Contents
Featured Posts
1. The Strategic Role of CISSP

2. CISSP Domains of Knowledge

CISSP is one of the most challenging exams ever because of its comprehensive perspectives and requirements of solid conceptual level understanding and in-depth insights into managerial and technical issues.
- Think Like a Manager!
It’s comprehensive, and you have to think from a variety of perspectives, such as board director, senior management, CISO, auditor, legal counsel, purchasing and HR staff, engineer, developer, project and program manager, end-user, attacker, and so forth. Experience or certifications of PMP, ITIL/ITSM, or CCNA help quite a bit. - But You Need to Know Technologies!
The CISSP exam, from my point of view, can be divided into two parts: management (Domain 1, 2, 5, 6, and 7) and technology (Domain 3, 4, and 8). It’s a body of knowledge, not a collection of discrete knowledge points.
3. Amicliens InfoSec Conceptual Model
- Build your own blueprint or conceptual model (e.g., Amicliens InfoSec Conceptual Model) in one week by skimming, browsing, speed-reading your study guide, mentoring, tutoring, training, or any other approaches available.
- Base your learning on the model and study topic by topic iteratively and progressively. This is the Agile way to increase knowledge (value) iteratively.
- After you have informed and enriched your conceptual model, it’s about time to read your study guide from cover to cover.
- Review the CISSP exam outline every day to ensure you are on the right track and measure your progress.
- Practice questions in Sudoku 365 (Wentz QOTD) until you understand the concepts behind each question and score higher than 80%. This approach is called test-driven.
Progressive Learning in Parallel (like the right-hand side). That is, read each domain progressively and in parallel like the right-hand side of animation depicts. Most people tend to read domain by domain like the left-hand side.

4. CISSP Exam Preparation Strategy

The critical success factors of CISSP are the effectiveness of your study plan, persistence, discipline, and communication with and support from your family and boss.
Exam Preparation Tips
5. CISSP Exam Preparation Materials
- To start your CISSP journey, please download The CISSP Exam Outline first. Read and explain it to your friends until you can do that well and feel confident.
- The Effective CISSP: Security and Risk Management is a CISSP starter book as a supplement to the official and other study guides. It helps you build a solid foundation for information security and risk management.
- The Sybex CISSP Official Study Guide (OSG) 8th is a tutorial to help you understand the CISSP exam outline.
- The Official ISC2 Guide to the CISSP CBK Reference 5th, also known as CBK, explains the CISSP exam outline in detail. When in doubt, refer to the CBK.
- It’s crucial to browse the CBK suggested references, the NIST Special Publications, and CISSP notes.
6. The Effective CISSP Series
My book, The Effective CISSP: Security and Risk Management, helps CISSP aspirants build a solid conceptual security model. It is not only a tutorial for information security but also a study guide for the CISSP exam and an informative reference for security professionals. Please visit Wentz’s Publications for details.
*** The CISSP Test-Driven Study Strategy
7. CISSP Starter Resource Kit
Study Guides
- The Effective CISSP: Security and Risk Management (Starter/Orientation)
- (ISC)2 CISSP Official Study Guide, 8th Edition (OSG) (Primary Source)
The following are optional materials:
- CISSP All-in-One Exam Guide, 8th Edition (AIO) (Secondary Source)
- The Official (ISC)2 Guide to the CISSP CBK Reference, 5th Edition (CBK) (When in doubt)
Videos
- (ISC)² Certification Webcasts
- Kelly Handerhan@Cybrary
- CISSP Shon Harris
- CISSP Domain 2 Review by Destination Certification
Notes
- Sunflower CISSP™ 2019 PDF Document by Frankrijker, Reina & Warnock
- CISSP Process Guide V.21, 2020 by Fadi Sodah (aka Madunix)
- Memory Palace CISSP Notes by Prashant Mohand
- Lance’s CISSP Notes
- TOP 10 TIPS for the CISSP exam by Luis Alejandro Sosa
8. Practice Question (Wentz QOTD)
Kindle Books and Paperback
I suggest doing practice questions in the following order:
- CISSP Official (ISC)2 Practice Tests
- How To Think Like A Manager for the CISSP Exam (Kindle)
- The Effective CISSP: Practice Questions (CISSP Sudoku 365)
QOTD (Question Of The Day)
Test Engine
9. CISSP Communities
The Effective CISSP Groups
- Effective CISSP Group Rules
- Effective CISSP Facebook Group
- Effective CISSP in Taiwan Facebook Group (中文)
- Effective CISSP Telegram Group
- Effective CISSP YouTube Channel
Facebook Groups
- The Effective CISSP Facebook Group
- CISSP Exam Preparation – Study Notes and Theory
- CISSP, CISM and PMP certification training by Thor Teaches!
- Information Audit
Chat Rooms
Forums
10. Other CISSP Resources
- NIST Glossary
- Wentz’s Glossary
- Rainbow Series
- ISC2 CISSP Glossary – Student Guide
- SNT Study Resources
- Thor Teaches Study resources