# Map all 8 CISSP domains as one program

Source: https://ai.techclick.in/blog_cissp_all_domains_guide
Markdown: https://ai.techclick.in/blog_cissp_all_domains_guide.md
Publisher: Techclick Infosec Pvt Ltd

Map all 8 CISSP domains as one security program. Manager mindset, PACES item analysis, and how the domains connect. Official ISC2 April 2024 exam outline only.

Quick answer

   CISSP is one connected program. Domain 1 sets policy and acceptable risk. Domain 2 names what you protect. Domains 3, 4, 5, and 8 build and grant the controls. Domain 6 proves they work. Domain 7 runs, detects, and recovers — then feeds lessons back to Domain 1. On the item, think manager: policy before product. After a miss, run PACES before you restudy a chapter.

## 1. Why the map beats a dump

 2 a.m. ransomware is on a file server. The engineer instinct is wipe and rebuild. The exam stem says  FIRST . The manager move is contain, assess scope, and protect evidence — then eradicate. Same night, same facts, two brains.

 That is the whole CISSP problem. Candidates fail by treating the Common Body of Knowledge as eight flash-card piles. The April 15, 2024  ISC2 CISSP exam outline  lists eight domains because they are the rooms of one job: design, engineer, and manage the organization’s security posture.

   Hero · one program, eight rooms

   Notice the loop, not a list. Policy and assets sit upstream of design, identity, software, proof, and operations.

 ISC2 states the credential tests deep technical  and  managerial knowledge. Computerized Adaptive Testing (CAT) does not walk domain 1, then 2, then 3. Items are selected to the outline weights. If you cannot connect rooms, a hard item feels random.

   This page is the map

   Deep-dives live on the Domain 1–8 lessons. Here you learn the wiring: manager mindset, PACES, and how a ticket travels across domains. Do not memorize every outline bullet on this page.

## 2. Mental model: one program, eight rooms

 Pre-train three words.  Policy  is the management statement of direction.  Control  is a safeguard you select after risk.  Evidence  is what Domain 6 and Domain 7 produce so Domain 1 can update residual risk.

 Read the program left to right, then back. Domain 1 decides what “enough security” means. Domain 2 classifies the thing you are protecting. Design, network, identity, and software (3, 4, 5, 8) implement that decision. Assessment proves it. Operations lives it. Lessons learned return to risk.

   Flow 1 · the domain loop

       CISSP eight domains as one program loop

- Decide → protect → prove → operate → update risk D1 Risk + policy Acceptable risk · 16% D2 Assets Classify · handle · 10% Build the controls D3 Design 13% · D4 Network 13% D5 IAM 13% · D8 Software 10% D6 Prove Test · audit · 12% D7 Operate Detect · recover · 13% Lessons → D1 Update residual risk Weights are official average weights from the April 2024 outline — not study-hour guesses CAT still samples all eight rooms. A 10% domain can still fail you if you treat it as optional. Read clockwise from D1. Operations is not the end — it is the sensor that updates risk. Say this out loud Policy sets the target. Assets name the thing. Design, network, identity, and software build the path. Testing proves it. Operations lives it and sends the residual-risk number back upstairs. ## 3. Manager mindset + PACES ISC2’s own description is the mindset: you design, engineer, and manage the posture. On FIRST / BEST items the engineer brain grabs a product. The manager brain asks who owns the decision, what risk is acceptable, and which control type fits — preventive, detective, or corrective — after the assessment. Visual · Path A tool vs Path B governance Path A buys a control. Path B writes or applies policy and finishes a risk assessment first. The exam almost always wants Path B on FIRST. Stem word Manager move Engineer trap FIRST Risk assessment, policy, or the next process step in the outline Install, configure, or wipe BEST Most complete risk-based answer that still enables the business The most technical or most expensive control Access dispute Data owner classifies and approves; security implements CISO or admin decides the label People at risk Safety and availability can outrank confidentiality (site, OT, emergency) Always lock it down New vendor / AI / SaaS Domain 1 supply-chain and risk concepts before a pilot Connect the API and “harden later” PACES is a Techclick item-analysis loop, not an ISC2 domain. Use it after every miss. It is how you force the manager lens onto four options. Visual · PACES sequence Do not open a 400-page chapter after a miss. Walk P → A → C → E → S first. The failure is usually C or E, not a missing port number. Letter Means Ask yourself P Possibility Read every interpretation of the stem Is FIRST asking for process order, not the “best tool”? A Alternatives Eliminate before you fall in love Which two options are the same layer of thinking? C Consequences Business and people impact Did I pick a tech fix that ignores residual risk or safety? E Evidence Outline language, not war-story habit Which domain task actually owns this? S Selection Name the failure pattern Engineer brain? Experience shortcut? Red-herring protocol? Unsafe shortcut “In my SOC we just isolate and reimage.” Real shops do that under a playbook. The exam still wants the outline order: investigations and incident management have evidence handling, then detection / response / mitigation / recovery / lessons learned. Your shop’s skip is not the scoring key. ## 4. How the eight domains connect One job sentence each. Official names and average weights are from the April 2024 outline. This is the wiring diagram, not the CBK dump. Domain Weight Job in the program Feeds / fed by 1. Security and Risk Management 16% Ethics, CIA + authenticity + nonrepudiation, governance, legal/privacy, policy stack, BIA, personnel security, risk, threat modeling, supply-chain risk, awareness Sets the target every other domain implements 2. Asset Security 10% Classify, handle, provision, lifecycle roles (owner / custodian / processor), retention, data states, DLP / DRM / CASB as protection methods Needs D1 policy; tells D3–D5–D8 what to protect 3. Security Architecture and Engineering 13% Secure design principles, models, system capabilities, crypto, site/facility, information-system lifecycle Turns D1/D2 requirements into a buildable design 4. Communication and Network Security 13% Secure architecture (OSI/TCP-IP, segmentation, ZT/micro-seg, SDN/VPC), harden components, secure channels Carries D2 assets along a D3 design 5. Identity and Access Management (IAM) 13% Physical/logical access, IAAA, federation, authorization models, provisioning lifecycle, auth systems Enforces D1 policy on D2 assets 6. Security Assessment and Testing 12% Assessment strategy, control testing, process data, reports, audits (internal / external / third-party) Proves D3–D5–D8 controls; evidence returns to D1 7. Security Operations 13% Investigations, logging/monitoring, CM, IR, patch, change, DR/BC, physical and personnel safety Runs the program; lessons update D1 residual risk 8. Software Development Security 10% Security in the SDLC, ecosystem controls (SAST/DAST/SCA/IAST), acquired software, secure coding Builds what D3 designed; D6 tests it; D7 runs it ISC2’s outline page also states AI security is interwoven across all eight domains , not a ninth domain. Same loop: govern the model (D1), classify training data and weights (D2), design and isolate the system (D3/D4), identity for agents (D5), red-team the model (D6), monitor drift and abuse (D7), secure the SDLC and libraries (D8). #### Upstream rooms D1 and D2. If these are missing, every later control is decoration. FIRST items live here more than candidates expect. #### Build rooms D3, D4, D5, D8. Pick these when the stem already has policy and classification and now asks how to implement. #### Proof room D6. Scan lists weakness. Pen test proves exploitability. Audit attests over a period. Do not mix those three. #### Live room D7. Contain before eradicate. Chain of custody if it may become evidence. DR tests are not the same as backups existing. ## 5. Decision flow: who owns FIRST Flowchart first. Use this when the stem is a messy workplace story. Flow 2 · route the FIRST move Decision flow for routing a CISSP scenario to the first domain Start: what is missing in the story? Is anyone hurt or still bleeding? YES D7 + people safety Contain · stabilize · 7.15 NO Policy / risk done? If NO → D1 first RA · policy · SCRM Asset classified? If NO → D2 Build it → D3 / D8 Move it → D4 Who may → D5 Prove it → D6 Diamond = missing input, not “favorite domain” If policy is absent, a perfect ZTNA design is the wrong FIRST answer. Diamond = decision. Always ask what input is missing before you pick a build-domain control. ## 6. How to choose the first move Compare stems the way CAT will mix them. Same company, different missing room. Situation First domain Manager first move Not first New KYC vendor will see customer PII D1 Supply-chain risk + contractual / regulatory requirements Buy a CASB and “onboard Friday” PII found in an unnamed US bucket D2 Classify, assign owner, set handling and location rules Turn on random encryption App design review, labels already set D3 Secure design principles (least privilege, fail securely, privacy by design) Write IR playbooks first Malware on a laptop, flat VLAN D4 then D7 Contain now; design micro-segmentation / ZT so blast radius shrinks Rewrite the security policy from scratch tonight Contractor still has standing admin D5 Deprovision + lifecycle / JIT; owner already decided the role New SIEM use-case as the only fix Buyer wants proof controls operated D6 Assessment / audit strategy that matches who must attest A self-made vuln-scan PDF Ransomware note on a file server D7 Incident management: detect, contain, then recover; preserve artifacts Reformat as step one CVE in a library, 40 services D8 Inventory / SCA / acquired-software impact, then patch via change Full-interruption DR test first Study time vs weight Official average weights: D1 16%; D3, D4, D5, D7 13% each; D6 12%; D2 and D8 10% each. Budget hours to the loop, not only to D1. CAT is compensatory — strong rooms can offset a weak one, but they are not a license to skip D8. ## 7. Item runbook: Side A / B / C Treat every scored item like a change ticket. Primary source for facts: the current CISSP Certification Exam Outline . ### Side A — Read the stem (external facts) #### Circle the verb FIRST, BEST, PRIMARY, MOST cost-effective, IMMEDIATELY, NOT. FIRST almost always wants process order from the outline, not your favorite tool.

- #### Name the asset and the role Who is speaking — owner, custodian, processor, CISO, engineer? Domain 2 roles decide who is allowed to choose the label. Domain 1 decides ethics if public safety is in the stem.

- #### Mark what is already done If the stem says “policy is approved” or “data is classified Restricted,” do not rewind to write policy. Move to the next room in the loop.

### Side B — PACES (your analysis)

- #### P and A Write one sentence for each option in manager language. Strike any option that installs a product before risk, or that skips a required lifecycle step (for example eradicate before contain when evidence still matters).

- #### C and E Consequences: people, residual risk, business enablement. Evidence: which outline task number could you point to? If you cannot point to a domain task, you are guessing from a vendor blog.

- #### S Name the pattern: engineer brain, experience shortcut, or red-herring protocol. Then commit. CAT does not allow review.

### Side C — Prove the pick

- #### Say the connecting sentence “D2 already classified it, so the first remaining gap is D5 deprovision” — or whatever the loop says. If you cannot say the sentence, you picked a silo.

- #### After a miss, PACES before reread Only then open the matching domain lesson. Do not reread all eight.

   Whiteboard card (say it, do not memorize a dump)
 D1 decide risk + write policy
D2 name + classify the asset
D3 design  ·  D4 carry  ·  D5 grant  ·  D8 build
D6 prove  ·  D7 run and recover  ·  back to D1
PACES after every miss

## 8. CAT runtime path

 Official CAT facts from ISC2 — not forum lore.

   Visual · proof and exam-day calm

   CAT targets items you have about a 50% chance of answering. Feeling that every item is hard is the design, not a fail signal.

   Fact  Official value  What you do with it

  Format  CAT only · multiple choice + advanced items  No linear form. No going back after you confirm.
  Length / time  100–150 items · 3 hours · breaks count against the clock  Answer at least 100 operational+pretest mix; do not stall 5 minutes on item 12.
  Pretest  25 unscored items inside the exam  You cannot see which. Treat every item as scored.
  Pass mark  700 out of 1000 scaled  You do not get a numeric score on the printout.
  Stop rules  95% confidence after 100 · or max length · or time  Stop at 100 can be pass or fail. Extra items mean the engine needs more data.
  Content order  Not in domain sections; weights still apply  The map matters more than “I studied D4 today.”
  Scoring  Compensatory across domains  You need overall proficiency, not “above” in every room.

 Experience, also official: five years cumulative full-time in two or more of the eight current domains. A qualifying degree or one credential on the ISC2 approved list may waive one year only. Full-time is defined as at least 35 hours/week for four weeks per month accrued. Part-time (20–34 hours) converts at 1040 hours = 6 months and 2080 hours = 12 months. Internships can count with letterhead documentation. Pass without the time and you may become an Associate of ISC2 and have six years to earn the experience.

   Eligibility proof

   Map your jobs to two or more outline domains by task, not by job title. “Firewall admin” can be D4 + D7. “IAM engineer” can be D5 + D1 policy. Write the domain numbers before you apply — ISC2 will ask for them.

## 9. Traps + proof checklist

   Failure  What it looks like  Fix

  Silo study  You can recite D5 models and still pick “install DLP” on a FIRST vendor item  Redraw the loop. Ask which input is missing.
  Engineer brain  Best tool wins  PACES letter C. Policy and risk assessment sit in D1 for a reason.
  Shop shortcut  “We reimage first”  Outline order: investigations + IR phases. Evidence can matter.
  Weight worship  Skip D2 and D8 because they are 10%  CAT still samples them. Software and assets are how other rooms fail in production.
  AI as a ninth domain  Wait for a dedicated AI chapter  Official stance: AI tasks are woven through all eight rooms.
  CAT panic  Hard item = I am failing  Official design: next item is aimed near 50% for you.
  Invented numbers  Forum weights, fake passing percentages  Use only the published average weights and 700/1000.

   Pilot checklist — you are ready for domain deep-dives when

- You can draw the eight-room loop from memory and point to official weights.

- You can PACES a missed FIRST item in under two minutes.

- You can route the eight situations in the choose table without opening notes.

- You can state CAT length, pretest count, no-review rule, and experience waiver from ISC2 pages.

- You know AI is across the outline, not a bonus domain.

## Knowledge check

   Six judgment items. Map, mindset, PACES, CAT. Check answers when you finish.

       Q1
       Procurement wants to connect a new AI vendor to customer records next sprint. The stem asks what the security professional should do FIRST. What is the manager pick?

           Stand up a sandbox pilot so engineering can measure latency
           Perform a risk assessment and apply Domain 1 supply-chain / governance requirements before the integration
           Buy a model-security product and put it in-line
           Train the SOC on prompt injection detections

       Correct:  b . FIRST + new vendor / AI is Domain 1: risk, governance, and supply-chain concepts. Pilot and tools come after the acceptable-risk decision. Re-read manager mindset and the choose table.

       Q2
       A ransomware note appears on a file server. An engineer starts a rebuild from gold images. What should have been FIRST in the Domain 7 incident path?

           Patch every adjacent host before touching the victim
           Contain and assess scope, and preserve artifacts if the event may become an investigation
           Issue a public statement so regulators hear it from you
           Rewrite the information security policy that night

       Correct:  b . Domain 7 incident management is detect → respond / mitigate → recover, with investigations requiring evidence handling. Wipe-first destroys both containment options and artifacts. Re-read the decision flow and traps.

       Q3
       Business and security disagree on whether a customer table is Internal or Restricted. Who decides the classification?

           The CISO, because Domain 1 owns governance
           The data custodian who runs backups
           The data owner
           The external auditor, so the label will survive SOC review

       Correct:  c . Domain 2 data roles: owners set classification and handling; custodians implement. Domain 1 does not steal the owner’s decision. Re-read how domains connect.

       Q4
       You missed a FIRST item by choosing “deploy a CASB this week.” Which PACES letter failed first?

           S — you named the failure pattern before you read the stem
           A — you eliminated nothing, but the stem was a NOT question
           C — you optimized for a tool instead of business / governance consequences
           E — PACES forbids using the exam outline as evidence

       Correct:  c . Consequences asks whether you thought impact and process, not a product. E is the opposite of “forbid the outline” — evidence  is  the outline. Re-read PACES.

       Q5
       A payments API will store PAN. The data owner has just classified it Restricted. What is the next connecting move across the map?

           Select handling rules and controls that match that classification and the residual risk already accepted in Domain 1
           Schedule a full-interruption DR test before any design work
           Publish an SBOM and stop — Domain 8 now owns the whole problem
           Skip design and jump to Domain 6 penetration testing of production

       Correct:  a . D2 just finished. Next rooms implement handling and controls under existing D1 risk appetite — D3/D5/D8, then D6 proves, D7 runs. Re-read the domain loop.

       Q6
       On CAT every item feels hard. You cannot review the last answer. What does ISC2’s CAT design say that feeling means?

           You have already failed; the last items are known-easy fail items
           Expected — the algorithm aims items at about a 50% chance for your current ability estimate
           You should skip remaining items to protect your score
           Hard items only appear if you are below proficiency in Domain 1

       Correct:  b . Official CAT FAQ: after each answer the next item is chosen so you have roughly a 50% chance. No review. Skipping risks the run-out-of-time fail if you never reach the minimum item count. Re-read CAT runtime.

       Check answers
       Reset

## Sources

- ISC2 — CISSP Certification Exam Outline (effective 15 April 2024): eight domains, average weights, exam length, item range, 700/1000, CAT, experience summary, AI woven across domains, PDF outline link.

- ISC2 — CISSP Exam Outline April 2024 (English PDF)

- ISC2 — Computerized Adaptive Testing : 100–150 items, 25 pretest, no review, compensatory scoring, stop rules, ~50% targeting.

- ISC2 — CISSP Experience Requirements : five years in two or more domains, one-year waiver, Associate of ISC2 (six years), full-time / part-time hour rules.

- ISC2 — CISSP certification overview

 Related:  Domain 1  ·  Domain 2  ·  Domain 3  ·  Domain 4  ·  Domain 5  ·  Domain 6  ·  Domain 7  ·  Domain 8

---
Cite this Techclick lesson with the source URL. Do not invent fees, batch dates, or job guarantees.
Browse all lessons: https://ai.techclick.in/blogs
AI index: https://ai.techclick.in/llms.txt
