TOLL FREE No : 1800-103-4583|customer_relations@qaiglobal.com
Menu

Certified Information Systems Security Professional (CISSP)

Register Now

Go to Training Calendar
Request In-house Training
Become a Trainer

DURATION: 5 Days

Course Overview

DAY 1

  • Security and Risk Management (Security, Risk, Compliance, Law, Regulations, Business Continuity)
  1. Understand and apply concepts of confidentiality, integrity and availability
  2. Apply security governance principles through
  3. Compliance
  4. Understand legal and regulatory issues pertain to information security in a global context
  5. Understand professional ethics
  6. Develop and implement documented security policy, standards, procedures and guidelines.
  7. Understand business continuity requirements
  8. Contribute to personnel security policies
  9. Understand and apply risk management concepts
  10. Understand and apply threat modelling
  11. Integrate security risk considerations into acquisition strategy and practice
  12. Establish and manage information security education, training and awareness

DAY 2

  • Asset Security (Protecting Security of Assets)
  1. Classify information and supporting assets (e.g. sensitivity, criticality)
  2. Determine and maintain ownership (e.g., data owners, system owners, business/mission owners
  3. Protect Privacy
  4. Ensure appropriate retention (e.g., media, hardware, personnel)  
  5. Determine data security controls (e.g., data at rest, data in transit)
  6. Establish handling requirements (markings, labels, storage, destruction of sensitive information)

  • Security Engineering (Engineering and Management of Security)
  1. Implement and manage engineering processes using secure design principles
  2. Understand the fundamental concepts of security models (e.g., Confidentiality, integrity and multi-level models)
  3. Select controls  and countermeasures based upon systems security evaluation models
  4. Understand security capabilities of information systems (e.g., memory protection, virtualization, trusted platform module, interfaces, fault tolerance)
  5. Assess and mitigate the vulnerabilities of security architectures, designs and solution elements
  6. Assess and mitigate vulnerabilities in web-based systems (e.g., XML, OWASP)
  7. Assess and mitigate vulnerabilities in mobile systems
  8. Assess and mitigate the vulnerabilities in embedded devices and cyber-physical systems (e.g., network-enables devices, internet of things (IOT)
  9. Apply cryptography
  10. Apply secure principles to site and facility design
  11.  Design and implement physical security

 

DAY 3

  • Communications and Network Security (Designing and Protecting Network Security)
  1. Apply secure design principles to network architecture (e.g., IP & non-IP protocols, segmentation
  2. Secure Network components
  3. Design and establish secure communication channels
  4. Prevent or mitigate network attacks

  • Identify and Access Management (Controlling Access and Managing Identity)
  1. Control physical and logical access to assets
  2. Manage identification and authentication of people and devices
  3. Integrate Identity as a service (e.g, cloud identity)
  4. Integrate third-party identity services (e.g., on-premise)
  5. Implement and manage authorization mechanisms
  6. Prevent or mitigate access control attacks
  7. Manage the identity and access provisioning lifecycle (e.g., provisioning review)

DAY 4

  • Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
  1. Design and validate assessment and test strategies
  2. Conduct security control testing
  3. Collect security process data (e.g, management and operational controls)
  4. Analyse and report test outputs (e.g. automated, manual)
  5. Conduct or facilitate internal and third party audits
  • Security Operations (Foundational Concepts, Investigations, Incident Management, Disaster Recovery)
  1. Understand and support investigations
  2. Understand requirements for investigation types
  3. Conduct logging and monitoring activities
  4. Secure the provisioning of resources
  5. Understand and apply foundational security operations concepts
  6. Employ resource protection techniques
  7. Conduct incident management
  8. Operate and maintain preventative measures
  9. Implement and support patch and vulnerability management
  10. Participate in and understand change management process (e.g., versioning, baselining, security impact analysis)
  11. Implement recovery strategies
  12. Implement disaster recovery processes
  13. Test disaster recovery plans
  14. Participate in business continuity planning and exercises
  15. Implement and manage physical security
  16. Participate in addressing personal safety concerns(e.g. Duress, travel, monitoring)

DAY 5

  • Software Development Security (Understanding, Applying, and Enforcing Software Security) 
  1. Understand and apply security in the software development lifecycle
  2. Enforce security controls in development environments
  3. Assess the effectiveness of software security
  4. Assess security impact of acquired software
  • MOCK TEST


Get 10% discount on a group of 4 or more nominations! (Discount will be applied during checkout)
Only applicable for selected batches and courses.

Certified Information Systems Security Professional (CISSP)

TrainingCourseLocationPriceQuantityAdd to Cart Button
SKU: N/A Category:
Our Clients