- What the "Associate of ISC2" Exam Domains Actually Are
- Domain 1: Security and Risk Management (16%)
- Domain 2: Asset Security (10%)
- Domain 3: Security Architecture and Engineering (13%)
- Domain 4: Communication and Network Security (13%)
- Domain 5: Identity and Access Management (13%)
- Domain 6: Security Assessment and Testing (12%)
- Domain 7: Security Operations (13%)
- Domain 8: Software Development Security (10%)
- How Domain Weighting Should Shape Your Prep
- Question Format and Scoring Mechanics
- FAQ
- Security and Risk Management is the heaviest domain at 16% and covers governance, legal issues, risk, threat modeling, and supply chain risk.
- Asset Security and Software Development Security are the lightest domains, each weighted at 10%.
- Four domains - Architecture and Engineering, Network Security, IAM, and Security Operations - are each weighted at 13%.
- The current outline covering these eight domains took effect April 15, 2024, and the exam requires 700 of 1000 points to pass.
What the "Associate of ISC2" Exam Domains Actually Are
Associate of ISC2 is not a standalone exam with its own content outline. It's a designation awarded by ISC2 after a candidate passes one of ISC2's certification exams that carries a work-experience requirement, then chooses the Associate pathway during the application process instead of waiting until experience is completed. Because the CISSP exam is by far the highest-volume route into this designation, this guide walks through the eight domains that make up the CISSP content outline - the domains you'll actually be tested on if you're pursuing Associate of ISC2 status through CISSP.
If you haven't yet confirmed how the designation itself works, it's worth reading What Is Associate Of ISC2? or the deeper breakdown at Associate Of ISC2 Certification before diving into domain content. This article assumes you already know the destination and just want the map of what's tested.
Domain 1: Security and Risk Management (16%)
This is the largest single domain on the exam, and it sets the tone for everything else. It's less about memorizing tools and more about understanding how security decisions get made and justified at an organizational level.
Security and Risk Management
Candidates must be comfortable moving between legal, governance, and operational risk concepts without losing precision.
- Governance frameworks, security policy structures, and organizational roles
- Legal and regulatory issues, including compliance and privacy considerations across jurisdictions
- Risk management concepts: risk assessment, treatment, and monitoring
- Threat modeling methodologies and how they inform control selection
- Supply chain risk management for vendors, third parties, and acquisitions
- Security awareness, education, and training program design
Because this domain touches so many adjacent topics, questions here often read like short workplace scenarios rather than definition recall. Expect to reason through a situation and pick the most defensible next step, not just name a term.
Domain 2: Asset Security (10%)
Asset Security is one of the two lightest-weighted domains, but it's foundational to how everything else in the outline connects. It's built around the lifecycle of information and the assets that carry it.
Asset Security
- Information and asset classification schemes
- Ownership responsibilities across data lifecycle stages
- Privacy protection and data handling requirements
- Retention, secure data destruction, and appropriate asset retention policies
- Determining and maintaining appropriate levels of protection based on classification
Don't underweight this domain just because its percentage is lower - questions here frequently connect back to concepts from Security and Risk Management, so weak fundamentals in classification and ownership will cost you points in multiple places on the exam.
Domain 3: Security Architecture and Engineering (13%)
This domain is dense with technical detail: cryptography, secure design principles, and physical security all live here. It rewards candidates who understand why a control works, not just what it's called.
Security Architecture and Engineering
- Secure design principles and engineering lifecycle concepts
- Security models and evaluation criteria
- Cryptographic concepts, methods, and their appropriate use cases
- Vulnerabilities in web-based, mobile, and embedded systems
- Physical security requirements for facilities and equipment
Cryptography questions tend to be conceptual rather than mathematical - you're more likely to be asked which cryptographic approach fits a scenario than to perform a calculation.
Domain 4: Communication and Network Security (13%)
Networking fundamentals show up throughout the exam, but this domain is where they're tested directly. Expect coverage of both classic network architecture and the security implications of modern, distributed environments.
Communication and Network Security
- Secure network architecture design, including segmentation
- Secure communication channels and protocols
- Network components and their security implications
- Wireless, cloud, and converged communication technologies
If your networking background is thinner than your governance or compliance background, this is a domain worth extra time - it's weighted the same as three other domains and is easy to underestimate.
Domain 5: Identity and Access Management (IAM) (13%)
IAM sits at the intersection of technical controls and organizational process. It's one of four domains sharing the 13% weighting, making it one of the more heavily represented content areas overall.
Identity and Access Management
- Physical and logical access control mechanisms
- Identification, authentication, and authorization models
- Identity as a service and third-party identity services
- Access control attacks and mitigation approaches
- Provisioning and deprovisioning lifecycle management
Domain 6: Security Assessment and Testing (12%)
This domain covers how organizations verify that their controls actually work - through audits, testing, and structured assessment processes.
Security Assessment and Testing
- Designing and validating assessment and test strategies
- Conducting security control testing
- Collecting and analyzing security process data
- Internal and third-party audit considerations
Questions in this domain often ask you to pick the right assessment method for a stated goal - knowing the difference between testing types matters more than memorizing tool names.
Domain 7: Security Operations (13%)
Security Operations is broad, covering the day-to-day work of running a security program: incident response, monitoring, recovery, and investigations.
Security Operations
- Investigation types and evidence handling requirements
- Logging, monitoring, and detection activities
- Incident management, from detection through lessons learned
- Disaster recovery and business continuity concepts
- Physical security operations
Domain 8: Software Development Security (10%)
The final domain, tied with Asset Security at the lowest weighting, focuses on embedding security into the software development lifecycle rather than deep coding knowledge.
Software Development Security
- Security in the software development lifecycle
- Security controls within development environments
- Assessing the effectiveness of software security
- Secure coding guidelines and standards
You don't need to be a developer to succeed here, but you do need to understand where security checkpoints belong across a typical development pipeline.
How Domain Weighting Should Shape Your Prep
With eight domains ranging from 10% to 16%, it's tempting to study everything equally. That's inefficient. The percentages exist for a reason, and your time allocation should roughly mirror them.
| Domain | Weight | Relative Priority |
|---|---|---|
| 1. Security and Risk Management | 16% | Highest |
| 3. Security Architecture and Engineering | 13% | High |
| 4. Communication and Network Security | 13% | High |
| 5. Identity and Access Management | 13% | High |
| 7. Security Operations | 13% | High |
| 6. Security Assessment and Testing | 12% | Moderate |
| 2. Asset Security | 10% | Standard |
| 8. Software Development Security | 10% | Standard |
Key Takeaway
Spend the largest block of study time on Security and Risk Management first - its concepts (governance, risk, legal issues) reappear as context inside questions from other domains, so mastering it early pays off across the whole exam.
If you want a structured week-by-week plan built around this exact weighting, the Associate of ISC2 Study Guide 2026: How to Pass on Your First Attempt lays out a full schedule. As a general shape, here's how a domain-weighted study block might look:
Security and Risk Management
- Governance, legal/regulatory issues, and risk management frameworks
- Threat modeling and supply chain risk
Architecture, Network Security, and IAM
- Cryptography fundamentals and secure design principles
- Access control models and network segmentation
Operations, Assessment, and remaining domains
- Incident response and recovery concepts
- Asset classification and software development security
Question Format and Scoring Mechanics
Domain content matters, but so does the format you'll encounter it in. The CISSP exam - the route this site focuses on for Associate of ISC2 - uses Computerized Adaptive Testing, delivering between 125 and 150 items across a 3-hour session. Questions mix standard multiple-choice with advanced innovative item types, and a passing result requires 700 of 1000 points. There's no experience prerequisite to sit the exam itself; the experience requirement only comes into play when you later apply for full certification.
The exam is delivered through Pearson VUE at ISC2 Authorized PPC and PVTC Select testing centers, with a fee of US$749 in the Americas (regional pricing and taxes vary by testing location). The current outline - the one behind every domain above - took effect April 15, 2024, and is available in English, German, Spanish, Japanese, and Simplified Chinese.
For a full walkthrough of what the adaptive format feels like in practice and how difficult candidates typically find it, see How Hard Is the Associate of ISC2 Exam? Complete Difficulty Guide 2026. For the exact scoring mechanics, Associate of ISC2 Passing Score 2026: Exactly What You Need to Pass breaks down the 700/1000 threshold in more detail.
What Happens to Domain Knowledge After You Pass
Passing the exam and choosing the Associate pathway doesn't mean the domain knowledge stops mattering. As an Associate of ISC2, you'll pay an Annual Maintenance Fee of US$50 and earn 15 CPE credits each year - and continuing education in these same eight domains is how most Associates accumulate those credits. Associate status tied to CISSP can be held for up to six years while you accumulate the required experience (up to one year of the five-year CISSP requirement can be waived by an approved degree or qualifying credential, plus endorsement by an ISC2 member). When you're ready to convert, you'll pay an US$85 upgrade AMF, and a fresh three-year certification cycle begins.
For the full eligibility picture, including how the experience and endorsement requirements interact with domain knowledge, see Associate of ISC2 Requirements 2026: Eligibility, Prerequisites & How to Qualify. If you're still weighing whether the time investment across all eight domains is worth it for your career, Is the Associate of ISC2 Certification Worth It? Complete ROI Analysis 2026 and Associate Of ISC2 Jobs are worth reading alongside this domain guide.
Testing Your Domain Knowledge Before Exam Day
Reading domain outlines is necessary but not sufficient - the adaptive, scenario-heavy question style rewards candidates who've practiced applying concepts under exam-like conditions. Working through domain-tagged practice questions on our practice test platform lets you see exactly where your Security and Risk Management knowledge is solid versus where your Software Development Security understanding needs another pass. Because the exam draws from all eight domains in proportion to their weighting, practicing across the full set - not just your strongest areas - on the practice site is the most reliable way to simulate real exam pressure before you sit for it at a Pearson VUE center.
Once you've built a study rhythm, keeping a condensed reference on hand for last-minute review is useful. The Associate of ISC2 Cheat Sheet 2026: One-Page Review of Must-Know Facts compiles the highest-yield facts from across all eight domains into a single page for the days right before your test.
Frequently Asked Questions
No. Associate of ISC2 is earned by passing any qualifying ISC2 exam with a work-experience requirement. The eight domains above belong to the CISSP outline, which this site focuses on as the highest-volume route into the designation. Other ISC2 exams (with their own experience-based Associate pathways) have different content outlines.
Security and Risk Management, since it's weighted heaviest at 16% and its concepts - governance, legal issues, risk - reappear as context in questions from other domains.
No. There's no experience prerequisite to sit the exam itself. Experience only becomes relevant when you later apply to upgrade from Associate of ISC2 to full certification.
The exam doesn't publish a fixed count per domain because it uses Computerized Adaptive Testing with 125 to 150 items total; however, the published percentages (10% to 16% per domain) indicate each domain's relative share of content across the exam.
The current outline took effect April 15, 2024, and remains the basis for the domains and weightings described in this guide. Always confirm against ISC2's current published outline before your exam date, which you can track via Associate of ISC2 Exam Dates 2026: Testing Windows, Deadlines & Scheduling.