Risk Management, Threat Modeling, Supply Chain, Security Awareness

Опубликовано: 22 Март 2026
на канале: bdubzz
226
11

Ready to ace the CISSP exam? Join our study group and get the ultimate guide to the Certified Information Systems Security Professional (CISSP) certification!

Session 5 completes Domain 1: Security and Risk Management. We will cover the following exam objectives:
1.9 Understand and apply risk management concepts
1.10 Understand and apply threat modeling concepts and methodologies
1.11 Apply Supply Chain Risk Management (SCRM) concepts
1.12 Establish and maintain a security awareness, education, and training program

Access slides, practice questions, and more: https://cissp.brittwhite.io

A huge thank you to Rotas Security for supporting this study group. Check them out at https://rotassecurity.com/ for your offensive security needs.

CISSP Resource Links:
Exam Outline: https://www.isc2.org/certifications/c...
Security and Risk Management (Summary): https://destcert.com/resources/domain...

Chapters:
00:00:00 Study Group Intro
00:00:51 Today's Objectives
00:02:18 Objective 1.9: Risk Management
00:03:50 Value, Risk, Treatment
00:05:08 Asset Valuation
00:06:37 Risk Analysis
00:09:47 Key Risk Management Terms
00:11:43 Annualized Loss Expectancy (ALE)
00:14:19 Risk Response & Treatment
00:17:18 Types of Controls
00:20:35 Categories of Controls
00:22:34 Safeguards & Countermeasures
00:23:17 Control Selection & Implementation
00:26:13 Measuring Control Effectiveness (PDCA Cycle)
00:28:23 Risk Management Frameworks
00:32:08 Risk Management Summary
00:32:44 Objective 1.10: Threat Modeling
00:34:35 STRIDE Methodology
00:37:05 PASTA Methodology
00:40:14 DREAD Methodology
00:42:32 Social Engineering
00:44:56 Common Social Engineering Attacks
00:47:33 Mitigating Social Engineering Attacks
00:48:54 Threat Modeling Summary
00:49:38 Objective 1.11: Supply Chain Risk Management (SCRM)
00:51:37 SCRM Key Activities
00:53:57 Major Supply Chain Risks
00:55:07 Supply Chain Risk Mitigations
00:56:59 SLR, SLA, & Reports
00:58:50 SCRM Review
00:59:49 Objective 1.12: Security Awareness
01:01:13 Awareness, Training, Education
01:03:24 Effective Training Methods
01:05:05 Prioritizing Training Topics
01:07:28 Evaluating Training Effectiveness
01:08:30 Key Security Training Metrics
01:10:03 Security Awareness Summary
01:13:08 Session Conclusion