Choose four of the CISSP domains to explore with independent research and discuss in more depth.

profilevelikocak
Lesson6withaudio1.pptx

Lesson 6

Chapter e16 Local Area Network Security

Chapter 34 Risk Management

Chapter e76 System Security

Chapter e79 Assessments and Audits

Chapter 77 Access Controls

z

Lesson 6 CISSP Domains, Weeks 7-8

The Certified Information Systems Security Professional (CISSP) is a valuable certification in the field of cybersecurity. “CISSP training is considered the gold standard for cyber security experts internationally. Despite thousands of jobs for CISSP certified individuals; there are only a few people who have this qualification.” (Warne, 2017) The CISSP domains changed a bit in early 2018, so you will find differences between the list of domains in two chapters of the book and the most updated version of 8 domains.

Read:

Chapter e16 Local Area Network Security

Chapter 34 Risk Management

Chapter e76 System Security

Chapter e79 Assessments and Audits

Chapter 77 Access Controls

z

Domains

Chapter 2 lists 10 domains:

Access control

Application security

Business continuity and disaster recovery planning

Cryptography

Information security and risk management

Legal regulations, compliance, and investigations

Operations security

Physical (environmental) security

Security architecture and design

Telecommunications and network security

Chapter 24 lists 8 domains (2018 list):

Security and risk management

Asset security

Security engineering

Communications and network security

Identity and asset management

Security assessment and testing

Security operations

Software development security

z

Chapter e16 Local Area Network Security

Most networks connect to the Internet

This chapter discusses how and where to implement effective controls in a LAN

Security pitfalls are identified

Guidelines for reducing security exposures were covered

z

Chapter 34 Risk Management

Risk Management should guide the design of our systems

Risk management analyzes and assesses factors that affect risk, treats the risks and continuously monitor the situations

z

Chapter e76 System Security

The objective is to improve protection of information system resources

The protection of a system must be documented in a systems security plan

The purpose is to provide an overview of the security requirements of the system and describe the controls in place or planned for meeting those requirements

z

Chapter e79 Assessments and Audits

This is the process of determining how effectively an entity being assessed meets specific security objectives

Three types of assessment and audit methods can be used : testing, examination, and interviewing

Testing is the process of exercising one or more assessment and audit objects under specified conditions to compare actual and expected behaviors

Examination is the process of checking, inspecting, reviewing, observing, studying, or analyzing one or more assessment and audit objects to facilitate understanding, achieve clarification, or obtain evidence.

Interviewing is the process of conducting discussions with individuals or groups within an organization to facilitate understanding, achieve clarification, or identify the location of evidence.

z

Chapter 77 Access Controls

Extensions of covered access control mechanisms and combinations are possible

Common access control policies are covered here

z

Midterm Paper

Choose four of the CISSP domains to explore with independent research and discuss in more depth. See page 21 for a list of the domains. You are free to choose from the new 2018 list of domains rather than the previous list in our book, but since our goal is not to study for the CISSP exam, the domains in the book are fine.

The paper should include a cover page, at least two references, citations in APA format, and a list of references. No abstract is required. The paper should be 5-7 pages in length, not including tables and figures.

z