Training Camp's Official (ISC)² CISSP 6-Day* Curriculum
The following curriculum is authorized by (ISC)² and prepares students for
on-site delivery of the following exam:
- Official (ISC)² CISSP Examination
Access Control
A collection of mechanisms that work together to create a security architecture
to protect the assets of the information system.
Access Control Concepts
- Concepts/Methodologies/Techniques
- Attacks
- Effectiveness
Telecommunications and Network Security
Discusses network structures, transmission methods, transport formats and security
measures used to provide availability, integrity and confidentiality.
Telecommunications and Network Security Concepts
- Network architecture and design
- Network components
- Communication channels
- Network attacks
Information Security Governance and Risk Management
The identification of an organization’s information assets and the development,
documentation and implementation of policies, standards, procedures and guidelines.
Info Sec Governance and Risk Management Concepts
- Security governance and policy
- Risk management concepts
- Personnel security
- Information classification/ownership
- Contractual agreements and procurement processes
- Security education, training and awareness
- Certification and accreditation
Software Development Security
Refers to the controls that are included within systems and applications software
and the steps used in their development.
Software Development Security Concepts
- Systems development life cycle (SDLC)
- Effectiveness of application security
- Application environment and security controls
Cryptography
The principles, means and methods of disguising information to ensure its integrity,
confidentiality and authenticity.
Cryptography Concepts
- Encryption concepts
- Public Key Infrastructure (PKI)
- Digital signatures
- Information hiding alternatives
- Cryptanalytic attacks
Security Architecture and Design
Contains the concepts, principles, structures and standards used to design, implement,
monitor, and secure, operating systems, equipment, networks, applications, and those
controls used to enforce various levels of confidentiality, integrity and availability.
Security Architecture and Design Concepts
- Fundamental concepts of security models
- Countermeasure principles
- Capabilities of information systems (e.g. memory protection, virtualization)
- Vulnerabilities and threats (e.g. cloud computing, aggregation, data flow control)
Operations Security
Used to identify the controls over hardware, media and the operators with access
privileges to any of these resources.
Operations Security Concepts
- Resource protection
- Attack prevention and response
- Incident response
- Patch and vulnerability management
Business Continuity and Disaster Recovery Planning
Addresses the preservation of the business in the face of major disruptions to normal
business operations.
Business Continuity and Disaster Recovery Concepts
- Business impact analysis
- Disaster recovery process
- Recovery strategy
- Provide training
Legal, Regulations, Investigations and Compliance
Addresses computer crime laws and regulations; the investigative measures and techniques
which can be used to determine if a crime has been committed and methods to gather
evidence.
Legal, Regulations, Investigations and Compliance Concepts
- Legal Issues
- Forensic procedures
- Investigations
- Compliance requirements/procedures
Physical (Environmental) Security
Addresses the threats, vulnerabilities and countermeasures that can be utilized
to physically protect an enterprise’s resources and sensitive information.
Physical (Environmental) Security Concepts
- Site/facility design considerations
- Internal security
- Perimeter security
- Facilities security
*Due to ISC²'s new and improved testing experience, along with enhanced support
and materials developed through our partnership with ISC2, the length
of Training Camp's CISSP Boot Camp will be 6 days effective March 18, 2013.