CISSP Course Introduction - USALearning

Transcription

CISSP Course IntroductionTable of ContentsDoD IA Workforce Management 8570.1 Certification Series CISSP Prep. 2Notices . 3Overview . 4Course Intent . 5CISSP Scope . 6CISSP Requirements . 7About the CISSP Exam . 8The Candidate Information Bulletin (CIB) . 9Page 1 of 10

DoD IA Workforce Management 8570.1 Certification Series CISSP PrepDoD IA Workforce Management8570.1 Certification SeriesCISSP Prep 2015 Carnegie Mellon University**001 Instructor: This is theCISSP preparation course, part of theDoD 8570 certification series.Page 2 of 10

NoticesNotices 2015 Carnegie Mellon UniversityThis material is distributed by the SEI only to course attendees for their own individual study.Except for the U.S. government purposes described below, this material SHALL NOT bereproduced or used in any other manner without requesting formal permission from the SoftwareEngineering Institute at permission@sei.cmu.edu.This material was created in the performance of Federal Government Contract NumberFA8721-05-C-0003 with Carnegie Mellon University for the operation of the Software EngineeringInstitute, a federally funded research and development center. The U.S. Government's rights to use,modify, reproduce, release, perform, display, or disclose this material are restricted by the Rights inTechnical Data-Noncommercial Items clauses (DFAR 252-227.7013 and DFAR 252-227.7013Alternate I) contained in the above identified contract. Any reproduction of this material or portionsthereof marked with this legend must also reproduce the disclaimers contained on this slide.Although the rights granted by contract do not require course attendance to use this material forU.S. Government purposes, the SEI recommends attendance to ensure proper understanding.THE MATERIAL IS PROVIDED ON AN “AS IS” BASIS, AND CARNEGIE MELLON DISCLAIMSANY AND ALL WARRANTIES, IMPLIED OR OTHERWISE (INCLUDING, BUT NOT LIMITED TO,WARRANTY OF FITNESS FOR A PARTICULAR PURPOSE, RESULTS OBTAINED FROM USEOF THE MATERIAL, MERCHANTABILITY, AND/OR NON-INFRINGEMENT).2**002 Here are the requisitecopyright notices.Page 3 of 10

OverviewOverviewCourse IntentWhat is a CISSP?About the ExamCandidate Information Bulletin3**003 And we'll talk a little bit aboutthe exam and what you can expect tosee on it.Page 4 of 10

Course IntentCourse IntentProvide a review of the CISSP “Common Body of Knowledge”Supplement preparation for the CISSP certification exam Course material is not endorsed by (ISC)2 and is not affiliated in any waywith (ISC)2Common Body of Knowledge (CBK) Domains Security & Risk ManagementAsset SecuritySecurity EngineeringCommunications & Network SecurityIdentity & Access ManagementSecurity Assessment & TestingSecurity OperationsSoftware Development Security4**004 The intent of this course is toprovide a review of the CISSPcommon body of knowledge, CBK.It's meant to supplement what youare already doing to prepare for theexam. There should be two sourcesof information that you use forreviewing that make sure youaddress any gaps in that. This coursecan be one of them. But go grab abook, some other online job training,whatever the case may be. Go find asecond source as you prepare for theexam to make sure that you'recovered through the eight areas onthe exam. The domains of the examare security and risk management,asset security, security engineering,Page 5 of 10

communications and networksecurity, identity and accessmanagement, security assessmentand testing, security operations. Andthen the last one is softwaredevelopment security.CISSP ScopeCISSP ScopeYou should consider and use other sources in preparation forthe CISSP exam!The knowledge gapother sources can fillScope of the CBKScope of the this review courseScope of the exam5**005 Again, consider using multiplesources of information as youprepare for this. Understand that thescope of the common body ofknowledge is this big. This course isactually going to provide some subsetof that as you're going through andpreparing for this. What that leaves isa gap in between what this coursecovers and what's on the body ofPage 6 of 10

knowledge. And that's why there's arecommendation that you look for asecond source of information asyou're preparing for the exam tomake sure you're covering that gap.CISSP RequirementsCISSP RequirementsGet an endorsement from an (ISC)2 memberPass the examCISSPs should be familiar with the CBK Taxonomy for mutual understandingMust have worked in at least two of the domains for at least 5years (4 years with a college degree)Annual maintenance6**006 The requirements forobtaining your CISSP certification,you have to be endorsed by anexisting CISSP member. You have topass the exam. And you should befamiliar with all of the material on theCBK or within the CBK, those eightdomains that we talked about. Youalso have to have some level of workexperience. Out of the eight domainsyou got to have several years ofPage 7 of 10

experience in at least two of them.And then of course, as with anycertification, you have to pay theannual maintenance fees in order tomaintain your cert.About the CISSP ExamAbout the CISSP Exam6 HoursComputer Based Testing only250 questions – multiple-choice25 questions are “experimental,” and not gradedGiven at the same time as other ISC2 examsMust score 700 out of 1000 to pass7**007 The exam itself is about sixhours, two hundred and fiftyquestions spread out over those eightdomains that we mentioned. Thereare twenty-five questions on that thatwon't be graded. They are testquestions or experimental in nature.ISC2 is just testing out new material.And you've got to get seven hundredout of a thousand in order to passthe exam.Page 8 of 10

The Candidate Information Bulletin (CIB)The Candidate Information Bulletin (CIB)Key areas of knowledge It will NOT help you pass the exam BUT – it can help you focus AND, help you get in the doorReferencesExam Information Test AdmittanceBreaksTesting RequirementsQuestion structureGradingetc.8**008 The candidate informationbulletin, something you should goand download, covers the logisticalinformation about the exam, how toget into the center, whatrequirements you need to have orneed to meet in order to take theexam. And it lists the key areas ofknowledge, but it is not a studyguide. So, it won't actually help youpass the exam. But it will give yousome pointers for where you shouldgo, or what areas you need to study.And then it has a complete list ofreferences in there. So, if there is anarea that you're not familiar with, youcan look at the references and goPage 9 of 10

grab that piece of information andtake a look at it.Page 10 of 10

CISSP Scope 5 CISSP Scope You should consider and use other sources in preparation for the CISSP exam! Scope of the CBK Scope of the this review course Scope of the exam The knowledge gap other sources can fill **005 Again, consider using multiple . sources of information as you . prepare for this. Understand that the . scope of the common body of