Key Takeaways:

  • CISSP Certification: Accredited by ANSI/ISO/IEC, it's the gold standard in cybersecurity, globally recognized and sought after.
  • Exclusive Benefits: CISSP certification grants access to elite professional networks, industry events, webinars, and career resources.
  • (ISC)² Oversight: (ISC)² continually ensures CISSP maintains its industry-leading status by reviewing and updating certification standards.
  • Path to Certification: Understand prerequisites, prepare for the exam, pass the CISSP examination, complete endorsement, and maintain certification.

Certified Information Systems Security Professional Certification was the first technology-related credential to earn ANSI/ISO/IEC Standard 17024 accreditation, making it the Gold Standard within the information security industry. This makes CISSP is one of the most sought after certification and a globally recognized standard of achievement. CISSP practice exams can help candidates clear it in the first attempt.

Once you achieve your CISSP certification you become member of the elite network of information security professionals and you also enjoy exclusive benefits as an (ISC)² member, including valuable resources such as access to leading industry conference registrations worldwide, access to information security webinars,  subscription to—InfoSecurity Professional  which is (ISC)2’s members-only digital magazine, access to a Career Center with current job listings, peer networking and idea exchange, and others.

The (ISC)2 board of directors continually review the entire spectrum of the consortium’s education and certification programs to ensure that (ISC)2 continues to provide the “gold standard” of professional certification in the information security industry.  To maintain the rigorous standard of CISSP and to meet the challenges of ever-increasing threat environment, the (ISC)2 has set the following requirements for achieving CISSP certification.

In this article, we delve into the fundamental CISSP requirements that prospective professionals must satisfy to attain this prestigious certification. From educational prerequisites and professional experience to navigating the examination process and upholding certification standards, we offer a thorough examination of the path to CISSP accreditation.

Whether you're an experienced cybersecurity practitioner seeking career advancement or an aspiring newcomer aiming to enter the field, gaining an insight into the CISSP requirements is the first step toward reaching your goals. Come with us as we explore the basic skills, industry standards, and best ways to get CISSP certified.

How to get CISSP Certification

In the realm of information security, the Certified Information Systems Security Professional (CISSP) certification stands as a pinnacle of achievement. Widely recognized and respected, CISSP certification validates an individual's expertise in designing, implementing, and managing cybersecurity programs. For aspiring professionals looking to advance their careers in cybersecurity, obtaining CISSP certification is a significant milestone. In this comprehensive guide, we will explore the step-by-step process of acquiring CISSP certification, from understanding the prerequisites to navigating the examination and maintaining certification.

Step 1: Understand the Prerequisites

Before embarking on the journey towards CISSP certification, it is crucial to understand the prerequisites. CISSP candidates must have a minimum of five years of cumulative, paid, full-time work experience in two or more of the eight domains of the CISSP Common Body of Knowledge (CBK). However, candidates with a four-year college degree or an approved credential may be eligible for a one-year experience waiver.

Step 2: Prepare for the CISSP Examination

Preparation is key to success in the CISSP examination. The exam covers eight domains, including Security and Risk Management, Asset Security, Security Architecture and Engineering, Communication and Network Security, Identity and Access Management (IAM), Security Assessment and Testing, Security Operations, and Software Development Security. Candidates can prepare for the exam through self-study using official study guides, attending training courses, and utilizing practice exams and question banks.

Step 3: Pass the CISSP Examination

The CISSP examination consists of 100-150 multiple-choice and advanced innovative questions. Candidates have up to three hours to complete the exam, and a passing score of 700 out of 1000 points is required. Upon passing the exam, candidates must endorse their experience and subscribe to the (ISC)² Code of Ethics to complete the certification process.

Step 4: Complete the Endorsement Process

After passing the CISSP examination, candidates must submit an endorsement application, affirming their professional experience in the field of information security. The endorsement process involves providing details of relevant work experience, including job titles, employment dates, and descriptions of duties performed in each of the CISSP domains. Endorsement applications are reviewed by (ISC)² and typically processed within four to six weeks.

Step 5: Maintain CISSP Certification

Maintaining CISSP certification requires adherence to the Continuing Professional Education (CPE) requirements set forth by (ISC)². CISSP professionals must earn and submit a minimum of 40 CPE credits annually, with a total of 120 CPE credits required over a three-year certification cycle. CPE credits can be earned through various activities, including attending training courses, participating in webinars, publishing articles, and engaging in volunteer work.

CISSP Experience requirements

The requirements include the following components:

  • Applicants must have a minimum of five years of direct full-time security professional work experience in two or more of the ten domains of the (ISC)² CISSP CBK

OR

  • Four years of direct full-time security professional work experience in two or more of the ten domains of the CISSP CBK with a four-year college degree or a credential from the (ISC)2-approved list

OR

  • If you don’t have the experience you can become an Associate of (ISC)² by successfully passing the CISSP exam. You’ll have six years to earn your experience to become a CISSP.
  • Note that only a one-year experience exemption is granted for education. Then again, there is a one-year waiver of the professional experience requirement for holding an additional credential on the (ISC)2 approved list.
  • Valid experience includes information systems security-related work performed as a practitioner, auditor, consultant, investigator or instructor, that requires Information Security knowledge and involves the direct application of that knowledge.
  • The five years of experience must be the equivalent of actual full-time Information Security work (not just Information Security responsibilities for a five year period); this requirement is cumulative, however, and may have been accrued over a much longer period of time.

Ten domains of CISSP CBK

CISSP is divided into 8 areas or domains, known collectively as the ‘Common Body of Knowledge CBK’. These domains are:

  • Security and Risk Management
  • Asset Security
  • Security Architecture and Engineering
  • Communication and Network Security
  • Identity and Access Management
  • Security Assesment and Testing
  • Security Operations
  • Software Development Security

CISSP Professional Experience Requirements

CISSP professional experience includes but not limited to:

  • Work requiring special education or intellectual attainment, usually including a liberal education or college degree.
  • Work requiring habitual memory of a body of knowledge shared with others doing similar work.
  • Management of projects and/or other employees.
  • Supervision of the work of others while working with a minimum of supervision of one’s self.
  • Work requiring the exercise of judgment, management decision-making, and discretion.
  • Work requiring the exercise of ethical judgment (as opposed to ethical behavior).
  • Creative writing and oral communication.
  • Teaching, instructing, training and the mentoring of others.
  • Research and development.
  • The specification and selection of controls and mechanisms (i.e. identification and authentication technology) (does not include the mere operation of these controls).
  • Applicable job title examples are CISO, Director, Manager, Supervisor, Analyst, Cryptographer, Cyber Architect, Information Assurance Engineer, Instructor, Professor, Lecturer, Investigator, Computer Scientist, Program Manager, Lead, etc.

Approved Credentials for Experience Waiver:

  • CCSP (Cisco Certified Security Professional)
  • CCNP Security (Cisco Certified Network Professional Security)
  • CERT Certified Computer Security Incident Handler (CSIH)
  • Certified Business Continuity Planner
  • Certified Computer Crime Investigator (Advanced) (CCCI)
  • Certified Computer Crime Prosecutor
  • Certified Computer Examiner (CCE)
  • Certified Forensic Computer Examiner (CFCE)
  • Certified Fraud Examiner (CFE)
  • Certified Information Systems Auditor (CISA)
  • Certified Information Security Manager (CISM)
  • Certified Internal Auditor (CIA)
  • Certified Protection Professional (CPP)
  • Certified Wireless Security Professional (CWSP)
  • CIW Web Security Associate
  • CIW  Security Analyst
  • CIS Web Security Professional
  • CIW Web Security Specialist
  • CompTIA Security+
  • Cyber Security Forensic Analyst (CSFA)
  • GIAC Certified Enterprise Defender (GCED)
  • GIAC Security Essentials Certification (GSEC)
  • GIAC Certified Firewall Analyst (GCFW)
  • GIAC Certified Intrusion Analyst (GCIA)
  • GIAC Certified Incident Handler (GCIH)
  • GIAC Certified Windows Security Administrator (GCWN)
  • GIAC Certified UNIX Security Administrator (GCUX)
  • GIAC Certified Forensic Analyst (GCFA)
  • GIAC Security Leadership Certification (GSLC)
  • GIAC Systems and Network Auditor (GSNA)
  • GIAC ISO 27000 Specialists (62700)
  • GIAC Certified Forensics Examiner (GCFE)
  • GIAC Information Security Professional (GISP)
  • GIAC Information Security Fundamentals (GISF)
  • Certified Penetration Tester (GPEN)
  • Information Security Management Systems Lead Auditor (IRCA)
  • Information Security Management Systems Principal Auditor (IRCA)
  • MCITP Microsoft Certified IT Professional
  • Microsoft Certified Systems Administrator (MCSA)
  • Microsoft Certified Systems Engineer (MCSE)
  • Master Business Continuity Planner (MBCP)
  • Systems Security Certified Practitioner (SSCP)

Once the candidate successfully clears the CISSP exam, his/her qualifications need to be endorsed by another CISSP in good standing. The endorser attests the candidate’s assertions regarding professional experience. If you cannot find a certified individual to act as an endorser, (ISC)² will act as an endorser for you. For further details, visit the (ISC)² website http://www.isc2.org. To prepare thoroughly for the exam, consider enrolling in a cyber security certification course or a cyber security bootcamp online to enhance your knowledge and skills.

Enroll in our Advanced Executive Program in Cybersecurity which is designed to help you pass exams in your first attempt and give you deep expertise that you’ll be able to draw upon throughout your IT career.

FAQs

1. Can I take the CISSP exam without experience?

No, candidates must have a minimum of five years of cumulative, paid, full-time work experience in two or more of the eight domains of the CISSP Common Body of Knowledge (CBK). However, candidates with a four-year college degree or an approved credential may be eligible for a one-year experience waiver.

2. Can anybody take the CISSP?

While anyone can technically register for the CISSP exam, only individuals who meet the experience requirements outlined by (ISC)² are eligible to attain CISSP certification. The certification is designed for experienced professionals working in the field of information security, and candidates must demonstrate a comprehensive understanding of cybersecurity concepts across various domains.

3. Does CISSP require coding?

No, CISSP certification does not specifically require proficiency in coding. While having some knowledge of coding languages may be beneficial, particularly in domains such as Software Development Security, CISSP focuses more on the broader principles and practices of information security, risk management, and security governance.

Duration and Fees for Our Online Cyber Security Training

Cyber Security training programs usually last from a few weeks to several months, with fees varying depending on the program and institution

Program NameDurationFees
Executive Certificate Program in Cybersecurity

Cohort Starts: 9 Jan, 2025

7 months$ 2,499
Caltech Cybersecurity Bootcamp

Cohort Starts: 13 Jan, 2025

6 Months$ 8,000
Professional Certificate Program in Cybersecurity

Cohort Starts: 17 Jan, 2025

20 weeks$ 3,500
Cyber Security Expert Masters Program4 months$ 2,599