« Log analysis - Use yo… | Home | Reasons for making ba… »

The 10 domains of Security



The International Information Systems Security Certification Consortium, also known as the (ISC)2 is the organisation that develops and takes the CISSP exam. CISSP stands for Certified Information Systems Security Professional.

The (ISC)2 created a so-called Common Body of Knowledge (CBK), which every CISSP has to have knowledge and a deep understanding of. The CBK consists of the following 10 domains:

  1. Security Management Practices
  2. Access Control Systems
  3. Telecommunications and Networking Security
  4. Cryptography
  5. Security Architecture and Models
  6. Operations Security
  7. Application and Systems Development Security
  8. Business Continuity Planning and Disaster Recovery Planning
  9. Law, Investigation, and Ethics
  10. Physical Security

As you can see, IT security consists of much more than just Cisco Access-lists or PKI infrastructures. These are security issues, of course (domain 2 and 4 respectively), but the field of knowledge is much wider.

In later articles I will describe all 10 domains in detail.



No comments:


About Sjaak Laan

Sjaak Laan

I am 45 years old and married with Angelina. We have 3 children of 12, 7 and 5 years old. We live in The Netherlands, in a place called Drachten

I work for Logica as Principal IT Architect. I have 20 years IT experience.

I own the following certificates:

ITAC Master Certified IT Architect

CISSP_logo CISSP (Certified Information Systems Security Professional)


TOGAF8_Certified_web TOGAF Certified Architect



I am a member of the:


I manage my business contacts using Linkedin.


I can be reached through sjaak.laan [ a t ] gmail [dot] com.

This site states my opinion only, and not nessecarily the opinion of my employer or of the clients I work for.