CISSP — Certified Information Systems Security Professional
The CISSP is the certification most likely to be sitting on a CISO's wall, and the one most likely to be misread by an engineer as "the advanced version of what this course teaches." It isn't. CISSP is ISC2's flagship credential for security management and breadth — eight domains spanning risk, architecture, network security, identity, assessment, operations, software security, and a fair amount of law, physical security, and business continuity this course never touches at all. It requires five years of paid security experience just to sit for it unconditionally. It is entirely multiple-choice — there is no terminal, no live cluster, no pipeline to break and fix. This page covers what it actually tests, what it costs in time and prerequisites, and — the part worth reading closely if you're deciding between this and this course's own Certified DevSecOps Professional (CDP) — exactly where the two overlap and where they don't.
Imagine two different badges for "knows about keeping a school safe." One badge means you can personally check every fire extinguisher, test every smoke alarm, and fix a jammed door yourself, right now, while someone times you. The other badge means you understand fire codes, know the evacuation law, can read a budget for new alarms, and can explain to the school board why the whole safety program matters — but you might never have held a fire extinguisher yourself. Both badges are real. Neither one replaces the other. CISSP is the second badge.
What CISSP is, and why a hands-on pipeline course profiles a management exam
☺ Like you're 10: This course is mostly about doing the work with your own hands. CISSP tests whether you understand the whole security program well enough to run it — a different, and genuinely broader, skill.
CISSP was created in 1994 by what is now ISC2 (the organization dropped the stylized "(ISC)²" name in 2023) and has spent three decades becoming the most widely recognized general-purpose security certification in the industry — accredited to ISO/IEC 17024 and, in the United States, on the DoD 8570/8140 approved baseline list for several IAT and IAM certification levels, which is why government and defense-contracting job postings still name it specifically. It certifies against ISC2's Common Body of Knowledge (CBK), organized into eight domains that together describe the whole discipline of information security — not one slice of the software delivery pipeline, the whole program: governance and risk, physical and personnel security, cryptography, network architecture, identity, assessment methodology, operations, and software security.
That breadth is exactly why it shows up on this site at all. This course builds toward the CDP — a hands-on, pipeline-specific credential that proves you can actually wire a SAST gate into a pipeline, triage a leaked secret, or sign a container. CISSP proves something adjacent and genuinely useful, but different in kind: that you understand security as an organizational program well enough to set policy, own risk decisions, and speak the language a CISO, an auditor, or a board needs. A DevSecOps engineer with strong CDP-grade skills and zero CISSP-grade breadth can still be blindsided by a question a compliance officer asks in a budget meeting. The reverse is just as true — a CISSP holder with no hands-on pipeline experience can describe SAST and DAST correctly on a multiple-choice question and still have never configured either one.
CDP asks "can you do the work?" and grades you on a live environment. CISSP asks "do you understand the whole program well enough to be trusted to run it?" and grades you on recall and judgment under a knowledge exam. Neither question is a subset of the other — which is exactly why one doesn't substitute for the other.
The eight CBK domains and their weights
☺ Like you're 10: Eight topics make up the whole exam, and only one of the eight lives anywhere near this course's usual territory.
ISC2 periodically refreshes the CISSP Exam Outline — domain names and weights have shifted slightly roughly every three years, most recently in an April 2024 update. The weights below reflect that most recent published outline at the time of writing; treat the exact percentages as directional rather than gospel and confirm the current numbers against ISC2's own Exam Outline PDF before you build a study plan around them.
Notice the shape: no single domain dominates the way Troubleshooting dominates the CKA. The heaviest, Domain 1 (Security and Risk Management), covers governance, legal and regulatory frameworks, risk assessment methodology, business continuity planning, and security awareness — none of which this course spends much time on, because none of it is pipeline-specific. The lightest domains, Asset Security and Software Development Security, are tied at 10% each — and it's Domain 8 specifically, the smallest slice of the entire exam, that overlaps most directly with what this course teaches all day.
Format, cost, and prerequisites — verify before you book
☺ Like you're 10: You can't just show up and pay — ISC2 wants proof you've already worked in security for years, and the exam itself changes shape depending on what language you take it in.
The details below are what ISC2 generally publishes and what candidates consistently report at the time of writing. As with every certification page on this site, treat this as planning information, not something to quote back at anyone — prices, question counts, and requirement rules have all changed over the certification's history.
| Item | What is generally published |
|---|---|
| Format | Computerized Adaptive Testing (CAT) for English-language sittings — the exam adapts to your answers in real time; a fixed linear format for other available languages |
| Question count | 100–150 questions (CAT, English); 250 questions (linear, other languages) |
| Duration | 3 hours (CAT); 6 hours (linear) |
| Passing score | A scaled score of 700 out of 1000 |
| Delivery | Pearson VUE test centers |
| Experience required | 5 years cumulative, paid, full-time work experience across 2 or more of the 8 CBK domains; 1 year can be waived with an approved four-year degree or an approved credential from ISC2's own list |
| No experience yet | Pass the exam anyway and become an Associate of ISC2, with up to 6 years to complete the experience requirement and convert to full CISSP |
| Endorsement | A current, active ISC2-certified professional must attest to your experience — submitted within 9 months of passing the exam |
| Price | Historically around USD $749 list; regional pricing and bundles are common |
| Maintenance | 3-year certification cycle; annual Continuing Professional Education (CPE) credits plus an Annual Maintenance Fee (AMF) are required to stay certified |
Unlike the AWS Security Specialty's merely-recommended experience level, CISSP's five-year requirement is checked and enforced — it's the reason many engineers sit CISSP later in their career than certifications this course otherwise profiles. If you don't yet have five years across two-plus domains, you can still take and pass the exam and hold the Associate of ISC2 title while the clock runs, or start with ISC2 Certified in Cybersecurity (CC) — the same organization's genuinely entry-level credential, with no experience requirement at all.
Everything in this table changes on ISC2's own schedule, not this site's. Confirm current pricing, question counts, and the experience-waiver list on the official ISC2 CISSP page before you register, and read the current CISSP Exam Outline PDF — the domain weights in the section above come from that same document.
Where CISSP overlaps this course, and where it doesn't
☺ Like you're 10: One of the eight topics is basically "the whole reason this course exists." The other seven are a different job, wearing a security badge.
Laid out domain by domain, the honest picture is that CISSP is mostly a different discipline that happens to share a subject with this course, not a superset of it:
| CISSP domain | Weight | Overlap with this course |
|---|---|---|
| 1 · Security and Risk Management | 16% | Loosely, via threat modeling and compliance & governance — but most of Domain 1 is law, regulation, and business-continuity planning this course never covers |
| 2 · Asset Security | 10% | Minimal — data classification and retention policy, largely outside pipeline security's scope |
| 3 · Security Architecture and Engineering | 13% | Conceptual overlap with cryptography & key management and secure design principles — tested as recall, not applied cryptography |
| 4 · Communication and Network Security | 13% | Essentially none — enterprise network architecture is a different layer than pipeline or workload security |
| 5 · Identity and Access Management | 13% | Related in spirit to workload identity & pipeline IAM, but scoped to enterprise workforce identity, not pipeline or machine identity |
| 6 · Security Assessment and Testing | 12% | Conceptual overlap with SAST, DAST & SCA — knowing what a scan category is and when to use it, not running one |
| 7 · Security Operations | 13% | Conceptual overlap with incident response & forensics, but Domain 7 also covers physical security and disaster recovery this course doesn't touch |
| 8 · Software Development Security | 10% | The closest match in the whole exam — secure SDLC concepts, maturity models, and software security governance, at a policy altitude rather than a tool-configuration one |
The schematic below makes the same point visually, plotted against this course's own hands-on flagship and its narrower ISC2 sibling.
CDP and CKS cluster in the top-left: narrow in scope, graded on whether you actually did the work. CISSP sits at the opposite corner entirely — the broadest scope of the four, tested through recall and judgment rather than execution. CSSLP splits the difference in an instructive way: narrow like CDP — it's specifically about the secure software lifecycle — but knowledge-based like CISSP. If Domain 8 is the part of CISSP that actually excites you, CSSLP is ISC2's own answer to "give me all of that, and none of the physical-security or business-continuity material."
Who in this course should actually consider it
☺ Like you're 10: Ask what you're actually trying to prove. "I can do the work" and "I understand the whole program" are different claims, and they need different badges.
Consider CISSP seriously if you're a security architect, a security manager, or a DevSecOps engineer with real eyes on a CISO or director-level track — roles where the job stops being "configure the scanner" and becomes "decide what the organization's risk posture should be and defend that decision to a board." It's also worth sitting if your employer or a government contract requires a DoD 8570/8140-approved baseline certification, since CISSP has held that recognition for years and a hiring filter built around it won't accept a hands-on pipeline credential as a substitute, however much more relevant that credential is to the daily work. And if you already have five-plus years in security across a couple of domains, the experience gate that stops many engineers cold is simply not a problem for you.
Reach for something narrower instead if what actually excites you is Domain 8's territory — secure SDLC, software security governance — without the other seven domains: CSSLP is ISC2's own answer to exactly that, and it's a closer neighbor to everything in the secure SDLC than CISSP will ever be. Reach for CISM instead if the goal is purely security management and governance without CISSP's architecture and network-security weight — CISM (from ISACA, a different body than ISC2) is narrower and more management-focused by design. And if what you actually want to prove is that you can wire a SAST gate into a pipeline, triage a leaked secret at 2am, or sign a container image — the skill this entire course is built around — sit the CDP, not CISSP. It will not ask you a single question about business continuity planning, and that's exactly the point: it's testing a different, narrower, deeper thing. The full picture of how all of this course's profiled certifications relate to each other lives on the certifications hub.
Skip CISSP for now, without guilt, if you're earlier than five years into a security career and want a credential you can actually sit today — ISC2 CC has no experience requirement and comes from the same organization, making it a genuine stepping stone rather than a detour.
Foxy: Hold on — a security course profiling an exam with zero terminal, zero pipeline, and a five-year waiting line? What am I missing?
Professor Owl: Nobody said this course teaches CISSP's material. It's here so you know honestly what it is and isn't — a management credential, not a harder version of the CDP.
Nutty the Squirrel: Domain 1 practically is my job description — risk registers, regulatory mapping, evidence an auditor can actually use. I'd pass that domain in my sleep.
Benny the Beaver: And Domain 8 — Software Development Security — is basically me. Ten percent of the exam is my entire job.
Timmy the Turtle: Ten percent. Not seventy. That's the number to sit with before anyone signs up expecting this to replace the CDP.
Foxy: So who's it actually for?
Professor Owl: Someone heading toward owning the whole security program, not just the pipeline slice of it. Complement the CDP with this. Don't swap one for the other.
1. How many CBK domains does CISSP cover, and which one overlaps this course's material most directly? 2. What is the formal experience requirement to sit CISSP unconditionally, and what happens if a candidate passes the exam without meeting it yet? 3. Name two CISSP domains that have essentially no overlap with this course. 4. What's the key difference in what CISSP and this course's CDP each actually test? 5. If someone wants ISC2's material on secure software development specifically, without the other seven domains, which certification should they look at instead?
Check your answers
- Eight domains. Domain 8, Software Development Security (10% of the exam), overlaps this course's material most directly — though even there, CISSP tests it as policy-level recall, not hands-on tool configuration.
- Five years of cumulative, paid, full-time work experience across two or more of the eight domains (one year waivable with an approved degree or credential). A candidate who passes without that experience becomes an Associate of ISC2 and has up to six years to complete the requirement.
- Any two of: Asset Security; Communication and Network Security; most of Security and Risk Management (the legal, regulatory, and business-continuity portions); most of Security Operations (the physical-security and disaster-recovery portions).
- CDP is entirely performance-based — graded on whether you actually did the work in a live environment. CISSP is entirely knowledge-based — graded on recall and judgment across a multiple-choice/adaptive exam testing breadth across an entire security program, not depth on pipeline tooling.
- CSSLP (Certified Secure Software Lifecycle Professional) — ISC2's own narrower, knowledge-based certification focused specifically on the secure software development lifecycle.