The eight CISSP domains, and what each one is worth
The eight CISSP domains are not equally sized, but they are much closer to equal than candidates expect. ISC2 publishes a weighting for each on its exam outline, and the spread runs from 16% at the top to 10% at the bottom — a range narrow enough that there is no domain you can afford to leave out and no domain that will carry you if the others are weak.
What each domain is worth
CISSP domain weightings, ISC2 exam outline
- 16%Security and Risk Management
- 13%Security Architecture and Engineering
- 13%Communication and Network Security
- 13%Identity and Access Management
- 13%Security Operations
- 12%Security Assessment and Testing
- 10%Asset Security
- 10%Software Development Security
- 100% in total — the weightings add up, which is how we check we copied them correctly.
ISC2 puts Security and Risk Management at 16%, the largest single share. Then four domains sit level at 13% each: Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, and Security Operations. Security Assessment and Testing at 12% follows, and Asset Security and Software Development Security at 10% each close the list. The eight add to 100, which is the arithmetic we run every time we copy a weighting.
Domain by domain, in plain terms
Security and Risk Management is the governance domain — policy, compliance, risk treatment, business continuity, ethics. It is the largest slice and the one technical candidates underestimate most, because it rewards a way of thinking rather than a set of facts.
Asset Security covers classification, ownership, handling and retention: knowing what you have, who is responsible for it and what happens to it at the end of its life.
Security Architecture and Engineering is design — secure models, cryptography, physical security, the properties a system has because of how it was built rather than what was bolted on.
Communication and Network Security is the one most engineers already have: segmentation, protocols, secure channels, the network as an attack surface.
Identity and Access Management covers who gets in, how that is proven, and how it is revoked — provisioning, federation, authorisation models.
Security Assessment and Testing is how you find out whether any of the above works: audit strategies, testing, collecting and reviewing the evidence.
Security Operations is the running of it — monitoring, investigation, incident response, recovery, the day-to-day discipline.
Software Development Security covers building software that does not undermine everything else, and it is the domain most often neglected by candidates who have never shipped code.
What the flat weighting means for studying
Because the biggest domain is 16% and the smallest is 10%, a candidate who knows six domains excellently and two not at all is looking at at least a fifth of the exam they cannot answer. On a computerised adaptive test, that is not something a strong performance elsewhere reliably compensates for.
The practical consequence is that CISSP rewards levelling rather than deepening. The hours that move your score are the ones spent on your weakest two domains, and for most working engineers those are Security and Risk Management and Software Development Security — the two furthest from day-to-day infrastructure work, and between them 26% of the paper.
Map your job before you buy a book
ISC2 requires five years of cumulative, full-time experience in two or more of the eight domains before it will certify you, which means the domain list does double duty: it is the study plan and it is the application form. Writing out what you have actually done under each of the eight headings takes an afternoon and answers two questions at once — where your study gaps are, and whether you can honestly make the experience claim at all.
It also tends to surprise people. Engineers who assumed they had no governance experience discover that three years of writing access-review evidence for auditors is squarely inside Security and Risk Management, and people who assumed the opposite discover their breadth is thinner than their CV implies.
What the weightings do not tell you
They do not tell you the number of questions per domain, because the exam is adaptive and the mix varies. They do not tell you how difficult each domain's questions are. And they emphatically do not tell you a pass rate — ISC2 does not publish one for CISSP, which is why there is no pass-rate figure anywhere on this site, not even a range.
Do not let a training provider's domain-by-domain “difficulty rating” substitute for the published weightings. The weightings are a fact ISC2 publishes; the ratings are somebody's opinion, sold with a course.
Where to take this next
If you are still deciding whether CISSP is the right target at all, read which certification matches the layer you work on. If the domains look unfamiliar rather than merely broad, Security+ against CISSP is the more useful comparison, because Security+ concentrates two-thirds of its paper into operations and threats where CISSP spreads evenly.
The two domains most candidates underestimate
Security and Risk Management is the biggest single share of the exam at 16%, and it is the domain where technically strong candidates lose the most marks. The material is not difficult in the way cryptography is difficult; it is unfamiliar. Risk treatment options, the difference between a policy and a standard, due care against due diligence, business impact analysis, the ethics canons — these are vocabulary and frameworks rather than mechanisms, and they do not yield to the kind of reasoning that works on a protocol question.
Software Development Security is the other one, and it is smaller at 10% but no less awkward for an infrastructure engineer. It covers the security implications of how software gets built and released rather than how to write code — development methodologies, testing in the pipeline, the risks in third-party and open-source components, database and application controls. You do not need to be a developer. You do need to be able to reason about a release process as an attack surface.
How the weightings interact with the adaptive format
It is tempting to read the percentages as a promise about how many questions you will see from each domain. They are not. The exam is computerised adaptive testing, which means the item pool is selected in response to your answers, and two candidates sitting the same certification see different papers of different lengths — anywhere from 100 to 150 questions inside the same three hours.
What the weightings do describe is how the exam is built and where its centre of gravity sits. Treat them as a budget for your study hours rather than as a forecast of your question mix, and they become the most useful free document in the process.
About the domains
How many domains does the CISSP exam have?
Which CISSP domain is hardest?
Did the CISSP domains change?
Do I need experience in all eight domains?
Still deciding between credentials? Work through which cybersecurity certification fits the stage you are at, or read how every figure on this site is checked. Fees, formats and eligibility rules change without warning — open the certifying body’s page before you pay for anything.