TopL  TopM  TopR 
MiddleL

Certified Information Systems Security Professional Course (CISSP®) start 1 Jul 2007

Vendor Name: Int. IS Security Certification Consortium (www.ISC2.org)
Version Number:
Date Published: 1-Jul-2007
Date Retired:
Program Description: The CISSP certification has become a pre-requisite for anyone looking to make a career in information security. The CISSP certification provides information security professionals with an objective measure of competence and a globally recognised standard of achievement. The CISSP credential suits mid- and senior-level managers who are working toward or have already attained positions as CISOs, CSOs or Senior Security Engineers.



The CISSP is developed and maintained by (ISC)² - the International Information Systems Security Certification Consortium - which is a not-for-profit organisation that developed the information security common body of knowledge (“CBK”), which is divided into 10 domains (described below) and a certification programme for information systems security professionals. There are pre-qualification requirements (described on this page) in terms of professional experience.

Program Outcomes
1. CISSP Domain 1) Security Management Practices * Types of Security Controls * Security Policies, Standards, Procedures, and Guidelines * Risk Management and Analysis
2. CISSP Domain 2) Access Control Systems * Identification, Authentication, and Authorization Technologies * Discretionary versus Mandatory Access Control Models * Rule-based and Role-based Access Control
3. CISSP Domain 3) Telecommunications and Network Security * TCP\IP Suite * LAN, MAN, and WAN Topologies and Technologies * Firewall Types and Architectures
4. CISSP Domain 4) Cryptography * Block and Stream Ciphers * Explanation and Uses of Symmetric Key Algorithms * Explanation and Uses of Asymmetric Key Algorithms
5. CISSP Domain 5) Security Architecture and Models * Critical Components of Every Computer * Access Control Models * Certification and Accreditation
6. CISSP Domain 6) Operations Security * Operations Department Responsibilities * Personnel and Roles * Media Library and Resource Protection
7. CISSP Domain 7) Application and System Development * Software Development Models * Database Models * Relational Database Components
8. CISSP Domain 8) Business Continuity and Disaster Recovery * Planning * Roles and Responsibilities * Liability and Due Care Issues * Business Impact Analysis
9. CISSP Domain 9) Law, Investigation and Ethics * Privacy Laws and Concerns * Complications of Computer Crime Investigation * Types of Evidence and How to Collect It
10. CISSP Domain 10) Physical Security * Facility Location and Construction Issues * Physical Vulnerabilities and Threats * Fencing, Lighting, and Perimeter Protection

No program document uploaded

Explanatory Notes:
CISSP Professional Experience Requirements

With effect from 1 October 2007, Applicants must have a minimum of five years of direct full-time security professional work experience in two or more of the ten domains of the (ISC)² CISSP CBK, and will have to have their qualifications endorsed by another (ISC)² credential holder.

CISSP professional experience includes:

* Work requiring special education or intellectual attainment, usually including a liberal education or college degree.
* Work requiring habitual memory of a body of knowledge shared with others doing similar work.
* Management of projects and/or other employees.
* Supervision of the work of others while working with a minimum of supervision of one's self.
* Work requiring the exercise of judgment, management decision-making, and discretion.
* Work requiring the exercise of ethical judgment (as opposed to ethical behavior).
* Creative writing and oral communication.
* Teaching, instructing, training and the mentoring of others.
* Research and development.
* The specification and selection of controls and mechanisms (i.e. identification and authentication technology) (does not include the mere operation of these controls).
* Applicable titles such as officer, director, manager, leader, supervisor, analyst, designer, cryptologist, cryptographer, cryptanalyst, architect, engineer, instructor, professor, investigator, consultant, salesman, representative, etc. Title may include programmer. It may include administrator, except where it applies to one who simply operates controls under the authority and supervision of others. Titles with the words "coder" or "operator" are likely excluded.

The applicant must meet the following requirements to qualify to sit for the examination:

* A. Subscribe to the (ISC)² Code of Ethics; and
* B. Have a minimum five years of direct full-time security professional work experience in two or more of the ten domains of the information systems security CBK® as described above.

Waiver of Experience: If certain circumstances apply and with appropriate documentation, candidates are eligible to waive a maximum of two years of professional experience* as follows:

* One year waiver of the professional experience requirement for education.
Candidates can substitute a maximum of one year of direct full-time security professional work experience described above if they have a four-year college degree OR Master’s Degree in information security from a U.S. National Center of Academic Excellence in information Security (CAEIAE) or regional equivalent. If you hold both a four-year degree and a Master’s degree, you may only apply for a one year waiver of experience.

* One-year waiver of the professional experience requirement for holding an additional credential on the (ISC)² approved list.

Valid experience includes information systems (IS) security-related work performed as a practitioner, auditor, consultant, investigator or instructor, that requires IS security knowledge and involves the direct application of that knowledge. The five years of experience must be the equivalent of actual full-time IS security work (not just IS security responsibilities for a five year period); this requirement is cumulative, however, and may have been accrued over a much longer period of time.

Matched Units (with elements listed)

ICAA5056B: Prepare disaster recovery and contingency plans

Download competency document

Unit Elements (and matched outcomes)

1. Evaluate impact of system on business continuity8
2. Evaluate threats to system8
3. Formulate prevention and recovery strategy8
4. Develop disaster recovery plan to support strategy8

ICAI4249A: Implement and evaluate data security

Download competency document

Unit Elements (and matched outcomes)

1. Implement data security2, 5, 6, 7
2. Evaluate data security2, 5, 6, 7

ICAI4251A: Implement and evaluate network and telecommunication security

Download competency document

Unit Elements (and matched outcomes)

1. Implement network and telecommunication security3
2. Assess vulnerabilities and respond3
3. Evaluate network and telecommunication security3

ICAI5196B: Implement secure encryption technologies

Download competency document

Unit Elements (and matched outcomes)

1. Determine encryption methods4
2. Implement encryption 4
3. Monitor encryption4

ICAI5250A: Develop, implement and evaluate system and application security

Download competency document

Unit Elements (and matched outcomes)

1. Develop system and application security7
2. Implement system and application security7
3. Evaluate system and application security7

ICAI5252A: Develop, implement and evaluate an incident response plan

Download competency document

Unit Elements (and matched outcomes)

1. Develop the incident response program8
2. Implement the incident response program8
3. Evaluate the incident response program8

ICAI5253A: Implement and evaluate systems for regulatory and standards compliance

Download competency document

Unit Elements (and matched outcomes)

1. Implement compliance systems1
2. Evaluate the compliance systems1

ICAS4124B: Monitor and administer network security

Download competency document

Unit Elements (and matched outcomes)

1. Ensure user accounts are controlled2
2. Secure file and resource access2, 5, 7
3. Monitor threats to the system1, 2

ICAS5118C: Manage system security

Download competency document

Unit Elements (and matched outcomes)

1. Identify threats to system6
2. Determine risk category1, 6
3. Identify appropriate controls 6
4. Include controls in the system6
5. Monitor system tools and procedures6

ICAS5123C: Manage network security

Download competency document

Unit Elements (and matched outcomes)

1. Identify threats to network3
2. Determine risk of network failure3
3. Plan suitable control methods for the network 3
4. Incorporate controls into the network2, 3
5. Implement additional security facilities3

ICAW4214A: Maintain ethical conduct

Download competency document

Unit Elements (and matched outcomes)

1. Protect the interests of clients8, 9
2. Produce quality products and services9
3. Ensure correct representation9
4. Produce code of ethics9
5. Maintain good work practices8, 9

PRSIR12A: Review security risk management plan

Download competency document

Unit Elements (and matched outcomes)

1. Establish review procedures1, 6, 9, 10
2. Test existing measures10
3. Evaluate results10
4. Implement corrective measures9, 10

View Printable report

Return to program list

Key
Match between program outcome (left) and element (right)
Multiple mappings exist for this element or program outcome
Element (right) does not match any program outcomes (left), but does match other programs
No mapping for this program outcome or element
MiddleR
BottomL BottomM BottomR