Brainmatics

Certified Information Systems Security Professional (CISSP) Exam Preparation

Certified Information Systems Security Professional (CISSP) merupakan sertifikasi global di bidang IT Security yang dikelola oleh International Information System Security Certification Consortium (ISC)².

Pada training ini, peserta akan mempelajari konsep dan best practices dari keamanan informasi secara komprehensif, yang mencakup 8 domain dari CISSP Common Body of Knowledge (CBK) . Delapan domain tersebut adalah Security and Risk Management, Asset Security, Security Engineering, Communications and Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, dan Software Development Security.

Setelah mengikuti training ini, peserta diharapkan memahami konsep dan best practices dari standar keamanan informasi yang mencakup 8 domain dari CISSP, peserta juga diharapkan siap untuk mengikuti ujian CISSP.
 
SKILL REQUIREMENTS

  1. Mengerti dan memahami knowledge tentang information security.

TARGET AUDIENCE

  1. Security Consultant
  2. Security Manager
  3. IT Director/Manager
  4. Security Auditor
  5. Security Analyst
  6. Security Systems Engineer
  7. Security Consultant
  8. Network Architect

 

CONTENT

1. Security and Risk Management (Security, Risk, Compliance, Law, Regulations, and Business Continuity)

    1.1. Confidentiality, integrity, and availability concepts
    1.2. Security governance principles
    1.3. Compliance
    1.4. Legal and regulatory issues
    1.5. Professional ethic
    1.6. Security policies, standards, procedures and guidelines

2. Asset Security (Protecting Security of Assets)

    2.1. Information and asset classification
    2.2. Ownership (e.g. data owners, system owners)
    2.3. Protect privacy
    2.4. Appropriate retention
    2.5. Data security controls
    2.6. Handling requirements (e.g. markings, labels, storage)

3. Security Engineering (Engineering and Management of Security)

    3.1. Engineering processes using secure design principles
    3.2. Security models fundamental concepts
    3.3. Security evaluation models
    3.4. Security capabilities of information systems
    3.5. Security architectures, designs, and solution elements vulnerabilities
    3.6. Web-based systems vulnerabilities
    3.7. Mobile systems vulnerabilities
    3.8. Embedded devices and cyber-physical systems vulnerabilities
    3.9. Cryptography
    3.10. Site and facility design secure principles
    3.11. Physical security

4. Communication and Network Security (Designing and Protecting Network Security)

    4.1. Secure network architecture design (e.g. IP & non-IP protocols, segmentation)
    4.2. Secure network components
    4.3. Secure communication channels
    4.4. Network attacks

5. Identity and Access Management (Controlling Access and Managing Identity)

    5.1. Physical and logical assets control
    5.2. Identification and authentication of people and devices
    5.3. Identity as a service (e.g. cloud identity)
    5.4. Third-party identity services (e.g. on-premise)
    5.5. Access control attacks
    5.6. Identity and access provisioning lifecycle (e.g. provisioning review)

6. Security Assessment and Testing (Designing, Performing, and Analyzing Security Testing)

    6.1. Assessment and test strategies
    6.2. Security process data (e.g. management and operational controls)
    6.3. Security control testing
    6.4. Test outputs (e.g. automated, manual)
    6.5. Security architectures vulnerabilities

7. Security Operations (Foundational Concepts, Investigations, Incident Management, and Disaster Recovery)

    7.1. Investigations support and requirements
    7.2. Logging and monitoring activities
    7.3. Provisioning of resources `
    7.4. Foundational security operations concepts
    7.5. Resource protection techniques
    7.6. Incident management
    7.7. Preventative measures
    7.8. Patch and vulnerability management
    7.9. Change management processes
    7.10. Recovery strategies
    7.11. Disaster recovery processes and plans
    7.12. Business continuity planning and exercises
    7.13. Physical security
    7.14. Personnel safety concerns

8. Software Development Security (Understanding, Applying, and Enforcing Software Security)

    8.1. Security in the software development lifecycle
    8.2. Development environment security controls
    8.3. Software security effectiveness
    8.4. Acquired software security impact

 

INSTRUCTOR

Irfan Akbar. Menyelesaikan S1 Jurusan Akuntansi di Universitas Padjajaran pada tahun 2003. Merupakan professional trainer yang sudah berpengalaman sejak tahun 2008 untuk training CISA Exam Preparation, CISSP Exam Preparation, CISM Exam Preparation, IT Service Management (ITIL v3), IT Risk Management, IT Strategic Plan (IT Blueprint), IT Enterprise Architecture using TOGAF, IT Business Analysis, COBIT 5 & COBIT 4.1, dan IT Auditing pada lembaga training yang ada di Jakarta dan Bandung. Telah tersertifikasi CISA, CISSP, CISM, CEHv7 dan ITIL v3 Foundation.