# Certified Information Systems Security Professional

> Guides security leadership aligned with the (ISC)² CISSP CBK—eight domains: Security and Risk Management; Asset Security; Security Architecture and Engineering; Communication and Network Security; IAM; Security Assessment and Testing; Security Operations; Software Development Security. Use for CISSP/CBK exam prep structure (no brain dumps), program design, policy and governance, risk and control selection, audit narratives, and translating CBK to practice. Triggers: CISSP, cissp, CBK, (ISC)², security domains, study plan, security governance, defense in depth. NOT SOC triage (soc-analyst), incident command (incident-responder), pentest (penetration-tester), cloud-only compliance (cloud-compliance-specialist), board strategy without CBK (chief-information-security-officer), control implementation (information-security-engineer), legal advice.

- Skill: `daemon-blockint-tech/certified-information-systems-security-professional` (Agent Skill, multi-file: 7 files)
- Install (CLI): `npx skillmds@latest add daemon-blockint-tech/certified-information-systems-security-professional`
- Raw SKILL.md: https://api.skillmd.com/api/skills/daemon-blockint-tech/certified-information-systems-security-professional/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: DevOps & Infra
- Author: daemon-blockint-tech (https://skillmd.com/u/daemon-blockint-tech)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/daemon-blockint-tech/certified-information-systems-security-professional

---


# Certified Information Systems Security Professional (CISSP)

## When to Use

- Structure **CISSP/CBK study** — domain map, manager mindset, practice workflow (no copyrighted items)
- Design **security programs** using CBK domains — policies, standards, procedures, ownership
- Frame **risk management** — threats, vulnerabilities, impact, treatment, residual risk
- Select and justify **controls** — administrative, technical, physical; defense in depth
- Support **audit and assessment** narratives — scope, sampling, findings, management responses
- Align work to **NIST CSF / ISO 27001** concepts at program level (not control-by-control automation)
- Explain **IAM, network security, crypto, and SDLC** at architecture and governance depth
- Translate CBK topics to **organizational roles** — what leaders decide vs technicians execute

## When NOT to Use

- SOC alert triage, shift handoffs, or playbook execution → `soc-analyst`
- Declared incident command, containment, forensics → `incident-responder`
- Execute penetration tests or exploit chains → `penetration-tester`
- Cloud-only attestations, CSPM evidence, residency packages → `cloud-compliance-specialist`
- Board-only strategy, appetite, crisis comms without CBK/program lens → `chief-information-security-officer`
- Deploy SIEM rules, hardening, IAM/terraform, EDR → `information-security-engineer`
- GRC program scope, gap assessments, audit prep packs → `compliance-specialist`
- Evidence automation from IdP/CI/CD/CSPM → `compliance-engineer`
- Enterprise reference architecture and zero-trust standards → `enterprise-security-architect`
- Risk registers, FAIR scoring, treatment matrices → `security-risk-analyst`
- Broad security strategy without CBK or certification framing → `cybersecurity`
- Legal interpretation, contracts, or regulatory filings → legal counsel

## Related skills

| Need | Skill |
|---|---|
| Executive program, board, appetite, crisis | `chief-information-security-officer` |
| Control deployment, SIEM/EDR, hardening | `information-security-engineer` |
| Reference architecture, zero trust, ARB | `enterprise-security-architect` |
| GRC program, frameworks, audit coordination | `compliance-specialist` |
| Control testing, evidence automation | `compliance-engineer` |
| Risk registers, inherent/residual, treatment | `security-risk-analyst` |
| Enterprise security strategy (non-CBK depth) | `cybersecurity` |

## Core Workflows

### 1. Scope and CBK orientation

Clarify whether the ask is exam prep, program design, audit narrative, or control selection. Map the topic to CBK domains and the manager vs technician boundary.

**See `references/cissp_scope_and_cbk_overview.md`.**

### 2. Security and risk management (Domain 1)

Governance, policies, risk treatment, BCP/DRP themes, legal/regulatory concepts at program level, and security awareness.

**See `references/security_and_risk_management.md`.**

### 3. Asset security and architecture (Domains 2–3)

Data classification, handling, retention; secure design principles, models, and evaluation criteria.

**See `references/asset_security_and_architecture.md`.**

### 4. Network, IAM, and assessment (Domains 4–6)

Secure communications, identity lifecycle, access models, and assessment types (audit, test, evaluate).

**See `references/network_iam_and_assessment.md`.**

### 5. Security operations and SDLC (Domains 7–8)

Monitoring, IR program elements, DR operations; secure SDLC, supply chain, and software assurance.

**See `references/security_operations_and_sdlc.md`.**

### 6. Apply CBK to organizational practice

Policies, NIST/ISO alignment, governance cadence, study workflow, and handoffs to specialist skills.

**See `references/applying_cissp_to_programs.md`.**

## Outputs

- **Domain study map** — topic checklist per CBK domain with weak-area focus
- **Program alignment brief** — how initiatives map to domains and control families
- **Policy/governance outline** — hierarchy (policy → standard → procedure), owners, review cadence
- **Risk and control narrative** — threat, control objective, implementation type, residual risk
- **Audit support memo** — scope, population, sampling approach, finding severity framing
- **Role handoff table** — CISSP-level decision vs engineering/GRC/IR execution owners

## Principles

- **Manager mindset** — breadth across domains; delegate depth to specialists
- **Defense in depth** — layer administrative, technical, and physical controls
- **Risk-based prioritization** — tie controls and spend to likelihood and impact
- **No exam brain dumps** — teach concepts and structure; do not reproduce copyrighted items
- **Complement, not replace** — use CISO/GRC/engineering skills for their execution lanes

## When to load references

- **CBK domains and exam context** → `references/cissp_scope_and_cbk_overview.md`
- **Domain 1** → `references/security_and_risk_management.md`
- **Domains 2–3** → `references/asset_security_and_architecture.md`
- **Domains 4–6** → `references/network_iam_and_assessment.md`
- **Domains 7–8** → `references/security_operations_and_sdlc.md`
- **Programs, frameworks, study workflow** → `references/applying_cissp_to_programs.md`

