Get in Touch

Course Outline

Security and Risk Management

  • Core principles of confidentiality, integrity, and availability (CIA)
  • Security governance, policy development, and frameworks (ISO 27001, NIST CSF)
  • Risk analysis, evaluation, and mitigation strategies
  • Business impact analysis, security awareness, and training programs
  • Legal, regulatory, compliance, and privacy considerations (GDPR, HIPAA, local laws)

Asset Security

  • Information classification, ownership, and protective measures
  • Data handling practices (retention, deletion, backup, and transfer)
  • Privacy protection and data lifecycle management
  • Safe usage of assets and media control measures

Security Engineering

  • Principles of secure system and architecture design
  • Cryptography: symmetric and asymmetric encryption, hashing, PKI, and key management
  • Physical security factors and hardware security modules (HSMs)
  • Secure virtualization, cloud-native security patterns, and secure API implementation

Communications and Network Security

  • Network models, protocols, and secure communication methods (TLS, VPN, IPSec)
  • Perimeter defenses, network segmentation, firewalls, and IDS/IPS
  • Wireless security, remote access solutions, and zero-trust network architectures
  • Secure network architecture design in cloud and hybrid environments

Identity and Access Management (IAM)

  • Access controls: identification, authentication, authorization, and accountability
  • Identity providers, federation, single sign-on (SSO), and cloud access federation
  • Privileged access management (PAM) and role-based access control (RBAC)
  • Identity lifecycle management: provisioning, deprovisioning, and entitlement reviews

Security Assessment and Testing

  • Security control testing: SAST, DAST, penetration testing, and vulnerability scanning
  • Audit methodologies and review frameworks
  • Log management, monitoring, and continuous assessment practices
  • Red teaming, blue teaming, and adversary simulation techniques

Security Operations

  • Incident response planning, management, and forensic investigations
  • Design and monitoring of security operations centers (SOC), including threat intelligence integration
  • Patching, vulnerability management, and configuration control
  • Business continuity, disaster recovery, and resilience planning

Software Development Security

  • Secure software development lifecycle (SDLC) and DevSecOps practices
  • Common vulnerabilities (extending beyond the OWASP Top 10) and mitigation strategies
  • Code review, static and dynamic analysis, and secure frameworks
  • Supply chain risks, dependency management, and runtime protection

Exam Strategy, Practice, and Conclusion

  • Overview of the CISSP exam format, question strategies, and time management
  • Mock exams and domain-specific quizzes
  • Gap analysis and development of personalized study plans
  • Suggested resources, professional communities, and continuous learning pathways

Summary and Future Steps

Requirements

  • A minimum of five years of cumulative, paid professional experience in at least two of the (ISC)² CISSP domains, or equivalent experience
  • Basic understanding of information security concepts, networking, and software systems
  • Knowledge of risk management, cryptography, and IT operations

Target Audience

  • Information security professionals preparing for the CISSP exam
  • Security architects, managers, and consultants
  • IT leaders, auditors, and governance specialists
 35 Hours

Number of participants


Price per participant

Testimonials (7)

Upcoming Courses

Related Categories