ISC2 · IT Certification

CISSP (Certified Information Systems Security Professional) study plan

Use this 16-week roadmap to focus on the exam domains that matter most, choose a strong core course, and turn your prep into a weekly plan.

Use the free PrepPath planner

CISSP (Certified Information Systems Security Professional) rewards consistent, blueprint-led practice. Start by learning the highest-weighted domains, then use practice results to rebalance your time before exam day.

How long to study

Plan on about 16 weeks

A 16-week CISSP (Certified Information Systems Security Professional) study plan gives most learners enough room for first-pass learning, targeted review, and at least one full practice pass. If you are already strong in the fundamentals, compress the early lessons and reserve the final weeks for weak domains and timed practice.

Blueprint breakdown

Study by domain weight

Domain Weight
Security and Risk Management
16%
Asset Security
10%
Security Architecture and Engineering
13%
Communication and Network Security
13%
Identity and Access Management (IAM)
13%
Security Assessment and Testing
12%
Security Operations
13%
Software Development Security
10%

What's on the exam

CISSP (Certified Information Systems Security Professional) domains explained

Security and Risk Management — 16%

Covers governance, compliance, ethics, risk management, threat modeling, business continuity, and personnel security.

Asset Security — 10%

Covers information and asset classification, ownership, privacy, retention, data states, and secure handling requirements.

Security Architecture and Engineering — 13%

Covers secure architecture models, cryptography, physical security, system design, vulnerabilities, and engineering controls.

Communication and Network Security — 13%

Covers secure network architecture, transmission methods, network components, secure channels, and communication protection.

Identity and Access Management (IAM) — 13%

Covers identity lifecycle, authentication, authorization, access control attacks, federation, and identity as a service.

Security Assessment and Testing — 12%

Covers security control testing, audits, vulnerability assessment, penetration testing, log review, and test-result reporting.

Security Operations — 13%

Covers investigations, logging, incident response, disaster recovery, resource protection, monitoring, and operational resilience.

Software Development Security — 10%

Covers secure SDLC, development methods, software security testing, code repositories, APIs, and software supply-chain risk.

Suggested timeline

A 16-week CISSP (Certified Information Systems Security Professional) plan, phase by phase

This is a blueprint-led default — front-load the heaviest domains, then convert weak spots from your mock results into targeted review. The free planner turns it into exact dates.

WhenFocus
Weeks 1–7
Foundations
Security and Risk Management, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM)
First-pass learning on the heaviest-weighted domains: read the guide, watch the core course, and start active-recall questions.
Weeks 8–13
Breadth
Security Operations, Security Assessment and Testing, Asset Security, Software Development Security
Cover the remaining domains and sit your first full, timed mock to expose weak areas.
Weeks 14–16
Review & mocks
Weakest domains + full mocks
Re-test with timed mocks, drill the domains your scores flag, then a light rest-and-logistics day before the exam.

Recommended prep kit

Guide, course, practice, and gear

FTC affiliate disclosure: this recommendation may contain a sponsored affiliate link. PrepPath may earn a commission at no extra cost to you.

Study guide

ISC2 CISSP Official Study Guide, 10th Edition (Sybex)

View on Amazon

FTC affiliate disclosure: this recommendation may contain a sponsored affiliate link. PrepPath may earn a commission at no extra cost to you.

Course

CISSP Certification Complete Course — All Domains

Open udemy resource

FTC affiliate disclosure: this recommendation may contain a sponsored affiliate link. PrepPath may earn a commission at no extra cost to you.

Practice exams

ISC2 CISSP Official Practice Tests, 4th Edition

View on Amazon

FTC affiliate disclosure: this recommendation may contain a sponsored affiliate link. PrepPath may earn a commission at no extra cost to you.

Gear

1080p webcam for Pearson VUE OnVUE online proctoring

View on Amazon

Free PrepPath planner

Turn this page into your calendar

Enter your exam date and weak domains, then PrepPath generates the day-by-day schedule.

Download or use PrepPath free

FAQ

CISSP (Certified Information Systems Security Professional) study plan questions

How long should I study for CISSP (Certified Information Systems Security Professional)?

A typical CISSP (Certified Information Systems Security Professional) study plan takes about 16 weeks. Shorten that if you already score well on practice tests, or extend it if the official objectives are new to you.

What is the best course for CISSP (Certified Information Systems Security Professional)?

The best course for CISSP (Certified Information Systems Security Professional) is one that maps lessons to the current exam domains and includes practice questions. This page recommends CISSP Certification Complete Course — All Domains as the core course to review first.

Which CISSP (Certified Information Systems Security Professional) domain should I study first?

Start with Security and Risk Management, because it carries about 16% of the exam blueprint, then move through lower-weight domains while tracking weak areas.

How does the free PrepPath planner help?

PrepPath turns your exam date, daily study hours, and confidence by domain into a calendar you can follow, then adjusts your focus after practice scores.

How many hours a day should I study for CISSP (Certified Information Systems Security Professional)?

Most candidates do well with about 1–2 focused hours on study days across a 16-week plan, ramping up in the final weeks for timed practice. Consistency beats marathon sessions — PrepPath spaces each domain out so you revisit it instead of cramming.

How many practice tests should I take before CISSP (Certified Information Systems Security Professional)?

Aim for at least 2–3 full, timed mock exams: one early to set a baseline, then more in the final third of your plan. Review every wrong answer and tag the domain it came from so PrepPath can rebalance your remaining days toward your real weak spots.