Security domains cybersecurity analysts need to know

EIGHTDOMAINS
1
2
3
4
5
6
7
8

CISSP 8 Security Domains • The Common Body of Knowledge (CBK)

As an analyst, you can explore various areas of cybersecurity that interest you. One way to explore those areas is by understanding different security domains and how they're used to organize the work of security professionals. In this reading you will learn more about CISSP's eight security domains and how they relate to the work you'll do as a security analyst.


The Eight Common Body of Knowledge (CBK) Domains#

The International Information System Security Certification Consortium (ISC)² defines eight primary domains that establish the global standard for information security management. These domains ensure that defensive teams have comprehensive coverage across people, processes, and technological assets.


Domain one: Security and risk management#

All organizations must develop their security posture. Security posture is an organization's ability to manage its defense of critical assets and data and react to change. Elements of the security and risk management domain that security analysts need to understand include:

  • Security Governance: The framework of policies, procedures, and oversight mechanisms ensuring that cybersecurity aligns with business objectives and regulatory mandates (e.g., GDPR, HIPAA, PCI-DSS).
  • Compliance & Regulatory Standards: Verifying that corporate systems adhere to international laws and industry benchmarks such as NIST CSF and ISO 27001.
  • Threat Modeling & Risk Assessment: Identifying vulnerabilities, analyzing the likelihood of exploitation, and formulating mitigation strategies before threat actors strike.
  • Business Continuity & Disaster Recovery: Creating operational plans that allow an enterprise to sustain critical functions during a severe incident or natural catastrophe.

Domain two: Asset security#

Asset security focuses on safeguarding digital and physical assets throughout their entire lifecycle. Key responsibilities include:

  • Data Classification: Categorizing data based on its sensitivity (e.g., Public, Internal, Confidential, Restricted).
  • Data at Rest, in Transit, and in Use: Ensuring cryptographic protections like AES-256 encryption on storage drives and TLS 1.3 encryption across network interfaces.
  • Retention & Secure Destruction: Establishing cryptographic wiping or physical degaussing procedures for hardware that has reached end-of-life.

Domain three: Security architecture and engineering#

This domain addresses the design and implementation of secure technical infrastructures. Analysts must understand fundamental security models (such as the Bell-LaPadula and Biba models), zero-trust architecture, hardware security modules (HSMs), and defense-in-depth principles.


Domain four: Communication and network security#

Network security establishes safeguards for data flowing across local area networks (LANs), wide area networks (WANs), and cloud infrastructures:

  • Segmentation & Micro-segmentation: Utilizing Virtual Local Area Networks (VLANs) and software-defined networking to isolate mission-critical databases from user workstations.
  • Firewalls & Intrusion Prevention Systems (IPS): Deep packet inspection systems that block unauthorized connections and detect known exploit signatures.
  • Secure Network Protocols: Disabling legacy unencrypted protocols (such as Telnet and FTP) in favor of SSH, HTTPS, and IPsec VPN tunnels.

Domain five: Identity and access management (IAM)#

Identity and Access Management controls which users and services can access specific enterprise resources:

  • Identification, Authentication, & Authorization: Verifying user identities through Multi-Factor Authentication (MFA) and granting least-privilege permissions based on Role-Based Access Control (RBAC).
  • Single Sign-On (SSO) & Federation: Utilizing protocols like SAML and OAuth 2.0 / OpenID Connect to securely federate credentials across enterprise applications.

Domains six through eight: Assessment, Operations, and Software#

  • Domain 6 (Security Assessment and Testing): Conducting vulnerability assessments, automated code scanning (SAST/DAST), and ethical red-team penetration tests.
  • Domain 7 (Security Operations): Real-time monitoring inside the Security Operations Center (SOC) using Security Information and Event Management (SIEM) tools, threat hunting, and incident response.
  • Domain 8 (Software Development Security): Integrating security into the DevOps pipeline (DevSecOps), guarding against OWASP Top 10 vulnerabilities like SQL injection, and ensuring code signing.
Sponsored Reference

Video Walkthrough & Explanation

Video WalkthroughHD 1080p

Security domains cybersecurity analysts need to know — Video Walkthrough

Sponsored Reference

Practice Check • Quick Quiz

Test Your Understanding

What is an organization's 'security posture' as defined in Domain One?

A
The physical ergonomic setup of analyst workstations inside the Security Operations Center.
B
An organization's overall ability to manage its defense of critical assets and data and react to security changes.
C
The total budget allocated for antivirus software licenses.
D
A legal document certifying compliance with social media regulations.