CISSP Mastery: 8 Domains of Security

The CISSP Common Body of Knowledge (CBK) is organized into eight distinct domains. Mastery of these areas is essential for professional certification and robust enterprise security architecture.

Domain 1: Security and Risk Management

Focuses on confidentiality, integrity, availability, compliance, legal issues, and professional ethics.

Domain 2: Asset Security

Covers data classification, ownership, retention, and security controls for information assets.

Domain 3: Security Architecture and Engineering

Covers security models, cryptography, physical security, and site/facility design.

Domain 4: Communication and Network Security

Details secure network architecture, communication protocols, and secure network components.

Domain 5: Identity and Access Management (IAM)

Focuses on access control models, identity management, and lifecycle provisioning.

Domain 6: Security Assessment and Testing

Covers vulnerability assessment, penetration testing, and security audit strategies.

Domain 7: Security Operations

Includes incident response, disaster recovery, investigations, and physical security.

Domain 8: Software Development Security

Covers SDLC phases, security within the development lifecycle, and database security.