CredenTrek
Independent roadmaps for accredited credentialsEdition 2026.2 · Register verified 9 October 2026
Library / Technology / No. 09
Cover of CredenTrek For CISSP
CredenTrek No. 09 · Technology Library · Computers · Cybersecurity · Certification Preparation

CredenTrek For CISSP

Choose It Right. Pass It Smart. Turn It into a Career.

CISSP is not a harder technical exam. It tests the judgement of a security leader.

Strong specialists answer as engineers when the exam asks what the business needs first. Others pass and find their experience does not fit the rules, miss the nine-month endorsement deadline or let their credential lapse. This book shows you the whole exam on one map and every decision around it.

Paperback · coming soonKindle · coming soon

Edition 2026.2 · Verified 9 October 2026. All 8 domains and 62 objectives verified against the ISC2 CISSP exam outline effective 15 April 2024; ISC2 has announced no later CISSP outline as of October 2026.

01The problem

Where candidates go wrong

CISSP is a senior credential, and candidates often prepare like junior ones. They memorise technical detail, then meet questions that ask what a security manager should do first. They study their favourite technical domains and neglect security and risk management, the heaviest domain.

The administration catches people too. Some pass the exam, then discover that their experience does not fit the rules, or that their endorsement must be completed within nine months. Others forget the annual maintenance fee and continuing education, and the credential they worked years for is suspended.

The gap this book fills

CISSP books usually teach all eight domains in great depth, often across more than a thousand pages. Few show you the whole exam on one map and then help with every decision around it, from the experience rule to endorsement and renewal. This book does both, and checks every changeable fact against ISC2's own documents.

02Snapshot

CISSP at a glance

These facts were checked against ISC2's CISSP pages, the exam outline effective 15 April 2024, ISC2's pricing page and its certification maintenance handbook in October 2026. Confirm them on isc2.org before you act.

Item Detail
Credential Certified Information Systems Security Professional (CISSP)
Issuing body ISC2
Level Advanced, for experienced security professionals
Experience Five years, full time, in two or more of the eight domains; one year can be waived
Without the experience Pass the exam and become an Associate of ISC2, with six years to gain it
Exam outline Effective 15 April 2024; eight domains
Format Computerised adaptive testing in all languages; 125 to 150 items; maximum three hours
Passing score 700 out of 1,000
Exam fee US$749 in most regions, plus any tax
Languages Chinese, English, German, Japanese and Spanish
Maintenance US$135 a year; 120 CPE credits every three years
03What changed

What changed in April 2024

ISC2 updated the exam on 15 April 2024, following a new job task analysis. Three changes matter. Computerised adaptive testing replaced the long fixed-form exam in German, Japanese and Spanish, so every language now has the shorter adaptive format. The maximum time became three hours for all languages. The domain weights also shifted slightly.

Domain Weight
1 · Security and Risk Management 16%
2 · Asset Security 10%
3 · Security Architecture and Engineering 13%
4 · Communication and Network Security 13%
5 · Identity and Access Management (IAM) 13%
6 · Security Assessment and Testing 12%
7 · Security Operations 13%
8 · Software Development Security 10%

Table 5.1 · Domain weights from the CISSP exam outline effective 15 April 2024.

04What you learn

What you will learn

You will learn what the CISSP exam tests in full: the eight domains and all 62 objectives of the current ISC2 exam outline, explained in plain English. You will see how the adaptive exam works, how it is scored and what changed in April 2024. You will test yourself with 16 practice questions written in the managerial style the exam rewards.

Around that content, you will learn how to check your experience against ISC2's rules and choose between full certification and the Associate route. You will also learn to plan your hours, book, budget, secure an endorsement and keep the credential active.

05Outputs

What you will have at the end

Output Where you build it
A written decision: full CISSP, Associate route or a different step Chapter 3
An experience record mapped to the eight domains Chapter 4
A self-rating on all 62 objectives Chapter 5
A weekly study plan split by domain Chapter 7 and Appendix B
A three-level budget, including annual fees Chapter 9 and Appendix C
Six message templates for ISC2 and Pearson VUE Chapter 10 and Appendix D
A senior job search, salary and advisory plan Chapters 11 to 13
CV lines and leadership interview stories Chapter 14 and Appendix F
A renewal plan for your three-year cycle Chapter 15
Your score on 16 practice questions Appendix G
06Contents

Sixteen chapters in six stages

Part I · Understand
  1. 1What CISSP Really Is
  2. 2The Professional Picture
Part II · Decide
  1. 3Is It Right for You Now?
  2. 4Eligibility and Requirements
Part III · Prepare
  1. 5The Exam Map
  2. 6Choosing Your Study Route
  3. 7Your Adaptive Study Plan
Part IV · Book and Sit
  1. 8Scheduling and Exam Day
  2. 9Costs and Budget
  3. 10Official Communication
Part V · Leverage
  1. 11Where It Is Valued Most
  2. 12Reading Salaries by Region
  3. 13Freelancing and Consulting
  4. 14Turning It into Career Proof
Part VI · Sustain and Grow
  1. 15Keeping It Active
  2. 16What Comes Next

Appendices. A. Official Sources Map · B. Weekly Plan Template · C. Budget Template · D. Message Templates · E. Exam-Day Checklist · F. CV and LinkedIn Template · G. Practice Questions · H. Glossary

07Sample

Try three practice questions

Three of the book's 16 questions, written for the book in the style of the exam. They are not ISC2 questions.

Question 1 · Domain 1 · 1.9

A risk assessment finds a high risk that would cost more to fix than the asset is worth. Senior management decides to live with it. Which response is this?

  1. AAvoidance
  2. BTransference
  3. CAcceptance
  4. DMitigation
Show answer
C. Choosing to live with a known risk, with management's approval, is risk acceptance.
Question 2 · Domain 1 · 1.3

Who holds final accountability for protecting an organisation's information assets?

  1. AThe security manager
  2. BSenior management
  3. CThe system administrator
  4. DThe external auditor
Show answer
B. Senior management holds final accountability. Security staff advise and implement, but accountability stays at the top.
Question 3 · Domain 1 · 1.7

What should be completed first when developing a business continuity plan?

  1. AA disaster recovery test
  2. BA business impact analysis
  3. CA purchase of backup equipment
  4. DAn awareness campaign
Show answer
B. A business impact analysis identifies critical functions and recovery priorities, which the rest of the plan depends on.
08Get the book

Paperback and Kindle

For experienced security professionals moving into senior, lead or management roles, and consultants who need a recognised credential.

Paperback · coming soonKindle · coming soon

Companion reading and kit

Search links on Amazon for items candidates often use alongside this book. We do not review them; check that any edition matches your exam version.

09Questions

Frequently asked

Is this an official ISC2 publication?
Independent publication. Not affiliated with, sponsored by or endorsed by ISC2. ISC2 and CISSP are trademarks of ISC2, Inc.
How current is the book?
This is edition 2026.2, verified on 9 October 2026. All 8 domains and 62 objectives verified against the ISC2 CISSP exam outline effective 15 April 2024; ISC2 has announced no later CISSP outline as of October 2026.
Does it include practice questions?
Yes. It includes 16 original practice questions with explained answers, written for the book in the style of the exam and mapped to the official outline. None is taken from a live exam.
Who is it for?
For experienced security professionals moving into senior, lead or management roles, and consultants who need a recognised credential.
What happens when the exam changes?
The book is updated in a new edition when the issuing body publishes a change. The update register on this site shows each known change and how it is handled.
→Also in the series