Course Outline
Security and Risk Management
- Core principles of confidentiality, integrity, and availability (CIA)
- Governance structures, policies, and standards (ISO 27001, NIST CSF)
- Conducting risk analysis, evaluation, and mitigation strategies
- Business impact analysis, security awareness programs, and training initiatives
- Legal frameworks, regulatory compliance, and privacy concerns (GDPR, HIPAA, local statutes)
Asset Security
- Information classification, ownership models, and protection strategies
- Data management practices (retention, disposal, backup, and transfer)
- Safeguarding privacy and managing the data lifecycle
- Secure asset utilization and media control protocols
Security Engineering
- Principles of secure system and architectural design
- Cryptographic methods: symmetric, asymmetric, hashing, PKI, and key management
- Physical security factors and hardware security modules (HSMs)
- Secure virtualization, cloud-native security patterns, and safe API integration
Communications and Network Security
- Network models, protocols, and secure communication standards (TLS, VPN, IPSec)
- Perimeter protection, network segmentation, firewalls, and IDS/IPS
- Wireless security, remote access controls, and zero-trust network architectures
- Designing secure network structures for cloud and hybrid environments
Identity and Access Management (IAM)
- Access control mechanisms: identification, authentication, authorization, and accountability
- Identity providers, federation protocols, SSO, and cloud access federation
- Privileged access management (PAM) and role-based access control (RBAC)
- Identity lifecycle management: provisioning, deprovisioning, and entitlement reviews
Security Assessment and Testing
- Control validation methods: SAST, DAST, penetration testing, and vulnerability scanning
- Audit methodologies and review frameworks
- Log administration, monitoring systems, and continuous assessment
- Red teaming, blue teaming, and adversary simulation tactics
Security Operations
- Incident response planning, management, and forensic analysis
- Security Operations Center (SOC) architecture, monitoring, and threat intelligence integration
- Patching procedures, vulnerability management, and configuration controls
- Business continuity, disaster recovery, and resilience strategies
Software Development Security
- Secure Software Development Lifecycle (SDLC) and DevSecOps methodologies
- Addressing common vulnerabilities (extending beyond OWASP Top 10) and mitigation techniques
- Code inspection, static/dynamic analysis, and secure development frameworks
- Supply chain risks, dependency management, and runtime safeguards
Exam Strategy, Practice and Wrap-Up
- CISSP exam structure, question-answering strategies, and time management
- Mock exams and domain-specific quizzes
- Gap analysis and individualized study planning
- Recommended resources, professional communities, and ongoing learning paths
Summary and Next Steps
Requirements
- Minimum of 5 years of cumulative, paid work experience in at least two (ISC)² CISSP domains, or equivalent professional experience
- Basic understanding of information security principles, network infrastructure, and software systems
- Proficiency in risk management, cryptographic concepts, and IT operational procedures
Target Audience
- Information security specialists preparing for the CISSP examination
- Security architects, managers, and consulting professionals
- IT leadership, auditors, and governance officers
Testimonials (7)
Being approachable and pushing us into interaction
Daniel - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
the topic was interesting itself and we had opportunity to discuss it with different perspectives.
Marcin - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
trainer competence
Evghenii - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Ion Temciuc - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Hanny - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
His knowledge, the way he explains and his kindness
Marcelo Martinez - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
I liked mix of theory and practical case example. Very good overview of each topic then going through slides.