CISSP study material // original practice items

Not exam content · rev 2026-10

CISSP CAT Practice

CISSP prep console8 domains · outline Apr 2024

Get the app

Doc CC-09Rev 2026-10Class study materialRead ~8 min

CISSP vs CISM: which security certification fits your role

Pick the ISC2 CISSP (Certified Information Systems Security Professional) if you want one credential that spans security architecture, networks, identity, operations and software as well as management; pick ISACA’s CISM (Certified Information Security Manager) if your job is running a security program — governance, risk, the program itself and incident management — and the technical layers belong to other teams.

Exam readout

Format
CAT, every language
Items
100–150
Time
3 hours
Pass mark
700 / 1000 scaled
Outline
8 domains · Apr 2024

The short verdict

CISSP is wide. Its eight domains run from risk management to software development security, and the heaviest of them, Security and Risk Management, carries only 16% of the current outline. CISM is deep in one direction: four areas, all of them about managing security rather than building it. The two overlap most in CISSP’s Domain 1, which is roughly where CISM lives full-time.

Most people comparing them are really choosing their next job. Architects, engineers, consultants and team leads who must talk credibly to network and development teams tend to fit CISSP. People already running a security function, or heading for a role with budgets, policies and board reporting, tend to fit CISM. Both are private professional certifications, not licenses, and plenty of senior people end up holding both.

CISSP vs CISM side by side

CISSP and CISM compared, as of October 2026
RefAspectCISSP (ISC2)CISM (ISACA)
R-01Focusbreadth: technical and managerial security across eight domainssecurity management: governance, risk, the security program, incidents
R-02Typical candidatepractitioners moving into senior, architect, lead or consulting rolesmanagers who run, build or advise an organization’s security program
R-03Content outline8 domains, outline effective April 2024; Domain 1 heaviest at 16%, Domains 2 and 8 lightest at 10%4 job-practice areas, all managerial; current weights on isaca.org
R-04Experience to certify5 years cumulative work in at least 2 of the 8 domains; one year can be waived by a relevant degree or one approved credential5 years of information security work, part of it in security management; substitutions and time limits set by ISACA
R-05Pass before the experience?yes — you become an Associate of ISC2 with 6 years to earn the 5yes — you apply for the certification once the experience is in place, within ISACA’s published window
R-06Exam formatadaptive (CAT): 100–150 items, up to 3 hours, 700 out of 1000 scaled to pass, no going back; details on the exam page150 multiple-choice items in 4 hours; scoring and delivery rules on isaca.org
R-07After passingendorsement by an ISC2-certified professional within 9 monthsan application to ISACA with verified work experience
R-08Keeping it120 CPE credits per 3-year cycle (at least 90 in Group A) plus an annual maintenance feecontinuing education on ISACA’s own cycle with yearly minimums, plus an annual maintenance fee

Fees are left out on purpose: both bodies set them by region and change them. Check current prices and policies on isc2.org and isaca.org before you plan a budget.

How much of CISSP a CISM holder already knows

A rough map of where the two outlines meet. It is our reading of both, domain by domain, not a crosswalk either body publishes.

CISSP domains and their overlap with CISM’s management focus
CISSP domainWeightOverlap with CISM
Domain 1 Security and Risk Management16%heavy — governance, risk analysis and responses, continuity planning, policy hierarchy
Domain 2 Asset Security10%partial — classification and ownership as program decisions; not media sanitization
Domain 3 Security Architecture and Engineering13%light — design principles in outline; security models, cryptography and facility controls are new
Domain 4 Communication and Network Security13%little — protocols, layers and network design are outside CISM’s scope
Domain 5 Identity and Access Management13%light — access policy and reviews; federation, Kerberos and access-control models are new
Domain 6 Security Assessment and Testing12%partial — assessment as a program activity; choosing and running specific test types is new
Domain 7 Security Operations13%partial — incident management and recovery planning; evidence handling and DR test mechanics are new
Domain 8 Software Development Security10%light — acquired-software risk; SDLC models and code-level testing are new

Read across the third column: a CISM holder moving to CISSP mostly needs Domains 3, 4, 5 and 8 — 49% of the outline. The reverse trip is shorter on content and longer on management judgment.

Which one fits your role

Read the job ads for the role you want next, not the one you have. If they ask for someone who can review a network design, challenge an identity architecture and sit in a risk committee in the same week, that is a CISSP-shaped job. If they ask for someone to own the security strategy, the policy set and the incident program, that is CISM-shaped.

CISSP is the better fit if you

  • work across several technical areas — networks, identity, cloud, operations, development — and want one credential that names all of them;
  • are moving from engineer or analyst into architect, lead or consultant roles, where breadth is the point;
  • need a credential that is approved under the U.S. DoD’s DoDM 8140.03 for the work role you hold or want (check the DoD’s own matrices for the role);
  • already have 4 or 5 years in two or more of the eight domains, so the experience rule is not the bottleneck.

CISM is the better fit if you

  • already manage people, budgets or a security function, or report on security to executives;
  • work in governance, risk and compliance and rarely configure anything yourself;
  • want a narrower exam where every question is a management question, rather than eight domains of mixed depth;
  • work in an organization that already uses ISACA credentials such as CISA for its audit and governance staff.

If both lists describe you, the deciding question is usually what you want to be asked about in an interview: how a control works, or how a program is run.

Should you get CISSP or CISM first?

Get the one that matches your current job first, because that is where your experience already counts. There is one ordering detail worth knowing: CISM is on ISC2’s list of credentials that can waive one year of the five years of CISSP experience. The waiver is capped at one year in total, a relevant degree or one listed credential, so if your degree already earns it, holding CISM first shortens nothing.

If you are short on experience, neither exam makes you wait: both let you sit first. The difference is what comes after. Pass CISSP without the five years and you become an Associate of ISC2, with six years to earn them; pass CISM and you apply for the certification once the experience is in place, within the window ISACA sets on isaca.org. The full CISSP rules, including what part-time work and internships count for, are on the CISSP requirements page, and the authoritative list of waiver credentials is on isc2.org.

Is CISM harder than CISSP?

They are hard in different ways, and no published figure settles it: ISC2 does not release CISSP pass rates, so any number you see quoted is somebody’s guess. What can be compared is the shape of each exam.

CISSP is harder on breadth. Eight domains means cryptography key counts, OSI layers, Kerberos, evidence handling and SDLC models can all appear in one sitting, and the adaptive format gives you no chance to return to an item. Candidates from a management background tend to find Domains 3 and 4 the steepest.

CISM is harder on judgment within a narrow field. Its questions ask what a security manager should do first or best, and the expected answer follows ISACA’s view of governance. Technically strong candidates often find this slippery, because the correct-looking technical fix is rarely the answer. That instinct is not wasted: CISSP rewards the same manager’s reflex — protect people, serve the business, escalate before you configure — which is why studying for one helps with the other.

Where CISA, CCSP and SSCP fit

Three neighboring credentials come up in the same decision. One line each on what they are for and how they relate to CISSP.

Neighboring certifications and their link to CISSP
CertificationIssuerWhat it is forRelation to CISSP
CISAISACAinformation systems audit and assurance; 150 items in 4 hourscomplements CISSP rather than competing; not on ISC2’s list of experience-waiver credentials
CCSPISC2cloud security architecture, data and operationsan active CISSP satisfies the entire CCSP experience requirement, so many take it second
SSCPISC2hands-on security administration; one year of experience in one of its domainson ISC2’s waiver list for CISSP, and a common stepping stone toward it

The waiver list changes; check it on isc2.org. CISA details are on isaca.org.

So the three-way question, CISA vs CISM vs CISSP, has a cleaner answer than the two-way one: audit work points to CISA, running a security program points to CISM, and practicing security across its technical and managerial layers points to CISSP. People who change track tend to add the second credential later instead of choosing again.

Three CISSP items on assessment and testing

Domain 6, Security Assessment and Testing, is 12% of the CISSP outline and the part closest to CISA’s audit territory. Each option has a note explaining why it is or is not the best answer.

Domain drill

Item 01 / 03

Answer, then read why each option is right or wrong. Keys 1–4 pick, N goes next.

D6Security Assessment and Testing

A static application security testing (SAST) tool flags a critical input validation flaw in a production continuous integration pipeline. What is the most appropriate next step?

Rationale

Pick an answer. The reasoning for every option lands here — including why the wrong ones looked right.

Questions people ask

Q01Is CISM harder than CISSP?

Neither is objectively harder. CISSP is broader, with eight domains, technical depth and an adaptive exam with no going back; CISM is narrower but every question is a management judgment in ISACA’s framing. Technical candidates usually find CISM’s judgment calls harder, managers usually find CISSP’s breadth harder.

Q02Which is better, CISA, CISM, or CISSP?

The one that matches the work. CISA fits information systems audit and assurance, CISM fits security management and governance, and CISSP fits broad security practice across technical and managerial domains.

Q03Should I get CISSP or CISM first?

Start with the one your current experience supports. Holding CISM can waive one year of CISSP experience, but only if a degree has not already used the single one-year waiver.

Q04Can I hold both CISSP and CISM?

Yes, and it is a common pairing for senior security managers. Each body runs its own maintenance cycle and annual fee, so you keep up continuing education for both.

Q05Does CISM count toward the CISSP experience requirement?

CISM is on ISC2’s list of credentials that can waive one of the five years. You still need the remaining four years of work in at least two CISSP domains; see the requirements page.

Debrief · key takeaways

  1. CISSP is breadth across eight domains; CISM is depth in security management.
  2. Choose by the job you want next, not by which looks better on a slide.
  3. CISM can waive one CISSP experience year; the waiver is capped at one year in total.
  4. No pass rates are published, so difficulty claims are opinions, ours included.
  5. Leaning CISSP? Test yourself across all eight domains on the free practice test, then read the CISSP certification overview and the study plan.

Field kit

Leaning toward CISSP?

Drill all eight domains between meetings. The CISSP prep app carries a larger question bank, on iPhone and Android.

Get the appPractice free on this site

End of document

Handle with mild caffeine