Course Outline
Security and Risk Management
- Core principles of confidentiality, integrity, and availability (CIA)
- Security governance structures, policy development, and framework alignment (ISO 27001, NIST CSF)
- Comprehensive risk analysis, assessment methodologies, and mitigation strategies
- Business impact analysis (BIA), security awareness programs, and workforce training
- Regulatory compliance, legal obligations, and privacy requirements (GDPR, HIPAA, applicable statutes)
Asset Security
- Information asset classification, stewardship, and protection mechanisms
- Data lifecycle operations: retention, destruction, backup, and transfer protocols
- Privacy safeguards and end-to-end data lifecycle management
- Secure asset utilization and media control standards
Security Engineering
- Principles for designing secure systems and architectures
- Cryptographic implementations: symmetric and asymmetric encryption, hashing, PKI, and key management
- Physical security measures and hardware security modules (HSMs)
- Secure virtualization, cloud-native security patterns, and secure API integration
Communications and Network Security
- Network models, protocol security, and secure communication channels (TLS, VPN, IPSec)
- Perimeter defense strategies, network segmentation, firewalls, and intrusion detection/prevention systems (IDS/IPS)
- Wireless security, remote access controls, and zero-trust network architecture
- Secure network design for cloud and hybrid infrastructure environments
Identity and Access Management (IAM)
- Access control mechanisms: identification, authentication, authorization, and accountability
- Identity providers, federation protocols, single sign-on (SSO), and cloud-based access federation
- Privileged access management (PAM) and role-based access control (RBAC)
- Identity lifecycle management: provisioning, deprovisioning, and entitlement reviews
Security Assessment and Testing
- Security control validation: SAST, DAST, penetration testing, and vulnerability scanning
- Audit strategies and review frameworks
- Log management, continuous monitoring, and ongoing assessment
- Adversarial simulation techniques, including red teaming and blue teaming
Security Operations
- Incident response planning, handling procedures, and forensic analysis
- SOC design, monitoring capabilities, and threat intelligence integration
- Patching programs, vulnerability management, and configuration control
- Business continuity, disaster recovery, and organizational resilience planning
Software Development Security
- Secure software development lifecycle (SDLC) and DevSecOps integration
- Identification of common vulnerabilities and mitigation patterns beyond OWASP Top 10
- Code review processes, static/dynamic analysis tools, and secure framework adoption
- Supply chain risk management, dependency oversight, and runtime protection measures
Exam Strategy, Practice and Wrap-Up
- CISSP examination structure, question analysis techniques, and time management strategies for government candidates
- Practice examinations and domain-specific assessments
- Skill gap analysis and personalized study plans
- Recommended educational resources, professional communities, and continuous learning pathways
Summary and Next Steps
Requirements
- Minimum of five years of cumulative, compensated professional experience spanning two or more (ISC)² CISSP domains, or equivalent demonstrated expertise
- Foundational understanding of information security principles, network infrastructures, and software architectures
- Competency in risk management frameworks, cryptographic methods, and IT operational procedures
Target Audience
- Information security practitioners preparing for the CISSP certification examination
- Security architects, managers, and external consultants
- IT executives, auditors, and governance specialists focused on for government standards and compliance
Testimonials (7)
Being approachable and pushing us into interaction
Daniel - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
the topic was interesting itself and we had opportunity to discuss it with different perspectives.
Marcin - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
trainer competence
Evghenii - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Ion Temciuc - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Hanny - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
His knowledge, the way he explains and his kindness
Marcelo Martinez - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
I liked mix of theory and practical case example. Very good overview of each topic then going through slides.