Welcome to Certified Information Systems Security Professional (CISSP®): Seventh Edition. With your completion of the prerequisites and necessary years of experience, you are firmly grounded in the knowledge requirements of today's security professional. This course will expand upon your knowledge by addressing the essential elements of the eight domains that comprise a Common Body of Knowledge (CBK®) for information systems security professionals. The course offers a job-related approach to the security process, while providing a framework to prepare for CISSP certification.
CISSP is the premier certification for today's information systems security professional. It remains the premier certification because the sponsoring organization, the International Information Systems Security Certification Consortium, Inc. (ISC)2®, regularly updates the test by using subject matter experts (SMEs) to make sure the material and the questions are relevant in today's security environment. By defining eight security domains that comprise a CBK, industry standards for the information systems security professional have been established. The skills and knowledge you gain in this course will help you master the eight CISSP domains and ensure your credibility and success within the information systems security field.
This course is intended for experienced IT security-related practitioners, auditors, consultants, investigators, or instructors, including network or security analysts and engineers, network administrators, information security specialists, and risk management professionals, who are pursuing CISSP training and certification to acquire the credibility and mobility to advance within their current computer security careers or to migrate to a related career. Through the study of all eight CISSP CBK domains, students will validate their knowledge by meeting the necessary preparation requirements to qualify to sit for the CISSP certification exam. Additional CISSP certification requirements include a minimum of five years of direct professional work experience in two or more fields related to the eight CBK security domains, or a college degree and four years of experience.
This course targets the 2024 version of the CISSP exam.
In this course, you will identify and reinforce the major security subjects from the eight domains of the (ISC)2 CISSP CBK. You will:
• Analyze components of the Security and Risk Management domain.
• Analyze components of the Asset Security domain.
• Analyze components of the Security Architecture and Engineering domain.
• Analyze components of the Communication and Network Security domain.
• Analyze components of the Identity and Access Management domain.
• Analyze components of the Security Assessment and Testing domain.
• Analyze components of the Security Operations domain.
• Analyze components of the Software Development Security domain
You will need to have the following software installed: Microsoft Windows® and Adobe® Acrobat® Reader or an equivalent PDF viewer. The course setup instructions provided in the first module of the course go into more detail about the hardware and software requirements.
In this course, you will explore a broad range of security concepts and best practices designed to meet the demands of increasingly specialized information systems security. Before you address specific security areas or elements, it is important that you have a plan in place for the overall management of these processes and elements. In this lesson, you will understand what comprises successful security and risk management.
涵盖的内容
16个插件
显示有关单元内容的信息
16个插件•总计460分钟
Getting Started with This Course•30分钟
Lesson Introduction•5分钟
Security Concepts•30分钟
Security Governance Principles•30分钟
Compliance•30分钟
Professional Ethics•30分钟
Security Documentation•30分钟
Risk Management•30分钟
Threat Modeling•30分钟
Risk Response•30分钟
Business Continuity Plan Fundamentals•30分钟
Acquisition Strategy and Practice•30分钟
Personnel Security Policies•30分钟
Security Awareness and Training•30分钟
Mastery Builder: Assessing Security and Risk Management•60分钟
Lesson Summary•5分钟
Asset Security
第 2 单元•小时 后完成
单元详情
In the last lesson, you learned the importance of the CIA triad and risk assessment and management. Because data is such an important asset to an organization, many of these same concepts will need to be applied to it as well. As data needs become more critical and the need to access it even more real time, it has become even more difficult to protect it. Organizations have always needed to protect their physical data assets and now they need to protect their logical data assets as well. Additionally, your users are no longer willing to exclusively work at their desk; they want whenever, wherever access. This means protecting data on more devices in more places than ever before. Companies need to consider all the places they store and transmit data and look for ways to protect it.
涵盖的内容
9个插件
显示有关单元内容的信息
9个插件•总计175分钟
Lesson Introduction•5分钟
Asset Classification•20分钟
Secure Data Handling•20分钟
Resource Provisioning and Protection•20分钟
Manage Data Lifecycle•20分钟
Asset Retention•20分钟
Data Security Controls•20分钟
Mastery Builder: Assessing Asset Security•45分钟
Lesson Summary•5分钟
Security Architecture and Engineering
第 3 单元•小时 后完成
单元详情
Now that you understand the relationship between assets, risks, and security, you can start to design cybersecurity for your organization.
涵盖的内容
15个插件
显示有关单元内容的信息
15个插件•总计490分钟
Lesson Introduction•5分钟
Security in the Engineering Lifecycle•35分钟
System Component Security•35分钟
Security Models•35分钟
Controls and Countermeasures in Enterprise Security•35分钟
Information System Security Capabilities•35分钟
Design and Architecture Vulnerability Mitigation•35分钟
Vulnerability Mitigation in Emerging Technologies•35分钟
Cryptography Concepts•35分钟
Cryptography Techniques•35分钟
Cryptanalytic Attacks•35分钟
Site and Facility Design for Physical Security•35分钟
Physical Security Implementation in Sites and Facilities•35分钟
In the last lesson, you learned about mitigation against vulnerabilities in system components, multiple architectures, and physical security. Many of those topics are pervasive in the CISSP® material, and you will see many of them throughout the course. Topics like defense in depth, cryptography, and network design will present themselves in regards to communication and network security as well. The network is changing, which means additional security measures are necessary. Voice and video are now delivered across the network, where before those were separate networks. Because the network has become such an important part of the business, protecting it has become critical. In this lesson, you will learn about security for your network systems.
涵盖的内容
7个插件
显示有关单元内容的信息
7个插件•总计315分钟
Lesson Introduction•5分钟
Network Protocol Security•65分钟
Network Components Security•65分钟
Communication Channel Security•65分钟
Network Attack Mitigation•65分钟
Mastery Builder: Assessing Communications and Network Security•45分钟
Lesson Summary•5分钟
Identity and Access Management
第 5 单元•小时 后完成
单元详情
A large part of maintaining the confidentiality, integrity, and availability of your data and your systems depends on identity and access control. By properly identifying the user or systems that are trying to gain access, you can determine how much, if any, control to grant them. This keeps unwanted entities out of your systems, while ensuring that the proper entities have exactly what they need, and no more. In this lesson, you will learn about identity and access management.
涵盖的内容
8个插件
显示有关单元内容的信息
8个插件•总计280分钟
Lesson Introduction•5分钟
Physical and Logical Access Control•45分钟
Identification and Authentication•45分钟
Identity as a Service•45分钟
Authorization Mechanisms•45分钟
Access Control Attack Mitigation•45分钟
Mastery Builder: Assessing Identity and Access Management•45分钟
Lesson Summary•5分钟
Security Assessment and Testing
第 6 单元•小时 后完成
单元详情
Now that you have an awareness of the importance of identification and access management, you will learn the importance of security assessments and testing to verify the security of your organization. It is only when you have done a thorough risk assessment of both your physical and logical assets that you can begin the work of protecting the organization. This lesson will delve further into vulnerability assessments, penetration testing, log reviews, all around testing, and validating your security.
涵盖的内容
7个插件
显示有关单元内容的信息
7个插件•总计175分钟
Lesson Introduction•5分钟
System Security Control Testing•30分钟
Software Security Control Testing•30分钟
Security Process Data Collection•30分钟
Audits•30分钟
Mastery Builder: Assessing Security Assessment and Testing•45分钟
Lesson Summary•5分钟
Security Operations
第 7 单元•小时 后完成
单元详情
Security operations is a concept that encompasses two basic ideas: to ensure that day-to-day activities that support the business are protected against risk and to deeply integrate security processes within those activities. Recognizing the importance of both of these ideas is a necessary step in ensuring the organization functions without any impairment. In this lesson, you will learn about the integral link between security and your day-to-day business operations.
In the last lesson, you learned about security operations. Many organizations not only manage their network infrastructure and systems, but also develop software. This can be for in-house use, or to sell to customers. In this final lesson, you will learn about developing software securely.
涵盖的内容
8个插件
显示有关单元内容的信息
8个插件•总计230分钟
Lesson Introduction•5分钟
Security Principles in the System Lifecycle•35分钟
Security Principles in the Software Development Lifecycle•35分钟
Security Controls in the Development Environment•35分钟
Database Security in Software Development•35分钟
Software Security Effectiveness Assessment•35分钟
Mastery Builder: Assessing Software Development Security•45分钟
Lesson Summary•5分钟
Completing the Course
第 9 单元•小时 后完成
单元详情
You'll wrap things up and then validate what you've learned in this course by taking an assessment.
Logical Operations is the world's largest general publisher of instructor-led technology curriculum, and a leader in the technical training community for over 40 years. We employ a rigorous, expert-driven authoring process that, for decades, has produced successful results for learners the world over. Our courseware aligns with real-world business needs and objectives, ensuring learners are able to apply their newly developed skills while on the job.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I purchase the Certificate?
When you purchase a Certificate you get access to all course materials, including graded assignments. Upon completing the course, your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.