Security Assessment and Testing
Domain 6 covers designing assessment and audit strategies, testing security controls, collecting security process data, reporting results and handling exceptions, and conducting internal, external and third-party audits.
Testing techniques
NIST groups technical assessment techniques into review techniques, which passively examine documentation, logs, rulesets and configurations; target identification and analysis, which discovers hosts, ports and potential vulnerabilities; and target vulnerability validation, which confirms them, for example by penetration testing.
Security process data and logs
Beyond technical tests, assessors collect evidence that processes work: account management, backup verification, training, DR/BC testing and management review. Logs are only useful as evidence if they are complete, protected and time-consistent.
Reporting, remediation and exceptions
Findings are prioritized by risk, remediated or formally handled as exceptions, and sometimes disclosed to outside parties. Unfixable findings do not disappear; they are tracked and accepted by the accountable official.
Audits and assessors
Audits may be internal, external or third-party, and on-premises, cloud or hybrid. The value of an assessment depends on the assessor's independence and on what the report actually covers.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.