CISSP®: become an information systems security expert
Your security decisions must remain consistent across the information system. Connect architecture, risks and safeguards to assess trade-offs more effectively. Strengthen your expertise to develop well-supported responses and communicate with technical teams and decision-makers alike.
- Duration
- 5 days 35 hours
- Code
- CIS01FR Code
- Certification
- CISSP® : Certified Information Systems Security Professional Certification
Accredited training for the CISSP® : Certified Information Systems Security Professional certification.
Presentation
CISSP training (Certified Information Systems Security Professional) is designed for professionals with advanced information security expertise, particularly CISOs and CIOs. It is also valuable across several cybersecurity roles.
Over 5 intensive days, each session is delivered by an ISC2-accredited trainer who prepares you for this prestigious certification. In line with certification requirements, the course covers the 8 key Common Body of Knowledge (CBK) domains, from risk management to software development security. Quizzes, real-world case studies and interactive discussions develop the skills needed to address complex information security challenges.
By the end of the course, you will be ready to take the CISSP exam. Passing it enables you to earn CISSP certification, subject to meeting ISC2's professional experience requirements (see the Certification tab for details).
Oo2 is an ISC2-accredited training partner (ATP). ATPs are authorised to deliver certification training meeting ISC2's rigorous quality standards.Objectives
By the end of this CISSP course, you will be able to:
- master the 8 ISC2 Common Body of Knowledge domains: risk management, asset security, architecture, networks, identity and access management, security testing, operations and software development;
- design and manage an organisation's overall security posture, integrating governance, compliance and risk management;
- apply advanced information systems security principles in technical and managerial contexts;
- prepare effectively for the official ISC2 CISSP exam.
Program
Module 1: master security and risk management
- Understanding, adhering to and promoting professional ethics.
- Understanding and applying security concepts.
- Evaluating and implementing security governance principles.
- Defining compliance requirements.
- Legal and regulatory aspects of information security from a holistic perspective.
- Requirements for different types of investigations: administrative, criminal, civil and others.
- Developing, documenting and implementing security policies, standards, procedures and guidelines.
- Identifying, analysing and prioritising business continuity requirements.
- Personnel security policies and procedures.
- Risk management and threat modelling concepts.
- Supply chain risk management principles.
- Creating and maintaining a security awareness, education and training programme.
Module 2: secure assets
- Identifying and classifying information and assets.
- Information and asset management requirements.
- Secure provisioning of resources.
- Managing the data lifecycle.
- Asset retention measures: end of life and end of support.
- Data security controls and compliance requirements.
Module 3: design security architecture and engineering
- Researching, implementing and managing engineering processes using secure design principles.
- Core security model concepts: Biba, Star Model, Bell-LaPadula and others.
- Selecting controls according to system security requirements.
- Information systems security capabilities: memory protection, Trusted Platform Module, encryption and decryption.
- Assessing and mitigating vulnerabilities in security architectures and solutions.
- Selecting and developing cryptographic solutions.
- Cryptanalytic attack methods.
- Security principles in site and facility design.
Module 4: secure communications and networks
- Assessing and implementing secure design principles for network architectures.
- Securing network components.
- Implementing secure communication channels in accordance with the design.
Module 5: manage identity and access
- Controlling physical and logical access to assets.
- Managing identification and authentication of people, devices and services.
- Federated identity with third-party services.
- Implementing and managing authorisation systems.
- Managing the identity and access provisioning lifecycle.
- Implementing authentication systems.
Module 6: assess and test security
- Designing and validating assessment, testing and audit strategies.
- Testing security controls.
- Collecting data from security processes.
- Analysing test results and preparing reports.
- Conducting and facilitating security audits.
Module 7: lead security operations
- Understanding and conducting investigations.
- Logging and monitoring activities.
- Configuration management: provisioning, baselining and automation.
- Core security operations concepts.
- Resource protection measures.
- Incident management.
- Detection and prevention measures.
- Patch and vulnerability management.
- Change management processes.
- Recovery strategies and disaster recovery processes.
- Business continuity planning and exercises.
- Physical and personnel security.
Module 8: secure software development
- Integrating security into the software development lifecycle.
- Security controls in software development ecosystems.
- Assessing software security effectiveness.
- Assessing the security impact of purchased software.
- Secure coding guidelines and standards.
Module 9: prepare for the CISSP exam
- Advice and tips for exam success.
- Assessment quizzes.
Audience
This course is for experienced information security professionals, particularly:
- information security and IT managers and directors, including CISOs and CIOs, seeking to structure their organisation's security posture;
- IT auditors and cybersecurity analysts seeking CISSP® certification;
- systems administrators and engineers moving into advanced information security roles.
Prerequisites
The following prerequisites apply to CISSP training:
- Technical skills: foundational knowledge of networks, operating systems and information security practices.
- Additional knowledge: basic familiarity with auditing standards and international business continuity management standards.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Case study
Course highlights
- ISC2-approved trainer: an accredited information security expert who shares practical experience across the 8 CBK domains.
- Official training partner (ATP): Oo2 is an ISC2 Accredited Training Partner, ensuring content meets the certification body's rigorous quality standards.
- Official course materials: learning resources directly aligned with the current CISSP syllabus for preparation faithful to the actual exam content.
- Practical, interactive learning: assessment quizzes, real-world case studies and discussions reinforce concepts and provide practice under conditions similar to the exam.
- Certification included: the CISSP® exam is included, with no additional exam fee.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Training content offered in partnership with (ISC)²
CISSP® is a registered trademark of (ISC)²
fr
en
