In this 5-day course we will analyze and discuss the topics tested in the CISSP exams
This course is intended for individuals who intend to pursue CISSP certification.
- Security and risk management
- Asset security
- Security Architecture and Engineering
- Communications and network security
- Identity and access management
- Security assessment and testing
- Security operations
- Security of software development
Before taking this course, the learner should have the following knowledge gained while performing the following roles:
• Chief Information Officer Officer
• Chief Information Security Officer
• Technical Director
• Manager/Compliance Officer
• Security Director
• The information architect
• Information Manager / Information Risk Manager or Consultant
• IT Specialist/Director/Manager
• Network/System Administrator
• Security administrator
• Security Architect / Security Analyst
• Security consultant
• Security manager
• Security Systems Engineer/ Security Engineer
Module 1: SECURITY AND RISK MANAGEMENT
Learning Objectives:
• Justify an organizational code of ethics.
• Relate confidentiality, integrity, availability, non-repudiation, authenticity, privacy and safety to due care and due diligence.
• Relate information security governance to organizational business strategies, goals, missions, and objectives.
• Apply the concepts of cybercrime to data breaches and other information security compromises.
• Relate legal, contractual, and regulatory requirements for privacy and data protection to information security objectives.
• Relate transborder data movement and import-export issues to data protection, privacy, and intellectual property protection.
Module 2: INFORMATION ASSET SECURITY
Learning Objectives:
• Relate the IT asset management and data security lifecycle models to information security.
• Explain the use of information classification and categorization, as two separate but related processes.
• Describe the different data states and their information security considerations.
• Describe the different roles involved in the use of information, and the security considerations for these roles.
• Describe the different types and categories of information security controls and their use.
• Select data security standards to meet organizational compliance requirements.
Module 3: IDENTITY AND ACCESS MANAGEMENT (IAM)
Learning Objectives:
• Explain the identity lifecycle as it applies to human and non-human users.
• Compare and contrast access control models, mechanisms, and concepts.
• Explain the role of authentication, authorization, and accounting in achieving information security goals and objectives.
• Explain how IAM implementations must protect physical and logical assets.
• Describe the role of credentials and the identity store in IAM systems.
Module 4: SECURITY ARCHITECTURE AND ENGINEERING
Learning Objectives:
• Describe the major components of security engineering standards.
• Explain major architectural models for information security.
• Explain the security capabilities implemented in hardware and firmware.
• Apply security principles to different information systems architectures and their environments.
• Determine the best application of cryptographic approaches to solving organizational information security needs.
• Manage the use of certificates and digital signatures to meet organizational information security needs.
• Discover the implications of the failure to use cryptographic techniques to protect the supply chain.
• Apply different cryptographic management solutions to meet the organizational information security needs.
• Verify cryptographic solutions are working and meeting the evolving threat of the real world.
• Describe defenses against common cryptographic attacks.
• Develop a management checklist to determine the organization's cryptologic state of health and readiness.
Module 5: COMMUNICATION AND NETWORK SECURITY
Learning Objectives:
• Describe the architectural characteristics, relevant technologies, protocols and security considerations of each of the layers in the OSI model.
• Explain the application of secure design practices in developing network infrastructure.
• Describe the evolution of methods to secure IP communications protocols.
• Explain the security implications of bound (cable and fiber) and unbound (wireless) network environments.
• Describe the evolution of, and security implications for, key network devices.
• Evaluate and contrast the security issues with voice communications in traditional and VoIP infrastructures.
• Describe and contrast the security considerations for key remote access technologies.
• Explain the security implications of software-defined networking (SDN) and network virtualization technologies.
Module 6: SOFTWARE DEVELOPMENT SECURITY
Learning Objectives:
• Recognize the many software elements that can put information systems security at risk.
• Identify and illustrate major causes of security weaknesses in source code.
• Illustrated major causes of security weaknesses in database and data warehouse systems.
• Explain the applicability of the OWASP framework to various web architectures.
• Select malware mitigation strategies appropriate to organizational information security needs.
• Contrast the ways that different software development methodologies, frameworks, and guidelines contribute to systems security.
• Explain the implementation of security controls for software development ecosystems.
• Choose an appropriate mix of security testing, assessment, controls, and management methods for different systems and application environments
Module 7: SECURITY ASSESSMENT AND TESTING
Learning Objectives:
• Describe the purpose, process, and objectives of formal and informal security assessment and testing.
• Apply professional and organizational ethics to security assessment and testing.
• Explain internal, external, and third-party assessment and testing.
• Explain management and governance issues related to planning and conducting security assessments.
• Explain the role of assessment in data-driven security decision-making.
Module 8: SECURITY OPERATIONS
Learning Objectives:
• Show how to efficiently and effectively gather and assess security data.
• Explain the security benefits of effective change management and change control.
• Develop incident response policies and plans.
• Link incident response to needs for security controls and their operational use.
• Relate security controls to improving and achieving required availability of information assets and systems.
• Understand the security and safety ramifications of various facilities, systems, and infrastructure characteristics.
Candidates must have a minimum of 5 years of cumulative full-time, paid work experience in 2 or more of the 8 areas of the CISSP CBK. Obtaining a 4-year college degree or regional equivalent or additional credential from the approved list (ISC)² will satisfy 1 year of required experience. Education credit will only satisfy 1 year of experience.
A candidate who does not have the experience to become a CISSP can become an Associate of (ISC)² by successfully passing the CISSP exam. The Associate (ISC)² will then have 6 years to gain the required 5 years of experience.
Accreditation
CISSP was the first information security accreditation to meet the stringent requirements of the ANSI/ISO/IEC 17024 standard.
CISSP CAT Exam Information
Duration of the exam: 3 hours
Number of questions: 100 – 150
Question format: multiple choice questions and advanced innovative questions
Pass mark: 700 out of 1000 points
Availability of exam language: English
Test Center: (ISC)2 Authorized PPC and PVTC Test Centers Select Pearson VUE
CISSP Bootcamp


