![]()
![]() ![]()
|
CISSP TRAINING PROPOSAL
Course Background
Domain 1 - Information Security and Risk Management This domain examines the identification of company assets, the proper way to determine the necessary level of protection required, and what type of budget to develop for security implementations, with the goal of reducing threats and monetary loss. Domain 2 - Access Control The domain examines mechanisms and methods used to enable administrators and managers to control what subjects can access, the extent of their capabilities after authorization and authentication, and the auditing and monitoring of these activities. Domain 3 - Cryptography The domain examines methods and techniques for disguising data for protection purposes. This involves cryptography techniques, approaches, and technologies. Domain 4 - Business Continuity and Disaster Recovery Planning The domain examines the preservation of business activities when faced with disruptions or disasters. It involves the identification of real risks, proper risk assessment, and countermeasure implementation. Domain 5 - Legal Regulations, Compliance, and Investigation he domain examines computer crimes, laws, and regulations. It includes techniques for investigating a crime, gathering evidence, and handling procedures. It also covers how to develop and implement an incident-handling program. Domain 6 - Physical Security The domain examines threats, risks, and countermeasures to protect facilities, hardware, data, media, and personnel. This involves facility selection, authorized entry methods, and environmental and safety procedures. Domain 7 - Operations Security The domain examines controls over personnel, hardware, systems, and auditing and monitoring techniques. It also covers possible abuse channels and how to recognize and address them. Domain 8 - Security Architecture and Design The domain examines concepts, principles, and standards for designing and implementing secure applications, operating systems, and systems. This covers international security measurement standards and their meaning for different types of platforms. Domain 9 - Application Security The domain examines the security components within operating systems and applications and how to best develop and measure their effectiveness. It looks at software life cycles, change control, and application security. Domain 10 - Telecommunications and Network Security The domain examines internal, external, public, and private communication systems; networking structures; devices; protocols; and remote access and administration. |