ISC2 CISSP

A free, self-paced 18 module training curriculum for ISC2 CISSP, built for security practitioners preparing across all eight ISC2 CBK domains. Completing every module issues a printable 18.0 contact hour certificate from TECHLEAD 187 LLC.

Domains covered

Module syllabus

  1. 1.1 Professional Ethics & Security Governance
    Understand the ISC2 Code of Professional Ethics, organizational governance principles, and alignment of security function to business strategy, mission, and objectives.
  2. 1.2 Security Concepts & Risk Management
    Apply confidentiality, integrity, availability, authenticity, and nonrepudiation principles; understand threat/vulnerability identification, risk assessment, and risk response strategies (accept, avoid, reduce, transfer).
  3. 1.3 Legal, Regulatory & Compliance
    Understand cybercrimes, data breaches, privacy regulations (GDPR, CCPA), import/export controls, transborder data flow, contractual requirements, and industry standards compliance.
  4. 2.1 Data Classification & Asset Management
    Identify and classify information and assets; establish asset ownership, inventory management (tangible and intangible), and appropriate handling requirements based on data classification levels.
  5. 2.2 Data Lifecycle & Protection Controls
    Manage data through its lifecycle (collection, location, maintenance, retention, remanence, destruction); implement data protection methods (DRM, DLP, CASB) appropriate to data states (at rest, in transit, in use).
  6. 3.1 Secure Design Principles & Threat Modeling
    Apply secure design principles (least privilege, defense in depth, secure defaults, fail securely, SoD, zero trust); understand threat modeling concepts and implement security models (Bell-LaPadula, Biba, Clark-Wilson).
  7. 3.2 Cryptography & PKI
    Select and determine cryptographic solutions; understand cryptographic lifecycle, methods (symmetric, asymmetric, elliptic curves, quantum), PKI infrastructure, key management, digital signatures, and cryptanalytic attacks.
  8. 3.3 Security Vulnerabilities in Modern Architectures
    Assess and mitigate vulnerabilities in diverse system architectures including cloud (SaaS, IaaS, PaaS), IoT, containerization, serverless, microservices, ICS, and edge computing systems.
  9. 4.1 Network Design & Transmission Security
    Design secure network architectures; understand network segmentation, defense in depth, secure communication protocols (TLS, VPN); establish transmission security controls for data in transit.
  10. 4.2 Remote Access & Secure Connectivity
    Implement secure remote access controls (VPNs, zero trust network); understand IPSec, SSL/TLS, 802.1X authentication; manage secure connectivity for distributed workforces and IoT devices.
  11. 5.1 Authentication & Identity Management
    Implement authentication mechanisms (MFA, biometrics, certificates); manage identity lifecycle; understand authentication factors and assurance levels per NIST SP 800-63B.
  12. 5.2 Access Control & Authorization
    Implement access control models (DAC, MAC, RBAC, ABAC); manage authorization using least privilege principles; implement privilege access management (PAM) and privileged account controls.
  13. 6.1 Vulnerability Assessment & Penetration Testing
    Conduct vulnerability assessments and penetration testing; understand assessment methodologies, scope definition, exploitation ethics, and remediation prioritization.
  14. 6.2 Security Audits & Compliance Testing
    Perform security audits and compliance testing; understand audit procedures, control testing methodologies, compliance frameworks (ISO 27001, SOC 2), and audit evidence collection.
  15. 7.1 Security Monitoring & Event Management
    Establish security monitoring and logging infrastructure; implement SIEM solutions; understand log analysis, event correlation, and continuous monitoring for threat detection.
  16. 7.2 Incident Response & Business Continuity
    Develop incident response plans and procedures; understand detection, containment, eradication, and recovery; implement business continuity and disaster recovery strategies.
  17. 8.1 Secure Development Lifecycle (SDLC)
    Implement secure SDLC practices; understand threat modeling in development, secure coding standards, code review processes, and security testing throughout the development pipeline.
  18. 8.2 Application Security & Vulnerability Management
    Identify and remediate application vulnerabilities; understand OWASP Top 10, input validation, output encoding, injection attacks, and application security testing (SAST, DAST).

What each module includes

An executive lesson briefing with five key concepts and official vendor documentation references, a scenario based knowledge check scored for mastery, an applied scenario evaluation, and supplemental verified videos plus official free hands on labs where available.

Start this curriculum

Other curricula

Published by TECHLEAD 187 LLC. Training certificates evidence completed instruction and contact hours; they are not vendor certifications and do not by themselves satisfy technical compliance requirements. Not affiliated with or endorsed by Google, Amazon Web Services, Microsoft, ISC2, Anthropic, or any U.S. government agency.