Course Outline
Security and Risk Management
- Core principles of confidentiality, integrity, and availability (CIA)
- Security governance, policy development, and frameworks (ISO 27001, NIST CSF)
- Processes for risk analysis, assessment, and mitigation
- Business impact analysis, security awareness programmes, and training initiatives
- Legal, regulatory, compliance, and privacy considerations (GDPR, HIPAA, and local legislation)
Asset Security
- Information classification, ownership models, and protection strategies
- Data handling protocols (retention, deletion, backup, and transfer)
- Privacy safeguards and data lifecycle management
- Responsible asset usage and media control mechanisms
Security Engineering
- Principles for secure system and architectural design
- Cryptography: symmetric and asymmetric encryption, hashing, PKI, and key management
- Physical security considerations and hardware security modules (HSMs)
- Secure virtualisation, cloud-native security patterns, and secure API integration
Communications and Network Security
- Network models, protocols, and secure communication standards (TLS, VPN, IPSec)
- Perimeter defences, network segmentation, firewalls, and IDS/IPS
- Wireless security, remote access controls, and zero-trust network architectures
- Designing secure network architectures for cloud and hybrid environments
Identity and Access Management (IAM)
- Access control mechanisms: identification, authentication, authorisation, and accountability
- Identity providers, federation, SSO, and access federation in cloud environments
- Privileged access management (PAM) and role-based access control (RBAC)
- Identity lifecycle management: provisioning, deprovisioning, and entitlement reviews
Security Assessment and Testing
- Security control testing methods: SAST, DAST, penetration testing, and vulnerability scanning
- Audit strategies and review frameworks
- Log management, monitoring, and continuous assessment practices
- Red teaming, blue teaming, and adversary simulation techniques
Security Operations
- Incident response planning, handling procedures, and digital forensics
- Security operations centre (SOC) design, monitoring, and threat intelligence integration
- Patching, vulnerability management, and configuration governance
- Business continuity, disaster recovery, and organisational resilience planning
Software Development Security
- Secure software development lifecycle (SDLC) and DevSecOps practices
- Common vulnerabilities (extending beyond OWASP Top 10) and mitigation patterns
- Code review, static/dynamic analysis, and secure development frameworks
- Supply chain risks, dependency management, and runtime protection
Exam Strategy, Practice and Wrap-Up
- CISSP exam structure, question answering strategies, and time management techniques
- Mock exams and domain-specific knowledge checks
- Gap analysis and formulation of personal study plans
- Recommended resources, professional communities, and continuous learning pathways
Summary and Next Steps
Requirements
- A minimum of five years of cumulative, paid professional experience in at least two of the (ISC)² CISSP domains, or equivalent industry experience
- Solid foundational understanding of information security principles, network infrastructure, and software systems
- Familiarity with risk management frameworks, cryptography, and IT operational processes
Intended Audience
- Information security professionals preparing for the CISSP certification examination
- Security architects, managers, and consultants
- IT leadership, auditors, and governance specialists
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6500 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (7)
Being approachable and pushing us into interaction
Daniel - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
the topic was interesting itself and we had opportunity to discuss it with different perspectives.
Marcin - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
trainer competence
Evghenii - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Ion Temciuc - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
Good material organization and understandable instructor's English.
Hanny - Arctic Stream
Course - CISSP - Certified Information Systems Security Professional
His knowledge, the way he explains and his kindness
Marcelo Martinez - EY GLOBAL SERVICES (POLAND) SP Z O O
Course - CISSP - Certified Information Systems Security Professional
I liked mix of theory and practical case example. Very good overview of each topic then going through slides.