Skip to content
CBT Nuggets
DemoBook a Demo
ISC2Professional

CISSP – Certified Information Systems Security Professional

Standardize your team on CISSP – Certified Information Systems Security Professional with a structured ISC2 training path — virtual labs and team admin reporting included on every CBT Nuggets training subscription.

1
Course
$749
Exam cost
8
Core skills
Security operations center analysts monitoring threat dashboards
Difficulty
Difficulty: 4 of 5 (Advanced)
Advanced
Exam cost
$749
Courses on path
1
Official source
Exam code
  • CISSP

Exam datasheet

Exam length
3 hours
Questions
100-150
Passing score
700 out of 1000 points
Format
Computerized Adaptive Testing (CAT); multiple choice and advanced item types
Prerequisites
Minimum five years cumulative, full-time experience in two or more CISSP domains
Recommended experience
Experienced security practitioners, managers and executives
Recertification
3 years

Skills your team builds

Security and Risk ManagementAsset SecuritySecurity Architecture and EngineeringCommunication and Network SecurityIdentity and Access Management (IAM)Security Assessment and TestingSecurity OperationsSoftware Development Security

Every certification includes

Expert-led video training
Virtual labs
Certification practice exams
Per-team completion reporting

ISC2 career ladder

Where CISSP – Certified Information Systems Security Professional sits in your team's ISC2 progression

The cert your team is on now, plus the levels above and below. Use this to map an engineer's next-step credential or to plan headcount coverage across tiers.

  1. Professional level

    3 certs

    CCSP – Certified Cloud Security Professional

    CCSP

    You are here

    CISSP – Certified Information Systems Security Professional

    CISSP

    You are here

    SSCP – Systems Security Certified Practitioner

    SSCP

    You are here
  2. Entry-level level

    1 cert

    CC – Certified in Cybersecurity

    CC

    You are here

Compliance coverage

CISSP – Certified Information Systems Security Professional on your audit packet

Compliance frameworks CISSP – Certified Information Systems Security Professional training is commonly cited against, plus the control families the cert addresses. Use this as a planning aid for the procurement conversation, your SOC 2 / HIPAA / PCI prep packet, or the CMMC self-assessment crosswalk — paired with your auditor’s formal control crosswalk for attestation-grade mapping.

  • FrameworkSOC 2
    Control families
    CC1CC2CC6CC7CC8
  • FrameworkHIPAA
    Control families
    164.308164.310164.312
  • FrameworkPCI DSS 4.0
    Control families
    Req 12
  • FrameworkCMMC L2
    Control families
    ACATAUIAIRRASCSI
  • FrameworkISO 27001
    Control families
    A.5A.8A.9A.12A.13A.14A.16
  • FrameworkNIST 800-53
    Control families
    ACATAUCPIAIRPLRASCSI

Mappings reflect the cert’s stated learning objectives against published framework control families. Not a formal attestation or substitute for vendor audit guidance — pair with your auditor’s control crosswalk for the official mapping your SOC 2 or HIPAA review requires.

Customer outcome

Make CISSP a coverage number your auditor can quote

CISSP – Certified Information Systems Security Professional certified engineers are easy to count and easy to prove. CBT Nuggets bundles the prep into a single team playlist so leadership sees who's on the path, who finished, and who's exam-ready — without spreadsheets.

1 path
from foundation to credential — assigned and tracked as one playlist

Coverage proof

Make CISSP a number on your team capability sheet, not a single engineer’s certificate.

Standardizing your team on CISSP gives leadership and auditors a coverage number they can quote — and gives ISC2 incident response a baseline of capability you can predict instead of hoping for.

Credential: CISSP – Certified Information Systems Security Professional

Exam
  • CISSP

Frequently asked questions about CISSP – Certified Information Systems Security Professional training

Common questions IT directors ask when evaluating CISSP – Certified Information Systems Security Professional training for their team.

How does CISSP – Certified Information Systems Security Professional fit our SOC 2 / HIPAA / PCI DSS 4.0 / CMMC L2 compliance program?

Teams in regulated industries commonly cite CISSP – Certified Information Systems Security Professional when documenting training coverage for SOC 2, HIPAA, PCI DSS 4.0, CMMC L2. The specific control families CISSP – Certified Information Systems Security Professional maps to depend on your environment and audit scope — see the compliance mapping section above this FAQ for the planning view, and pair it with your auditor's control crosswalk for the formal attestation mapping. Team reporting in CBT Nuggets documents assigned training, completion, and certification coverage for the audit packet your reviewer actually wants to see.

What's the ROI of certifying our team on CISSP – Certified Information Systems Security Professional?

IT Directors typically frame CISSP – Certified Information Systems Security Professional ROI in operational terms — faster troubleshooting, defensible role coverage, predictable onboarding velocity, and audit-ready training documentation. The metrics that matter aren't seat-time or completion percentages; they're mean time to resolve, time-to-productivity for new ISC2 hires, and certification coverage by role.

How does CBT Nuggets CISSP – Certified Information Systems Security Professional training compare to Pluralsight, LinkedIn Learning, or Udemy Business?

CBT Nuggets CISSP – Certified Information Systems Security Professional courses are built by named expert trainers (not crowd-sourced contributors), include hands-on virtual labs in many courses, and include certification practice exams mapped to the vendor's published exam objectives. Team admin reporting tracks assignment, completion, and exam-readiness per engineer — the surface managers actually use to manage team training programs. See /compare for the full feature comparison.

How do I assign and track CISSP – Certified Information Systems Security Professional training for my team?

From the admin console, managers create a training playlist (one or more courses on the CISSP – Certified Information Systems Security Professional path), assign it to specific engineers or role groups, and track completion + practice-exam scores per learner. Team-wide reporting rolls up to a single dashboard you can export for monthly leadership reviews or quarterly compliance reporting. No spreadsheet, no per-engineer license fiddling.

How long does it take to certify a team on CISSP – Certified Information Systems Security Professional?

Depends on the cert and the team's starting baseline. Entry-level ISC2 certs typically run 4–6 weeks per engineer from a cold start; associate-level certs run 8–12 weeks; professional/expert tracks can run 3–6 months. Most teams budget the full quarter for any associate-level certification so engineers have time to actually apply the lab work before the exam.

What if ISC2 updates the CISSP – Certified Information Systems Security Professional exam objectives?

CBT Nuggets updates ISC2 course content as exam objectives refresh — typically within weeks of the vendor's release. When ISC2 restructures or renames a track (a common pattern), the assigned training paths stay aligned with the same team training plan; managers don't have to rebuild the playlist from scratch. The training stays current without anyone losing their certification status mid-stream.

Ready to CISSP – Certified Information Systems Security Professional-certify your team?

Build CISSP – Certified Information Systems Security Professional capability across your team

See how CBT Nuggets helps IT Directors plan and track CISSP – Certified Information Systems Security Professional training across the team — labs, practice exams, and reporting included.