Module 2 - 01-2 Flashcards
The Eight CISSP Security Domains
What does CISSP stand for?
Certified Information Systems Security Professional (CISSP)
What are Core Security Concepts called?
Security Domains
As of 2022, how many Security Domains has the CISSP defined?
Eight (8)
What are the Eight CISSP Security Domains?
1) Security and Risk Management
2) Asset Security
3) Security Architecture and Engineering
4) Communication and Network Security
5) Identity and Access Management
6) Security Assessment and Testing
7) Security Operations
8) Software Development Security
What is the First (1st) CISSP Security Domain?
1) Security and Risk Management
Define (1) Security and Risk Management
Defines security goals and objectives, risk mitigation, compliance, business continuity, and the law
What is the Second (2nd) CISSP Security Domain?
2) Asset Security
Define (2) Asset Security
Secures digital and physical assets.
It’s also related to the storage, maintenance, retention, and destruction of data.
What is the Third (3rd) CISSP Security Domain?
3) Security Architecture and Engineering
Define (3) Security Architecture and Engineering
Optimizes data security by ensuring effective tools, systems, and processes are in place
What is the Fourth (4th) CISSP Security Domain?
4) Communication and Network Security
Define (4) Communication and Network Security
Manage and secure physical networks and wireless communications
What is the Fifth (5th) CISSP Security Domain?
5) Identity and Access Management
Define (5) Identity and Access Management
Keeps data secure, by ensuring users follow established policies to control and manage physical assets, like office spaces, and logical assets, such as networks and applications
What is the Sixth (6th) CISSP Security Domain?
6) Security Assessment and Testing
Define (6) Security Assessment and Testing
Conducting security control testing, collecting and analyzing data, and conducting security audits to monitor for risks, threats, and vulnerabilities
What is the Seventh (7th) CISSP Security Domain?
7) Security Operations
Define (7) Security Operations
Conducting investigations and implementing preventative measures
What is the Eighth (8th) CISSP Security Domain?
8) Software Development Security
Define (8) Software Development Security
Uses secure coding practices, which are a set of recommended guidelines that are used to create secure applications and services
Define Firewall
A device used to monitor and filter incoming and outgoing computer network traffic