
Welcome to CISSP A–Z (2026)
This is your complete, all-in-one path from zero to CISSP-ready — and then further than any other course takes you.
What to expect: I walk you through all eight CISSP domains, aligned to the current ISC2 exam outline (effective April 15, 2024, current through 2026), with AI and machine-learning risk woven in exactly the way the exam now tests it. Every lesson is tagged by level, so newcomers get the fundamentals in plain English and seasoned pros get advanced depth they won't find elsewhere.
How it's built: Each topic comes as a short, focused video lesson paired with a downloadable student study guide for that session — read it, highlight it, make it yours. On top of that, you get a comprehensive master study guide covering the entire course, plus a full test bank of exam-style practice questions to drill your readiness. Watch, read, review, and test yourself all the way to exam day. You'll also get exam tips, common traps to avoid, real-world war stories from my assessment work, and knowledge-check questions to lock it in.
The bonus that sets us apart: A full GRC and compliance deep-dive — CUI, CMMC, DFARS, the FAR, FedRAMP, and a control-family-by-family walkthrough of NIST SP 800-171 Rev 3 — taught by someone who assesses these environments for a living.
Follow the sections in order, or jump to what you need. You'll leave exam-ready and job-ready.
— Dr. Dwayne Hodges, CISSP
Explore a practical CISSP exam prep roadmap covering the eight domains, adaptive testing, passing criteria, the ISC2 common body of knowledge, and the endorsement path to earn the credential.
Understand the five pillars of information security: confidentiality, integrity, availability, authenticity, and non-repudiation, and how encryption, access controls, hashing, and digital signatures protect them.
Master business continuity basics, including business impact analysis, recovery metrics such as recovery time objective, recovery point objective, maximum tolerable downtime, and contrast with disaster recovery and external dependencies.
Master data retention and asset lifecycle management by applying legal holds, retention schedules, and EOL/EOS strategies to minimize liability and ensure proper destruction.
Navigate vulnerabilities across client/server, cloud, IoT, and AI systems by learning the pattern: inference, aggregation, and covert channels, plus key defenses like segmentation and strict access controls.
Master IPsec, TLS, and SSH as they secure traffic across layer three to the transport layer, while understanding converged networks and segmentation to reduce risk.
Secure voice and video channels and remote access by encrypting data in transit. Authenticate strongly, enforce zero-trust, and govern third-party connections with end-to-end encryption.
Explore Kerberos, the Windows domain authentication engine, with KDC, TGT, and service tickets; compare Radius and TACACS+ for network access and device administration, plus credential management.
Design and validate a measurable assessment strategy that defines scope, independence, and rigor across on-prem, cloud, and hybrid environments, aligning to NIST 853-A, 800-115, and 800-171-A.
Collect technical and administrative data to prove controls operate, differentiate KPI from KRI, document access and oversight data, training completion, backup verification, and disaster recovery data—no data equals no proof.
Analyze test findings to drive remediation, document time-boxed exceptions and private ethical disclosures, and support independent audits that validate the security program.
Master investigations and digital forensics by preserving evidence with chain of custody and order of volatility, and distinguishing administrative, civil, regulatory, and criminal investigations by their proof standards.
Secure the development ecosystem by hardening the CI/CD pipeline, repositories, and secrets. Apply SAST, DAST, IAST, and SCA with auditing and risk analysis to close the SDLC loop.
Unpack the CMMC three levels, how to scope assessments, and the three assessment types, with SPRS scoring, plan of action and milestones, annual affirmations, and flow down to subcontractors.
This course contains the use of artificial intelligence.
Over 11 hours and 83 video lectures, a student study guide for every domain, and a full test bank of over 1000 exam-style practice questions — everything you need to go from zero to CISSP-ready
If you want a CISSP course that treats you like an adult and prepares you for the job — not just the test — you're in the right place.
I built CISSP A–Z to be the only CISSP course you'll need, and then I built a second course on top of it. First, you get complete, current coverage of all eight CISSP domains, aligned to the ISC2 exam outline in effect for 2026. I teach it in plain English from the ground up, so a career changer never feels lost — and I push into real depth so a twenty-year veteran still learns something. Every lesson is tagged by level, so you always know whether you're building a foundation, drilling exam-core material, or going advanced.
Then comes the part no other course gives you: a governance, risk, and compliance deep-dive into the regulatory machinery that's actually driving cybersecurity hiring right now. CMMC. CUI protection. DFARS and the FAR. FedRAMP. And a plain-English, control-family-by-control-family walkthrough of NIST SP 800-171 Rev 3 that you won't find anywhere else on this platform. That's the difference between passing a test and becoming the person in the room who understands how the rules really work.
I've lived both sides of this. I spent a career building security programs as a U.S. Army cybersecurity officer, and today I assess and advise Defense Industrial Base companies as a CMMC-certified assessor. I teach the way I wish someone had taught me: hard things broken into bite-size pieces, real war stories instead of dry theory, exam tips that reflect how ISC2 actually thinks, and the honest truth about what matters on test day versus what matters on the job.
Everything is built from authoritative primary sources — NIST, ISC2, the Code of Federal Regulations, Cyber AB, FedRAMP — and I keep the fast-moving compliance details current. Whenever exam content and real-world compliance diverge, I tell you exactly which is which.
What's inside — course topics
Welcome & Orientation
Instructor introduction and the promise of this course
Who this course is for and how to use it
How the CISSP exam actually works: CAT delivery, the eight domains, weighting, and scoring
The crawl-walk-run study path and how lessons are tagged by level
Domain 1 — Security & Risk Management (16%)
Security governance, the CIA triad, and core principles
Risk management concepts, treatment, and frameworks
Compliance, legal and regulatory issues, and the ISC2 Code of Ethics
Business continuity, personnel security, and security awareness
AI governance and integrating ML/LLM risk into the enterprise (advanced thread)
Domain 2 — Asset Security (10%)
Information and asset classification and ownership
Data lifecycle, handling, retention, and destruction
Data states and protection methods
Classifying and protecting AI assets: datasets, models, and model weights (advanced thread)
Domain 3 — Security Architecture & Engineering (13%)
Secure design principles and security models
Cryptography fundamentals, PKI, and applied crypto
Security capabilities of systems and vulnerabilities across platforms
Physical security for facilities and infrastructure
Prompt injection, adversarial ML, and secure AI compute (advanced thread)
Domain 4 — Communication & Network Security (13%)
Secure network architecture and the OSI/TCP-IP models
Secure network components and communication channels
Wireless, cellular, and modern network defense
Zero Trust and securing AI workloads (advanced thread)
Domain 5 — Identity & Access Management (13%)
Identity, authentication, and the access control lifecycle
Access control models and federated identity
Provisioning, credential management, and IAM in the cloud
Domain 6 — Security Assessment & Testing (12%)
Assessment and test strategies
Security control testing, vulnerability assessment, and penetration testing
Logging, monitoring, and reporting
Audits: internal, external, and third-party
Domain 7 — Security Operations (13%)
Investigations, evidence, and digital forensics
Detective and preventive measures; SIEM and SOC operations
Incident management, disaster recovery, and business continuity execution
Patch, change, and configuration management
AI for defensive automation (advanced thread)
Domain 8 — Software Development Security (10%)
Security in the software development lifecycle
Secure coding, OWASP, and application security controls
Software supply chain and third-party software risk
Assessing software security effectiveness
GRC Mega-Section — The differentiator ( Additional content)
The compliance landscape: FCI vs. CUI, the DFARS/FAR/CMMC relationship, and why 2026 is the demand catalyst
NIST foundations: 800-53 Rev 5 baselines and the Risk Management Framework
CMMC program deep dive: levels, scoping, assessment types, SPRS, POA&Ms, flow-down, and the ecosystem
DFARS, 32 CFR, 48 CFR, and the FAR — the clauses that drive real-world demand
FedRAMP requirements for cloud that stores, processes, or transmits CUI
The Anatomy Section: a plain-English, family-by-family walkthrough of all control families in NIST SP 800-171 Rev 3
NIST AI Risk Management Framework as the bridge between AI risk and compliance
Whether you're changing careers, finishing a degree, leading a team, or a seasoned pro finally adding the credential — I'll meet you where you are and get you CISSP-ready. Let's get to work
Dr. Dwayne Hodges, USA ( Ret.), CISSP ,CCISO, LCCA, CCP, CHP. CNDA, CEH, ITIL, SEC +, ECES