ISC2 publishes exactly what the CC tests and how much each part is worth. Here it is — every domain, its weight, the topics inside it, and the lessons that cover them.
Domain 1
Security Principles
Core cybersecurity concepts, risk management, governance, controls, and professional ethics. Official weighting 24%.
5 topics in this domain
- Understand cybersecurity concepts
- Understand risk management concepts
- Understand governance concepts
- Understand cybersecurity controls
- Maintain professional and ethical conduct
Domain 2
Security Governance
Governance, Risk, and Compliance; redundancy (BC/DR); security awareness; and measuring effectiveness. Official weighting 17.3%.
4 topics in this domain
- Plan Governance, Risk, and Compliance (GRC)
- Understand redundancy
- Understand security awareness
- Measure cybersecurity effectiveness
Domain 3
Identity And Access Management (IAM) Concepts
Identity lifecycle management and logical access controls. Official weighting 20%.
2 topics in this domain
- Understand identity life cycle management
- Understand logical access controls
Domain 4
Networking and Cloud Security Concepts
Network security, network security architecture, and cloud security. Official weighting 21.3%.
3 topics in this domain
- Understand network security
- Understand network security architecture
- Understand cloud security
Domain 5
Security Operations and Incident Response
Data security, security operations, incident response, asset protection, and security testing. Official weighting 17.3%.
5 topics in this domain
- Understand data security
- Understand security operations
- Understand Incident Response (IR)
- Understand asset protection
- Understand security testing