E-guide CISSP Prep: 4 Steps to Achieve Your Certification

Similar documents
E-guide Getting your CISSP Certification

Certified information Systems Security Professional(CISSP) Bootcamp

ISSMP is in compliance with the stringent requirements of ANSI/ISO/IEC Standard

Course Outline. CISSP - Certified Information Systems Security Professional

Pearson CISSP Cert Guide with Labs. Course Outline. Pearson CISSP Cert Guide with Labs. 17 Oct

CyberVista Certify cybervista.net

Certification Exam Outline Effective Date: April 2018

FOUNDATION CERTIFICATE IN INFORMATION SECURITY v2.0 INTRODUCING THE TOP 5 DISCIPLINES IN INFORMATION SECURITY SUMMARY

CISM - Certified Information Security Manager. Course Outline. CISM - Certified Information Security Manager.

ISSEP is in compliance with the stringent requirements of ANSI/ISO/IEC Standard

CISM - Certified Information Security Manager. Course Outline. CISM - Certified Information Security Manager. 22 Mar

Shon Harris s Newly Updated CISSP Materials

"Charting the Course... Certified Information Systems Auditor (CISA) Course Summary

The fast track to top skills and top jobs in cyber. Guaranteed.

Building the Cybersecurity Workforce. November 2017

Certified Information Security Manager (CISM) Course Overview

EXAM PREPARATION GUIDE

Cyber Security Program

Certification Exam Outline Effective Date: September 2013

HCISPP HealthCare Information Security and Privacy Practitioner

(ISC) 2 CONTINUING PROFESSIONAL EDUCATION (CPE) POLICIES AND GUIDELINES

GUIDELINES FOR SUBMITTING CONTINUING PROFESSIONAL EDUCATION (CPE) CREDITS

GUIDELINES FOR SUBMITING CONTINUING PROFESSIONAL EDUCATION (CPE) CREDITS

Security Program Design:

FRAMEWORK MAPPING HITRUST CSF V9 TO ISO 27001/27002:2013. Visit us online at Flank.org to learn more.

Cybersecurity Auditing in an Unsecure World

Continuous protection to reduce risk and maintain production availability

BUILDING CYBERSECURITY CAPABILITY, MATURITY, RESILIENCE

(ISC) 2 CONTINUING PROFESSIONAL EDUCATION (CPE) POLICIES AND GUIDELINES

CISA Training.

EU General Data Protection Regulation (GDPR) Achieving compliance

COURSE BROCHURE. COBIT5 FOUNDATION Training & Certification

CCISO Blueprint v1. EC-Council

Computer Information Systems (CIS) CIS 105 Current Operating Systems/Security CIS 101 Introduction to Computers

CISSP* CBK (ISC) GUIDE TO THE. OFFICIAL (ISCf. \Xjfl^J Taylor &. Francis Group ' Boca Raton London New York. CRC Press THIRD EDITION

Project Management Professional (PMP) Exam Preparation elearning Course

Principles of Information Security, Fourth Edition. Chapter 1 Introduction to Information Security

Information Systems and Tech (IST)

Why MyITstudy is the best solution for your IT training needs

Application for Certification

COURSE BROCHURE CISA TRAINING

Department of Management Services REQUEST FOR INFORMATION

Certified Manager Certification

Ingram Micro Cyber Security Portfolio

Reasons to Become CISSP Certified. Keith A. Watson, CISSP CERIAS

CIPP/G (Certified Information Privacy Professional US Government)

PRODUCT SAFETY PROFESSIONAL CERTIFICATION PROGRAM DETAILS. Overview

EXAM PREPARATION GUIDE

Google Cloud & the General Data Protection Regulation (GDPR)

Workforce Certification

Course Outline. CISSP - Certified Information Systems Security Professional 2015 (Course & Labs)

CIPT Certified Information Privacy Technologist

M.S. IN INFORMATION ASSURANCE MAJOR: CYBERSECURITY. Graduate Program

DFARS Compliance. SLAIT Consulting SECURITY SERVICES. Mike D Arezzo Director of Security Services. SLAITCONSULTING.com

Access Control and Physical Security Management. Contents are subject to change. For the latest updates visit

Certification Exam Outline Effective Date: April 2015

CompTIA Security+ Study Guide (SY0-501)

IS305 Managing Risk in Information Systems [Onsite and Online]

TEL2813/IS2820 Security Management

Cissp Certification All In One Exam Guide Shon Harris

BUILD YOUR CYBERSECURITY SKILLS WITH TRASYS INTERNATIONAL

Certified Cyber Security Specialist

SY CompTIA Security+ Course Outline. SY CompTIA Security+ 31 Oct

Implementation of Business Continuity Management System (BCMS) based on ISO 22301:2012 requirements

VMEdu. 94 (Out of 100) D&B Rating. A+ BBB Rating. VMEdu Training. VMEdu Platform

DATA SHEET RISK & CYBERSECURITY PRACTICE EMPOWERING CUSTOMERS TO TAKE COMMAND OF THEIR EVOLVING RISK & CYBERSECURITY POSTURE

Computer Information Systems (CIS) CIS 105 Current Operating Systems/Security CIS 101 Introduction to Computers

Certified Information Systems Auditor (CISA)

RISK MANAGEMENT Education and Certification

The GenCyber Program. By Chris Ralph

New York Cybersecurity. New York Cybersecurity. Requirements for Financial Services Companies (23NYCRR 500) Solution Brief

Advent IM Ltd ISO/IEC 27001:2013 vs

Strengthening Capacity in Cyber Talent sans.org/cybertalent

ISAO SO Product Outline

Certified in Risk and Information Systems ControlTM Certification Training - Brochure

COURSE BROCHURE. Professional Cloud Service Manager Training & Certification

Background of the North America Top Technology Initiatives Survey

Controlled Document Page 1 of 6. Effective Date: 6/19/13. Approved by: CAB/F. Approved on: 6/19/13. Version Supersedes:

Practitioner Certificate in Business Continuity Management (PCBCM) Course Description. 10 th December, 2015 Version 2.0

TARGET2-SECURITIES INFORMATION SECURITY REQUIREMENTS

locuz.com SOC Services

IE156: ICS410: ICS/SCADA Security Essentials

Criminal Justice Information Security (CJIS) Guide for ShareBase in the Hyland Cloud

EXAM PREPARATION GUIDE

Security Management Models And Practices Feb 5, 2008

Associate in Science and Bachelor of Science in Information Technology

Information Governance: What s all the Hype? Raymond K. Cunningham, Jr. CRM, CA, CDIA+, CIP, CIPM University of Illinois Foundation

EXAM PREPARATION GUIDE

THE POWER OF TECH-SAVVY BOARDS:

THE ISACA CURACAO CHAPTER IS ORGANIZING FOLLOWING INFORMATION SECURITY AND TECHNOLOGY SESSIONS ON MAY 15-MAY :

BCM Program Development

BENEFITS of MEMBERSHIP FOR YOUR INSTITUTION

Evaluating and Improving Cybersecurity Capabilities of the Electricity Critical Infrastructure

COMESA CYBER SECURITY PROGRAM KHARTOUM, SUDAN

Free Cissp Official Isc2 Practice Tests By Mike Chapple

EXAM PREPARATION GUIDE

EXAM PREPARATION GUIDE

Security Policies and Procedures Principles and Practices

EXAM PREPARATION GUIDE

Master the implementation and management of a Cybersecurity Program based on ISO/IEC 27032

Transcription:

CISSP Prep: 4 Steps to Achieve Your Certification Practice for the exam and keep your skills sharp

: Thank you for downloading our CISSP certification guide. Aside from this handy PDF, you can also access critical CISSP certification information on SearchSecurity.com. Obtaining CISSP certification is globally recognized as a standard of achievement for security professionals. Today, many large corporations and governmental agencies now require the certification for a position, thus giving CISSPs a higher earning potential and greatly expanded career opportunities. In partnership with global information security educator and certification leader (ISC)², SearchSecurity.com is providing information security professionals tools and resources to earn and maintain your CISSP certification. Page 1 of 11

Step 1: Test Your Knowledge First, test your knowledge by taking the CISSP practice exam. This is a free benefit to SearchSecurity.com members. We encourage you to come back often while you are studying for the CISSP. Page 2 of 11

Step 2: Study for the CISSP Test with Trainings and Texts Learn more about CISSP domains The CISSP exam covers 8 subject areas, which are referred to as domains. These domains are drawn from various security topics within the (ISC)² Common Body of Knowledge, a framework of best practices, methodologies, technologies, and concepts. The CISSP candidate must have at least 5 years of paid full-time experience in 2 or more of the domains. Prepare for the 8 domains listed below with 10 free lessons from SearchSecurity s CISSP Essentials Security School, featuring videos, tutorials, and sample exam questions. Page 3 of 11

The 10 lessons in CISSP Essentials Security School are broken down into three domain groups. The first three domains focus on securing assets and reveal the essential elements to build an organizational enterprise security program, including the frameworks, technologies and methodologies to protect every company's primary information asset: its data. Domains 4-6 focus on securing the infrastructure as they reveal the nuts and bolts of how to best apply security to everyday computer and business operations. Fundamental concepts explored in the sessions include how to effectively design security architectures, implement secure networks and build security into applications and systems. Finally domains 7-10 cover the business of security, an area that is ignored far too often in some of today's "status quo" enterprises. Security is often thought of exclusively in terms of technology, but corporate security is much more. It involves everything from governance, business management and regulatory compliance, to an understanding of physical security, disaster recovery and the law. Page 4 of 11

An Overview of the 8 CISSP Domains Security and Risk Management (Security, Risk, Compliance, Law, Regulations, and Business Continuity) Confidentiality, integrity, and availability concepts Security governance principles Compliance Legal and regulatory issues Professional ethic Security policies, standards, procedures and guidelines Asset Security (Protecting Security of Assets) Information and asset classification Ownership (e.g. data owners, system owners) Protect privacy Appropriate retention Data security controls Handling requirements (e.g. markings, labels, storage) Security Engineering (Engineering and Management of Security) Engineering processes using secure design principles Security models fundamental concepts Security evaluation models Page 5 of 11

Security capabilities of information systems Security architectures, designs, and solution elements vulnerabilities Web-based systems vulnerabilities Mobile systems vulnerabilities Embedded devices and cyber-physical systems vulnerabilities Cryptography Site and facility design secure principles Physical security Communication and Network Security (Designing and Protecting Network Security) Secure network architecture design (e.g. IP & non-ip protocols, segmentation) Secure network components Secure communication channels Network attacks Identity and Access Management (Controlling Access and Managing Identity) Physical and logical assets control Identification and authentication of people and devices Identity as a service (e.g. cloud identity) Third-party identity services (e.g. on-premise) Access control attacks Page 6 of 11

Identity and access provisioning lifecycle (e.g. provisioning review) Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing) Assessment and test strategies Security process data (e.g. management and operational controls) Security control testing Test outputs (e.g. automated, manual) Security architectures vulnerabilities Security Operations (Foundational Concepts, Investigations, Incident Management, and Disaster Recovery) Investigations support and requirements Logging and monitoring activities Provisioning of resources Foundational security operations concepts Resource protection techniques Incident management Preventative measures Patch and vulnerability management Change management processes Recovery strategies Disaster recovery processes and plans Page 7 of 11

Business continuity planning and exercises Physical security Personnel safety concerns Software Development Security (Understanding, Applying, and Enforcing Software Security) Security in the software development lifecycle Development environment security controls Software security effectiveness Acquired software security impact Buy the Official (ISC)² Guide to the CISSP CBK Find all official ISC² textbooks here. All (ISC)² members receive 50% off Official (ISC)² Textbooks as a member benefit. Page 8 of 11

Step 3: Retake the CISSP Practice Exam This practice session will offer you a preview of 20 questions pulled straight from previous CISSP exams to give you a sneak peak of what the certification exam entails. Come back daily for a new batch of questions and check out our related study resources to help boost your score. As a member of SearchSecurity, you have free access to our database of CISSP practice test questions, presented in cooperation with (ISC)². Page 9 of 11

Step 4: Schedule your Exam Date You can schedule your exam with Pearson Vue (ISC)² testing partner. Already a CISSP? SearchSecurity.com has the resources you need to earn your CPEs -- including these (ISC)² approved methods: Attend a local, live seminar with industry experts. Go online and participate in one of our Virtual Events. Stay informed with Information Security magazine. Use our free online training courses Learn more about SearchSecurity.com's CPE options. What is CISSP? To learn more about CISSP certification check out their website. And for more information, please email (ISC)² Education or call +1.866.462.4777 (toll-free in North America only) or +1.703.891.6781 outside the United States. Page 10 of 11

About SearchSecurity IT security pros turn to SearchSecurity.com for the information they require to keep their corporate data, systems and assets secure. We're the only information resource that provides immediate access to breaking industry news, virus alerts, new hacker threats and attacks, security certification training resources, security standard compliance, webcasts, white papers, podcasts, Security Schools, a selection of highly focused security newsletters and more -- all at no cost. For further reading, visit us at http://searchsecurity.com/ Images; Fotalia 2017 TechTarget. No part of this publication may be transmitted or reproduced in any form or by any means without written permission from the publisher. Page 11 of 11