Study Guide 2026: Pass on Your First Attempt
An honest, lab-tested PCNSA roadmap for 2026 - exam blueprint, real prep timeline, salary impact, and the mistakes that fail most first-timers.
CompTIAIs CySA+ Worth It in 2026? Salary, Jobs & Full Breakdown
A no-fluff look at CySA+ pay bands, hiring demand, and how it stacks up against Security+ and CASP+.
DevOpsSplunk vs Datadog: Side-by-Side Comparison for 2026
Logs, metrics, pricing, certification paths - which observability stack wins for your team in 2026.
Explore certification practice material
Get verified practice questions and exam dumps with a 100% pass guarantee.
