GRC Careers
Home › Certifications › CISSP

CISSP Certification

Certified Information Systems Security Professional  ·  ISC2  ·  Cybersecurity Leadership

CISSP is ISC2's globally recognized certification for experienced security professionals who design, implement, and manage an enterprise cybersecurity program. ISC2 calls it the world's premier cybersecurity certification.

Exam at a Glance

Domains
8 (CBK, below)
Experience Required
5 years
Accreditation
ANAB / ISO-IEC 17024
Recognition
U.S. DoD 8140 approved
Exam Format
See ISC2
Exam Fee
See ISC2
Maintenance (CPE)
See ISC2

The eight domains, the 5-year experience requirement, and the accreditations (ANAB / ISO/IEC 17024; U.S. DoD 8140) are verified 2026-08-06 against ISC2. Confirm the current exam format, fee, and CPE/maintenance requirements at isc2.org before you register.

Overview

CISSP certifies that you can design, build, and run an enterprise security program across all of its major disciplines, from governance and risk to architecture, operations, and software security. It is aimed at experienced practitioners, not beginners, which is why it carries a five-year experience requirement.

The credential is one of the most requested in cybersecurity, is accredited to ISO/IEC 17024, and is recognized under the U.S. Department of Defense 8140 framework. It pairs well with management and audit credentials such as CISM and CISA.

The Eight Domains (CISSP CBK)

1

Domain 1 — Security and Risk Management

Governance, compliance, legal and regulatory issues, and the risk principles that underpin a security program.

2

Domain 2 — Asset Security

Classifying, handling, retaining, and protecting information and assets across their lifecycle.

3

Domain 3 — Security Architecture and Engineering

Secure design principles, security models, cryptography, and engineering secure systems.

4

Domain 4 — Communication and Network Security

Securing network architecture, components, and communication channels.

5

Domain 5 — Identity and Access Management (IAM)

Managing identities and controlling how access is granted, reviewed, and revoked.

6

Domain 6 — Security Assessment and Testing

Designing and performing security assessments, tests, and audits.

7

Domain 7 — Security Operations

Running day-to-day security: monitoring, incident response, investigations, and recovery.

8

Domain 8 — Software Development Security

Building security into the software development lifecycle.

Who CISSP Is For

Browse live security and GRC jobs →Hand-reviewed security, governance, risk, and compliance roles on GRC Careers
📘 Preparing for the exam? Review the official CISSP exam outline and requirements on the ISC2 official page →

Free practice, right now

Play the CISSP practice game

60 original multiple-choice questions and 37 flashcards, split across the real CISSP domains, so a low score points you at the exact area to study. Runs in your browser. No account, no payment.

Play the CISSP game freeAll 11 practice banks

This certification guide stays free permanently. The individual practice games are being replaced by one game covering every exam.

NEW GAMES IN DEVELOPMENT

Get told the moment the full game drops.

The CISSP practice game here is free today. When the full game launches, the individual games are retired and replaced by one game covering every exam. Sign up now and you get a free coupon for it. New questions and quizzes after launch run on a monthly subscription.

Signing up adds you to the GRC Careers newsletter, which is how the coupon reaches you. One click unsubscribe. We never sell your address.

Related Certifications

Frequently Asked Questions

What is the CISSP certification?

CISSP, Certified Information Systems Security Professional, is an ISC2 certification for experienced professionals who design, implement, and manage an enterprise cybersecurity program across eight domains.

What are the eight CISSP domains?

Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; Identity and Access Management; Security Assessment and Testing; Security Operations; and Software Development Security.

How much experience does CISSP require?

ISC2 requires five years of cumulative paid work experience across the CISSP domains. Confirm current requirements, including any experience waivers, on the ISC2 CISSP page.

Is CISSP recognized by the U.S. government?

Yes. CISSP is accredited to ISO/IEC 17024 and is approved under the U.S. Department of Defense 8140 framework, as stated by ISC2.

How should I prepare for CISSP?

Study the official ISC2 CISSP exam outline and CBK, and use reputable published study materials. Avoid braindump sites; they violate exam rules and are often inaccurate.

Official Resources

CISSP and ISC2 are trademarks of ISC2. GRC Careers is not affiliated with, endorsed by, or accredited by ISC2. This page is an independent study aid and contains no real exam questions.

Educational reference only and not legal, compliance, or certification advice. © 2026 GRC Careers · AI-Governance-Jobs.com · From the GRC Careers network.