
Explore the seven SSCP domains—from security operations and access controls to cryptography and network security—guided by the official ISC squared exam outline to prepare for the SSCP exam.
Explore the SSCP toolbox, a curated collection of approaches, methodologies, and techniques. Synthesize and apply insights, understand your learner, and self-assess to stay prepared for any question.
Discover your SSCP learner profile—novice, doer, no, or warrior—and move through a life cycle toward mastery across all seven domains, building your toolbox and study plan.
Develop your SSCP study plan using the toolbox of the five Ws and H. Self-assess your learner type, synthesize and apply knowledge, and maintain consistent exam preparation.
Discover the IC squared code of professional ethics and its four canons, and learn how upholding these standards is foundational to the SSCP and security operations.
Master core security concepts like the CIA triad and defense in depth, and learn key terms such as due diligence, accountability, privacy, non repudiation, and the six information lifecycle phases.
Identify and implement security controls by category—administrative, technical, and physical—then explore functional control types to assess compliance and mitigate risk.
Identify and apply seven functional security control types—preventative, deterrent, detective, corrective, recovery, directive, compensating—and map them across administrative, physical, and technical categories.
Explore the asset management lifecycle across hardware, software, and data, focusing on data classification schemes, ownership, and the build versus buy decision plus inventory and licensing.
Explore the asset data lifecycle—from planning to creating, storing, using, archiving, and destroying—driven by data policy, retention, and roles: data owner, controller, processor, custodian, steward, data subject, and administrator.
Learn the change management lifecycle and its risk ties, covering RFC, CAB decisions, testing, deployment, and CMDB documentation, with security impact analysis and rollback planning.
Engage people with security awareness and training aligned with culture-specific needs and code of ethics. Use campaigns to mitigate social engineering, tailgating, and impersonation via say-something and front line reporting.
collaborate with physical security operations to plan, conduct, analyze, and report assessments that secure facilities with access control, CPTED, defense-in-depth, and audience-aware communication.
review the core concepts of security operations and administration, including ethics, confidentiality, integrity, availability, access control, asset management lifecycle, data lifecycle, security controls, change management, and security awareness.
Explore single and multi-factor authentication (MFA) within access controls, covering authentication factors, identify and authenticate, authorize, and monitor access for accountability.
Discover how single sign-on provides centralized authentication and access control via directory services, with federated identity management, just-in-time access, and FIDO/FIDO2 security standards.
Explore Kerberos as a standardized single sign-on solution, and learn how the KDC, AS, and TGS issue tickets (TGT and service tickets) to enable secure authentication and resource access.
Explore how devices prove their identity through triple A protocols, port-based 802.1x NAC, and remote access gateways using RADIUS, TACACS, and Diameter.
Explore federated access and federated identity management, extending trust to external third parties using tokens and standards like SAML, OAuth 2.0, and OpenID Connect, with identity providers and service Providers.
Explore inter network trust architectures by identifying seven trust types: one-way, two-way, transitive, non-transitive, external, forest, realm, and shortcut, and learn how zero trust and third-party connections secure access.
Explore the identity management lifecycle, including the IAAA/IAAAA process, provisioning, entitlement management, and auditing for accountability, with centralized versus decentralized identity management and SSO and LDAP.
Explore how to understand and apply access controls, including mandatory access control, discretionary access control, RBAC, ABAC, and the access control matrix and capability table.
Explore six major security models, from state machine and information flow to matrix-based and take-grant, and evaluate confidentiality, integrity, and availability.
Explore the full scope of access controls, including authentication factors, SSO, Kerberos, SAML, OpenID Connect, IAM basics, and RBAC.
Master risk identification, monitoring, and analysis vocabulary in domain three by defining must-know concepts like risk, threat, vulnerability, likelihood, impact, countermeasures, and residual risk.
Define the business impact analysis (bia), its iso origins, and its role in determining system criticality, downtime, and recovery priorities for coop and dr.
Explore impact assessments within risk management, detailing the risk assessment process and preparation, the five-step process, vulnerability and penetration testing, and qualitative and quantitative analysis for SSCP exam readiness.
Explore threat modeling within risk management by identifying threats, threat sources, and vulnerabilities, using STRIDE, DREAD, PASTA, TRIKE, VAST, and AS/NZS 4360 methodologies.
Explore threat intelligence within risk management concepts, analyzing TTPS, indicators of compromise, and threat actor patterns to anticipate, detect, and deter adversaries using MITRE ATT&CK frameworks and cyber kill chain.
Explore risk tolerance and risk treatment, including avoid, accept, transfer, mitigate, recast, and ignore, guided by NIST definitions, and apply seven functional controls across physical, administrative, and logical categories.
Explore risk management frameworks and their role in information security. Learn how ISO 27001/27002, ISO 31000, and NIST RMF guide governance, risk, and compliance for the SSCP exam.
Spotlight on the NIST RMF highlights a seven-step process that integrates security and risk management into the SDLC, covering prepare, categorize, select, implement, assess, authorize, and monitor.
Explore how risk visibility and reporting drive actionable security decisions using risk registers, heat maps, and indicators of compromise in the SSCP domain.
Learn how governance, risk, and compliance shape security decisions by interpreting external laws, privacy regulations like GDPR, transborder data flows, and PII protections to ensure compliant risk management.
Spotlight on the GDPR clarifies personal data definitions, data subject rights (including DSAR and right to be forgotten), breach reporting, and the roles of data controllers and processors.
Explore how security assessment and vulnerability management identify risks, monitor and analyze controls, and guide remediation through defined workflows, testing methods, and nist-based frameworks.
Shining a spotlight on risk review, lecture covers supply chain risk management and CSCRM across the SDLC, emphasizing third-party risk, risk identification, monitoring, and governance with SLAs and due diligence.
Operate and monitor security platforms through continuous monitoring and ISCM as defined by NIST SP800-137, focusing on events of interest, and use IDS/IPS, logging, auditing, and SIEM to mitigate risks.
Analyze monitoring results to reveal the current state of risk through continuous monitoring, security baselines, event data analysis, visualization metrics and dashboards, and communication of findings for governance and compliance.
Master risk identification, monitoring, and analysis, including BIA insights, threat modeling and threat intelligence, risk management frameworks, GDPR considerations, and continuous monitoring across supply chain and security domains.
Learn to define, detect, contain, and recover from security incidents by following the incident lifecycle, guided by NIST standards and the SSCP CBK.
Examine the legal aspects of forensic investigations—internal and external types, including criminal, civil, and regulatory, with the nine-step eDiscovery reference model and first responder evidence collection.
Develop forensic investigations by applying chain of custody, admissibility criteria, and handling real, documentary, testimonial, and live evidence at the incident scene.
Explore BCP and DRP planning, distinguishing disaster recovery from business continuity, and map these to a six-step process guided by a business impact analysis and practical training.
Develops backup and redundancy concepts for business continuity and disaster recovery, covering mirror, full, incremental, and differential backups, RTO and RPO, and backup storage strategies.
Explore how testing and drills validate BCP and DRP, from desk check and tabletop exercises to parallel and full eruption tests, ensuring continuity and recovery readiness.
Master the incident response lifecycle with six ordered phases—preparation, detection and analysis, containment, eradication, recovery, and post-incident activity—plus forensic evidence handling and BCP/DR planning.
Explore why cryptography supports confidentiality, integrity, and authenticity, covering data ownership, non repudiation, and IP protections like patents, copyrights, trademarks, encryption across data at rest, in transit, and in use.
Explore hashing and salting to represent data integrity and secure passwords, including hash functions, fixed-size outputs, rainbow tables, and the use of salt and pepper.
Explore encryption concepts, including symmetric and asymmetric systems, key management, non repudiation, and protocols like TLS, RSA, and ECC, to prepare for the SSCP exam.
explore non-repudiation and digital signatures, including how private keys create verifiable proofs of origin and message integrity through hashing and eight procedural steps.
Discover secure communication protocols, encryption for data in transit, and key authentication methods, including TLS, IPSec, VPNs, SSH, Kerberos, and email security standards S/MIME and PGP.
Explore how IPsec provides data origin authentication, integrity, and confidentiality using AH and ESP, negotiates security associations with IKE and ISAKMP, and supports transport and tunnel modes.
Explore how the public key infrastructure enables secure authentication, digital certificates, and trusted communications by detailing X.509 v3 certificates, certificate authorities, and the certificate lifecycle from enrollment to revocation.
Explore the major cryptographic attacks, from analytic and implementation attacks to brute force, frequency analysis, meet-in-the-middle, and birthday attacks, with countermeasures to eliminate patterns and strengthen key management.
Explore key cryptography concepts, including confidentiality, integrity, authenticity, and non-repudiation. Learn hashing, salting, and digital signatures, plus PKI, certificates, and secure protocols like IPsec and TLS.
Explore the OSI model's seven layers, data encapsulation, and how data moves from data stream to segment, packet, frame, and bits, including TCP/IP mapping and layer roles.
Explore IPv4 and IPv6 addressing, including 32-bit vs 128-bit addresses, subnet masks, and CIDR notation, plus private ranges, loopback, APIPA, IPsec, and QoS.
Explore connectivity foundations across cabling media, topology types, and transmission methods, from copper and fiber to frequency-based wireless schemes like fhss, dss, and ofdm.
Learn the fundamentals of software-defined networking, including the three planes—application, control, and data—and how vxlan overlays with vni and vtep enable scalable, automated networks.
Explore 22 network attack types from dos to arp and dns spoofing, and learn countermeasures to safeguard availability, confidentiality, and integrity.
Learn how to implement network access controls with 802.1X port-based NAC, using supplicants, authenticators, and radius or tacacs+ to pre- or post-admission access and secure remote VPNs.
Discover how to manage network security with inline, passive, and virtualized devices, VLANs and private PVLANs, NAT and NAT traversal, and endpoint management using MDM, MAM, and UEM.
Understand how network-based security devices protect environments, including firewalls and in-line protections. Compare stateful vs stateless firewalls, proxy and web application firewalls, DMZ design, and IDS/IPS to tailor secure configurations.
Master secure wireless communications by applying encryption with WPA2/3, protecting SSIDs, and defending against rogue access points, evil twins, and Bluetooth, NFC, and IoT risks.
Explore the fundamentals of network and communications security, from OSI model and IP addressing to VPNs, 802.1X authentication, firewalls, and SD-WAN concepts.
Explore malicious code and malware types, from viruses to rootkits, and learn practical defense in depth with antivirus, code signing, behavior blocking, and user awareness.
Implement endpoint device security using host-based intrusion prevention, firewalls, application whitelisting, and whole-disk encryption with TPM/HSM; enable secure browsing and endpoint detection and response.
Assess mobile device deployment options, including BYOD and COPE, and how corporate policies govern access to resources. Explore MDM and MAM, encryption, and containerization to mitigate risk on mobile devices.
Explore cloud security basics, including the NIST definition and five essential characteristics, service models (IaaS, PaaS, SaaS) and deployment models, the shared responsibility model, and virtualization fundamentals.
Explore cloud security's legal and regulatory landscape, including GDPR, data privacy and PII, cross-border transfers, E-discovery, and hosting contracts within the cloud shared responsibility model.
Explore cloud data storage types—volume, object, file, and block—and how they map to cloud service models under the shared responsibility model, with protections and bcdr planning.
Explore cloud security in third-party outsourcing by focusing on auditing controls, SOC reports, and the shared responsibility model to validate data protection in the cloud.
Secure virtual environments require hardening virtual machines, hypervisors, and containers, with vulnerability assessments, patch management, encryption, access controls, and continuity planning for resilient operation.
Explore key points in systems and application security, including malware, countermeasures, endpoint and mobile security, cloud security, data storage, legal considerations, and auditing to prep for the SSCP exam.
The Systems Security Certified Practitioner (SSCP) certification is a globally recognized credential in the field of cybersecurity. The SSCP certification validates the knowledge and skills required to implement, monitor, and administer cybersecurity policies and procedures to protect information systems from unauthorized access, misuse, and destruction.
The SSCP certification exam tests knowledge in all of the above domains. The Systems Security Certified Practitioner Course provides participants with the knowledge and skills required to pass the SSCP certification exam. The course covers the seven domains of the (ISC)² SSCP Common Body of Knowledge (CBK) and includes hands-on exercises and real-world scenarios to help participants apply their knowledge in a practical setting.
Participants will learn about access controls and the different types of access controls used to protect information systems and data.Participants will learn about security operations and administration, including incident response, disaster recovery, and business continuity planning.Participants will learn how to identify, monitor, and analyze risks to information systems and data.
Overall, the SSCP certification and course are designed for professionals who are looking to demonstrate their knowledge and skills in implementing and administering cybersecurity policies and procedures to protect information systems and data. The SSCP certification is suitable for a wide range of professionals, including security administrators, network security engineers, and systems administrators.