CISSP
Certification Training & Preparation
  |
|
Detailed Course Description: |
|
The Ten Domains In Detail:
CISSP
candidates are expected to be knowledgeable of the concepts,
skills and technologies embodied in each domain. Here is an
overview of the range of topics students will explore for each
domain: |
|
Domain 1: Security Management Practices
-
Types of Security Controls
-
Components of a Security
Program
-
Security Policies, Standards,
Procedures, and Guidelines
-
Risk Management and Analysis
-
Information Classification
-
Employee Management Issues
-
Threats, Vulnerabilities and
Corresponding Administrative Controls
|
|
Domain 2: Access
Control Systems and Methodology
-
Identification,
Authentication, and Authorization Techniques and
Technologies
-
Biometrics, Smart Cards, and
Memory Cards
-
Single Sign-On Technologies
and Their Risks
-
Discretionary versus Mandatory
Access Control Models
-
Rule-based and Role-based
Access Control
-
Object Reuse Issues and Social
Engineering
-
Emissions Security Risks and
Solutions
-
Specific Attacks and
Countermeasures
|
|
Domain 3: Cryptography
-
Historical Uses of
Cryptography
-
Block and Stream Ciphers
-
Explanation and Uses of
Symmetric Key Algorithms
-
Explanation and Uses of
Asymmetric Key Algorithms
-
Public Key Infrastructure
Components
-
Data Integrity Algorithms and
Technologies
-
IPSec, SSL, SSH, and PGP
-
Secure Electronic Transactions
-
Key Management
-
Attacks on Cryptosystems
|
|
Domain
4:
Physical Security
-
Facility Location and
Construction Issues
-
Physical Vulnerabilities and
Threats
-
Doors, Windows, and Secure
Room Concerns
-
Hardware Metrics and Backup
Options
-
Electrical Power Issues and
Solutions
-
Fire Detection and Suppression
-
Fencing, Lighting, and
Perimeter Protection
-
Physical Intrusion Detection
Systems
|
|
Domain 5: Enterprise Security Architecture
-
Critical Components of Every
Computer
-
Processes and Threads
-
The OSI Model
-
Operating System Protection
Mechanisms
-
Ring Architecture and Trusted
Components
-
Virtual Machines, Layering,
and Virtual Memory
-
Access Control Models
-
Orange Book, ITSEC, and Common
Criteria
-
Certification and
Accreditation
-
Covert Channels and Types of
Attacks
-
Buffer Overflows and Data
Validation Attacks
|
|
Domain
6:
Law, Investigation, and Ethics
-
Different Ethics Sets
-
Computer Criminal Profiles
-
Types of Crimes
-
Liability and Due Care Topics
-
Privacy Laws and Concerns
-
Complications of Computer
Crime Investigation
-
Types of Evidence and How to
Collect It
-
Forensics
-
Legal Systems
|
|
Domain 7: Telecommunications,
Networks, and Internet Security
-
TCP\IP Suite
-
LAN, MAN, and WAN Topologies
and Technologies
-
Cable Types and Issues
-
Broadband versus Baseband
Technologies
-
Ethernet and Token Ring
-
Network Devices
-
Firewall Types and
Architectures
-
Dial-up and VPN Protocols
-
DNS and NAT Network Services
-
FDDI and SONET
-
X.25, Frame Relay, and ATM
-
Wireless LANs and Security
Issues
-
Cell Phone Fraud
-
VoIP
-
Types of Attacks
|
|
Domain 8:
Business Continuity Planning
-
Roles and Responsibilities
-
Liability and Due Care Issues
-
Business Impact Analysis
-
Identification of Different
Types of Threats
-
Development Process of BCP
-
Backup Options and
Technologies
-
Types of Offsite Facilities
-
Implementation and Testing of
BCP
|
|
Domain 9: Applications & Systems Development
-
Software Development Models
-
Prototyping and CASE Tools
-
Object-Oriented Programming
-
Middleware Technologies
-
ActiveX, Java, OLE, and ODBC
-
Database Models
-
Relational Database Components
-
CGI, Cookies, and Artificial
Intelligence
-
Different Types of Malware
|
Domain 10: Operations
Security
-
Operations Department Responsibilities
-
Personnel and Roles
- Media
Library and Resource Protection
- Types of
Intrusion Detection Systems
-
Vulnerability and Penetration Testing
-
Facsimile Security
- RAID,
Redundant Servers, and Clustering
|
|
Course
Information:
Various sample deliverables are offered utilizing
public domain templates, checklists, and forms. Templates will
change continuously adapting to changes in the computer
information security services industry.
NCS Data Systems consultants
working in the disaster planning and recovery and security field
will be dynamically implementing new scenarios that are over and
above the base scenarios used in student workbooks.
Please note that this is not a class that will
explain the very intricacies of each and every technique and
template available.
NCS Data Systems consultants
constantly revise information used in this class.
|
|
To enroll in the class or for further
information and class schedules please contact us via
training@ncsdata.net
|