Course Outline
Security and Risk Management
- Core principles of confidentiality, integrity, and availability (CIA)
- Security governance, policies, and standards (ISO 27001, NIST CSF)
- Evaluating, measuring, and reducing risk
- Business impact analysis, security awareness, and staff training
- Legal frameworks, regulations, compliance, and privacy concerns (GDPR, HIPAA, local statutes)
Asset Security
- Information categorization, ownership, and safeguards
- Managing data (retention, deletion, backup, and transfer)
- Protecting privacy and overseeing the data lifecycle
- Securing asset usage and controlling media
Security Engineering
- Principles for secure system and architecture design
- Cryptographic methods: symmetric, asymmetric, hashing, PKI, and key management
- Physical security aspects and hardware security modules (HSMs)
- Secure virtualization, cloud-native security patterns, and safe API usage
Communications and Network Security
- Network models, protocols, and secure communication channels (TLS, VPN, IPSec)
- Perimeter protections, network segmentation, firewalls, and IDS/IPS
- Wireless security, remote access, and zero-trust network designs
- Designing secure network architectures for cloud and hybrid setups
Identity and Access Management (IAM)
- Access control mechanisms: identification, authentication, authorization, and accountability
- Identity providers, federation, SSO, and cloud-based access federation
- Privileged access management (PAM) and role-based access control (RBAC)
- Managing the identity lifecycle: provisioning, deprovisioning, and entitlement audits
Security Assessment and Testing
- Testing security controls: SAST, DAST, penetration testing, and vulnerability scans
- Strategies for auditing and review frameworks
- Log oversight, monitoring, and ongoing assessment
- Techniques for red teaming, blue teaming, and simulating adversaries
Security Operations
- Planning, executing, and forensics for incident response
- Designing, monitoring, and integrating threat intelligence into the SOC
- Patch management, vulnerability remediation, and configuration control
- Planning for business continuity, disaster recovery, and organizational resilience
Software Development Security
- Secure software development lifecycle (SDLC) and DevSecOps practices
- Common vulnerabilities (extending beyond the OWASP Top 10) and mitigation strategies
- Code inspection, static/dynamic analysis, and secure frameworks
- Managing supply chain risks, dependencies, and runtime security
Exam Strategy, Practice and Conclusion
- Understanding the CISSP exam structure, question techniques, and time management
- Simulated exams and domain-specific quizzes
- Identifying knowledge gaps and creating personal study plans
- Suggested resources, professional communities, and pathways for continued learning
Overview and Future Steps
Requirements
- A minimum of 5 years of cumulative, paid professional experience in at least two of the (ISC)² CISSP domains, or comparable expertise
- Basic understanding of information security principles, networking, and software systems
- Awareness of risk management, cryptography, and IT operations
Target Audience
- Information security specialists aiming to sit for the CISSP exam
- Security architects, managers, and consultants
- IT executives, auditors, and governance specialists
Testimonials (7)
Being approachable and pushing us into interaction
Daniel - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
the topic was interesting itself and we had opportunity to discuss it with different perspectives.
Marcin - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
trainer competence
Evghenii - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Ion Temciuc - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Hanny - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
His knowledge, the way he explains and his kindness
Marcelo Martinez - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
I liked mix of theory and practical case example. Very good overview of each topic then going through slides.