The JournalCareer2024-11-22 16 min read

CISSP Complete Study Guide: 8 Domains Explained

The gold-standard security management cert. 8 domains, 100–150 questions, and a mindset most technical candidates get wrong. Complete 90-day plan from a certified holder.

Written by
KS
Kowser Shaki
Senior Editor
CISSP Complete Study Guide: 8 Domains Explained

CISSP is the cert every security manager wants on the wall. And in the Middle East it's a legal shortcut - most UAE and KSA government cybersecurity postings list CISSP as a hard requirement. But it's also the most misunderstood exam in security. Technical candidates fail it not because they don't know the material, but because they answer like engineers instead of managers. Here's how to think about CISSP correctly and pass in 90 days.

Isometric diagram of the eight CISSP security domains
Isometric diagram of the eight CISSP security domains

§The 8 CISSP domains

DomainWeightFocus
Security & Risk Management16%Governance, compliance, risk, BCP
Asset Security10%Classification, ownership, retention
Security Architecture & Engineering13%Secure design, cryptography, physical
Communication & Network Security13%Secure networks, secure comms
Identity & Access Management13%IAM lifecycle, provisioning, SSO
Security Assessment & Testing12%Audits, testing, metrics
Security Operations13%IR, forensics, DR, patch mgmt
Software Development Security10%Secure SDLC, code review, DevSecOps

§The exam format that trips technical people

English exams use Computer Adaptive Testing (CAT): 100–150 questions in 3 hours. The engine adjusts difficulty as you answer. You can't skip or return to questions. Pass mark: 700/1000, but nobody sees a score - you either 'provisionally passed' or 'did not pass' at the end.

The killer trap: think like a manager, not an engineer. If a question asks 'what should you do first when you discover unauthorized access,' the technical answer is 'contain the breach.' The CISSP answer is 'notify management and initiate the incident response plan.' Process before action. Documentation before heroics. Every question.

Security team discussing CISSP risk management concepts
Security team discussing CISSP risk management concepts

§The 90-day plan

  • Weeks 1–3: Security & Risk Management + Asset Security. Learn to think in risk terms - quantitative vs qualitative, ALE = SLE × ARO
  • Weeks 4–6: Security Architecture + Cryptography. Deep on Bell-LaPadula, Biba, Clark-Wilson models; symmetric, asymmetric, hashing
  • Weeks 7–8: Communication & Network Security. OSI, protocols, secure design at architecture level (not troubleshooting)
  • Weeks 9–10: IAM + Assessment & Testing. Identity lifecycle, SAML, OAuth, penetration testing methodology
  • Weeks 11–12: Security Operations + Software Security. IR lifecycle, forensics, DR, secure SDLC
  • Week 13: Practice CAT-style exams daily. Focus on read-and-decide speed.

§The CISSP manager mindset

The exam is written for someone who has already been a director of security. If you're a hands-on engineer, you have to actively translate. Rules of thumb:

  • Safety of life > business continuity > data > property
  • Policy before technology. Always.
  • Escalate before acting on anything you don't own
  • Least privilege, separation of duties, need-to-know - invoked in >20% of answers
  • When in doubt, pick the most administrative-sounding answer

§Endorsement - the step people forget

Passing the exam doesn't make you a CISSP. You need 5 years of full-time paid work in 2+ of the 8 domains. Waivers up to 1 year for degrees or approved certs (Security+, CCSP, CISM, CEH, etc.). After passing, you have 9 months to submit an endorsement application. An existing CISSP endorses you (or ISC² endorses you for a fee). Miss the window and you retake the exam.

§Salary - where CISSP pays off

LocationPost-CISSP salary range
Dhaka, BangladeshBDT 200k–450k/mo
Dubai, UAEAED 30k–55k/mo
Riyadh, KSASAR 35k–65k/mo
Remote (US clients)USD 10k–18k/mo

This is where CISSP earns its price tag. In Dhaka, a CISSP holder at a bank or telco makes 2–3x what a Security+/CEH-only candidate makes. In the Gulf, CISSP-holding CISOs command AED 55–90k/mo packages.

"The single biggest reason people fail CISSP is answering 'what would you do' from a technician's perspective. Every answer has to sound like a director defending it to auditors. Once that clicks, the exam becomes easy."
- Kowser Shaki, KNScert

§Best resources

  • Official (ISC)² CISSP CBK Reference - the definitive text, dry but complete
  • Sybex CISSP Official Study Guide (10th edition) - the readable option
  • Destination CISSP by Rob Witcher - free YouTube MindMap videos, gold standard for review
  • Boson CISSP practice tests - the closest to real exam difficulty
  • Pete Zerger's 'CISSP Exam Cram' YouTube playlist - free, sharp, saves time

§FAQ

How much does CISSP cost?

USD 749 exam fee, plus USD 125 annual maintenance fee once certified.

Do I need 5 years of experience before taking the exam?

No. Pass first, become an 'Associate of (ISC)²' for up to 6 years while earning the experience, then get endorsed.

Is CISSP worth it in Bangladesh?

Yes if you're targeting director+ security roles at banks, telcos, or MNC subsidiaries. Overkill for junior analyst roles.

Can I self-study for CISSP?

Yes, but expect 250–400 hours. Boot camps are USD 3–5k and worth it only if your employer pays.

KS
Written by
Kowser Shaki

Certified practitioner and lead curriculum architect at KNScert. Writes about cert strategy, exam tactics, and the real-world skills employers actually pay for.

Was this useful?
100% Pass Guarantee

Stop reading. Start passing.

Verified Q&A, hands-on simulators, and expert workbooks - updated monthly to match the live exam.

Discussion(0)

0/4000
Loading comments…

Explore certification practice material

Get verified practice questions and exam dumps with a 100% pass guarantee.

Limited Offer
20% OFFon every exam
CodeSAVE20
Sale ends inLive
24
Hours
00
Minutes
00
Seconds
100% pass rate guarantee