Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
CCSP Domain 6 - Legal & Compliance
Rating: 4.6 out of 5(340 ratings)
2,979 students

CCSP Domain 6 - Legal & Compliance

Fine tune your knowledge that you need to pass the CCSP Exam for the Legal domain up to date with the Aug 22 exam.
Last updated 11/2022
English

What you'll learn

  • Understand what (ISC)2 expects you to know about laws and regulations for the CCSP exam under the August 2022 update.
  • Recognize laws and regulations and be able to divide them in to categories such as privacy or healthcare.
  • Comprehend what an audit entails.
  • Understand what industrial controls systems and programmable logic computers are used for.
  • Understand the privacy maturity model.

Course content

11 sections25 lectures2h 50m total length
  • Introduction to the Legal domain11:20

    In this video we will cover:


    • Legal and Compliance (13% of the Test).

    • Legal? What If you are not a Lawyer?

    • What do you need to know about the exam?

    • ENISA Cloud Computing Key Legal Issues.

    • Contracts

    • CSP and MSP

    • Contract Parts

    In this video you will learn:


    What should you know about information security laws for the test and the fundamental legal issues with the cloud? You are not expected to be a lawyer. Your responsibility is to talk to the lawyers to ensure you are protecting data appropriately.


    We have significant legal problems with clouds, including:

    • data protection,

    • availability

    • Integrity,

    • confidentiality,

    • intellectual-property control,

    • professional negligence,

    • outsourcing concerns, and

    • changes in IT and IS control.


    These are a few of the topics of concern we have with moving to the cloud.


    So it is critical that you read and possibly negotiate your contract with the cloud provider.


    We have two different terms for cloud providers: Cloud Service Providers and Managed Service Providers. It is good to know the difference.

    In contracts, there are many parts that include:

    • MSA- Master Services Agreement,

    • SLA- Service Legal Agreement, and

    • PLA- Privacy Legal Agreement.

    I recommend that you download and look through all of the additional content I have added in the format of files. In particular the CSA Guidance 4.0. This is a CSA exam. They partnered with ISC2 to provide a solid testing environment.


    We encourage you to learn more about Legal Intro by watching this complete video. See you in the Next Video.

  • Read the ENISA Cloud Computing Security Risk Assessment document

Requirements

  • A desire to learn what you need to know about laws and regulations for the CCSP exam.
  • There are no requirements. An understanding of networking can be very beneficial though.
  • A basic understanding of information security is recommended.

Description

In this course we walk through all of the critical concepts within the Legal and Compliance domain. Legal is only 13% of the test, but if you are not properly prepared it can have a huge impact on your success. I will guide you through all of the concepts that you need to know and advise you on the level of knowledge that you need to get comfortable with.

There is nearly 3 hours of video content plus course notes based on information from my book: Cloud Guardians.

In here you will learn about privacy laws (especially ones that are good to be aware of), financial laws, health care laws and many other regulations. Privacy laws include the EU's GDPR, Canada's PIPEDA and more.

There are also many US Government regulations that you should be familiar with such as the CLOUD act, Fed RAMP, and the Stored Communication Act (SCA).

You will be guided through the parts of a contract as well as contractual requirements such as PCI-DSS.

In order to be in compliance with applicable laws, regulations, standards, contracts and policies it is necessary to have audits performed. We will explore the AICPA's auditing standard and resulting reports, such as SOC 2 Type II.

The final piece to this domain is the topic of forensics. Especially how the cloud impacts a forensic investigation.

Who this course is for:

  • This course is intended for people that are preparing for the (ISC)2 CCSP exam with the August 2022 updates..
  • This course would benefit anyone working to expand their knowledge and understanding of the cloud and its impact on laws and regulations.