{"id":186628,"date":"2026-01-28T16:24:04","date_gmt":"2026-01-28T15:24:04","guid":{"rendered":"https:\/\/liora.io\/en\/?p=186628"},"modified":"2026-08-09T19:47:32","modified_gmt":"2026-08-09T18:47:32","slug":"all-about-cissp","status":"publish","type":"post","link":"https:\/\/liora.io\/en\/all-about-cissp","title":{"rendered":"CISSP Certification: What is it? How to obtain it?"},"content":{"rendered":"\n<p><strong>Globally recognized, the CISSP certification confirms the expertise of information security professionals. Encompassing all <a href=\"https:\/\/liora.io\/en\/cybersecurity-the-ultimate-guide\"><u>cybersecurity<\/u><\/a> facets through its Common Body of Knowledge, this certification isn&#8217;t just about mastering theoretical concepts-it&#8217;s primarily about their practical application within a business context. So, what exactly is the CISSP? What does its program entail? And what prerequisites must be met? Find out below.<\/strong><\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"what-does-cissp-mean\">What does CISSP mean?<\/h2>\n\n\n<p>The CISSP (Certified Information Systems Security Professional) serves as a professional credential for <a href=\"https:\/\/liora.io\/en\/cybersecurity-analyst-tasks-skills-training\">cybersecurity specialists<\/a>. First introduced in 1994 in the United States, it represents one of the pioneering cybersecurity certifications. At a time when the Internet was only beginning to evolve, the need to address <a href=\"https:\/\/liora.io\/en\/exploring-information-systems-is-definition-and-components\">information system<\/a> security concerns was already apparent.<\/p>\n\n\n<p>In today\u2019s environment, the CISSP demands even greater effort and creativity from cybersecurity experts to keep pace with increasingly sophisticated malicious hackers.<\/p>\n\n\n<p>Therefore, the CISSP assesses not only the technical knowledge of those certified but also their capabilities in risk analysis and their skills in performing system audits. The core objective is to <a href=\"https:\/\/liora.io\/en\/data-literacy-why-is-it-important-for-a-company\">effectively apply<\/a> cybersecurity principles to meet the specific needs of organizations.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"\/en\/courses\/cloud-dev\/cloud-engineer\">Find a course for you<\/a><\/div><\/div>\n\n\n<h2 class=\"wp-block-heading\" id=\"the-8-domains-of-the-cbk\">The 8 domains of the CBK<\/h2>\n\n\n<p>Overseen by the (ISC)\u00b2 (International Information Systems Security Certification Consortium), the CISSP training is grounded in a Common Body of Knowledge, known as the CBK. This CBK is categorized into 8 domains, each contributing differently to the overall grade.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"1-security-and-risk-management\">1 :  Security and Risk Management<\/h3>\n\n\n<p>This domain, making up 16% of the score, is the most significant. For a good reason: you must prove your <strong>understanding of crucial cybersecurity concepts<\/strong>, including:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Data confidentiality, integrity, and availability;<\/li>\n<li>Basic principles of risk management (including identification, evaluation, and mitigation of risks);<\/li>\n<li><a href=\"https:\/\/www.iso.org\/isoiec-27001-information-security.html\">ISO\/IEC standards<\/a>, security policy management, and business impact analysis;<\/li>\n<li>Compliance with laws, regulations, and industry standards.<\/li>\n<\/ul>\n\n\n<h3 class=\"wp-block-heading\" id=\"2-asset-security\">2 :  Asset Security<\/h3>\n\n\n<p>Accounting for 10% of the total grade, this CISSP domain concentrates on the <strong>classification of information<\/strong> according to data sensitivity and criticality.<\/p>\n\n\n<p>It covers the responsibilities of asset owners\/custodians, the information lifecycle, along with the protection and disposal of media.<\/p>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Illustration for 2 - Asset Security\" decoding=\"async\" height=\"514\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2024\/06\/certification-cissp1.jpg\" style=\"width:100%;height:auto\" width=\"900\"\/><\/figure>\n\n\n<h3 class=\"wp-block-heading\" id=\"3-security-architecture-and-engineering\">3 :  Security Architecture and Engineering<\/h3>\n\n\n<p>Comprising 13% of the score, this domain evaluates primarily the engineering processes. It zooms in on:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Security architecture principles and models;<\/li>\n<li>Development and evaluation of secure architectures;<\/li>\n<li>Cryptographic principles, methods, and their applications;<\/li>\n<li>Security of physical sites and facilities.<\/li>\n<\/ul>\n\n\n<h3 class=\"wp-block-heading\" id=\"4-communication-and-network-security\">4 :  Communication and Network Security<\/h3>\n\n\n<p>Here, you\u2019re tested on your ability to <strong>secure network components<\/strong>, establish secure communication channels, and thwart network attacks.<\/p>\n\n\n<p>The curriculum includes:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Network topologies, protocols, and devices;<\/li>\n<li>Firewalls, intrusion detection systems, VPNs;<\/li>\n<li>Authentication and authorization in network environments;<\/li>\n<li>Network attack types and defensive strategies.<\/li>\n<\/ul>\n\n\n<p>This area contributes 13% to the overall CISSP score.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"\/en\/courses\/cloud-dev\/cloud-engineer\">Discover our courses<\/a><\/div><\/div>\n\n\n<h3 class=\"wp-block-heading\" id=\"5-identity-and-access-management-iam\">5 :  Identity and Access Management (IAM)<\/h3>\n\n\n<p>Also representing 13% of the final score, this domain is all about <strong>managing both physical and logical access to resources.<\/strong><\/p>\n\n\n<p>Topics covered include:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Identity management techniques and technology;<\/li>\n<li>Access control models (RBAC, ABAC, MAC, DAC);<\/li>\n<li>Identity creation, management, and deletion;<\/li>\n<li>IAM technologies (SSO, MFA, LDAP directories).<\/li>\n<\/ul>\n\n\n<h3 class=\"wp-block-heading\" id=\"6-security-assessment-and-testing\">6 :  Security Assessment and Testing<\/h3>\n\n\n<p>Valued at 12% of the total CISSP certification score, this domain showcases your understanding of <strong>assessment strategies<\/strong> and <a href=\"https:\/\/liora.io\/en\/dlp-data-loss-prevention-principles-and-implementation\">security testing<\/a> methodologies (including vulnerability, penetration, and both functional and non-functional testing) along with internal audits.<\/p>\n\n\n<h3 class=\"wp-block-heading\" id=\"7-security-operations\">7 :  Security Operations<\/h3>\n\n\n<p>This domain (13% of the final score) covers:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Incident management<\/strong>: detection, response, and recovery processes concerning security incidents.<\/li>\n<li><strong>Business continuity and disaster recovery planning<\/strong>: preparedness and responding to emergencies.<\/li>\n<li><strong>Security resource management<\/strong>: monitoring, logging, and maintenance of security devices.<\/li>\n<li><strong>Facility security management<\/strong>: protections against intrusions and natural disasters.<\/li>\n<\/ul>\n\n\n<figure class=\"wp-block-image size-full\" style=\"margin-top:32px;margin-bottom:32px\"><img alt=\"Illustration for 7 - Security Operations\" decoding=\"async\" height=\"514\" loading=\"lazy\" src=\"https:\/\/liora.io\/app\/uploads\/sites\/9\/2024\/06\/certification-cissp2.jpg\" style=\"width:100%;height:auto\" width=\"900\"\/><\/figure>\n\n\n<h3 class=\"wp-block-heading\" id=\"8-software-development-security\">8 :  Software Development Security<\/h3>\n\n\n<p>Accounting for 10% of the total, this domain dwells on <strong>incorporating security throughout the software development lifecycle<\/strong>, across various environments.<\/p>\n\n\n<p>CISSP\u2019s 8 comprehensive domains make it one of the most challenging-but also most rewarding and highly regarded-certifications in the data security sphere.<\/p>\n\n\n<h2 class=\"wp-block-heading\" id=\"a-certification-reserved-for-cybersecurity-experts\">A certification reserved for cybersecurity experts<\/h2>\n\n\n<p>The CISSP&#8217;s prestige is matched by its rigor. Indeed, even prior to sitting the exam, four mandatory prerequisites must be met:<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>Prove 5 years of professional cybersecurity experience;<\/li>\n<li>Securing a third-party endorsement;<\/li>\n<li>Adhering to the (ISC)\u00b2 code of ethics;<\/li>\n<li>Consenting to a possible audit.<\/li>\n<\/ul>\n\n\n<p>Subsequently, passing the CISSP exam-consisting of 100 to 150 multiple-choice questions and requiring a 70% success rate-is imperative.<\/p>\n\n\n<p>To successfully navigate the CISSP certification exam, proper preparation is key. Liora is here to support you with its Cyber Analyst training.<\/p>\n\n\n<div class=\"wp-block-buttons is-layout-flex wp-block-buttons-is-layout-flex is-content-justification-center wp-container-core-buttons-is-layout-5ee10de4\" style=\"margin-top:32px;margin-bottom:32px\"><div class=\"wp-block-button\"><a class=\"wp-block-button__link wp-element-button\" href=\"\/en\/courses\/cloud-dev\/cloud-engineer\">Join Liora<\/a><\/div><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Globally recognized, the CISSP certification confirms the expertise of information security professionals. Encompassing all cybersecurity facets through its Common Body of Knowledge, this certification isn\u2019t just about mastering theoretical concepts-it\u2019s primarily about their practical application within a business context. So, what exactly is the CISSP? What does its program entail? And what prerequisites must be met? Find out below.<\/p>\n","protected":false},"author":85,"featured_media":186630,"comment_status":"open","ping_status":"open","sticky":false,"template":"elementor_theme","format":"standard","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"categories":[2426],"class_list":["post-186628","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity"],"acf":[],"_links":{"self":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/186628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/users\/85"}],"replies":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/comments?post=186628"}],"version-history":[{"count":5,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/186628\/revisions"}],"predecessor-version":[{"id":211104,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/posts\/186628\/revisions\/211104"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media\/186630"}],"wp:attachment":[{"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/media?parent=186628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/liora.io\/en\/wp-json\/wp\/v2\/categories?post=186628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}