Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Jones, Daniel

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A structured, exam-oriented walkthrough of the CISSP Common Body of Knowledge that turns eight dense security domains into readable study material for certification candidates and newcomers to information security alike. Best for self-studying beginners who want a single consolidated reference before investing in heavier official guides. 【Book Arc】 - **Opening (~0%–10%)**: Lays out the book's four-part structure and the CISSP domain map, then opens Domain 1 (Security and Risk Management) — defining risk, threat, and vulnerability, and grounding the CIA triad, governance, and compliance/law requirements. - **Early (~10%–32%)**: Moves into the technical core — security architecture and engineering, secure design principles, mobile and endpoint vulnerabilities, networking models (OSI vs. TCP/IP), and Identity and Access Management (IAAA, authentication factors, federation, identity brokers). - **Middle (~32%–50%)**: Covers operational lifecycle concerns — asset inventory, provisioning/de-provisioning, change and patch management, vulnerability management, audit phases, and the start of software development security (SDLC models, secure coding, SAST/IAST, API threats). - **Late (~50%–75%)**: Connects security to business strategy — mission/goals/objectives, business continuity and disaster recovery planning, and the alignment of security strategy with organizational continuity (excerpts are thinner here). - **Ending (~75%–100%)**: Closes with exam logistics — the eight domains and their weightings, CAT testing format, language availability, and question counts. The excerpts do not cover the final domains in depth. 【Key Takeaways】 - **Risk management is the spine of the whole book** (Opening): risk, threat, and vulnerability are defined early and revisited across governance, architecture, and operations — understanding this vocabulary is the prerequisite for every later domain. - **CIA plus governance and compliance form Domain 1's foundation** (Opening): confidentiality, integrity, and availability are paired with laws (S.B. 1386, HITECH, GDPR) and intellectual-property rules, showing security as a legal and business obligation, not just a technical one. - **Secure design must be built into the engineering process, not bolted on** (Early): the design → requirements → system design → implementation sequence, plus layered endpoint defenses and OWASP guidance, frames security as a lifecycle discipline. - **IAM rests on IAAA — Identification, Authentication, Authorization, Accountability** (Early): authentication factors (know/are/have), SSO, LDAP, biometrics, and identity-broker/federation concepts explain how access is granted and tracked across trust domains. - **Assets and changes need lifecycle management** (Early–Middle): inventory, provisioning/de-provisioning, centralized patch management (e.g., WSUS), rollback capability, and patch-compliance reporting are presented as concrete operational controls. - **Auditing follows four phases** (Early): preparation, performance (fieldwork), reporting, and follow-up/closure — with follow-up audits verifying that corrective actions actually worked. - **Secure coding is now a first-class concern** (Middle): SAST and IAST tools catch issues like buffer overflows, SQL injection, and XSS, but the book stresses that automated tools miss some vulnerabilities and carry false positives. - **Exam mechanics matter as much as content** (Middle): the eight domains and their weightings, CAT format (100–150 questions), and multilingual availability are spelled out so candidates can plan study time proportionally. 【Reading Tips】 - **Deep-read Domains 1, 3, and 5** (risk management, architecture/engineering, IAM) — the excerpts show these carry the most conceptual weight and reappear throughout later material. - **Skim the exam-logistics section** (domain weightings, CAT format) once for planning, then return to it when scheduling your test. - **Treat the SDLC and secure-coding sections as practical checklists** — note SAST/IAST trade-offs and API attack types; these are easy to underestimate. - **Watch for thin coverage** in business continuity/disaster recovery and the later domains; supplement with official CBK references if those are your weak areas. - **Use the domain weightings as a study budget**: Security and Risk Management (15%) and Communication/Network Security (14%) deserve the most time. 【Coverage Limits】 This guide reflects the stratified excerpts provided, which concentrate on Domains 1, 3, 5, and 8 plus exam logistics; the later domains and the business continuity/disaster recovery material are only partially represented, so some chapters are summarized more thinly than others.
Excerpt 1
calculation of assessing the associated risk, implementing and testing measures, mitigating the risks become a core responsibility of the security and manage...
View in text
Excerpt 2
re difficult to manage centrally and apply a unified policy. However, the security policies, standards, baselines, and procedures must be applied whenever po...
View in text
Excerpt 3
resources, manage the lifecycle, as well as security as you know what you own, how you use it, and who uses it. This also helps to manage costs and reduce ad...
View in text
Excerpt 4
eapon. It can be, stolen, used against an entity, alter the integrity, alter the meaning, erased, and used to construct strategies to destroy a business or a...
View in text
Excerpt 5
specific taste. Such entities are known as trade secrets . - Trademark: A symbol, logo, or a text or something similar, which represents a brand or a busines...
View in text
Excerpt 6
helps an organization to demonstrate continually improving adequacy, effectiveness and suitability. ISMS Process The process comprises four stages; namely, P...
View in text
Excerpt 7
mmon variables and methods cover the class, whereas objects define unique characteristics. Parts of a class (subclasses) and collections of classes (supercla...
View in text
Excerpt 8
nd CU. Memory Management Unit (MMU): Provides addresses and sequence to the stored data and converts logical addressing to physical addressing. Pre-fetch Uni...
View in text
Tags
AI categories
CybersecurityProgrammingEducation
Publish Year: 2021
Language: English
File Format: PDF
File Size: 15.2 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…