GISP logo
Focused certification exam prep
Start practice

GISP Exam Domains 2026: Complete Guide to All 8 Content Areas

TL;DR
  • GISP covers the same eight domains ISC2 uses for CISSP, tested across 150 questions in 4 hours.
  • You need 70% to pass, and the exam is open book with printed materials only - no digital notes.
  • Each attempt costs $999, with a $399 practice exam and a 120-day window from activation to sit the test.
  • Software Development Security and Security Architecture and Engineering trip up candidates who skip hands-on technical review.

GISP Domain Overview: Why Eight Areas Instead of a GIAC-Style Blueprint

Most GIAC certifications are built around a narrow technical specialty - forensics, penetration testing, incident handling. GISP is different. GIAC designed the Information Security Professional certification to mirror the eight domains ISC2 uses for the CISSP exam, giving candidates a broad, managerial-plus-technical view of the entire security discipline. If you've researched what GISP actually is or looked into the meaning behind the acronym, you already know it positions holders as generalists who can speak fluently across governance, architecture, operations, and development.

That breadth is exactly why domain-by-domain planning matters more for GISP than for a single-topic GIAC exam. You're not drilling one skill set - you're building working knowledge across eight distinct disciplines, each with its own vocabulary, frameworks, and common exam traps. This guide breaks down all eight domains as GIAC has adopted them, tells you what to actually memorize versus understand conceptually, and shows how the domains map onto the exam's 150-question, 4-hour format.

Open-Book Reality Check: GISP allows printed books, notes, and study guides during the exam, but nothing digital. That changes how you should prepare for each domain - tabbed reference material matters more than raw memorization for detail-heavy domains like Domain 8.

Domain 1: Security and Risk Management

This domain anchors the entire exam. It covers governance, compliance, legal and regulatory issues, professional ethics, risk assessment methodologies, business continuity planning, and security policy development. Expect scenario questions that ask you to identify the correct risk treatment option (avoid, mitigate, transfer, accept) or to distinguish between qualitative and quantitative risk analysis.

What to Master

Candidates need working familiarity with risk management frameworks, BIA (business impact analysis) mechanics, and the difference between policies, standards, procedures, and guidelines.

  • Quantitative risk formulas: SLE, ARO, ALE
  • Due care versus due diligence in legal contexts
  • Third-party and supply chain risk considerations

Domain 2: Asset Security

Asset Security focuses on classifying, handling, and protecting information and physical assets throughout their lifecycle. This domain is smaller in scope than Domain 1 but still tests specific, memorizable content - data classification schemes, data remanence, retention policies, and data states (at rest, in transit, in use).

  • Ownership roles: data owner, data custodian, data controller, data processor
  • Secure data disposal methods and when each is appropriate
  • Privacy considerations tied to classification tiers

Domain 3: Security Architecture and Engineering

This is one of the most technically dense domains on the exam. It spans secure design principles, cryptography, security models (Bell-LaPadula, Biba, Clark-Wilson), and physical security controls. Candidates frequently underestimate the cryptography subtopics - symmetric versus asymmetric algorithms, hashing, PKI components, and common attack vectors against cryptographic implementations.

Domain or Topic Name: Security Models and Cryptography

Expect direct recall questions on which model addresses confidentiality versus integrity, and applied questions asking you to select the right cryptographic control for a given scenario.

  • Know the purpose of each classic security model, not just its name
  • Understand key exchange, digital signatures, and certificate chains
  • If this domain feels heavier than the others, that's consistent with what most candidates report - a detailed breakdown of relative domain weight is covered in our GISP difficulty guide.

    Domain 4: Communication and Network Security

    This domain tests the OSI and TCP/IP models, network topologies, secure network components (firewalls, VPNs, IDS/IPS), and wireless security standards. It rewards candidates who understand the "why" behind protocols rather than just port numbers.

    • Segmentation strategies and their security rationale
    • Common network attacks: MITM, DNS poisoning, ARP spoofing
    • Secure protocols and their insecure predecessors (e.g., SSH vs. Telnet)

    Domain 5: Identity and Access Management (IAM)

    IAM covers authentication factors, access control models (RBAC, ABAC, MAC, DAC), identity federation, and provisioning/deprovisioning lifecycle management. This domain frequently overlaps conceptually with Domain 1's governance content, so studying them close together can reinforce retention.

    Access Control Models

    Be able to distinguish access control models by their defining characteristic, not just their acronym.

    • RBAC: permissions tied to job function
    • ABAC: permissions tied to contextual attributes
    • Federated identity concepts: SSO, SAML, OAuth basics

    Domain 6: Security Assessment and Testing

    This domain covers audit strategies, vulnerability assessments, penetration testing types, and security control testing methodologies. It's less about memorizing tool names and more about understanding the purpose and sequence of assessment activities - the difference between a vulnerability scan and a full penetration test, for example, or when a black-box versus white-box test is appropriate.

    • Log review and synthetic transaction testing concepts
    • Internal versus external and third-party audits
    • Key performance and risk indicators used in reporting

    Domain 7: Security Operations

    Security Operations is broad and operationally focused: incident response, disaster recovery, digital forensics basics, change management, and physical security operations. Given GISP's generalist scope, this domain tends to test procedural sequencing - what happens first in an incident response lifecycle, or which recovery site type fits a given recovery time objective.

    Incident Response Lifecycle

    Candidates should know the standard phases in order and be able to identify which phase a described scenario belongs to.

  • Detection, response, mitigation, reporting, recovery, remediation, lessons learned
  • Difference between DRP, BCP, and COOP
  • Domain 8: Software Development Security

    The final domain covers the software development lifecycle (SDLC), secure coding practices, and common application vulnerabilities. This is frequently the domain non-developers find least intuitive, since it requires familiarity with concepts like injection flaws, secure DevOps practices, and change control within development environments - even if you've never written production code.

    • SDLC phases and where security controls are integrated
    • OWASP-style vulnerability categories (injection, broken auth, etc.)
    • Database security concepts: normalization, aggregation, inference
    Generalist Trap: Candidates from a governance or compliance background often over-prepare for Domains 1 and 2 while under-preparing for Domains 3, 4, and 8. Since GISP tests all eight domains broadly, technical gaps in architecture, networking, or development security can quietly cost you the exam even if your risk management knowledge is excellent.

    How the 150 Questions Are Distributed Across Domains

    GIAC does not publish an exact question count per domain for GISP, and candidates should avoid relying on invented percentages circulating online. What is confirmed is the overall structure: 150 questions delivered in a 4-hour window, with a required score of 70% to pass. Rather than trying to guess precise per-domain weighting, plan your study time so that no domain is left unreviewed - a scenario-based exam like this can pull questions from any of the eight areas in combination, not in isolation. For a deeper look at exactly what "70%" means in practice and how scoring works, see our GISP passing score breakdown.

    Exam AttributeDetail
    Total Questions150
    Time Allowed4 hours
    Passing Score70%
    Domains Covered8 (aligned to ISC2 CISSP domains)
    Reference MaterialsPrinted books/notes allowed; digital not allowed
    Completion Window120 days from activation

    Mapping Domains to a Study Calendar

    Because GISP's eight domains vary heavily in technical depth, a flat "study everything equally" approach wastes time. A more efficient method is to schedule denser, technical domains earlier - when you have the most energy and time buffer - and save lighter, governance-style domains for the final review weeks when spaced repetition of terminology is more valuable than deep conceptual work.

    Weeks 1-2

    Technical Foundations

    • Domain 3: Security Architecture and Engineering
    • Domain 4: Communication and Network Security
    Weeks 3-4

    Operational and Access Domains

    • Domain 5: Identity and Access Management
    • Domain 7: Security Operations
    Weeks 5-6

    Assessment and Development

    • Domain 6: Security Assessment and Testing
    • Domain 8: Software Development Security
    Weeks 7-8

    Governance and Final Review

    • Domain 1: Security and Risk Management
    • Domain 2: Asset Security
    • Full-length practice exam and reference-tab organization

    This is a starting framework, not a rigid rule - candidates with development or network backgrounds may want to flip weeks around. For a more complete week-by-week plan with resource recommendations, our GISP study guide covers pacing in more depth.

    Key Takeaway

    Because the exam is open book, build a tabbed index of your printed materials organized by domain number during your study weeks - not the night before. This turns your reference materials into a fast lookup tool rather than something you're reading cold during the exam.

    Exam Format, Fees, and Logistics Tied to the Domains

    Domain knowledge doesn't exist in a vacuum - it has to fit inside GISP's specific logistics. The exam is delivered as a single web-based, proctored test, either remotely through ProctorU or onsite via Pearson VUE. Once you activate your exam window, you have 120 days to schedule and sit for it, which affects how you should pace domain review: cramming all eight domains into the final two weeks of a 120-day window is far riskier than distributing study across the full period.

    • Attempt cost: $999
    • Retake cost: $899
    • Attempt extension: $479
    • Practice exam: $399
    • Renewal fee: $499 (before applicable tax on all fees)

    Given these costs, most candidates want to pass on the first attempt rather than budget for a retake. A full pricing breakdown, including how the practice exam and extension fees interact with your study timeline, is available in our GISP certification cost guide. If you're still confirming you meet the prerequisites before paying the attempt fee, check our GISP requirements overview first.

    Because the exam is open book, your domain prep should produce two outputs: internalized understanding (for scenario and conceptual questions) and a well-organized physical reference set (for detail lookups like formulas, port numbers, or model names). Trying to build that reference set from digital notes won't help you on exam day, since only printed materials are permitted.

    Once certified, remember that GISP stays active for four years, with renewal requiring 36 CPEs - so domain knowledge isn't a one-time study sprint but something you'll need to keep current, particularly in fast-moving areas like Domain 3 and Domain 8. You can practice with domain-aligned questions any time using the GISP practice test platform to check retention well after your initial exam date.

    Who Actually Uses These Domains: GISP's generalist, eight-domain structure is why it appeals to security managers, GRC analysts, IT auditors, and technical leads who need credibility across the full security stack rather than in one narrow specialty. If you're evaluating whether this breadth matches your career goals, our GISP jobs overview and GISP salary guide break down where the certification tends to show up in job postings.

    For candidates still deciding whether to commit to the exam fee and prep time, it helps to see the full picture side by side - domain scope, cost, difficulty, and career payoff. Our GISP ROI analysis and pass rate data breakdown both reference these same eight domains when explaining where candidates typically lose points. And once you're deep into prep, our GISP cheat sheet condenses domain-specific facts into a single quick-reference page for the final days before your exam window closes.

    Frequently Asked Questions

    Are all eight GISP domains weighted equally on the exam?

    GIAC has not published an official per-domain weighting for GISP. The confirmed structure is 150 questions across all eight domains in a 4-hour exam, so candidates should prepare each domain thoroughly rather than assume any single area is safe to skip.

    Why do GISP's domains match the CISSP domains?

    GIAC built the GISP objectives around the same eight cybersecurity knowledge domains ISC2 uses for CISSP, giving GISP a similarly broad, generalist scope rather than a narrow technical focus like most other GIAC certifications.

    Can I bring printed notes for each domain into the exam?

    Yes. GISP is open book, and printed books, notes, and study guides are permitted. Digital reference materials, including e-readers or laptops with notes, are not allowed during the proctored exam.

    Which domain should I study first?

    There's no single correct order, but many candidates benefit from tackling technically dense domains like Security Architecture and Engineering or Communication and Network Security earlier, saving governance-heavy domains like Security and Risk Management for closer to exam day.

    Does the 120-day exam window affect how I should plan domain study?

    Yes. Since you must complete the exam within 120 days of activation, it's more effective to spread review of all eight domains across that window rather than activating early and cramming domains at the end.

    Ready to pass your GISP exam?

    Put this into practice with free GISP questions across every exam domain.