CISSP and CCSP Certification Guide is a practical, engineering-focused study guide for the two certifications that define the senior end of the information security profession. It is written for practitioners who already have hands-on security experience and need a structured guide that connects the exam material to the work they actually do.
The book covers all eight CISSP domains and all six CCSP domains in the depth the exams require, with a running focus on the judgement the exams are designed to test rather than the memorisation they discourage. It covers security and risk management, asset security and data governance, security architecture and engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security — then the cloud-specific domains on cloud architecture, data security, platform and infrastructure security, and application security.
It is explicit about the failure modes the exams test: a control that is documented but not implemented, a risk that is accepted informally with no owner, a classification scheme nobody enforces, an encryption key stored alongside the data it protects, an incident response plan that has never been rehearsed, a secure development program that is bypassed under delivery pressure. Each is presented with the failure, the countermeasure the exam expects, and the reasoning behind the correct answer.
Fourteen chapters, ~45,000 words. Written for candidates preparing for either exam, and for working security professionals who want a disciplined refresher of the full discipline.