CISSP Security Domains Flashcards
Security and Risk Management
Defines security goals and objectives, risk mitigation, compliance, business continuity, and the law
Asset Security
securing digital and physical assets. It’s also related to the storage, maintenance, retention, and destruction of data.
Security Architecture and Engineering
This domain focuses on optimizing data security by ensuring effective tools, systems, and processes are in place.
Communication and Network Security
Manage and secure physical networks and wireless communication.
Identity and Access Management
keeps data secure, by ensuring users follow established policies to control and manage physical assets, like office spaces, and logical assets, such as networks and applications.
Security Assessment and Testing
Conducting security control testing, collecting and analyzing data, and conducting security audits to monitor for risks, threats, and vulnerabilities.
Security Operations
conducting investigations and implementing preventative measures.
Software Development Security
Uses secure coding practices, which are a set of recommended guidelines that are used to create secure applications and services.