- GISP is a 150-question, 4-hour open-book exam requiring a 70% score to pass.
- Registration costs $999, with retakes at $899 and renewal every four years for $499.
- The exam maps to the same eight domains ISC2 uses for the CISSP exam.
- Candidates get 120 days from activation to schedule and complete the exam.
What Is the GISP Certification?
The GIAC Information Security Professional (GISP) certification is a vendor-neutral credential administered by GIAC that validates broad, management-level knowledge of information security. Unlike narrow, tool-specific GIAC certifications, GISP is built around the same eight knowledge domains that ISC2 uses for the CISSP exam, making it a recognizable option for security professionals who want a GIAC-branded credential that still speaks the language hiring managers already understand.
If you're still deciding whether this credential fits your career goals, our broader overview of what GISP certification actually covers and the plainer explainer on what is GISP are good starting points before you commit to registration fees.
Exam Format and Registration Mechanics
Understanding the mechanics of the GISP exam matters just as much as knowing the content, because the format changes how you should prepare. The exam is delivered as a single web-based proctored test. You can take it remotely through ProctorU or in person at a Pearson VUE testing center - there is no separate practical lab component.
- Length: 150 questions, 4-hour time limit
- Passing score: 70%
- Activation window: 120 days to schedule and complete the exam once your access is activated
- Reference materials: open book - printed books, notes, and study guides are permitted; digital devices and files are not
The open-book format is one of the most misunderstood aspects of GISP. It does not make the exam easy - with 150 questions in four hours, you have roughly 96 seconds per question, which leaves little time to flip through binders unless your notes are extremely well organized in advance. For a full breakdown of what that time pressure actually feels like in practice, see how hard the GISP exam really is.
What It Costs
| Item | Price |
|---|---|
| Exam attempt | $999 |
| Retake | $899 |
| Attempt extension | $479 |
| Practice exam | $399 |
| Renewal (every 4 years) | $499 |
All prices are before applicable tax. Because a single attempt runs close to $1,000, most candidates budget for one serious attempt rather than planning to retake casually. For the complete fee structure, including what triggers extension charges, read our dedicated GISP certification cost breakdown.
Key Takeaway
Build your printed reference index before exam day - with 150 questions and a 4-hour clock, an unorganized binder of notes will cost you more time than it saves.
The Eight GISP Domains
GISP's content blueprint mirrors the eight domains used in the CISSP body of knowledge. Each domain contributes a portion of the 150 exam questions, and treating them as equally weighted study blocks is a reasonable default unless GIAC's current exam outline specifies otherwise.
Domain 1: Security and Risk Management
Covers governance, legal and regulatory issues, risk assessment methodology, and security policy frameworks.
- Risk analysis terminology and quantitative vs. qualitative approaches
- Business continuity and disaster recovery planning fundamentals
Domain 2: Asset Security
Focuses on classifying, handling, and protecting information and physical assets throughout their lifecycle.
- Data classification schemes and retention requirements
- Data ownership roles versus data custodianship
Domain 3: Security Architecture and Engineering
Tests understanding of secure design principles, cryptography, and engineering models.
- Security models (Bell-LaPadula, Biba, etc.) and their use cases
- Cryptographic algorithm categories and key management basics
Domain 4: Communication and Network Security
Covers network architecture, secure protocols, and common attack surfaces.
- OSI model mapping to real-world security controls
- Segmentation, VPNs, and secure network device configuration concepts
Domain 5: Identity and Access Management (IAM)
Covers authentication, authorization, and identity lifecycle management.
- Access control models: RBAC, ABAC, MAC, DAC
- Federation, SSO, and identity provisioning workflows
Domain 6: Security Assessment and Testing
Focuses on audit strategies, vulnerability assessment, and test types.
- Differences between vulnerability scans, penetration tests, and audits
- Log review and security control testing methodology
Domain 7: Security Operations
Covers day-to-day operational security, incident response, and recovery.
- Incident response phases and evidence handling
- Change management and configuration management basics
Domain 8: Software Development Security
Tests knowledge of secure SDLC practices and application-layer risks.
- Secure coding principles and common vulnerability classes
- Software development lifecycle models and where security fits in
For a much deeper dive into each domain - including subtopics, sample question angles, and where candidates typically lose points - see our full GISP exam domains guide. If you want to know exactly how many points you need across these domains to clear the bar, check what score you actually need to pass GISP.
Who Hires GISP Holders
GISP tends to appeal to professionals moving from technical roles into broader security leadership, compliance, or GRC-adjacent positions. Because the domains span governance, architecture, and operations rather than one narrow skill, it's often listed alongside or as an alternative to CISSP in job postings for:
- Security analysts moving toward security management
- IT auditors and compliance specialists
- Security architects and engineers with governance responsibilities
- Government and contractor roles requiring a broad security credential
To see how these roles map to actual postings and titles, browse our roundup of GISP jobs. If you're weighing whether the credential justifies its cost against career upside, our GISP ROI analysis and GISP salary guide go through the qualitative case in detail without relying on invented numbers.
Building a Domain-Weighted Study Plan
Because GISP spreads across eight fairly distinct domains, the most efficient prep sequences group related domains together rather than studying them in the order they're listed. A simple technique-agnostic approach: study your weakest domains earlier while your energy and time buffer are highest, and save domains you already know well for light review near the end.
Governance and Risk Foundations
- Work through Domain 1 (Security and Risk Management) and Domain 2 (Asset Security)
- Build your printed glossary of terms for open-book reference
Technical Core
- Cover Domain 3 (Security Architecture and Engineering) and Domain 4 (Communication and Network Security)
- Practice cryptography and network diagram-based questions
Access and Assessment
- Study Domain 5 (IAM) and Domain 6 (Security Assessment and Testing)
- Take a timed practice exam to test your 96-seconds-per-question pace
Operations, Development, and Full Review
- Finish Domain 7 (Security Operations) and Domain 8 (Software Development Security)
- Run full-length review sessions across all eight domains
This is a starting framework, not a rigid template - adjust it based on which domains overlap with your job experience. For a more detailed week-by-week plan with specific resource recommendations, see our full GISP study guide, and bookmark our GISP cheat sheet for quick reviews in your final week. Before you lock in a study calendar, confirm your testing window against current GISP exam dates and scheduling deadlines so your 120-day activation clock doesn't run out mid-plan.
Maintaining the Certification
GISP certification remains active for four years from the date you earn it. To keep it active, GIAC requires renewal through continuing education: you'll need to accumulate 36 CPEs and pay the $499 renewal fee before your certification expires. There is no requirement to retake the full exam if you renew on time through the CPE path.
Before you even sit the exam, it's worth confirming you meet GIAC's baseline eligibility expectations - GISP doesn't have rigid prerequisites like some vendor certifications, but understanding the practical entry requirements will save you registration headaches. Our GISP requirements guide covers eligibility in detail.
GISP vs. CISSP: How They Compare
Since GISP's domains mirror the CISSP body of knowledge, candidates often ask which credential to pursue. The core distinction isn't content - it's format and governing body.
| Factor | GISP | CISSP |
|---|---|---|
| Governing Body | GIAC | ISC2 |
| Domains Tested | Same 8 domains | Same 8 domains |
| Exam Format | 150 questions, 4 hours, open book | Adaptive/linear format, closed book |
| Reference Materials | Printed books and notes allowed | Not allowed |
| Renewal Cycle | 4 years, 36 CPEs | 3 years, CPE-based |
The open-book format is the single biggest practical difference, and it changes how you prepare far more than it changes what you need to know. Because the underlying domains are identical, much of the conceptual prep work overlaps - which is one reason candidates sometimes research both credentials side by side using resources like our GISP certification overview before deciding where to invest their exam fee.
Clearing Up the Terminology
If you've landed here searching for basic definitions, you're not alone - "GISP" gets abbreviated and referenced inconsistently across job postings and forums. For quick reference, we've published short explainers on what GISP means, what GISP stands for, what a GISP professional actually does, and what does GISP mean in an HR or job-posting context. These are useful to skim before you start serious prep, especially if you're comparing GISP to similarly named credentials.
Once terminology is settled, the next practical step is deciding how you'll prepare. Formal GISP training programs exist alongside self-study paths, and many candidates supplement either route with targeted practice questions on GISP Exam Prep to check domain-by-domain readiness before spending $999 on the actual attempt.
Key Takeaway
Don't confuse general searches about "what GISP means" with exam-day prep - settle definitions early, then shift all remaining study time to the eight domains themselves.
Frequently Asked Questions
The GISP exam contains 150 questions, and candidates have 4 hours to complete it. A score of 70% or higher is required to pass.
Yes. GISP is an open-book exam, meaning printed books, notes, and study guides are permitted in the testing environment. Digital references, including e-books and files on a device, are not allowed.
A standard exam attempt costs $999. Retakes are priced at $899, an attempt extension is $479, a practice exam from GIAC is $399, and renewal after four years costs $499, all before tax.
GISP certification is valid for four years. To maintain it, you must renew by earning 36 continuing professional education (CPE) credits and paying the $499 renewal fee before expiration.
The GISP exam is web-based and proctored. You can take it remotely through ProctorU or in person at a Pearson VUE testing center, depending on your preference and location.