Access Control Systems and Methodologies
- Access control concepts, methodologies, and implementation
- Access controls: detective, corrective, and preventative
- Access control techniques in centralised and decentralized environments
- Access control risks, vulnerabilities, and exposures
Security Architecture and Models
- Secure operating system principles, concepts, mechanisms, controls, and standards
- Secure architecture design, modeling, and protection
- Security models: confidentiality, integrity, information flow requirements
- Common criteria, ITSEC, TCSEC, IETF IPSEC
- Technical platforms
- System security preventative, detective, and corrective measures
Disaster Recovery and Business Continuity Planning
- Business continuity planning, business impact analysis, recovery strategies, recovery plan development, and implementation
- Disaster recovery planning, implementation, and restoration
- Compare and contrast disaster recovery and business continuity
Security Management Practices
- Organizational security roles
- Identification of information assets
- Security management planning
- Security policy development; use of guidelines, standards, and procedures
- Security awareness training
- Employment agreements and practices
- Risk management tools and techniques
Law, Investigation, and Ethics
- Computer crime detection methods
- Applicable computer crime laws
- Evidence gathering and preservation methods
- Computer crime investigation methods and techniques
- ISC2 and IAB ethics application
Physical Security
- Secure site design, configuration, and selection elements
- Access control and protection methods for facility, information, equipment, and personnel
Operations Security
- Resource protection mechanisms and techniques
- Operation security principles, techniques, and mechanisms; principles of good practice and limitation of abuses
- Operations security preventative, detective, and corrective measures
Cryptography
- Cryptographic concepts, methods, and practices
- Public and private key algorithms and uses
- Key distribution and key management use
- Methods of attack, strength of function
Telecommunications and Network Security
- Overview of communications and network security
- Voice communications, data communications, local area, wide area, and remote access
- Internet/Intranet/Extranet, firewalls, routers, and network protocols
- Telecommunication and network security preventative, detective, and corrective measures
Application and System Development
- System development process and security controls
- System development life-cycle, change controls, application controls, system and application integrity
- Database structure, concepts, design techniques, and security implications
Review and Q&A Session
- Review concepts introduced in previous sessions
- Answer specific questions or concerns regarding CISSP preparation material
Testing Taking Tips and Study Techniques
- Tips for additional preparation for the CISSP exam
- Additional resources
- Techniques for scoring well on the exam