Below is a maintainable changelog for the CISSP hub. Each entry lists the date, a short summary, and the areas impacted (Syllabus, Cheatsheet, Practice, Resources, Copy).
2025-09-20 — v1.0 • Initial Release
Summary: First publication of the CISSP study hub (ISC2 branding).
What’s included
- Overview: exam mindset, audience, readiness checklist, 6–10 week plan
- Syllabus: 8 CBK domains with shortcode hook to curriculum data
- Cheatsheet: high-yield contrasts (governance/risk math, models, IAM, crypto/PKI/TLS, cloud, IR/BCP/DR)
- Practice: app embed with progression (domain drills → scenarios → full mocks)
- FAQ: eligibility/experience, scoring mindset, domain depth, endorsement/CPEs
- Resources: official ISC2 pages, NIST/ISO/CIS frameworks, OWASP/MITRE, tools, lab ideas
- Updates: this changelog page
Impacted areas: Syllabus • Cheatsheet • Practice • Resources • Copy
How we version changes
- Patch updates (typos, clarifications): increment patch (e.g., v1.0.1).
- Objective mapping or section adds: increment minor (e.g., v1.1).
- Major blueprint shifts (ISC2 exam outline refresh): increment major (e.g., v2.0).
We align to ISC2’s published exam outline/CBK. When those change, we update the syllabus mapping first, then mirror adjustments across cheatsheet and practice coverage.
Update templates (copy & reuse)
Template — Minor update
- Date: YYYY-MM-DD — v1.x.y
- Summary: One-line description
- Changes:
- Impacted areas: Syllabus / Cheatsheet / Practice / Resources / Copy
Template — Objective/coverage update
- Date: YYYY-MM-DD — v1.x
- Summary: Objective mapping adjusted for domain
- Changes:
- Syllabus: updated objectives <A → B>
- Cheatsheet: added/edited section on
- Practice: increased item coverage for
- Resources: added official/vendor doc links
- Impacted areas: Syllabus • Cheatsheet • Practice • Resources
Template — Major revision
- Date: YYYY-MM-DD — v2.0
- Summary: Major ISC2 blueprint release; full hub refresh
- Changes:
- Syllabus: restructured per new CBK outline
- Cheatsheet: overhauled contrasts/workflows
- Practice: regenerated mocks/drills to match new weighting
- FAQ/Overview: replaced outdated guidance
- Impacted areas: All
Pending / backlog
- Add zero trust reference diagram (PDP/PEP flows) in Architecture & Engineering.
- Expand PKI revocation (OCSP stapling, must-staple, pinning caveats) with quick decision trees.
- Enrich cloud posture content (CSPM vs CWPP vs CASB scenarios; multi-cloud guardrails).
- Add IR decision trees (containment vs eradication vs recovery) + small pcap/log exercises.
- Include governance quick-maps (policy → standard → baseline → procedure → guideline) with role examples (Owner, Custodian, Steward, DPO).
Last reviewed: 2025-09-20