
Leverage the CIA triad, security governance, and risk management—risk assessment and response—within ISO 27000, ITIL, and COBIT frameworks to support policy, continuity, disaster recovery, and compliance.
develop and implement a business continuity plan with disaster recovery as a subplan, identify risks, define recovery timelines, and establish crisis communication and incident response.
Explore the components of business continuity and disaster recovery planning, including maximum tolerable downtime, RPO and RTO, backup strategies, facility options, and testing to ensure resilience.
Explore asset security with a data focus, covering the CIA triad, access control, data states, classification, risk, and practical controls like hardening, auditing, encryption, and retention.
Provide an overview of security engineering focusing on secure design, security policies, and security models like Bell-LaPadula and Biba, along with cryptography and PKI.
Explore security engineering concepts in CISSP, including PKI, digital certificates, certificate authorities, registration authorities, CRLs, and data protection through SSL/TLS, IPsec, VPNs, SSH, and cryptographic attacks.
Explore the essentials of communications and network security, from the OSI model and network devices to common threats, firewalls, VPNs, wireless security, and cloud implications.
Explore identity and access management through authentication, authorization, and auditing, covering single sign-on, access control models, and defenses against threats like brute force and authorization creep.
Present security assessment and testing through ethical penetration testing, covering black box, white box, and gray box approaches to identify weaknesses for management action.
Analyze protocol analyzers such as Wireshark and traffic capture in promiscuous mode; evaluate hardware and software intrusion detection systems, signature databases, pattern versus profile learning, and safe honeypot labs.
Explore incident response leadership, forensic evidence collection and chain-of-custody, root-cause analysis, plus backups, fault tolerance, and business continuity to minimize cyber incident impact.
Explore software development security across the lifecycle, covering object-oriented design, databases, data warehousing and data mining, and vulnerabilities like code injection; learn design practices, acid transactions, and capability maturity model.
About this course:
In the information security industry, the Certified Information Systems Security Professional (CISSP) is the most widely recognized qualification. CISSP validates the in-depth technological and management knowledge and experience of an information security professional to effectively plan, develop and maintain an organization's overall security.
Covers eight security areas that are essential to the protection of information systems, corporations and national infrastructure. Knowing that security is an enterprise-wide problem, these areas provide the applicant with a broad understanding of the technological, administrative and human factors that need to effectively collaborate to keep information and systems secure.