• United India colony ,Kodambakkam, Chennai.
  • +91 - 99406 11306     044-24731102/ 24732532
  • training@rjpinfotek.com

CISSP

                                                                              Duration:40 Hrs

About CISSP

The Certified Information Systems Security Professional (CISSP) is the most globally recognized certification in the information security market. CISSP validates an information security professional's deep technical  and managerial knowledge and experience to effectively design, engineer, and manage the overall security posture of an organization.

The broad spectrum of topics included in the CISSP Common Body of Knowledge (CBK) ensure its relevancy across all disciplines in the field of information security. Successful candidates are competent in the following 8 domains:

  1. Security and Risk Management
  2. Asset Security
  3. Security Engineering
  4. Communications and Network Security
  5. Identity and Access Management
  6. Security Assessment and Testing
  7. Security Operations
  8. Software Development Security

Domain 1: Security and Risk Management

  1. 1.1 Understand and apply concepts of confidentiality, integrity and availability
  2. 1.2 Apply security governance principles
  3. 1.3 Compliance
  4. 1.4 Understand legal and regulatory issues that pertain to information security in a global context
  5. 1.5 Understand professional ethics
  6. 1.6 Develop and implement documented security policy, standards, procedures, and guidelines
  7. 1.7 Understand business continuity requirements
  8. 1.8 Contribute to personnel security policies
  9. 1.9 Understand and apply risk management concepts
  10. 1.10 Understand and apply threat modeling
  11. 1.11 Integrate security risk considerations into acquisition strategy and practice
  12. 1.12 Establish and manage information security education, training, and awareness

Domain 2: Asset Security

  1. 2.1 Classify information and supporting assets
  2. 2.2 Determine and maintain ownership
  3. 2.3 Protect privacy
  4. 2.4 Ensure appropriate retention
  5. 2.5 Determine data security controls
  6. 2.6 Establish handling requirements

Domain 3: Security Engineering

  1. 3.1 Implement and manage engineering processes using secure design principles
  2. 3.2 Understand the fundamental concepts of security models
  3. 3.3 Select controls and countermeasures based upon systems security evaluation models
  4. 3.4 Understand security capabilities of information systems
  5. 3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
  6. 3.6 Assess and mitigate vulnerabilities in web-based systems
  7. 3.7 Assess and mitigate vulnerabilities in mobile systems
  8. 3.8 Assess and mitigate vulnerabilities in embedded devices and cyber-physical systems
  9. 3.9 Apply cryptography
  10. 3.10 Apply secure principles to site and facility design
  11. 3.11 Design and implement physical security

Domain 4: Communications and Network Security

  1. 4.1 Apply secure design principles to network architecture
  2. 4.2 Secure network components
  3. 4.3 Design and establish secure communication channels
  4. 4.4 Prevent or mitigate network attacks

Domain 5: Identity and Access Management

  1. 5.1 Control physical and logical access to assets
  2. 5.2 Manage identification and authentication of people and devices
  3. 5.3 Integrate identity as a service
  4. 5.4 Integrate third-party identity services
  5. 5.5 Implement and manage authorization mechanisms
  6. 5.6 Prevent or mitigate access control attacks
  7. 5.7 Manage the identity and access provisioning lifecycle

Domain 6: Security Assessment and Testing

  1. 6.1 Design and validate assessment and test strategies
  2. 6.2 Conduct security control testing
  3. 6.3 Collect security process data
  4. 6.4 Analyze and report test outputs
  5. 6.5 Conduct or facilitate internal and third party audits

      Domain 7: Security Operations

      1. 7.1 Understand and support investigations
      2. 7.2 Understand requirements for investigation types
      3. 7.3 Conduct logging and monitoring activities
      4. 7.4 Secure the provisioning of resources
      5. 7.5 Understand and apply foundational security operations concepts
      6. 7.6 Employ resource protection techniques
      7. 7.7 Conduct incident management
      8. 7.8 Operate and maintain preventative measures
      9. 7.9 Implement and support patch and vulnerability management
      10. 7.10 Participate in and understand change management processes
      11. 7.11 Implement recovery strategies
      12. 7.12 Implement disaster recovery processes
      13. 7.13 Test disaster recovery plans
      14. 7.14 Participate in business continuity planning and exercises
      15. 7.15 Implement and manage physical security
      16. 7.16 Participate in addressing personnel safety concerns

      Domain 8: Software Development Security

      • 8.1 Understand and apply security in the software development lifecycle
      • 8.2 Enforce security controls in development environments
      • 8.3 Assess the effectiveness of software security
      • 8.4 Assess security impact of acquired software

                    Next Batch Starts on (09-12-2017)

                    In-Demand Courses

                    x