Certified Information Systems Security Professional

ISC2 · CISSP · Expert

ISC2 · ISC2

Certified Information Systems Security Professional

CISSPactiveExpert
Official ISC2 source · isc2.org

CISSP · ● Active · Expert · ISC2

ISC2's flagship security certification — the gold standard for information security professionals globally. Required endorsement from an existing CISSP holder within 9 months of passing. The most respected credential at the expert level across all security domains.


Exam facts

FieldValue
Cost$749 USD
Duration3 hours
Questions100–150 (CAT format)
Passing700/1000 scaled
FormatMultiple choice (Computerized Adaptive Testing)
DeliveryPearson VUE
LanguagesEnglish (primary); Japanese available
Valid3 years
Renewal120 CPE credits over 3 years + $135 annual maintenance fee
Prerequisites5 years cumulative paid work experience in 2+ of 8 CBK domains (waivable with degree or approved cert)
Released1994 (current CBK v2024 revision)
RetiringN/A

Vendor source — ISC2 CISSP Certification ↗

Official exam guide — CISSP Exam Blueprint ↗

Exam objectives — CISSP CBK Domains (2024) ↗


About

The CISSP (Certified Information Systems Security Professional) is the premier vendor-neutral security certification recognized globally by enterprises, government agencies, and Fortune 500 companies. Launched in 1994, CISSP validates mastery across eight domains of information security and is widely considered the benchmark credential for security architects, managers, and senior technical leaders. The 2024 update to the Common Body of Knowledge (CBK) reflects modern threat landscapes, cloud security, zero-trust architectures, and AI-driven security operations. Unlike entry-level certs, CISSP requires verified professional experience and endorsement, making it a lifetime achievement in the security field.


Domain context — Security

Core information security and risk management across people, processes, and technology. CISSP sits at the expert apex — a prerequisite for CISO roles and a signal of deep, multi-domain security competency.

Read full deep dive — ISC2 Ecosystem ↗


Topics covered

CISSP's eight Common Body of Knowledge (CBK) domains, weighted by exam emphasis (2024 update):

  • Security & Risk Management (16%) — Risk assessment, governance, compliance frameworks (ISO 27001, NIST, COBIT), privacy regulations (GDPR, CCPA), business continuity, disaster recovery.
  • Asset Security (10%) — Data classification, handling, retention, destruction. Physical security. Media sanitization.
  • Security Architecture and Engineering (13%) — Cryptography, PKI, secure design principles, CIA triad, defense-in-depth, resilience.
  • Communication and Network Security (13%) — OSI model, network protocols, VPNs, firewalls, intrusion detection, wireless security.
  • Identity and Access Management (IAM) (13%) — Authentication, authorization, identity federation, MFA, SSO, privilege management, directory services.
  • Security Assessment and Testing (12%) — Vulnerability management, penetration testing, security testing methodologies, code review.
  • Security Operations (13%) — Incident response, detection and monitoring, SIEM, forensics, threat hunting, log analysis.
  • Software Development Security (10%) — Secure SDLC, threat modeling, API security, supply chain security, secure coding practices.

Source: ISC2 CISSP CBK Overview ↗


Common skills at Security · Expert

Shared competencies across the security domain at expert level — not specific to CISSP, but foundational for the role.

  • Risk quantification and Monte Carlo modeling — Translate threat and vulnerability data into financial risk metrics; communicate upward to executives and boards.
  • Enterprise architecture and security integration — Design security into systems at scale; work with infrastructure and application teams across hybrid/multi-cloud.
  • Incident response leadership — Triage, contain, remediate, and communicate major breaches; lead cross-functional war rooms.
  • Compliance program design — Map regulatory frameworks (SOC 2, ISO 27001, HIPAA, PCI-DSS, FedRAMP) to business controls; coordinate audits.
  • Threat intelligence synthesis — Translate open-source and proprietary threat data into prioritized defensive actions.
  • Executive communication — Explain technical security to C-suite in business language; justify budget for security initiatives.

Recommended courses at Security · Expert

ProviderTitleCostURL
ISC2 OfficialCISSP Training Bootcamp (5 days)$1,995
Destination CertificationCISSP MasterClass (Rob Witcher)$695–$995
CybraryCISSP (Official ISC2 Content)Free / $99/month premium
Kelly Handerhan (Cybrary)CISSP Deep Dive (Domain-by-domain)Free / Premium
Andrew Ramdayal (Udemy)CISSP - Complete Package (8+ hours)$12–$99
INE (Information Security)CISSP Bootcamp (OnDemand)$199–$399

Course-selection rule: Rob Witcher's Destination Cert MasterClass and Kelly Handerhan's Cybrary series are widely regarded as the gold standard for CISSP prep. The official ISC2 bootcamp is expensive but direct; Cybrary's free content is comprehensive for budget-conscious learners.


Practice exams

ProviderTitleCostURL
BosonExSim-Max CISSP (200+ questions, adaptive)$99–$149
Destination CertificationCISSP Practice Exams (250+ questions)$69–$99
WhizlabsCISSP Practice Tests (2000+ questions)$99
ISC2 OfficialOfficial CISSP Practice Exams$50–$100

Books

TitleAuthorPublisherYearISBNURL
CISSP Study Guide (8th Edition)Mike Chapple, James Stewart, Darril GibsonSybex2023978-1119790280
CISSP All-in-One Exam Guide (8th Edition)Shon Harris, Fernando MaymíMcGraw-Hill2023978-1260474572
The CISSP Prep Guide (3rd Edition)Ronald Krutz, Russell Dean VinesWiley2022978-1119679981
CISSP For Dummies (5th Edition)Lawrence C. Miller, Peter GregoryFor Dummies2021978-1119696339

Book rule: All titles are current (2023–2023) and reflect the 2024 CBK update or are explicitly compatible with it. The Sybex and McGraw-Hill guides are industry standards; Whizlabs and INE also publish companion study materials.


Typical job titles at Security · Expert

Security Architect · Chief Information Security Officer (CISO) · Information Security Manager · Senior Security Engineer · Risk Manager · Compliance Officer · Security Operations Center (SOC) Director · Incident Response Manager · Enterprise Security Manager

(Job titles drawn from current job-board postings (LinkedIn, Indeed, Glassdoor) that list CISSP as required or strongly preferred.)


Salary

RegionRangeSource
USD$120,000–$200,000+Glassdoor CISSP Salary ↗ · Robert Half 2024 Salary Guide ↗ · Levels.fyi Security ↗
ZARR2,200,000–R3,600,000 (annualized)Pnet Security Roles ↗ · PayScale South Africa ↗
GBP£90,000–£160,000IT Jobs Watch Security ↗ · Hays Salary Report ↗
EUR€95,000–€180,000 (DE/FR/NL)Robert Half Europe ↗ · Salary.com Europe ↗
AUDA$150,000–A$250,000SEEK Australia ↗ · PageUp IT Salary Report ↗

Salary note: CISSP holders command significant premiums over non-certified peers in the same role. The credential is a hard requirement for many C-suite and director-level positions, especially in regulated industries (finance, healthcare, government). Regional data reflects 2024–2025 surveys; ZAR data is drawn from South African job boards and adjusted for PPP.


Skills validated

Concrete technologies, frameworks, and practices tested by the CISSP exam — distinct from general domain competencies.

  • Cryptography fundamentals — Symmetric/asymmetric encryption, hashing, digital signatures, PKI, certificate lifecycle management.
  • Access control models — RBAC, ABAC, DAC, threat actors with varying privilege levels, identity federation (SAML, OAuth 2.0).
  • Secure development lifecycle (SDLC) — Threat modeling (STRIDE, PASTA), code review, static/dynamic analysis, secure coding standards (OWASP Top 10).
  • Incident response process — Detection, containment, eradication, recovery, post-incident review; chain of custody and evidence handling.
  • Risk management frameworks — NIST RMF, ISO 31000, quantitative/qualitative risk analysis, risk tolerance thresholds.
  • Network security architectures — Firewalls, VPNs, IDS/IPS, DMZ design, network segmentation, zero-trust principles.
  • Compliance and governance — SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, FedRAMP, audit planning and execution.
  • Business continuity and disaster recovery (BC/DR) — RTO, RPO, backup strategies, failover, recovery testing.
  • Vulnerability and penetration testing methodologies — Scope, methodology, reporting, remediation tracking.
  • Threat intelligence and malware analysis — TTPs, indicators of compromise (IOCs), threat feeds, tactical/strategic/operational intelligence.

Experience prerequisites and Associate path

Standard path (5-year experience required):

  • 5 years cumulative paid professional work experience in 2 or more of the 8 CBK domains.
  • Experience can span multiple roles and employers; military, government, and contracting work counts if full-time equivalent.
  • Once you pass the exam, you have 9 months to secure endorsement from an active CISSP holder. Without endorsement, you hold "Associate of ISC2" status until endorsed.

Faster path (with degree or approved cert):

  • Bachelor's degree in relevant field (Computer Science, Information Security, etc.) + 4 years experience in 2+ CBK domains.
  • Or: GIAC (GPEN, GCIH, GCIA, GSEC), CompTIA (Security+), (ISC)² CAP, or other approved credentials waive 1 year of experience.

Associate of ISC2 status:

  • Pass the exam without the required experience.
  • Hold "Associate" badge for 5 years while building experience.
  • Once you reach 5 years in 2+ CBK domains, you can be endorsed to full CISSP.

Endorsement process

After passing the exam, you must secure endorsement from an active CISSP (or CCSK, CCEP, CISSP-ISSAP holder) within 9 months:

  1. Contact an eligible endorser (can be a colleague, former manager, or mentor with active CISSP).
  2. Endorser reviews your experience and verifies your work history.
  3. ISC2 sends endorsement form to both you and the endorser for digital signature.
  4. Once signed, ISC2 grants you full CISSP status.
  5. Endorsement does not confer approval or liability on the endorser — it confirms you've met the experience requirement.

Finding an endorser: ISC2 maintains a limited endorser directory, but many CISSPs participate in local chapters or security communities. LinkedIn and industry conferences are also valuable resources.


Related certifications

  • Stacks with: SSCP (ISC2) ↗ — complement at associate/professional level, covers narrower scope
  • Prerequisite for: CISSP-ISSAP (ISC2) ↗ — specialized architecture track (requires active CISSP)
  • Prerequisite for: CAP (ISC2) ↗ — certification and accreditation (requires active CISSP)
  • Equivalents at this level: GIAC GSLC (GIAC) ↗ — vendor-neutral alternative at expert scope
  • Alternative at this level: ECIH (EC-Council) ↗ — ethical hacking specialist (narrower scope, overlapping domains)
  • Vendor overview: ISC2 Overview ↗

Renewal and maintenance

After certification:

  • Valid for 3 years from the date ISC2 grants your active CISSP status.
  • 120 CPE credits required over the 3-year cycle (average 40 CPEs/year).
  • $135 annual maintenance fee (AMF) due each year to maintain active status.
  • CPE sources: Training courses, conference attendance, published articles, volunteer work in security organizations, university teaching, advanced degrees, or ISC2-approved webinars.
  • Renewal process: At year 3, submit CPE transcript and renew AMF; ISC2 grants a new 3-year certificate.

Without renewal, your credential lapses to "lapsed CISSP" and you lose the title — though many employers honor lapsed status if you maintain currency.


Career impact and trajectory

Pre-CISSP: Security roles typically max out at Senior Security Engineer or Manager without CISSP. Advancement to CISO, Chief Risk Officer (CRO), or director-level positions often requires CISSP or equivalent pedigree.

At CISSP: Opens doors to executive-track roles, C-level advisor positions, board opportunities, and high-stakes consulting. Government and regulated-industry (financial, healthcare) roles frequently mandate CISSP.

Post-CISSP: Many professionals pursue specialized paths:

  • CISSP-ISSAP (Architecture) — for security architects and infrastructure leaders.
  • CAP (Certification & Accreditation) — for government/federal security compliance roles (especially FedRAMP, NIST).
  • CCSK (Cloud) — for cloud security specialization (often taken alongside CISSP).
  • GIAC certifications — for deeper technical specialization (GPEN for pentest, GCIH for incident response, GCIA for defensive).

Sources


Last verified: 2026-05-01
Parent ecosystem: ISC2 Ecosystem
Parent domain: Security Domain
Vendor overview: ISC2 Vendor Overview

Rate this cert
Was this helpful?
Comments ()
0/2000