
Learn CISSP and its eight-domain CBK with a beginner focus on domain 1. Prepare with exam-style questions and anime-based demonstrations.
Prioritize ethics over merely passing exams, following ISC Square’s commitment to prevent unethical use of knowledge. See how ethics shape trust, cooperation, workplace conversations, and public speeches, and avoid harm.
Explore how ethics guide technology via the ten commandments of computer ethics, emphasizing not harming others and respecting intellectual work, under ISC Square's Code before the CISSP exam.
Build a strong security foundation by establishing essential knowledge and a learning mindset, linking technical concepts and unfamiliar terms into a well-structured, rooted understanding.
Apply defense in depth by layering safeguards tailored to the attack and assets, and avoid obscurity, ensuring information assets stay protected even if security mechanisms are known.
Define access control as the intermediary between subject and object, applying the least privilege and need to know to restrict access and protect assets.
Explore how authenticity relies on proper authentication to confirm that something is genuine, and how non-repudiation uses traceability to prevent denying actions.
Learn how organizational structures and governance shape information processing, contrast governance with compliance, and explore management systems and frameworks that ensure rules are followed.
Align security functions with the organization's business strategy, goals, and audience, balancing protection with innovation and service quality. Governance and management guide decisions to support strategic objectives and stakeholder trust.
Clarify organizational roles in information security, from business owners to system owners and administrators. Collaboratively define responsibilities, policies, and resource allocation to protect assets and align security with business goals.
Discover security management frameworks like ISO-IEC 27001, 27002, NIST SP 800-37, COBIT, FedRAMP, COSO, PCI DSS, and ITIL, and how risk assessment informs information security management and governance.
Establish governance and internal control to foster trust and ensure implementation of organizational operations. Align due diligence with due care by creating rules and acting responsibly to secure the enterprise.
align security advice with laws and regulations to protect credibility and public trust, and design flexible information systems that adapt to evolving legal standards and compliance requirements.
Explore the main types of intellectual property—trademarks, patents, copyrights, licenses, and trade secrets—and how laws like the DMCA, first sale doctrine, and public domain protections safeguard them.
Trace the history from COCOM to the Wassenaar Arrangement and explore how export controls, including ITAR and USML, govern dual-use items and cryptographic systems to protect environment and national security.
Discover cross-border data flow under GDPR, compare with DPD, and apply rights of access, erasure, and data portability, plus adequacy certification and 72-hour breach notification.
Protect personal information by clarifying use scope and obtaining consent before disclosures, covering PII and PHI. Examine HIPAA and HITECH distinctions, COPPA for children, and patient rights in privacy governance.
Explore methods for investigating evidence, emphasizing careful collection and proper storage to preserve probative value. Policy experts must understand how to collect, store, and prioritize evidence amid stronger opposing evidence.
Explore the categories and rules governing evidence, including real, direct, circumstantial, corroborative, hearsay, and secondary evidence, the best and parole evidence rules, and chain of custody.
Organize security methods around the company's goals and document them in a clear, hierarchical structure to ensure security measures protect assets and align actions with objectives.
Document policy, standards, and procedures to align security goals with organization strategy, using baselines and guidelines for scoping and tailoring, guided by top-down decisions and business cases.
Identify and prioritize the most critical functions to restore quickly after disasters, estimate recovery time, and allocate resources to support the disaster recovery plan and reassure stakeholders.
Human beings introduce vulnerabilities, but with proper training and motivation they become invaluable security assets, viewing people as a vital component of any security initiative.
Learn to conduct thorough candidate screening and background checks, verifying employment and education history, references, social media reviews, and interviews, while upholding standardized processes and anti-discrimination legal compliance.
Learn to create and use job descriptions, sign employment and nondisclosure agreements (including CISSP exam NDA), and onboard staff through training, orientation, and policy leadership.
Explore how an IAM system registers employee accounts with IDs. It explains department-based permission changes, revoking old rights, dismissal handling, exit interviews, and post-employment terms like non-disclosure and non-compete.
Use a vendor management system to assess cost, financial stability, staffing, and ISO-aligned structures, then select, monitor, and survey vendors to prevent monopolies and safeguard data.
Perform qualitative and quantitative risk analysis with a risk analysis matrix, assess impact and likelihood, and calculate ale, sle, aro, and roi across assets.
Evaluate risk management controls from security and privacy perspectives, balancing ROI with costs, and apply privacy-by-design to protect personal information throughout planning, consent, and system use.
Continuously monitor risks in real-time to stay informed about the current risk landscape across industries and act immediately to prevent money laundering, protect patient data, and address product quality.
Explore reporting risk management credibly through external audits and SOC frameworks (SOC 1–3) to verify controls and third-party governance, emphasizing transparency and alignment with practice.
Course Overview
CISSP (Certified Information Systems Security Professional) is a globally recognized certification in the field of information security.
This course covers the following categories in CISSP CBK Domain 1.
The CISSP exam emphasizes the ability to think in accordance with principles that can be applied in any situation. You may find the explanations in the course to be a little brief, but this will help you to grasp the whole picture smoothly.
Course Content
Study Videos by Domain
Downloadable PDF slides
CISSP Exam Preparation
Multiple Choice Practice Questions
Notes
This is not an official training course provided by (ISC)².
The exam content may have changed since the course was created.
This course covers the certification for CISSP Domain 1. Other domains are not covered in this course.
The content of this course is the same as the English version of the “【日本語】初心者から学べるCISSP講座:CBK Domain 1” course.
Trademarks
(ISC)2 and CISSP® appearing in this video content and accompanying text are registered trademarks of their respective companies.
The names of servers, software, and products appearing in this video content and accompanying text are the trademarks or registered trademarks of their respective developers. The names of products, organizations, and groups are listed solely for the purpose of creating this course, and the author has no intention of infringing on any of these trademarks.