|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-the-complete-exam-guide/
课程评论:没有评论
课程名称:CISSP - 完整考试指南 概述:CISSP (认证信息系统安全专家) 是信息安全认证中的金标准,涵盖技术和管理方面的深刻概念。这门课程旨在教会学员如何有效设计、工程化以及管理组织的整体安全状态,主要内容包括以下几个重要领域: 1. **安全与风险管理**:本领域是CISSP考试中最重要的部分之一。它奠定了基础,涵盖了其他领域所需的安全概念。学员将深入理解安全的含义以及评估和管理风险的核心概念,这对每个领域都是至关重要的。 2. **资产安全**:资产是我们所重视的一切。保护高价值资产(例如敏感数据)在其生命周期中的安全至关重要。课程将涉及数据标准、分类、法规、保留和保护组织价值的控制措施。 3. **安全工程**:工程是理解和设计有效系统的过程。安全是任何设计良好的系统的基本组成部分。本领域将帮助学员理解工程生命周期以及数据结构和物理设施所需的各种模型和安全组件,并学习密码学在信息安全中的作用。 4. **通信与网络安全**:信息不仅仅是存储的,也需要在传输过程中确保安全。理解网络模型、协议、硬件组件及其潜在攻击载体对于信息安全至关重要,此领域也是CISSP考试中最重要的部分之一。 5. **身份与访问管理**:控制谁可以访问宝贵资源有助于保障机密性、完整性和可用性。CISSP必须理解验证主体真实性的机制和技术,以便授予访问权限,并确保只发生适当的交互,从而降低潜在攻击的风险。 6. **安全评估与测试**:了解安全措施的有效性至关重要。通过收集和审查日志、验证软件开发安全性及进行安全审计与认证,可以获得安全状态和需求的保证和洞察。 7. **安全运营**:从事件响应(涉及证据调查)到设施访问管理和灾难恢复计划的测试与实施,此领域要求将安全原则和概念付诸实践。 8. **软件开发生命周期中的安全**:许多公开的安全问题源于软件代码中的缺陷。虽然CISSP不需要成为软件开发人员,但必须理解并能沟通软件开发中的安全需求。本领域将教授软件开发的重要术语和概念。 该课程旨在为学员提供全面的CISSP考试准备,帮助他们在信息安全领域建立扎实的理论基础与实践技能。
CISSP is the gold standard for security certifications. It covers the breadth of information security's deep technical and managerial concepts. Learning to effectively design, engineer, and manage the overall security posture of an organization. This course covers Domain 1 - Security and Risk Management. This domain is one of the most important domains in the CISSP exam. It lays the foundation, covering security concepts that all the other domains build upon. Understanding exactly what security means and the core concepts around assessing and managing the wide array of risks we face is fundamental to every domain in the CISSP. Domain 2 - Asset Security. An asset is anything we value. When we have highly valued assets, such as sensitive data, securing those assets throughout their lifecycle is paramount. We will learn about data standards, classification, regulations, retention, and controls to protect organizational value. Domain 3 - Security Engineering. Engineering is about understanding and designing systems that work. Security is a fundamental part of any well-designed system. This domain will help you understand the engineering lifecycle and various models and security components required in data structures and physical facilities. We also learn how cryptography fits in to information security. Domain 4 - Communication and Network Security. Information is not just stored; it is also transmitted and must be secured in transit. Understanding networking models, protocols, hardware components, and possible attack vectors is vital to information security. It is one of the most important domains on the CISSP exam. Domain 5 - Identity and Access Management. Controlling who can access valuable resources can lead to proper confidentiality, integrity, and availability. A CISSP must understand mechanisms and techniques to verify a subject's authenticity before authorizing access. They must be able to assure that only proper interactions have occurred and mitigate potential attacks. Domain 6 - Security Assessment and Testing. Understanding the effectiveness of your security measures is vital. As you collect and review logs, verify software development security, and undergo security audits and certification you can have some assurance and insight into your security status and needs. Domain 7- Security Operations. From incident response that involves investigation of evidence to facility access management and disaster recovery planning, testing, and implementation, this domain requires putting security principles and concepts into practice. Domain 8 - Security in the Software Development Life Cycle. Many of the most publicized security issues have stemmed from flaws in the software code. While a CISSP does not have to be a software developer, they must understand and be able to communicate software development security needs. In this domain you will learn important terminology and concepts of software development.