Get in Touch
 Duration 35 hours

Course Outline

Security and Risk Management

  • Foundations of confidentiality, integrity, and availability (CIA).
  • Security governance, policies, and frameworks (ISO 27001, NIST CSF).
  • Risk analysis, assessment, and mitigation strategies.
  • Business impact analysis, security awareness, and training initiatives.
  • Legal, regulatory, compliance, and privacy issues (GDPR, HIPAA, local laws).

Asset Security

  • Information classification, ownership, and protection.
  • Data handling procedures (retention, deletion, backup, transfer).
  • Privacy protection and data lifecycle management.
  • Secure use of assets and media control.

Security Engineering

  • Principles of secure system and architecture design.
  • Cryptography: symmetric, asymmetric, hashing, PKI, and key management.
  • Physical security considerations and hardware security modules (HSMs).
  • Secure virtualisation, cloud-native security patterns, and secure API usage.

Communications and Network Security

  • Network models, protocols, and secure communications (TLS, VPN, IPSec).
  • Perimeter defences, segmentation, firewalls, and IDS/IPS.
  • Wireless security, remote access, and zero-trust network architectures.
  • Secure design of network architectures in cloud and hybrid environments.

Identity and Access Management (IAM)

  • Access control: identification, authentication, authorization, and accountability.
  • Identity providers, federation, SSO, and access federation in the cloud.
  • Privileged access management (PAM) and role-based access control (RBAC).
  • Identity lifecycle management: provisioning, deprovisioning, and entitlement reviews.

Security Assessment and Testing

  • Testing security controls: SAST, DAST, penetration testing, and vulnerability scanning.
  • Audit strategies and review frameworks.
  • Log management, monitoring, and continuous assessment.
  • Red teaming, blue teaming, and adversary simulation techniques.

Security Operations

  • Incident response planning, handling, and forensics.
  • Security Operations Centre (SOC) design, monitoring, and threat intelligence integration.
  • Patching, vulnerability management, and configuration management.
  • Business continuity, disaster recovery, and resilience planning.

Software Development Security

  • Secure Software Development Lifecycle (SDLC) and DevSecOps practices.
  • Common vulnerabilities (beyond the OWASP Top 10) and mitigation patterns.
  • Code review, static/dynamic analysis, and secure frameworks.
  • Supply chain risks, dependency management, and runtime protection.

Exam Strategy, Practice, and Wrap-Up

  • CISSP exam format, question strategy, and time management.
  • Practice exams and domain-specific quizzes.
  • Gap analysis and personal study plans.
  • Recommended resources, communities, and continuous learning paths.

Summary and Next Steps

Requirements

  • At least 5 years of cumulative, paid work experience in two or more of the (ISC)² CISSP domains, or equivalent experience.
  • Foundational knowledge of information security concepts, networks, and software systems.
  • Familiarity with risk management, cryptography, and IT operations.

Target Audience

  • Information security professionals preparing for the CISSP exam.
  • Security architects, managers, and consultants.
  • IT leaders, auditors, and governance professionals.

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 8000 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (7)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories