Certified Information Systems Security Professional (CISSP)
Certified Information Systems Security Professional (CISSP)
Certified Information Systems Security Professional (CISSP)
Length of exam
3 hours
Number of items
100 - 150
Item format
Multiple choice and advanced innovative items
Passing grade
700 out of 1000 points
Exam language
English
availability Testing center
(ISC)2 Authorized PPC and PVTC Select Pearson VUE
Testing Centers
1.5 Understand legal and regulatory issues that pertain to information security
in a holistic context
» Cybercrimes and data breaches » Import/export controls
» Licensing and Intellectual Property » Transborder data flow
(IP) requirements
2.5 Ensure appropriate asset retention (e.g., End-of-Life (EOL), End-of-Support (EOS))
3.4 Understand security capabilities of Information Systems (IS) (e.g., memory protection,
Trusted Platform Module (TPM), encryption/decryption)
3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution
elements
» Wiring closets/intermediate distribution facilities » Utilities and Heating, Ventilation, and Air
» Server rooms/data centers Conditioning (HVAC)
» Media storage facilities » Environmental issues
» Evidence storage » Fire prevention, detection, and suppression
» Restricted and work area security » Power (e.g., redundant, backup)
» Internal
» External
» Third-party
» Media management
» Media protection techniques
» Detection
» Response » Recovery
» Mitigation » Remediation
» Response » Restoration
» Personnel » Training and awareness
» Communications » Lessons learned
» Assessment
» Read-through/tabletop
» Parallel
» Walkthrough
» Full interruption
» Simulation
8.1 Understand and integrate security in the Software Development Life Cycle (SDLC)
» Development methodologies (e.g., Agile, Waterfall, DevOps, DevSecOps)
» Maturity models (e.g., Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM))
» Operation and maintenance
» Change management
» Integrated Product Team (IPT)
Legal Info
For any questions related to (ISC)²’s legal policies, please contact the (ISC)2
Legal Department at legal@isc2.org.
Any Questions?
(ISC)² Candidate Services
311 Park Place Blvd, Suite 400
Clearwater, FL 33759
(ISC)² Americas
Tel: +1.866.331.ISC2 (4722)
Email: info@isc2.org
(ISC)² EMEA
Tel: +44 (0)203 300 1625
Email: info-emea@isc2.org
v8/2020 16