Krishnakumar Mahadevan

CISSP Central

Welcome to CISSP Central , the ultimate podcast for aspiring and certified CISSP professionals! Whether you’re studying for the CISSP 2024 syllabus exam or looking to sharpen your cybersecurity skills, this podcast is your go-to resource. Each episode dives deep into the critical domains of cybersecurity, offering insights, tips, and real-world experiences from industry experts. Join us as we explore the latest trends, challenges, and solutions in information security, helping you stay ahead in a rapidly evolving digital world. From encryption to risk management, compliance to cloud security,...

Author

Krishnakumar Mahadevan

Category

Technology

Podcast website

mkkpro.com

Latest episode

Oct 16, 2024

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android almost 10M downloads · 4.8 rating iOS soon

Episodes

CISSP Domain4 Intro and Section 1 16.10.2024

4.0 DOMAIN 4: COMMUNICATION AND NETWORK SECURITY 4.1 Apply secure design principles in network architectures 4.1.1 Open System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models 4.1.2 Internet Protocol (IP) version 4 and 6 (IPv6) 4.1.3 Secure Protocols: IPsec, SSH, SSL/TLS 4.1.4 Implications of multilayer protocols 4.1.5 Converged Protocols (iSCSI, VoIP, etc....

CISSP Domain3 Section 10 16.10.2024

3.10 Manage the information system lifecycle 3.10.1 Stakeholder needs & requirements 3.10.2 Requirements Analysis 3.10.3 Architectural design 3.10.4 Development / Implementation 3.10.5 Integration 3.10.6 Verification & Validation 3.10.7 Transition / deployment 3.10.8 Operations and maintenance/sustainment 3.10.9 Retirement / disposal

CISSP Domain3 Section 9 16.10.2024

3.9 Design Site and Facility security controls 3.9.1 Wiring closets/intermediate distribution frame 3.9.2 Server rooms/data centers 3.9.3 Media storage facilities 3.9.4 Evidence storage 3.9.5 Restricted and work area security 3.9.6 Utilities and Heating, Ventilation, and Air Conditioning (HVAC) 3.9.7 Environmental issues (e.g., natural disasters, man-made) 3.9.8 Fire prevention, detection, and sup...

CISSP Domain3 Section 8 16.10.2024

3.8 Apply security principles to site and facility design 3.8.1 Facility Design 3.8.2 Implement Site and Facility Security Controls 3.8.3 Physical Security Threats 3.8.4 Layered Defense Model

CISSP Domain3 Section 7 16.10.2024

3.7 Understand methods of cryptanalytic attacks 3.7.1 Brute-force 3.7.2 Ciphertext only 3.7.3 Known Plaintext 3.7.4 Frequency Analysis 3.7.5 Chosen Ciphertext 3.7.6 Implementation Attacks 3.7.7 Side-channel Attack (SCA) 3.7.8 Fault injection 3.7.9 Timing Attacks 3.7.10 Man-in-the-Middle (MITM) 3.7.11 Pass the hash 3.7.12 Kerberos Exploitation 3.7.13 Ransomware 3.7.14 Other Key Attacks

CISSP Domain3 Section 6 16.10.2024

3.6 Select and determine cryptographic solutions 3.6.1 Cryptographic life cycle 3.6.2 Cryptographic methods 3.6.3 Public key infrastructure 3.6.4 Key Management practices 3.6.5 Digital Signatures and Digital Certificates

CISSP Domain3 Section 5 16.10.2024

3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements 3.5.1 Client-based systems 3.5.2 Server-based systems 3.5.3 Database systems 3.5.4 Cryptographic Systems 3.5.5 Operational Technology / Industrial Control Systems (ICS) 3.5.6 Cloud-based Systems 3.5.7 Distributed Systems 3.5.8 Internet of Things (IOT) 3.5.9 Microservices 3.5.10 Containerization 3....

CISSP Domain3 Section 4 16.10.2024

3.4 Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)

CISSP Domain3 Section 3 16.10.2024

3.3 Select controls based upon systems security requirements Here we will go over the steps to take when deciding the security controls to deploy according to the needs of the system. Some of these needs were covered in Domain 1's discussion.

CISSP Domain3 Section 2 16.10.2024

3.2 Understand the fundamental concepts of security models 3.2.1 Security Models 3.2.2 Lattice-based models 3.2.3 Rule-based models 3.2.4 Other models & Concepts 3.2.5 Evaluation Criteria (ITSEC, TCSEC and CC)

CISSP Domain3 Intro and Section 1 16.10.2024

3.0 DOMAIN 3: SECURITY ARCHITECTURE AND ENGINEERING 3.1 Research, implement, and manage engineering processes using secure design principles. 3.1.1 Threat Modeling 3.1.2 Least Privilege 3.1.3 Defense in depth 3.1.4 Secure Defaults 3.1.5 Fail Securely 3.1.6 Separation of Duties 3.1.7 Keep it simple and Small 3.1.8 Zero trust or trust but verify 3.1.9 Privacy by design (PbD) 3.1.10 Shared Responsibi...

CISSP Domain2 Section 5 and 6 16.10.2024

2.5 Ensure appropriate asset retention 2.6 Determine data security controls & compliance requirements 2.6.1 Data States 2.6.2 Scoping and Tailoring (NIST SP 800-53B) 2.6.3 Standards Selection 2.6.4 Data Protection methods

CISSP Domain2 Section 4 16.10.2024

2.4 Manage Data Lifecycle 2.4.1 Data Roles 2.4.2 Data Collection 2.4.3 Data Location 2.4.4 Data Maintenance 2.4.5 Data Retention 2.4.6 Data Remanence 2.4.7 Data Destruction

CISSP Domain2 Section 3 16.10.2024

2.3 Provision information and assets securely 2.3.1 Information and asset ownership 2.3.2 Asset inventory 2.3.2 Asset Management

CISSP Domain2 Section 2 16.10.2024

2.2 Establish information and asset handling requirements 2.2.1 Information and Asset Handling: 2.2.2 Handling Requirements: 2.2.3 Media Storage: 2.2.4 Transportation: 2.2.5 Transmission & Transfer: 2.2.6 Media retention and destruction:

CISSP Domain2 Intro and Section 1 16.10.2024

2.0 DOMAIN 2: ASSET SECURITY 2.1 Identify and classify information and assets 2.1.1 Data Classification 2.1.2 Asset Classification 2.1.3 Other key concepts of Asset Security

CISSP Domain1 Section 11 and 12 16.10.2024

1.11 Apply supply chain risk management (SCRM) concepts 1.11.1 Risks associated with the acquisition of products and services from suppliers and providers 1.11.2 Risk mitigations 1.12 Establish and maintain a security awareness, education, and Training program 1.12.1 Methods & techniques to increase awareness and training 1.12.2 Periodic content reviews to include emerging technologies and tre...

CISSP Domain1 Section 10 16.10.2024

1.10 Understand & apply threat modelling & Methodologies 1.10.1 STRIDE Model 1.10.2 PASTA Model 1.10.3 DREAD Model

CISSP Domain1 Section 9 16.10.2024

1.9 Understand and apply risk management concepts 1.9.1 Threat and Vulnerability Identification 1.9.2 Risk Analysis, assessment, and scope 1.9.3 Risk response and treatment 1.9.4 Applicable Types of Controls 1.9.5 Control Assessments 1.9.6 Continuous monitoring and measurement 1.9.7 Reporting (e.g., Internal, External) 1.9.8 Continuous improvement (e.g., risk maturity modeling) 1.9.9 Risk Framewor...

CISSP Domain1 Section 8 16.10.2024

1.8 Contribute to and enforce personnel security policies and procedures 1.8.1 Candidate Screening and Hiring 1.8.2 Employment agreements and policy driven requirements 1.8.3 Onboarding, transfers, and termination processes 1.8.4 Vendor, consultant, and contractor agreements and controls

CISSP Domain1 Section 5, 6 and 7 16.10.2024

1.5 Understand requirements for investigation types 1.6 Develop, document, & implement security policy, standards, procedures, & guidelines 1.6.1 Security Policies 7 1.6.2 Standards, Procedures Baselines, and Guidelines 1.7 Identify, analyze, and prioritize Business Continuity (BC) requirements 1.7.1 Business Impact Analysis 1.7.2 External Dependencies

CISSP Domain1 Section 4 16.10.2024

1.4 Understanding of Info Security legal and regulatory problems 1.4.1 Cybercrimes and data breaches 1.4.2 Licensing and intellectual property requirements 1.4.3 Import/export controls 1.4.4 Transborder data flow. 1.4.5 Issues Related to Privacy 1.4.6 Contractual, Legal, Industry Standards, & Regulatory Requirements

CISSP Domain1 Section 3 16.10.2024

1.3 Evaluate, apply, and sustain security governance principles. 1.3.1 Alignment of the security function to business strategy 1.3.2 Organizational processes (e.g., acquisitions, divestitures, etc.,) 1.3.3 Organizational roles and responsibilities 1.3.4 Security Control Frameworks 1.3.5 Due Care and Due Diligence

CISSP Domain1 Section 1 and Section 2 16.10.2024

1.1 Understand, adhere to, and promote professional ethics 1.1.1 (ISC)2 Code of Professional Ethics 1.1.2 Organizational code of ethics 1.2 Understand and apply security concepts 1.2.1 Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation

Introduction to CISSP 2024 16.10.2024

This is just an introduction episode of CISSP Central podcast, and this entire podcast series is based on a published book named C(R)ISSP: The most concise handbook for CISSP 2024, written by myself, which can be purchased directly from Amazon.

Listen to the CISSP Central podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.