Last updated:
CISSP domain
What are the eight CISSP domains and their current weights?
Direct answer
The CISSP outline contains eight weighted domains spanning risk, assets, architecture, networks, identity, assessment, operations, and software development; together their weights total 100 percent. Use domain weights for coverage planning, not to estimate a fixed live item count in an adaptive exam. First, compare your baseline evidence with all eight current domains and their official objectives, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
the eight CISSP domains: a practical decision framework
| Check | How to use it |
|---|---|
| Objective | Use domain weights for coverage planning, not to estimate a fixed live item count in an adaptive exam. |
| First move | compare your baseline evidence with all eight current domains and their official objectives |
| Common trap | Studying only the largest domain, ignoring cross-domain decisions, or converting weights into guaranteed question counts. |
the eight CISSP domains in practice
A candidate spends half of all study time on Domain 1 because it has the largest weight and barely revisits Domains 2 and 8 after one strong quiz.
Weights guide coverage but do not justify neglect. Preserve broad competence and direct extra time toward evidence-backed weaknesses and cross-domain errors.
What matters most for the eight CISSP domains
Use domain weights for coverage planning, not to estimate a fixed live item count in an adaptive exam.
The CISSP outline contains eight weighted domains spanning risk, assets, architecture, networks, identity, assessment, operations, and software development; together their weights total 100 percent. The useful question is not whether an isolated fact looks familiar, but whether you can apply it under the actor, authority, objective, qualifier, and constraints in the scenario.
How to work on the eight CISSP domains
compare your baseline evidence with all eight current domains and their official objectives
Study the eight CISSP domains from the current official objectives, then test the concepts through changed actors and cross-domain scenarios. Review each miss by error type so familiar terminology does not hide weak application.
- Name the actor and the authority that actor holds.
- Underline the qualifier and the required business or security outcome.
- Check sequence, scope, constraints, and residual risk before choosing.
The mistake that distorts the eight CISSP domains
Studying only the largest domain, ignoring cross-domain decisions, or converting weights into guaranteed question counts.
This error can survive repeated question practice when review stops at the correct letter. Rework the item until you can state the transferable rule without quoting the stem.
How to test transfer in the eight CISSP domains
Weights guide coverage but do not justify neglect. Preserve broad competence and direct extra time toward evidence-backed weaknesses and cross-domain errors.
Retest the eight CISSP domains with a changed actor, qualifier, constraint, or domain context. Keep the result only when the same reasoning survives unfamiliar wording and you can explain what evidence would make another option stronger.
- Use an unfamiliar scenario rather than a repeated item.
- Record confidence before opening the explanation.
- Name the evidence that would reverse the decision.
Sources and fact check
Source checked: 2026-08-24
- CertArc is an independent exam-preparation platform and is not affiliated with or endorsed by ISC2.
- CertArc uses original practice questions, not live or recalled exam items, and does not reproduce the CISSP CAT algorithm.
- Practice performance is study evidence, not a pass prediction or guarantee.
Frequently asked questions
What are the eight CISSP domains and their current weights?
The CISSP outline contains eight weighted domains spanning risk, assets, architecture, networks, identity, assessment, operations, and software development; together their weights total 100 percent. Use domain weights for coverage planning, not to estimate a fixed live item count in an adaptive exam. First, compare your baseline evidence with all eight current domains and their official objectives, then verify the decision on unfamiliar scenarios and explain why the strongest distractor loses.
What should I study first in the eight CISSP domains?
Compare your baseline evidence with all eight current domains and their official objectives Use the current official objectives as the coverage boundary and practice changed scenarios after learning the concepts.
How does the eight CISSP domains connect to other CISSP domains?
Use domain weights for coverage planning, not to estimate a fixed live item count in an adaptive exam. Cross-domain questions often connect governance, assets, architecture, identity, assessment, operations, and software decisions.
What is a common the eight CISSP domains study error?
Studying only the largest domain, ignoring cross-domain decisions, or converting weights into guaranteed question counts. Review the miss by concept and decision error instead of rereading the entire domain.
How do I know the eight CISSP domains is improving?
Look for stable performance on unfamiliar items, better confidence calibration, clearer option elimination, and fewer repeated error types. A single percentage is insufficient.