|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-certified-information-systems-security-professional-qj/
课程评论:没有评论
**课程名称:** CISSP - 注册信息系统安全专家认证 (2025年考试) **课程概述:** 本课程是关于 CISSP(注册信息系统安全专家)认证的备考课程。CISSP 是全球信息安全领域最受认可的认证之一,旨在验证信息安全专业人员在设计、工程和管理组织整体安全态势方面的深度技术和管理知识与经验。 课程涵盖了 CISSP 通用知识体系 (CBK®) 中的八大核心领域,确保其在信息安全所有学科中的相关性。成功通过考试的候选人将在以下八个领域具备专业能力: 1. **安全与风险管理 (16%)**:奠定基础,涵盖所有其他领域的基础安全概念、风险评估和管理。 2. **资产安全 (10%)**:关注有价值的资产(如敏感数据)的整个生命周期保护,包括数据标准、分类、法规、保留和控制。 3. **安全架构与工程 (13%)**:理解和设计安全可靠的系统,包括工程生命周期、模型、数据结构、物理设施安全以及密码学。 4. **通信与网络安全 (13%)**:确保信息在传输过程中的安全,关键在于理解网络模型、协议、硬件组件和潜在攻击。 5. **身份与访问管理 (IAM) (13%)**:控制对资源的访问,确保机密性、完整性和可用性,包括验证主体身份、授权访问和缓解攻击。 6. **安全评估与测试 (12%)**:评估安全措施的有效性,通过日志审查、软件开发安全验证、安全审计和认证来了解安全状态。 7. **安全运营 (13%)**:将安全原则和概念付诸实践,包括事件响应、取证调查、设施访问管理以及灾难恢复规划、测试和实施。 8. **软件开发安全 (10%)**:理解软件代码中的安全问题,能够沟通软件开发的安全需求,了解相关的术语和概念。 **CISSP CAT 考试信息:** * **考试形式:** 计算机自适应测试 (CAT - 适用于所有英文考试)。其他语言考试为线性固定形式。 * **考试时长:** 3 小时 * **题目数量:** 100 - 150 题 * **题型:** 选择题及高级创新题。 * **及格分数:** 1000 分制中的 700 分。 * **考试语言:** 支持中文、英文、德文、日文、西班牙文。 * **考试中心:** 国际ISC²授权的Pearson VUE考试中心。 **中文科目的考试安排:** 自2024年4月15日起,中文CISSP考试将提供一个月的预约窗口。之后的预约窗口将于每季度末提供: * 2024年4月15日至5月15日 * 2024年9月1日至9月30日 * 2024年12月1日至12月31日
CISSP - Certified Information Systems Security ProfessionalThe Certified Information Systems Security Professional (CISSP) is the most globally recognized certification in the information security market. CISSP validates an information security professional's deep technical and managerial knowledge and experience to effectively design, engineer, and manage the overall security posture of an organization.The broad spectrum of topics included in the CISSP Common Body of Knowledge (CBK®) ensure its relevancy across all disciplines in the field of information security. Successful candidates are competent in the following eight domains:1. Security and Risk Management16%2. Asset Security10%3. Security Architecture and Engineering13%4. Communication and Network Security13%5. Identity and Access Management (IAM)13%6. Security Assessment and Testing12%7. Security Operations13%8. Software Development Security10%CISSP DOMAINDomain 1 - Security and Risk Management. This domain is one of the most important domains in the CISSP exam. It lays the foundation, covering security concepts that all the other domains build upon. Understanding exactly what security means and the core concepts around assessing and managing the wide array of risks we face is fundamental to every domain in the CISSP.Domain 2 - Asset Security. An asset is anything we value. When we have highly valued assets, such as sensitive data, securing those assets throughout their lifecycle is paramount. We will learn about data standards, classification, regulations, retention, and controls to protect organizational value.Domain 3 - Security Engineering. Engineering is about understanding and designing systems that work. Security is a fundamental part of any well-designed system. This domain will help you understand the engineering lifecycle and various models and security components required in data structures and physical facilities. We also learn how cryptography fits in to information security.Domain 4 - Communication and Network Security. Information is not just stored; it is also transmitted and must be secured in transit. Understanding networking models, protocols, hardware components, and possible attack vectors is vital to information security. It is one of the most important domains on the CISSP exam.Domain 5 - Identity and Access Management. Controlling who can access valuable resources can lead to proper confidentiality, integrity, and availability. A CISSP must understand mechanisms and techniques to verify a subject's authenticity before authorizing access. They must be able to assure that only proper interactions have occurred and mitigate potential attacks.Domain 6 - Security Assessment and Testing. Understanding the effectiveness of your security measures is vital. As you collect and review logs, verify software development security, and undergo security audits and certification you can have some assurance and insight into your security status and needs.Domain 7- Security Operations. From incident response that involves investigation of evidence to facility access management and disaster recovery planning, testing, and implementation, this domain requires putting security principles and concepts into practice.Domain 8 - Software Development Security. Many of the most publicized security issues have stemmed from flaws in the software code. While a CISSP does not have to be a software developer, they must understand and be able to communicate software development security needs. In this domain you will learn important terminology and concepts of software development.CISSP CAT Examination InformationThe CISSP exam uses Computerized Adaptive Testing (CAT) for all English exams. CISSP exams in all other languages are administered as linear, fixed-form exams. You can learn more about CISSP CAT.Length of exam: 3 hoursNumber of items: 100 - 150Item format: Multiple choice and advanced innovative itemsPassing grade: 700 out of 1000 pointsExam language availability: Chinese, English, German, Japanese, SpanishTesting center: ISC2 Authorized PPC and PVTC Select Pearson VUE Testing CentersEffective April 15, 2024 the Chinese language CISSP will be available for a one-month appointment window. Appointments will resume on September 1, 2024 for one-month windows at the end of each quarter:04/15 - 05/15/2024 (April 15 to May 15, 2024)09/01 - 09/30/2024 (September 1 to September 30, 2024)12/01 - 12/31/2024 (December 1 to December 31, 2024)