The whole CISSP syllabus on one page: eight domains with their current exam weights, the major topics inside each, and the key concepts underneath. Blue-dashed terms open the full definition in the glossary; every domain links straight into domain-filtered flashcards. Based on the current ISC2 CISSP Exam Outline, independently summarized.

CISSP

8 domains · weights from the current exam outline

      • CIA
      • Authenticity
      • Non-repudiation
      • ISC2 Code of Ethics
      • Alignment with business strategy
      • Roles and accountability
      • GRC
      • GDPR
      • PCI DSS
      • PII
      • Criminal vs civil vs administrative law
      • Intellectual property
      • Policy (mandatory, high level)
      • Standard (mandatory, specific)
      • Procedure (step by step)
      • Guideline (recommended)
      • Screening
      • Onboarding / offboarding
      • SoD
      • Job rotation
      • NDAs
        • Threats
        • Vulnerabilities
        • Asset valuation
        • Risk acceptance
        • Risk avoidance
        • Risk mitigation
        • Risk transfer
      • Quantitative risk
        SLE = Asset Value × Exposure Factor
        ALE = SLE × ARO
      • Preventive / detective / corrective
      • Administrative / technical / physical
      • Compensating controls
      • STRIDE
      • Attack trees
      • Reduction analysis
      • Phishing simulations
      • Role-based training
      • Culture
      • Classification levels
      • Labelling and marking
      • Asset ownership
      • Asset inventory
      • Handling requirements
      • Create → store → use → share → archive → destroy
      • Who is who
        Owner — accountable for the data
        Controller — decides purpose & means
        Custodian — day-to-day care
        Processor — handles data for a controller
        Subject/user — the person the data is about
      • Data retention
      • Data remanence
      • Secure destruction (purge, crypto-erase, destroy)
      • EOL
      • EOS
      • Data at rest
      • Data in transit
      • Data in use
      • Least privilege
      • Defense in depth
      • Secure defaults
      • Fail secure
      • SoD
      • Zero Trust
      • Privacy by design
      • Shared responsibility
      • Keep it simple
      • Bell-LaPadula (confidentiality)
      • Biba (integrity)
      • Clark-Wilson
      • Brewer-Nash
      • TPM
      • HSM
      • Memory protection
      • Trusted execution
      • Single points of failure
      • Covert channels
      • Emanations
      • SaaS
      • PaaS
      • IaaS
      • Containers
      • Microservices
      • Serverless
      • Virtualization
      • IoT
      • Edge computing
        • AES
        • Fast bulk encryption
        • Key distribution problem
        • MITM
        • Brute force
        • Side channel
        • Birthday attack
      • PFS
      • Encryption at a glance
        AES = symmetric = fast bulk encryption
        RSA/ECC = asymmetric = keys & signatures
        SHA = hashing = integrity
      • Perimeter and zones
      • Environmental controls
      • Fire suppression
      • Motion detection
      • Acquire → implement → operate → retire
      • TLS
      • SSL
      • SSH
      • DNSSEC
      • SNMP
      • DHCP
      • DNS
        • IPSec
        • AH — authentication/integrity
        • ESP — encryption/confidentiality
        • IKE — key exchange
      • AH vs ESP
        AH = authentication and integrity only
        ESP = encryption/confidentiality plus security services
      • VLAN
      • Segmentation
      • Microsegmentation
      • DMZ / screened subnet
      • VPC
      • North-south traffic
      • East-west traffic
      • WPA3
      • Enterprise vs PSK
      • Captive portals
      • VPN
      • Voice and collaboration
      • Remote access
      • Physical and logical access
      • Identification
      • Authentication
      • Authorization
      • Accounting
      • AAA
      • MFA
      • Something you know / have / are
      • Session management
      • Identity proofing
      • SSO
      • FIM
      • SAML
      • OAuth
      • OIDC
      • Federation standards
        SAML = enterprise federation / browser SSO
        OAuth = delegated authorization
        OIDC = authentication & identity on OAuth 2.0
        SCIM = provisioning / deprovisioning
      • PAM
      • JIT
      • Break-glass accounts
      • Service accounts
      • SCIM
      • Joiner / mover / leaver
      • Access reviews
      • Internal assessment
      • External assessment
      • Third-party assessment
      • VA
      • PT
      • Red / Blue / Purple teams
      • Breach and attack simulation
      • VA vs PT
        Vulnerability Assessment = identify and evaluate weaknesses
        Penetration Test = authorized exploitation to demonstrate impact
      • Log review
      • Synthetic transactions
      • Security audits
      • SSAE-18 / SOC reports
      • Compliance testing
      • KPI
      • KRI
      • Security metrics
      • Test-result analysis
      • Remediation
      • Exceptions
      • Evidence handling
      • Chain of custody
      • Digital forensics
      • eDiscovery
      • IR
      • CSIRT
      • Incident-response sequence
        Detection / Analysis
        → Containment
        → Eradication / Remediation
        → Recovery
        → Lessons Learned
      • Configuration management
      • Change management
      • Patch and vulnerability management
      • Resource protection
      • Need to know / least privilege
      • Guards and access controls
      • Duress
      • Travel security
      • SDLC
      • SSDLC
      • Security in requirements and design
      • Threat modelling
      • Agile
      • Waterfall
      • DevOps / DevSecOps
      • Software maturity models
      • CI/CD
      • Repositories
      • Code signing
      • Change management
      • SAST
      • DAST
      • IAST
      • SCA
      • RASP
      • Testing at a glance
        SAST = analyze code without executing it
        DAST = test the running application externally
        IAST = instrument the app while it runs
        SCA = analyze third-party components
      • SBOM
      • COTS
      • Open source
      • Libraries and dependencies
      • OWASP
      • Input validation
      • API
      • API authentication and authorization
      • Auditing and logging of changes
      • Risk analysis of acquired software
      • CSP

Study-status markers reflect only your local flashcard activity in this browser — they are not a measure of CISSP exam readiness.

Further study: the official ISC2 CISSP Exam Outline is the authoritative statement of the domains and their weights.

Independent CISSP study aid. CISSP is a registered trademark of ISC2. This resource is not affiliated with or endorsed by ISC2.