CISSP,即Certified Information Systems Security Professional,是非赢利公司ISC2(http://www.isc2.org/)对信息系统安全从业人员进行的专业认证。ISC2定义了安全的CBK(Common Body of Knowledge),即将安全分成了十个域:
* Security Management Practices
* Security Architecture and Models
* Access Control Systems & Methodology
* Application Development Security
* Operations Security
* Physical Security
* Cryptography
* Telecommunications, Network & Internet Security
* Business Continuity Planning
* Law, Investigations & Ethics
每个域中又分为很多不同的知识点,详细介绍可见《CISSP Study Guide》等文档。从1991年开始,经过10年左右的发展,全球的CISSP已有数千人。