examOS.
Exam CatalogueStudy PlansRoadmapsBlogs
Login

ExamOS

Credits PolicyReferral PolicyQuality StandardsPricingPrivacy PolicyTerms of UseContact UsReport a Bug

Follow us

Disclaimer: ExamOS is an independent platform, not affiliated with any certification provider, and does not use or distribute exam dumps.

Share your feedback

Checking sign-in status...

examOS.Study Plan
Disclaimer: ExamOS is an independent platform, not affiliated with any certification provider, and does not use or distribute exam dumps.
← Back to Exam Details

Study Plan

CISSP – Study Plan

A condensed 8-week plan for the CISSP exam. Master all eight domains of cybersecurity governance, risk management, security architecture, operations, and software development security.

ISC2CISSPPassing score: 700 / 1000Experienced security practitioners, managers, and leaders with 5+ years cumulative work experience in at least 2 of the 8 CISSP domains18-Jul-202654 views
Start date: _______________Target exam date: _______________
8 WeeksDuration
~50 hrsTotal Study Time
8 DomainsExam Coverage

Stay consistent by setting a target date for this certification.

Set target

How to use this plan

  1. 1Read and reflect. Start the week with the ISC2 Official Study Guide or equivalent material. For every concept, think about how it applies at the organizational level, not just the technical level.
  2. 2Practice the managerial mindset. For every scenario you encounter, ask: what is the business risk, what are the options, and which option best balances security with business objectives?
  3. 3Practice with ExamOS. Use the quiz modes in the order specified in this Study Plan.
  4. 4Learn to eliminate, not just select. CISSP questions often have two plausible answers. Train yourself to identify the specific clue in the question that makes one answer better than the other. The ISC2 answer is the one that is most broadly correct and least likely to introduce new risk.
Rookie ModeChallenger ModeLegend Mode

Week-by-Week Breakdown


W1

Week 1

Self-Assessment

This week is about mapping your current knowledge against the eight exam domains, understanding the CAT format, and internalizing the ISC2 Code of Ethics, which is tested directly and also informs the correct answer on ethics-adjacent questions.

Topics

  • CISSP exam format and CAT behavior
  • ISC2 Code of Ethics (four canons)
  • CIA triad and DAD triad
  • Governance fundamentals
  • Risk management overview
  • Self-assessment across all eight domains

Activities

W2

Week 2

Security and Risk Management and Asset Security (Domains 1-2, ~25%)

Domains 1 and 2 are the governance foundation of CISSP. Domain 1 (Security and Risk Management) is the conceptual backbone of the entire exam: risk assessment, business continuity, compliance, and privacy. Domain 2 (Asset Security) covers data classification, retention, and protection. Together they represent a quarter of the exam and frame how every other domain should be evaluated.

Topics

  • Risk assessment: qualitative vs quantitative
  • Risk treatment: avoid, transfer, mitigate, accept
  • Business continuity and disaster recovery planning
  • Governance: policies, standards, procedures, guidelines
  • Compliance frameworks: GDPR, HIPAA, PCI-DSS, NIST
  • Privacy principles: PII, PHI, data sovereignty
W3

Week 3

Security Architecture and Engineering (Domain 3, ~13%)

This domain covers the technical foundations of secure system design: cryptographic controls, security models, secure design principles, and physical security. It is the most conceptually dense domain because cryptography alone covers symmetric, asymmetric, hashing, PKI, digital signatures, and key management. Take the time to understand the "why" behind each control, not just the "what."

Topics

  • Secure design principles: defense in depth, least privilege, zero trust
  • Security models: Bell-LaPadula, Biba, Clark-Wilson
  • Cryptography: symmetric, asymmetric, hashing, PKI
  • Digital signatures and certificates
  • Key management lifecycle
  • Cloud security architecture: shared responsibility
W4

Week 4

Communication and Network Security (Domain 4, ~13%)

Network security is tested at the architectural level. The exam does not ask you to configure a firewall. It asks you to design a network architecture that segments critical assets, defends against common attack vectors, and supports secure remote access. Know the OSI model, common protocols, and the security implications of each layer.

Topics

  • OSI and TCP/IP models and security at each layer
  • Network security devices: firewalls, IDS/IPS, proxies
  • Common network attacks and mitigations
  • Network segmentation and microsegmentation
  • Wireless security: WPA2, WPA3, 802.1X
  • VPN technologies: IPsec, SSL/TLS
  • SASE and zero trust network architecture
W5

Week 5

Identity and Access Management and Security Assessment (Domains 5-6, ~25%)

Domains 5 and 6 are studied together because they represent two sides of the same discipline: controlling who has access (IAM) and verifying that controls work (assessment and testing). IAM covers authentication, authorization, federation, and privileged access. Assessment covers vulnerability scanning, penetration testing, audits, and BC/DR testing.

Topics

  • Authentication factors and biometrics
  • SSO and federation: SAML, OAuth, OpenID Connect
  • Access control models: DAC, MAC, RBAC, ABAC
  • Identity lifecycle and privileged access management
  • Vulnerability assessment and penetration testing
  • Security audits: internal, external, third-party
W6

Week 6

Security Operations and Software Development Security (Domains 7-8, ~24%)

Domains 7 and 8 are studied together because modern security operations increasingly overlap with software development. Incident response, forensics, and SOC operations (Domain 7) connect directly to secure SDLC, DevSecOps, and supply chain security (Domain 8). The exam tests both operational maturity and development security awareness.

Topics

  • Incident response lifecycle: preparation through lessons learned
  • Digital forensics: evidence handling, chain of custody
  • SOC operations: monitoring, threat hunting, triage
  • Patch and change management
  • Secure SDLC: requirements through deployment
  • OWASP Top 10 and common vulnerabilities
W7

Week 7

Cross-Domain Scenarios and Managerial Mindset

This is the week that separates candidates who know the material from candidates who pass the exam. CISSP questions frequently span multiple domains and require you to evaluate trade-offs from a business perspective. This week practices that skill: reading a scenario, identifying the binding constraint, and choosing the answer that best serves the organization.

Topics

  • Cross-domain scenario reasoning
  • Managerial vs technical answer selection
  • Risk-benefit trade-off analysis
  • ISC2 Code of Ethics application
  • CAT exam strategy and pacing
  • Weak domain targeted review

Activities

W8

Week 8

Exam Simulation and Booking

Your final push. This week is full exam simulation mode using Legend mode. The CAT format means you cannot go back to questions, so you need to practice making confident, final decisions under time pressure.

Topics

  • Full syllabus review across all eight domains
  • CAT format strategy and pacing
  • Time management (up to 3 hours for 100-150 questions)
  • Confident decision-making without revision
  • Exam day preparation

Activities

  • Take at least 3 ExamOS Legend mode full quizzes (80% hard questions, timed).

Daily Study Routine

Suggested 2–3 Hour Day

TimeActivity
15 minLook over yesterday's wrong answers. For each one, identify whether the miss was a knowledge gap or a mindset gap.
30 minRead the ISC2 Official Study Guide or equivalent material for this week's domain
30 minReview flashcards (concepts, frameworks, acronyms, port numbers)
30 minTake an ExamOS quiz (Challenger or Legend mode, depending on the week)
15 minLog missed concepts and review them the next morning

Stay consistent by setting a target date for this certification.

Set target
  • Read the official CISSP exam outline end to end and rate your confidence for each domain.
  • Read and memorize the ISC2 Code of Ethics (four canons, in priority order).
  • Review the Well-Architected Framework or NIST CSF as a governance reference.
  • Take the ExamOS Rookie mode quiz (30 questions). Note any domain below 60%.
  • Goal:Know where your gaps are across all eight domains.
    Rookie Mode
    Rookie Mode
  • Data classification and lifecycle management
  • Data retention and destruction
  • Activities

    • Create a risk register for a sample organization with at least 5 identified risks.
    • Map GDPR, HIPAA, and PCI-DSS requirements to a sample environment.
    • Design a data classification policy and retention schedule for a mock company.
    • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
    Goal:Design governance frameworks and data protection strategies.
    Challenger Mode
    Challenger Mode
  • Site and facility security controls
  • Activities

    • Design a PKI hierarchy for a medium-sized enterprise including certificate lifecycle.
    • Compare symmetric vs asymmetric encryption and identify appropriate use cases for each.
    • Map the shared responsibility model across IaaS, PaaS, and SaaS.
    • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
    Goal:Apply cryptographic controls and secure design principles to enterprise architecture.
    Challenger Mode
    Challenger Mode

    Activities

    • Design a segmented network architecture for a multi-zone enterprise.
    • Map common attacks (DoS, MITM, spoofing) to OSI layers and propose mitigations.
    • Compare VPN protocols and identify the right choice for different remote access scenarios.
    • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
    Goal:Design secure network architectures and defend against network-based attacks.
    Challenger Mode
    Challenger Mode
  • BC/DR testing types and planning
  • Activities

    • Design an IAM solution for a cloud migration scenario using RBAC and federation.
    • Compare penetration testing approaches (black-box, white-box, gray-box) and when each is appropriate.
    • Design a BC/DR test plan including tabletop, walkthrough, and full interruption exercises.
    • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
    Goal:Design IAM solutions with least privilege and validate controls through structured testing.
    Challenger Mode
    Challenger Mode
  • DevSecOps: SAST, DAST, CI/CD security gates
  • Software supply chain security and SBOM
  • Activities

    • Create an incident response plan for a medium-sized organization.
    • Practice chain of custody documentation for a sample forensic scenario.
    • Map security activities to each phase of the SDLC.
    • Design a DevSecOps pipeline with security gates at each stage.
    • Take the ExamOS Challenger quiz. Repeat until you pass 2 times in a row.
    Goal:Operationalize incident response and integrate security into the software lifecycle.
    Challenger Mode
    Challenger Mode
    • Solve at least 10 cross-domain scenarios (ExamOS case study mode). For each, explain why the correct answer serves the business better than the alternatives.
    • Review every question you got wrong this week and categorize the mistake: technical gap, managerial mindset failure, or misread question.
    • Take targeted Challenger quizzes on your two weakest domains until 3 consecutive passes above 75%.
    • Review the ISC2 Code of Ethics one final time.
    • Take 3 full-domain ExamOS Challenger quizzes. Repeat until 3 consecutive passes above 70%.
    Goal:Think like a manager, not a technician, on every question.
    Challenger Mode
    Challenger Mode
  • Simulate real exam conditions at least once: no phone, no breaks, no going back to previous questions, same time of day you plan to actually sit the exam.
  • For every Legend question you miss, review the explanation and write one sentence identifying the managerial principle behind the correct answer.
  • Once you are consistently hitting 80% or above on Legend mode across two or more sessions, book your exam. You are ready.
  • Goal:Consistent above 80% on Legend mode across two or more sessions.
    Legend Mode
    Legend Mode

    Overview

    The CISSP is the most widely recognized certification in cybersecurity. It validates your ability to design, implement, and manage a cybersecurity program at the enterprise level. It is not a technical certification. It is a managerial certification that tests whether you can make risk-balanced, governance-aware decisions that protect an organization's assets while enabling business objectives.

    This is the single most important thing to understand about CISSP: the correct answer is almost always the one that best serves the business, not the one that is most technically thorough. Candidates with deep technical backgrounds consistently struggle with this shift. If you find yourself choosing the most secure option without considering cost, feasibility, or business impact, you are answering the wrong question.

    Domain Weight
    Security and Risk Management ~15%
    Asset Security ~10%
    Security Architecture and Engineering ~13%
    Communication and Network Security ~13%
    Identity and Access Management ~13%
    Security Assessment and Testing ~12%
    Security Operations ~13%
    Software Development Security ~11%

    A note on the CAT format: The CISSP uses Computerized Adaptive Testing. This means the exam adapts to your performance in real time. If you answer correctly, the next question is harder. If you answer incorrectly, the next question is easier. The exam ends when it has determined with 95% statistical confidence that you are above or below the passing threshold, or when you reach 175 questions. This has several implications for your test-taking strategy:

    • You cannot go back to previous questions. Each answer is final.
    • The difficulty of your questions increases as you answer correctly. Hard questions are a good sign, not a bad one.
    • The exam may end at any point between 100 and 150 questions. Do not panic if it ends early.
    • You cannot calculate how many questions you can "afford to miss." The adaptive algorithm makes this meaningless.

    Recommended experience: 5+ years of cumulative, paid work experience in 2 or more of the 8 CISSP domains. If you have a 4-year college degree or an approved certification (such as CompTIA Security+, CISA, or CISM), you can substitute 1 year of experience. You can take the exam without the required experience and earn Associate of ISC2 status, then have up to 6 years to accumulate the full experience requirement.

    A note on the managerial mindset: This plan will repeatedly ask you to choose the answer that serves the business, not the answer that is most technically secure. This is not a suggestion. It is the fundamental lens through which every CISSP question must be evaluated. When in doubt, ask: "What would a CISO recommend to the board?"

    Frequently Asked Questions

    Do I need 5 years of experience before taking the exam?

    No. You can take the exam at any time. If you pass without the required experience, you earn Associate of ISC2 status and have up to 6 years to accumulate the 5 years of work experience. A 4-year college degree or an approved certification (CompTIA Security+, CISA, CISM, etc.) can substitute for 1 year of experience.

    How does the CAT format affect my test-taking strategy?

    The CAT format means you cannot go back to previous questions. Each answer is final. This requires a different mindset than a linear exam: you must be confident in your first answer and move on. Do not second-guess yourself. The adaptive algorithm means that harder questions are a sign you are performing well, not a sign you are failing. The exam ends when it has determined with 95% confidence whether you are above or below the passing threshold.

    How many practice questions should I aim for?

    At least 1,000 unique questions across all domains. Focus on questions that explain why each answer is right and why the others are wrong. For CISSP, the explanation matters more than the question itself because the exam tests reasoning, not recall.

    When should I book the exam?

    Once you are consistently hitting 80% or above on Legend mode across two or more sessions, and you feel confident applying the managerial mindset to cross-domain scenarios, you are ready. Trust your preparation.

    How long is the exam?

    3 hours for 100 to 150 questions in the CAT format. The exam ends when the algorithm has determined your competency level with 95% statistical confidence, which may be before you reach 150 questions. The minimum is 100 items. Candidates who pass with high confidence often finish at 100 questions. Most candidates finish in 2 to 3 hours. Budget your time for the full 3 hours, but do not be alarmed if the exam ends earlier.

    What is the passing score?

    The adaptive algorithm uses a scaled scoring model. The difficulty of questions you receive adapts to your performance, so the raw number of correct answers needed varies. Do not try to calculate how many questions you can afford to miss.

    I am a non-native English speaker. Can I get extra time?

    Yes. If English is not your primary language, you may request a one-time 25-question, 60-minute extension by contacting ISC2 before your exam appointment. This accommodation is available for the English-language exam only and must be requested in advance through the ISC2 accommodations process.

    Can I use reference materials during the exam?

    No. The CISSP exam is closed-book. You cannot access documentation, websites, or any external resources during the test. All questions are designed to be answerable from your professional knowledge and the study materials you have reviewed.

    What is the managerial mindset?

    The CISSP tests governance-aware, risk-balanced decision-making. The most common failure mode for technical practitioners is defaulting to the most technically secure answer rather than the answer that best balances security with business objectives. When evaluating answer choices, ask: "What would a CISO recommend to the board?" The correct answer protects the business, complies with regulations, and is feasible to implement.

    What are the most common ways people fail?

    • Choosing the most secure answer instead of the most appropriate answer. The CISSP tests risk management, not security maximalism. An answer that eliminates all risk but costs 10x the budget is wrong. An answer that reduces risk to an acceptable level within business constraints is right.
    • Not understanding the CAT format. Candidates who do not understand adaptive testing panic when questions get harder or waste time trying to calculate how many questions they can miss. Neither strategy helps.
    • Weak cryptography knowledge. Cryptography questions are embedded across multiple domains. If you do not understand PKI, digital signatures, key management, and encryption algorithms at a conceptual level, you will lose marks on questions in architecture, network security, and operations.
    • Ignoring the ISC2 Code of Ethics. Ethics questions appear directly and also influence the correct answer on scenario questions. The four canons are in priority order: protect society, act honorably, provide diligent service, advance the profession.
    • Confusing security models. Bell-LaPadula (confidentiality, no read up/no write down), Biba (integrity, no read down/no write up), and Clark-Wilson (integrity through well-formed transactions) are tested frequently. Know the purpose and rules of each.
    • Underestimating Domain 1. At ~15%, it is the heaviest domain, and its concepts (risk, governance, compliance, BCP/DR) frame questions across all other domains.

    What are the three biggest preparation mistakes?

    1. Studying with a technical mindset. CISSP is a managerial exam. If you are studying it like a technical certification (memorizing port numbers, configuring firewalls, writing code), you are preparing for the wrong test. Study governance, risk frameworks, and business impact analysis.
    2. Not practicing enough cross-domain questions. CISSP questions frequently span multiple domains. A single question might reference incident response (Domain 7), legal compliance (Domain 1), and network architecture (Domain 4). If you only study domains in isolation, you will struggle with integrated scenarios.
    3. Rushing to take the exam. CISSP has a roughly 50% first-time pass rate. Candidates who book the exam based on study hours rather than practice scores consistently underperform. Wait until you are hitting 80% or above on Legend mode before scheduling.

    Is there a renewal option?

    Yes. CISSP is valid for 3 years. To renew, you must earn 120 CPE credits during the 3-year cycle (minimum 40 Category A credits, with the remainder in Category B or C). You must also pay an annual maintenance fee ($125/year). If you do not meet the CPE requirements, your certification lapses and you must retake the exam.


    Quick-Reference: What Is on the Exam

    For the full, always-current list, visit the official CISSP exam outline.

    Domain Key Skills
    Security and Risk Management (~15%) Security governance (policies, standards, procedures, guidelines), risk management (identification, assessment, treatment: avoid/transfer/mitigate/accept), compliance and legal frameworks (GDPR, HIPAA, PCI-DSS, SOX, NIST), BCP and DRP (RTO, RPO, MTD, BIA), privacy principles (PII, PHI, data sovereignty), ISC2 Code of Ethics, security awareness training, supply chain risk management
    Asset Security (~10%) Data classification (government and commercial models), data lifecycle (creation, storage, use, sharing, archival, destruction), data retention policies, data protection controls (encryption, masking, tokenization, DLP), asset inventory and management, data remanence and sanitization
    Security Architecture and Engineering (~13%) Secure design principles (defense in depth, least privilege, zero trust, fail secure, separation of duties), security models (Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash), cryptography (symmetric, asymmetric, hashing, PKI, digital signatures, key management), cloud security (shared responsibility, IaaS/PaaS/SaaS), secure hardware (TPM, HSM, secure enclaves), site and facility security (physical controls, environmental controls)
    Communication and Network Security (~13%) OSI and TCP/IP models (security at each layer), network devices (firewalls, IDS/IPS, WAF, proxies, load balancers), network attacks (DoS/DDoS, MITM, ARP spoofing, DNS poisoning), network segmentation (VLANs, microsegmentation, SDN), wireless security (WPA2, WPA3, 802.1X, EAP), VPN (IPsec transport/tunnel mode, SSL/TLS), SASE and zero trust network access
    Identity and Access Management (~13%) Authentication (factors, biometrics, MFA, passwordless), identity federation (SAML 2.0, OAuth 2.0, OpenID Connect, RADIUS, LDAP), access control models (DAC, MAC, RBAC, ABAC, rule-based), identity lifecycle (provisioning, review, deprovisioning), privileged access management (PAM, just-in-time, just-enough-access), directory services and identity providers
    Security Assessment and Testing (~12%) Vulnerability assessment (scanning, prioritization, reporting), penetration testing (black-box, white-box, gray-box, rules of engagement), security audits (internal, external, third-party, SOC reports), test types (synthetic transactions, misconfiguration review, code review), BC/DR testing (tabletop, walkthrough, simulation, full interruption), log reviews and data analytics
    Security Operations (~13%) Incident response (preparation, detection, containment, eradication, recovery, lessons learned), digital forensics (evidence handling, chain of custody, acquisition methods, legal hold), SOC operations (monitoring, triage, threat hunting, SIEM), patch and vulnerability management, change and configuration management, physical security (CCTV, access badges, mantraps), personnel security (background checks, onboarding, offboarding)
    Software Development Security (~11%) Secure SDLC (security requirements, threat modeling, secure design, secure coding, security testing, secure deployment), OWASP Top 10 (injection, broken auth, XSS, CSRF, SSRF), security testing (SAST, DAST, IAST, RASP, fuzzing), DevSecOps (CI/CD security gates, infrastructure as code scanning), software supply chain (SBOM, code signing, repository security), secure coding practices (input validation, output encoding, parameterized queries, error handling)