|
|
|
| CISSP Training and Exam |
|
|
|
|
e are the first company in Kenya to host the Certified Information Systems Security Professional (CISSP) exam. We have already signed a contract with the International Informational Systems Security Certification Consortium (ISC)2 to host the exam which is the first time in East and Central Africa. Previously people have had to travel overseas to take the exam. Our trainers are all fully qualified and certified for the courses that they teach, and have an average of 8 years industry experience.
CISSP is the premier IT Security credential in the world. It is highly regarded in industry as the gold standard and highly sought after by IT professionals and IT organizations.
The following topics are at taught for CISSP to cover the It security CISSP common body of knowledge:
1.Information Security & Risk Management - Security management entails the identification of an organization's information assets and the development, documentation, and implementation of policies, standards, procedures, and guidelines. Management tools such as data classification and risk assessment/analysis are used to identify threats, classify assets, and to rate system vulnerabilities so that effective controls can be implemented.
2.Security Architecture and Design - The Security Architecture and Models domain contains the concepts, principles, structures, and standards used to design, monitor, and secure operating systems, equipment, networks, applications and those controls used to enforce various levels of availability, integrity, and confidentiality.
3.Access Control - Access controls are a collection of mechanisms that work together to create a security architecture to protect the assets of the information system.
4.Application Security - This domain addresses the important security concepts that apply to application software development. It outlines the environment where software is designed and developed and explains the critical role software plays in providing information system security.
5.Operations Security - Operations Security is used to identify the controls over hardware, media, and the operators and administrators with access privileges to any of these resources. Audit and monitoring are the mechanisms, tools, and facilities that permit the identification of security events and subsequent actions to identify the key elements and report the pertinent information to the appropriate individual, group, or process.
6.Physical Security - The physical security domain provides protection techniques for the entire facility, from the outside perimeter to the inside office space, including all of the information system resources.
7.Cryptography - The cryptography domain addresses the principles, means, and methods of disguising information to ensure its integrity, confidentiality and authenticity.
8.Telecommunications & Network Security - The telecommunications, network, and Internet security domain discusses the:
9.Business Continuity & Disaster Recovery Planning - The Business Continuity Plan (BCP) domain addresses the preservation and recovery of business operations in the event of outages.
10.Legal, Regulations, Compliance & Investigations - The Law, Investigations, and Ethics domain addresses:
|