- GISP Domain Overview: Why Eight Areas Instead of a GIAC-Style Blueprint
- Domain 1: Security and Risk Management
- Domain 2: Asset Security
- Domain 3: Security Architecture and Engineering
- Domain 4: Communication and Network Security
- Domain 5: Identity and Access Management (IAM)
- Domain 6: Security Assessment and Testing
- Domain 7: Security Operations
- Domain 8: Software Development Security
- How the 150 Questions Are Distributed Across Domains
- Mapping Domains to a Study Calendar
- Exam Format, Fees, and Logistics Tied to the Domains
- Frequently Asked Questions
- GISP covers the same eight domains ISC2 uses for CISSP, tested across 150 questions in 4 hours.
- You need 70% to pass, and the exam is open book with printed materials only - no digital notes.
- Each attempt costs $999, with a $399 practice exam and a 120-day window from activation to sit the test.
- Software Development Security and Security Architecture and Engineering trip up candidates who skip hands-on technical review.
GISP Domain Overview: Why Eight Areas Instead of a GIAC-Style Blueprint
Most GIAC certifications are built around a narrow technical specialty - forensics, penetration testing, incident handling. GISP is different. GIAC designed the Information Security Professional certification to mirror the eight domains ISC2 uses for the CISSP exam, giving candidates a broad, managerial-plus-technical view of the entire security discipline. If you've researched what GISP actually is or looked into the meaning behind the acronym, you already know it positions holders as generalists who can speak fluently across governance, architecture, operations, and development.
That breadth is exactly why domain-by-domain planning matters more for GISP than for a single-topic GIAC exam. You're not drilling one skill set - you're building working knowledge across eight distinct disciplines, each with its own vocabulary, frameworks, and common exam traps. This guide breaks down all eight domains as GIAC has adopted them, tells you what to actually memorize versus understand conceptually, and shows how the domains map onto the exam's 150-question, 4-hour format.
Domain 1: Security and Risk Management
This domain anchors the entire exam. It covers governance, compliance, legal and regulatory issues, professional ethics, risk assessment methodologies, business continuity planning, and security policy development. Expect scenario questions that ask you to identify the correct risk treatment option (avoid, mitigate, transfer, accept) or to distinguish between qualitative and quantitative risk analysis.
What to Master
Candidates need working familiarity with risk management frameworks, BIA (business impact analysis) mechanics, and the difference between policies, standards, procedures, and guidelines.
- Quantitative risk formulas: SLE, ARO, ALE
- Due care versus due diligence in legal contexts
- Third-party and supply chain risk considerations
Domain 2: Asset Security
Asset Security focuses on classifying, handling, and protecting information and physical assets throughout their lifecycle. This domain is smaller in scope than Domain 1 but still tests specific, memorizable content - data classification schemes, data remanence, retention policies, and data states (at rest, in transit, in use).
- Ownership roles: data owner, data custodian, data controller, data processor
- Secure data disposal methods and when each is appropriate
- Privacy considerations tied to classification tiers
Domain 3: Security Architecture and Engineering
This is one of the most technically dense domains on the exam. It spans secure design principles, cryptography, security models (Bell-LaPadula, Biba, Clark-Wilson), and physical security controls. Candidates frequently underestimate the cryptography subtopics - symmetric versus asymmetric algorithms, hashing, PKI components, and common attack vectors against cryptographic implementations.
Domain or Topic Name: Security Models and Cryptography
Expect direct recall questions on which model addresses confidentiality versus integrity, and applied questions asking you to select the right cryptographic control for a given scenario.
If this domain feels heavier than the others, that's consistent with what most candidates report - a detailed breakdown of relative domain weight is covered in our GISP difficulty guide.
Domain 4: Communication and Network Security
This domain tests the OSI and TCP/IP models, network topologies, secure network components (firewalls, VPNs, IDS/IPS), and wireless security standards. It rewards candidates who understand the "why" behind protocols rather than just port numbers.
- Segmentation strategies and their security rationale
- Common network attacks: MITM, DNS poisoning, ARP spoofing
- Secure protocols and their insecure predecessors (e.g., SSH vs. Telnet)
Domain 5: Identity and Access Management (IAM)
IAM covers authentication factors, access control models (RBAC, ABAC, MAC, DAC), identity federation, and provisioning/deprovisioning lifecycle management. This domain frequently overlaps conceptually with Domain 1's governance content, so studying them close together can reinforce retention.
Access Control Models
Be able to distinguish access control models by their defining characteristic, not just their acronym.
- RBAC: permissions tied to job function
- ABAC: permissions tied to contextual attributes
- Federated identity concepts: SSO, SAML, OAuth basics
Domain 6: Security Assessment and Testing
This domain covers audit strategies, vulnerability assessments, penetration testing types, and security control testing methodologies. It's less about memorizing tool names and more about understanding the purpose and sequence of assessment activities - the difference between a vulnerability scan and a full penetration test, for example, or when a black-box versus white-box test is appropriate.
- Log review and synthetic transaction testing concepts
- Internal versus external and third-party audits
- Key performance and risk indicators used in reporting
Domain 7: Security Operations
Security Operations is broad and operationally focused: incident response, disaster recovery, digital forensics basics, change management, and physical security operations. Given GISP's generalist scope, this domain tends to test procedural sequencing - what happens first in an incident response lifecycle, or which recovery site type fits a given recovery time objective.
Incident Response Lifecycle
Candidates should know the standard phases in order and be able to identify which phase a described scenario belongs to.
Domain 8: Software Development Security
The final domain covers the software development lifecycle (SDLC), secure coding practices, and common application vulnerabilities. This is frequently the domain non-developers find least intuitive, since it requires familiarity with concepts like injection flaws, secure DevOps practices, and change control within development environments - even if you've never written production code.
- SDLC phases and where security controls are integrated
- OWASP-style vulnerability categories (injection, broken auth, etc.)
- Database security concepts: normalization, aggregation, inference
How the 150 Questions Are Distributed Across Domains
GIAC does not publish an exact question count per domain for GISP, and candidates should avoid relying on invented percentages circulating online. What is confirmed is the overall structure: 150 questions delivered in a 4-hour window, with a required score of 70% to pass. Rather than trying to guess precise per-domain weighting, plan your study time so that no domain is left unreviewed - a scenario-based exam like this can pull questions from any of the eight areas in combination, not in isolation. For a deeper look at exactly what "70%" means in practice and how scoring works, see our GISP passing score breakdown.
| Exam Attribute | Detail |
|---|---|
| Total Questions | 150 |
| Time Allowed | 4 hours |
| Passing Score | 70% |
| Domains Covered | 8 (aligned to ISC2 CISSP domains) |
| Reference Materials | Printed books/notes allowed; digital not allowed |
| Completion Window | 120 days from activation |
Mapping Domains to a Study Calendar
Because GISP's eight domains vary heavily in technical depth, a flat "study everything equally" approach wastes time. A more efficient method is to schedule denser, technical domains earlier - when you have the most energy and time buffer - and save lighter, governance-style domains for the final review weeks when spaced repetition of terminology is more valuable than deep conceptual work.
Technical Foundations
- Domain 3: Security Architecture and Engineering
- Domain 4: Communication and Network Security
Operational and Access Domains
- Domain 5: Identity and Access Management
- Domain 7: Security Operations
Assessment and Development
- Domain 6: Security Assessment and Testing
- Domain 8: Software Development Security
Governance and Final Review
- Domain 1: Security and Risk Management
- Domain 2: Asset Security
- Full-length practice exam and reference-tab organization
This is a starting framework, not a rigid rule - candidates with development or network backgrounds may want to flip weeks around. For a more complete week-by-week plan with resource recommendations, our GISP study guide covers pacing in more depth.
Key Takeaway
Because the exam is open book, build a tabbed index of your printed materials organized by domain number during your study weeks - not the night before. This turns your reference materials into a fast lookup tool rather than something you're reading cold during the exam.
Exam Format, Fees, and Logistics Tied to the Domains
Domain knowledge doesn't exist in a vacuum - it has to fit inside GISP's specific logistics. The exam is delivered as a single web-based, proctored test, either remotely through ProctorU or onsite via Pearson VUE. Once you activate your exam window, you have 120 days to schedule and sit for it, which affects how you should pace domain review: cramming all eight domains into the final two weeks of a 120-day window is far riskier than distributing study across the full period.
- Attempt cost: $999
- Retake cost: $899
- Attempt extension: $479
- Practice exam: $399
- Renewal fee: $499 (before applicable tax on all fees)
Given these costs, most candidates want to pass on the first attempt rather than budget for a retake. A full pricing breakdown, including how the practice exam and extension fees interact with your study timeline, is available in our GISP certification cost guide. If you're still confirming you meet the prerequisites before paying the attempt fee, check our GISP requirements overview first.
Because the exam is open book, your domain prep should produce two outputs: internalized understanding (for scenario and conceptual questions) and a well-organized physical reference set (for detail lookups like formulas, port numbers, or model names). Trying to build that reference set from digital notes won't help you on exam day, since only printed materials are permitted.
Once certified, remember that GISP stays active for four years, with renewal requiring 36 CPEs - so domain knowledge isn't a one-time study sprint but something you'll need to keep current, particularly in fast-moving areas like Domain 3 and Domain 8. You can practice with domain-aligned questions any time using the GISP practice test platform to check retention well after your initial exam date.
For candidates still deciding whether to commit to the exam fee and prep time, it helps to see the full picture side by side - domain scope, cost, difficulty, and career payoff. Our GISP ROI analysis and pass rate data breakdown both reference these same eight domains when explaining where candidates typically lose points. And once you're deep into prep, our GISP cheat sheet condenses domain-specific facts into a single quick-reference page for the final days before your exam window closes.
Frequently Asked Questions
GIAC has not published an official per-domain weighting for GISP. The confirmed structure is 150 questions across all eight domains in a 4-hour exam, so candidates should prepare each domain thoroughly rather than assume any single area is safe to skip.
GIAC built the GISP objectives around the same eight cybersecurity knowledge domains ISC2 uses for CISSP, giving GISP a similarly broad, generalist scope rather than a narrow technical focus like most other GIAC certifications.
Yes. GISP is open book, and printed books, notes, and study guides are permitted. Digital reference materials, including e-readers or laptops with notes, are not allowed during the proctored exam.
There's no single correct order, but many candidates benefit from tackling technically dense domains like Security Architecture and Engineering or Communication and Network Security earlier, saving governance-heavy domains like Security and Risk Management for closer to exam day.
Yes. Since you must complete the exam within 120 days of activation, it's more effective to spread review of all eight domains across that window rather than activating early and cramming domains at the end.