
Security and Risk Management – First CISSP Objective
CISSP has been distributed into eight major network security objectives, which includes:
- Security & Risk Management
- Asset Security
- Security Engineering
- Communication & Network Security
- Identity & Access Management
- Security Assessment & Testing
- Security Operations
- Software Development Security
The 15% of the Exam Questions are taken from the Security & Risk Management domain in the CISSP certification exam. The domain has been divided further into 12 objectives that you should be able to understand.
You should be able to apply and understand the following 12 objectives of the first CISSP domain.
- Confidentiality, Integrity & Availability – The CIA Triad
- Second objective includes Security Governance Principles, Organizational Processes, Security Roles, Security Control Frameworks
- Third objective covers Legislative, Regulatory Compliance of Cyber Security & Privacy
- Fourth objective covers Computer Crimes, Licensing, Intellectual property, import/export controls, internal and external data flows, privacy and data breaches.
- Code of Ethics is covered in fifth objectives.
- Sixth objective enable you to develop, maintain and implement a documented security policy for your organization according to international/national security standards and guidelines.
- Business continuity planning, business impact analysis are covered in the seventh objective.
- Eighth objective explains the Personnel security policies, employment policies, consistent process for terminations, screening controls for job candidates, vendors/contractors and consultants screening etc.
- You will learn about how to identify vulnerabilities & potential threats, how to apply security controls to manage risks, and how to identify potential threats and vulnerabilities by performing risk assessments.
- How to perform threat modeling to asses potential attacks and mitigate risks and defuse those attacks by various methods are covered in objective ten.
- This objective covers how to integrate security risks considerations into your organizations’s best practices and in its strategy and mission.
- Establishing an Information Security Education & Awareness program is part of the final objective in Security & Risk Management.