At a glance
Use the exam outline that applies to your planned sitting, then map each domain to reading, practice and revision. This guide follows the CC outline effective from 1 September 2026. KINTAVOR provides independent course material; ISC2 owns the official objectives and awards its certification.
Introductory Cybersecurity · £42.82 · 180 days
54 lessons, 750 original questions and 15 safe labs. Online, self-paced learning in British English.
One-off payment with no automatic renewal. The official ISC2 exam and any voucher are excluded.
Turn the outline into a personal study map
For an English-language exam plan, keep the official English outline beside your notes. Record the version date, mark the objectives you can explain and write down one practical decision for each area. A domain label alone does not demonstrate that you can apply the idea.
For example, connect access management to a fictional starter, role change and leaver in a UK organisation. List the permissions to grant, review or remove and explain who approves each step. This is an illustrative study scenario; it does not replace your employer’s policies.
Which version should up-to-date preparation use?
For students taking the exam under the outline effective from 1 September 2026, the authoritative reference is the future PDF published by ISC2, identified as v01/2026. KINTAVOR uses the internal editorial code CC_2026_09 to prevent old questions or lessons from being mixed in silently.
Each item stores its version, domain, objective, sub-objective, source, review date, difficulty, editorial status and change history. When another version appears, a new relationship is created; previous content is not deleted or relabelled as though it had always been new.
The five domains and their weightings
| Domain | Weight | Approach |
|---|---|---|
| Security principles | 24 % | Concepts, risks, basic governance, controls and ethics. |
| Security governance | 17.3 % | GRC, continuity, recovery, awareness and measurement. |
| IAM concepts | 20 % | Identity lifecycle and logical access controls. |
| Network and cloud security | 21.3 % | Networks, defensive architecture and cloud models. |
| Operations and response | 17.3 % | Data, monitoring, incidents, assets and testing. |
The printed values total 99.9% due to rounding, although the document declares a total of 100%. It is unwise to change a weighting to “correct” this: a rigorous platform preserves the official values and documents the difference.
What you study within each domain
1. Security principles
Includes confidentiality, integrity and availability; authentication, authorisation and accounting; non-repudiation and privacy; risk processes; laws, frameworks, policies and procedures; technical, administrative and physical controls; and professional conduct, due care and due diligence.
2. Security governance
Covers the purpose of GRC, business continuity, disaster recovery, redundancy, culture and leadership, social engineering, password protection, awareness, metrics, key risk indicators, dashboards and reports.
3. Identity and Access Management
Focuses on roles, provisioning, review and deprovisioning, frameworks and tools, least privilege, separation of duties and access control models. Multifactor authentication is useful supplementary knowledge within AAA, but does not appear as a separate, explicitly stated sub-objective in the future PDF.
4. Networks and cloud
Covers OSI and TCP/IP, IPv4 and IPv6, VPNs, firewalls, ports, applications, Wi‑Fi, Bluetooth, ICS, IoT, zones, VLANs, microsegmentation, defence in depth, Zero Trust, cloud characteristics, service and deployment models, and shared security.
5. Operations and incident response
Brings together data classification and sanitisation; encryption, hashing and quantum-resistant cryptography; logs, monitoring and triage; threat actors and intelligence; response; assets and changes; blue, red and purple teams; vulnerabilities, static and dynamic analysis, modelling and physical testing.
How to check whether a course covers the outline
A list of titles does not demonstrate coverage. A useful check links each lesson and question to a specific public objective and then measures gaps or excessive concentration on popular topics. A bank may contain many password questions yet still ignore continuity, metrics or change management.
- Check that every question has a valid version and objective.
- Verify the overall distribution against the published weightings.
- Detect references to weightings, names or structures from the 2025 outline.
- Review contradictory explanations, repeated options and semantic duplicates.
- Temporarily withdraw any reported item until it is resolved.
How to allocate study time by weighting and difficulty
Weighting guides time allocation but should not become the only rule. A domain with a lower percentage may contain concepts that are new to you. Use the weighting as a starting point, add time for identified weak areas and reserve cross-domain sessions for scenarios combining IAM, networks, data and response.
At KINTAVOR, module 0 does not compete with the five domains: it provides a learning foundation. Subsequent statistics distinguish performance in official domains from supplementary activities. This prevents improvement in basic computing from masking a real weakness in the syllabus.
Frequently asked questions
Can I study using 2025 materials?
It may help with stable concepts, but its weightings and structure must not be mixed with the version effective from September 2026. Each item of content needs version control.
Why do the percentages add up to 99.9%?
This results from rounding the printed values. The official document states a total of 100%.
Is MFA part of the syllabus?
It is a useful learning concept related to authentication and AAA. It must not be labelled as a separate, explicitly stated sub-objective of the future outline.
Does the UK course use English terminology?
Yes. The teaching is in British English and retains standard technical terms. This guide links to ISC2’s English outline so that you can check objective names and the applicable version directly.
Check which domains you recognise
A short diagnostic can help you decide where to start before opening the first module.
Official sources consulted
Source links checked on 15 September 2026. Requirements, prices and policies may change.
