To understand these changes lets first go two versions back CISSP 2012 made from 10 Domains:
- Information Security Governance and Risk Management
- Access Control
- Security Architecture and Design
- Physical and Environmental Security
- Telecommunications and Network Security
- Cryptography
- Business Continuity and Disaster Recovery
- Legal, Regulations, Compliance, and Investigations
- Software Development Security
- Security Operations
In 2015 new changes happened to CISSP and the 10 domains became 8 domains:
- Security and Risk Management
- Asset Security
- Security Engineering
- Communication and Network Security
- Identity and Access Management
- Security Assessment and Testing [the official book is 1304 pages, this domain is 49 pages ONLY!!]
- Security Operations
- Software Development Security
Summary for what happened in 2015:
- No topics were REMOVED from the exam.
- New topics were added to the exam.7% such as:
- Talking about SCADA & Dnp3 protocol, IoT
- More about Converged protocols (e.g., FCoE, MPLS, VoIP, iSCSI)
- New Investigation types, Asset types
- DevOps , Agile and Scrum overview
- Attribute-based access control ABAC
- The Book was condensed from 10 domains to 8 domains but the content was not removed. It was simply restructured
In April 2018 few changes happened again, But we still have 8 domains:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
Summary for what happened in 2018:
- “Security Engineering” Domain name changed to “Security Architecture and Engineering”
- No topics were REMOVED from the exam.
- Only 1% New topics were added to the exam and Official Book.
- Content restructured again.
- Domains weight changed in the exam
Domain Average Weight in CAT exam
Security and Risk Management 15%
Asset Security 10%
Security Architecture and Engineering 13%
Communication and Network Security 14%
Identity and Access Management (IAM) 13%
Security Assessment and Testing 12%
Security Operations 13%
Software Development Security 10%
So Nothing really changed from 2015 version to 2018 version, just remember that exam now in CAT format since December 2017