Ready to ace the CISSP exam? Join our study group and get the ultimate guide to the Certified Information Systems Security Professional (CISSP) certification!
Session 3 continues with Domain 1: Security and Risk Management. We will cover the following exam objectives:
1.5 Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
1.6 Develop, document, and implement security policy, standards, procedures, and guidelines
Access slides, practice questions, and more: https://cissp.brittwhite.io
A huge thank you to Rotas Security for supporting this study group. Check them out at https://rotassecurity.com/ for your offensive security needs.
CISSP Resource Links:
Exam Outline: https://www.isc2.org/certifications/c...
Security and Risk Management (Summary): https://destcert.com/resources/domain...
Chapters:
00:00 Welcome and Introduction
01:24 Objective 1.5: Investigation Types
02:16 Criminal Investigations
04:37 Civil Investigations
07:34 Regulatory Investigations
09:22 Administrative Investigations
11:36 Industry Standards Investigations
14:15 Objective 1.6: Security Policy & Documentation
15:40 Documentation Hierarchy
17:13 Deep Dive on Policies
19:53 Understanding Standards
21:21 Procedures Explained
23:11 Baselines & Security Floors
25:26 Guidelines & Recommendations
27:34 Documentation Implementation
29:13 Anti-Malware Policy Example
30:35 Benefits of Documentation
31:13 Pitfalls to Avoid
31:56 Review & Key Points
33:10 Session Recap
35:01 After-Party & Next Session