|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/issap-information-systems-security-architecture-qa-test/
课程评论:没有评论
课程名称:ISSAP 信息系统安全架构专业考试模拟测试 课程概述: ISSAP(信息系统安全架构专业认证)是针对拥有CISSP证书的专业人士,专注于设计安全解决方案并为管理层提供基于风险的指导,以满足组织目标。ISSAP专家帮助确保安全解决方案与组织背景相一致,包括愿景、使命、战略、政策、需求、变更及外部因素。CISSP-ISSAP认证适合担任首席安全架构师或分析师的候选人,通常以独立顾问或类似角色工作。作为架构师,候选人在信息安全部门发挥关键作用。 考试领域概述: - **领域1:治理、合规与风险管理架构** - 确定法律、监管、组织及行业要求 - 管理风险 - **领域2:安全架构建模** - 确定安全架构方法 - 验证和确认设计(例如,功能验收测试(FAT)、回归测试) - **领域3:基础设施安全架构** - 制定基础设施安全要求 - 设计深度防御架构 - 保护共享服务(如无线、电子邮件、VoIP、统一通信、域名系统(DNS)、网络时间协议(NTP)) - 整合技术安全控制 - 设计和整合基础设施监控 - 设计基础设施加密解决方案 - 设计安全的网络和通信基础设施(如虚拟专用网络(VPN)、Internet协议安全(IPsec)、传输层安全(TLS)) - 评估物理和环境安全要求 - **领域4:身份与访问管理(IAM)架构** - 设计身份管理与生命周期 - 设计访问控制管理与生命周期 - 设计身份与访问解决方案 - **领域5:应用安全架构** - 将软件开发生命周期(SDLC)与应用安全架构集成(如需求追踪矩阵(RTM)、安全架构文档、安全编码) - 确定应用安全能力要求和策略(如开源、云服务提供商(CSP)、软件即服务(SaaS)/基础设施即服务(IaaS)/平台即服务(PaaS)环境) - 识别应用的常见主动控制(如OWASP) - **领域6:安全运营架构** - 收集安全运营要求(如法律、合规、组织和业务要求) - 设计信息安全监控(如安全信息和事件管理(SIEM)、内部威胁、威胁情报、用户行为分析、事件响应(IR)程序) - 设计业务连续性(BC)和韧性解决方案 - 验证业务连续性计划(BCP)/灾难恢复计划(DRP)架构 - 设计事件响应(IR)管理 该课程旨在帮助学员深入理解信息系统安全架构的各个领域,提升其在信息安全领域的专业能力和知识水平。
ISSAP Information Systems Security Architecture Professional Exam Practice Test The Information Systems Security Architecture Professional (ISSAP) is a CISSP who specializes in designing security solutions and providing management with risk-based guidance to meet organizational goals. ISSAPs facilitate the alignment of security solutions within the organizational context (e.g., vision, mission, strategy, policies, requirements, change, and external factors).The CISSP-ISSAP is an appropriate credential if the candidate is a chief security architect or analyst. Typically, the candidate works as an independent consultant or in a similar capacity. As the architect, candidates play a key role in the information security department.ISSAP Exam Domain:-Domain 1. Architect for Governance, Compliance and Risk ManagementDetermine legal, regulatory, organizational and industry requirementsManage RiskDomain 2. Security Architecture ModelingIdentify security architecture approachVerify and validate design (e.g., Functional Acceptance Testing (FAT), regression)Domain 3. Infrastructure Security ArchitectureDevelop infrastructure security requirementsDesign defense-in-depth architectureSecure shared services (e.g., wireless, e-mail, Voice over Internet Protocol (VoIP), Unified Communications (UC), Domain Name System (DNS), Network Time Protocol (NTP))Integrate technical security controlsDesign and integrate infrastructure monitoringDesign infrastructure cryptographic solutionsDesign secure network and communication infrastructure (e.g., Virtual Private Network (VPN), Internet Protocol Security (IPsec), Transport Layer Security (TLS))Evaluate physical and environmental security requirementsDomain 4. Identity and Access Management (IAM) ArchitectureDesign identity management and lifecycleDesign access control management and lifecycleDesign identity and access solutionsDomain 5. Architect for Application SecurityIntegrate Software Development Life Cycle (SDLC) with application security architecture (e.g., Requirements Traceability Matrix (RTM), security architecture documentation, secure coding)Determine application security capability requirements and strategy (e.g., open source, Cloud Service Providers (CSP), Software as a Service (SaaS)/Infrastructure as a Service (IaaS)/ Platform as a Service (PaaS) environments)Identify common proactive controls for applications (e.g., Open Web Application Security Project (OWASP))Domain 6. Security Operations ArchitectureGather security operations requirements (e.g., legal, compliance, organizational, and business requirements)Design information security monitoring (e.g., Security Information and Event Management (SIEM), insider threat, threat intelligence, user behavior analytics, Incident Response (IR) procedures)Design Business Continuity (BC) and resiliency solutionsValidate Business Continuity Plan (BCP)/Disaster Recovery Plan (DRP) architectureDesign Incident Response (IR) management