Free · printable · no signup
CISSP (Certified Information Systems Security Professional) Exam Cheat Sheet (2026)
A free, printable CISSP (Certified Information Systems Security Professional) exam cheat sheet: the 115 highest-yield points to know, grouped into 8 sections that follow the exam's content areas, each section with its published weight.
- Free to read, print and keep — no signup, no email, no paywall.
- 115 of the 115 points carry a citation to the rule they come from.
- The real CISSP (Certified Information Systems Security Professional) exam: 180 minutes.
- Prints from your browser (Ctrl-P, or Cmd-P on a Mac) — the navigation, buttons and links drop out of the printed copy.
- 122 free CISSP (Certified Information Systems Security Professional) practice questions on the same material, every one explained.
- Last updated: September 2026.

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.
Security and Risk Management
16% of the exam- Four canons
- Protect society, the common good, necessary public trust and confidence, and the infrastructure; act honorably, honestly, justly, responsibly and legally; provide diligent and competent service to principals; advance and protect the profession.· ISC2 Code of Ethics
- Duty to report
- Members who observe another member breaching the Code are obligated to follow the ethics complaint procedure; failing to do so may itself breach Canon IV.· ISC2 Code of Ethics
- Standing to complain
- Anyone may complain about Canons I or II, only principals (employer/contractor relationship) about Canon III, and only other ethics-bound professionals about Canon IV.· ISC2 Ethical Complaint Procedures
- Nonrepudiation
- A service that gives evidence of origin (or receipt) so a party cannot falsely deny having sent (or received) data.· RFC 4949 Internet Security Glossary
- Mission first
- Understanding the organizational mission is the first Organizational Context outcome and informs cybersecurity risk management.· NIST CSF 2.0 GV.OC-01
- GDPR breach notice
- A controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a breach, unless the breach is unlikely to result in a risk to individuals.· GDPR Art. 33(1)
- Transborder transfers
- A transfer to a country covered by a Commission adequacy decision needs no specific authorisation; otherwise safeguards such as standard clauses or binding corporate rules apply.· GDPR Art. 45–46
- Idea versus expression
- Copyright protects the expression of a work, never the underlying idea, procedure, process or method of operation.· 17 U.S.C. §102(b)
- MTD, RTO, RPO
- MTD is how long a process can be disrupted before impact is unacceptable; RTO is how long a supporting system may be down; RPO is the point in time to which data must be recoverable.· NIST SP 800-34 Rev. 1 §3.2
- External dependencies
- The BIA should capture the suppliers and services a process relies on, because their recovery capability limits yours.· ISC2 CISSP Exam Outline 1.7
- Termination
- On termination, disable system access within a defined period, revoke credentials, conduct an exit interview and retrieve organizational property.· NIST SP 800-53 Rev. 5 PS-4
- External personnel
- Security requirements for contractors and service providers are established and documented, typically in contracts.· NIST SP 800-53 Rev. 5 PS-7
- Four responses
- Organizations can accept, avoid, mitigate, or share/transfer risk, or combine them.· NIST SP 800-39 Task 3-1
- Transfer is not reduction
- Transferring risk (e.g., insurance) shifts liability but reduces neither the likelihood of harm nor its consequences.· NIST SP 800-39 Task 3-1
- Accept within tolerance
- Acceptance is appropriate when the risk is within organizational risk tolerance; avoidance when it exceeds tolerance and no practical safeguard exists.· NIST SP 800-39 Task 3-1
- Model threats at design
- Use threat modeling or attack-surface mapping during design to assess security risk in software.· NIST SP 800-218 PW.1.1
- SBOM
- A formal record of the components, and their supply chain relationships, used to build software.· NIST SP 800-161r1 glossary (from E.O. 14028)
Asset Security
10% of the exam- Inventories
- Maintain inventories of hardware, of software, services and systems, and of data; prioritize assets by classification and criticality.· NIST CSF 2.0 ID.AM-01/02/05/07
- Information owner
- The official with authority for specified information who sets the policies for its collection, processing, dissemination and disposal.· NIST SP 800-37 Rev. 2 App. D
- FIPS 199 categorization
- Rate potential impact (low, moderate, high) for confidentiality, integrity and availability; a system takes the highest value for each objective across its information types.· FIPS 199 §3
- Controller and processor
- The controller determines the purposes and means of processing; the processor processes personal data on the controller's behalf.· GDPR Art. 4(7)–(8)
- Pseudonymised data
- Data that can be attributed to a person with additional information is still information about an identifiable person.· GDPR Art. 4(5); Recital 26
- Data minimisation
- Personal data must be adequate, relevant and limited to what is necessary for the purpose.· GDPR Art. 5(1)(c)
- Retention example
- HIPAA Security Rule documentation is retained for six years from creation or the date last in effect, whichever is later.· 45 CFR §164.316(b)(2)(i)
- Tailoring
- Tailoring includes applying scoping considerations, selecting compensating controls and supplementing the baseline, with documented justification.· NIST SP 800-37 Rev. 2 Task S-2
- End of support
- When software reaches end-of-life, patches will never be released, so other risk responses such as isolation or replacement are required.· NIST SP 800-40 Rev. 4 §2
- Data protection tools
- The outline groups DRM, DLP and CASB as data protection methods chosen according to data state and location.· ISC2 CISSP Exam Outline 2.6
- Clear
- Logical techniques through the normal interface that protect against simple, non-invasive recovery; not appropriate for hard copy.· NIST SP 800-88 Rev. 2 §3.1.1
- Purge
- Makes recovery infeasible even with state-of-the-art laboratory techniques while leaving the media reusable, e.g., dedicated sanitize commands or cryptographic erase; prefer it to clear when possible.· NIST SP 800-88 Rev. 2 §3.1.2
- No degaussing flash
- Degaussing should not be used on non-magnetic media such as SSDs.· NIST SP 800-88 Rev. 2 §3.1.2
- Cloud storage
- For logical or virtual storage, cryptographic erase may be the only viable purge option.· NIST SP 800-88 Rev. 2 §3.1.2
- Destroy
- Renders data unrecoverable and the media unusable; appropriate for all hard copy and most media.· NIST SP 800-88 Rev. 2 §3.1.3
Security Architecture and Engineering
13% of the exam- Least privilege
- Grant each entity only the minimum resources and authorizations it needs to do its work.· RFC 4949
- Fail in a known state
- Components fail to a defined safe state so failures do not cause loss of confidentiality, integrity or availability.· NIST SP 800-53 Rev. 5 SC-24
- No implicit trust
- Zero trust grants no implicit trust to assets or accounts based solely on physical or network location.· NIST SP 800-207 §2
- PE, PA, PEP
- The policy engine decides and logs, the policy administrator executes the decision, and the policy enforcement point enables, monitors and terminates connections.· NIST SP 800-207 §3
- Simple security property
- Read access only if the subject's clearance dominates the object's classification (no read up).· RFC 4949
- *-property
- Write access only if the object's classification dominates the subject's clearance (no write down).· RFC 4949
- Biba
- Integrity levels; a subject may not modify an object at a higher or incomparable integrity level.· RFC 4949
- Brewer-Nash
- Enforces the Chinese wall: after reading one firm's data, a subject cannot read a competitor's in the same conflict class.· RFC 4949
- IaaS
- The consumer controls operating systems, storage and deployed applications but not the underlying infrastructure.· NIST SP 800-145
- SaaS
- The consumer controls at most limited user-specific application settings.· NIST SP 800-145
- Essential characteristics
- On-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.· NIST SP 800-145
- AES
- 128-bit blocks with 128-, 192- or 256-bit keys.· FIPS 197
- Cryptoperiod
- The time span during which a specific key is authorized for use.· NIST SP 800-57 Part 1 Rev. 5 §5.3
- Revocation
- Certificates can become invalid before expiry, for example on key compromise; the CA revokes them and publishes status such as CRLs.· RFC 5280
- Salting
- A per-password random salt makes offline dictionary attacks harder because precomputed values cannot be reused.· RFC 4949
- Post-quantum
- FIPS 203 (ML-KEM) addresses the risk that large quantum computers could break factoring- and discrete-log-based public-key schemes, including elliptic curve.· FIPS 203 §1.2
Communication and Network Security
13% of the exam- IPv6 address types
- Unicast, anycast (delivered to the nearest of a set) and multicast (delivered to all of a set); there is no broadcast.· RFC 4291 §2
- AH versus ESP
- AH provides integrity and data origin authentication; ESP adds confidentiality.· RFC 4301 §3.2
- Transport versus tunnel
- Transport mode protects the next-layer payload; tunnel mode protects the whole encapsulated IP packet, as between gateways.· RFC 4301
- TLS 1.3
- Static RSA and Diffie-Hellman suites are removed; all public-key key exchanges provide forward secrecy.· RFC 8446 §1.2
- DNSSEC
- Adds origin authentication and integrity to DNS data, not confidentiality or protection from denial of service.· RFC 4033
- Micro-segmentation
- Enforcing policy between individual workloads limits lateral movement inside a data center.· ISC2 CISSP Exam Outline 4.1; NIST SP 800-207
- SDN planes
- SDN separates the forwarding plane from the control plane, with control logic in controllers.· RFC 7426
- Anti-spoofing at the edge
- Filter traffic so that packets leaving a network carry only its legitimately assigned source addresses.· RFC 2827 (BCP 38)
- iSCSI
- Carries SCSI storage over TCP/IP; protect it with authentication such as CHAP, IPsec and isolation.· RFC 7143 §9
- Jitter
- IP packet delay variation, the variation in delay between packets.· RFC 3393
- Converged examples
- The outline names iSCSI, VoIP, InfiniBand over Ethernet and Compute Express Link as converged protocols.· ISC2 CISSP Exam Outline 4.1
- 802.1X roles
- Supplicant (device), authenticator (switch or access point) and authentication server (typically RADIUS).· IEEE 802.1X
- SSH
- A protocol for secure remote login and other secure services over an insecure network, replacing cleartext tools such as Telnet.· RFC 4251
- Split tunneling
- Sending only internal traffic through the VPN stops the organization inspecting or protecting the rest and can bridge trusted and untrusted networks.· NIST SP 800-46 Rev. 2
Identity and Access Management (IAM)
13% of the exam- Password length
- At least 15 characters for passwords used as a single factor; at least 8 when used only within multi-factor authentication.· NIST SP 800-63B-4 §3.1.1.2
- No composition or rotation rules
- No character-mix rules and no periodic changes; force a change on evidence of compromise and check against a blocklist.· NIST SP 800-63B-4 §3.1.1.2
- Phishing resistance
- Manually entered OTP and out-of-band codes are not phishing-resistant; channel binding (e.g., PIV/CAC) or verifier name binding (e.g., WebAuthn) are.· NIST SP 800-63B-4 §3.2.5
- Authentication fatigue
- Approve-only push prompts are no longer acceptable; the secret must be transferred between the out-of-band device and the primary channel.· NIST SP 800-63B-4 §3.1.3
- OAuth 2.0
- A client obtains an access token from an authorization server to reach protected resources on the resource owner's behalf, without the owner's credentials.· RFC 6749
- Kerberos tickets
- A ticket-granting ticket from the authentication service is used to obtain service tickets.· RFC 4120
- Kerberos clocks
- Clocks must be loosely synchronized because timestamps are checked within a clock-skew window to detect replay.· RFC 4120 §3.2.3
- MAC
- Compares security labels with clearances; an entity cannot by its own volition grant others access.· RFC 4949
- DAC
- Access based on identity, with an owner who may grant and revoke access rights.· RFC 4949
- ABAC
- Evaluates attributes of subject, object and environment against policy.· NIST SP 800-162
- Risk-based
- Dynamic policy can weigh behavioral and environmental signals such as location, time and device state.· NIST SP 800-207 §2.1
- Account management
- Notify account managers on termination or transfer, review accounts periodically, and align account management with personnel processes.· NIST SP 800-53 Rev. 5 AC-2
- Transfers
- On reassignment, review whether existing access is still needed.· NIST SP 800-53 Rev. 5 PS-5
- Privileged use
- Log the execution of privileged functions, and have administrators use non-privileged accounts for non-security tasks.· NIST SP 800-53 Rev. 5 AC-6(9), AC-6(2)
- Reauthentication at AAL3
- The overall reauthentication timeout at AAL3 is no more than 12 hours.· NIST SP 800-63B-4 §2.3.3
Security Assessment and Testing
12% of the exam- Scan versus penetration test
- Scanning identifies potential vulnerabilities; penetration testing tries to exploit them to confirm existence and impact.· NIST SP 800-115 §4–5
- Four phases
- Penetration testing can be viewed as planning, discovery, attack and reporting; no testing occurs in planning, where rules, approval and goals are set.· NIST SP 800-115 §5.2
- Review techniques
- Documentation, log, ruleset and configuration reviews examine systems passively.· NIST SP 800-115 §3
- Backups are validated
- Backups should be stored offsite, rotated and periodically validated.· NIST SP 800-34 Rev. 1
- Time synchronization
- Synchronize logging hosts' clocks to a common time source so events can be correlated.· NIST SP 800-92
- Centralized logging
- Use log management infrastructure with centralized log servers.· NIST SP 800-92
- Prioritize by risk
- A fix is higher priority when it reduces risk more; low-risk flaws on a few low-importance assets rank lower.· NIST SP 800-40 Rev. 4
- POA&M
- Weaknesses not yet remediated are tracked in a plan of action and milestones, and residual risk is accepted by the authorizing official.· NIST SP 800-37 Rev. 2
- Coordinated disclosure
- Report vulnerabilities to the vendor and coordinate publication with remediation.· ISO/IEC 29147
- Assessor independence
- Select control assessors for both technical expertise and the level of independence required.· NIST SP 800-37 Rev. 2 Task A-1
- SOC 2 Type 1 versus Type 2
- Type 1 addresses control design at a point in time; Type 2 adds operating effectiveness over a period.· AICPA SOC 2 guide
- Server-side enforcement
- Access control is only effective in trusted server-side code, so interfaces such as APIs are tested directly.· OWASP Top 10:2025 A01 Broken Access Control
Security Operations
13% of the exam- Order of volatility
- Registers and cache; routing and ARP tables, process table, kernel statistics and memory; temporary file systems; disk; remote logs; physical configuration; archival media.· RFC 3227 §2.1
- Don't shut down early
- Do not shut down until evidence collection is complete; evidence may be lost and attackers may alter shutdown routines.· RFC 3227 §2.2
- Work on copies
- Make a bit-level copy for analysis, because analysis alters access times.· RFC 3227 §2
- Chain of custody
- Document each person who handled evidence, when it was transferred and why.· NIST SP 800-72 / 800-101 Rev. 1 glossary
- Detection trade-off
- Reducing false negatives usually increases false positives, and vice versa.· NIST SP 800-94 §2.2
- Signature versus anomaly
- Signatures catch known threats; anomaly-based detection compares activity to a baseline and can flag new attacks.· NIST SP 800-94 §2.3
- Emergency changes
- Unscheduled changes are still managed and go through change control after the fact, with a security impact analysis.· NIST SP 800-128 §3.3
- Separation of duties
- Divide process steps so no single entity can subvert the process alone.· RFC 4949; NIST SP 800-53 Rev. 5 AC-5
- Patching removes the flaw
- Installing a patch, update or upgrade is the only risk response that completely eliminates a vulnerability without removing functionality.· NIST SP 800-40 Rev. 4 §2
- When patching is not viable
- A patch may not exist yet or the software may be end-of-life; use other risk responses such as mitigation or isolation.· NIST SP 800-40 Rev. 4 §2
- Prioritize patches
- Deploy first the patches that reduce the most risk.· NIST SP 800-40 Rev. 4
- Differential versus incremental
- A differential holds changes since the last full backup (restore full + last differential); an incremental holds changes since the last backup of any type (restore full + every incremental).· NIST SP 800-34 Rev. 1 §5.1.2
- Alternate sites
- Cold sites provide space and infrastructure; warm sites add equipment; hot sites are fully operational with current software; mirrored sites add real-time mirroring at the highest cost.· NIST SP 800-34 Rev. 1 §3.4.3, §5.1.5
- Tabletop versus functional
- Tabletop exercises are discussion-based; functional exercises have staff perform their duties in a simulated operational environment.· NIST SP 800-34 Rev. 1 §3.5.3
Software Development Security
10% of the exam- SSDF groups
- Prepare the Organization (PO), Protect the Software (PS), Produce Well-Secured Software (PW), Respond to Vulnerabilities (RV).· NIST SP 800-218 §2
- Toolchains
- Implement supporting toolchains so security checks are automated in the development process.· NIST SP 800-218 PO.3
- CMM levels
- Initial, Repeatable, Defined, Managed, Optimizing.· SEI CMM for Software v1.1
- Protect code
- Store all forms of code with restricted access to prevent unauthorized access and tampering.· NIST SP 800-218 PS.1
- Release integrity
- Make integrity verification information, such as hashes and signatures, available to acquirers.· NIST SP 800-218 PS.2.1
- Components
- Inventory component versions continuously and use software composition analysis to automate tracking of known vulnerabilities.· OWASP Top 10:2025 A03 Software Supply Chain Failures
- Review and test
- Review or analyze human-readable code (PW.7) and test executable code (PW.8).· NIST SP 800-218 PW.7, PW.8
- Intake
- Gather vulnerability information from acquirers, users and public sources.· NIST SP 800-218 RV.1.1
- Root cause
- Analyze vulnerabilities to identify root causes and similar weaknesses.· NIST SP 800-218 RV.3
- Injection
- Prefer safe APIs and parameterized interfaces; add positive server-side input validation.· OWASP Top 10:2025 A05 Injection
- Access control
- Deny by default and enforce record ownership in server-side code; guard against insecure direct object references.· OWASP Top 10:2025 A01 Broken Access Control
- Supplier requirements
- Communicate security requirements to third-party suppliers of software.· NIST SP 800-218 PO.1.3
Now prove you know them
Reading an outline is not the same as recalling it under exam pressure. Drill the free CISSP (Certified Information Systems Security Professional) questions to find the areas you keep missing, then sit a full timed mock.
Study aid, not a substitute for the official material — always confirm the current rule with ISC2.