LiveCISSP · 8 Domains · 2024 CAT

    Your CISSP
    defense readiness, mapped.

    Read all 8 domains right here — no third-party logins — then run a timed, scenario-based mock. Get a per-domain readiness report that shows exactly where you're exposed. Built to train the manager's mindset CISSP actually scores.

    Server-graded, no answer leaks Full 8-domain guide on-page Free to start
    How it works

    Read, test, close the gaps

    01

    Read the 8 domains

    Full study guides for every domain — governance, asset security, architecture, networks, IAM, testing, operations, and software security — rendered right here on the page.

    02

    Take a timed mock

    A 100-question, domain-weighted mock of scenario questions written from the manager's point of view — the way ISC2 actually asks them.

    03

    Get your gap report

    A per-domain and per-objective scorecard shows your strongest and weakest areas, with a full explanation for every question you missed.

    Study material · all 8 domains, on this page

    Read first. Then prove it on a mock.

    Domain-by-domain guides updated for the 2024 objectives — read them right here, then take a timed mock and get a gap report that shows exactly what to revisit.

    Domain 1 · 16% of the exam

    Security and Risk Management

    Governance, risk, compliance, ethics, BCP — the largest and most foundational domain.

    12 objectives · tap a sub-topic to expand

    1.1

    Understand, adhere to, and promote professional ethics (OSG-10 Chpts 1,19)

    • As a CISSP, you must understand and follow the (ISC)² code of ethics, as well as your organization’s own code
    1.2

    Understand and apply security concepts (OSG-10 Chpt 1)

    1.3

    Evaluate, apply, and sustain security governance principles (OSG-10 Chpt 1)

    • Security governance: the collection of policies, roles, processes/practices used to make security decisions in an org; related to supporting, evaluating, defining, and directing the security efforts of an org; it involves making sure that security strategies align with business goals, and that they are comprehensive and consistent across the organization
      • Security governance is the implementation of a security solution and a management method that are tightly interconnected
    • The security function: the aspect of operating a business that focuses on the task of evaluating and improving security over time
      • To manage security, an org must implement proper and sufficient security governance
      • The act of performing a risk assessment to drive the security policy is the clearest and most direct example of management of the security function
    • Third-party governance: external entity oversight that may be mandated by law, regulation, industry standards, contractual obligation, or licensing requirement; outside investigator or auditors are often involved
    1.4

    Understand legal, regulatory, and compliance issues that pertain to information security in a holistic context (OSG-10 Chpt 4)

    1.5

    Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards) (OSG-10 Chpt 19)

    1.6

    Develop, document, and implement security policy, standards, procedures and guidelines (OSG-10 Chpt 1)

    1.7

    Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements (OSG-10 Chpt 3)

    1.8

    Contribute to and enforce personnel security policies and procedures (OSG-10 Chpt 2)

    • People are often considered the weakest element in any security solution; no matter what physical or logical controls are deployed, humans can discover ways to avoid, circumvent/subvert, or disable them
      • Malicious actors are routinely targeting users with phishing and spear phishing campaigns, social engineering, and other types of attacks, and everybody is a target
      • Once attackers compromise an account, they can use that entry point to move around the network and elevate their privileges
      • People can also become a key security asset when they are properly trained and are motivated to protect not only themselves but the security of the organization as well
      • Part of planning for security includes having standards in place for job descriptions, job classifications, work tasks, job responsibilities, prevention of collusion, candidate screening, background checks, security clearances, employment and nondisclosure agreements
    1.9

    Understand and apply risk management concepts (OSG-10 Chpt 2)

    1.10

    Understand and apply threat modeling concepts and methodologies (OSG-10 Chpt 1)

    1.11

    Apply Supply Chain Risk Management (SCRM) concepts (OSG-10 Chpt 1)

    1.12

    Establish and maintain a security awareness, education, and training program (OSG-10 Chpt 2)

    Done reading? Put it to the test with a full timed mock.

    Why most retakes happen

    The best technical answer is usually the wrong CISSP answer.

    CISSP rarely fails people on facts — it fails them on mindset. Answer as a risk-aware manager, not a hands-on technician: protect life first, follow policy, weigh cost against risk, and govern before you reach for a tool. Every mock question here is written and scored that way.

    Access

    Reading is free. Go deeper with Edge.

    Free

    ₹0

    Read + one full mock

    • All 8 domains of study material
    • 1 full 100-Q mock exam
    • Score + domain breakdown
    • Preview of full gap analysis
    MOST POPULAR

    GCCERA Edge

    Included

    Everything unlocked

    • 3 mock exams
    • Full objective-level gap report
    • Every wrong-answer explanation
    • Difficulty & strongest/focus breakdown

    Not affiliated with or endorsed by ISC2. CISSP is a registered mark of ISC2, Inc. Study guides adapted from jefferywmoore/CISSP-Study-Resources (Apache-2.0). Practice questions are original, written by GCC ERA for exam preparation.

    Don't fail twice. Know where you stand.

    Read the domains, take one honest mock, and get a clear map of what to study — before exam day.