
Explore domain one security and risk management in CISSP, using whiteboard sessions and visuals to build a clear, memorable understanding.
Learn how to pass CISSP by focusing on the primary reference material, finding a study guide or instructor, and using Cybex ninth edition with supplementary notes.
Discover a CISSP domain 1 exam strategy centered on courage and commitment, using a single primary reference (Cybex ninth edition) and building concepts with notes and context.
Explore domain 1 security and risk management by examining principles, confidentiality, integrity, availability, and non repudiation, and how policies and governance derive from frameworks, risk assessment, vulnerability assessment, and testing.
Navigate domain 1 of the CISSP syllabus, outlining security and risk management foundations, CIA triad, governance, threat modeling, and business continuity planning.
Explore the organizational and (ISC)² code of professional ethics, including the preamble and four canons—protect society, act honorably, provide diligent service to principals, and advance and protect the profession.
Explore how core security principles underpin policy and governance, and apply CIA triad concepts (confidentiality, integrity, and availability) in real-world information security scenarios.
Examine the core information security principles - confidentiality, integrity, availability, authenticity, and nonrepudiation - and how access control strengthens secure systems in CISSP domain 1.
Select an appropriate security framework, tailor a policy via risk, vulnerability assessments, and testing, and balance the CIA triad—confidentiality, integrity, availability—with legal defensibility and cost effectiveness.
Explore the triple-A framework of identification, authentication, authorization, auditing, and accounting; learn how logs enable monitoring, auditing, and accountability in secure access control.
Explore four protection mechanisms—layering (defense in depth), parallel controls, abstraction, and data hiding—and how they complement security principles and security controls to safeguard information.
Define and distinguish physical and logical security boundaries, and illustrate how firewalls, security zones, and trust levels separate low-trust internet access from high-trust internal networks.
We explain how a data center is segmented into logical boundaries, including a DMZ, an internet boundary, and a management zone, using firewalls, a jump post, and two-factor authentication.
Use a top-down security management planning approach to translate the information security policy into standards, baselines, guidelines, and procedures, with senior and middle management guiding implementation.
Understand how organizational processes, such as acquisitions, merger, and divestiture, along with third-party governance, shape security policy, risk, and governance across roles from senior managers to custodians and auditors.
Analyze how security models and frameworks define governance, policy, and processes, and apply principles like confidentiality, integrity, and availability within security architectures and risk frameworks.
Explore security control frameworks such as ISO/IEC 27000, COBIT, and NIST CSF, and understand governance concepts like stakeholder value and the governance vs management distinction.
The lecture contrasts security control framework with the RMF, outlining its seven steps—initiation, categorization, selection, implementation, assessment, authorization, monitoring—and the CSF’s identify, protect, detect, respond, recover.
Analyze due diligence and due care, apply threat modeling (stride, pasta, sd3+ c), prioritize risks, and implement supply chain risk management.
Learn to perform reduction analysis in threat modeling by identifying trust boundaries, data flow paths, input points, and privileged operations, then apply security policy and due diligence.
Explore how compliance in a company is driven by legal and regulatory requirements, internal risk assessments, and how US laws evolve—from constitution to judiciary—through risk management frameworks 837 and 853.
Trace the history of data privacy from the fourth amendment to modern laws. Highlight acts like privacy act 1974, ferpa, hipaa, calea, copa, glba, patriot act, hitech, and ccp.
Trace the evolution of computer crime law from 1984 to 1996, including CFA and the 1991 sentencing guidelines. Then summarize FISMA 2002 and DHS modernization shaping federal cybersecurity.
Explore intellectual property basics, contrasting copyright, trademark, patent, and trade secret, and learn how DMCA, timelines, and penalties shape licensing and IP protection.
Explore software licensing types—contractual, shrink-wrap, click-through, and cloud service licenses—highlighting consent methods, cost implications, and corporate risk management.
Examine the GDPR and cross-border data sharing, detailing lawful processing, purpose limitation, data minimization, accuracy, storage limits, security, accountability, and the role of standard contractual clauses and binding corporate rules.
Plan security management top-down by turning the information security policy into standards, baselines, guidelines, and procedures. Align these with business plans to implement and enforce governance.
Understand the four investigation types—administrative, criminal, civil, and regulatory—and learn admissible evidence, chain of custody, and the nine-step e-discovery process.
Master the IOCE six principles, chain of custody, write blockers, hash verification, RAM data capture, and core investigation concepts like subpoenas, warrants, and data integrity.
Define business continuity planning and its role in business continuity management, emphasize availability, prioritize people's safety, and connect BCP with disaster recovery and related processes.
Explore the five-step process of business continuity planning, from project initiation and senior-management approval to business impact assessment, continuity planning, approval and implementation, and ongoing education, maintenance, and testing.
Outline the five-step BCP process and explain how project initiation defines scope and planning, covering business organization analysis, BCP team selection, and resource and legal considerations.
Present a complete cycle of business continuity planning, from project scope and BIA to risk assessment, continuity strategy, implementation, testing, and emergency guidance.
Explore business continuity management foundations, including BCP and DRP, and the four-step process: scope, BIA, continuity planning, approval—plus RPO, RTO, ALE, and vital records.
Assess and implement personnel security through defined job descriptions, screening, onboarding, and ongoing oversight, enforcing least privilege, privilege creep prevention, and robust vendor management.
Do you feel CISSP certification is difficult?
This course will make CISSP certification fun and easy. This module of "Concepts of CISSP" series will cover domain1. We will be releasing separate domains as separate modules.
Welcome to CISSP. CISSP is one of the most reputable courses in the world of information security. The CISSP covers the fundamental elements of the entire cybersecurity field – from security and risk management to communication and network security to security testing and operations. The CISSP is designed for security professionals who have spent a few years in the industry, are currently in an information security position, and want to study cybersecurity leadership and operations.
We will cover CISSP syllabus here and will focus on topics to explore core concepts, looking at the wider landscape and see tips and tricks for exams questions.
I will be presenting drawings and whiteboard sessions to better engage with you and make the entire journey fun. The main goal of my course is to make the material as vivid as possible.
Please note that the CISSP exam outline documented on CISSP website may not appear exactly same in my video discussions. The reason is because some of the topics are already discussed in the videos and we have overlapping situations. Please comment on if there is something missing or need more explanations. I will be happy to improvise by adding new content to the module.
I'm hoping you'll find this training useful and enjoyable. If you happen to have any questions and further suggestions, feel free to reach out.