0% found this document useful (0 votes)
74 views3 pages

CISSP 4th Edition: Key Security Domains

The document outlines the 8 domains covered by the CISSP certification. Each domain is summarized as focusing on a different area of cybersecurity including security and risk management, asset security, security engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security. Key topics covered within each domain are also briefly listed.

Uploaded by

Andinet
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
74 views3 pages

CISSP 4th Edition: Key Security Domains

The document outlines the 8 domains covered by the CISSP certification. Each domain is summarized as focusing on a different area of cybersecurity including security and risk management, asset security, security engineering, communication and network security, identity and access management, security assessment and testing, security operations, and software development security. Key topics covered within each domain are also briefly listed.

Uploaded by

Andinet
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CISSP Domains(4th Edition)

Domain1:Security and Risk Management (Security, Risk, Compliance,


Law, Regulations, and Business Continuity)

Confidentiality, integrity, and availability concepts


Security governance principles
Compliance
Legal and regulatory issues
Professional ethic
Security policies, standards, procedures and guidelines

Domain2:Asset Security (Protecting Security of Assets)

Information and asset classification


Ownership (e.g. data owners, system owners)
Protect privacy
Appropriate retention
Data security controls
Handling requirements (e.g. markings, labels, storage)

Domain3:Security Engineering (Engineering and Management of


Security)

Engineering processes using secure design principles


Security models fundamental concepts
Security evaluation models
Security capabilities of information systems
Security architectures, designs, and solution elements vulnerabilities
Web-based systems vulnerabilities
Mobile systems vulnerabilities
Embedded devices and cyber-physical systems vulnerabilities
Cryptography
Site and facility design secure principles
Physical security

Domain4:Communication and Network Security (Designing and


Protecting Network Security)

Secure network architecture design (e.g. IP & non-IP protocols, segmentation)


Secure network components
Secure communication channels
Network attacks

Domain5:Identity and Access Management (Controlling Access and


Managing Identity)

Physical and logical assets control


Identification and authentication of people and devices
Identity as a service (e.g. cloud identity)
Third-party identity services (e.g. on-premise)
Access control attacks
Identity and access provisioning lifecycle (e.g. provisioning review)

Domain6:Security Assessment and Testing (Designing, Performing,


and Analyzing Security Testing)

Assessment and test strategies


Security process data (e.g. management and operational controls)
Security control testing
Test outputs (e.g. automated, manual)
Security architectures vulnerabilities

Domain7:Security Operations (Foundational Concepts, Investigations,


Incident Management, and Disaster Recovery)

Investigations support and requirements


Logging and monitoring activities
Provisioning of resources
Foundational security operations concepts
Resource protection techniques
Incident management
Preventative measures
Patch and vulnerability management
Change management processes
Recovery strategies
Disaster recovery processes and plans
Business continuity planning and exercises
Physical security
Personnel safety concerns

Domain8:Software Development Security (Understanding, Applying,


and Enforcing Software Security)

Security in the software development lifecycle


Development environment security controls
Software security effectiveness
Acquired software security impact

You might also like