CISSP Certification Training & Preparation  

Detailed Course Description:

The Ten Domains In Detail:

 

CISSP candidates are expected to be knowledgeable of the concepts, skills and technologies embodied in each domain. Here is an overview of the range of topics students will explore for each domain:

Domain 1:     Security Management Practices

  • Types of Security Controls

  • Components of a Security Program

  • Security Policies, Standards, Procedures, and Guidelines

  • Risk Management and Analysis

  • Information Classification

  • Employee Management Issues

  • Threats, Vulnerabilities and Corresponding Administrative Controls

Domain 2:     Access Control Systems and Methodology

  • Identification, Authentication, and Authorization Techniques and Technologies

  • Biometrics, Smart Cards, and Memory Cards

  • Single Sign-On Technologies and Their Risks

  • Discretionary versus Mandatory Access Control Models

  • Rule-based and Role-based Access Control

  • Object Reuse Issues and Social Engineering

  • Emissions Security Risks and Solutions

  • Specific Attacks and Countermeasures

Domain 3:     Cryptography

  • Historical Uses of Cryptography

  • Block and Stream Ciphers

  • Explanation and Uses of Symmetric Key Algorithms

  • Explanation and Uses of Asymmetric Key Algorithms

  • Public Key Infrastructure Components

  • Data Integrity Algorithms and Technologies

  • IPSec, SSL, SSH, and PGP

  • Secure Electronic Transactions

  • Key Management

  • Attacks on Cryptosystems

Domain 4:     Physical Security

  • Facility Location and Construction Issues

  • Physical Vulnerabilities and Threats

  • Doors, Windows, and Secure Room Concerns

  • Hardware Metrics and Backup Options

  • Electrical Power Issues and Solutions

  • Fire Detection and Suppression

  • Fencing, Lighting, and Perimeter Protection

  • Physical Intrusion Detection Systems

Domain 5:     Enterprise Security Architecture

  • Critical Components of Every Computer

  • Processes and Threads

  • The OSI Model

  • Operating System Protection Mechanisms

  • Ring Architecture and Trusted Components

  • Virtual Machines, Layering, and Virtual Memory

  • Access Control Models

  • Orange Book, ITSEC, and Common Criteria

  • Certification and Accreditation

  • Covert Channels and Types of Attacks

  • Buffer Overflows and Data Validation Attacks

Domain 6:     Law, Investigation, and Ethics

  • Different Ethics Sets

  • Computer Criminal Profiles

  • Types of Crimes

  • Liability and Due Care Topics

  • Privacy Laws and Concerns

  • Complications of Computer Crime Investigation

  • Types of Evidence and How to Collect It

  • Forensics

  • Legal Systems

Domain 7:      Telecommunications, Networks, and Internet Security

  • TCP\IP Suite

  • LAN, MAN, and WAN Topologies and Technologies

  • Cable Types and Issues

  • Broadband versus Baseband Technologies

  • Ethernet and Token Ring

  • Network Devices

  • Firewall Types and Architectures

  • Dial-up and VPN Protocols

  • DNS and NAT Network Services

  • FDDI and SONET

  • X.25, Frame Relay, and ATM

  • Wireless LANs and Security Issues

  • Cell Phone Fraud

  • VoIP

  • Types of Attacks

 

Domain 8    Business Continuity Planning

  • Roles and Responsibilities

  • Liability and Due Care Issues

  • Business Impact Analysis

  • Identification of Different Types of Threats

  • Development Process of BCP

  • Backup Options and Technologies

  • Types of Offsite Facilities

  • Implementation and Testing of BCP

 

Domain 9:      Applications & Systems Development

  • Software Development Models

  • Prototyping and CASE Tools

  • Object-Oriented Programming

  • Middleware Technologies

  • ActiveX, Java, OLE, and ODBC

  • Database Models

  • Relational Database Components

  • CGI, Cookies, and Artificial Intelligence

  • Different Types of Malware

Domain 10:     Operations Security
  • Operations Department Responsibilities
  • Personnel and Roles
  • Media Library and Resource Protection
  • Types of Intrusion Detection Systems
  • Vulnerability and Penetration Testing
  • Facsimile Security
  • RAID, Redundant Servers, and Clustering

Course Information:

 

Various sample deliverables are offered utilizing public domain templates, checklists, and forms. Templates will change continuously adapting to changes in the computer information security services industry.

 

NCS Data Systems consultants working in the disaster planning and recovery and security field will be dynamically implementing new scenarios that are over and above the base scenarios used in student workbooks.

 

Please note that this is not a class that will explain the very intricacies of each and every technique and template available.

 

NCS Data Systems consultants constantly revise information used in this class.

 

To enroll in the class or for further information and class schedules please contact us via training@ncsdata.net