|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/issmp-information-systems-security-management-prof-qa-test/
课程评论:没有评论
课程名称:ISSMP 信息系统安全管理专业考试实践测试 课程概述: ISSMP 信息系统安全管理专业考试(ISSMP)是针对安全领导者的培训项目,旨在培养能够建立、呈现和治理信息安全程序的专业人才。ISSMP专业人员负责将安全程序与组织的使命、目标和战略对齐,以满足企业的财务和操作需求,支持其所期望的风险管理水平。通过本课程,学员能够证明其在建立、呈现和治理信息安全程序方面的知识和领导能力。 考试内容领域: - **领域一:领导力与业务管理** - 建立安全在组织文化、愿景和使命中的角色 - 将安全程序与组织治理对齐 - 定义并实施信息安全战略 - 确定并维护安全政策框架 - 管理合同和协议中的安全要求 - 管理安全意识和培训项目 - 定义、测量和报告安全指标 - 准备、获取和管理安全预算 - 管理安全程序 - 应用产品开发和项目管理原则 - **领域二:系统生命周期管理** - 管理安全与系统开发生命周期(SDLC)的整合 - 将新业务倡议和新兴技术整合到安全架构中 - 定义并监督全面的漏洞管理程序(如漏洞扫描、渗透测试、威胁分析) - 管理变更控制的安全方面 - **领域三:风险管理** - 开发和管理风险管理程序 - 进行风险评估 - 管理供应链中的安全风险(例如:供应商、承包商、第三方风险) - **领域四:威胁情报与事件管理** - 建立和维护威胁情报程序 - 建立和维护事件处理与调查程序 - **领域五:应急管理** - 促进应急计划的制定 - 开发恢复策略 - 维护应急计划、操作持续性计划(COOP)、业务连续性计划(BCP)和灾难恢复计划(DRP) - 管理灾难响应和恢复过程 - **领域六:法律、伦理与安全合规管理** - 识别与信息安全相关的法律和法规的影响 - 遵循(ISC)²伦理守则,涉及管理问题 - 根据适用的法律、法规和行业最佳实践验证合规性 - 协调审计师和监管机构,以支持内部和外部审计过程 - 记录和管理合规例外 本课程将帮助学员掌握信息安全管理的领导力和专业技能,为在信息安全领域的发展奠定坚实基础。
ISSMP Information Systems Security Management Professional Exam Practice Test The Information Systems Security Management Professional (ISSMP) is security leader who specializes in establishing, presenting and governing information security programs and demonstrates management and leadership skills. ISSMPs direct the alignment of security programs with the organization's mission, goals and strategies in order to meet enterprise financial and operational requirements in support of its desired risk position.Proves your knowledge and leadership skills establishing, presenting and governing information security programsISSMP Exam Domain:-Domain 1: Leadership and Business ManagementEstablish security's role in organizational culture, vision and missionAlign security program with organizational governanceDefine and implement information security strategiesDefine and maintain security policy framework Determine applicable external standardsManage security requirements in contracts and agreementsManage security awareness and training programsDefine, measure and report security metricsPrepare, obtain and administer security budgetManage security programsApply product development and project management principlesDomain 2: Systems Lifecycle ManagementManage integration of security into Systems Development Life Cycle (SDLC)Integrate new business initiatives and emerging technologies into the security architectureDefine and oversee comprehensive vulnerability management programs (e.g., vulnerability scanning, penetration testing, threat analysis)Manage security aspects of change controlDomain 3: Risk ManagementDevelop and manage a risk management programConduct risk assessmentsManage security risks within the supply chain (e.g., supplier, vendor, third-party risk)Domain 4: Threat Intelligence and Incident ManagementEstablish and maintain threat intelligence programEstablish and maintain incident handling and investigation programDomain 5: Contingency ManagementFacilitate development of contingency plansDevelop recovery strategiesMaintain contingency plan, Continuity of Operations Plan (COOP), business continuity plan (BCP) and disaster recovery plan (DRP)Manage disaster response and recovery processDomain 6: Law, Ethics and Security Compliance ManagementIdentify the impact of laws and regulations that relate to information securityAdhere to the (ISC)2 Code of Ethics as related to management issuesValidate compliance in accordance with applicable laws, regulations and industry best practicesCoordinate with auditors and regulators in support of the internal and external audit processesDocument and manage compliance exceptions