Krishnakumar Mahadevan
CISSP Central
Welcome to CISSP Central , the ultimate podcast for aspiring and certified CISSP professionals! Whether you’re studying for the CISSP 2024 syllabus exam or looking to sharpen your cybersecurity skills, this podcast is your go-to resource. Each episode dives deep into the critical domains of cybersecurity, offering insights, tips, and real-world experiences from industry experts. Join us as we explore the latest trends, challenges, and solutions in information security, helping you stay ahead in a rapidly evolving digital world. From encryption to risk management, compliance to cloud security,...
Author
Krishnakumar Mahadevan
Category
Podcast website
Latest episode
Oct 16, 2024
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
CISSP Domain4 Intro and Section 1 16.10.2024 31:50
4.0 DOMAIN 4: COMMUNICATION AND NETWORK SECURITY 4.1 Apply secure design principles in network architectures 4.1.1 Open System Interconnection (OSI) and Transmission Control Protocol/Internet Protocol (TCP/IP) models 4.1.2 Internet Protocol (IP) version 4 and 6 (IPv6) 4.1.3 Secure Protocols: IPsec, SSH, SSL/TLS 4.1.4 Implications of multilayer protocols 4.1.5 Converged Protocols (iSCSI, VoIP, etc....
CISSP Domain3 Section 10 16.10.2024 12:37
3.10 Manage the information system lifecycle 3.10.1 Stakeholder needs & requirements 3.10.2 Requirements Analysis 3.10.3 Architectural design 3.10.4 Development / Implementation 3.10.5 Integration 3.10.6 Verification & Validation 3.10.7 Transition / deployment 3.10.8 Operations and maintenance/sustainment 3.10.9 Retirement / disposal
CISSP Domain3 Section 9 16.10.2024 16:16
3.9 Design Site and Facility security controls 3.9.1 Wiring closets/intermediate distribution frame 3.9.2 Server rooms/data centers 3.9.3 Media storage facilities 3.9.4 Evidence storage 3.9.5 Restricted and work area security 3.9.6 Utilities and Heating, Ventilation, and Air Conditioning (HVAC) 3.9.7 Environmental issues (e.g., natural disasters, man-made) 3.9.8 Fire prevention, detection, and sup...
CISSP Domain3 Section 8 16.10.2024 12:45
3.8 Apply security principles to site and facility design 3.8.1 Facility Design 3.8.2 Implement Site and Facility Security Controls 3.8.3 Physical Security Threats 3.8.4 Layered Defense Model
CISSP Domain3 Section 7 16.10.2024 17:53
3.7 Understand methods of cryptanalytic attacks 3.7.1 Brute-force 3.7.2 Ciphertext only 3.7.3 Known Plaintext 3.7.4 Frequency Analysis 3.7.5 Chosen Ciphertext 3.7.6 Implementation Attacks 3.7.7 Side-channel Attack (SCA) 3.7.8 Fault injection 3.7.9 Timing Attacks 3.7.10 Man-in-the-Middle (MITM) 3.7.11 Pass the hash 3.7.12 Kerberos Exploitation 3.7.13 Ransomware 3.7.14 Other Key Attacks
CISSP Domain3 Section 6 16.10.2024 16:04
3.6 Select and determine cryptographic solutions 3.6.1 Cryptographic life cycle 3.6.2 Cryptographic methods 3.6.3 Public key infrastructure 3.6.4 Key Management practices 3.6.5 Digital Signatures and Digital Certificates
CISSP Domain3 Section 5 16.10.2024 22:37
3.5 Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements 3.5.1 Client-based systems 3.5.2 Server-based systems 3.5.3 Database systems 3.5.4 Cryptographic Systems 3.5.5 Operational Technology / Industrial Control Systems (ICS) 3.5.6 Cloud-based Systems 3.5.7 Distributed Systems 3.5.8 Internet of Things (IOT) 3.5.9 Microservices 3.5.10 Containerization 3....
CISSP Domain3 Section 4 16.10.2024 21:10
3.4 Understand security capabilities of Information Systems (IS) (e.g., memory protection, Trusted Platform Module (TPM), encryption/decryption)
CISSP Domain3 Section 3 16.10.2024 10:27
3.3 Select controls based upon systems security requirements Here we will go over the steps to take when deciding the security controls to deploy according to the needs of the system. Some of these needs were covered in Domain 1's discussion.
CISSP Domain3 Section 2 16.10.2024 15:20
3.2 Understand the fundamental concepts of security models 3.2.1 Security Models 3.2.2 Lattice-based models 3.2.3 Rule-based models 3.2.4 Other models & Concepts 3.2.5 Evaluation Criteria (ITSEC, TCSEC and CC)
CISSP Domain3 Intro and Section 1 16.10.2024 17:36
3.0 DOMAIN 3: SECURITY ARCHITECTURE AND ENGINEERING 3.1 Research, implement, and manage engineering processes using secure design principles. 3.1.1 Threat Modeling 3.1.2 Least Privilege 3.1.3 Defense in depth 3.1.4 Secure Defaults 3.1.5 Fail Securely 3.1.6 Separation of Duties 3.1.7 Keep it simple and Small 3.1.8 Zero trust or trust but verify 3.1.9 Privacy by design (PbD) 3.1.10 Shared Responsibi...
CISSP Domain2 Section 5 and 6 16.10.2024 15:53
2.5 Ensure appropriate asset retention 2.6 Determine data security controls & compliance requirements 2.6.1 Data States 2.6.2 Scoping and Tailoring (NIST SP 800-53B) 2.6.3 Standards Selection 2.6.4 Data Protection methods
CISSP Domain2 Section 4 16.10.2024 12:40
2.4 Manage Data Lifecycle 2.4.1 Data Roles 2.4.2 Data Collection 2.4.3 Data Location 2.4.4 Data Maintenance 2.4.5 Data Retention 2.4.6 Data Remanence 2.4.7 Data Destruction
CISSP Domain2 Section 3 16.10.2024 9:49
2.3 Provision information and assets securely 2.3.1 Information and asset ownership 2.3.2 Asset inventory 2.3.2 Asset Management
CISSP Domain2 Section 2 16.10.2024 10:13
2.2 Establish information and asset handling requirements 2.2.1 Information and Asset Handling: 2.2.2 Handling Requirements: 2.2.3 Media Storage: 2.2.4 Transportation: 2.2.5 Transmission & Transfer: 2.2.6 Media retention and destruction:
CISSP Domain2 Intro and Section 1 16.10.2024 13:34
2.0 DOMAIN 2: ASSET SECURITY 2.1 Identify and classify information and assets 2.1.1 Data Classification 2.1.2 Asset Classification 2.1.3 Other key concepts of Asset Security
CISSP Domain1 Section 11 and 12 16.10.2024 10:18
1.11 Apply supply chain risk management (SCRM) concepts 1.11.1 Risks associated with the acquisition of products and services from suppliers and providers 1.11.2 Risk mitigations 1.12 Establish and maintain a security awareness, education, and Training program 1.12.1 Methods & techniques to increase awareness and training 1.12.2 Periodic content reviews to include emerging technologies and tre...
CISSP Domain1 Section 10 16.10.2024 8:55
1.10 Understand & apply threat modelling & Methodologies 1.10.1 STRIDE Model 1.10.2 PASTA Model 1.10.3 DREAD Model
CISSP Domain1 Section 9 16.10.2024 13:23
1.9 Understand and apply risk management concepts 1.9.1 Threat and Vulnerability Identification 1.9.2 Risk Analysis, assessment, and scope 1.9.3 Risk response and treatment 1.9.4 Applicable Types of Controls 1.9.5 Control Assessments 1.9.6 Continuous monitoring and measurement 1.9.7 Reporting (e.g., Internal, External) 1.9.8 Continuous improvement (e.g., risk maturity modeling) 1.9.9 Risk Framewor...
CISSP Domain1 Section 8 16.10.2024 12:25
1.8 Contribute to and enforce personnel security policies and procedures 1.8.1 Candidate Screening and Hiring 1.8.2 Employment agreements and policy driven requirements 1.8.3 Onboarding, transfers, and termination processes 1.8.4 Vendor, consultant, and contractor agreements and controls
CISSP Domain1 Section 5, 6 and 7 16.10.2024 10:24
1.5 Understand requirements for investigation types 1.6 Develop, document, & implement security policy, standards, procedures, & guidelines 1.6.1 Security Policies 7 1.6.2 Standards, Procedures Baselines, and Guidelines 1.7 Identify, analyze, and prioritize Business Continuity (BC) requirements 1.7.1 Business Impact Analysis 1.7.2 External Dependencies
CISSP Domain1 Section 4 16.10.2024 10:36
1.4 Understanding of Info Security legal and regulatory problems 1.4.1 Cybercrimes and data breaches 1.4.2 Licensing and intellectual property requirements 1.4.3 Import/export controls 1.4.4 Transborder data flow. 1.4.5 Issues Related to Privacy 1.4.6 Contractual, Legal, Industry Standards, & Regulatory Requirements
CISSP Domain1 Section 3 16.10.2024 10:17
1.3 Evaluate, apply, and sustain security governance principles. 1.3.1 Alignment of the security function to business strategy 1.3.2 Organizational processes (e.g., acquisitions, divestitures, etc.,) 1.3.3 Organizational roles and responsibilities 1.3.4 Security Control Frameworks 1.3.5 Due Care and Due Diligence
CISSP Domain1 Section 1 and Section 2 16.10.2024 14:14
1.1 Understand, adhere to, and promote professional ethics 1.1.1 (ISC)2 Code of Professional Ethics 1.1.2 Organizational code of ethics 1.2 Understand and apply security concepts 1.2.1 Confidentiality, Integrity, Availability, Authenticity, and Non-repudiation
Introduction to CISSP 2024 16.10.2024 9:44
This is just an introduction episode of CISSP Central podcast, and this entire podcast series is based on a published book named C(R)ISSP: The most concise handbook for CISSP 2024, written by myself, which can be purchased directly from Amazon.
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.