You have worked in information security, IT audit, network infrastructure or risk management for years. Now you are considering CISSP®. The first question is often not Which book should I buy? It is Does my experience count?
For professionals in Bangladesh, the answer depends on the work you have actually done – not your job title or where you work. Here is how to assess your eligibility, understand the exam and plan your preparation.
CISSP® Eligibility: the short answer
To earn the CISSP® certification, ISC2 requires five years of cumulative, full-time work experience in at least two of the eight CISSP® domains. An eligible degree or an approved credential may satisfy up to one year of that requirement; the two routes cannot be combined for a two-year waiver. Part-time work and internships can also count under ISC2’s rules. Review the current ISC2 experience requirements before applying.
You can still take the exam if you do not yet have the required experience. If you pass, you may apply to become an Associate of ISC2 while you gain the remaining experience. ISC2 allows up to six years to meet the CISSP® experience requirement through that path. Passing the exam alone does not make you a CISSP® certificate holder.
Does your work experience count?
ISC2 assesses relevant duties across at least two domains. Consider what you were responsible for in each role:
| Your work | Domains it may relate to |
|---|---|
| Reviewing security policies, risks or third-party controls | Security and Risk Management |
| Managing user access, privileged accounts or authentication | Identity and Access Management |
| Designing network segmentation or secure infrastructure | Communication and Network Security; Security Architecture and Engineering |
| Investigating alerts, responding to incidents or improving recovery plans | Security Operations |
| Testing controls or coordinating security assessments | Security Assessment and Testing |
These are examples, not an eligibility ruling. A network engineer, IT auditor or bank security professional in Bangladesh may have relevant experience, but ISC2 determines whether the documented work satisfies its requirements.
Before studying, make a simple experience record: employer, dates, hours worked, your actual security responsibilities, and which domains each responsibility relates to. If you plan to count an internship, check ISC2’s documentation rules. If you are relying on a degree or another certification for a waiver, confirm that it appears under ISC2’s current criteria.
What does the CISSP® exam cover in 2026?
The current ISC2 exam outline covers eight domains:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management (IAM)
- Security Assessment and Testing
- Security Operations
- Software Development Security
The exam uses computerized adaptive testing, lasts three hours, and contains 100–150 items, including multiple-choice and advanced item types. ISC2 currently lists English, Chinese, German, Japanese and Spanish as exam languages; Bangla is not listed. If you learn concepts in Bengali, also practise reading security scenarios and terminology in English before booking your exam.
The breadth of the domains is why memorizing definitions is insufficient. You need to connect technical controls to risk, business needs, governance and the most appropriate next decision.
A practical 10-week preparation approach
This is an illustrative study plan, not a promise that every candidate will be exam-ready in ten weeks. Adjust it to your experience and diagnostic results.
| Period | Focus | What to produce |
|---|---|---|
| Weeks 1–2 | Read the official outline; assess your strengths; study risk management and asset security. | A domain-by-domain gap list and realistic weekly study hours. |
| Weeks 3–5 | Work through architecture, networks and identity management. | Short notes that explain why a control fits a business scenario. |
| Weeks 6–7 | Study assessment, operations and software development security. | A list of weak concepts and the decisions you repeatedly get wrong. |
| Weeks 8–9 | Practise mixed-domain questions and review explanations. | A mistake log grouped by domain and reasoning error. |
| Week 10 | Take a timed practice assessment and revisit weak areas. | A decision about whether to book the exam or extend your preparation. |
For example, imagine a service provider requests broad administrator access to a financial institution’s system to fix an urgent issue. A useful security response weighs the operational need against least privilege, approval, limited access time, logging and review. The point is to practice reasoning through risk and controls, not to guess which technical tool sounds most impressive. This is an illustrative learning scenario, not an ISC2 exam question.
Frequently asked questions
Can I take the CISSP® exam without five years of experience?
Yes. If you pass before meeting the experience requirement, ISC2 offers the Associate of ISC2 pathway. You cannot represent yourself as CISSP® certified until you meet the certification requirements and ISC2 approves your application.
Can an IT auditor or network professional pursue CISSP®?
Potentially. Your job title does not settle the question. Map your actual duties and documented experience against at least two domains, then check ISC2’s official rules.
Does a preparation course award the CISSP® certification?
No. A course can help you prepare; ISC2 awards the certification after its exam, experience, endorsement and other applicable requirements are met.
Take the next step
If your background aligns with the CISSP® path, build your experience map first and use the official exam outline to guide your study. For structured, live preparation across all eight domains, explore the CISSP® Exam Preparation Program at Transfotech Global Bangladesh. You can also speak with the TGB team about how the program fits your experience and preparation goals.