Chapter 14 Flashcards
DoD Directive 8570.01
“Information Assurance Training, Certification and Workforce Management”
Affects any DoD facility or contractor organization
Ensures that all personnel who are directly involved with information security possess security certifications
DoD Directive 8140
A new, operationally focused cybersecurity training framework
Will replace the 8570.01 directive
Developed by the Defense Information Systems Agency (DISA)
Roles identified by the 8140 directive include:
Security provision Operate and maintain Protect and defend Analyze Operate and collect Oversight and development Investigate
U.S. DoD/NSA Training Standards
Are actually training requirements for specific job responsibilities
Developed by the CNSS and NSTISS committees
Provide guidance for course and professional certification vendors to develop curriculum and materials that meet DoD/NSA requirements
NSTISS-4011
National Training Standard for Information Systems Security (InfoSec) Professionals
CNSS-4012
National Information Assurance Training Standard for Senior System Managers
CNSS-4013
National Information Assurance Training Standard for System Administrators (SA)
CNSS-4014
Information Assurance Officer (IAO) Training NSTISSC-4015 National Training Standard for System Certifiers
CNSS-4016
National Information Assurance Training Standard for Risk Analysts
Vendor-Neutral Professional Certifications
A certification is an official statement that validates the fact that a person has satisfied specific job requirements, including:
Possessing a certain level of experience
Completing a course of study
Passing an examination
Seven Main (ISC)^2 Certifications
Systems Security Certified Practitioner (SSCP)
Certified Information Systems Security Professional (CISSP)
Certified Authorization Professional (CAP)
Certified Secure Software Lifecycle Professional (CSSLP)
Certified Cyber Forensics Professional (CCFP)
HealthCare Certified Information Security Privacy Practitioner (HCISPP)
Certified Cloud Security Professional (CCSP)
SSCP
Covers the seven domains of best practices for information security
CISSP
Demonstrates competence in the eight domains of the (ISC)2 CISSP Common Body of Knowledge (CBK)
CAP
Provides a method to measure the knowledge and skills of professionals involved in authorizing and maintaining information systems
CSSLP
Evaluates professionals for the knowledge and skills necessary to develop and deploy secure applications