CISSP Domain Mind Map: The Whole Syllabus on One Page
INSIGHT · 6 min read · September 2026 · Mindsgate
Every CISSP domain, topic and key concept on one interactive map — with exam weights, glossary deep links and domain-filtered flashcards.
The whole CISSP syllabus on one page: eight domains with their current exam weights, the major topics inside each, and the key concepts underneath. Blue-dashed terms open the full definition in the glossary; every domain links straight into domain-filtered flashcards. Based on the current ISC2 CISSP Exam Outline, independently summarized.
CISSP Glossary → CISSP Flashcards → Chapter Score Tracker →
Focus on a domain
All domains D1 Security and Risk Management 16% D2 Asset Security 10% D3 Security Architecture and Engineering 13% D4 Communication and Network Security 13% D5 Identity and Access Management (IAM) 13% D6 Security Assessment and Testing 12% D7 Security Operations 13% D8 Software Development Security 10%
View
Expand all Collapse all Reset view − + CISSP
8 domains · weights from the current exam outline
D1 Security and Risk Management 16% Security principles and ethicsCIA Authenticity Non-repudiation ISC2 Code of Ethics Security governanceAlignment with business strategy Roles and accountability GRC Security frameworks Legal, regulatory, privacy and complianceGDPR PCI DSS PII Criminal vs civil vs administrative law Intellectual property Policies, standards, procedures and guidelinesPolicy (mandatory, high level) Standard (mandatory, specific) Procedure (step by step) Guideline (recommended) Business continuity and BIA Personnel securityScreening Onboarding / offboarding SoD Job rotation NDAs Risk management IdentifyThreats Vulnerabilities Asset valuation Analyze TreatRisk acceptance Risk avoidance Risk mitigation Risk transfer MonitorQuantitative risk
SLE = Asset Value × Exposure Factor
ALE = SLE × ARO
Controls and control assessmentPreventive / detective / corrective Administrative / technical / physical Compensating controls Threat modellingSTRIDE PASTA VAST DREAD Attack trees Reduction analysis Four methodologies
STRIDE = categorize (6 threat classes)
DREAD = rate (5 scoring questions)
PASTA = 7-stage, risk/asset-centric
VAST = Agile-integrated, scalable
Supply Chain Risk Management Security awareness and trainingPhishing simulations Role-based training Culture Information and asset classificationClassification levels Labelling and marking Asset ownership and inventoryAsset ownership Asset inventory Handling requirements Data lifecycleCreate → store → use → share → archive → destroy Data rolesWho is who
Owner — accountable for the data
Controller — decides purpose & means
Custodian — day-to-day care
Processor — handles data for a controller
Subject/user — the person the data is about
Data retention and destructionData retention Data remanence Secure destruction (purge, crypto-erase, destroy) EOL EOS Data statesData at rest Data in transit Data in use Data protection controlsD3 Security Architecture and Engineering 13% Secure design principlesLeast privilege DiD Secure defaults Fail secure SoD Zero Trust Privacy by design Shared responsibility Keep it simple Defense-in-depth vocabulary
Related terms: layering · classifications · zones · realms
compartments · silos · segmentations
lattice structure · protection rings
Security models System security capabilitiesTPM HSM Memory protection Trusted execution Architecture vulnerabilitiesSingle points of failure Covert channels Emanations Cloud and distributed architectureSaaS PaaS IaaS Containers Microservices Serverless Virtualization IoT Edge computing Cryptography SymmetricAES Fast bulk encryption Key distribution problem Asymmetric Integrity PKI AttacksMITM Brute force Side channel Birthday attack PFS Encryption at a glance
AES = symmetric = fast bulk encryption
RSA/ECC = asymmetric = keys & signatures
SHA = hashing = integrity
Physical and site security Information-system lifecycleAcquire → implement → operate → retire D4 Communication and Network Security 13% OSI and TCP/IP models Secure network protocolsTLS SSL SSH DNSSEC SNMP DHCP DNS IPsecIPSec AH — authentication/integrity ESP — encryption/confidentiality IKE — key exchange AH vs ESP
AH = authentication and integrity only
ESP = encryption/confidentiality plus security services
Network architecture and segmentation Traffic flowsNorth-south traffic East-west traffic Wireless and mobileWPA3 CCMP Zigbee Enterprise vs PSK Captive portals Wireless crypto lineage
WEP → TKIP (WPA) → CCMP/AES (WPA2) → SAE (WPA3)
SDN and virtual networking Network monitoring and defense Secure communication channelsVPN EAP PAP CHAP PVC Voice and collaboration PPP authentication
PAP = plaintext (no protection)
CHAP = challenge/response, password never sent
EAP = extensible framework (40+ methods)
D5 Identity and Access Management (IAM) 13% Access control fundamentalsPhysical and logical access Identification Authentication Authorization Accounting AAA AuthenticationMFA Something you know / have / are Session management Identity proofing Federation and SSOSSO FIM SAML OAuth OIDC Federation standards
SAML = enterprise federation / browser SSO
OAuth = delegated authorization
OIDC = authentication & identity on OAuth 2.0
SCIM = provisioning / deprovisioning
Privileged accessPAM JIT Break-glass accounts Service accounts Authorization models Provisioning and lifecycleSCIM Joiner / mover / leaver Access reviews Authentication systemsD6 Security Assessment and Testing 12% Assessment strategiesInternal assessment External assessment Third-party assessment Security control testing Vulnerability assessment and pen testingVA PT Red / Blue / Purple teams Breach and attack simulation VA vs PT
Vulnerability Assessment = identify and evaluate weaknesses
Penetration Test = authorized exploitation to demonstrate impact
Code and interface testing Log review and monitoring testsLog review Synthetic transactions Compliance and auditsSecurity audits SSAE-18 / SOC reports Compliance testing Metrics and remediationKPI KRI Security metrics Test-result analysis Remediation Exceptions Investigations and forensicsEvidence handling Chain of custody Digital forensics eDiscovery Logging and monitoring Detection and prevention technologies Incident managementIR CSIRT Incident-response sequence
Detection / Analysis
→ Containment
→ Eradication / Remediation
→ Recovery
→ Lessons Learned
Operational securityConfiguration management Change management Patch and vulnerability management Resource protection Need to know / least privilege Backup, recovery and resilience Physical and personnel securityGuards and access controls Duress Travel security D8 Software Development Security 10% Secure SDLCSDLC SSDLC Security in requirements and design Threat modelling Development methodologiesAgile Waterfall DevOps / DevSecOps SW-CMM CI/CD and configuration managementCI/CD Repositories Code signing Change management Application security testingSAST DAST IAST SCA RASP Testing at a glance
SAST = analyze code without executing it
DAST = test the running application externally
IAST = instrument the app while it runs
SCA = analyze third-party components
Software supply chainSBOM COTS Open source Libraries and dependencies Secure coding and APIsOWASP Input validation API API authentication and authorization XSRF Software security effectivenessAuditing and logging of changes Risk analysis of acquired software CSP