The CISSP (Certified Information Systems Security Professional) certification covers 8 security domains from the (ISC)² Common Body of Knowledge (CBK):
- Security and Risk Management
- Security concepts and principles
- Risk management
- Governance and compliance
- Policies, standards, and ethics
- Business continuity and disaster recovery
- Asset Security
- Data classification and ownership
- Data privacy
- Data protection
- Retention and destruction
- Handling sensitive information
- Security Architecture and Engineering
- Secure design principles
- Security models
- Cryptography
- Physical security
- Vulnerability management
- Communication and Network Security
- Network architecture
- Secure communication channels
- Network protocols
- Wireless security
- Network attacks and defenses
- Identity and Access Management (IAM)
- Identification and authentication
- Authorization
- Access control models
- Identity lifecycle management
- Privileged access management
- Security Assessment and Testing
- Security testing methods
- Vulnerability assessments
- Penetration testing
- Auditing
- Security monitoring
- Security Operations
- Incident response
- Logging and monitoring
- Digital forensics
- Disaster recovery operations
- Secure operations practices
- Software Development Security
- Secure software development lifecycle (SDLC)
- Secure coding practices
- Software vulnerabilities
- Application security testing
- DevSecOps concepts
A common way to remember them:
“Risk, Assets, Architecture, Network, Identity, Testing, Operations, Software”.