|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-certification-domains-1-2-3-4/
课程评论:没有评论
课程名称:CISSP认证:第1、2、3和4领域视频培训-2021 课程概述:本课程旨在通过第1、2、3和4领域的视频培训,提供您通过CISSP认证所需的知识、经验和实用技能。培训讲师拥有超过18年的经验,能将CISSP培训要求转化为真实的案例,以便学员更好地理解。 课程包含: - 第1领域视频:13个部分,31个视频,附带10道CISSP练习题 - 第2领域视频:5个部分,9个视频,附带10道CISSP练习题 - 第3领域视频:11个部分,16个视频,附带10道CISSP练习题 - 第4领域视频:3个部分,7个视频,附带10道CISSP练习题 本课程涵盖2021年4月最新CISSP考试的内容,逐一分析CISSP考试所需的各个目标,复杂性和能力水平各不相同。CISSP课程/考试的下次升级将于2023年进行。 第1领域涵盖: - 机密性、完整性和可用性概念 - 安全治理原则 - 合规要求 - 风险管理概念 - 供应链的风险管理 - 安全意识、教育和培训程序的建立与维护 第2领域涉及: - 数据和资产的识别与分类 - 数据保护控制的制定 - 信息和资产处理要求 第3领域重点: - 安全设计原则的实施与管理 - 系统安全要求下的控制选择 - 密码学方法的应用 - 设施安全控制的实施 第4领域聚焦于: - 网络架构中的安全设计原则 - 安全通信通道的实施 - 硬件操作及网络访问控制 注意事项:通过CISSP测试,您需要具备足够的经验和知识。考试的原始语言为英语,但也提供其他语言版本。解答考试问题时要从管理者或风险顾问的角度考虑,制定前瞻性的思维方式。建议使用多种学习来源来增强备考效果,而不仅仅依赖单一材料。 本课程为希望获得CISSP认证的学员提供全面的准备信息,致力于帮助他们以最佳状态通过认证考试。
In this CISSP Domain 1, 2, 3, and 4 video training course, I will provide you the knowledge, experience and practical skills you need to pass the CISSP certification. In addition, you will get my years of experience (Over 18 years) as I translate CISSP training requirements into real-world examples.Included in this course:CISSP Domain 1 Videos13 Sections - 31 Videos10 CISSP practice questionsCISSP Domain 2 Videos5 Sections - 9 Videos10 CISSP practice questionsCISSP Domain 3 Videos11 Sections - 16 Videos10 CISSP practice questionsCISSP Domain 4 Videos3 Sections - 7 Videos10 CISSP practice questionsThe curriculum in this course covers the content that will be on the most current CISSP exam (April 2021). Each objective that is required for the CISSP exam will be covered in varying degrees of complexity and competency. The next upgrade to the CISSP curriculum/exam will occur in 2023.In Domain 1 we will cover:IntroductionIntroductionPurposeISC2Understand and apply concepts of confidentiality, integrity and availabilityConfidentialityIntegrityAvailabilityEvaluate and apply security governance principlesAlignment of security function to business strategy, goals, mission, and objectivesOrganizational processes (e.g., acquisitions, divestitures, governance committeesOrganizational roles and responsibilitiesSecurity control frameworksDue care/due diligenceDetermine compliance requirementsContractual, legal, industry standards, and regulatory requirementsPrivacy requirementsUnderstand legal and regulatory issues that pertain to information security in a global contextCyber crimes and data breachesLicensing and intellectual property requirementsImport/export controlsTrans-border data flowPrivacyUnderstand, adhere to, and promote professional ethics(ISC)² Code of Professional EthicsOrganizational code of ethicsDevelop, document, and implement security policy, standards, procedures, and guidelinesIdentify, analyze, and prioritize Business Continuity (BC) requirementDevelop and document scope and planBusiness Impact Analysis (BIA)Contribute to and enforce personnel security policies and proceduresCandidate screening and hiringEmployment agreements and policiesOnboarding and termination processesVendor, consultant, and contractor agreements and controlsCompliance policy requirementsPrivacy policy requirementsUnderstand and apply risk management conceptsIdentify threats and vulnerabilitiesRisk assessment/analysisRisk responseCountermeasure selection and implementationApplicable types of controls (e.g., preventive, detective, corrective)Security Control Assessment (SCA)Monitoring and measurementAsset valuationReportingContinuous improvementRisk frameworksUnderstand and apply threat modeling concepts and methodologiesThreat modeling methodologiesThreat modeling conceptsApply risk-based management concepts to the supply chainRisks associated with hardware, software, and servicesThird-party assessment and monitoringMinimum security requirementsService-level requirementsEstablish and maintain a security awareness, education, and training programMethods and techniques to present awareness and trainingPeriodic content reviewsProgram effectiveness evaluationIn Domain 2 we will cover:Identify and classify information and assetsData ClassificationAsset ClassificationDetermine and maintain information and asset ownershipProtect privacyData ownersData processorsData remanenceCollection limitationEnsure appropriate asset retentionDetermine data security controlsUnderstand data statesScoping and tailoringStandards selectionData protection methodsEstablish information and asset handling requirementsIn Domain 3 we will cover:Implementation and management of engineering processes using secure design principlesAsset RetentionConfinementUnderstanding of the fundamental concepts of security modelsSelection of controls based upon systems security requirementsSecurity capabilities of information systemsAssessment and mitigation of vulnerabilities within a security architectureClient-based systemsServer-based systemsDatabase systemsCryptographic systemsIndustrial Control Systems (ICS)Cloud-based systemsDistributed systemsInternet of Things (IoT)Assessment and mitigation in web-based systemsAssessment and mitigation in mobile-based systemsAssessment and mitigation in embedded devicesApply cryptographic methodsCryptographic life-cycleCryptographic methodsPublic Key InfrastructureKey management practicesDigital SignaturesNon-repudiationIntegrity (e.g. Hashing)Cryptographic attacksDigital Rights Management (DRM)Application of security principles to sites and facility designImplementation of site and facility security controlsWiring closets/intermediate distribution facilitiesServer rooms/data centersMedia storage facilitiesEvidence storageRestricted and work area securityUtilities and Heating, Ventilation, and Air Conditioning (HVAC)Environmental issuesFire prevention, detection, and suppressionIn Domain 4 we will cover:Implement secure design principles in network architecturesOpen System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) modelsInternet Protocol (IP) networkingImplications of multil-ayer protocolsConverged protocolsSoftware-defined networksWireless networksSecure network componentsOperation of hardwareTransmission mediaNetwork Access Control (NAC) devicesEndpoint securityContent-distribution networksImplement secure communication channels according to designVoiceMultimedia collaborationRemote accessData communicationsVirtualized networksNotes / Disclaimers:In order for you to pass the CISSP test you need to have the substantial knowledge through experience and knowledge.The test was originally written in English, but there are other language versions availableAnswering the questions you need to consider the "perfect world" scenario and that work around options may be technically correct, but they may not meet (ISC)2 point of viewYou need to be able to spot the keywords (DR, BCP, Policy, Standards, etc.) as well as the indicators (First, Best, Last, Least, Most)Understand and answer every question from the Manager, CISO, or Risk Advisers Point of View (PoV). Answering the questions from a CIO or technical perspective will place your thinking too high or down in the weeds too far.Understand that you are to answer the questions based on being proactive within your environment. Enable a Vulnerability Management Program before you have vulnerability issues.The English version of the CISSP exam, utilizes the Computerized Adaptive Testing (CAT) format and is 3 hours long with 100-150 questionsMost people studying for CISSP certification will various media sources, test banks, and various books to enhance their test taking experience.Don't rely on one source to teach you all that you need to know for the CISSP….Invest in multiple training opportunities. The future payoff is worth the time and energy.