CISSP Training Course

Training course

This is a free, self-paced reading course for the ISC2 Certified Information Systems Security Professional (CISSP), the credential hiring managers reach for when staffing CISOs, security architects, security managers, and senior engineers. The CISSP is a breadth exam, and breadth is what makes it hard: eight domains, from cryptography and network protocols through governance, forensics, and secure software, with adaptive delivery that will find any domain you skipped. This course exists to give you a single ordered pass across all eight before you start drilling questions.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight from the outline that took effect April 15, 2024. That structure matters more on the CISSP than on most exams, because the weights are deliberately flat, six of the eight domains sit between 12% and 13%, and no single domain will carry you. Security and Risk Management is the heaviest at 16%, and it is also the domain that sets the vantage point the rest of the exam is written from: not what is technically correct, but what a security professional advising the business should do first.

CISSP Professional level 8 modules Domain-weighted Self-paced Free account

What the course covers

Security and Risk Management

Module 1 · 16%

The exam’s center of gravity: governance, risk assessment and treatment, legal and regulatory compliance, privacy, professional ethics, business continuity foundations, security policy, awareness, and supply chain risk management.

Asset Security

Module 2 · 10%

Information and asset handling across the full lifecycle, data roles and ownership, classification and labeling, retention and minimization, media sanitization and remanence, and protecting data at rest, in transit, and in use.

Security Architecture and Engineering

Module 3 · 13%

Secure design principles, formal security models, cryptography and cryptanalytic attacks, hardware and virtualization security, cloud shared responsibility, and the physical and environmental design of facilities and data centers.

Communication and Network Security

Module 4 · 13%

Secure network architecture and protocols: segmentation and screened subnets, IPsec and TLS, wireless security, 802.1X port-based access control, VoIP and converged networks, software-defined networking, and the attacks that target each layer.

Identity and Access Management (IAM)

Module 5 · 13%

The identity lifecycle end to end, authentication factors and biometrics, federation with SAML, OAuth, and OIDC, Kerberos, access control models, privileged access management, just-in-time access, and zero trust.

Security Assessment and Testing

Module 6 · 12%

Proving controls actually work: vulnerability assessments versus penetration tests, SAST, DAST, and fuzzing, audit strategies and SOC reports, security metrics, and validating disaster recovery without breaking production.

Security Operations

Module 7 · 13%

Security day to day, incident response, digital forensics and evidence handling, logging with SIEM and UEBA, backups and recovery sites, patch and change management, and catching exfiltration before it succeeds.

Software Development Security

Module 8 · 10%

Security built into software rather than bolted on: secure SDLC and DevSecOps, threat modeling, injection and XSS, software supply chain and SBOMs, secrets management, and secure design principles like complete mediation.

How to use it

Read a module, then test that domain immediately with the CISSP practice exam rather than waiting until you have read all eight. Adaptive delivery is unforgiving of a weak domain. The engine will keep probing wherever your answers are inconsistent, so a domain you skimmed is a domain the exam will find. The habit that separates a pass from a near miss is reading each scenario for the vantage point rather than the technology: when two answers are both technically true, the CISSP wants the one a security professional advising the business would take first, and that is a reflex you build by working scenarios, not by rereading definitions. The course modules themselves require a free Certifym account to open.

For exam logistics, the 100 to 150 adaptive items, the three-hour window, the 700-out-of-1000 scaled cut score, the five-year experience requirement, and how the April 2024 outline changed the weights, see the CISSP certification guide.

CISSP Training Course

A domain-by-domain training course for the ISC2 CISSP exam.

This course walks through the eight domains of the ISC2 CISSP Common Body of Knowledge in the same weighting order the exam uses. Every lesson pairs the concept, why it matters on the exam, and how it shows up in the real world. Companion practice-exam sets in Certifym Exams reinforce each domain.

Module 1: Security and Risk Management 15% of exam

Foundational principles (CIA and beyond), security governance, compliance and legal, professional ethics, security documentation, business continuity requirements, personnel security, risk management, threat modeling, supply-chain risk, and awareness programs.

  • 1.1 Foundational Security Principles 10 min Free preview
  • 1.2 Security Governance 9 min πŸ”’
  • 1.3 Compliance, Legal, and Regulatory Requirements 11 min πŸ”’
  • 1.4 Professional Ethics 6 min πŸ”’
  • 1.5 Security Documentation: Policies, Standards, Procedures, Guidelines 7 min πŸ”’
  • 1.6 Business Continuity Requirements 10 min πŸ”’
  • 1.7 Personnel Security 8 min πŸ”’
  • 1.8 Risk Management Concepts 12 min πŸ”’
  • 1.9 Threat Modeling 8 min πŸ”’
  • 1.10 Supply Chain Risk Management 8 min πŸ”’
  • 1.11 Security Awareness, Education, and Training 6 min πŸ”’

Module 2: Asset Security 10% of exam

Information and asset classification, ownership, retention, data states, protection methods, and secure data lifecycle.

  • 2.1 Information and Asset Classification 8 min πŸ”’
  • 2.2 Ownership: Data Owners, Custodians, Processors 7 min πŸ”’
  • 2.3 Data Lifecycle: Create, Store, Use, Share, Archive, Destroy 7 min πŸ”’
  • 2.4 Data States: At Rest, In Transit, In Use 7 min πŸ”’
  • 2.5 Retention and Destruction 8 min πŸ”’
  • 2.6 Data Protection Methods: DLP, DRM, Tokenization 8 min πŸ”’
  • 2.7 Privacy Considerations: PII, PHI, and Data Minimization 7 min πŸ”’
  • 2.8 Asset Handling and Storage Requirements 6 min πŸ”’

Module 3: Security Architecture and Engineering 13% of exam

Secure design principles, security models, evaluation criteria, cryptography, and physical security.

  • 3.1 Secure Design Principles 8 min πŸ”’
  • 3.2 Security Models: Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash 9 min πŸ”’
  • 3.3 Evaluation Criteria: TCSEC, ITSEC, Common Criteria 7 min πŸ”’
  • 3.4 System Components and Vulnerabilities 8 min πŸ”’
  • 3.5 Cryptography Fundamentals 8 min πŸ”’
  • 3.6 Symmetric Cryptography 8 min πŸ”’
  • 3.7 Asymmetric Cryptography and PKI 9 min πŸ”’
  • 3.8 Hashing and Digital Signatures 8 min πŸ”’
  • 3.9 Cryptographic Attacks 8 min πŸ”’
  • 3.10 Physical Security Design 8 min πŸ”’

Module 4: Communication and Network Security 13% of exam

Secure network design, protocols and services, secure channels, and network attack defense.

  • 4.1 The OSI and TCP/IP Models 8 min πŸ”’
  • 4.2 Secure Network Design and Segmentation 8 min πŸ”’
  • 4.3 IP Networking and Common Protocols 8 min πŸ”’
  • 4.4 Wireless Networking Security 7 min πŸ”’
  • 4.5 Secure Communication Channels: TLS, IPsec, VPN 9 min πŸ”’
  • 4.6 Network Attacks and Countermeasures 8 min πŸ”’
  • 4.7 Network Devices and Boundary Controls 8 min πŸ”’
  • 4.8 Content Delivery, Load Balancing, and DDoS Defense 7 min πŸ”’

Module 5: Identity and Access Management (IAM) 13% of exam

Access control principles, identification and authentication, federation, provisioning, and access review.

  • 5.1 Access Control Principles: DAC, MAC, RBAC, ABAC 8 min πŸ”’
  • 5.2 Identification and Authentication 7 min πŸ”’
  • 5.3 Multifactor Authentication 6 min πŸ”’
  • 5.4 Biometrics 6 min πŸ”’
  • 5.5 Single Sign-On and Federated Identity 7 min πŸ”’
  • 5.6 SAML, OAuth 2.0, and OpenID Connect 8 min πŸ”’
  • 5.7 Kerberos 8 min πŸ”’
  • 5.8 Identity Lifecycle: Provisioning, Review, Deprovisioning 7 min πŸ”’
  • 5.9 Privileged Access Management 7 min πŸ”’

Module 6: Security Assessment and Testing 12% of exam

Assessment strategies, vulnerability testing, penetration testing, audit, and reporting.

  • 6.1 Assessment and Testing Strategy 7 min πŸ”’
  • 6.2 Vulnerability Assessment 7 min πŸ”’
  • 6.3 Penetration Testing 8 min πŸ”’
  • 6.4 Code Review and Testing 7 min πŸ”’
  • 6.5 Log Review and Analysis 6 min πŸ”’
  • 6.6 Synthetic Transactions and Real User Monitoring 5 min πŸ”’
  • 6.7 Audit Types: Internal, External, Third-Party (SOC 1/2/3) 7 min πŸ”’
  • 6.8 Reporting and Remediation Tracking 6 min πŸ”’

Module 7: Security Operations 13% of exam

Detective and preventive operations, incident response, evidence handling, recovery, and change management.

  • 7.1 Investigations: Administrative, Criminal, Civil, Regulatory 7 min πŸ”’
  • 7.2 Evidence Handling and Chain of Custody 7 min πŸ”’
  • 7.3 Logging, Monitoring, and SIEM 6 min πŸ”’
  • 7.4 Incident Response Lifecycle 8 min πŸ”’
  • 7.5 Disaster Recovery Strategies 7 min πŸ”’
  • 7.6 Backup Strategies and Verification 6 min πŸ”’
  • 7.7 Business Continuity Plan Execution 5 min πŸ”’
  • 7.8 Change and Configuration Management 6 min πŸ”’
  • 7.9 Patch and Vulnerability Management 6 min πŸ”’
  • 7.10 Physical Security Operations 6 min πŸ”’

Module 8: Software Development Security 11% of exam

Secure SDLC, development environment security, coding standards, and application security testing.

  • 8.1 The Secure Software Development Lifecycle 7 min πŸ”’
  • 8.2 Development Methodologies: Waterfall, Agile, DevSecOps 7 min πŸ”’
  • 8.3 Maturity Models: BSIMM, SAMM 5 min πŸ”’
  • 8.4 Secure Coding Standards and Common Weaknesses 7 min πŸ”’
  • 8.5 OWASP Top 10 and Application-Layer Attacks 8 min πŸ”’
  • 8.6 Database Security and Data Warehousing 6 min πŸ”’
  • 8.7 Application Security Testing: SAST, DAST, IAST 5 min πŸ”’
  • 8.8 Software Supply Chain Security 7 min πŸ”’
  • 8.9 Assessing Acquired Software 6 min πŸ”’

Frequently asked questions about the CISSP training course

Is the CISSP training course free?

Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.

How is the course structured?

One module per official CISSP domain, in ISC2’s published order, with each module weighted to the domain’s published percentage under the April 2024 outline. Because the CISSP weights are unusually flat, the module lengths are closer together than on most certification courses, that is intentional and it mirrors the exam.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative exam outline and sells its own official training and CBK reference material. This course is an independent study companion written to be read in order alongside practice questions, not a substitute for the official outline, which you should download from isc2.org and check against your own preparation.

Do I need experience before starting the course?

You can read it at any stage, but the CISSP itself carries a five-year experience requirement, and the exam is written from the perspective of someone who has advised a business on security decisions. If you are earlier than that, the SSCP course covers the same technical ground at a practitioner’s altitude, and CC is the entry point below it.

What should I do after finishing the course?

Move to the CISSP practice exam and work until you are clearing 70% across every domain individually, not on average. Averaging over eight domains hides exactly the weakness adaptive delivery is built to find. Then book with Pearson VUE.

Is the course current with the latest CISSP outline?

The modules are built against the outline that took effect April 15, 2024, in which Security and Risk Management grew to 16%, Software Development Security trimmed to 10%, and cloud, zero trust, and supply chain thinking were woven through all eight domains rather than isolated in one. ISC2 can revise the outline at any time; download the current exam outline from isc2.org before you sit.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these study materials are intended. The CISSP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and endorsement policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.