Cyber Attacks

Threat Modeling

2020-07-16T06:02:07+00:00Tags: , , , , , , , , , , , , , , , , , , , , |

Threat Modeling A categorization model, which describes the threats to an organization, and why and how these threats become vulnerable. Threat modeling, is attack-centric. Threat modeling is usually applied to software applications, but it can be used for operating systems, and devices. Threat modeling also helps design architects to identify the threats, potential security [...]

Security Control Assessment

2020-07-16T07:24:28+00:00Tags: , , , , , , , , , , , , , , |

Security Control Assessment Security Control Assessment that ensures that the security policies enforced in an organization are meeting their goals and objectives. CSA also reports about the quality of risk management processes including incident response action plans. A well-executed assessment process of security control provides inputs to enhance the running security control, [...]

Identification of Vulnerability & Threats

2020-07-16T05:39:14+00:00Tags: , , , , , , , , , , , , , , , , , |

Identification of Vulnerability & Threats Identification of vulnerability & threats is one of most important the aspects of CISSP training course.   Vulnerability A vulnerability is a weakness in a system or its design. Classifying vulnerabilities helps in identifying its impact on the system. Vulnerability greatly increases the risk of the organization's assets. Policy [...]

Personal Security

2020-07-16T05:45:39+00:00Tags: , , , , , , , , , , , , , , |

Personal Security Personal security policies concern people associated with the organization, such as employees, contractors, consultants, and users. Personal security is one of the aspects of CISSP training course. Personnel security plays a vital role in protecting an organization's valuable assets. Therefore, the organization must have policies regarding the security of its personnel. These [...]

Business Continuity Requirements

2020-07-16T05:34:41+00:00Tags: , , , , , , , , , , , , , , , , |

Business Continuity Requirements Business continuity requirements, ensures the continuity of IT operations that is maintained from the primary or alternate locations during an incident or disastrous events.Business continuity requirements are based on the business continuity planning (BCP). Develop and Document Scope and Plan Business Continuity Planning (BCP) BCP aims to prevent interruptions to operations [...]

Security Policies & Standards

2020-07-16T05:53:43+00:00Tags: , , , , , , , , , , , , , , |

Security Policies & Standards A person who intends to obtain CISSP certificate must be well aware of the differences and relationships between the following: Policies Standards Guidelines Procedures 1- Policy: A security policy is a written document in an organization outlining how to protect the organization from threats and how to handle situations when [...]

Security Concepts

2020-07-16T05:50:40+00:00Tags: , , , , , , , , , , , , , , , , , |

Security Concepts Asset: An asset is anything valuable to an organization. It may vary from tangible items (people, computers) to intangible items (as example Bank accounts, database information). Read more about tangible Items and intangible items Valuable Information Assets: Security of these assets is an important aspect of information security environment. Greater value assets [...]

Professional Ethics

2020-07-16T05:47:44+00:00Tags: , , , , , , , , , , , |

Professional Ethics Ethical behavior and professional is a requirement for maintaining your CISSP certification because the profession of information security is based on trust. Professionals may be handling sensitive or confidential information. Ethically sound and professional ethics need to be adhered by the professionals. Two important points to keep in mind: Unethical activity doesn’t [...]

Legal & Regulatory Issues

2020-07-16T05:43:32+00:00Tags: , , , , , , , , , , , , , , , , , , , , , , , |

Legal & Regulatory Issues Today, one of the important aspects of cyber security is legal & regulatory issues. The following list of issues, may have legal or regulatory implications and lead to civil or criminal liability on the part of an organization. Cyber Crime Criminal activities committed over communication networks, such as the Internet, Telephone, [...]

Go to Top