ISC2 Certified Information Systems Security Professional (CISSP)
Comprehensive Cybersecurity Leadership, Security Architecture, Risk Management, Operations and Governance
2 Days Intensive CISSP Exam Preparation Bootcamp – 16 Training Hours
ISC2 CISSP – Certified Information Systems Security Professional
The Certified Information Systems Security Professional (CISSP) is one of the world's leading cybersecurity certifications, designed to validate the knowledge, skills and experience required to effectively design, implement and manage an organization's overall cybersecurity program.
CISSP covers cybersecurity from both technical and managerial perspectives, including security governance, risk management, asset protection, security architecture, network security, identity and access management, security assessment, security operations and software development security.
The CISSP examination is organized into eight domains and uses Computerized Adaptive Testing (CAT) with scenario-oriented and advanced item types.
This intensive bootcamp is designed to help participants understand the CISSP Common Body of Knowledge (CBK), develop the CISSP way of thinking, analyze scenario-based questions and prepare systematically for the certification examination.
Why Attend CISSP Exam Preparation Bootcamp?
CISSP is not simply a test of cybersecurity terminology.
The examination evaluates whether candidates can apply security knowledge and professional judgment across different organizational situations.
This bootcamp focuses on:
- Understanding the eight CISSP domains
- Connecting technical security concepts with business objectives
- Security governance and risk management
- Security architecture and engineering principles
- Network and communication security
- Identity and Access Management (IAM)
- Security assessment and testing
- Security operations
- Software development security
- Scenario-based decision making
- Risk-based security decisions
- Management-oriented security thinking
- CISSP exam question analysis
- Exam strategy and time management
Participants will be trained to understand why an answer is correct, rather than simply memorizing terminology.
CISSP Exam Overview
| Item | CISSP |
|---|---|
| Certification | Certified Information Systems Security Professional |
| Certification Body | ISC2 |
| Exam Type | Computerized Adaptive Testing (CAT) |
| Number of Items | 100–150 |
| Maximum Exam Time | 3 Hours |
| Item Format | Multiple Choice and Advanced Item Types |
| Passing Score | 700 / 1000 |
| Exam Languages | English, Chinese, German, Japanese, Spanish |
| Testing | Pearson VUE Testing Centers |
| Domains | 8 Domains |
The current CISSP examination uses CAT and presents between 100 and 150 items within a maximum of three hours. The passing score is 700 out of 1000 points.
The CAT examination dynamically determines the candidate's ability level based on responses to previous questions. Therefore, candidates should not expect every question to have the same level of difficulty.
CISSP Examination Domains
The current CISSP Exam Outline consists of eight domains:
| Domain | Domain Name | Weight |
|---|---|---|
| Domain 1 | Security and Risk Management | 16% |
| Domain 2 | Asset Security | 10% |
| Domain 3 | Security Architecture and Engineering | 13% |
| Domain 4 | Communication and Network Security | 13% |
| Domain 5 | Identity and Access Management (IAM) | 13% |
| Domain 6 | Security Assessment and Testing | 12% |
| Domain 7 | Security Operations | 13% |
| Domain 8 | Software Development Security | 10% |
These are the current domain weights published in the ISC2 CISSP Exam Outline.
2-Day CISSP Exam Preparation Syllabus
DAY 1 – Governance, Risk, Architecture, Network and IAM
Domain 1 – Security and Risk Management
Participants will explore:
- Security and risk management principles
- ISC2 Code of Professional Ethics
- Organizational ethics
- Confidentiality, Integrity and Availability
- Authenticity and Nonrepudiation
- Security governance principles
- Security governance structure
- Organizational roles and responsibilities
- Security policies, standards, guidelines and procedures
- Security control frameworks
- Due care and due diligence
- Legal, regulatory and compliance requirements
- Privacy requirements
- Risk management
- Risk assessment
- Risk treatment
- Risk monitoring
- Supply chain risk
- Security awareness and training
- Business continuity considerations
- Personnel security
- Security strategy alignment with business objectives
Domain 1 is particularly important because CISSP questions frequently require candidates to understand business context, governance, risk and management responsibility, rather than immediately selecting a technical solution.
Domain 2 – Asset Security
Topics include:
- Information and asset classification
- Asset ownership
- Asset management
- Data ownership
- Data classification
- Data handling requirements
- Data retention
- Data protection
- Data privacy
- Data security lifecycle
- Storage security
- Data destruction
- Information handling procedures
- Security requirements based on asset value
The focus is not simply on protecting "data," but understanding what information exists, who owns it, how it should be classified and what security controls are appropriate throughout its lifecycle.
Domain 3 – Security Architecture and Engineering
Topics include:
- Security architecture principles
- Security models
- Security design principles
- Secure engineering principles
- Security architecture frameworks
- Infrastructure security
- Security boundaries
- Trust models
- Cryptography
- Cryptographic algorithms
- Key management
- Secure hardware and firmware
- Physical security
- Environmental security
- Vulnerabilities and countermeasures
- Cloud security architecture
- Virtualization
- IoT and emerging technologies
Participants will learn to distinguish between security requirements, architecture, design decisions and implementation controls.
Domain 4 – Communication and Network Security
Topics include:
- Network architecture
- Secure network design
- OSI and TCP/IP concepts
- Network protocols
- Secure communication
- Network segmentation
- Security zones
- Firewalls
- IDS/IPS
- VPN
- Proxy
- Network access control
- Wireless security
- Remote access
- Telecommunications
- Network attacks
- Secure network architecture
- Cloud and distributed network environments
A major focus is understanding why a particular network architecture or security control should be selected in a given scenario.
Domain 5 – Identity and Access Management (IAM)
Topics include:
- Identity management
- Identification
- Authentication
- Authorization
- Accountability
- Access control models
- Mandatory Access Control
- Discretionary Access Control
- Role-Based Access Control
- Attribute-Based Access Control
- Rule-Based Access Control
- Federation
- Single Sign-On
- Privileged Access Management
- Account management
- Access provisioning
- Access review
- Authentication factors
- Biometrics
- Credential management
Participants will practice analyzing access-control scenarios and selecting solutions based on business requirements, security risk and least privilege.
DAY 2 – Assessment, Operations and Software Security
Domain 6 – Security Assessment and Testing
Topics include:
- Security assessment
- Security testing
- Control assessment
- Vulnerability assessment
- Penetration testing
- Security audits
- Internal and external assessments
- Testing methodologies
- Test planning
- Test results
- Reporting
- Security metrics
- Key Performance Indicators
- Key Risk Indicators
- Continuous monitoring
- Control effectiveness
- Remediation
The emphasis is on understanding the difference between assessment, testing, audit, vulnerability assessment and penetration testing, and determining which activity is appropriate for a particular objective.
Domain 7 – Security Operations
Topics include:
- Security operations principles
- Operational procedures
- Incident management
- Incident response
- Detection and analysis
- Containment
- Eradication
- Recovery
- Lessons learned
- Disaster recovery
- Business continuity
- Backup
- Recovery strategies
- Disaster recovery testing
- Logging and monitoring
- Security Information and Event Management
- Vulnerability management
- Patch management
- Change management
- Configuration management
- Evidence handling
- Digital forensics
- Investigations
- Personnel security
- Security awareness
- Physical security operations
Domain 7 requires candidates to understand how security is operated and maintained over time, not simply how a security solution is initially designed.
Domain 8 – Software Development Security
Topics include:
- Secure software development
- Software development lifecycle
- Security requirements
- Secure architecture
- Secure coding
- Application security
- Software testing
- Code review
- Security testing
- DevSecOps
- Software supply chain
- Third-party software
- Application vulnerabilities
- Secure deployment
- Software maintenance
The objective is to integrate security throughout the software development lifecycle rather than treating security as an activity performed only after development is completed.
Practical CISSP Case Study
Enterprise Banking Security Transformation
A financial institution is developing a new digital banking platform.
The organization has identified several risks:
- Sensitive customer information
- Increasing cyberattacks
- Third-party service providers
- Cloud infrastructure
- Remote employees
- Regulatory requirements
- Mobile applications
- Legacy systems
- Increasing software development velocity
The CISO asks the security team to develop an enterprise security strategy.
Participants must determine:
- Which assets require the highest level of protection?
- Who should own the information?
- How should information be classified?
- What risks should be prioritized?
- Which security architecture should be implemented?
- How should privileged access be controlled?
- How should networks be segmented?
- What security testing should be performed?
- How should security incidents be handled?
- How should security be integrated into software development?
This case study demonstrates how CISSP domains are interconnected.
A real-world security decision rarely belongs to only one domain.
Comprehensive CISSP Exam Preparation
The bootcamp does not focus solely on memorizing definitions.
Participants are trained to analyze questions using:
1. Identify the Security Objective
Determine what the question is actually asking.
Is the objective:
- Risk reduction?
- Compliance?
- Confidentiality?
- Integrity?
- Availability?
- Governance?
- Access control?
- Detection?
- Prevention?
- Recovery?
- Business continuity?
2. Identify the Role
Determine who is responsible for the decision.
For example:
- Senior management
- CISO
- Security manager
- Data owner
- System owner
- Security architect
- Security administrator
- Auditor
3. Understand the Business Context
CISSP questions often require the candidate to consider:
Business → Risk → Security Requirement → Control
rather than immediately choosing a technology.
4. Select the BEST Answer
CISSP questions may contain several answers that appear technically correct.
The objective is to select the BEST answer based on the scenario, security principles, business requirements and risk.
CISSP Practice Questions
Sample Question 1
A company is implementing a new information security program. Senior management wants to ensure that security investments support the organization's strategic objectives.
What should be performed FIRST?
A. Deploy additional security technologies
B. Conduct a penetration test
C. Align the security program with business objectives
D. Implement multifactor authentication
Correct Answer: C
Explanation
Security must support organizational goals and business requirements.
A CISSP candidate should avoid immediately selecting a technical control before understanding the business context and security objectives.
Sample Question 2
An organization discovers that employees have excessive privileges on a critical application.
What is the MOST appropriate security principle to apply?
A. Defense in depth
B. Least privilege
C. Separation of duties
D. Nonrepudiation
Correct Answer: B
Explanation
Least privilege ensures that users receive only the access necessary to perform their authorized responsibilities.
Sample Question 3
A security team discovers a critical vulnerability in a production system. The business owner is concerned that immediately applying the patch could disrupt a critical business process.
What should the security manager do FIRST?
A. Immediately shut down the system
B. Ignore the vulnerability
C. Assess the risk and business impact
D. Notify law enforcement
Correct Answer: C
Explanation
CISSP questions frequently require a risk-based decision.
The security professional should evaluate the vulnerability, likelihood, impact and business requirements before determining the appropriate treatment.
Sample Question 4
An organization wants to determine whether its security controls are operating effectively.
Which activity is MOST appropriate?
A. Security assessment
B. Asset classification
C. Data destruction
D. User provisioning
Correct Answer: A
Explanation
Security assessment is used to evaluate whether security controls and processes are appropriately designed and/or operating as intended.
CISSP Question Analysis Techniques
Participants will practice identifying:
Keywords
Words such as:
- FIRST
- BEST
- MOST
- LEAST
- NEXT
- PRIMARY
- MOST IMPORTANT
- SHOULD
- BEFORE
- AFTER
These words can significantly change the correct answer.
Management vs Technical Thinking
A common CISSP mistake is selecting the most technically sophisticated solution.
The better answer may instead be:
- Establish policy
- Conduct risk assessment
- Obtain management approval
- Define requirements
- Assign ownership
- Perform due diligence
- Evaluate business impact
Risk-Based Thinking
When multiple answers appear reasonable, consider:
Which answer best addresses the organization's risk while supporting business objectives?
Training Methodology
The bootcamp uses an exam-oriented approach combining:
- Instructor-led explanation
- CISSP CBK discussion
- Domain-by-domain review
- Scenario-based case studies
- Real-world enterprise security examples
- Practice questions
- Question analysis
- Answer elimination techniques
- Risk-based decision making
- Management perspective
- Exam strategy
- Mock examination
Target Participants
CISSP is suitable for experienced cybersecurity and information security professionals, including:
- Chief Information Security Officers
- Information Security Managers
- Security Managers
- Security Architects
- Security Engineers
- Security Consultants
- Security Auditors
- Security Analysts
- IT Managers
- IT Directors
- Network Architects
- Risk Managers
- IT Governance Professionals
- Cybersecurity Professionals
- Information Security Professionals
ISC2 also identifies roles such as CISO, CIO, security director, IT manager, security architect, security auditor, security consultant and network architect among typical CISSP audiences.
CISSP Prerequisites and Experience Requirements
To become a CISSP, candidates must have a minimum of five years of cumulative full-time work experience in two or more of the eight CISSP domains.
One year of required experience may be waived through an applicable four-year college degree or an approved ISC2 credential/credential pathway. ISC2 updated its experience-waiver list in April 2026, so candidates should check the current official requirements when planning certification.
Candidates who do not yet have the required experience can take and pass the CISSP examination and become an Associate of ISC2, then have up to six years to obtain the required experience.
CISSP Learning Outcomes
After completing the bootcamp, participants are expected to be able to:
- Explain the eight CISSP domains
- Understand CISSP security principles
- Apply security governance principles
- Analyze information security risks
- Understand asset security requirements
- Evaluate security architecture
- Design secure network environments
- Apply IAM principles
- Understand security assessment and testing
- Manage security operations concepts
- Integrate security into software development
- Analyze scenario-based CISSP questions
- Apply risk-based decision making
- Distinguish technical solutions from management-level decisions
- Improve CISSP examination readiness
CISSP Eight-Domain Summary
| Domain | Focus |
|---|---|
| Domain 1 | Security and Risk Management |
| Domain 2 | Asset Security |
| Domain 3 | Security Architecture and Engineering |
| Domain 4 | Communication and Network Security |
| Domain 5 | Identity and Access Management |
| Domain 6 | Security Assessment and Testing |
| Domain 7 | Security Operations |
| Domain 8 | Software Development Security |
The eight-domain structure and current weighting are based on the ISC2 CISSP Exam Outline.
Duration
2 Days Intensive Bootcamp
Total: 16 Training Hours
The program is structured to provide an intensive review of all eight CISSP domains while giving significant attention to scenario-based examination techniques.
Delivery Methods
Online Live Training
Interactive instructor-led training delivered through an online classroom.
Offline Classroom Training
Face-to-face intensive CISSP preparation.
In-House Corporate Training
Customized CISSP preparation for organizations and enterprise security teams.
Training Language
Presentation Material: English
Instructor Delivery: English / Bahasa Indonesia
Practice Questions: English
Because the CISSP examination uses English and other specified languages, participants are also trained to become familiar with the terminology and question structure commonly encountered in the examination.
Training Focus
The primary focus of this CISSP bootcamp is:
Understand → Analyze → Apply → Select the BEST Answer
Rather than simply memorizing security terminology, participants learn to approach questions from the perspective of:
Business → Governance → Risk → Security Requirement → Control → Verification
This approach is particularly important for scenario-based CISSP questions.
About the Trainer
Hery Purnama – Certified Trainer
Hery Purnama is an experienced IT professional and trainer with extensive experience across:
- Information Security
- IT Governance
- IT Risk Management
- IT Audit
- Cybersecurity
- IT Service Management
- Project Management
- Compliance
- Technology Consulting
- Business Consulting
His training approach combines certification examination preparation with practical enterprise scenarios, helping participants understand not only what a security concept means, but also how and when it should be applied in an organizational environment.
Why Pursue CISSP?
CISSP provides a broad professional foundation for information security leadership and senior cybersecurity roles.
The certification validates knowledge across eight major areas of cybersecurity and demonstrates an individual's ability to address security from both technical and managerial perspectives.
CISSP is particularly relevant for professionals who want to progress toward roles involving:
- Cybersecurity leadership
- Information security management
- Security architecture
- Security governance
- Risk management
- Security operations
- Security consulting
- Enterprise security strategy
ISC2 describes CISSP as a certification for cybersecurity professionals with the knowledge and experience to lead an organization's information security program.
Start Your CISSP Certification Journey
Preparing for CISSP requires more than reading security concepts.
You need to understand the relationship between security, business, risk, governance, technology and organizational objectives.
Through this intensive 2-day bootcamp, participants will review the complete CISSP eight-domain structure, practice scenario-based questions and develop the decision-making approach required for the examination.
Build Your Knowledge. Strengthen Your Security Judgment. Prepare for CISSP.
ISC2 CISSP Exam Preparation Bootcamp
2 Days | 16 Training Hours | 8 CISSP Domains | Scenario-Based Exam Preparation
0 Komentar