Module 1: Security Principles
Understand Cybersecurity Concepts
- Confidentiality
- Integrity
- Availability
- Authentication, Authorization, Accounting (AAA)
- Non-repudiation
- Privacy
Understand Risk Management Concepts
- Risk management lifecycle
- Risk management processes
Understand Governance Concepts
- Regulations and laws
- Frameworks and guidelines
- Policies, standards (e.g., International Organization for Standardization (ISO), Center for Internet Security), procedures
Understand Cybersecurity Controls
- Technical controls
- Administrative controls
- Physical controls
Maintain Professional and Ethical Conduct
- Professional code of conduct
- Due care and due diligence
- ISC2 Code of Ethics
Module 2: Security Governance
Plan Governance, Risk, and Compliance (GRC)
- Purpose
- Importance
- Frameworks and tools
Understand Redundancy
- Business Continuity (BC)
- Disaster Recovery (DR)
Understand Security Awareness
- Organizational culture (e.g., importance of security, security leadership)
- Concepts (e.g., social engineering, password protection, phishing)
Measure Cybersecurity Effectiveness
- Key metrics, Key Risk Indicators (KRI)
- Dashboards, score cards, reports
Module 3: Identity and Access Management (AIM) Concepts
Understand Identity Life Cycle Management
- Roles definition
- Provision
- Review
- Deprovision
- Frameworks and tools
Understand Logical Access Controls
- Principle of Least Privilege (PoLP)
- Separation of Duties (SoD)
- Access control models
- CC Certification Exam Outline
Module 4: Network and Cloud Security Concepts
Understand Network Security
- Concepts (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), Virtual Private Network (VPN))
- Firewalls (e.g., ports, applications)
- Wireless (e.g., Wi-Fi, Bluetooth)
- Embedded systems (e.g., Industrial Control System (ICS)), Internet Of Things (IoT)
Understand Network Security Architecture
- Comprehending network segmentation (e.g., Firewall zones, Virtual Local Area Network (VLAN), micro-segmentation)
- Defense in Depth
- Zero Trust (ZT)
Understand Cloud Security
- Characteristics (e.g., Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling)
- Service models
- Deployment models
- Shared security model (e.g., roles and responsibilities)
Module 5: Security Operations and Incident Response
Understand Data Security
- Data handling (e.g., classification, labeling, masking, and sanitization)
- Encryption (e.g., symmetric, asymmetric, hashing, quantum resistant cryptography)
Understand Security Operations
- Logging and monitoring security events
- Security event triage (e.g., incident use cases, prioritization, correlation)
- Threat actors (e.g., types, motivations)
- Cyber threat intelligence
- Threat frameworks
Understand Incident Response (IR)
- Data handling policy implementing Incident Response Plan (IRP)
- Incident Response (IR) exercises (e.g., testing, tabletop)
Understand Asset Protection
- Asset lifecycle management (e.g., End Of Life (EOL) software and devices)
- Configuration and change management
Understand Security Testing
- Security readiness testing (e.g., blue teaming, purple teaming, red teaming)
- Application testing (e.g., vulnerability scanning, static analysis, dynamic analysis, threat modeling)
- Physical penetration testing (e.g., phishing, tailgating, impersonation)