Security and Risk Management carries the largest single weight; the remaining seven domains are weighted between 10% and 13%. Give the higher-weighted domains proportionally more study time, then confirm against the official outline before your exam date.
1Security and Risk Management — policy, governance, compliance, risk and BCP/DR fundamentals.16%
2Asset Security — data classification, ownership, retention and privacy protection.10%
3Security Architecture and Engineering — secure design principles, cryptography and system models.13%
4Communication and Network Security — secure network architecture and communication channels.13%
5Identity and Access Management — provisioning lifecycle, authentication and access-control models.13%
6Security Assessment and Testing — designing and conducting assessment and audit strategies.12%
7Security Operations — investigations, incident management, recovery and physical security.13%
8Software Development Security — secure SDLC, application controls and secure coding guidelines.10%