Where you stand today
Second attempt. You already own Domain 5. The bank below is deliberately over-weighted toward everything else.
Exam facts to plan against
| Format | Computer Adaptive Testing (CAT), English |
|---|---|
| Length | 100–150 items in 3 hours (min. 75 scored items) |
| Pace | ~72 seconds per item at the 150-item ceiling |
| Pass mark | 700 / 1000 scaled — not a percentage |
| Item types | Multiple choice + advanced innovative items |
| Outline | Effective 15 April 2024 (current for 2026) |
Domain weight vs. your bank
Column 3 is how much of this app's practice sits in each domain. D5 is intentionally thin.
| Domain | Exam | Your drills | Score |
|---|
The five-move opening
- Fix the mindset before the content. You did not fail on facts — people who ace D5 know facts. Open Manager Mindset and read the twelve rules until they are reflex. Then run Trap Mode in the quiz engine.
- Meet the material before you drill it. Flashcards → Learn mode, one domain at a time, right after the ISSA session that covers it. Answers stay on screen; you are reading, not testing. Then switch to Weak-domain weighted, 20 cards, ten minutes a day, every day — that is where it sticks. Grading everything "Blank" means you skipped the reading pass.
- Question volume beats re-reading. Target 30–50 questions/day across D1–D4 and D6–D8. Read every rationale, including the ones you got right.
- Teach it back. After each ISSA session, run the matching Jeopardy board out loud — alone or with a cohort partner. Retrieval out loud is the highest-yield 15 minutes you have.
- Bank it for EDITS. Every domain you close becomes a service line. See the EDITS column in the 21-Session Plan.
The twelve rules that decide your second attempt
You know the technology. The CISSP is not testing whether you can fix it — it is testing whether you would authorize fixing it, in that order, at that moment.
- Human life and safety outrank everything. If an option protects a person and another protects an asset, the person wins. Always. No exceptions, no cost argument.
- You are the risk advisor, not the hands on the keyboard. When one option is "configure/patch/reimage" and another is "assess, escalate, or get the owner's decision" — the manager answer almost always wins.
- Governance before technology. Policy, then standard, then procedure, then tool. An answer that buys a product before there is a policy is wrong even when the product would work.
- Fix the process, not the instance. One misconfigured server is a symptom. If an option addresses how that server got misconfigured, prefer it.
- FIRST means earliest correct step, not most important step. "FIRST" usually maps to: identify scope / classify the asset / notify the owner / consult the plan. "BEST" means most complete and durable. "MOST" means greatest effect.
- The data owner decides; the custodian implements; security advises. If a question asks who approves anything about data — classification, access, retention, disposal — the business/data owner approves it.
- Never act on a system without authority. No scanning, no testing, no disconnecting production, no touching evidence without written authorization and defined scope. In Domain 6 and Domain 7 this single rule decides many items.
- Assume a mature, funded, supportive organization. ISC2's world has budget, management buy-in, and an existing plan. Do not pick the pragmatic shortcut you would pick for a real small client — that instinct is exactly what an experienced consultant fails on.
- Prevent > detect > correct. Given equally valid controls, the preventive one ranks highest, then detective, then corrective. Compensating controls are what you use when the primary control is not feasible — not a first choice.
- Follow the plan that already exists. Incident response, DR, change management, evidence handling — if a documented process exists, the right answer invokes it rather than improvising a better idea.
- Root cause over blame, documentation over memory. Lessons-learned, chain of custody, change records, and written approvals are almost never the wrong answer.
- No vendor, no brand, no cleverness. If an option names a product or a niche technique while another states a principle, choose the principle.
Every trap in the bank, by domain
These are the one-line trap notes attached to all 0 questions. Skim this the morning of the exam.
The 21-session cohort map
Mondays and Thursdays, 4:00 p.m. Pacific / 6:00 p.m. Central. Confirm each date against Kelly's calendar — holidays may shift the tail by one session.
| # | Date (Central) | Likely focus | Do before | Do after |
|---|
Every domain is an EDITS service line
You said EDITS should benefit. Here is the conversion — study output becomes a billable asset instead of a note you never reopen.
| Domain | Build this while you study it | What it sells |
|---|---|---|
| D1 Risk & Governance | A one-page risk register template + a small-business security policy set (AUP, access, incident, retention) | Policy-and-risk starter package — the single easiest first engagement for a new client |
| D2 Asset Security | Data classification + retention/disposal schedule tailored to a private practice | HIPAA/records readiness — you already have the Caring Hands Pediatrics precedent |
| D3 Architecture | Secure baseline checklist for a small office (endpoint, backup, crypto, physical) | Part of the Architect retainer tier |
| D4 Network | Network segmentation + Wi-Fi hardening assessment sheet | Fixed-fee network review, natural upsell from Maintain to Optimize |
| D5 IAM | Access review / recertification workbook and joiner-mover-leaver runbook | Your strength — make it the visible one |
| D6 Assessment | Repeatable client security assessment with rules of engagement and a report template | The recurring annual review that turns one-time clients into retainers |
| D7 Operations | Incident response plan + backup/restore test procedure + evidence handling card | Tabletop exercise as a paid half-day — high margin, low delivery cost |
| D8 Software | Third-party/SaaS vetting checklist and SBOM questions for client purchases | Vendor review service; protects clients from supply-chain surprises |
Progress
—
Domain readiness
| Domain | Weight | Answered | Accuracy |
|---|