Showing posts with label CISSP. Show all posts
Showing posts with label CISSP. Show all posts

Friday, January 24, 2020

How did I prepare for my CISSP exam?

I cleared CISSP exam in the first attempt last week. I have been working in the technology area for 10 years now in several roles (from the Engineer level position to the Director level position). I followed the following resources in the sequential order.
  • Cybrary CISSP Free Online course by Kelly Handerhan : This gave me a quick overview of CISSP course. [Spent roughly 30 hours here.]
  • CISSP by Shon Harris : Read first four domains. I got in-depth knowledge of those four domains. [Spent about 20 hours here.]
  • Simple CISSP by Phil Martin (Audio Book): Great to listen during lunch, workouts and drive-time. [Spent about 30 hours here. Listened to some sections multiple times.]
  • Spent some time going over r/cissp comments. Saw lots of advice that CISSP exam is more about management-based questions and less about knowledge-based questions. I decided to focus more on 'WHY' factors of all the security domains, rather than trying to memorize every technical details and numbers.
  • I set a 60 days goal to appear for the exam and registered for the test.
  • During first 50 days, I read CISSP Official 7th edition book cover to cover, word by word, highlighting the areas that I felt crucial. Also, completed CISSP Official Practice tests during those days. [Spent roughly 2 hours each day; 1 hour during the work lunch and 1 hour at home]
  • Next 7 days, I read Eleventh Hour CISSP study guide by Eric Conrad.
  • During last three days, I reviewed all of the highlights I made on CISSP Official 7th Edition book and summaries/quizzes at the end of each chapter.
  • Took a good enough sleep and rested before the exam.
During the testing, I planned to finish 40 question during the first hour, 50 questions during the second hour and 60 questions during the third hour. Since CISSP exam is the adaptive test and can't go back to correct the answers, I wanted to make sure I carefully read and answered the top 100 questions. I kept track of the number of questions I answered approx every 30 minutes and made sure I was on track.
Majority of the questions were scenario based questions and I had to think from the management perspective to answer the questions. It was a terrifying experience to go through those questions. I had to remind myself several times not to worry but focus on the questions and what would I do as a CIO or CISO while answering the questions. My test completed at 102 questions. And, sure enough, I passed the test.
I hope you find this information useful for your own CISSP journey. Best of Luck!

Monday, November 6, 2017

Understanding CISSP domains

Disclaimer: I am writing this blog as a personal notebook for CISSP exam preparation. It shouldn't be used as otherwise.

CISSP Common Body of Knowledge covers 8 domains.

WHY?
1. Security & Risk Management

WHAT?
2. Security of Asset
3. Security of Network and Communication
4. Security of Software and Development

HOW?
5.Assessment and Testing
6. Security Engineering
7. Security Operations
8. Identity and Auth Management


1. Security & Risk Management

WHY?

  • It is all about CIA (Confidentiality, Integrity and Availability), also referred as AIC

HOW?  

  • Administrative/Management(soft) Controls,
  • Technical (logical) Controls and 
  • Physical/Operational Controls

Control Types:

  • Preventive
  • Detective
  • Corrective
  • Deterrant
  • Recovery

Understand these terminologies is crucial:

  • Asset: What we are trying to protect
  • Vulnerability: Weakness or gap in our protection efforts
  • Threats: Anything that can exploit a vulnerability
  • Risk: The potential loss of an asset as a result of a threat exploiting a vulnerability. It is the intersection of above three (Asset, Vulnerability and Threat)
  • Corrective Action : Assessing threats and identifying vulnerabilities is critical to understanding the risk to assets and take appropriate corrective action.

Security Frameworks:
1. ISO/IEC 27000 Series
  • Defines ISMS (Information Security Management System)
  • Specifies the components/controls that need to be in place to have a complete security program
  • It is like a parts list.
2. Enterprise/Security Architecture Frameworks
  • Zachman, ToGAF, DoDAF, MoDAF, SABSA
  • It shows how to integrate those components/controls into the various layers (Executives, Business Managers, System Architects, Engineers, Technicians, Enterprise) within an organization.
  • It is a blueprint to follow when building something with those parts.
3. System Architecture
  • COBIT (private organizations), NIST SP 800-53 (Federal), COSO Internal Control
  • Defines how we can develop those components/controls
4. Process Development
  • Defines how to manage those components/controls
  • Process Management tools (ITIL, Six Sigma, CMMI/Capability Maturity Model Integration)
5. Process Life Cycle
  • Discuss how to keep the process up-to-date and healthy
  • 4 steps process in cyclic order: Plan - Implement - Operate/Maintain - Evaluate

Let's see how these frameworks come in play. Suppose a company hires you to create a comprehensive security program. First you would do is look up ISO 27000 as a guidance to create an ISMS which provides all the controls you should put in place. Then, you choose a security framework such as ToGAF to create the ISMS and start the Process Life Cycle.
You go in the planning phase. You gather the right people, identify what needs to be done and identify the possible solutions.
Then, you go to the implementation phase. You create blueprints and implement them. You continuously make sure framework attributes (Strategic alignment, Business Enablement, Process Enhancement) are being monitored to ensure success. At this point, you have selected and implemented various controls. The categorization of controls into administrative, technical & physical along with the functional grouping (such as preventive, deterrent, detective etc) will have been a great help.
Ideally before going live, external party audits your implementation, more than likely the auditor will check your implementation against COBIT/NIST SP 800-53. They will find your shortcomings.Once you have addressed any audit shortcomings, you will enter the Maintain step.
At this point, you will want to manage the process using ITIL, Six Sigma or CMMI. This will help you in the Evaluate step, which then feeds back into Plan.



References: