
Learn CISSP eligibility, including required experience or alternative pathways, and the endorsement and exam process, then explore the eight security domains and related career tracks.
Examine the eight CISSP domains—security and risk management, asset security, security engineering, communications and network security, identity and access management, security assessment and testing, security operations, and software development security.
Explains the CIA triad—confidentiality, integrity, and availability—and how they protect data from unauthorized access, tampering, and denial of service. Emphasizes encryption, least privilege, hash-based integrity checks, and firewall protection.
Explore identification, authentication, authorization, and accounting through server login, username and password credentials, and authorization decisions about what users can do. Learn how auditing records user activity with log files.
Non-repudiation prevents a user from denying a transaction by maintaining logs and records of the event, including time, device, and IP details.
Apply defense in depth by layering multiple controls across data, application, host, and network to detect and deter attacks at each checkpoint.
Learn how abstraction groups users into roles to apply policies efficiently, practice data hiding to restrict access, and use encryption to protect data in transit and at rest.
Learn security governance and its link to corporate and IT governance, with clear controls and roles to identify threats and monitor breaches. Understand data classification and protection.
Learn security roles and responsibilities, from senior managers approving changes to data owners and custodians protecting data, and examine policy types, standards, procedures, and testing.
Identify and rank threats through threat modeling, applying secure by design and default. Categorize spoofing, tampering, repudiation, information disclosure, DoS, and privilege escalation, and assess assets and safeguards.
Learn how personal security relies on separation of duties, background verification and employment screening, and strong agreements to enforce policies with risk assessment and security controls.
Learn to establish a business continuity plan within a management system, prioritizing people, assessing impacts, and planning for natural and man-made disasters with defined recovery time and recovery point objectives.
Explore criminal, civil, and administrative law, intellectual property rights, and information security regulations, including PCI DSS, encryption, and licensing practices essential for security professionals.
Classify and label hardware and data assets, apply labeling and watermarking, and securely erase data. Learn MTBF and MTTR basics and compare symmetric versus asymmetric encryption with digital certificates.
Explain data at rest and data in motion, and outline classic and modern ciphers—Caesar, substitution, OTP, RSA, AES, DES, 3DES—and public/private keys.
Examine symmetric and public-key cryptography, including RSA, ECC, and El-Gamal, and how hash functions, digital signatures, and certificates secure integrity, authenticity, and online communications.
Explore IPsec as architecture for secure communications between two devices over VPN tunnels, using transport and tunnel modes with AH and ESP, addressing man-in-the-middle, dictionary attacks, and key management.
Explore how the central processing unit, operating system, and memory architectures enable multitasking and multiprogramming, and how virtualization via hypervisor and virtual machines shapes security.
BYOD policies enable employees to bring their own devices to work and access company resources. Enhancing morale and job satisfaction, BYOD increases security risks from malware and unmanaged devices.
Learn how cache RAM speeds up systems by buffering data from slower devices to faster memory. See how caches appear in hardware and as browser cookies and temporary files.
Explore cloud computing and its service models—software as a service, platform as a service, and infrastructure as a service—through real-world examples like Office 365 and Google Docs.
Explore device security for Android (linux-based, open source) and Apple devices, including remote wiping and locking, effective screen locks, and GPS tracking to prevent casual access.
assess site selection and facility design to withstand natural disasters, and implement a layered physical security approach with deterrence, denial, and detection, including fences and motion sensors.
Explore the OSI reference model, a seven-layer framework from ISO that guides secure network communications via open system interconnection, from application to physical layers, using protocols to move data.
Explore the OSI model from physical to application layers, detailing frames, packets, MAC addresses, IP routing, transport segmentation, sessions, presentation encryption, and application interactions.
Tcp/ip four-layer model contrasts with the OSI seven-layer framework, highlighting application, transport, internet, and link layers. Describe packet creation, routing, and reassembly with port numbers as examples.
Explore the three-way handshake and compare tcp and udp, highlighting connection-oriented reliable transfer with sequencing and flow control versus connectionless, fast delivery with no delivery guarantees and lower overhead.
Understand private versus public IP addresses, including private ranges 10, 172, and 192, and review IPv4 class A/B/C addressing and IPv6 128-bit addressing.
Explore how the domain name system translates human-friendly names into ip addresses, enabling browsers to reach sites via dns servers and domain mappings.
Explore wifi basics, wireless standards, and secure access practices, including hidden ssids, wardriving awareness, and WPA encryption, followed by firewall fundamentals for controlling traffic and preventing intrusions.
Understand collision domains and broadcast domains, how hubs create a single collision domain, how switches and routers segment networks, and half duplex behavior in reducing collisions.
Learn about cabling types such as coaxial, twisted pair, and optical fiber, and explore topologies like bus, star, and token ring with devices such as switches and routers.
Compare authentication protocols CHAP and PAP, highlighting how CHAP uses a three-way handshake to prevent clear-text credentials, unlike PAP's username and password sent in the clear.
Learn how a vpn creates a secure tunnel over the internet to connect private sites, enabling encrypted and authenticated data traffic across untrusted networks.
Explore how network address translation maps private IPs to public IPs with static and dynamic NAT, and compare circuit switching, packet switching, and DoS attacks.
Explore authentication factors, including passwords, pins, and biometric methods, and examine password length, complexity, expiration, and history, plus biometric recognition challenges like false acceptance and rejection rates.
Explore types of access control including preventive, detective, corrective, recovery, deterrence, and compensating controls, plus logical and physical controls and the concept of single sign on.
Explore Kerberos ticket systems and ssl single sign-on for authenticating service requests across trusted networks. Understand aaa—authentication, authorization, accountability—and the roles of radius and diameter in securing access.
Define permissions, rights, and privileges, and emphasize implicit deny as the default in access control. Explain defense of depth through layered security with policies, VPNs, firewalls, DMZs, and secure architecture.
Explore discretionary access control by illustrating group-based permissions, ACLs on objects, and owner-driven access decisions that grant or restrict data access.
Explore NAC governance with managed administrators and rule-based, attribute-based, and mandatory access control, and review attacks like dictionary, brute force, rainbow table password attacks, spoofing, phishing, and denial of service.
Learn protection methods against attacks, including Windows file protection, ransomware defense via restricted permissions, strong passwords, multi-factor authentication, account lockout, and last login notifications.
Assess security levels through testing to reveal flaws in controls and authentication. Explore automated scan tool-assisted penetration testing, risk assessment, posture assessment, and internal versus external audits.
Explore penetration testing fundamentals, including white box and black box approaches, network discovery with Nmap, port scanning, securing services like SSH over Telnet, and reporting findings.
Explore code review as the foundation of software assessment, covering the six-step inspection, static testing with automated tools, and dynamic testing with scripted inputs to validate security and performance.
Test interfaces across API, GUI, CLI, and physical interfaces to ensure security requirements in complex software systems; perform discovery analysis, KPI tracking, and use-case and misuse-case testing with pre-production scanning.
Learn to manage security operations by applying the need-to-know principle, least privilege, and permissions controls, with revocation, separation of duties, and transitive trust concepts.
Label backups with dates and departments; secure data in transit and at rest, including offsite storage; manage hardware and software assets; protect licenses with recovery emails and CCTV.
Master the change management process from request to approval and implementation. Assess change types and impacts on people, networks, costs, risk, plus stakeholder analysis, communication, and readiness.
Master patch management by identifying new patches, evaluating and testing them, approving and deploying updates, and verifying deployment to keep operating systems up to date and secure.
Learn how to detect, respond to, mitigate, report, and recover from security incidents, preserving confidentiality, integrity, and availability while analyzing root causes and lessons learned.
Enhance security with basic preventive measures: keep apps and OS up to date, disable unused services, deploy MBSA, IDS/IPS, and up-to-date anti-malware and firewalls, recognizing DOS and man-in-the-middle threats.
Explore intrusion detection and prevention systems, including signature-based detection with a database of known attacks and behavior-based detection using baseline activity.
Explore common log types for incident detection and auditing, including security, system, application, firewall, and proxy logs. See how logs capture access, changes, and events across files and systems.
Assess egress and inbound monitoring with firewalls, data loss prevention, and logging and alerts, while comparing intrusion detection systems to intrusion prevention systems and applying knowledge-based and behavior-based detection.
Audit trails monitor security by recording comprehensive system activity to detect threats, prevent incidents, and show a before-and-after view of system state for cyber law prosecutions.
Understand disaster recovery planning, addressing natural and man-made disasters, single point of failure, system resilience, and data protection via raid 0, 1, 5, 6, and 10.
Protect servers with load balancing for scalability and high availability, ensure quality of service, monitor bandwidth and latency, and enable automated recovery with UPS and backup generators for business continuity.
Explain recovery strategy as part of a data protection plan, comparing backup options from local to remote and disaster recovery sites like hot and warm sites, service bureaus, and cloud.
Explore disaster recovery site types, defined recovery objectives, and backup strategies from full, incremental, and differential backups to minimize data loss and downtime.
Investigate security incidents with a focus on lawful inquiry, evidence handling, and forensic discovery, detailing real, documentary, and testimonial evidence, and the role of law enforcement.
Investigate incidents by informal interviews with affected users and never hack back. Use a three-step process—direction and identification, response and reporting, recovery and remediation—covering incidents like scanning and compromise.
Explore the five generations of programming languages, from machine code and assembly to high level, fourth generation declarative languages, and fifth generation with artificial intelligence and visual interfaces.
Explore the fundamentals of object oriented programming, defining data types and operations, and see how messages drive behavior through classes and objects, including inheritance, delegation, polymorphism, cohesion, and coupling.
Learn the system development lifecycle, from planning and feasibility to design, development, testing, deployment, maintenance, evaluation, and disposal, emphasizing stakeholder communication and requirement analysis.
Explore software development lifecycle models, highlighting the waterfall's rigidity, the benefits of incremental and agile approaches, and the capability maturity model levels guiding process maturity.
Develop secure and reliable software by integrating development and operations workflows and mastering testing methods. Understand database concepts such as atomicity, consistency, isolation, keys, and open database connectivity.
Explore knowledge-based systems and expert systems, powered by artificial intelligence, that support human decision making, illustrated by a Jet Airways example and a discussion of decision-support tools.
Explore how computer viruses replicate and propagate, including master boot record and file infector techniques, Trojan horses, spyware, Stuxnet, and common application and password attacks.
The CISSP: Certified Information Systems Security Professional Certification certification training package covers topics such as Access Control Systems, Cryptography, and Security Management Practices, teaching students the eight domains of information system security knowledge.
The new eight domains are:
The CISSP Certification is administered by the International Information Systems Security Certification Consortium or (ISC)². (ISC)² promotes the CISSP exam as an aid to evaluating personnel performing information security functions. Candidates for this exam are typically network security professionals and system administrators with at least four years of direct work experience in two or more of the ten test domains. As the first ANSI ISO accredited credential in the field of information security, the Certified Information Systems Security Professional (CISSP) certification provides information security professionals with not only an objective measure of competence, but a globally recognized standard of achievement.
Who is the target audience?
*note: This course is not for someone who simply looking to crack Exam only, This course will provide you the knowledge to appear for Interview and Include the knowledge of CISSP Course