# Mithril Dojo — Credential Learning Guide (CISSP® / CISA®)

Checked 2026-10-07. Exam outlines, eligibility, and maintenance rules change; candidates must confirm current requirements with each credentialing body before registering.

## What this guide is

This guide and the original knowledge checks show where the Dojo's AI-agent safety training overlaps with publicly stated CISSP/CISA domains. They are not exam-preparation courses, official practice exams, guarantees of certification, or substitutes for required work experience. Mithril Dojo is not sponsored, endorsed, or accredited by ISC2, ISACA, or Black Hat. Credential names and marks belong to their respective owners.

## Which pathway to explore

| | CISSP® | CISA® |
| --- | --- | --- |
| Primary focus | Broad security design, operations, and management | Information systems audit, IT controls, operations, and asset protection |
| Exam structure | Eight domains; current outline describes CAT, 100–150 items, 3 hours | Five job-practice domains; 150 questions |
| Experience overview | Five cumulative years across at least two of eight domains; a qualifying degree or credential may waive up to one year | Five years of professional IS audit, control, or security work is the baseline; verify current substitutions and waivers with ISACA |
| Maintenance | 120 CPE over three years: 90 Group A and 30 Group A/B; 40 annually is the policy's suggested pace | At least 20 CPE annually and 120 over three years |
| Dojo overlap | Partial alignment, especially risk/ethics, IAM, assessment/testing, and selected operations topics | Partial alignment, especially audit evidence, reporting, follow-up, and information-asset protection |

Passing an exam is separate from receiving and maintaining a credential. Endorsement/application, experience verification, ethics, fees, and CPE requirements still apply under the issuer's current rules.

## Alignment with the current Dojo curriculum

“Strong touchpoint” means the current course directly practises a related learning outcome; “partial” means only a subset; “not covered” means the course does not assess it. This mapping does not predict exam performance.

### CISSP® — eight domains

| Official domain | Dojo alignment | Evidence and gaps |
| --- | --- | --- |
| 1. Security and Risk Management | Strong touchpoint | Authorization, ethics, legal boundaries, scope, risk, responsible disclosure. Broad governance and business continuity are not covered |
| 2. Asset Security | Partial | Synthetic data, excluding secrets/PII, minimizing evidence. Classification, retention, disposal, lifecycle controls are not covered |
| 3. Security Architecture and Engineering | Partial | Least privilege, isolation, secure design decisions. Cryptography, model internals, and broad architecture are not covered |
| 4. Communication and Network Security | Limited | Egress restriction as a concept. Network design, protocols, and hands-on infrastructure are not covered |
| 5. Identity and Access Management | Strong touchpoint | Agent permissions, approval gates, short-lived access, non-human identity boundaries. Broad authentication design is not covered |
| 6. Security Assessment and Testing | Strong touchpoint | Scope decisions, safe testing, evidence quality, reproducibility, remediation checks. No assessment of real systems is included |
| 7. Security Operations | Partial | Reading synthetic logs, reporting, escalation, retest. SOC, incident response, and continuity are not covered |
| 8. Software Development Security | Partial | AI workflow threat analysis and safe change proposals. SDLC, secure coding, and code-review labs are not covered |

### CISA® — five job-practice domains

| Official domain | Weight | Dojo alignment | Evidence and gaps |
| --- | ---: | --- | --- |
| 1. Information Systems Auditing Process | 18% | Partial | Scope, evidence, reporting, follow-up. Audit standards, planning, sampling, and QA are not covered |
| 2. Governance and Management of IT | 18% | Limited | Ethics, approver, policy, risk boundaries. IT governance, organization, vendors, and performance management are not covered |
| 3. Information Systems Acquisition, Development and Implementation | 12% | Limited | Review of agent policy and safe acceptance criteria. Acquisition, project controls, migration, and post-implementation review are not covered |
| 4. Information Systems Operations and Business Resilience | 26% | Limited | Logs, stop conditions, retest. Operations, change management, backup, BCP/DR are not covered |
| 5. Protection of Information Assets | 26% | Partial | IAM, data minimization, evidence protection, threat awareness. Cryptography, network/endpoints, monitoring, and forensic practice are not covered |

## How to use the learning materials

1. Read the current official exam outline and separately inventory your work experience and knowledge.
2. Use the alignment tables to distinguish Dojo touchpoints from subjects that require official or broader study resources.
3. Use `certification-practice.en.md` only as an original diagnostic quiz. Do not convert its score into a predicted exam result.
4. Prefer current official ISC2/ISACA resources for exam preparation. Do not use the Dojo as your sole preparation source.

## CPE and completion evidence

Dojo does not award, approve, or guarantee CPE hours. Learners must determine whether an activity qualifies under their credential body's current policy and ask the issuer when uncertain. Any attendance statement should report actual attendance, content, and timing only; it must not say “CPE awarded” or imply approved-provider status. See `cpe-attendance-record.en.md`.

## Instructor credential disclosure

No individual instructor credentials are currently listed as verified for Dojo. This is a publication status, not a claim that no instructor holds a credential.

Do not list an instructor's CISSP/CISA or other credential until evidence and the individual's permission to publish have been checked. If verified, disclose only credential name, verification date/status, issuer, and instructor-approved wording. Do not publish credential numbers, private badge URLs, or identity documents. An instructor's credential does not imply endorsement or accreditation of the Dojo.

## Official references

- [ISC2 CISSP Exam Outline](https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline) — includes a Japanese outline link
- [ISC2 CISSP Experience Requirements](https://www.isc2.org/certifications/cissp/cissp-experience-requirements)
- [ISC2 Member Policies / CPE requirements](https://www.isc2.org/policies-procedures/member-policies)
- [ISACA CISA Exam Content Outline](https://www.isaca.org/credentialing/cisa/cisa-exam-content-outline)
- [ISACA Earn a CISA Certification](https://www.isaca.org/credentialing/cisa/get-cisa-certified)
- [ISACA Maintain CISA / CPE](https://www.isaca.org/credentialing/cisa/maintain-cisa-certification)
