Active Study Plan

CISSP Certification

A structured 4-month journey to pass the CISSP exam, tailored to your 5 years of PAM/IAM experience

16
Weeks Total
8
Domains
15-20
Hours/Week
0
Topics Done

Your PAM/IAM Advantage

With 5 years of PAM/IAM experience, Domain 5 (Identity & Access Management) will be your strongest area. This plan leverages your expertise to accelerate learning in related domains while focusing extra attention on areas outside your daily work.

Overall Progress 0%

Study Timeline

4 months · 8 domains · Exam ready

01

Foundation & Core Security

Weeks 1-4 · Building the knowledge base

0%
Complete
Domain 1
Security and Risk Management
15%
The largest domain covering security governance, compliance, legal/regulatory issues, professional ethics, and business continuity. This domain establishes the foundation for all other security concepts and is heavily weighted in the exam.
Key Topics
CIA Triad, DAD, and security governance principles
Risk management frameworks (NIST, ISO 27001, COBIT)
Quantitative vs Qualitative risk analysis (ALE, SLE, ARO)
Legal, regulatory, and compliance requirements (GDPR, HIPAA, SOX)
Business Continuity Planning (BCP) and Disaster Recovery (DR)
Security policies, standards, procedures, and guidelines
Professional ethics and (ISC)² Code of Ethics
Domain 2
Asset Security
10%
Covers the classification and ownership of information and assets, privacy protection, data retention policies, and secure handling of data throughout its lifecycle. Your PAM experience gives you insight into data handling requirements.
Key Topics
Data classification levels (Public, Private, Confidential, Top Secret)
Data ownership roles (Owner, Custodian, Steward, User)
Data lifecycle: Create, Store, Use, Share, Archive, Destroy
Data remanence and secure destruction methods
Privacy protection and data sovereignty
02

Architecture & Engineering

Weeks 5-8 · Technical deep dive

0%
Complete
Domain 3
Security Architecture and Engineering
13%
A highly technical domain covering security models, cryptography, secure design principles, and physical security. This requires dedicated study as it's concept-heavy with many formulas and models to memorize.
Key Topics
Security models (Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash)
Cryptography fundamentals (Symmetric, Asymmetric, Hashing)
PKI, digital certificates, and certificate authorities
Secure design principles (Defense in Depth, Zero Trust)
Site and facility security controls
Trusted Computing Base (TCB) and security evaluation criteria
Domain 4
Communication and Network Security
13%
Covers network architecture, protocols, and secure communication channels. Understanding the OSI model and how security applies at each layer is crucial. Your CyberArk experience with network segmentation will help here.
Key Topics
OSI and TCP/IP models with security at each layer
Network devices (Routers, Switches, Firewalls, IDS/IPS)
VPNs, TLS/SSL, IPSec protocols
Wireless security (WPA3, 802.1X)
Network attacks and countermeasures
03

Identity, Operations & Assessment

Weeks 9-12 · Your strongest domains + critical skills

0%
Complete
Domain 5
Identity and Access Management (IAM)
13%
Your Expertise
This is your wheelhouse! With 5 years of PAM/IAM and CyberArk experience, you already understand most of these concepts practically. Focus on learning the CISSP-specific terminology and edge cases you might not encounter daily.
Key Topics (Review & Gap-Fill)
Authentication factors (Type 1, 2, 3) and MFA concepts Strong
Access control models (DAC, MAC, RBAC, ABAC) Strong
Privileged Access Management (PAM) principles Strong
Identity federation and SSO (SAML, OAuth, OpenID Connect)
Identity provisioning and lifecycle management Strong
Credential management and session management
Domain 6
Security Assessment and Testing
12%
Covers vulnerability assessments, penetration testing, security audits, and KPIs/metrics. Your SOC analyst content creation background for @soc_analysts will help you understand assessment methodologies.
Key Topics
Vulnerability assessment vs Penetration testing
Log reviews and synthetic transactions
Security audit types (Internal, External, Third-party)
SOC reports (Type 1, Type 2) and audit standards
Security metrics, KPIs, and KRIs
Domain 7
Security Operations
13%
A large domain covering incident response, forensics, disaster recovery, and operational security. Your @soc_analysts content creation gives you familiarity with SOC operations and incident handling.
Key Topics
Incident response lifecycle (Preparation Lessons Learned)
Digital forensics and evidence handling (Chain of Custody)
Disaster Recovery (RPO, RTO, MTD, MTBF, MTTR)
Backup strategies and site recovery options
Change and configuration management
Logging, monitoring, and SIEM concepts
04

Software Security & Exam Prep

Weeks 13-16 · Final domain + intensive review

0%
Complete
Domain 8
Software Development Security
11%
Covers secure software development lifecycle (SDLC), common vulnerabilities, and secure coding practices. While you don't have a coding background, CISSP tests concepts not coding skills—focus on understanding the principles.
Key Topics
SDLC models (Waterfall, Agile, DevSecOps)
OWASP Top 10 vulnerabilities
Secure coding practices and input validation
Database security (SQL injection, stored procedures)
Code review and security testing (SAST, DAST)
Software acquisition and third-party security
Final 2 Weeks
Intensive Exam Preparation
Critical
The CISSP exam is adaptive (CAT format) with 125-175 questions over 4 hours. Focus on understanding concepts deeply rather than memorizing facts. Think like a manager, not a technician.
Exam Strategy Checklist
Complete 2 full-length practice exams (Boson, Official Practice Tests)
Review all weak domains identified from practice tests
Master the "Think Like a Manager" mindset
Review glossary terms and acronyms
Rest well the night before—no cramming!

Recommended Weekly Schedule

15-20 hours per week for optimal retention

Monday - Tuesday
Read 1-2 chapters from Official Study Guide
Take notes using active recall method
Watch corresponding video lectures
Wednesday - Thursday
Practice questions (50-75 per session)
Review incorrect answers deeply
Create flashcards for weak areas
Friday
Review MindMaps and visual aids
Teach concepts (record for @soc_analysts!)
Light practice questions
Weekend
Deep dive on one complex topic
Full domain practice test
Review and plan next week

CISSP Success Tips

Strategies from successful candidates

Think Like a Manager
CISSP tests management thinking, not technical implementation. When in doubt, choose the answer that protects the organization and human life first.
Understand, Don't Memorize
The exam tests conceptual understanding. Know WHY things work, not just what they are. Your PAM experience gives you practical context—leverage it.
Use Active Recall
Test yourself constantly. Read a section, close the book, and explain it out loud. Create content for @soc_analysts to reinforce learning.
Pace Yourself
4 months is sufficient with consistent study. Don't burn out—sustainable daily progress beats weekend cramming every time.