| Certified
Information Systems Security Professional
(CISSP)
Common Body of Knowledge (CBK) Review
The Ten CBK Domains
and Their Subsections
- Security Management Practices
- Concepts & Objectives
- Risk Management
- Policies and Procedures
- Information Classification
- Information Security Roles and Responsibilities
- Information Security Awareness
- Handling Incidents
- Access Control Systems & Methodology
- Concepts
- Issues
- Identification & Authentication
- Single Sign On
- Centralized Access Control Methodologies
- Decentralized/Distributed Access Control
Methodologies
- Access Control Technologies
- Access Control Monitoring
- Law, Investigations, Ethics
- Laws and Regulations
- Conducting Investigations
- Information Ethics
TOP
- Physical Security
- Facilities Management
- Personnel Security
- Physical Controls
- Business Continuity & Disaster
Recovery Planning
- Business Continuity Concepts
- Disaster Recovery Concepts
- Recovery Planning Process
- Program Management
- Vulnerability Assessment
- Plan Development & Maintenance
- Plan Testing
- Prevention
- Security Architecture & Models
- Computer Science and Architecture
- Security and Control Concepts
- Security Models
- Evaluation Criteria
- Host Based Security
- Client Server Security
- Network Architecture
- Network Security
- IP Security Architecture
TOP
- Cryptography
- History
- Definitions
- Applications & Uses of Cryptography
- Protocols and Standards
- Basic Technologies
- Encryptions Systems
- Symmetric / Asymmetric Cryptography
- Digital Signatures
- E-mail Security Using Encryption
- Internet Security Using Encryption
- Key Management
- Public Key Infrastructure (PKI)
- Cryptanalysis & Attacks
- Export Issues
- Telecommunications & Network
Security
- Communications Security Management
- Network Protocols
- Identification & Authentication
- Data Communications
- Internet & Web Security
- Attack Methods
- Multimedia Security
- Incident Response Management
TOP
- Applications & Systems Development
- Definitions
- Security Goals & Threats
- System Life Cycle
- Security Architecture
- Change Control
- Application Development & Security
Measures
- Databases and Data Warehousing
- Knowledge Based Systems
- Operations Security
- Resources
- Privileges
- Control Mechanisms
- Potential Abuses
- Appropriate Controls
- Principles
TOP
|