cissp domainsEnglish8 min read

The 8 CISSP Domains Explained, With Their Exact 2024 Weightings

All 8 CISSP domains explained with their exact April 2024 weightings, from Security and Risk Management at 16 percent down. See what each covers and where to spend your study time.

Marcus Chen
Marcus Chen
July 26, 20268 min readUpdated August 16, 2026

The CISSP is built from eight domains, and since April 15, 2024 they carry updated weightings from ISC2's latest job task analysis. If you are planning your study, those weightings are the map. They tell you that Security and Risk Management is now the single heaviest domain at 16 percent, and that the "mile wide, inch deep" reputation is literally true: eight domains, none more than 16 percent, all of them fair game.

This is every domain, its exact 2024 weight, what it actually covers, and how to read the weights as a study budget. It is written to the current outline effective April 15, 2024, not the pre-2024 percentages that older guides still list.

Quick takeaways

  • There are eight CISSP domains. As of the April 15, 2024 outline, Security and Risk Management is the heaviest at 16 percent; the rest range from 10 to 13 percent.
  • The 2024 refresh was small: Domain 1 rose from 15 to 16 percent and Domain 8 fell from 11 to 10 percent. Everything else held. If a guide shows 15 and 11, it is pre-2024.
  • The exam is deliberately broad and shallow, which is why cross-domain understanding beats deep expertise in any one area.
  • The CISSP rewards the manager's answer, not the technician's, across every domain. That framing matters as much as the content.
  • PrepClubs' CISSP track spreads original scenario questions across all eight domains, weighted to the 2024 outline, so your practice mirrors the real exam balance.
  • PrepClubs is independent prep material and is not affiliated with or endorsed by ISC2.

The 8 domains and their 2024 weightings

Here is the full picture, per the ISC2 exam outline effective April 15, 2024.

# CISSP domain 2024 weight
1 Security and Risk Management 16%
2 Asset Security 10%
3 Security Architecture and Engineering 13%
4 Communication and Network Security 13%
5 Identity and Access Management (IAM) 13%
6 Security Assessment and Testing 12%
7 Security Operations 13%
8 Software Development Security 10%

Read that spread carefully. The gap between the biggest domain (16 percent) and the smallest (10 percent) is only six points. No single domain dominates. This is the mathematical proof of the "mile wide, inch deep" saying: you cannot pass by being excellent at two domains and ignoring the others, because even the largest is only about a sixth of the exam.

Bar chart of the 8 CISSP domains with their 2024 weightings, Security and Risk Management at 16 percent as the largest

What changed in the 2024 refresh

ISC2 runs a job task analysis roughly every three years and adjusts the outline to match what security professionals actually do. The April 15, 2024 update was minor by design:

  • Domain 1, Security and Risk Management: 15% to 16%.
  • Domain 8, Software Development Security: 11% to 10%.
  • All six other domains: unchanged.

The practical rule for spotting stale material: if a study guide lists Domain 1 at 15 percent and Domain 8 at 11 percent, it predates the 2024 refresh. The content is largely the same, but the weightings, and therefore the study budget, are slightly off. Use the 2024 numbers above.

Domain by domain: what each one covers

Domain 1: Security and Risk Management (16%)

The heaviest domain, and the foundation the others build on. Security governance principles, compliance and legal issues, professional ethics, security policies and standards, risk management concepts (identification, assessment, response), threat modeling, business continuity, and security awareness. Many candidates study this first precisely because it frames the risk-based thinking the whole exam rewards.

Domain 2: Asset Security (10%)

Protecting information and assets across their lifecycle. Data classification and handling, ownership and roles, data retention and destruction, and the controls that protect data at each stage. Smaller in weight, but it underpins the reasoning in several other domains.

Domain 3: Security Architecture and Engineering (13%)

The design and engineering layer. Secure design principles, security models, cryptography (this is where the heaviest crypto content lives), physical security, and the security capabilities of information systems. Many candidates rate this the hardest domain because of the cryptography and the abstract models.

Domain 4: Communication and Network Security (13%)

Securing the network. Secure network architecture and design, secure communication channels, network components, and the security of protocols. If you come from a networking background, this domain plays to your strengths.

Domain 5: Identity and Access Management, IAM (13%)

Controlling who gets access to what. Identification, authentication, and authorization, identity lifecycle, access control models (RBAC, ABAC, and others), and federated identity. A conceptually clean domain that rewards precise definitions.

Domain 6: Security Assessment and Testing (12%)

Verifying that controls work. Assessment and test strategies, security control testing, collecting security process data, analyzing test output, and audits (internal, external, third-party). This domain is about proving security, not building it.

Domain 7: Security Operations (13%)

Running security day to day. Investigations, logging and monitoring, incident management, detective and preventive measures, patch and vulnerability management, and disaster recovery. It overlaps with the operational realities of a working security team.

Domain 8: Software Development Security (10%)

Building security into software. The security implications of the development lifecycle, secure coding practices, assessing software security, and the risks of acquired software. Tied with Asset Security as the smallest domain at 10 percent.

How to read the weights as a study budget

Because no domain dominates, your study time should be spread, but not evenly. Overlay the weights on your available hours. If you have 40 hours of focused study left:

Domain Weight Hours (of 40)
1 Security and Risk Management 16% About 6.5
3, 4, 5, 7 (each 13%) 13% each About 5 each
6 Security Assessment and Testing 12% About 5
2, 8 (each 10%) 10% each About 4 each

Two study principles fall out of this. First, give Domain 1 the most time, because it is heaviest and because its risk-based logic informs how you answer questions in every other domain. Second, do not skip your weak domains just because they are small; a 10-percent domain you ignore is a chunk of guaranteed lost marks on an exam where the margin is thin.

FAQ

What are the 8 CISSP domains?

Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security, per the ISC2 exam outline.

Which CISSP domain is the most important?

By weight, Security and Risk Management at 16 percent (the 2024 outline). It is also foundational, because the risk-based reasoning it teaches shapes the correct answer across every other domain.

Which CISSP domain is the hardest?

Most candidates name Domain 3, Security Architecture and Engineering, because it carries the heaviest cryptography and the most abstract security models. Difficulty is personal, though; your diagnostic will tell you which domains are hardest for you specifically.

What changed in the 2024 CISSP domains?

Domain 1 rose from 15 to 16 percent and Domain 8 fell from 11 to 10 percent, effective April 15, 2024. All other domain weights stayed the same. The domain names and count did not change.

Do I need to master all 8 domains?

Yes. The exam is deliberately broad, and no domain is more than 16 percent, so you cannot pass by concentrating on a few. Consistent competence across all eight is the reliable path.

Are these the current CISSP domain weightings?

Yes. These are the weightings from the ISC2 outline effective April 15, 2024, current as of 2026. Confirm the latest figures on ISC2's own certification site before your exam, since ISC2 refreshes the outline on a roughly triennial cycle.

Practice across all eight, weighted like the real exam

Knowing the eight domains and their 2024 weights is the map. Practicing across all of them, in the right proportion, is the journey. That is how PrepClubs' CISSP track is built: original, scenario-level questions spread across all eight domains and weighted to the 2024 outline, each with a written rationale that teaches the manager-minded reasoning the exam rewards, plus a free diagnostic to find your weak domains first. It is a one-time purchase with 30 days of access, not a subscription you rent by the year. If you prepare with PrepClubs and do not pass your real test, we extend your access at no extra cost. No fine print. PrepClubs has helped more than 1,600 students prepare for cognitive and certification assessments. Start with the free CISSP diagnostic.

FAQ

Common questions

What are the 8 CISSP domains?

Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Software Development Security, per the ISC2 exam outline.

Which CISSP domain is the most important?

By weight, Security and Risk Management at 16 percent (the 2024 outline). It is also foundational, because the risk-based reasoning it teaches shapes the correct answer across every other domain.

Which CISSP domain is the hardest?

Most candidates name Domain 3, Security Architecture and Engineering, because it carries the heaviest cryptography and the most abstract security models. Difficulty is personal, though; your diagnostic will tell you which domains are hardest for you specifically.

What changed in the 2024 CISSP domains?

Domain 1 rose from 15 to 16 percent and Domain 8 fell from 11 to 10 percent, effective April 15, 2024. All other domain weights stayed the same. The domain names and count did not change.

Do I need to master all 8 domains?

Yes. The exam is deliberately broad, and no domain is more than 16 percent, so you cannot pass by concentrating on a few. Consistent competence across all eight is the reliable path.

Are these the current CISSP domain weightings?

Yes. These are the weightings from the ISC2 outline effective April 15, 2024, current as of 2026. Confirm the latest figures on ISC2's own certification site before your exam, since ISC2 refreshes the outline on a roughly triennial cycle.