ISC CISSP Exam Overview:
| Certification Vendor: | ISC2 |
| Exam Name: | Certified Information Systems Security Professional (CISSP) |
| Exam Number: | CISSP |
| Related Certifications: | ISC2 Certified in Cybersecurity (CC) ISC2 Certified Cloud Security Professional (CCSP) ISC2 Systems Security Certified Practitioner (SSCP) |
| Exam Price: | USD $749 |
| Certificate Validity Period: | 3 years |
| Exam Duration: | 180 minutes |
| Passing Score: | 700 out of 1000 |
| Real Exam Qty: | 100-150 |
| Exam Format: | Computerized Adaptive Testing (CAT), Advanced Innovative Questions, Multiple Choice |
| Available Languages: | Japanese, Chinese, Spanish, English, German |
| Sample Questions: | ISC CISSP Sample Questions |
| Exam Way: | Pearson VUE testing centers with Computerized Adaptive Testing (CAT) |
| Pre Condition: | Minimum 5 years cumulative paid work experience in two or more CISSP domains. A relevant four-year degree or approved credential may substitute for one year of experience. |
| Official Syllabus URL: | https://www.isc2.org/certifications/cissp/cissp-certification-exam-outline |
How to earn ACSA credential?
The candidate must earn 40 continuing education units (CEUs) for the ACSA credential. The CEUs may be earned through participation in the ISSA-certified training course, obtaining CEUs from any other Information Systems Security Association (ISSA) member, obtaining certification credits for passing the exam, or through participating in many other online sites.
The Associate level requires passing one exam to achieve. The ACSA credential is defined as conforming to the requirements of NCEES, the American Society for Testing and Materials (ASTM), and the International Information Systems Security Certification Consortium (ISC). Passing this exam does not qualify a candidate for any CISSP certification nor does it make an individual eligible for any other ISC credential. The Associate level of certification requires passing one exam to achieve. The ACSA credential is defined as conforming to the requirements of NCEES, the American Society for Testing and Materials (ASTM), and the International Information Systems Security Certification Consortium (ISC). The test will not earn a CISSP valid certification.
Career Benefits
When you're CISSP certified, there are a lot of benefits you will receive. By creating new opportunities to excel in your security profession, your career will improve visibility, credibility, and job security. With your deep base of experience in cybersecurity and cloud computing, you can be a high-demand employee. Furthermore, you’ll become an (ISC)2 member and part of the worldwide technical community with many membership benefits once you obtain your CISSP. Besides, you can connect with the global community of cybersecurity leaders. Moreover, the average licensed CISSP salary in the USA is USD 135,510 as rendered by the vendor.
For more info visit:
ISC CISSP Exam Reference
Reference: https://www.isc2.org/cissp/default.aspx
ISC CISSP Exam Syllabus Topics:
| Section | Weight | Objectives |
| Software Development Security | 11% | - Understand software development lifecycle security
- 1. DevSecOps
- 2. Secure SDLC
- Identify and mitigate vulnerabilities
- 1. Static and dynamic testing
- 2. Code review
- Assess software security effectiveness
- 1. Application testing
- 2. Security metrics
|
| Identity and Access Management | 13% | - Control physical and logical access
- 1. Access provisioning
- 2. Identity lifecycle
- Manage identification and authentication
- 1. Federated identity
- 2. MFA
- Integrate identity as a service
|
| Security and Risk Management | 15% | - Understand requirements for investigation types
- 1. Administrative investigations
- 2. Criminal investigations
- Apply supply chain risk management concepts
- 1. Third-party governance
- 2. Vendor assessments
- Understand legal and regulatory issues
- 1. Cyber crimes and data breaches
- 2. Licensing and intellectual property
- Understand and apply security concepts
- 1. Security governance principles
- 2. Confidentiality, integrity and availability
- 3. Due care and due diligence
- Understand and apply threat modeling concepts
- 1. Attack surfaces
- 2. Threat actors
- Determine compliance requirements
- 1. Privacy requirements
- 2. Legal and regulatory requirements
- Develop and manage security policies
- 1. Policy lifecycle
- 2. Standards and guidelines
- Identify and analyze threats and vulnerabilities
- 1. Threat modeling
- 2. Risk analysis methodologies
- Evaluate and apply security governance principles
- 1. Organizational processes
- 2. Roles and responsibilities
- 3. Security policies and procedures
- Establish and manage security awareness training
- 1. Training effectiveness
- 2. Awareness programs
- Apply risk management concepts
- 1. Risk treatment
- 2. Risk assessment
- 3. Risk monitoring
|
| Security Operations | 13% | - Implement incident management
- 1. Recovery procedures
- 2. Incident response
- Understand and support investigations
- 1. Evidence handling
- 2. Digital forensics
- Conduct logging and monitoring activities
- 1. SIEM
- 2. Continuous monitoring
- Operate and maintain preventive measures
- 1. Backup operations
- 2. Patch management
- Implement disaster recovery processes
- 1. Recovery testing
- 2. Business continuity
|
| Asset Security | 10% | - Manage data lifecycle
- 1. Data sharing
- 2. Data storage
- Identify and classify information and assets
- 1. Data classification
- 2. Asset ownership
- Establish information handling requirements
- 1. Data retention
- 2. Secure disposal
- Provision resources securely
- 1. Media handling
- 2. Asset lifecycle management
|
| Communication and Network Security | 13% | - Implement secure design principles in networks
- 1. Network architecture
- 2. Segmentation
- Implement secure communication channels
- 1. VPN
- 2. Secure protocols
- Secure network components
- 1. Firewalls
- 2. Routers and switches
|
| Security Architecture and Engineering | 13% | - Apply cryptography
- 1. Encryption methods
- 2. PKI
- Assess vulnerabilities of architectures
- 1. Cloud-based systems
- 2. Embedded systems
- Research and implement security models
- 1. Security frameworks
- 2. Trusted computing base
- Select controls based on security requirements
- 1. Detective controls
- 2. Preventive controls
- Understand security capabilities of systems
- 1. Virtualization
- 2. Hardware security
|
| Security Assessment and Testing | 12% | - Collect and analyze test outputs
- 1. Reporting
- 2. Log reviews
- Conduct security control testing
- 1. Penetration testing
- 2. Vulnerability assessments
- Design and validate assessment strategies
- 1. Audit strategies
- 2. Security testing
|
Frequently Asked Questions
1. What kinds of study material ITBraindumps provides?
Test engine: study test engine can be downloaded and run on your own devices. Practice the test on the interactive & simulated environment.
PDF (duplicate of the test engine): the contents are the same as the test engine, support printing.
2. How long can I get the products after purchase?
You will receive an email attached with the CISSP study material within 5-10 minutes, and then you can instantly download it for study. If you do not get the study material after purchase, please contact us with email immediately.
3. Can I get the updated products and how to get?
Yes, you will enjoy one year free update after purchase. If there is any update, our system will automatically send the updated study material to your payment email.
4. What's the applicable operating system of the test engine?
Online test engine can supports Windows / Mac / Android / iOS, etc., because it is the software based on WEB browser. You can use it on any electronic device and practice with self-paced.
Online test engine supports offline practice, while the precondition is that you should run it with the internet at the first time.
PC test engine is suitable for windows operating system, running on the Java environment, and can install on multiple computers.
PDF version: can be read under the Adobe reader, or many other free readers, including OpenOffice, Foxit Reader and Google Docs
5. How does your testing engine works?
Once download and installed on your PC, you can practice test questions, review your CISSP questions & answers using two different options 'practice exam' and 'virtual exam'.
Virtual Exam - test yourself with CISSP exam questions with a time limit.
Practice exam - review CISSP exam questions one by one, see correct answers.
6. How often do you release your products updates?
All the products are updated frequently but not on a fixed date. Our professional team pays a great attention to the exam updates and they always upgrade the content accordingly.
7. Do you have any discounts?
We offer some discounts to our customers. There is no limit to some special discount. You can check regularly of our site to get the coupons.