Security Operations
Domain 7 is day-to-day security: investigations and forensics, logging and monitoring, configuration and change management, foundational operations concepts, incident management, patching, recovery strategies, DR testing and physical and personnel safety.
Investigations and evidence
Evidence must be collected in an order that preserves the most fragile data first, handled so its integrity can be shown, and analyzed on copies. Rushing to shut a system down can destroy the evidence you need.
Monitoring, configuration and change
Detection relies on IDPS, logs and SIEM, tuned to balance false positives against false negatives. Configuration management sets approved baselines and detects drift; change management keeps even emergency changes under control.
Patch and vulnerability management
Patching is the only response that removes a vulnerability without removing functionality, but it is not always immediately possible. When a patch is late or will never come, other responses must carry the load.
Recovery strategies and DR testing
Recovery design matches backup methods and alternate sites to the RTO and RPO from the BIA, trading cost against speed. Plans are then exercised, from discussion-based tabletop sessions to functional and full-scale exercises.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.