Krishnakumar Mahadevan

CISSP Central

Welcome to CISSP Central , the ultimate podcast for aspiring and certified CISSP professionals! Whether you’re studying for the CISSP 2024 syllabus exam or looking to sharpen your cybersecurity skills, this podcast is your go-to resource. Each episode dives deep into the critical domains of cybersecurity, offering insights, tips, and real-world experiences from industry experts. Join us as we explore the latest trends, challenges, and solutions in information security, helping you stay ahead in a rapidly evolving digital world. From encryption to risk management, compliance to cloud security,...

Author

Krishnakumar Mahadevan

Category

Technology

Podcast website

mkkpro.com

Latest episode

Oct 16, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

CISSP Domain8 Section 5 16.10.2024

8.5 Define and apply secure coding guidelines and standards 8.5.1 Security weaknesses and vulnerabilities at the source-code level 8.5.2 Security of application programming interfaces (API) 8.5.3 Secure Coding Practices 8.5.4 Software-defined security

CISSP Domain8 Section 3 and 4 16.10.2024

8.3 Assess the effectiveness of software security 8.3.1 Auditing and logging of changes 8.3.2 Risk analysis and mitigation 8.4 Assess security impact of acquired software 8.4.1 Commercial-off-the-shelf (COTS) 8.4.2 Open Source 8.4.3 Third-Party 8.4.4 Managed Services (e.g.., enterprise applications) 8.4.5 Cloud Services (e.g.., SaaS, IaaS, PaaS)

CISSP Domain8 Section2 16.10.2024

8.2 Identify & apply security controls in development environments 8.2.1 Programming languages 8.2.2 Libraries 8.2.3 Tool sets 8.2.4 Integrated Development Environment (IDE) 8.2.5 Runtime 8.2.6 Continuous Integration and Continuous Delivery (CI / CD) 8.2.7 Software Configuration Management (SCM) 8.2.8 Code Repositories 8.2.9 Application security testing (e.g., SAST, DAST, IAST & SCA)

CISSP Domain8 Intro and Section 1 16.10.2024

8.1 Understand and integrate security in the software development lifecycle 8.1.1 Development Methodologies 8.1.2 Maturity Models (e.g., Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM)) 8.1.3 Operations & Maintenance 8.1.4 Change Management 8.1.5 Integrated Product Team (IPT)

CISSP Domain7 Section 13, 14 and 15 16.10.2024

7.13 Participate in Business Continuity (BC) planning and exercises 7.14 Implement and manage physical security 7.15 Address personnel safety and security concerns 7.15.1 Travel 7.15.2 Security Training & Awareness 7.15.3 Emergency Management 7.15.4 Duress

CISSP Domain7 Section 12 16.10.2024

7.12 Test Disaster Recovery Plans 7.12.1 Read-through/Checklist 7.12.2 Walk-through/Tabletop 7.12.3 Simulation 7.12.4 Parallel 7.12.5 Full Interruption 7.12.6 Communications (e.g., stakeholders, test status, regulators)

CISSP Domain7 Section 11 16.10.2024

7.11 Implement Disaster Recovery Process 7.11.1 Response 7.11.2 Personnel 7.11.3 Communications 7.11.4 Assessment 7.11.5 Restoration 7.11.6 Training & Awareness 7.11.7 Lessons Learned

CISSP Domain7 Section 8, 9 and 10 16.10.2024

7.8 Implement and support patch and vulnerability management 7.9 Understand and participate in change management processes 7.10 Implement recovery strategies 7.10.1 Backup storage strategies 7.10.2 Recovery site strategies 7.10.3 Multiple processing sites 7.10.4 System resilience, high availability (HA), Quality of Service (QoS), and fault tolerance (FT)

CISSP Domain7 Section 7 16.10.2024

7.7 Operate and maintain detection and preventative measures 7.7.1 Firewall 7.7.2 Intrusion detection and prevention systems 7.7.3 Whitelisting/Blacklisting 7.7.4 Third-party provided security services 7.7.5 Sandboxing 7.7.6 Honeypots / Honeynets 7.7.7 Anti-malware 7.7.8 Machine learning and artificial intelligence (AI) based tools

CISSP Domain7 Section 6 16.10.2024

7.6 Conduct incident management 7.6.1 Detection 7.6.2 Response 7.6.3 Mitigation 7.6.4 Reporting 7.6.5 Recovery 7.6.6 Remediation 7.6.7 Lessons Learned

CISSP Domain7 Section 5 16.10.2024

7.5 Apply resource protection techniques 7.5.1 Media Management 7.5.2 Hardware and software asset management 7.5.3 Data at rest/Data in transit

CISSP Domain7 Section 3 and Section 4 16.10.2024

7.3 Perform Configuration Management (e.g., provisioning, baselining, automation) 7.4 Apply foundational security operations concepts 7.4.1 Need to know/Least privileges 7.4.2 Separation of Duties (SoD) and responsibilities 7.4.3 Privileged account management 7.4.4 Job rotation 7.4.5 Service Level Agreement (SLA)

CISSP Domain7 Section 2 16.10.2024

7.2 Conduct logging and monitoring activities 7.2.1 Intrusion detection and prevention systems (IDPS) 7.2.2 Security information and Event Management (SIEM) 7.2.3 Security orchestration, automation, and response (SOAR) 7.2.4 Continuous Monitoring 7.2.5 Egress Monitoring 7.2.6 Log Management 7.2.7 Threat Intelligence (e.g. Threat feeds, threat hunting) 7.2.8 User and Entity Behavior Analytics (UEBA...

CISSP Domain7 Intro and Section 1 16.10.2024

7.0 DOMAIN 7: SECURITY OPERATIONS 7.1 Understand and support investigations 7.1.1 Evidence Collection and Handling 7.1.2 Reporting and Documentation 7.1.3 Investigation Techniques 7.1.4 Digital forensics tools, tactics, and procedures 7.1.5 Artifacts (e.g., data, computers, networks, mobile devices)

CISSP Domain6 Intro and Section 4 16.10.2024

6.4 Analyze test output and generate report 6.4.1 Remediation 6.4.2 Exception Handling 6.4.3 Ethical disclosure 6.5 Conduct or facilitate security audits 6.5.1 Internal 6.5.2 External 6.5.3 Third Party 6.5.4 Location

CISSP Domain6 Intro and Section 3 16.10.2024

6.3 Collect Security Process data 6.3.1 Account Management 6.3.2 Management review and approval 6.3.3 Key Performance and Risk Indicator 6.3.4 Backup Verification data 6.3.5 Training and Awareness 6.3.6 Disaster Recovery (DR) and Business Continuity (BC)

CISSP Domain6 Section 2 16.10.2024

6.2 Conduct Security Control Testing 6.2.1 Vulnerability Assessment 6.2.2 Penetration Testing 6.2.3 Log Reviews 6.2.4 Synthetic Transaction 6.2.5 Code review and testing 6.2.6 Misuse case testing 6.2.7 Coverage analysis 6.2.8 Interface Testing 6.2.9 Breach attack simulations (BAS) 6.2.10 Compliance checks

CISSP Domain6 Intro and Section 1 16.10.2024

6.0 DOMAIN 6: SECURITY ASSESSMENT AND TESTING 6.1 Design and Validate assessment, test, and audit strategies 6.1.1 Internal 6.1.2 External 6.1.3 Third-party 6.1.4 Location (e.g. on-premises, cloud, hybrid)

CISSP Domain5 Intro and Section 5 16.10.2024

5.5 Manage the identity and access provisioning lifecycle 5.5.1 Account access review (e.g., user, system, service) 5.5.2 Provisioning and deprovisioning (e.g., on/off boarding & transfers) 5.5.3 Role definition & transition (e.g. people assigned to new roles) 5.5.4 Privilege escalation (e.g. use of sudo, auditing its use) 5.5.5 Service Accounts Management 5.5.6 Implement Authentication Sy...

CISSP Domain5 Intro and Section 4 16.10.2024

5.4 Implement and manage authorization mechanisms

CISSP Domain5 Intro and Section 3 16.10.2024

5.3 Federated identity with a third-party service 5.3.1 On-Premises 5.3.2 Cloud 5.3.3 Hybrid

CISSP Domain5 Section 2 16.10.2024

5.2 Design identification and authentication Strategy (e.g., people, devices, and services) 5.2.1 Groups and Roles 5.2.2 Authentication, Authorization and Accounting (AAA) (e.g., MFA, password-less authentication) 5.2.3 Session management 5.2.4 Registration, proofing, and establishment of identity 5.2.5 Federated Identity Management (FIM) 5.2.6 Credential Management Systems (e.g. Password vault) 5...

CISSP Domain5 Intro and Section 1 16.10.2024

5.0 DOMAIN 5: IDENTITY & ACCESS MANAGEMENT (IAM) 5.1 Control physical and logical access to assets 5.1.1 Information 5.1.2 Systems 5.1.3 Devices 5.1.4 Facilities 5.1.5 Applications 5.1.6 Services

CISSP Domain4 Section 3 16.10.2024

4.3 Implement secure communication channels according to design 4.3.1 Voice, video, and collaboration (e.g., conferencing, Zoom rooms) 4.3.2 Remote access (e.g., network administrative functions) 4.3.3 Data communications (e.g., backhaul networks, satellite) 4.3.4 Third-party connectivity (e.g., telecom providers, h/w support)

CISSP Domain4 Section 2 16.10.2024

4.2 Secure Network Components 4.2.1 Operation of infrastructure 4.2.2 Transmission Media 4.2.3 Network Access Control (NAC) devices 4.2.4 Endpoint Security (e.g. host-based)

Listen to the CISSP Central podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.