CISSP — Certified Information Systems Security Professional
This roadmap prepares you for the (ISC)2 CISSP exam by teaching the eight CBK domains in a deliberately non-linear sequence: it opens with the Domain 1 conceptual spine (risk, governance, the CIA triad) that every other domain leans on, then bridges through Identity & Access Management, Network Security, and Security Operations — the domains where hands-on infrastructure and incident-response experience converts fastest into CBK vocabulary — before closing with Security Architecture/Cryptography and Secure Software Development, the two domains a hands-on practitioner is least likely to have absorbed by osmosis. Every lesson ends by contrasting the CISSP 'best answer for the organization' mindset against the instinctive 'technician who fixes it' reflex, because that reframe — not raw technical knowledge — is what the exam actually tests. Exam preparation only — CISSP certification is issued exclusively by (ISC)2, never by VigilForge.
📋 Lessons by Domain (20 total — click a domain, no need to scroll through all of them)
Security & Risk Management
16% of exam 4 lessonsThe vocabulary every other CISSP domain assumes you already have: confidentiality/integrity/availability precisely defined, the policy-standard-procedure-guideline hierarchy, due care vs due diligence, and the manager-vs-technician reflex the whole exam is built around.
How CISSP actually measures risk in dollars: single loss expectancy, annualized rate of occurrence, annualized loss expectancy — and why the manager answer sometimes rejects a safeguard that would work perfectly.
The vocabulary behind 'no read up, no write down' and its mirror image: Bell-LaPadula for confidentiality, Biba for integrity, and Clark-Wilson's process-based alternative — enough to answer D1/D5 policy questions before the full D3 architecture treatment.
The exam's legal vocabulary is GDPR/US-anchored, not DGSSI/Loi 09-08 — this lesson gives the specific framework the exam actually tests: GDPR breach notification, contract/liability basics, and the four IP protection types, each precisely distinguished from the others.
Asset Security
10% of exam 2 lessonsWho classifies data and who protects it are different people with different jobs — data owner vs custodian vs steward, the full data lifecycle, and the NIST Clear/Purge/Destroy framework for choosing the right media sanitization method.
Privacy by design as an architectural stance, not a policy afterthought; why 'keep everything forever, just in case' is a liability rather than a safety net; and why a vendor's security posture is the client organization's risk regardless of whose staff caused the breach.
Security Architecture & Engineering
13% of exam 3 lessonsThe first real cold-start gap: why symmetric and asymmetric encryption solve different problems and are usually combined, why hashing isn't 'weak encryption' but a different tool entirely, and how the PKI trust chain lets you trust a stranger's public key.
What a Trusted Computing Base actually is and why it must stay minimal, the security-mode vocabulary for systems handling mixed classification levels, Common Criteria evaluation assurance levels as a trust signal, and the physical-security layering that protects everything else in this domain.
How cryptography actually fails in practice — brute force, known-plaintext, and birthday-style collision attacks — plus the key management lifecycle CISSP treats as more operationally important than algorithm choice: generation, distribution, storage, rotation, and destruction.
Communication & Network Security
13% of exam 2 lessonsThe OSI model read as a security map, why segmentation exists beyond performance, the secure-protocol replacements for every legacy insecure one, and ARP poisoning as the canonical layer-2 attack — the domain where Nginx/Cloudflare experience maps almost directly onto CBK vocabulary.
The firewall generations from packet-filtering to next-gen, IPsec's two modes and why one leaks routing metadata the other doesn't, and the WPA2-to-WPA3 handshake fix that closed the KRACK-class vulnerability — the second network lesson, past OSI and segmentation.
Identity & Access Management
13% of exam 2 lessonsDAC/MAC/RBAC/ABAC as the practical mechanisms behind D1's theoretical models, plus SAML and OAuth/OIDC federation vocabulary — the domain where Keycloak-style IAM experience converts fastest into CISSP terminology.
The joiner-mover-leaver lifecycle those access-control mechanisms actually run inside — why de-provisioning, not provisioning, is where real breaches happen, plus the authentication-factor vocabulary CISSP tests precisely.
Security Assessment & Testing
12% of exam 2 lessonsBlack/gray/white-box testing as a knowledge spectrum, why a vulnerability assessment, a penetration test, and an audit are three different deliverables, and SAST vs DAST as complementary rather than competing tools — the domain closest to pentest/audit coordination work.
Why a good security metric must be actionable, not just measurable; log review as a distinct discipline from log collection; and continuous monitoring as the structural answer to the gap point-in-time testing always leaves open.
Security Operations
13% of exam 2 lessonsThe formal NIST incident-response lifecycle behind the DDoS/intrusion response you already do by instinct, containment vs eradication vs recovery, and the RTO/RPO/MTD vocabulary that decides which disaster-recovery site strategy is actually justified.
Where RTO and RPO actually come from — the Business Impact Analysis process that produces them — and why an untested continuity plan is, for CISSP purposes, functionally indistinguishable from no plan at all, through the five levels of plan testing.
Software Development Security
10% of exam 2 lessonsThe second and final cold-start gap: why 'shift-left' isn't a slogan but a cost argument, why parameterized queries structurally eliminate injection rather than just filtering it, and aggregation/inference as the two ways a database can leak more than any single query should — closing the loop back to Lesson 1's opening SQL injection example.
Three more code/data confusion vulnerability classes precisely distinguished from each other and from injection, plus CMMI and SAMM as two different lenses for measuring how mature a secure development process actually is — beyond any single vulnerability finding.
Capstone / Cross-Domain Review
1 lessonNot Domain Order 1→8
This roadmap opens with the Domain 1 spine, bridges through the domains where operational experience converts fastest (IAM, network, SecOps), and closes with the real cold-start gaps (crypto/architecture, secure SDLC). Lesson order reflects that path, not the exam outline's numbering.
Exam Prep Only
CISSP certification is issued exclusively by (ISC)², following its own exam and endorsement process — never by VigilForge.
What You'll Learn
- ✓ Reason through scenario questions the way CISSP grades them — the best answer for the organization, not the fastest technical fix
- ✓ Convert hands-on IAM, network, and incident-response experience directly into CBK vocabulary
- ✓ Cover the two genuine cold-start gaps for an operations-heavy background: cryptography/security architecture and secure SDLC theory
- ✓ Practice scenario-based, distractor-explained questions across all eight CBK domains