The CISSP study plan: eight weeks, weighted like the exam
A week-by-week schedule for the April 2024 CISSP outline. It spends your hours where the exam spends its points, uses six full practice tests as checkpoints, and shows how to review each one so your score actually moves.

Before you start
Know which exam you are training for. The CISSP outline in force is the one ISC2 made effective on April 15, 2024. It has eight domains and 62 numbered objectives, from 1.1 (professional ethics) to 8.5 (secure coding guidelines). ISC2's outline page also says it continues to weave AI-specific security tasks into all eight domains, such as prompt injection, data poisoning and model drift, without changing the weights.
Know the format. Every CISSP exam, in every language, is a computerized adaptive test (CAT): between 100 and 150 items in a maximum of three hours, including 25 unscored pretest items you cannot tell apart from the rest. You cannot go back to change an answer. If any of that is new, read how the CISSP CAT exam works first, because it changes how you should practice.
Know the experience rule. Certification requires five years of cumulative, full-time experience in two or more of the eight domains. A relevant degree or a credential from ISC2's approved list can cover one year, and only one. You can still take the exam before you have the experience: passing makes you an Associate of ISC2, with six years to earn it. After you pass, you have nine months to complete the endorsement application.
Set an honest target. The pass mark is 700 on a scale of 1,000. That is a scaled score, not 70% correct, and on an adaptive exam everyone answers roughly half of the items correctly because the test keeps adjusting to them. Nobody outside ISC2 can convert a practice score into a scaled score. This plan uses 75% on full practice tests you have not seen before as a practice target, because a steady margin on unseen questions is the best signal you can measure yourself.
Where the points are
ISC2 builds every exam to these weights, whether it stops at 100 items or runs to 150. One domain is clearly heavier; the rest are close together.
The 8-week CISSP study plan
About 10 hours a week. Each week pairs reading with daily scenario questions, and six weeks end with a full practice test you review the same week.
- W1
Baseline and Security and Risk Management, part 1
Take practice test 1 cold, timed, before you study anything. Review it fully. Then start Domain 1: the ISC2 Code of Ethics and its four canons in order, the security concepts, governance principles, roles and responsibilities, due care and due diligence, and the legal, regulatory and privacy objectives.
- W2
Security and Risk Management, part 2, and Asset Security
Investigation types, policy, standards, procedures and guidelines, business continuity requirements and the BIA, personnel security, risk management, threat modeling, supply chain risk and awareness programs. Then Domain 2: classification, handling, data roles, the data lifecycle, retention and data states.
- W3
Security Architecture and Engineering
Secure design principles, security models such as Bell-LaPadula and Biba, selecting controls, the vulnerabilities of each system type from ICS to serverless, cryptographic solutions and cryptanalytic attacks, site and facility controls and the system lifecycle. Take and review practice test 2.
- W4
Communication and Network Security
OSI and TCP/IP, secure protocols, segmentation from VLANs to micro-segmentation, wireless and cellular, SDN and VPCs, network components and secure channels for voice, remote access and third-party connections. Learn the reasoning, not port trivia.
- W5
Identity and Access Management, and Security Assessment and Testing
Authentication strategy, federation, authorization models (RBAC, rule-based, MAC, DAC, ABAC, risk-based) and the provisioning lifecycle. Then assessment and audit strategy, control testing, process data, reporting and audits. Take and review practice test 3.
- W6
Security Operations
Investigations and evidence, logging and monitoring, configuration and change management, incident management steps, patching, recovery strategies, DR processes and tests, BC exercises, physical security and personnel safety. Take and review practice test 4.
- W7
Software Development Security and your weak spots
Security in the SDLC, development ecosystems and CI/CD, software security testing, acquired and open-source software, secure coding and API security. Spend the second half of the week on your two lowest domains. Take and review practice test 5.
- W8
Dress rehearsal
Take practice test 6 early in the week as a timed rehearsal, answering each item once with no going back. Review it, reread your list of missed rules, and rest the day before the exam. Book when your unseen test scores sit at or above your target.
How to review a practice test
Reviewing a test well takes about as long as taking it. That review is where the score moves.
- 1
Sort every item into three piles
Wrong; right but guessed; right and sure. The first two piles are your study list, because a lucky guess hides a gap the score does not show.
- 2
Read the explanation for every option
CISSP distractors are usually real security actions at the wrong moment: a technical fix before the risk is understood, an escalation before the facts, a tool before the policy. Learn why each one loses in that scenario.
- 3
Write the rule you missed in one line
For example: people's safety comes first; management owns the risk decision; classify before you protect. After two tests the same few rules repeat. Those are your real weak spots.
- 4
Move next week's hours to the gap
Compare your results by domain and shift time toward the lowest one before the next test.
Adjust the plan to your situation
| Practice test | When | What you are looking for |
|---|---|---|
| 1 | Week 1, before studying | A baseline and your weakest domain |
| 2 | End of week 3 | Whether Domains 1 to 3 have moved |
| 3 | End of week 5 | Network, identity and testing gaps |
| 4 | End of week 6 | Operations, incident and recovery reasoning |
| 5 | End of week 7 | Software security and your weak-spot work |
| 6 | Week 8 | A timed rehearsal at or above your target |
Practice the way the exam is delivered
Answer once. The CAT exam does not let you review or change an answer. From week 3 onward, take your practice tests without going back, so committing to an answer becomes a habit.
Pace yourself. Three hours for up to 150 items is 72 seconds per item if you reach the maximum. The course tests have 125 questions in 150 minutes, the same pace. Breaks are allowed but count against the three hours.
Think like a manager. Most CISSP items ask what to do FIRST or what is BEST. Read the guide on the CISSP manager mindset before your first review, and try the 10 free CISSP questions to see the style.
Six practice tests for six checkpoints
750 original CISSP questions in six 125-question tests, weighted like the April 2024 outline, with every option explained for your reviews.
CISSP study plan FAQ
How long should I study for the CISSP?
It depends on your experience and weekly hours. This plan assumes about 10 hours a week over eight weeks for someone already working in security; with less time or less experience across the domains, stretch the same steps to twelve weeks.
Which CISSP domain should I study most?
Security and Risk Management, at 16%, is the heaviest. The other six domains sit between 10% and 13%, so none can be skipped. ISC2 builds every exam to the outline's domain weights, whatever its length.
What score should I get on practice tests before booking?
ISC2 scores the exam on a 700 out of 1,000 scale and does not convert it to a percentage. This plan uses 75% on practice tests you have not seen before as its own readiness target. It is a benchmark, not an ISC2 number.
Do I need five years of experience before taking the exam?
No. You can sit the exam without it. If you pass without the required experience, you become an Associate of ISC2 and have six years to earn the five years of experience in two or more domains.
Which book should I use?
ISC2 publishes a list of suggested references, including the Official ISC2 Guide to the CISSP CBK, but says it does not endorse any particular text or author. Use a reference book to fix weak areas and spend most of your time on scenario practice.
More guides: CISSP manager mindset · CISSP CAT exam explained · Free CISSP practice questions · all guides