MurtaqaCISSP Readiness
AR
Murtaqa guide

The Eight CISSP Domains

A guide to the eight current CISSP domains, official weights, scope, and evidence of improvement.

The eight measured domains

Security and Risk Management

Ethics, governance, risk, compliance, business continuity, awareness, and supply-chain risk.

Build a decision map for Security and Risk Management, then solve mixed scenarios and explain why each distractor is weaker.

Asset Security

Information and asset classification, ownership, handling, lifecycle, retention, and destruction.

Build a decision map for Asset Security, then solve mixed scenarios and explain why each distractor is weaker.

Security Architecture and Engineering

Secure design principles, models, cryptography, system and facility security, and system lifecycle.

Build a decision map for Security Architecture and Engineering, then solve mixed scenarios and explain why each distractor is weaker.

Communication and Network Security

Secure network design, components, communication channels, remote access, and segmentation.

Build a decision map for Communication and Network Security, then solve mixed scenarios and explain why each distractor is weaker.

Identity and Access Management

Identity proofing, authentication, authorization, federation, account lifecycle, and access review.

Build a decision map for Identity and Access Management, then solve mixed scenarios and explain why each distractor is weaker.

Security Assessment and Testing

Assessment and test strategies, result analysis, audits, metrics, and control validation.

Build a decision map for Security Assessment and Testing, then solve mixed scenarios and explain why each distractor is weaker.

Security Operations

Investigation, response, recovery, monitoring, vulnerability and change management, continuity, and physical security.

Build a decision map for Security Operations, then solve mixed scenarios and explain why each distractor is weaker.

Software Development Security

Integrating security into the development lifecycle, requirements, design, implementation, testing, and software supply chain.

Build a decision map for Software Development Security, then solve mixed scenarios and explain why each distractor is weaker.

How to study across domains

  • Start with the asset, risk, and business objective before selecting a control.
  • Connect technical design with ownership, evidence, and governance.
  • Practice mixed management and technical scenarios under time.
  • Verify the current outline and experience requirements directly with ISC2.
Primary references

Official sources

Links should be rechecked before a high-stakes decision.

Turn the guide into evidence

Choose your assessment depth

Use Quick for a directional reading or Full when you want broader evidence and a richer report.