Certified Information Systems Security Professional (CISSP)
When to Use
- Structure CISSP/CBK study — domain map, manager mindset, practice workflow (no copyrighted items)
- Design security programs using CBK domains — policies, standards, procedures, ownership
- Frame risk management — threats, vulnerabilities, impact, treatment, residual risk
- Select and justify controls — administrative, technical, physical; defense in depth
- Support audit and assessment narratives — scope, sampling, findings, management responses
- Align work to NIST CSF / ISO 27001 concepts at program level (not control-by-control automation)
- Explain IAM, network security, crypto, and SDLC at architecture and governance depth
- Translate CBK topics to organizational roles — what leaders decide vs technicians execute
When NOT to Use
- SOC alert triage, shift handoffs, or playbook execution →
soc-analyst
- Declared incident command, containment, forensics →
incident-responder
- Execute penetration tests or exploit chains →
penetration-tester
- Cloud-only attestations, CSPM evidence, residency packages →
cloud-compliance-specialist
- Board-only strategy, appetite, crisis comms without CBK/program lens →
chief-information-security-officer
- Deploy SIEM rules, hardening, IAM/terraform, EDR →
information-security-engineer
- GRC program scope, gap assessments, audit prep packs →
compliance-specialist
- Evidence automation from IdP/CI/CD/CSPM →
compliance-engineer
- Enterprise reference architecture and zero-trust standards →
enterprise-security-architect
- Risk registers, FAIR scoring, treatment matrices →
security-risk-analyst
- Broad security strategy without CBK or certification framing →
cybersecurity
- Legal interpretation, contracts, or regulatory filings → legal counsel
Related skills
| Need |
Skill |
| Executive program, board, appetite, crisis |
chief-information-security-officer |
| Control deployment, SIEM/EDR, hardening |
information-security-engineer |
| Reference architecture, zero trust, ARB |
enterprise-security-architect |
| GRC program, frameworks, audit coordination |
compliance-specialist |
| Control testing, evidence automation |
compliance-engineer |
| Risk registers, inherent/residual, treatment |
security-risk-analyst |
| Enterprise security strategy (non-CBK depth) |
cybersecurity |
Core Workflows
1. Scope and CBK orientation
Clarify whether the ask is exam prep, program design, audit narrative, or control selection. Map the topic to CBK domains and the manager vs technician boundary.
See references/cissp_scope_and_cbk_overview.md.
2. Security and risk management (Domain 1)
Governance, policies, risk treatment, BCP/DRP themes, legal/regulatory concepts at program level, and security awareness.
See references/security_and_risk_management.md.
3. Asset security and architecture (Domains 2–3)
Data classification, handling, retention; secure design principles, models, and evaluation criteria.
See references/asset_security_and_architecture.md.
4. Network, IAM, and assessment (Domains 4–6)
Secure communications, identity lifecycle, access models, and assessment types (audit, test, evaluate).
See references/network_iam_and_assessment.md.
5. Security operations and SDLC (Domains 7–8)
Monitoring, IR program elements, DR operations; secure SDLC, supply chain, and software assurance.
See references/security_operations_and_sdlc.md.
6. Apply CBK to organizational practice
Policies, NIST/ISO alignment, governance cadence, study workflow, and handoffs to specialist skills.
See references/applying_cissp_to_programs.md.
Outputs
- Domain study map — topic checklist per CBK domain with weak-area focus
- Program alignment brief — how initiatives map to domains and control families
- Policy/governance outline — hierarchy (policy → standard → procedure), owners, review cadence
- Risk and control narrative — threat, control objective, implementation type, residual risk
- Audit support memo — scope, population, sampling approach, finding severity framing
- Role handoff table — CISSP-level decision vs engineering/GRC/IR execution owners
Principles
- Manager mindset — breadth across domains; delegate depth to specialists
- Defense in depth — layer administrative, technical, and physical controls
- Risk-based prioritization — tie controls and spend to likelihood and impact
- No exam brain dumps — teach concepts and structure; do not reproduce copyrighted items
- Complement, not replace — use CISO/GRC/engineering skills for their execution lanes
When to load references
- CBK domains and exam context →
references/cissp_scope_and_cbk_overview.md
- Domain 1 →
references/security_and_risk_management.md
- Domains 2–3 →
references/asset_security_and_architecture.md
- Domains 4–6 →
references/network_iam_and_assessment.md
- Domains 7–8 →
references/security_operations_and_sdlc.md
- Programs, frameworks, study workflow →
references/applying_cissp_to_programs.md
1---2name: certified-information-systems-security-professional3description: Guides security leadership aligned with the (ISC)² CISSP CBK—eight domains: Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; IAM; Security Assessment and Testing; Security Operations; Software Development Security. Use for CISSP/CBK exam prep structure (no brain dumps), program design, policy and governance, risk and control selection, audit narratives, and translating CBK to practice. Triggers: CISSP, cissp, CBK, (ISC)², security domains, study plan, security governance, defense in depth. NOT SOC triage (soc-analyst), incident command (incident-responder), pentest (penetration-tester), cloud-only compliance (cloud-compliance-specialist), board strategy without CBK (chief-information-security-officer), control implementation (information-security-engineer), legal advice.4---56# Certified Information Systems Security Professional (CISSP)78## When to Use910- Structure **CISSP/CBK study** — domain map, manager mindset, practice workflow (no copyrighted items)11- Design **security programs** using CBK domains — policies, standards, procedures, ownership12- Frame **risk management** — threats, vulnerabilities, impact, treatment, residual risk13- Select and justify **controls** — administrative, technical, physical; defense in depth14- Support **audit and assessment** narratives — scope, sampling, findings, management responses15- Align work to **NIST CSF / ISO 27001** concepts at program level (not control-by-control automation)16- Explain **IAM, network security, crypto, and SDLC** at architecture and governance depth17- Translate CBK topics to **organizational roles** — what leaders decide vs technicians execute1819## When NOT to Use2021- SOC alert triage, shift handoffs, or playbook execution → `soc-analyst`22- Declared incident command, containment, forensics → `incident-responder`23- Execute penetration tests or exploit chains → `penetration-tester`24- Cloud-only attestations, CSPM evidence, residency packages → `cloud-compliance-specialist`25- Board-only strategy, appetite, crisis comms without CBK/program lens → `chief-information-security-officer`26- Deploy SIEM rules, hardening, IAM/terraform, EDR → `information-security-engineer`27- GRC program scope, gap assessments, audit prep packs → `compliance-specialist`28- Evidence automation from IdP/CI/CD/CSPM → `compliance-engineer`29- Enterprise reference architecture and zero-trust standards → `enterprise-security-architect`30- Risk registers, FAIR scoring, treatment matrices → `security-risk-analyst`31- Broad security strategy without CBK or certification framing → `cybersecurity`32- Legal interpretation, contracts, or regulatory filings → legal counsel3334## Related skills3536| Need | Skill |37|---|---|38| Executive program, board, appetite, crisis | `chief-information-security-officer` |39| Control deployment, SIEM/EDR, hardening | `information-security-engineer` |40| Reference architecture, zero trust, ARB | `enterprise-security-architect` |41| GRC program, frameworks, audit coordination | `compliance-specialist` |42| Control testing, evidence automation | `compliance-engineer` |43| Risk registers, inherent/residual, treatment | `security-risk-analyst` |44| Enterprise security strategy (non-CBK depth) | `cybersecurity` |4546## Core Workflows4748### 1. Scope and CBK orientation4950Clarify whether the ask is exam prep, program design, audit narrative, or control selection. Map the topic to CBK domains and the manager vs technician boundary.5152**See `references/cissp_scope_and_cbk_overview.md`.**5354### 2. Security and risk management (Domain 1)5556Governance, policies, risk treatment, BCP/DRP themes, legal/regulatory concepts at program level, and security awareness.5758**See `references/security_and_risk_management.md`.**5960### 3. Asset security and architecture (Domains 2–3)6162Data classification, handling, retention; secure design principles, models, and evaluation criteria.6364**See `references/asset_security_and_architecture.md`.**6566### 4. Network, IAM, and assessment (Domains 4–6)6768Secure communications, identity lifecycle, access models, and assessment types (audit, test, evaluate).6970**See `references/network_iam_and_assessment.md`.**7172### 5. Security operations and SDLC (Domains 7–8)7374Monitoring, IR program elements, DR operations; secure SDLC, supply chain, and software assurance.7576**See `references/security_operations_and_sdlc.md`.**7778### 6. Apply CBK to organizational practice7980Policies, NIST/ISO alignment, governance cadence, study workflow, and handoffs to specialist skills.8182**See `references/applying_cissp_to_programs.md`.**8384## Outputs8586- **Domain study map** — topic checklist per CBK domain with weak-area focus87- **Program alignment brief** — how initiatives map to domains and control families88- **Policy/governance outline** — hierarchy (policy → standard → procedure), owners, review cadence89- **Risk and control narrative** — threat, control objective, implementation type, residual risk90- **Audit support memo** — scope, population, sampling approach, finding severity framing91- **Role handoff table** — CISSP-level decision vs engineering/GRC/IR execution owners9293## Principles9495- **Manager mindset** — breadth across domains; delegate depth to specialists96- **Defense in depth** — layer administrative, technical, and physical controls97- **Risk-based prioritization** — tie controls and spend to likelihood and impact98- **No exam brain dumps** — teach concepts and structure; do not reproduce copyrighted items99- **Complement, not replace** — use CISO/GRC/engineering skills for their execution lanes100101## When to load references102103- **CBK domains and exam context** → `references/cissp_scope_and_cbk_overview.md`104- **Domain 1** → `references/security_and_risk_management.md`105- **Domains 2–3** → `references/asset_security_and_architecture.md`106- **Domains 4–6** → `references/network_iam_and_assessment.md`107- **Domains 7–8** → `references/security_operations_and_sdlc.md`108- **Programs, frameworks, study workflow** → `references/applying_cissp_to_programs.md`