Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
daemon-blockint-tech avatar

Certified Information Systems Security Professional

  • 29 installs
  • 7 repo stars
  • Updated May 20, 2026
  • daemon-blockint-tech/agentic-enteprises-skill

Apply the CISSP CBK across its eight domains: security program design, risk and control selection, audit narratives, and structured exam prep.

About

Guides security leadership aligned with the (ISC)² CISSP CBK across its eight domains, covering program design, policy, risk and control selection, and CBK study structure. A developer or security lead uses it for CISSP prep or translating CBK to practice.

  • Covers the eight (ISC)² CISSP CBK domains
  • Program design, control selection, and defense in depth

Certified Information Systems Security Professional by the numbers

  • 29 all-time installs (skills.sh)
  • Ranked #1,501 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Jul 29, 2026 (Skillselion catalog sync)
npx skills add https://github.com/daemon-blockint-tech/agentic-enteprises-skill --skill certified-information-systems-security-professional

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs29
repo stars7
Last updatedMay 20, 2026
Repositorydaemon-blockint-tech/agentic-enteprises-skill

What it does

Apply the CISSP CBK across its eight domains: security program design, risk and control selection, audit narratives, and structured exam prep.

Files

SKILL.mdMarkdownGitHub ↗

Certified Information Systems Security Professional (CISSP)

When to Use

  • Structure CISSP/CBK study — domain map, manager mindset, practice workflow (no copyrighted items)
  • Design security programs using CBK domains — policies, standards, procedures, ownership
  • Frame risk management — threats, vulnerabilities, impact, treatment, residual risk
  • Select and justify controls — administrative, technical, physical; defense in depth
  • Support audit and assessment narratives — scope, sampling, findings, management responses
  • Align work to NIST CSF / ISO 27001 concepts at program level (not control-by-control automation)
  • Explain IAM, network security, crypto, and SDLC at architecture and governance depth
  • Translate CBK topics to organizational roles — what leaders decide vs technicians execute

When NOT to Use

  • SOC alert triage, shift handoffs, or playbook execution → soc-analyst
  • Declared incident command, containment, forensics → incident-responder
  • Execute penetration tests or exploit chains → penetration-tester
  • Cloud-only attestations, CSPM evidence, residency packages → cloud-compliance-specialist
  • Board-only strategy, appetite, crisis comms without CBK/program lens → chief-information-security-officer
  • Deploy SIEM rules, hardening, IAM/terraform, EDR → information-security-engineer
  • GRC program scope, gap assessments, audit prep packs → compliance-specialist
  • Evidence automation from IdP/CI/CD/CSPM → compliance-engineer
  • Enterprise reference architecture and zero-trust standards → enterprise-security-architect
  • Risk registers, FAIR scoring, treatment matrices → security-risk-analyst
  • Broad security strategy without CBK or certification framing → cybersecurity
  • Legal interpretation, contracts, or regulatory filings → legal counsel

Related skills

NeedSkill
Executive program, board, appetite, crisischief-information-security-officer
Control deployment, SIEM/EDR, hardeninginformation-security-engineer
Reference architecture, zero trust, ARBenterprise-security-architect
GRC program, frameworks, audit coordinationcompliance-specialist
Control testing, evidence automationcompliance-engineer
Risk registers, inherent/residual, treatmentsecurity-risk-analyst
Enterprise security strategy (non-CBK depth)cybersecurity

Core Workflows

1. Scope and CBK orientation

Clarify whether the ask is exam prep, program design, audit narrative, or control selection. Map the topic to CBK domains and the manager vs technician boundary.

See `references/cissp_scope_and_cbk_overview.md`.

2. Security and risk management (Domain 1)

Governance, policies, risk treatment, BCP/DRP themes, legal/regulatory concepts at program level, and security awareness.

See `references/security_and_risk_management.md`.

3. Asset security and architecture (Domains 2–3)

Data classification, handling, retention; secure design principles, models, and evaluation criteria.

See `references/asset_security_and_architecture.md`.

4. Network, IAM, and assessment (Domains 4–6)

Secure communications, identity lifecycle, access models, and assessment types (audit, test, evaluate).

See `references/network_iam_and_assessment.md`.

5. Security operations and SDLC (Domains 7–8)

Monitoring, IR program elements, DR operations; secure SDLC, supply chain, and software assurance.

See `references/security_operations_and_sdlc.md`.

6. Apply CBK to organizational practice

Policies, NIST/ISO alignment, governance cadence, study workflow, and handoffs to specialist skills.

See `references/applying_cissp_to_programs.md`.

Outputs

  • Domain study map — topic checklist per CBK domain with weak-area focus
  • Program alignment brief — how initiatives map to domains and control families
  • Policy/governance outline — hierarchy (policy → standard → procedure), owners, review cadence
  • Risk and control narrative — threat, control objective, implementation type, residual risk
  • Audit support memo — scope, population, sampling approach, finding severity framing
  • Role handoff table — CISSP-level decision vs engineering/GRC/IR execution owners

Principles

  • Manager mindset — breadth across domains; delegate depth to specialists
  • Defense in depth — layer administrative, technical, and physical controls
  • Risk-based prioritization — tie controls and spend to likelihood and impact
  • No exam brain dumps — teach concepts and structure; do not reproduce copyrighted items
  • Complement, not replace — use CISO/GRC/engineering skills for their execution lanes

When to load references

  • CBK domains and exam contextreferences/cissp_scope_and_cbk_overview.md
  • Domain 1references/security_and_risk_management.md
  • Domains 2–3references/asset_security_and_architecture.md
  • Domains 4–6references/network_iam_and_assessment.md
  • Domains 7–8references/security_operations_and_sdlc.md
  • Programs, frameworks, study workflowreferences/applying_cissp_to_programs.md

Related skills

Securitycomplianceappsec

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.