
Andrew Romdahl introduces the CISSP course, focusing on mindset and applying industry experience to an ambiguous exam while guaranteeing up-to-date content for current tests.
Own the CISSP exam by balancing knowledge and mindset, study the 1100-slide slide deck, and master scenario-based questions for the 2024 exam.
Learn the CISSP exam format, a three-hour computer adaptive test with 100–150 questions and no backtracking. Master all eight domains with equal emphasis and adopt a confident exam mindset.
Review the study guide before watching videos, skip what you already know, watch the mindset videos, complete the quick quizzes, and take the end-course mock exam to pass CISSP.
Prepare for the CISSP exam with about 800 practice questions, including 250 in-course, 100 end, and 50 ultra hard items, plus free video explanations and the mindset.
Explore ISC ethics and the canons: protect society, act honestly and justly, provide diligent service, and advance the profession; memorize the canons for exam readiness.
Balance the organizational code of ethics with the ISC square ethics, following laws like Sarbanes-Oxley, HIPAA, and PCI. Protect sensitive data, avoid conflicts of interest, and maintain respectful conduct.
Adopt a CISSP mindset that views security from a holistic, management perspective, safeguarding assets, especially people’s lives, through high-level policies rather than solely technical controls.
Explore the CIA triad (confidentiality, integrity, and availability) along with access control, encryption, secure communications, and the role of fault tolerance and backups in preventing disruption.
Identify and authenticate users, authorize access, and audit actions to establish accountability. Maintain logs to prove who did what, enforcing policy through identification, authentication, authorization, and auditing.
Explore non-repudiation by showing how CCTV evidence prevents denial of actions. Learn how digital signatures, access controls, and accountability build systems where participants cannot repudiate their events.
Adopt a CISSP mindset that prioritizes security policies and risk management over purely technical fixes. Balance confidentiality, integrity, availability, and authenticity while protecting business with a baseline and cost-benefit decisions.
Align security with business goals to enable, not block, innovation. Reduce risk to acceptable levels by partnering with executives and applying practical controls like encryption, TLS, VPNs, and data minimization.
Assess how acquisitions and divestitures impact security across data, people, and systems. Plan secure integration with due diligence, risk assessment, and compliance to prevent data leakage and preserve continuity.
Learn how security governance aligns information security with business goals, enabling risk-based decisions, governance oversight, and user training to protect assets and enable growth.
Explore the roles that drive security - end users, owners, custodians - and how least privilege, policy, backups, and audits counter social engineering and shape risk management.
Explore ISO 27,001, PCI DSS, and FedRAMP frameworks to shape an information security management system and cloud data protection.
Compare due diligence and due care to show how security professionals research risks and plan controls, then take concrete actions such as encryption, firewalls, and training to protect data.
Master essential laws and standards for security and privacy, including Sarbanes-Oxley, PCI, GDPR, and HIPAA, with a focus on memorization for exam readiness.
Learn how intellectual property protections guard creators with copyrights, trademarks, patents, and trade secrets. Understand enforcement, registration basics, and NDAs to prevent IP theft and economic loss.
Understand data localization and data sovereignty through cross-border storage examples. See how laws like GDPR apply based on where data originates and where it should remain.
Master import export controls by understanding ITAR and EAR regulations, which cover military and dual-use items, encryption software, drones, and semiconductors, enforced to protect national security and commerce.
Explore foundational computer crime laws from the 1984 Comprehensive Crime Act to the 1996 National Information Infrastructure Protection Act, including CFAA, FISMA, and related privacy provisions.
Explore a global view of privacy laws, including GDPR, HIPAA, COPPA, GLBA, and CCPA, and learn how data subjects’ rights, data controllers, and cross-border transfers shape privacy practice.
Learn how Sarbanes-Oxley enforces internal controls, audits, and penalties for accurate financial reporting, and how PCI DSS protects cardholder data through 12 requirements, secure networks, encryption, and access controls.
Learn to evaluate vendor security controls before contracting, covering data use, location, encryption, key management, audits, and third-party dependencies. Assess vendor incident response and assurance measures to protect sensitive data.
Adopt a practical mindset by knowing key laws and regulations for the exam. Focus on GDPR, PCI-DSS, CCPA, and SOX, with SOC audits covered later.
Explore administrative, criminal, civil, regulatory, and industry standards investigations, and how HR and IT handle policy violations, misconduct, evidence, chain of custody, and regulatory or ISO-style compliance.
Learn how security governance uses policy, standard, procedure, and guidelines to define responsibilities and implement controls through a top-down, exam-focused approach.
Focus on a policy driven security mindset by understanding the policy standard procedure hierarchy and that management drives security through policy before technical fixes.
Discover how business continuity planning keeps critical services running before, during, and after disasters, and how disaster recovery and the business impact analysis support rapid restoration.
Learn the seven steps of building a well-defined business continuity plan from NIST 854 rev. 1, including BIA, contingency policy, recovery strategies, testing, and ongoing maintenance.
Identify and prioritize mission critical business processes through a business impact analysis, determine resource requirements and interdependencies, and set tolerable downtime (MTD), recovery time objectives (RTO), and recovery point objectives (RPO).
Identify external dependencies such as SaaS, cloud providers, and vendors, and build BCP contingencies with SLA guarantees, backup options, and failover plans to protect operations.
Adopt a BCP mindset focused on preserving human life and keeping the company running through disruptions. Align risk appetite and MTD with vendor contracts before pursuing technology fixes.
Identify personnel as the weakest security link and implement rigorous screening, onboarding, training, access provisioning, and ongoing background checks to prevent insider threats.
Enforce security through employment agreements that require employees to understand and accept security responsibilities before accessing systems, including acceptable use, NDA, non-compete and non-solicit, IP ownership, and code of conduct.
Onboard new hires with background checks, employment agreements, and security training; reassess access during transfers to enforce least privilege, then terminate access and collect company property at exit.
Explore how to manage vendor risks with NDAs, SLAs, MSAs, and DPAs, defining confidentiality, service levels, governance, and data processing obligations under privacy laws such as GDPR and HIPAA.
Adopt a personnel security mindset by managing the user lifecycle from onboarding to offboarding, enforcing policies and NDAs, providing ongoing monitoring and training to reduce insider threats and ensure trustworthiness.
Master risk management concepts by applying the threat times vulnerability framework, identifying assets, threats, vectors, and safeguards, and understanding risk tolerance and exposure.
Understand how assets such as people, data, and technology face threats and vulnerabilities, creating risk, and how countermeasures like training, antivirus, and firewalls reduce exposure within the risk management cycle.
Learn to value information assets by weighing tangible costs, intangible worth, regulatory impacts, and the cost of not being in compliance, and translate risk into business terms for senior management.
Assess risk with quantitative and qualitative methods, compute single loss expectancy and annualized loss expectancy from asset value and exposure factor, and evaluate safeguards like antivirus and firewall.
Explore risk response strategies, from acceptance and transfer to deterrence, avoidance, and mitigation, and learn how total risk and residual risk are calculated using threat, vulnerability, and asset value.
Explore how zero-day threats drive cybersecurity insurance and how policies transfer risk to cover data breaches, financial losses, and legal liabilities, plus incident response.
Apply cost-benefit analysis within risk management to select countermeasures cheaper than asset value, ensure attacker costs exceed gains, and verify fail-safe and fail-secure options with tests.
Build asset security with a layered approach by combining physical, technical or logical, and administrative controls, and apply seven control types: directive, deterrent, preventive, detective, corrective, recovery, and compensating.
Apply the risk management framework from NIST SP 800-37 to integrate information security into the system development lifecycle, guiding categorization, control selection, implementation, assessment, authorization, and ongoing monitoring.
Think like management to reduce risk to an acceptable level, balance risk, cost, and compliance, and assess if a fix is right and worth the spend.
Passing the CISSP exam is not just about studying thousands of pages of information, it’s about having the right mindset. The exam is designed to test how you think as a security leader, not just what you’ve memorized. That’s why this course goes beyond the content and gives you the CISSP Mindset Framework, proven to help thousands of students pass on their first attempt.
This Full CISSP Course and Mindset provides complete coverage of all exam topics explained in simple, easy-to-understand language, with real-world examples that make the material stick. But what makes it different is the focus on the mindset strategies you need: how to break down complex scenario-based questions, eliminate wrong answers, and choose the best option under exam pressure.
Inside this course, you will:
Learn all CISSP concepts in a clear and structured way
Apply the CISSP Mindset to approach every question with confidence
Discover test-taking strategies to avoid traps and manage your time effectively
Gain the knowledge and mental preparation to think like a CISSP-certified professional
Follow-along router, switch, and firewall configuration exercises
Whether you’re an IT professional, manager, or aspiring security leader, this course will give you both the knowledge and mindset required to succeed.
By the end, you won’t just be ready to take the CISSP exam and you’ll be ready to pass it with confidence.