All certifications / CISSP / Lessons
CISSP 2024 outline lessons
Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Security & risk management
- Professional ethics: ISC2 Code of Ethics canons and organizational ethics
- Security concepts: CIA triad, authenticity, non-repudiation
- Security governance: alignment with business strategy, roles, due care vs due diligence
- Legal and regulatory issues: cybercrime, privacy law, intellectual property, transborder data flow
- Investigation types: administrative, criminal, civil, regulatory
- Policies, standards, procedures, baselines and guidelines
- Business continuity: BIA, RTO/RPO/MTD, BCP scope
- Personnel security: screening, onboarding, transfers, termination, vendor agreements
- Risk management: identification, assessment (qualitative and quantitative), response, frameworks
- Threat modeling methodologies (STRIDE, PASTA) and supply chain risk management
- Security awareness, education and training program effectiveness
Domain 2: Asset security
- Identifying and classifying information and assets
- Information and asset handling requirements (marking, labeling, storage)
- Provisioning resources securely and asset inventory
- Data lifecycle: create, store, use, share, archive, destroy
- Data roles: owner, controller, processor, custodian, steward, subject
- Data collection limitation, location and maintenance
- Data retention and end-of-life (EOL/EOS) assets
- Data remanence and sanitization: clearing, purging, destruction
- Data security controls for data at rest, in transit and in use
- Scoping, tailoring and standards selection; DRM, DLP and CASB
Domain 3: Security architecture & engineering
- Secure design principles: least privilege, defense in depth, secure defaults, fail securely, zero trust, privacy by design, SASE
- Security models: Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash
- Controls based on system security requirements; evaluation criteria (Common Criteria)
- Security capabilities of information systems: TPM, memory protection, HSM
- Vulnerabilities in architectures: client, server, database, cloud, IoT, ICS/OT, virtualization, containers, serverless
- Cryptographic solutions: symmetric, asymmetric, hashing, PKI, key management lifecycle
- Cryptanalytic attacks: brute force, side channel, man-in-the-middle, pass the hash, ransomware
- Secure site and facility design
- Site and facility controls: wiring closets, server rooms, utilities, HVAC, fire suppression, environmental
- Information system lifecycle: stakeholder needs through retirement
Domain 4: Communication & network security
- OSI and TCP/IP models and where controls apply
- IPv4/IPv6, secure protocols (TLS, IPsec, SSH, SNMPv3) and their uses
- Converged protocols: iSCSI, VoIP, InfiniBand, Fibre Channel over Ethernet
- Micro-segmentation, SDN, VXLAN, VPC and software-defined perimeters
- Wireless networks: Wi-Fi security (WPA3), Bluetooth, Zigbee, cellular/5G
- Content distribution networks and traffic flows (north-south, east-west)
- Network components: firewalls, IDS/IPS, NAC, proxies, transmission media, endpoint security
- Secure communication channels: voice, video, remote access, data communications, third-party connectivity
- Network attacks and mitigations: DDoS, spoofing, on-path, DNS attacks
- Monitoring and management: network observability, capacity, logging
Domain 5: Identity & access management
- Controlling physical and logical access to information, systems, devices, facilities and applications
- Identification, authentication and authorization; MFA and passwordless
- Identity management implementation: groups, roles, AAA, session management, registration and proofing
- Federated identity with third parties: SAML, OAuth 2.0, OIDC
- Credential management systems and single sign-on
- Just-in-time access and privileged access management
- Authorization mechanisms: RBAC, rule-based, MAC, DAC, ABAC, risk-based
- Identity and access provisioning lifecycle: account access review, provisioning and deprovisioning
- Authentication systems: Kerberos, RADIUS, TACACS+
- Access control attacks and biometrics: FAR, FRR, CER
Domain 6: Security assessment & testing
- Designing and validating assessment, test and audit strategies (internal, external, third party)
- Vulnerability assessment and penetration testing (rules of engagement, testing knowledge levels)
- Log reviews, synthetic transactions and breach and attack simulation
- Code review and testing: static, dynamic, fuzzing, misuse case, test coverage, interface testing
- Compliance checks
- Collecting security process data: account management, management review, KPIs and KRIs, backup verification, training, DR/BC
- Analyzing test output and generating reports; exception handling and remediation
- Conducting or facilitating security audits: SOC 1/SOC 2/SOC 3, Type I vs Type II
- Location of audits: on premises, cloud, hybrid
Domain 7: Security operations
- Investigations: evidence collection and handling, chain of custody, digital forensics tools and techniques
- Logging and monitoring: SIEM, SOAR, continuous monitoring, UEBA, threat intelligence and hunting
- Configuration management: provisioning, baselining, automation
- Foundational operations concepts: need to know, least privilege, separation of duties, job rotation, SLAs
- Resource protection: media management, backups
- Incident management: detection, response, mitigation, reporting, recovery, remediation, lessons learned
- Detective and preventive measures: firewalls, IDS/IPS, allow and deny lists, sandboxing, honeypots, anti-malware, ML/AI tools
- Patch and vulnerability management; change management
- Recovery strategies: backup types, recovery sites, resilience, high availability
- Disaster recovery processes and DR plan testing (read-through, walkthrough, simulation, parallel, full interruption)
- Business continuity participation, physical security and personnel safety (travel, duress, emergency management)
Domain 8: Software development security
- Security in the SDLC: waterfall, agile, DevOps, DevSecOps, scaled agile
- Maturity models: CMM, SAMM; operations, maintenance and change management
- Integrated product teams and security in the development ecosystem
- Development ecosystem controls: languages, libraries, toolsets, IDE, runtime, CI/CD, SCM, code repositories
- Application security testing: SAST, DAST, SCA, IAST
- Assessing effectiveness of software security: auditing, logging, risk analysis
- Security impact of acquired software: COTS, open source, third party, managed services (SaaS, PaaS, IaaS)
- Secure coding guidelines and standards: source code weaknesses, API security, secure coding practices
- Software-defined security
- Common weaknesses: injection, XSS, CSRF, buffer overflow, race conditions, insecure deserialization