05/06/15Nyhed i CISSP

ISC 2 har i april opdateret det officielle CISSP pensum, så det i højere grad afspejler de betydelige ændringer, der er sket i både de tekniske og ledelsesmæssige aspekter, indenfor informationssikkerhed siden sidste revision i 2012. I den forbindelse har CISSP eksamen også ændret sig, så alle der forbereder sig på at tage eksamen skal være opmærksom på det nye indhold i forhold til at besvare spørgsmålene og bestå eksamen.

Oprindeligt meldte ISC 2 ud, at der kun var planlagt en beskeden ansigtsløftning, dog har det vist sig at der er tale om en større opdatering af pensum hvor op til 30% er nyt indhold, hvilket naturligvis stiller nye krav til viden indenfor informationssikkerhed.

Man skal nok betragte det som et udtryk for hvor hurtigt informationssikkerhedsbranchen udvikler sig, hvorfor det er naturligt at de centrale komponenter i en af de mest anerkendte it sikkerheds certificeringer Certified Information Systems Security Professional (CISSP) også bliver ajourført.

Den store nyhed er, at de ti foregående CBK-domæner er blevet til otte nye CBK-domæner:
Security and Risk Management
Asset Security
Security Engineering
Communications and Network Security
Identity and Access Management
Security Assessment and Testing
Security Operations
Software Development Security

Denne reorganisering af kapitalerne lægger mere vægt på en mere integreret måde at håndtere informationssikkerhed på, bl.a. bliver de gamle domæner Information Security Governance, Business Continuity and Legal Regulations samlet under Security and Risk Management. En andet spændende opdatering er at der nu er et domæne der omhandler risikoanalyse og test under Security Assessment and Testing.

De 8 CISSP domæner:

 Security and Risk Management (Security, Risk, Compliance, Law, Regulations, and Business Continuity)
• Confidentiality, integrity, and availability concepts
• Security governance principles
• Compliance
• Legal and regulatory issues
• Professional ethic
• Security policies, standards, procedures and guidelines

Asset Security (Protecting Security of Assets)
• Information and asset classification
• Ownership (e.g. data owners, system owners)
• Protect privacy
• Appropriate retention
• Data security controls
Handling requirements (e.g. markings, labels, storage)

Security Engineering (Engineering and Management of Security)
• Engineering processes using secure design principles
• Security models fundamental concepts
• Security evaluation models
• Security capabilities of information systems
• Security architectures, designs, and solution elements vulnerabilities
• Web-based systems vulnerabilities
• Mobile systems vulnerabilities
• Embedded devices and cyber-physical systems vulnerabilities
• Cryptography
• Site and facility design secure principles
• Physical security

Communication and Network Security (Designing and Protecting Network Security)
• Secure network architecture design (e.g. IP & non-IP protocols, segmentation)
• Secure network components
• Secure communication channels
• Network attacks

Identity and Access Management (Controlling Access and Managing Identity)
• Physical and logical assets control
• Identification and authentication of people and devices
• Identity as a service (e.g. cloud identity)
• Third-party identity services (e.g. on-premise)
• Access control attacks
• Identity and access provisioning lifecycle (e.g. provisioning review)

Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)
• Assessment and test strategies
• Security process data (e.g. management and operational controls)
• Security control testing
• Test outputs (e.g. automated, manual)
• Security architectures vulnerabilities

Security Operations (Foundational Concepts, Investigations, Incident Management, and Disaster Recovery)
• Investigations support and requirements
• Logging and monitoring activities
• Provisioning of resources
• Foundational security operations concepts
• Resource protection techniques
• Incident management
• Preventative measures
• Patch and vulnerability management
• Change management processes
• Recovery strategies
• Disaster recovery processes and plans
• Business continuity planning and exercises
• Physical security
• Personnel safety concerns

Software Development Security (Understanding, Applying, and Enforcing Software Security)
• Security in the software development lifecycle
• Development environment security controls
• Software security effectiveness
• Acquired software security impact

Ønsker du mere information om CISSP Bootcamp, er du velkommen til at kontakte os på tlf. 70 209 209 eller på info@digicure.dk

 

Nyhedsoversigt