Shon Gerber from the Reduce Cyber Risk and CISSP Cyber Training podcasts provides valuable insight, guidance, and training to you each week that only a senior cybersecurity expert can perform. Shon has over 21+ years of experience in cybersecurity from large corporations, government, and even as a college professor. Shon provides you the information and knowledge you need pass the CISSP exam the first time along with practical steps needed to enhance and grow your cybersecurity career. Shon is a CISSP since 2009 and has over 21 years of experience in corporate, government, and collegiate environments. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. In addition, you will receive extremely valuable security tips and techniques that you can put into practice immediately setting you apart from other individuals within the world of cybersecurity. Lets get going….GIDDY UP!
Send us Fan Mail
One careless QR scan can quietly turn a “private” chat into a live wiretap. We start with a timely threat story: Russian APT-style actors abusing Signal’s linked device flow by pushing phishing links that contain malicious QR codes, so messages can be mirrored to an attacker device in real time. If you use Signal, WhatsApp, or Telegram at work, this is the kind of simple, human-triggered failure mode worth building into your security awareness habits.
Then we shift into CISSP Question Thursday with a rapid, practical run through CISSP Domain 7.1 style topics in digital forensics and incident response. We break down what comes first when handling digital evidence (forensic copy before analysis), how to examine a suspicious file without detonating it (static analysis), and what makes an incident report useful under pressure (a clear timeline of events and actions taken). We also cover insider threat artifacts, mobile device forensics tools like Cellebrite UFED, and why chain of custody is the backbone that keeps evidence credible from collection to court.
Along the way, we talk about root cause analysis, anomaly-based detection for network traffic, and why clear writing beats big jargon when you’re briefing executives, legal, or a board. If you want exam-ready thinking that also maps to real investigations, you’ll get it here.
Subscribe for weekly CISSP training, share this with a teammate who scans QR codes too fast, and leave a review with the topic you want next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
A breach can hit your headlines even when your own systems never get touched, and that’s exactly why third-party risk management keeps showing up on the CISSP exam and in real incident reports. We walk through the Vimeo breach tied to its analytics vendor Anodot, where compromised vendor access and authentication tokens gave attackers a clean path to customer data. No video content or payment data was taken, but names, emails, and metadata exposure is still a trust and reputation problem that security teams have to own.
From there, we zoom out to the bigger pattern behind modern supply chain security: attackers increasingly go after dependencies, CI/CD pipelines, shared developer tools, and widely used vendors because one compromise can cascade across hundreds of customers. We talk about how to reduce that exposure with a stronger TPRM program, including vendor risk tiering, continuous monitoring, SBOM thinking, and practical contractual controls like breach notification timelines, right to audit language, and clear subcontractor disclosure with flow-down requirements to address fourth-party risk.
We also shift into CISSP Domain 1 rapid review mode: what the exam really wants when it asks about due diligence, evidence, and proportional risk decisions. You’ll hear clean explanations of SOC 2 Type 1 vs SOC 2 Type 2, where ISO 27001 fits, why questionnaires like SIG are not proof, and which frameworks matter for third-party and supply chain risk management including NIST 800-161, ISO 27036, and NIST CSF 2.0. We close with practice scenarios that mirror common CISSP traps so you can spot them fast.
Subscribe for more CISSP training, share this with a study partner, and leave a review so more security pros can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
One bad AI decision can cost you more than money. It can cost you trust, trigger regulators overnight, and put your name on the hook when the board asks, “Who approved this?” We dig into AI governance through a CISSP lens, using real-world banking and credit union scenarios that show how fast things go sideways when AI tools slip outside your controls.
We start with the uncomfortable reality behind modern AI adoption: vendors ship powerful models, teams connect third parties, and employees reach for whatever chatbot is quickest. From AI-powered lending platforms that promise speed and fairness, to shadow AI that starts with a simple copy paste of customer data, the common thread is the same. Policies are not protection unless you can detect, enforce, and prove what’s happening with data, models, and vendors.
Then we get practical. We walk through what examiners and auditors actually look for, why NIST AI RMF and existing third-party risk management rules are becoming the default playbook, and how to build evidence that holds up. Expect clear guidance on independent bias testing, explainability, contract language like right to audit and incident notification SLAs, and why model revalidation must be triggered by material change rather than an annual calendar cycle. We also tie the work back to CISSP domains and run practice questions designed to expose the “easy” answers that fail in real governance.
If you’re responsible for security, compliance, or risk, this is your roadmap for governing AI before it governs you. Subscribe, share with a teammate, and leave a review so more CISSP candidates and security leaders can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
That forgotten cloud storage you stopped thinking about months ago can become a real attack path today. We start with a simple but dangerous scenario: abandoned AWS S3 buckets and other orphaned cloud storage that can be re-registered, repurposed, and used to serve malicious content to systems that still “trust” the old source. We walk through why this turns into a supply chain-style problem, what signals to look for, and the practical mitigations that matter most: proper decommissioning, continuous monitoring, tight access control, and disciplined cloud asset inventories.
From there, we shift into CISSP Domain 6.1 and the real work of designing and validating assessment, test, and audit strategies. We explain how we approach building a security assessment and testing program from the ground up: clear objectives, tight scope, risk-based prioritisation, stakeholder alignment, and baselines grounded in frameworks like NIST CSF, ISO 27001, CIS Benchmarks, and NIST SP 800-53. The aim is simple: identify vulnerabilities, validate security controls, and turn findings into remediation that leadership can act on.
We also break down core security testing methods you will see on the CISSP and in real organisations: vulnerability assessment, penetration testing (white box, black box, gray box), fuzz testing, SAST and DAST for application security, plus red team, blue team, and purple team collaboration. Finally, we demystify SOC 1 vs SOC 2 and Type 1 vs Type 2 reports, why they matter for third-party risk management, and how cyber resilience thinking (including the Cyber Resiliency Index) ties everything back to continuity and trust. If this helps, subscribe, share the show with a colleague studying CISSP, and leave a review with the topic you want next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
A six-instruction timing glitch in the Linux kernel can be the difference between “low-priv user” and full root control, and that is why we dig into the Bad EPoll vulnerability from a CISSP-ready, manager-first angle. We start by grounding what the Linux kernel EPoll subsystem does, why it is foundational to high-performance I/O, and why “just disable it” is not a real option when you’re dealing with production Linux servers, desktops, cloud workloads, and Android devices.
Then we unpack the security mechanics in clear terms: a use-after-free race condition, an impossibly thin race window, and the way memory corruption turns into privilege escalation. We also talk about what makes this case extra concerning, including the report that it can be triggered from inside Chrome’s rendering sandbox. If you’ve ever relied on sandboxing, kernel boundaries, or “we run scanners” as your safety net, this story forces a more honest view of defense in depth.
From there we connect the dots to CISSP Domain 8 software development security and real secure SDLC practice. We walk through where SAST, DAST, fuzzing, KASAN-style instrumentation, and AI-assisted code review help and where they fail, especially for concurrency bugs. The real takeaway is a layered detection strategy: automated testing plus manual secure code review for high-blast-radius code, support for external researchers through bug bounty programmes, and a patch management process that moves in days with verification and regression testing so incomplete fixes do not slip through.
If this helps you think like a manager, subscribe, share the episode with a study buddy, and leave a review so more CISSP candidates can find it.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Imagine hearing a claim that the most sensitive identity data in the United States could be sitting on a personal thumb drive. That allegation is still unverified and under investigation, but it gives us a rare chance to see CISSP Domain 2 asset security in real time, with consequences that go far beyond a typical data breach.
I walk through what’s being reported about Social Security Administration data access and potential copying, then I put on the Domain 2 lens: data classification and handling requirements, who the true data owner is, what custodians should be enforcing, and how processors should be limited by scope, purpose, and time. We talk about why “high” impact data under FIPS 199 should automatically trigger stricter controls, and how failures in encryption, logging, and data loss prevention can let sensitive datasets slip outside organizational boundaries.
We also dig into the part most teams get wrong: the data lifecycle. If you cannot execute secure disposal and verify it, you cannot “close Pandora’s box.” Using NIST SP 800-88, we break down clear, purge, and destroy, connect it to real operational controls like removable media restrictions, and turn the whole story into practical exam guidance and CISO-level program lessons you can use with leadership.
Subscribe for more CISSP-ready breakdowns, share this with someone studying Domain 2, and leave a review so more security pros can find the show. What is the first control you would fix in your own environment?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
A vendor gets breached and suddenly your perimeter does not matter, because the attacker does not need to “hack” you. They just reuse the access you already approved. That’s the core lesson behind the Shiny Hunters campaign targeting Oracle PeopleSoft servers at colleges and universities, where compromised access led to large-scale theft of student data and a messy, high-impact supply chain incident.
We walk through what supply chain security really means for modern cybersecurity and for the CISSP exam: it’s not only the software you buy, but also hardware vendors, cloud service providers, managed service providers, open source libraries, and contractors with privileged access. I break down the four supply chain attack vectors you need to know cold: compromised credentials and OAuth tokens, malicious code injection in CI/CD pipelines, open source package attacks like typosquatting and maintainer compromise, and hardware tampering. Along the way, we map the ideas to CISSP Domains 1, 3, 5, and 8 so you can answer questions like a manager, not just a technician.
Then we go deeper on two concepts that keep showing up in both real breaches and exam questions. First, SBOM (Software Bill of Materials), the “nutrition label” that tells you exactly what’s inside your software so you can respond fast when a new CVE hits. Second, OAuth token governance, where long-lived or overly broad tokens can become silent master keys if you do not scope, expire, inventory, revoke, and monitor them properly. We finish with three practice questions and the reasoning behind the best answers and the common distractors.
If this helps, subscribe so you do not miss the next training, share the episode with a CISSP study partner, and leave a review to help more security pros find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Your endpoint tool can be world class and still get taken out first. That’s the unsettling reality behind a new wave of “EDR killer” capabilities being packaged inside ransomware-as-a-service platforms, where affiliates can plug in advanced evasion without building it themselves. When attackers can blind endpoint detection and response before the ransomware payload runs, the old comfort of “we have EDR, so we’re covered” turns into a single point of failure.
We unpack the reporting on a highly active ransomware operation and its toolset, then zoom in on the technical path that makes this work: BYOVD, bring your own vulnerable driver. With admin access, attackers load a legitimate but vulnerable signed driver, escalate into kernel mode, and terminate security processes from below the privilege stack. From there, we shift to what matters for real security programs: defence in depth, kernel integrity protections like HVCI and KMCI, strict driver allow and block policies, and aggressive driver hygiene to reduce attack surface.
Then we put on the CISSP lens. We tie the scenario to Domain 7 security operations (EDR limits, incident response, monitoring), Domain 3 security architecture and engineering (layered controls, hardening), and Domain 1 security and risk management (risk = threat × vulnerability × impact, plus threat landscape shifts). The big takeaway is simple: your job isn’t to find the fanciest tool, it’s to build a program that still works when one control fails and to communicate that risk clearly to leadership.
If this helps you think like a manager and study smarter, subscribe for weekly CISSP-focused breakdowns, share the episode with a teammate, and leave a review so more people can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Someone is stealing encrypted data right now and they are not trying to read it today. They are saving it for later, betting that quantum computing will eventually break the encryption that protects it. I dig into the “Harvest Now, Decrypt Later” strategy, why it matters most for long-term confidentiality, and how security leaders can talk about it as a present-day risk instead of science fiction.
From there, I get practical with post-quantum planning: what the NIST post-quantum cryptography standards signal, why quantum key distribution is still niche for most organisations, and the big architectural idea to remember for the CISSP and for real enterprise security programs: crypto agility. We walk through concrete steps like building a cryptographic inventory, mapping where RSA and elliptic curve crypto live, identifying data with 10 to 20 year secrecy needs, and pushing vendors for a clear PQC roadmap.
Then we pivot into CISSP Domain 1 supply chain risk management (SCRM and CSCRM). I explain why supply chains are a prime target, how modern supply chain attacks can ride in through poisoned open source packages, and what SolarWinds showed the world about scale and impact. We close with the nuts and bolts that actually reduce third-party risk: lifecycle supplier management, meaningful assessments (on-site when it matters), document and policy review, audits, and minimum security requirements baked into contracts and SLAs.
If you want more training, check out CISSP Cyber Training, subscribe for weekly updates, share this with a friend who owns risk, and leave a quick review so more CISSP candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Your software is only as trustworthy as the dependencies you quietly inherit and attackers know it. Today I break down the NCSC warning on software supply chain security and why open source package ecosystems have become a high-value target for real-world compromises that spread fast through CI/CD pipelines.
I walk through the attack patterns that keep showing up in incidents: maintainer account compromise, expired domain takeover, typosquatting, and credential chaining. We connect each technique to the CISSP mindset so you can spot it in scenario questions and, more importantly, recognise it in your own environment. Along the way, I explain why Node.js, Python, and Rust projects are especially exposed, how automation can turn “latest version” convenience into an enterprise incident, and why developer environments often become an overlooked attack surface.
Then we get practical with controls you can actually implement: pausing automatic dependency updates when compromise is suspected, adding human approval for critical packages, rotating credentials immediately, enforcing MFA on developer and registry accounts, and using private or trusted registries to mirror and vet dependencies. I also zoom out to show how to build supply chain security into the secure SDLC with software composition analysis (SCA), code signing, checksum verification, audit logging, continuous monitoring, and an SBOM so you can respond fast when a package turns toxic.
If this helps you tighten your dependency management and level up your CISSP prep, subscribe, share this with a teammate, and leave a quick review so more security pros can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
The breach that takes down a company often does not kick in the front door. It walks in through a “simple” integration you set up months ago, powered by a token no one remembered to rotate. We start with a real-world Zapier-style scenario and unpack how researchers chained together a harmless-looking code block, an AWS Lambda environment, and a misconfigured IAM role to reach private repository files and ultimately an NPM token that could enable a supply chain attack.
From there, we zoom out to the bigger cloud security problem: non-human identities. Service accounts, API keys, and OAuth tokens multiply fast, and they are frequently overprivileged, poorly tracked, and left active long after an integration is retired. We also talk about why SaaS-to-SaaS connections are so hard to secure, and why agentic AI makes visibility even more urgent. If you do not know what systems are connected, what data crosses those links, and who owns the risk, you are effectively trusting an invisible tunnel into your environment.
To make this actionable, we lay out a four-phase third-party risk management (TPRM) framework you can apply immediately: build a vendor and integration inventory with tiering, run real due diligence (SOC 2 Type II, ISO 27001, data access scope, subprocessors and fourth parties), lock protections into contracts (DPA language, right to audit, breach notification expectations), then enforce ongoing monitoring and governance with quarterly token reviews, logging, and incident response playbooks. If you are studying for the CISSP, you will also see exactly how this maps to Domain 1, Domain 3, Domain 4, and Domain 5.
Subscribe for more practical CISSP training, share this with a teammate who owns vendor approvals, and leave a review so more security pros can find it. What is the one integration you would audit first?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Your firewall can be patched tomorrow, but what about the place your system hides its real secrets today? We start with a timely warning about a serious Fortinet FortiGate vulnerability and why perimeter devices are still a make-or-break control, then we pivot into the deeper layer most people ignore until it’s too late: memory.
We walk through CISSP Domain 3.4 by focusing on what memory protection is actually trying to achieve: confidentiality, integrity, and process isolation. From there, we unpack how modern operating systems enforce separation with paging, segmentation, and strict read, write, execute controls. You’ll hear why Meltdown and Spectre were such a big deal, how speculative execution can leak passwords and encryption keys from privileged memory, and why patching decisions are never just “apply everything” but a risk-based vulnerability management call that depends on visibility into what you run.
Next, we connect memory protection to virtualization security. We break down hypervisors, guest and host isolation, Type 1 versus Type 2 designs, and the threats that keep security teams up at night: VM escape, side-channel leakage through shared CPU resources, and the operational hazards of memory overcommitment. Then we bring in hardware roots of trust through TPMs: secure boot, measured boot, key storage for full disk encryption, TPM 2.0 types, and how HSM-style key management shows up in cloud environments. We close with practical best practices, from firmware and microcode updates to choosing encryption controls that fit your actual risk.
If you’re studying for the CISSP or building a real-world security strategy, subscribe, share this with a teammate, and leave a review so more security pros can find it.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
AI agents are landing in production faster than most security teams can track them, and the scariest part is how normal they can look. When an autonomous agent runs the same workflow 10,000 times, your SIEM and EDR may see “nothing to worry about” even while the agent quietly drifts outside its intended scope. That is the core AI governance problem we tackle, through the lens of CISSP thinking and real security leadership.
We walk through what is driving the mess: board-level pressure, AI FOMO, and the dangerous habit of treating AI agents like old-school automation. Then we get concrete. We talk about why many enterprises still lack an inventory of AI agents, why traditional security tooling is tuned for human behaviour anomalies, and what it actually takes to be audit-ready. We cover practical governance frameworks like tiered autonomy, why observability is more than collecting output logs, and how to design decision-path tracing with execution records and decision logs you can act on.
To make it actionable for exam prep and day-to-day work, I close with CISSP-style practice questions on the exact scenarios you will face: detection gaps, human approval bottlenecks, least privilege for agents, proving decisions during audits, and architecting platforms that balance operational efficiency with risk management. If you are serious about passing, I also share how my CISSP Sprint cohort is structured to force momentum, including booking your exam date early.
Subscribe for weekly CISSP-focused training, share this with a teammate building AI workflows, and leave a review so more security pros can find the show. What part of AI agent governance is your biggest blind spot right now?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Your security program can be airtight and still get wrecked by someone else’s breach. We open with a Wired-style reality check: third-party app ecosystems and data brokers collecting location analytics at massive scale, then getting hacked or resold in ways your users never expected. If your organisation issues mobile devices, this is where security awareness, MDM controls, and clear “don’t allow tracking unless required” guidance stops being a nice-to-have and starts becoming risk reduction.
From there, we dig into CISSP Domain 2.3: provisioning resources securely, with the mindset of a senior security professional. We walk through information ownership versus asset ownership, why “IT owns the data” is often the wrong answer, and how classification (public, internal, confidential and beyond) drives least privilege and need-to-know access. We also cover the practical friction points: owners who don’t realise they’re owners, systems spread across teams, and the need to document decisions so risk acceptance is explicit instead of accidental.
We then connect the dots across asset management, configuration management systems, and modern cloud operations. Expect talk on lifecycle tracking, secure disposal, rogue devices and shadow IT, plus the unique headaches of virtual sprawl, snapshots, tagging, data residency, and the cloud shared responsibility model. If you’re studying for the CISSP exam or trying to run a cleaner security programme at work, you’ll leave with a clearer map of what to inventory, who to hold accountable, and which controls keep resources from drifting into chaos.
Subscribe for weekly CISSP-focused training, share this with a teammate who manages cloud or endpoints, and leave a review with the hardest “ownership” problem you’ve seen in the wild.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
BitLocker feels like a safety net until you see how a single bypass can change the whole risk picture. Today we react to the Yellow Key vulnerability (noted in the news and referenced as CVE 2645585) and use it as a practical CISSP training moment: a public proof of concept is available, a vendor patch is not, and the attack hinges on physical access. That mix forces you to think clearly about what “high risk” actually means, why “critical” is not always the right label, and how real security teams respond when the perfect fix does not exist yet.
We connect the story to CISSP domains you are actively tested on. Domain 3 shows up in the basics of data at rest encryption and the uncomfortable truth that encryption is only as strong as its implementation. Domain 7 shows up in zero-day vulnerability management, compensating controls, and the need to have patch deployment ready to move the moment Microsoft ships a fix. We also highlight why secure boot and firmware integrity checks matter, and why endpoint detection may not help when an attacker can silently read files with little to no logging signal.
Then we shift into five exam-style questions designed to sharpen your decision-making: how to classify risk using likelihood and impact, how to spot absolute-language distractors, which CIA triad principle is actually failing when data is accessed without detection, and why data minimisation can reduce breach impact more than “adding another tool.” If you’re studying for the CISSP exam and want practice that feels like real life, this is built for you.
Subscribe for weekly CISSP practice, share this with a study partner, and leave a review so more candidates can find the show. What control would you tighten first if a BitLocker bypass hit your fleet tomorrow?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Default passwords are the kind of problem everyone “knows” about and yet they still open doors for attackers every day. We start with a quick reality check on router security and why factory settings, legacy gear, and unmanaged IoT and OT devices can turn a simple misconfiguration into redirect attacks, man-in-the-middle exposure, DDoS headaches, or silent monitoring. If you’re studying for the CISSP or defending a real network, you’ll walk away with a clearer sense of what to fix first and how to roll changes out without creating change-management chaos.
Then we shift into CISSP Domain 1.6: understanding requirements for investigation types. We break down administrative, criminal, civil, and regulatory investigations and why the burden of proof changes everything. We talk through why HR and legal need to be involved early, when law enforcement is (and is not) helpful, and how sloppy evidence handling can get key artifacts thrown out. We also cover e-discovery and legal holds, using the Electronic Discovery Reference Model (EDRM) to make the process easier to remember and apply.
To close, we get practical about evidence: admissibility, chain of custody, and the forensics basics that protect data integrity, including media, memory, network, software, and embedded device analysis, plus the value of write blockers and disciplined documentation. If you want to pass the CISSP and operate like a calm, credible security professional during an incident, this is the mindset. Subscribe for weekly CISSP-focused training, share this with a teammate, and leave a review with the investigation topic you want us to tackle next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Eight terabytes of stolen schematics is not just a scary number, it is a reminder that cyber risk becomes business risk fast. We start with the Wired report on the Foxconn ransomware attack and unpack what a claim like that could mean in the real world: intellectual property exposure, supply chain disruption, customer impact, and the uncomfortable truth that recovery is only one part of the story when data walks out the door.
From there, we switch into CISSP Domain 7 Security Operations mode and work through practical exam-style questions with the “how would this hold up at work” mindset. We break down why live forensics imaging can be the right call during an insider threat investigation, using the order of volatility and the kinds of RAM artifacts that disappear the moment you shut a machine down. We also tackle a Patch Tuesday nightmare scenario where a CVSS 9.8 vulnerability is already being exploited but the change advisory board will not meet for ten days, and we explain why an emergency change process plus compensating controls is the mature security operations answer.
We also cover a common privileged access failure where a domain admin uses an elevated account for email and browsing, and how least privilege plus a privileged access workstation (PAW) architecture can prevent a single phish from becoming domain compromise. Finally, we sharpen the fundamentals with an RTO/RPO recovery timeline question and a SIEM brute force threshold miss that illustrates false negatives and the need for better tuning and behavioural baselines.
Subscribe for weekly CISSP training, share this with a study partner, and leave a review so more security pros can find the show. What topic do you want me to turn into practice questions next?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Next Peak: https://nextpeak.net/services/icr/
A regional conflict can spike your cyber risk even if your offices never move and your headcount never changes. That is the uncomfortable reality behind geopolitical cyber risk, and it is why I brought on Helen Lee, Director of Intelligence Cyber Research at NextPeak, to break down how global flashpoints turn into real security problems for businesses of every size. If your security program only reacts to today’s alerts, you are already behind the curve.
We dig into what “geopolitical cyber risk” actually means, why awareness so often fails to become action, and how to bridge that gap with practical, decision ready outputs. Helen shares concrete examples that make the risk feel real: how hardware and supply chains can become national security issues, why router ecosystems can create broad exposure, and how second and third order effects in semiconductor production can introduce new vulnerabilities across your tech stack. We also talk about the World Economic Forum data showing that organisations expect geopolitical tensions to increase cyber risk while many are still adjusting their posture.
From there, we get operational. We cover where this work fits in an existing security stack, how to “bake it in” at the governance, risk, and compliance layer, and why threat intelligence teams will be critical for monitoring geocyber indicators and handing off actionable guidance to the SOC and leadership. Helen walks through offerings like a geopolitical cyber risk index, assessments, advisory support, customised reporting, and future focused tabletop exercises that test readiness for plausible scenarios years ahead. If you are studying for the CISSP, this conversation ties directly to Security and Risk Management, third party risk, supply chain risk, and communicating risk to executives and boards.
Subscribe for more practical CISSP focused conversations, share this with a security leader who owns vendor risk, and leave a review so more people can find the show. What is the biggest geopolitical risk you think your organisation is ignoring right now?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Your browser just became a security boundary you can’t afford to ignore. We start with ClaudeBleed, a vulnerability in the Claude AI Chrome extension that shows how an AI browser agent can be hijacked by another malicious extension, even one with zero special permissions. When an agent can act “as you” inside a trusted environment, the risk jumps from theory to real outcomes like silent email sending, data loss through Google Drive, or code theft from private repos.
We walk through the mechanics in plain language: the extension’s communication model is too trusting, relying on origin assumptions instead of validating true execution context. That opens the door to script injection and environment-level manipulation, where the most sophisticated part of the attack is making bad actions look normal from the inside. We also talk about the vendor response, why partial patches can still leave uncomfortable gaps, and why “trust but verify” matters when AI tools move faster than enterprise controls.
Then we pivot to CISSP Domain 3.9 design site and facility security controls, because reliability and security still live in wiring closets, server rooms, and restricted work areas. We cover practical facility security: locks and limited access, airflow and HVAC planning, avoiding storage-room chaos, why cameras must be monitored, how badge systems fail in real life, and how media and evidence storage ties into legal hold, forensics, encryption, and key management. We finish with environmental and resilience essentials including UPS vs generators, fire detection and suppression options, and power quality issues like sags, spikes, surges, and brownouts.
Subscribe for weekly CISSP-ready lessons, share this with a teammate who lives in Chrome, and leave a review so more security pros can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Quiet failures are the ones that scare me most, and enterprise AI creates a brand-new way for them to spread. If a chatbot becomes the “trusted employee” everyone relies on, a slow drip of bad documents, outdated procedures, or deliberately manipulated data can poison decisions for months without a single red flag. We break down what that looks like in real organizations, why it differs from the Hollywood version of a hack, and how the business impact shows up as confident misinformation rather than obvious outages.
We also dig into the difference between data poisoning (deliberate manipulation) and data pollution (accidental garbage at scale), then connect it to retrieval augmented generation (RAG). RAG is powerful because it answers from your internal knowledge base, but that same knowledge base becomes the attack surface and the “source of truth” the model won’t question. I share practical steps you can take right now: audit what your AI actually trusts, map the full AI contact surface across workflows and repositories, treat the AI pipeline like an untrusted vendor, and assign a named owner for accuracy and security.
Then we shift into CISSP Domain 1 practice with exam-style questions that force real trade-offs: using annual loss expectancy (ALE) to recommend a risk treatment to the board, applying NIST RMF guidance even when controls are inherited through FedRAMP, handling an ethics dilemma under the ISC2 Code of Ethics, spotting the biggest BCP gap when RTO and RPO targets collide with backup frequency, and explaining why HIPAA compliance does not automatically equal GDPR compliance for EU citizen data.
If you’re studying for the CISSP or you’re building security controls around AI and cloud systems, this one is built to sharpen both your judgement and your test readiness. Subscribe, share this with a friend who’s deploying AI internally, and leave a quick review so more CISSP candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
MFA feels like the finish line until you watch a company wire tens of millions of dollars to an attacker without a single password being stolen. We dig into why business email compromise (BEC) still works even in “secure” environments, because the real target is the decision point: trust, timing, urgency, and authority. When attackers can spoof executives or use deepfake voice and video, the authentication layer often never gets challenged in a meaningful way.
We break down practical, real-world defenses that go beyond “more tools”: fixing payment and approval workflows, defining what counts as a high-risk transaction, forcing out-of-band verification using known contact details, adding mandatory pauses for unusual transfers, and training teams with realistic BEC scenarios during end-of-quarter and holiday pressure. The big takeaway is that blocked phishing emails are not the same thing as protected money movement, and leadership has to own that gap.
Then we pivot into CISSP Domain 7 with a clear, test-focused walkthrough of disaster recovery plans. A DR plan on paper is not resilience, so we cover the five primary DR testing types: read-through checklist, walkthrough and tabletop, simulation, parallel, and full interruption. You will learn what each test proves, why most organizations stop at simulation, and how to build toward higher-confidence testing without taking reckless risks.
If this helps you, subscribe for weekly CISSP-focused cyber training, share the episode with a teammate, and leave a review so more people can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
A single compromised identity can turn your whole environment into a hallway of unlocked doors and cross-domain attacks are built to exploit exactly that. We start with a timely real-world breach theme and use it to explain how adversaries move between endpoints, cloud platforms, and third-party connections by abusing identity and privileged access, not just by running noisy malware. If your organization relies on a patchwork of identity tools, limited visibility, and “normal looking” logins, you may not see the threat until it has already jumped domains.
From there, we pivot into CISSP Domain 8.4 thinking: how to evaluate acquired software without guessing. We break down what to look for in open source software (community activity, maintenance signals, orphaned project risk), what makes COTS software uniquely hard to assess (no source code visibility for deep vulnerability assessment), and what matters most for SaaS and managed services (encryption for data at rest and in transit, plus clear SLAs that define performance metrics and incident response expectations). We also cover why the shared responsibility model is non-negotiable for cloud security clarity, especially around account management and access control.
We round it out with hands-on evaluation methods that map to both the exam and real security programs: threat modeling to uncover dependency risk, dependency scanning to catch vulnerable libraries, sandbox testing in a controlled environment, and periodic reassessments as threats evolve. If you’re studying for the CISSP or building a safer vendor and software intake process, this one gives you a practical checklist mindset. Subscribe for more CISSP training, share this with a study partner, and leave a review with the software risk topic you want us to cover next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Ransomware actors are getting quieter, faster, and more custom and that should change how you study for the CISSP and how you defend your environment. We start with a quick personal update on a new CISSP Sprint: an eight-week live cohort built to give you structure, accountability, and weekly sessions so you can realistically target exam day without paying boot camp prices. Seats are limited, with an early bird option, because the whole point is real feedback and momentum.
From there we dig into a timely threat story: Trigona ransomware and its use of a custom data exfiltration tool designed to evade common detection patterns. We break down what it means when attackers move away from popular utilities and how bandwidth saturation, connection rotation, and encrypted outbound traffic can slip past monitoring. If you’re studying CISSP security operations and incident thinking, this is a clean example of how credential theft, endpoint interference, and network visibility all connect.
Then we shift into CISSP Domain 3 cryptography and make the rules stick: symmetric versus asymmetric encryption, what key does what for confidentiality, and how digital signatures actually deliver integrity and non-repudiation. We also cover elliptic curve cryptography, key size advantages, and why quantum computing is forcing real post-quantum cryptography planning now, not later. Finally, we share a board briefing framework for CISOs and security leaders so you can translate technical risk into business impact, loss cases, and a clear ask the board can act on.
Subscribe for weekly CISSP-focused cybersecurity training, share this with a study partner or a security leader, and leave a review so more people can find the show. What part do you want us to go deeper on next: crypto rules, ransomware tradecraft, or board communication?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Three Microsoft Defender zero-days are reportedly being exploited, and that is the kind of headline that tests whether our security program is real or just optimistic. I break down what we know, including BlueHammer (CVE-2026-33825) landing in Patch Tuesday while Red Sun and Undefend were described as still unpatched at the time, and the practical response: update fast, verify coverage, and keep your eyes on threat intel so local privilege escalation does not become a bigger incident.
From there, I keep the CISSP momentum going with Domain 2.5 retention requirements, because retention is one of those “boring” topics that turns you into a hero the day something goes wrong. We walk through why retention exists (regulatory compliance, legal mandates, litigation holds, audits, and business continuity), what you should actually retain (security logs, audit trails, backups, PCAP where it makes sense, and especially configuration files and system documentation), and how to test backup and recovery so it works when you need it. We also hit the real-world trade-offs: cost vs risk, over-retention vs under-retention, GDPR-style data minimisation, and secure disposal with documentation you can show an auditor.
Then I shift into security leadership with segment two of the boardroom cybersecurity series: five business translations that convert security speak into language boards can act on. Vulnerabilities become business exposure, alert volume becomes risk prevented, budget requests become ROI, AI threats become operational risk, and compliance becomes business continuity. If you want clearer retention policies, stronger audit readiness, and better executive buy-in, subscribe, share the show, and leave a review so more security pros can find it.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
The next wave of AI in cybersecurity is not a theory project, it’s an operational deadline. I open with a timely look at reporting that the White House wants federal agencies to get access to Anthropic’s Claude Mythos, and why that scramble matters for every security team. If Mythos can help uncover vulnerabilities and accelerate exploit development, the same capability that strengthens defense can also supercharge attackers. We talk about why the government wants guardrails, why supply chain risk becomes a bigger deal, and why the gap between AI leaders may be measured in months, not years.
From there, I shift into practical CISSP Domain 2.5 fundamentals: appropriate asset retention, end of life, and end of support. We walk through what “end of life” really means, why unsupported systems become high-value targets, and how to build a real end-of-life process with asset inventory, sunsetting plans, data migration, continuity planning, and secure disposal. I also share why documentation isn’t busywork, especially when legal hold and chain of custody can block normal modernization efforts, and how retention policies can reduce both compliance exposure and litigation risk.
Finally, I kick off a boardroom cybersecurity series built for senior security professionals and aspiring CISOs. The core idea is simple: boards don’t make decisions in CVSS scores or alert counts, they make decisions in revenue impact, downtime, safety, and recovery time. I explain how to translate technical risk into business language, what boards actually want to know, and how strong executive communication turns a security leader into a strategic advisor. Subscribe, share this with a teammate, and leave a review so more CISSP and cybersecurity leaders can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
AI didn’t just make deepfakes easier. It made targeted sexual abuse scalable. I open with a Wired-reported reality that’s hitting schools worldwide: AI tools that can generate fake nude images from ordinary photos, spread through bots and subscription services, and leave students and families dealing with humiliation, harassment, and real trauma. If you’re a cybersecurity professional, this is a moment where your skills can protect your community, not just your company.
I walk through concrete ways to help: offering free threat briefings to school districts, helping draft acceptable use and AI governance policies, adding mandatory reporting language, and building age-appropriate deepfake awareness training for staff and students. If you’re in threat intelligence, you can document and report active infrastructure. If you’re in GRC or vendor risk, you can push synthetic media controls and stronger AI governance. I also talk about incident response basics for schools: evidence collection, platform takedowns, and tabletop exercises that prepare teams for a fast-moving crisis.
Then we pivot into CISSP exam prep with practical questions tied to today’s threats. We break down quantitative risk assessment (ALE, SLE, ARO) and how cost of mitigation drives the right response. We hit GDPR Article 22 and AI transparency, post-quantum cryptography for long-term retention, SSD sanitisation aligned to NIST 800-88 using cryptographic erasure, and zero trust in 5G edge networks using software-defined perimeter controls for least privilege IoT communications.
Subscribe for weekly CISSP training, share this with someone who works with schools, and leave a review so more defenders can find it.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
An AI model that can uncover thousands of zero-days and potentially chain multiple vulnerabilities into an automated exploit is not just a scary headline, it’s a stress test for every risk program on the planet. I open with what the Mythos news implies for real-world defense: attacker behavior may shift from human pace to machine speed, and many SIEM and EDR detections are still tuned for human patterns. That’s why we talk candidly about what security teams may need to do next, including tightening externally facing systems and moving faster toward a zero trust architecture.
Then we pivot into CISSP Domain 1 risk management concepts, translating exam language into decisions you’ll actually make in a business. We define the core terminology like assets, threats, vulnerabilities, exposure, safeguards, attacks and breaches, then walk through control categories (technical, administrative, physical) and control types (preventive, detective, corrective, deterrent, recovery and compensating). If you’ve ever wondered why risk conversations go sideways, we also dig into the difference between risk appetite, risk capacity, and risk tolerance, and why you can’t set these without business leaders in the room.
We also tackle quantitative risk analysis versus qualitative risk analysis, including CISSP formulas such as AV, EF, SLE, ARO and ALE, plus a critical reality check on “fake precision” and how to apply a cost-benefit analysis that holds up. Finally, we cover security control assessments, monitoring and measurement, building a risk register safely, and how maturity models and risk frameworks like CMMI, ISO 31000, NIST approaches, ISO 27005, COBIT, SABSA and PCI DSS fit into a defensible cybersecurity risk management program. Subscribe, share this with a CISSP study partner, and leave a review so more security pros can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A single disgruntled admin can do more damage with “normal” IT tools than many attackers can with malware, and that reality changes how we should think about both security and careers. I start with a true insider attack story where legitimate administrative access was used to lock out users, disrupt operations, and attempt extortion, then I break down the practical controls that reduce insider threat risk: least privilege, immutable backups, privileged activity alerting, and real segregation of duties.
From there, I share the cybersecurity career roadmap most people never get. Instead of pushing everyone into the same crowded paths, I talk through high-demand roles with less competition, especially GRC (governance, risk, and compliance) and OT/ICS security. If you’re breaking into cyber, we cover how risk assessments, policy writing, audit coordination, and vendor risk management can become your unfair advantage, even with a non-traditional background. If you’re drawn to critical infrastructure, we dig into why IT plus OT security skills are rare, how to start learning SCADA and industrial environments, and why the salary upside is real.
For mid-career and senior pros, we shift into what actually unlocks leadership: risk quantification, FAIR methodology, supply chain security, cloud security architecture, and speaking the language of the board through metrics and a risk register. If you want to move toward CISO or virtual CISO work, this is about becoming a business risk advisor, not just the person who runs tools. Subscribe, share this with a friend building their cyber career, and leave a review. What role are you aiming for next?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
LinkedIn might be doing more in your browser than you think. We start with a report dubbing it “BrowserGate” a claim that LinkedIn quietly checks for installed Chrome extensions using hidden JavaScript, raising real questions about privacy, browser fingerprinting, and what platforms should disclose to users when collecting device level signals tied to real identities and jobs.
From there, we shift into a core CISSP topic that shows up everywhere in real security work: implementing and supporting patch vulnerability management (CISSP Domain 7.8). We talk about why patching is not just maintenance, but a primary security control that shrinks your attack surface across the entire ecosystem, including servers, endpoints, cloud services, mobile devices, and OT/ICS environments where uptime and safety make patching harder. We also cover the uncomfortable reality of unpatchable legacy systems and how compensating controls like micro-segmentation and network isolation help manage risk when a vendor will never ship an update.
We ground the conversation with the Apache Struts remote code execution lesson and the Equifax breach, then walk through a practical patch management lifecycle: evaluate applicability, test in non-production when needed, follow change management approvals, deploy with rollback plans, and verify with follow-up scans. You’ll also hear clear CISSP-ready distinctions between hotfix vs patch vs update, authenticated vs unauthenticated vulnerability scanning, CVE feeds, CVSS prioritisation, MTTR metrics, and how to respond when a zero-day vulnerability has no patch yet.
If this helps your CISSP prep, subscribe, share the episode with a study partner, and leave a review so more security learners can find it. What part of patch and vulnerability management is hardest in your environment right now?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A ransomware headline is easy to ignore until you realize it can shut down a factory line, break supplier networks, and trigger contract penalties that dwarf the original IT cleanup. We start with a real-world manufacturing case study from the UK where cyber incidents are becoming routine, then zoom in on why revenue hits are so brutal in an industry that often runs on tight margins. The Jaguar Land Rover disruption adds a sobering lesson: a single breach can ripple outward into suppliers, logistics, and even wider economic impact.
From there, we switch into CISSP Question Thursday with Domain 4 focused practice that sharpens how you think under exam pressure. We walk through a zero trust private cloud scenario and explain why microsegmentation with software-defined networking gives the most granular workload-to-workload control for stopping east-west lateral movement after a compromised web server. We also tackle the split tunnel VPN tradeoff that can turn an endpoint into a bridge for attackers, plus a legacy ARP weakness that opens the door to ARP spoofing and man-in-the-middle attacks.
We round it out with high-value protocols and technologies you’re likely to see on the CISSP exam: DKIM for cryptographic email integrity and domain validation, WPA3’s SAE for stronger protection against offline dictionary attacks, and VXLAN in shared infrastructure where encryption is not provided by default and must be layered in with controls like IPsec or MACsec. If you’re studying communications and network security, this one connects technical decisions to real business risk. Subscribe, share with a study partner, and leave a review so more CISSP candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Passing the CISSP is a huge win, but the part that quietly ends careers is what comes after: keeping the certification active. I walk you through how to submit ISC2 CPEs in a way that is accurate, defensible, and easy to repeat, so you never wake up to a renewal deadline panic. We talk real numbers too: 120 CPE credits per three-year cycle, a minimum of 40 each year, and the $125 annual maintenance fee that can sneak up on you if you are not watching your dashboard.
Before we get into the portal clicks, I bring up an idea that matters for every cybersecurity professional: the hidden cost of cybersecurity specialisation. Specialising can raise your income and sharpen your value, but without broad context you can lose the big picture, mis-prioritise risk, over-rely on tools, and slow down detection and response. The goal is to build depth while staying fluent across the CISSP domains and the business realities those domains protect.
Then we go step by step through CPE submission: choosing the right category (education, contributions, professional development, or unique work experience), understanding Group A vs Group B, selecting relevant CISSP domain areas, converting time into credit hours, and attaching supporting documentation that holds up during an ISC2 audit. I also share the most common mistakes that waste time, including waiting until the last minute, entering hours incorrectly, miscategorising activities, and failing to save proof for at least 12 months beyond your certification expiration date.
If you want more practical CISSP training and a smoother CPE routine, subscribe, share this with a friend who is newly certified, and leave a review so more people can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A cheap camera on a pole can become a surveillance pipeline, and that’s not a movie plot, it’s a real security problem. I start with a news-driven look at alleged CCTV espionage tied to critical infrastructure and why CISSP Domain 3 isn’t just theory. If you don’t know what devices are installed at your sites, what they record, and where that data goes, you can lose control of your environment long before an attacker ever touches your firewall.
From there, I pivot into a focused Domain 3 question set that drills the kind of reasoning the CISSP exam rewards. We unpack why collapsing multiple security layers into one “highly capable” security appliance creates a single point of failure, and how defense in depth is really about independent layers, resilience, and clear risk acceptance. I also review classic security models, including the Bell-LaPadula lattice model and its “no read up, no write down” confidentiality rules, plus how it differs from integrity-focused Biba and the commercial Clark-Wilson approach.
We then hit core security architecture and engineering concepts: the trusted computing base (TCB), what the reference monitor is, and why the security kernel is the component that implements it. On the crypto side, I explain why elliptic curve cryptography (ECC) is the best strength-to-key ratio choice for digital signatures on low-powered IoT devices. Finally, we cover database security threats like inference (and how it relates to aggregation), and wrap with a practical safety topic for data centers: Class C electrical fires and why CO2 or clean agents are preferred to protect hardware.
Subscribe for weekly CISSP prep, share this with a study partner, and if it helped you think more clearly, leave a review so more candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The fastest way to lose control of your security program is to ignore the systems that control everything else. I start with a timely CISA warning: attackers went after an endpoint management system, the kind of “one system that touches many” platform that can turn a single compromise into enterprise-wide fallout. We talk through practical hardening moves like multi-factor authentication, limiting where admins can log in from, and adding extra checks for high-impact access, because centralized management consoles are prime targets for nation-state and supply chain motivated attacks.
Then we pivot to the bigger wave: AI GRC (governance, risk, and compliance) in the age of artificial intelligence. AI adoption is exploding while AI governance lags, and that gap is where regulatory fines, privacy failures, and reputational damage tend to show up. I break down GRC in clear terms, explain why traditional audits and sample-based testing struggle with always-on AI decisions, and lay out what AI governance needs to add: an AI inventory, explainable AI requirements, named model owners, fairness and bias assessments, model lifecycle governance, and third-party AI risk management.
We also map the AI regulatory landscape you need to know, including the EU AI Act, the NIST AI RMF, and ISO 42001 as an emerging certifiable AI management system. From there, I walk through seven risks companies must understand: algorithmic discrimination, non-compliance, model drift, data governance and GDPR privacy exposure, black box accountability gaps, vendor and supply chain AI risk, and shadow AI from unauthorized employee tool use.
You’ll leave with an eight-step roadmap you can apply immediately, plus next actions like downloading the NIST AI RMF, running a quick AI inventory, assessing EU exposure, and updating vendor due diligence for AI. Subscribe, share this with your GRC or security team, and leave a review so more CISSP learners can find the training.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A “just visiting a website” iPhone hack is the kind of story that snaps you out of autopilot, and that’s where we start. Dark Sword shows how sophisticated mobile malware can ride on compromised sites and silently pull sensitive data from iOS devices. The fix is refreshingly practical: patch quickly, encourage the people around you to patch, and treat update discipline as real cybersecurity risk management, not a minor inconvenience.
Then I shift into CISSP Domain 2 Asset Security with a set of deep-dive practice questions that mirror how ISC2 likes to test your thinking. We break down what data classification is actually for, how to spot the “primary purpose” in tricky answer choices, and why value drives controls. From there we tackle cloud security responsibility with a healthcare scenario and a misconfigured ACL, clarifying why the organisation and its data owners remain accountable even when a cloud provider runs the infrastructure.
We also navigate a common GRC conflict: legal retention requirements versus security’s desire to reduce breach exposure, and how to land on a defensible data retention policy. Finally, we get hands-on with media sanitisation, including why DOD 5220.22-M overwriting can fail on SSDs under NIST 800-88 guidance, and we close with access governance basics like least privilege and need to know when roles change.
If you’re studying for the CISSP exam or tightening real-world security controls, subscribe, share this with a study partner, and leave a review so more candidates can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
AI is not a future cybersecurity problem. It is a right now career problem, and it is also a massive opportunity if you prepare the right way. I walk through how AI is changing cybersecurity forever, from AI-generated phishing and malware to brand new attack surfaces like prompt injection and LLM attacks. At the same time, I explain why modern defense stacks are getting smarter fast, with AI baked into SIEM, EDR, XDR, threat intelligence, and cloud security posture tools.
We also zoom out to what senior leaders are expected to do today. CSOs and CISOs are hired to protect more than systems. They protect revenue, brand trust, and business continuity, and they have to communicate risk in language the board can act on. If you want to grow into leadership, I share the mindset shift away from being the “job of no” and toward enabling the business with clear trade-offs, metrics, and outcomes.
Whether you are new to cyber or you have 5 to 20 years in, you will leave with a practical plan: which certifications build momentum, which roles AI is disrupting, what skills AI cannot replace, and how to run a 12-month upskill roadmap that keeps you relevant in the AI era. If this helps you, subscribe, share it with one person in cyber, and please leave a review so more CISSP and cybersecurity professionals can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
AI is starting to change cybersecurity budgets in a surprising place: cyber insurance premiums. We dig into why insurers now care about how you use AI, how “more automation” can still mean “more risk,” and what it looks like when AI expands your attack surface through new APIs, sensitive data exposure, and code that ships with hidden security flaws. If you’re a security leader, risk manager, or CISSP candidate, this is the kind of real-world pressure that turns governance from a buzzword into a business necessity.
From there, we shift into CISSP Question Thursday with Domain 1 practice questions and clear walk-throughs. We cover why discretionary access control matches a data classification model where data owners set permissions, how to use the CIA triad as a risk-based decision tool (especially for e-commerce where availability equals revenue), and a clean distinction between due diligence and due care that you can use in audits, interviews, and exam answers.
We also tackle a scenario every organisation faces: cloud outsourcing and accountability. Even with a contract, you can’t fully transfer liability for protected customer data, and regulators still expect you to manage compliance, vendor risk, and controls. We close with a governance lesson on why awareness training must evolve with the threat landscape, including modern social engineering like deepfake-driven attacks. Subscribe, share this with a friend studying CISSP, and leave a review or comment with the hardest Domain 1 concept you’re trying to master.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The ground under cybersecurity careers is shifting, and the fastest movers are pairing CISSP with modern, high-leverage skills that command premium pay. We dig into a practical roadmap: first, how to prepare your SOC for agentic AI with four concrete moves—reskill analysts to supervise and validate models, establish new roles for AI governance and orchestration, redesign playbooks around automation and escalation, and enforce tight guardrails with approvals and audit trails. The goal is simple: turn AI from chaos into a disciplined force multiplier.
From there, we unpack five high-income skills that dovetail with CISSP’s leadership mindset. Modern GRC is no longer paperwork; it’s resilience, litigation exposure, and executive storytelling—with VCISO opportunities that reward clear risk narratives and continuous evidence automation. Cloud security architecture centers on software-defined security, Terraform policies as code, zero trust in Kubernetes, and the legal boundaries of shared responsibility and data residency. AI ethics and governance emerges as the unofficial ninth domain, where shadow AI containment, dataset audits for PII, and prompt-injection testing meet global regulation and model risk policy.
We also dive into advanced identity as the new perimeter—taming machine identities, secrets sprawl, and rolling out phishing-resistant FIDO2 to make zero trust real. Finally, we get tactical with software supply chain security: SBOMs, signed artifacts, dependency hygiene, and CI/CD security gates that protect velocity without breaking builds. Along the way, we share market pay signals, “decision architect” expectations for senior roles, and smart bridge certifications like CISM, AI governance credentials, and CISA that accelerate credibility.
If you’re ready to pivot from “security says no” to “here’s how to do it safely,” this is your map. Subscribe, share with a teammate who needs a nudge, and leave a quick review to help more CISSPs find their niche and lead the way.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security readiness is slipping while threats race ahead—so we zero in on what actually moves the needle. We start with a frank look at why so many teams feel behind: AI-driven attacks, budget constraints, and a hiring market that demands senior talent at entry-level pay. Then we get practical, connecting CISSP Domain 1 concepts to real decisions leaders make every week: how to align risk management with business goals, how to write policies that drive action, and how to use standards, baselines, guidelines, and SOPs to turn strategy into measurable outcomes.
From there, we dig into quantitative risk without the fluff. You’ll hear how to compute Single Loss Expectancy and Annualized Loss Expectancy, and why ALE clarifies budget asks better than any slide deck. We contrast due care and due diligence in plain terms: patch what’s critical now, and keep a repeatable process that proves you act responsibly over time. We also revisit ISC2 ethics, centering the top priority—protect society and the common good—and show how that principle shapes daily choices around audits, monitoring, and vendor assurance.
Cloud security gets its own spotlight. When penetration tests are restricted, we show how to leverage SOC 2 Type II and ISO 27001 under NDA, map those assurances to your control set and risk appetite, and close gaps with compensating controls. Along the way, we challenge common hiring myths, explore smart uses of MSPs, and show why cross-training software engineers into security often outperforms chasing more certifications. The result is a clear, actionable path from policy to practice that helps you harden faster and justify every control with data.
If you’re studying for the CISSP or leading a team that needs wins now, this session brings usable strategies, not buzzwords. Subscribe, share with a teammate who needs it, and leave a review to tell us which takeaway you’ll implement first.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Stop guessing which software to trust. We break down a clear, repeatable path to evaluate commercial off-the-shelf tools, open source projects, custom third‑party builds, and cloud services so you can pass CISSP Domain 8.4 with confidence and protect your environment in the real world. We start with exam-winning tactics—how to slow down, read for intent, and think like a manager—then move into concrete practices that tame software risk without stalling delivery.
You’ll hear how to interrogate vendor claims, separate real certifications from marketing fluff, and judge patch cadences and incident response maturity. We dig into open source realities: vetting contributors, scanning dependencies against the NVD, building and maintaining an SBOM, and avoiding abandoned projects that explode under pressure. For third-party development, we outline what strong contracts look like—SLAs with teeth, security clauses, indemnity—and the proof you should see: code audits, SAST/DAST, penetration tests, and meaningful logging around integrations.
Cloud isn’t a shortcut; it’s a shift in responsibility. We map the questions that matter for SaaS, IaaS, and PaaS: data protection, tenant isolation, hypervisor hardening, API security, and event visibility into your SIEM. Then we stitch it all into an evaluation workflow you can run every time: functional fit, vendor validation, layered security assessment, compliance and licensing review, sandbox integration testing, and a deployment plan that defines fix‑forward and rollback before anything hits production. Wrap it with monitoring, periodic reassessment, and documentation that procurement, IT, and security can actually use, and you’ve built a trustworthy software supply chain.
If this helped you think sharper about software risk and the CISSP exam, subscribe, share it with a teammate, and leave a quick review telling us your top vendor vetting question. Your feedback shapes future episodes.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
AI just found hundreds of high-severity vulnerabilities hiding in open source, and the market flinched. We dig into what Anthropic’s Claude Code Security actually means for security teams, why vendors like CrowdStrike and Okta aren’t going away, and how the real change lands on roles, workflows, and the skills you need next. From CI/CD integration to vulnerability discovery at scale, we frame where general models augment specialized tools and where human expertise still anchors the stack.
We also get tactical with five CISSP-style AI questions designed to sharpen your instincts. You’ll learn how adversaries reverse engineer decision boundaries to drive up false negatives, what adversarial examples look like in practice, and why adversarial training matters. We break down indirect prompt injection—how a crafted document can hijack an LLM to exfiltrate session data—and outline guardrails that actually reduce risk. Then we map AI risk using NIST’s AI RMF, focusing on the Measure function to evaluate potential harms to protected classes, and we unpack why federated learning still faces privacy leakage through gradient updates without differential privacy and secure aggregation.
If you’re in a SOC or building AppSec pipelines, this conversation gives you a blueprint to adapt: automate tier one triage, monitor for model drift, add OOD detection, and treat your models like code with tests, reviews, and rollbacks. If you’re planning your career, we share concrete pivot paths into detection engineering with ML, AI governance, and assurance. Want more hands-on practice and mentorship to pass the CISSP the first time and future-proof your skills? Subscribe, share this with a teammate, and leave a review with the next AI topic you want us to tackle.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Want a clear path from CISSP to top-tier pay without getting lost in buzzwords? We break down five high-income specialties that pair perfectly with CISSP leadership: modern GRC, cloud security as code, AI ethics and governance, advanced identity, and software supply chain security. Along the way, we unpack how AI reasoning tools like Claude Code Security are reshaping AppSec by cutting false positives and detecting logic flaws scanners miss, and we translate that shift into concrete workflows, better guardrails, and faster delivery.
We start with the career pivot many leaders are making—moving from generalist security management to “decision architect.” That means pairing risk fluency with hands-on understanding of Terraform, Kubernetes, and CI/CD gates, then proving value through resilient architectures and evidence-driven dashboards for boards. You’ll hear why GRC is exploding under new enforcement trends, how to automate continuous evidence to beat audit fatigue, and where vCISO opportunities command premium rates when strategy meets measurable outcomes.
From there, we get practical. We walk through cloud guardrails that stop drift before it hits prod, share how to navigate shared responsibility with AWS and Azure, and outline identity-first zero trust that tames API key sprawl and enables passwordless access. On AI, we go deep on shadow AI containment, prompt-injection red teaming, model transparency, and data loss prevention tuned for embeddings—governance that accelerates, not blocks. Finally, we turn to software supply chain security: SBOM mandates, signed artifacts, dependency risk, and the DevSecOps policies that keep pipelines moving while raising assurance.
If you’re mapping your next move, we also compare salary bands across roles and highlight bridge certifications—CISM for program leadership, AI governance credentials for compliance depth, and CISA for audit rigor—to level up fast. Subscribe, share this with a teammate plotting their niche, and leave a quick review to tell us which specialty you’re pursuing next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Half of CISSP candidates fail not because they lack knowledge, but because they answer like technicians when the exam demands a manager’s mindset. We dig into the three traps that derail smart people—technical heroism, perfect security fantasies, and the confusion of multiple “right” answers—and replace them with clear mental models that work under pressure. You’ll learn how to pick process over panic, see risk through the business lens, and choose the action that enables everything else.
We also dive into a timely security development: researchers demonstrate how permissive AI assistants with web browsing can act as covert command and control channels. If your network blocks known C2 nodes but allows AI egress, malware can route requests through an assistant to fetch malicious URLs—slipping past controls you trust. We talk through practical countermeasures: AI governance on par with high‑risk SaaS, disciplined inventory and policy control, enterprise logging and audit features, and the hard realities of traffic inspection and packet decryption without crushing reliability.
From there, we translate exam strategy into daily leadership. We outline the executive lens: decide who you are (risk manager), fix what the business cares about (continuity within risk appetite), and follow procedural DNA (assess, plan, execute). When a question asks what to do first, look for “assess the situation” or “consult the policy.” When choices seem equally solid, use a strict priority: life safety, legal and regulatory, business continuity, then assets and tech. And when tempted by the strongest control, match cost to value with proportional safeguards like full disk encryption and remote wipe for low-risk laptops.
If you’re ready to pass the CISSP and lead with clarity in an AI-shaped threat landscape, this conversation gives you the mindset, examples, and filters to get there. If it helped, follow the show, share it with a colleague, and leave a quick review—what trap do you see most often?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A router headline can feel distant until it lands in your network plan. We start with the growing chatter around possible TP-Link restrictions and what that means for ISPs, small businesses, and anyone balancing budget against risk. Then we roll up our sleeves and walk through the operational controls that actually hold the line when attackers probe, insiders slip, or vendors fail to deliver.
We break down principle of least privilege with practical steps: role-based access control reviews, automated provisioning tied to HR changes, and audit-ready logging that trims lateral movement without choking productivity. From there, we layer need-to-know onto data itself—classification that means something, ABAC for context like location and time, micro-segmentation to narrow reach, and data masking to reveal only what’s required. These moves reduce curiosity-driven access and keep sensitive information from leaking when an account gets compromised.
Money moves and high-stakes changes demand stronger gates. That’s where separation of duties and two-person control come in. We map how to split initiation and approval for transactions and admin changes, keep monitoring independent from administration, and add automation that routes approvals fast. To surface blind spots and fraud, we add job rotation and mandatory vacations—planned, documented, and measured to keep continuity while fresh eyes catch issues. For the riskiest identities, we get specific about Privileged Access Management: vaults, rotating credentials, and session recording that start with domain admins and expand carefully, with legacy integration checked up front.
Because third-party risk is your risk, we close with service level agreements that matter: clear scope, measurable uptime and response times, remedies that bite, data ownership that’s unambiguous, and explicit audit rights. Everything ties back to inventory discipline and a replacement roadmap, so regulatory shifts don’t turn into fire drills. Subscribe, share this with a teammate who owns access controls, and leave a review with the one control you’ll tighten this week.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Alarms go off, dashboards turn red, and leadership wants everything fixed yesterday—sound familiar? We dig into the real craft of vulnerability management: deciding what truly matters, when to defer safely, and how to protect customers while keeping the business moving. Along the way, we unpack the forces shaping 2025 security: AI-fueled threats, smarter cyber insurance, the edge of quantum risk, stricter privacy laws, and the rising stakes of DevOps security.
We share a practical triage framework that goes beyond CVSS. Learn how to validate scanner noise, confirm versions, and use a second tool when the data looks off. When patching collides with uptime or legacy systems, we outline compensating controls that actually reduce exploitability—segmentation, allow-lists, credential tightening, and targeted monitoring—plus the documentation and triggers that prevent “temporary” exceptions from turning permanent. You’ll hear how to communicate residual risk with time-bound plans and metrics leaders understand, from blast radius to downtime cost and insurance obligations.
Ethical disclosure gets real, too. When a researcher’s 30-day clock clashes with a 45-day fix, coordination beats confrontation. We talk through private progress updates, revised timelines, and interim mitigations that put users first. For vendors and open source, we highlight respectful escalation paths, legal prep, and why responsible disclosure typically reduces harm better than full, premature detail drops. In complex multi-cloud setups, we recommend assigning a cross-team coordinator who aligns priorities, patches the most exposed services first, and bakes checks into CI/CD so the next fix is faster.
Subscribe for more CISSP-ready breakdowns, share this with a teammate who lives in the patch queue, and leave a review with your toughest triage scenario—we might feature it next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The weakest link is often sitting on the edge, blinking away with expired firmware and no vendor support. We kick off with a blunt reality check on outdated firewalls, load balancers, and IoT gateways, and why waiting two years to retire them is a gift to attackers. From there, we guide you through Domain 7.7 with a practical blueprint for operating and maintaining detective and preventive measures that actually hold up under pressure.
We unpack firewall fundamentals with clear, real‑world tradeoffs: when a simple packet filter is enough, when stateful inspection and deep packet inspection earn their keep, and how a WAF stops the web attacks your L3/L4 controls will miss. You’ll hear how RTBH can deflect denial‑of‑service floods upstream, and why segmentation is your best friend for reducing blast radius—whether you use internal segmentation firewalls for R&D, Purdue‑style tiers for industrial networks, or controlled air gaps for the most sensitive systems. In the cloud, we separate security groups from true firewalls and show how to stitch policies across hybrid environments without creating blind spots.
Detection makes prevention smarter, so we break down IDS versus IPS in plain language. Baseline first, then block with intent to avoid outages. We compare host‑based and network‑based sensors, explain where to place them, and share tactics for cutting alert noise. You’ll also get straight talk on allowlists and blacklists, the right way to maintain them, and why stale entries cause the ugliest outages. We explore sandboxing for safe detonation and learning, and give an unvarnished take on honeypots and honeynets—where they help, where they waste time, and what legal lines to respect.
Not every team can build a 24x7 SOC, so we outline how MSSPs can extend your coverage with clear SLAs and ownership. Endpoint anti‑malware remains non‑negotiable, but tool sprawl is a trap—choose a strong EDR and manage it well. Finally, we dive into AI and machine learning: how they supercharge detection, triage, and response—and how adversaries use them too. The throughline is simple: shrink attack surface, raise signal quality, and respond faster than threats can pivot. If this helps you secure one more edge box or tune one more control, share it with a teammate, subscribe for more practical walkthroughs, and drop a review so we can keep raising the bar together.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A surprising number of security leaders admit they’re flying blind on hardware and firmware. We start by exposing how shared BIOS passwords, slow maintenance cycles, and careless e‑waste practices create avoidable risk, then lay out the fixes: privileged vaulting, disciplined asset disposition, and practical ways to repurpose gear without leaking data. That real-world foundation sets the stage for a focused tour through CISSP Domain 5—Identity and Access Management—built for practitioners who want clarity over jargon.
We break down least privilege in plain terms and show how to reduce the initial friction with cleanly defined roles and entitlement catalogs. From there, we compare RBAC and ABAC: when baseline roles are enough, and when context-aware attributes like device, location, and data sensitivity should drive policy. Authentication gets the same treatment. Multi-factor authentication, biometrics, and phishing-resistant methods raise the bar, while single sign-on and identity federation streamline access across cloud apps using standards like OAuth, OpenID Connect, and SAML. In modern cloud environments, token-based models win for scalability and security, and we explain why.
Governance ties it all together. We walk through identity proofing for solid onboarding, separation of duties to curb fraud, and IGA workflows that make approvals, recertifications, and audits far less painful. Regular access reviews emerge as the unsung hero that prevents privilege creep before it becomes an incident. If you’re prepping for the CISSP—or just tightening your IAM program—this episode gives you the why behind the what, with steps you can apply today.
Enjoyed the conversation and want more deep dives? Subscribe, share with a teammate who needs a quick IAM refresher, and leave a review to help others find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What happens when custom malware turns IoT into a springboard for OT, and gas pumps become levers for panic? We open with a timely look at Iranian-linked operations targeting PLCs and use that story to ground a full, practical tour of CISSP Domain 6.4: how to analyze scan output and generate reports that actually drive action.
We break down the anatomy of a high-value vulnerability report—clean executive summaries, CVE and CVSS clarity, and the business context that separates theoretical risk from real-world impact. From there, we map a repeatable cadence for internal scans full of misconfigurations, default creds, and end-of-life software, plus a strategy to turn noisy findings into steady wins through prioritization, trend metrics, and small, fast fixes that build momentum.
On the perimeter, we focus on external scans across web apps, APIs, cloud edges, and third parties. You’ll hear hard-earned tactics for handling M&A exposure, vendor VPNs, misconfigured buckets, and certificate drift without breaking production. We share validation steps that avoid false positives and chaos in prod, then show how to formalize exceptions with risk assessments, compensating controls, and an auditable register that satisfies PCI DSS, HIPAA, SOX, and GDPR expectations.
We close with ethical disclosure done right—timelines, ISO/IEC 29147 alignment, and when to coordinate versus publish—so you protect users and your organization without stepping into legal traps. If you’re studying for the CISSP or building a vulnerability management program that survives contact with reality, this guide will help you prioritize what matters, communicate clearly, and keep improving.
Enjoyed the show? Subscribe, share with a teammate, and leave a quick review so others can find it. Tell us: what metric best proves your remediation progress?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ransomware isn’t always after your data anymore—sometimes the goal is to burn your operations down. We open with a hard look at the Stoli bankruptcy and what it teaches about ERP paralysis, regulatory deadlines, and why “we’ll restore soon” is not a resilience plan. From there, we shift into a high-impact CISSP Domain 4 walkthrough that connects real-world failures to the protocols and controls that actually reduce risk.
We break down HTTPS beyond the lock icon—what it secures, what metadata remains exposed, and how certificate trust can be subverted. You’ll get a clear mental model for DNS defenses: why DNSSEC protects integrity but not confidentiality, and how DoH and DoT encrypt queries while complicating DNS filtering. We compare SFTP over SSH with FTPS, clarify LDAP StartTLS on port 389 vs LDAPS on 636, and explain the practical differences between IPsec transport and tunnel modes, including when ESP’s symmetric encryption is the right fit.
We also zoom in on TLS hygiene: why enabling TLS 1.0 or 1.1 invites downgrade and deprecated cipher risks, what HSTS really does (and doesn’t do), and why Perfect Forward Secrecy matters when adversaries stockpile encrypted traffic. And we call out a critical truth for both practitioners and exam-takers: HTTPS can’t stop phishing, so user trust and certificate validation remain frontline defenses.
If you’re preparing for the CISSP or leading security strategy, this episode gives you crisp explanations, memorable heuristics, and business-first context to improve your decisions. Subscribe, share with a teammate who handles compliance filings, and leave a review with the toughest crypto or network security question you want us to unpack next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Podcast Link(s): https://www.securityweek.com/cyber-insights-2026-api-security/
Agentic AI doesn’t just call your APIs; it creates them, connects them, and expands your attack surface faster than most teams can map it. We open with a frank look at autonomous agents, the Model Context Protocol (MCP), and why weak authentication, misconfigurations, and shadow APIs are still the easiest doors to pry open. Then we get tactical: continuous discovery, behavioral analytics, context-driven access, and the governance you need to monitor what AI spins up and revoke what shouldn’t exist.
From there, we shift to the CISSP core: end of life, end of support, and the asset retention practices that keep you compliant and resilient. We define the terms, share real-world pitfalls, and outline practical sunsetting plans that include data migration, isolation when necessary, and rock-solid disposal. Documentation is the quiet hero—config backups, change logs, destruction certificates, and retention schedules shaped with legal and compliance. Over-retention inflates breach impact and cost; under-retention invites fines and operational gaps. We walk through legal holds, immutable backups, and the cost conversations that stop data hoarding.
By the end, you’ll have a clear blueprint: integrate lifecycle management into procurement, track vendor notices, consider extended or third-party support when needed, and use compensating controls for what must linger. Train your teams, audit your process, and map ownership so you can prove what you keep, why you keep it, and when you delete it. If you’re ready to tighten API security and retire legacy systems without breaking the business, this one’s for you. Subscribe, share with your team, and leave a quick review to help others find the show. What legacy system will you decommission first?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Podcast Link(s): https://www.cisa.gov/news-events/news/dhs-launches-over-100-million-funding-strengthen-communities-cyber-defenses
Cyber attacks don’t skip small towns, and today we dig into how local governments can turn policy into protection. We start with the new funding landscape for state, local, tribal, and territorial agencies—what’s approved, where the dollars flow, and why alignment with CISA and the NIST Cybersecurity Framework is the difference between good intentions and measurable risk reduction. From staffing gaps to critical infrastructure dependencies, we break down a practical way to prioritize controls, track progress, and build lightweight governance that keeps projects moving and leaders informed.
Then we pivot into CISSP Domain 1.8 with real scenarios that security teams face every week. What do you do when phishing simulations stall at a 40% click rate? We outline how to redesign awareness with role-based content, immediate coaching, and the right technical controls to lower human-driven risk. What’s the right response when a new admin refuses to sign an NDA? Bring legal in, set the standard, and be ready to stand firm on conditions for sensitive access. We also unpack training repayment disputes during offboarding and why access revocation, asset return, and exfiltration monitoring must come before chasing dollars.
We don’t stop there. An employee’s personal cybersecurity blog can be a liability or an asset—depending on how you set guidelines and review content. And when insider risk hits hard—a soon-to-be-terminated analyst copying files to a USB drive—the immediate play is decisive: disable access, secure devices, preserve evidence, and coordinate with HR and legal. Throughout, we keep the focus on clear policy, consistent enforcement, and actionable steps that work for resource-constrained teams as well as larger enterprises.
If you’re a security leader, an aspiring CISSP, or the de facto defender for a small community, you’ll leave with concrete actions to raise your defenses, educate your people, and respond fast when signals turn red. Subscribe, share this with a teammate who needs a sharper playbook, and leave a review to help more practitioners find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A quiet identity revolution is underway, and it’s not about people. CrowdStrike’s move to acquire Signal shines a light on the fastest‑growing attack surface in modern environments: non‑human identities. From AI agents and APIs to service and machine accounts, these credentials outnumber employees, hold powerful permissions, and often live outside traditional IAM hygiene. We unpack why this matters now, how it reshapes identity security strategy, and what it means for your Business Impact Analysis and continuity planning.
We walk through a clear, exam‑ready BIA flow that translates risk into action. You’ll learn how to frame impact categories, build time‑based escalation paths, and set realistic RTO, RPO, and maximum tolerable downtime in partnership with the business. We dig into prioritization drivers—safety of life, legal mandates, revenue exposure, and customer obligations—and show how to avoid the trap of “non‑essential” processes that quietly block recovery. Along the way, we map threats, vulnerabilities, and controls, then score risk with likelihood and impact using real sources like historical incidents and threat intelligence.
From there, we get practical: process workarounds, technology redundancy, workforce continuity, and supply chain resilience with alternate vendors and stockpiles. We compare hot, warm, and cold sites to cloud‑based recovery, and we stress selection criteria like cost, risk tolerance, and whether strategies actually hit your recovery targets. Finally, we cover governance and communication: executive approvals, confidentiality of plans, testing from tabletop to full interruption, vital records protection, and smooth transitions from life safety to business operations. The throughline is simple and powerful: business impact drives recovery priorities, not technology. Subscribe, share with a teammate who owns service accounts, and leave a quick review to help others find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Cybercrime now runs like a tech startup—with roles, KPIs, and customer support—while most defenders are stuck in annual review cycles. We dive into how this underground economy operates as a service chain, why ransomware-as-a-service lowers the barrier to entry, and what leaders can do to close the agility gap. From faster iteration to data-driven decisions, we map out a defense that keeps pace with attackers rather than reacting months later.
We also shift into CISSP Domain 1.8 with scenario-driven insights you can apply today. You’ll hear how to design an insider threat program that respects privacy while delivering real defense in depth, including behavior analytics, transparent monitoring policies, and legal and HR oversight. We break down the executive-level risk when background checks slip during mergers, the right first move when a senior developer with admin access gives notice to join a competitor, and how to navigate employment gaps without crossing legal or ethical lines. Then we take on a thorny integrity case: a cloud security architect who lied about a required certification. Policy clarity, culture, and legal risk all collide—and we walk through the reasoning.
Throughout, we connect the AI arms race to practical security outcomes. Attackers are using AI to craft better phishing and faster exploits; defenders need AI for correlation, anomaly detection, and automation—without sacrificing governance. The throughline is speed with discipline: shorten feedback loops, harden the human layer, and align security operations to measurable risk reduction.
If you’re preparing for the CISSP or leveling up your security leadership, this episode blends strategy with concrete steps you can implement now. Subscribe, share with your team, and leave a review to tell us which scenario challenged your thinking most.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Start with the reality check: today’s AI-enabled businesses face nine fast-evolving risks—data poisoning, model tampering, tool poisoning, prompt injection, adversarial inputs, model theft, model inversion, supply chain exposures, and jailbreak techniques. We break each one down in plain terms to show how attackers manipulate training data, models, and the pipelines around them, then connect those threats to the operational stakes leaders care about: safety, brand, legal exposure, and customer trust.
From there, we shift gears into a practical continuity blueprint. We clarify the difference between BCM, BCP, and DRP—governance, process continuity, and tech recovery—so you can prioritize business outcomes before buying tools. You’ll hear a clear approach for scoping by criticality, setting a planning horizon for short disruptions and long outages, and aligning with enterprise risk management so recovery targets match risk appetite and mission. We also walk through organizational analysis, stakeholder roles, and the often-missed step of mapping upstream suppliers and downstream distributors alongside cloud, SaaS, and utilities.
The middle third focuses on execution. We outline how to build the BCP team with real decision authority, ensure succession and time-zone coverage, and run tabletops that expose single points of failure—like that forgotten server in a closet or a license that blocks failover. Then we cover resource planning across people, technology, facilities, vendors, and funding, including emergency spend, insurance alignment, and utility commitments for alternate sites. We close with regulatory expectations, SLAs, and the need for documented testing and continuous improvement so audits and real incidents both go better.
If you found this helpful, subscribe, leave a quick review, and share it with a teammate who owns risk, compliance, or operations. Your support helps more CISSP candidates and security leaders build resilience that actually works when it counts.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What happens when your “helper” becomes your riskiest insider? We dig into the fast-approaching reality of AI agents acting with superuser access, approving transactions, and even signing contracts—creating doppelganger identities that expand attack surfaces in unexpected ways. Drawing from recent headlines and real operations experience, we break down how least privilege, identity governance, and auditable workflows can keep autonomy from turning into an open door.
From there, we get tactical with CISSP-grade scenarios that force hard choices under pressure. An unauthorized “emergency” firewall change takes down a service—how do you keep agility without chaos? A SOC drowns in 10,000 alerts a day—what truly cuts noise while catching multi-stage attacks? We make the case for SOAR playbooks that enrich, correlate, and act, turning acronym soup into a coherent response engine. When teams push back on PAM, we show how to implement full recording and vaulting without slowing incidents by using auto-approved, time-bound emergency access and strict post-incident review.
Then we navigate the thorniest problem in modern defense: patching during active exploitation when fixes break critical APIs. Instead of hair-on-fire deployments or risky delays, we map compensating controls—WAF hardening, segmentation, and targeted monitoring—while working toward a compatible patch path. And when a high-value database shows 45 days of persistence, we explain how to capture live memory and disk snapshots, coordinate isolation during a maintenance window, and communicate risk tradeoffs to leadership without tipping attackers or losing evidence.
If you want clear, applied guidance on AI insider risk, emergency change control, alert fatigue, PAM adoption, patch strategy, and forensics versus uptime, this conversation delivers practical answers you can put to work today. Subscribe, share with your team, and leave a review—what decision here changed how you’ll handle your next incident?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Your TV, camera, or even a smart bird feeder can be a beachhead for attackers. We dive into the Kimwolf botnet and expose how low-cost IoT turns into residential proxies that scan, DDoS, and quietly pivot across your home or enterprise network. From weak defaults and exposed ADB to shady apps, we call out the telltale signs and the simple architecture changes that shut the door: dedicated IoT VLANs, strict egress controls, and logging that actually sees what leaves your network.
Then we switch gears into CISSP Domain 7.1 and break down what a defensible investigation looks like when the alarms go off. Evidence collection starts with a mindset: don’t touch originals, document everything, and assume you’ll need to defend the process in court. We cover IOCE-aligned practices, creating bit-for-bit copies with hashes, and when to engage a forensic retainer so you are not building a plan mid-incident. Memory captures, media recovery, network telemetry, and software analysis all play a role in reconstructing the timeline and proving what happened.
Legal readiness sits at the core. We talk about involving counsel early, understanding insurer-approved panels, and mapping out rules of engagement for interviews and device access in your IR policy and onboarding. We clarify evidence authorities—voluntary surrender, subpoenas, and search warrants—plus the three evidence types and how chain of custody preserves admissibility. By the end, you’ll have a clear blueprint: segment IoT, monitor outbound traffic, and run investigations that survive scrutiny.
If this helped sharpen your security playbook, subscribe, share with your team, and leave a quick review to help others find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ready to turn CISSP Domain 3.5 into practical moves you can deploy on Monday? We unpack how real SOC teams apply microsegmentation, identity-aware controls, and targeted inspection to crush lateral movement without dragging performance. Along the way, we demystify AI’s role: where detection engineering benefits from crisp use cases, how Tier 1 triage speeds up, and why models still need human oversight and rigorous validation to stay trustworthy.
We also step through common network design traps that drain budgets and weaken defenses. VLAN sprawl looks tidy on paper but collapses under hybrid cloud dynamics. Central chokepoints promise control yet introduce latency and single failure domains. The smarter path is selective inline inspection where risk is highest, strong encryption everywhere else, and host-based enforcement that understands identity and context after decryption. If you’ve been tempted to collapse controls into one “do-everything” appliance, we lay out the hidden cost: a fragile core that turns into a single point of failure when you need it most.
To ground the theory, we walk through scenario-style questions that mirror real decisions security leaders face: stopping east-west movement, balancing HA with inspection, drawing zero trust boundaries that don’t assume implicit trust, and enforcing policy on encrypted traffic. You’ll leave with patterns you can adapt immediately: start small, define use cases, validate outputs like code, and iterate with tight feedback loops. Whether you run a SOC, partner with an MSP, or are targeting a first-time CISSP pass, this conversation gives you a clear map from concept to control. If this helped, follow the show, share it with a teammate, and leave a quick review so others can find it too.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A neighboring Wi‑Fi, a handful of stolen credentials, and a quiet leap into a high‑value network—the kind of pivot that sounds cinematic until you realize how practical it is. We unpack that playbook and turn it into concrete defenses you can deploy across your environment, from client endpoints and browsers to databases, servers, and industrial control systems.
We start at the edge, where phishing, drive‑by downloads, and man‑in‑the‑middle still win far too often. You’ll get a clear blueprint for upgrading endpoint security with EDR, strict patching, and browser hardening, plus when to retire or sandbox legacy applets and how to stop sensitive data bleeding from local caches. From there we map the landscape of modern data platforms: the internal, conceptual, and external layers of databases; the resilience of distributed DBs; the interoperability and pitfalls of ODBC; and the security tradeoffs between NoSQL flexibility and relational ACID guarantees. Expect practical guardrails like TLS on every link, parameterized queries for SQLi defense, and role‑based access with tight segregation of duties.
Finally, we focus on servers and ICS, where downtime costs real money and, in OT, can impact safety. Learn how to prioritize hardening and patching without breaking legacy apps, isolate critical services to reduce blast radius, centralize logging to a SIEM, and apply the Purdue model to segment OT from IT. We share tested moves for OT environments—firewalls and DMZs, constrained remote access, realistic backup and recovery plans—and explain how to integrate safety and cybersecurity so alarms, procedures, and people work as one.
If you find this valuable, subscribe, share it with a teammate who owns Wi‑Fi or databases, and leave a quick review telling us the first control you’ll implement this week. Your feedback helps more practitioners discover tools that actually reduce risk.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
One unauthenticated request should not be all it takes to compromise your app—but with React-To-Shell, that’s the reality many teams are facing. We unpack what this vulnerability hits across React server components and Next.js app router setups, why default configs can be enough to fall, and how active threat actors are already abusing it. From construction to entertainment to cloud-native platforms, the exposure is broad, the proofs are reliable and the window for safe procrastination has closed.
We share a clear action plan: upgrade affected versions now, rotate secrets that touch your React servers, and turn on relevant WAF protections from providers like Cloudflare and Microsoft. Then we widen the lens to the bigger lesson: security testing that looks mature on paper can still miss API edges and misconfigurations for months. You’ll hear why credentialed vulnerability scans with passive monitoring are the lowest-impact way to surface issues in production, how “medium” findings can chain into critical compromise, and when external assessors deliver the most value for resilience rather than routine compliance.
To make testing count without breaking customer-facing services, we walk through purple teaming—pairing red team attacks with blue team collaboration—to validate both technical controls and security awareness. We cover scoping rules that prevent disruption, scenarios that mirror current tradecraft, and practical CISSP takeaways for domain coverage on assessments, software security and third-party risk. If your web stack touches React, or your program relies on scans and annual pen tests alone, this is your checklist and your nudge to act.
If this helped you prioritize what to fix first, subscribe, share with a teammate and leave a quick review—it helps more security folks find us and harden faster.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A single convincing email can move real money. We break down how Scripted Sparrow and other BEC crews spoof reply chains, impersonate trusted service providers, and slip under approval thresholds to nudge finance teams into wiring funds. The threat isn’t flashy malware; it’s pressure, process gaps, and the illusion of internal approval. We talk through the red flags that matter, from sudden vendor banking changes to realistic W9 attachments and urgent payment timelines, and then lay out the safeguards that stop these scams cold.
From there, we zoom out to the full incident management lifecycle and make it practical. You’ll hear how we define an incident by its impact on confidentiality, integrity, and availability, and why that clarity speeds action. We map the steps—detection, response, mitigation, reporting, recovery, remediation, and lessons learned—and explain what they look like in a real company: one-click phishing reporting for employees, prepared legal statements for regulators, isolation choices that protect revenue, and documentation habits that pay off when auditors and insurers start asking questions.
We also get honest about today’s attack surface. Cloud sharing, APIs, and over-permissive identities push sensitive data to the edge, making containment harder if an attacker lands. Expect persistence: backdoors, credential reuse, and lateral movement thrive when local admin rights and flat networks remain. The antidote is a blend of stronger finance workflows, pre-briefed legal and communications teams, and regular tabletop drills that involve everyone who touches money, systems, or messaging.
If you’re serious about preventing wire fraud and surviving security incidents with your business intact, this conversation gives you a focused plan you can adopt today. Subscribe, share with your finance and HR leaders, and leave a review with the one control you’ll implement first.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Headlines say the talent shortage is easing, yet nearly half of UK businesses still lack basic cyber skills. That disconnect sets the stage for a frank, practical tour through what actually reduces risk—no buzzwords required. We open with real takeaways from the UK’s international cyber skills initiatives and move quickly to the daily decisions that shape resilience: encryption in the cloud, least privilege by default, and how to keep role-based access control from collapsing under credential creep.
We make the identity layer tangible. Single sign-on can simplify life and lower password reuse, but it also centralizes risk. We share how to counterbalance SSO with MFA, conditional access, and strong monitoring. Cloud-based IAM accelerates deployment and gives flexibility, yet brings ongoing costs and integration challenges with legacy systems; outsourcing introduces a loss of control that must be offset by airtight requirements, auditability, and vendor transparency. Phishing remains the most reliable social engineering vector, so security awareness training isn’t optional—it’s the routine that turns policy into behavior.
Zero trust becomes manageable when you stop treating it like a switch and start treating it like a program. We outline a phased path: define protect surfaces, segment by sensitivity, apply continuous verification where the impact is highest, and expand deliberately. Vendor access deserves the same precision: NDAs for legal guardrails, least privilege for scope, monitoring for assurance, and scheduled reviews to remove stale permissions. Along the way, we talk mentorship, pro bono work, and competitions as concrete ways to grow talent while delivering real security outcomes.
We also road-test your knowledge with a focused Domain 1.9 CISSP question set, reinforcing the core ideas with scenario-based reasoning. If you’re preparing for the CISSP or leading a security program, you’ll walk away with a clear playbook: encrypt by default, minimize access, verify continuously, and measure what matters. If this resonates, subscribe, share with a teammate, and leave a review so others can find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What happens when cybersecurity meets the engine room of the business? We dig into the partnership between the CISO and COO and show how shared risk, clear language about money, and practical tabletop drills turn security into operational resilience. Ransomware, supply chain delays, and customer impact aren’t just IT issues—they’re revenue issues—so we map exactly how to build alignment before a crisis hits.
We break down CISSP Domain 1.5 with a plain-English tour of law categories and the statutes you actually need to know: CFAA and NIIPA for unauthorized access and critical infrastructure, FISMA and the NIST standards for federal-grade security programs, and the federal modernization that centralized oversight under DHS. Then we go deeper into intellectual property: what copyrights, trademarks, patents, and trade secrets protect; how DMCA and AI complicate ownership; and how licensing and click-through terms can quietly put your data and code at risk if you don’t read them with counsel.
Cross-border data is now daily business, so we unpack export controls on chips and encryption, transborder data flow obligations, and privacy regimes that carry real teeth: GDPR’s 72-hour notification, China’s PIPL and local representation, and state laws like CCPA that mirror EU rights. The practical takeaway is a tighter incident playbook: define “breach” with evidence-based thresholds, pre-wire stakeholder communications, and use tabletop exercises to test both technical recovery and regulatory reporting.
If you’re studying for the CISSP or leading a security program, this is the legal-ops blueprint you can use today. Subscribe, share this with your ops and legal teams, and leave a review to tell us which regulation gives you the biggest headache—we’ll tackle it next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Headlines about eight Chrome zero days aren’t just noise—they’re a prompt to act with precision. We open with the fastest, most reliable steps to reduce exposure: force updates with MDM, restart browsers to trigger patches, narrow to a hardened enterprise browser, and brief your SOC to tune EDR for active exploit patterns. You’ll get a focused checklist that’s quick to run and easy to defend to leadership.
From there, we turn the lens to CISSP Domain 8 with five questions that teach more than they test. We explain why strict schema validation for JSON beats blanket escaping, and how misuse and abuse case analysis during requirements gives you the strongest assurance that security is built into design, not bolted on. We also break down supply chain risk in CI/CD with a practical recipe: software composition analysis, cryptographic signature checks, internal artifact repositories, and policy gates that block malicious or license-violating packages before they ship.
Design flaws are the silent killers. We highlight a common mistake—putting sensitive business logic in the browser—and show how to move decisions server-side, validate every request, and protect against client tampering. Finally, we get tactical about containerized microservices: image signing plus runtime verification, read-only filesystems, minimal base images, and network policies that enforce least privilege. These are the controls that turn incident response into a manageable drill, not a firestorm.
If you’re preparing for the CISSP or leading an engineering team, you’ll leave with strategies you can apply today: browser patching that sticks, threat modeling that finds real risks, SCA that calms your pipeline, and container security that proves runtime trust. Enjoyed this conversation? Subscribe, share with a teammate, and leave a quick review to help more people find it.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A single malicious insider flipped Disney menus to Wingdings and tampered with allergy labels—proof that weak offboarding and sloppy access can turn small privileges into big threats. We take that lesson and translate it into a practical roadmap for secure software: clear requirements, security controls in design, disciplined code reviews, honest UAT, and change management that prevents chaos and rollback roulette.
From there, we compare the major development models through a security lens. Waterfall shines when predictability and compliance evidence are non‑negotiable, with strong documentation and defined testing phases. Spiral brings a risk-first mindset, iterating through planning, analysis, engineering, and evaluation so teams can learn early and pivot with purpose. Agile and DevSecOps embed security into user stories, definition of done, and sprint reviews, using short cycles, prioritized backlogs, and continuous testing to catch vulnerabilities before they calcify into technical debt.
We also put structure around improvement. The Capability Maturity Model shows how to move from ad hoc heroics to standardized, measurable, and optimized practices that satisfy auditors and reduce incidents. The IDEAL model guides change itself—initiate with sponsorship, diagnose gaps, establish plans and metrics, act through implementation and training, and learn via feedback and retrospectives—so security improvements stick. Throughout, we share practical tips: how to weigh security controls against usability, why executive support unlocks real progress, and how to choose the right lifecycle for your risk, regulation, and release cadence.
If you’re preparing for the CISSP or leading teams that ship software, this is your playbook for building security into every step without slowing down what matters. Enjoyed the conversation? Subscribe, share with a teammate, and leave a review with your biggest SDLC win—or your most painful lesson.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A headline about hacked nanny cams is more than a cautionary tale—it’s a mirror for how easily convenience eclipses security. We start with the Korean IP camera case to highlight simple, high-impact steps anyone can take: change default credentials, use unique passwords, turn off remote access unless you truly need it, and keep firmware current. Then we ask the harder question: how do you prove security works when the stakes are higher than a living room feed?
Shifting into CISSP Domain 6, we break down audit readiness, independence, and risk-based assurance. If you’re eyeing ISO 27001, the smartest first move is an internal audit program aligned with the standard’s control objectives. It validates design and operating effectiveness before an external auditor walks in, and it surfaces the documentation and evidence gaps that slow teams down. We also unpack governance: when boards want independent assurance, the audit function should report outside IT. Self-assessments still help, but they don’t replace a real audit.
Risk should lead, not scanner severity. Consider a “medium” vulnerability on a critical payment system that demands authenticated access and precise timing. Rather than knee-jerk patching or dismissal, a structured risk analysis weighs business impact, likelihood, and compensating controls like monitoring and segregation of duties. That approach drives better prioritization and stronger outcomes.
For ongoing evaluation, snapshots alone aren’t enough. Instead of doubling costly SOC 2s, blend risk-based self-assessments, targeted internal audits, and continuous monitoring to maximize coverage and value. And when your cloud provider won’t allow pen tests on shared PaaS, you can still gain assurance: request SOC 2 Type II, ISO 27001, and pen test summaries under NDA, then map their scope and results to your control requirements and risk appetite. Close gaps with compensating controls and a clear shared responsibility matrix.
If you’re preparing for the CISSP or modernizing your assurance program, this conversation will help you cut noise, focus effort, and build confidence where it counts. Subscribe, share with a teammate who handles audits, and leave a review to tell us what assurance challenge you want solved next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
If audits feel like paperwork purgatory, this conversation will change your mind. We unpack Domain 6 with a clear, practical path: how to scope a security audit that executives will fund, teams will follow, and regulators will respect. Along the way, we touch on a fresh angle in the news—an open source LLM tool sniffing out Python zero days—and connect it to what development shops can do right now to lower risk without slowing delivery.
We start by demystifying what a security audit is and how it differs from an assessment. Then we get into the decisions that matter: choosing one framework to anchor your work (NIST CSF, ISO 27001, or PCI DSS where applicable), keeping policies lean enough to use under pressure, and building a scope that targets high-value processes like account provisioning or privileged access. You’ll hear why internal audits build muscle, external audits unlock credibility, and third-party audits protect your supply chain when a vendor stalls or gets breached. We talk straight about cost, bias, and the communication gaps that derail progress—and how to fix them.
From there we focus on outcomes. You’ll learn to prioritize incident response and third-party risk for the biggest return, write right-to-audit clauses that actually help, and map findings to business impact so leaders say yes to headcount and tooling. We share ways to pair tougher controls with enablement—like deploying a password manager before lengthening passphrases—so adoption sticks. Expect practical reminders on interview planning, evidence collection, and keeping stakeholders aligned without burning goodwill. It’s a playbook for turning findings into funding and audits into forward motion.
If this helped you reframe how you approach Domain 6 and security audits, subscribe, leave a review, and share it with a teammate who’s staring down their next audit. Your support helps more people find CISSP Cyber Training.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Zero trust isn’t a checkbox or a buzzword; it’s a mindset shift that changes how we design networks, ship code, and protect data. We dig into what “never trust, always verify” actually looks like when you have a messy reality: hybrid clouds, legacy apps living next to microservices, and users hopping on through VPNs that still grant too much access after MFA.
We start with a timely lesson from an AI analytics supplier breach to show why third-party integrations can be your Achilles heel. From there, we map out where policy should live and how it should be enforced: near the workload, with PEPs at gateways or in a service mesh, and a central PDP to keep logic consistent while decisions happen at wire speed. You’ll hear why relying on VLANs, static ACLs, or a “trusted subnet” breaks the zero trust promise, and how to move toward per-request evaluation that accounts for identity, device posture, location, and behavior.
Then we go data-first. Labels, encryption, and rights management let policies travel with sensitive files, so access and usage rules hold even off-network. We contrast ZTNA with legacy VPNs, explain how to avoid turning MFA into a broad hall pass, and share a realistic migration path: start with one critical application, microsegment around it, validate performance and usability, and expand. This is the playbook that reduces lateral movement, shrinks blast radius, and helps you pass the CISSP with real-world understanding.
If this resonates, subscribe, share with a teammate who’s designing access controls, and leave a review with your biggest zero trust roadblock. Your feedback helps shape future deep dives and study guides.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security programs fail when they try to do everything at once. We walk through a clear three-phase plan that keeps you focused and effective: start with a real gap assessment anchored in leadership’s risk tolerance, convert findings into decisions to mitigate, accept, or transfer risk, and then implement with a balanced mix of people, process, and tools. Along the way, we share what to look for when hiring a virtual CISO and how to turn that engagement into actionable momentum instead of another shelfware report.
From there, we tighten the perimeter by defining bounds that keep systems within safe lanes: role-based access control, data classification, DLP, segmentation, encryption, and change management that shrinks blast radius. We get tactical with process isolation, sandboxing, capability-based security, and application whitelisting, plus a grounded comparison of MAC vs DAC and when a hybrid model makes sense. Defense in depth ties it together with physical safeguards, network protections, EDR and patching, application security practices, and data security. We keep the human layer practical with targeted awareness training and a tested incident response plan.
Resilience is the throughline. We advocate for secure defaults and least privilege by design, logging that’s actually reviewed, and updates that apply on a measured cadence. When things break, fail safely: graceful degradation, clean error handling, separation of concerns, redundancy, and real-world drills that expose weak spots early. Governance keeps the program honest with separation of duties, dual control, job rotation, and change boards that prevent unilateral risk. Finally, we demystify zero trust: start small, micro-segment your crown jewels, verify continuously, and respect cloud nuances without overcomplicating your stack.
If this helps you clarify your next move, follow the show, share it with a teammate, and leave a quick review so others can find it. Tell us: which phase are you tackling first?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Words can trigger audits, budget panic, or calm execution, and few words carry more weight than “leak” and “breach.” We unpack the real differences, the legal and regulatory implications of each, and how precise language shapes incident response. From there, we get hands-on with CISSP-ready concepts—data states, DLP, CASB, DRM, minimization, sovereignty, and sensitivity labels—and translate them into moves you can make this week.
We start by mapping data states—at rest, in transit, in use—and explaining why data in use often deserves the strongest controls. You’ll hear how teams over-index on storage encryption while under-protecting live workflows, and how to fix that with device posture checks, least privilege, just-in-time access, and application-layer monitoring. Then we dive into data minimization: setting clear retention rules, automating deletion, and killing the “we might need it someday” habit that inflates breach impact and eDiscovery pain. Along the way, sensitivity labels become the glue for governance, tying classification to access, encryption, and audit.
Next, we stress-test common tools. DLP is great at stopping careless exfiltration but struggles with insiders who have legitimate access, so we show how to tune policies, coach users, and add approvals for mass exports. DRM protects intellectual property but introduces compatibility and friction; we outline how to pilot it with high-value content and measure productivity impact. For cloud journeys, CASB delivers visibility into sanctioned and shadow SaaS, enforces consistent policies, and even helps manage data egress costs—vital for budgets and compliance. Finally, we navigate data sovereignty, cross-border flows, and practical tactics like regional storage, masking, and pseudonymization to keep regulators satisfied and data safe.
Whether you’re studying for the CISSP or leading security strategy, you’ll leave with clear definitions, sharper communication, and a toolkit for governing what you keep, protecting what you use, and deleting what you don’t. If you found this helpful, subscribe, leave a review, and share it with a teammate who still calls every incident a breach.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A graphing calculator running ChatGPT might make headlines, but our real job is keeping sensitive data from walking out the door. We break down the data states that matter most—at rest, in transit, and in use—and show how to pair encryption, access control, and monitoring without drowning in complexity. Along the way, we share a pragmatic blueprint for classification and labeling that teams actually follow, from visual tags and watermarks to tightly governed upgrade and downgrade paths that keep owners accountable.
From there, we zoom out to strategy. Risk tolerance drives control selection, so we talk through scoping and tailoring: how to apply NIST and ISO 27001 sensibly, where GDPR and HIPAA come into play, and why focused logging beats “collect everything” fantasies. You’ll hear the real differences between DRM and DLP—licensing and usage enforcement versus data path control—and when each tool earns its keep. We also lay out transfer procedures that work in the wild: SFTP with verified keys, email encryption, FIPS‑validated USBs, and restricted cloud shares with time‑boxed access.
Cloud isn’t a blind spot when a CASB sits between your users and SaaS. We explain how a CASB delivers visibility into shadow IT, enforces policy across apps, integrates with identity for conditional access, and even helps you rein in egress costs. Tie it all together and you get a layered, test‑ready approach that helps you pass the CISSP while protecting what matters most. If this helped sharpen your plan, follow the show, share it with a teammate, and leave a quick review so we can keep building tools that move you forward.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A single compromised API key can undo months of hard work. We open with a clear-eyed look at a reported Treasury-related incident tied to a privileged access platform and use it to expose a bigger problem: API governance that lags behind development speed. If an API is a doorway into your environment, why do so many teams leave it unlocked, unlogged, and unmanaged? We share a practical blueprint for centralizing API traffic through gateways, tightening authentication, rotating keys, and getting real visibility into what flows in and out.
From there, we dive into CISSP Domain 1.6 with crisp, exam-style questions that double as leadership lessons. We compare civil and criminal standards of proof, explain where regulatory investigations fit, and show how penalties differ across case types. You’ll hear why chain of custody can make or break a criminal data theft case, how direct and circumstantial evidence complement each other, and what lawful collection requires under search and seizure laws. Along the way, we clarify GDPR’s reach, the role of the SEC in insider trading probes, and how ECPA, CFAA, and FISMA divide responsibilities across privacy, computer crime, and federal system security.
We also make the case for forensic readiness as a standing control, not a post-breach scramble. Centralized logging, synchronized time, packet capture on critical paths, immutable storage, and clear retention policies give you faster answers and stronger footing with regulators. Inside the organization, administrative investigations live or die by policy clarity, and whistleblower protections keep truth-tellers safe enough to speak. By the end, you’ll have tangible steps to harden APIs, gather admissible evidence, and navigate the maze of legal and regulatory expectations with confidence.
If this helped sharpen your thinking, follow the show, share it with a teammate who owns APIs or incident response, and leave a quick review so others can find us. Your feedback guides what we tackle next.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A tiny payload hidden in a legitimate-looking NuGet package can sit inside an industrial network for years, then trigger cascading failures in minutes. That chilling scenario sets the stage for a hands-on tour of CISSP Domain 1.4, where we show how to turn high-level rules into clear, defensible security controls that protect real systems and pass tough audits. We connect the dots between contracts that demand fast breach notifications, laws with sector-specific obligations, and frameworks that teach you how to structure your program.
We break down the essentials: identify the data in scope, pick a backbone framework (ISO 27001 or NIST CSF), and map each requirement to specific controls and evidence. You’ll hear practical mappings for HIPAA, GLBA, COPPA, FERPA, NYDFS, DORA, SOX, FISMA, and PCI DSS, plus how to handle extraterritorial reach under GDPR and data localization that shapes your cloud strategy. We also highlight why contractual terms often outrun statutes and how to build a requirements register so operations knows exactly what to log, how fast to notify, and which controls must exist.
Then we get tactical. Learn how to create a regulatory register, assemble audit-ready proof (policies, procedures, configs, logs, training, attestations), and run incident tabletop exercises that include vendors and clarify when the notification clock starts. For industrial environments with rare patch windows, we offer pragmatic steps: maintain a software bill of materials, verify package sources, enforce code signing where possible, document every change, and compensate with monitoring and segmentation when upgrades are risky. By the end, you’ll have a blueprint to translate compliance into resilience—fast enough for 72-hour breach clocks, strong enough to handle delayed threats, and simple enough to sustain.
Subscribe for more CISSP-ready training, share this episode with your security team, and leave a review to help others find the show. What framework are you mapping to today?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Ransomware doesn’t wait for your change window, and neither do we. This episode takes you inside the decisions that matter when privileged accounts start hopping across systems, Exchange servers attract fresh exploits, and the clock is running on recovery. We open with the newest CISA guidance on Microsoft Exchange and translate it into moves you can apply today: enforce least privilege with a real PAM, choose stronger MFA than SMS, disable basic auth, and lock in transport protections that withstand downgrade tricks.
From there, we get practical about TLS and HSTS. Rolling TLS everywhere sounds simple until certificates, ciphers, and legacy services push back. We map a staged path that starts with critical links, reduces misconfigurations, and grows coverage without breaking internal apps. HSTS then adds a policy backbone that reduces user error, blocks session hijacking, and tightens browser behavior, with clear notes on latency, preload lists, and subdomain scope.
When incidents hit, priorities flip. We break down the right call when lateral movement continues during a ransomware event: disable privileged accounts and switch to preapproved emergency access. On evidence handling, we reinforce the nonnegotiable step for integrity—cryptographic hashing before and after imaging—plus secondary measures for custody and confidentiality. Disaster recovery gets the same scrutiny: meeting RTO while missing RPO means your backup cadence or replication policy failed, not your failover drill. We also cover immutable logs with WORM storage to prevent admin tampering and why emergency patches should be followed by a retrospective CAB review to keep governance intact after the fire is out.
If you’re preparing for the CISSP or sharpening day-to-day security operations, this session delivers clear, actionable guidance you can put to work immediately. Subscribe, share with your team, and leave a review to help more practitioners find these practical playbooks. What’s the one control you’d implement tomorrow to cut lateral movement in half?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
A single Windows shortcut can open the door to espionage—and that’s exactly where we begin. We break down a fresh LNK exploit campaign to show how hidden command execution and DLL sideloading slip past busy teams, then pivot into the core defense most organizations underuse: disciplined configuration management. From baselines and version control to change boards and rapid rollback, we map the habits and tools that turn chaos into control.
We walk through building secure, realistic baselines with CIS Benchmarks and NIST 800‑128, and why “simple and enforceable” beats “perfect and ignored.” You’ll hear how least privilege for change stops shadow tweaks, how EDR and application firewalls catch command and control, and how automation with Ansible, SCCM, and Terraform keeps fleets consistent. We spotlight the CMDB as a living source of truth—only valuable if you maintain ownership, automate updates, and report on drift so leadership and risk teams can act.
Change governance becomes your stabilizer. A change control board aligns IT, security, operations, risk, and compliance before big moves, while an emergency change advisory board authorizes fast action for zero‑days and incidents with a strict post‑implementation review. We break down the full change lifecycle—request, impact analysis, staging, implementation, verification, CMDB updates—and the common pitfalls to avoid, including undocumented changes, brittle rollbacks, and ignoring post‑change scan results. Expect practical guidance on when to auto‑patch Windows, how to iterate quarterly without overengineering, and what metrics prove progress.
If you’re aiming to master CISSP Domain 7 or just want fewer outages and faster recovery, this conversation gives you a clear blueprint to reduce attack surface and increase stability. If it helps, share it with a teammate, subscribe for more deep dives, and leave a quick review so we can keep improving for you.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Quantum threats aren’t waiting politely on the horizon, and neither should we. We kick off with Signal’s bold move to deploy post-quantum encryption, unpacking the “belt and suspenders” approach that blends classical cryptography with quantum-resistant algorithms. No jargon traps—just clear takeaways on why this matters for privacy, resilience, and the pressure it puts on other messaging platforms to evolve. We point you to smart reads from Ars Technica and Bruce Schneier that make the technical guts approachable and actionable.
From there, we switch gears into a focused CISSP Domain 8 walkthrough: how to weave security into every phase of the software development lifecycle. We talk practical integration across waterfall, agile, and DevOps; show why change management, continuous monitoring, and application-aware incident response are non-negotiable; and explain how maturity models like CMMI and BSIMM help teams move from reactive to repeatable. We also break down the developer’s toolbox—secure language choices, vetted libraries with SCA, hardened runtimes, and IDE plugins that surface issues in real time—so teams can ship faster without trading away safety.
Speed meets rigor in the CI/CD pipeline, where shift-left security comes alive with SAST, DAST, and SOAR-driven checks. We cover repository hygiene, secret scanning, and how to measure effectiveness with audit trails and risk analysis that map code issues to business impact. You’ll get a clear view of third-party risk across COTS and open source, the shared responsibility model for SaaS, PaaS, and IaaS, and the daily practices that keep APIs from leaking data: least privilege, strict authorization, input validation, and rate limiting. We close with software-defined security—policies as code—bringing consistency, versioning, and automation to your defenses. Subscribe, share with a teammate who owns your pipeline, and leave a review to tell us the next Domain 8 topic you want us to deep-dive.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
One DNS bug shouldn’t take your business offline—but it did for thousands. We open with the AWS East outage to show how a single point of failure in DNS can cascade through critical systems, then get tactical about building resilience that actually holds up under stress. From multi‑region architecture and failover planning to budget trade‑offs leaders often dodge, we make the case for redundancy you can defend to finance and prove with tests, not promises.
From there, we translate CISSP Domain 6.4 into actionable steps. You’ll hear how to structure vulnerability reports that leaders read and teams use: crisp executive summaries, deep technical details, and remediation plans with owners and timelines. We contrast internal and external scans—what they find, where they break, and how to plan windows that won’t knock over production. Expect practical guidance on ranking findings by business impact, taming false positives, and using trend analysis to show improvement over time.
Validation and exception handling take center stage as we walk through verifying exploitability, aligning CVSS with real risk, and documenting exceptions the right way. When patching isn’t possible, we outline compensating controls like segmentation, WAFs, logging, and virtual patching that reduce exposure without halting operations. We close with ethical disclosure best practices—coordinated timelines, bug bounty channels, and the legal safeguards that keep researchers and organizations on the same team.
If you want resilient architectures, credible reporting, and a vulnerability program that leadership trusts, this conversation gives you the blueprint. Subscribe, share this with your team, and leave a quick review with your top takeaway—what’s the first resilience fix you’ll prioritize this quarter?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
You can harden your network and still miss the front door: aging edge devices with elevated access, thin logging, and long‑ignored firmware. We dig into the uncomfortable truth behind “set it and forget it” firewalls, VPNs, and gateways, then lay out a practical Domain 7 playbook that helps you detect faster, respond cleaner, and recover without chaos.
We start with the incident management sequence that actually works under pressure—detection, response, mitigation, reporting, recovery, remediation, and lessons learned—showing how legal timelines, stakeholder updates, and RTO/RPO planning fit together. From there, we map the controls that pull their weight: next‑gen firewalls and WAFs, IDS/IPS, smart whitelisting and blacklisting, sandboxing that anticipates time‑bomb malware, and when to lean on EDR, MDR, and UEBA to cut through alert fatigue.
Then we get hands‑on with vulnerability and patch management, focusing on asset inventory, critical‑first prioritization, scanning automation, and staged deployments with real rollback plans. We connect the dots to change management so fixes don’t become outages. Resilience gets its due: backup integrity and rotation, hot/warm/cold recovery sites, multi‑region processing, HA pairs, QoS to preserve critical traffic, and fault‑tolerant design that keeps services running when parts fail.
Finally, we round out security operations with disaster recovery drills—from tabletop to full cutover—plus business continuity planning that aligns cyber recovery with revenue‑critical processes. Physical security and personal safety close the loop: layered access, surveillance, environmental controls, and travel and duress protocols that protect your people as well as your data. If you’re preparing for the CISSP or sharpening a real program, you’ll leave with concrete steps to reduce risk now and a roadmap to mature over time.
Enjoyed this deep dive? Subscribe, share with a teammate who owns Domain 7, and leave a quick review to help others find the show. Your feedback shapes future topics and tools we build for you.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Headlines about a massive F5 Big-IP exposure aren’t noise—they’re a masterclass in why Security Operations must be disciplined, fast, and auditable. We open with what the F5 situation means for enterprise risk, patch urgency, and long-term persistence threats, then shift into a practical, exam-ready walkthrough of CISSP Domain 7. The goal: help you think like an operator and answer like a pro when pressure spikes.
We map investigations from preparation to presentation, showing how evidence collection, handling, and chain of custody turn raw logs into defensible findings. You’ll hear how live versus dead forensics trade-offs play out, which artifacts matter across endpoints, networks, and mobile, and why standardized procedures keep teams synchronized. From there, we connect visibility to action: IDS and IPS for detection and control, SIEM for correlation and retention, and egress monitoring to catch data theft and command-and-control that slip past perimeter thinking. Threat intelligence and UEBA add context and behavior baselines so you find the meaningful anomalies without drowning in alerts.
We also dig into the operational backbone that keeps environments stable: configuration management, security baselines, and automation to eliminate drift and reduce manual error. Then we anchor on foundational principles—least privilege, need-to-know, separation of duties, job rotation, and PAM—to limit blast radius when credentials or processes fail. Finally, we close with resource protection and media management: classification, encryption, verifiable backups, and secure disposal and transport, so your controls hold up under legal scrutiny and real-world adversaries.
Whether you’re tightening controls after the F5 news or sharpening focus for the CISSP, this guide to Domain 7 gives you a clear, actionable path. If this was helpful, follow the show, share it with a teammate, and leave a quick review—what Security Operations topic should we explore next?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Quantum isn’t a distant sci‑fi threat—it's shaping security decisions right now. We open with what NIST’s new post‑quantum FIPS 203/204/205 actually mean for your crypto roadmap, why “harvest now, decrypt later” raises the stakes for long‑lived data, and how the 2035 federal mandate will ripple through contractors, audits, and CMMC. Then we get practical, translating policy pressure into the access decisions you make every day and the concepts you’ll see on the CISSP exam.
We break down mandatory access control (labels, clearance, strict need‑to‑know), discretionary access control (owner grants, permission creep), role‑based access control (job functions, least privilege at scale), attribute‑based access control (context, dynamic conditions), and rule‑based control (fine‑grained logic and exceptions). Along the way, we highlight the keywords that unlock tricky multiple‑choice items—“classification,” “owner,” “job role,” “attributes,” “rules”—so you can map questions to the correct model fast. More importantly, we explain how to combine models without creating chaos: use RBAC for baseline entitlements, layer ABAC for context and risk signals, lean on rule-based policies for surgical exceptions, and reserve MAC for highly classified domains where enforcement must be absolute.
If attackers are stockpiling ciphertext for a quantum tomorrow, the answer is a two‑track plan: crypto agility to adopt quantum‑resistant algorithms and disciplined access governance to limit blast radius today. We share actionable cues for exam success, practical design tips for avoiding privilege escalation, and a reminder that good security is repeatable security—clear roles, auditable policies, and continuous review.
Subscribe for weekly CISSP prep you can use on the job, share this with a teammate who’s wrangling access models, and leave a review to help others find the show. Your support also fuels our charity‑funded training that gives back while you level up.
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us Fan Mail
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
https://www.jeffersonfisher.com/
A spike in ransomware on the factory floor isn’t just a headline; it’s a stress test for how we design, segment, and measure our defenses. We open with the realities of manufacturing risk—legacy OT, flat networks, and high stakes for uptime—then translate that urgency into a practical walkthrough of CISSP Domain 6: the assessments, testing, and metrics that actually prove security works. Along the way, we share a surprising leadership edge from a trial lawyer’s communication book that helps you argue less, align faster, and get executive buy‑in when the first vuln report lights up like a Christmas tree.
We break down internal vs external audits and when each makes sense, plus a smart cadence for third‑party and supply chain reviews that acknowledges your perimeter now includes APIs and vendor tunnels. From vulnerability scans and scoped penetration tests to SIEM‑driven log reviews and synthetic transactions, we map out a toolkit that catches issues before users do. We go deeper on secure code reviews, unit/integration testing, and interface testing for APIs, because the quiet paths between services are often where real risk hides.
Then we shift to the machinery of proof: breach and attack simulation for continuous validation, compliance checks to spot drift, and the metrics that matter—MTTD, MTTR, patch rates, vuln density, mean time to report. We lay out how to run account reviews, verify backups you can trust, and exercise DR/BC so recovery is muscle memory. Finally, we tackle remediation prioritization, exception handling with compensating controls, and ethical disclosure that minimizes harm while nudging vendors to act. If you’re preparing for the CISSP or elevating your program, you’ll leave with a clearer map and concrete next steps.
If this helped, follow the show, share it with a teammate, and drop a review—what’s one control or metric you’re upgrading this quarter?
Gain exclusive access to 360 FREE CISSP Practice Questions at FreeCISSPQuestions.com and have them delivered directly to your inbox! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success.
Join now and start your journey toward CISSP mastery today!
Send us a text
Leadership churn is reshaping security from the top down. We open the door on why CISO tenures are shrinking to 18–26 months and what that says about pressure, culture, compensation, and board-level risk literacy. From startups that stretch leaders thin to enterprises that treat security as a cost center until the breach, we map the real incentives behind the “revolving door”—and share what actually extends tenure: clear mandates, aligned executives, and measurable outcomes.
Then we flip to hands-on security with a crisp CISSP Domain 5 deep dive. You’ll hear real-world IAM scenarios and how to reason through them: federated identity where users authenticate but can’t access apps (hint: attribute-to-role mapping at the service provider), RBAC implementations that quietly violate least privilege, and when mandatory access control beats RBAC or ABAC for classified environments. We also dissect deprovisioning gaps that leave terminated users active in SaaS platforms and outline the operational fixes—source-of-truth integration, event-driven provisioning, and reconciliation from the SaaS side. To cap it off, we tackle a red-team classic: static admin creds in scripts. The modern answer isn’t longer passwords; it’s just-in-time privilege through PAM and secret vaulting so nothing sensitive sits on disk.
If you’re a senior technologist eyeing the CISO seat—or a CISO seeking sustainability—you’ll get a blueprint for aligning authority, resources, and risk. And if you’re prepping for the CISSP exam, these identity and access patterns will sharpen your instincts for both test day and production. Enjoy the conversation, and if it helps, subscribe, share it with a teammate, and leave a quick review so others can find it too.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A headline‑grabbing data leak is the wake‑up call; what you do next is the difference between panic and control. We start with concrete actions you can take today—check exposure with Have I Been Pwned, lock down your credit with freezes, turn on MFA, and keep meticulous records so you have proof when it counts. From there, we switch gears into the playbook every CISSP candidate and security leader needs: a clear path through the access control maze that actually maps to real work.
We break down Discretionary Access Control (DAC) and why it’s fast but fragile, then show how non‑discretionary models keep large environments consistent. Role‑Based Access Control (RBAC) gets the spotlight with practical guidance: define roles by job function, automate approvals, prevent role explosion, and audit entitlements so inheritance doesn’t hand out surprise privileges. We separate role‑based from rule‑based—one tied to people and jobs, the other to conditions like time, location, and transaction type—using examples you can adopt immediately.
For high‑assurance scenarios, we dig into Mandatory Access Control (MAC): labels, clearances, compartments, and the uncompromising policies that protect the most sensitive data. Finally, we look ahead with Attribute‑Based Access Control (ABAC), where context drives decisions in cloud and zero trust architectures. User attributes, device posture, data sensitivity, time, and geo all combine to answer the crucial question: should this subject access this object, right now?
You’ll walk away with exam‑ready cues, battle‑tested pros and cons, and a mental model to pick the right approach for your team. If this helped, subscribe, share it with a teammate who keeps mixing up role‑based and rule‑based, and leave a quick review so others can find us.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
The fastest way to lose trust is to let AI adoption outrun your governance. We open with a blunt look at AI sprawl and shadow AI—how unsanctioned tools slip past weak policies, create data exposure, and strain legacy controls—then lay out a practical path for teams that don’t have a big‑tech budget: continuous discovery via proxies or CASB‑like tools, real‑time monitoring through a trusted partner, and risk assessments that focus on business impact, not buzzwords. The goal isn’t to slow innovation; it’s to make it safe and repeatable.
From there, we bring CISSP Domain 1.3 to life with five scenario‑based questions that mirror real leadership decisions. You’ll hear why federated governance outperforms heavy central mandates in multinationals, how defining risk appetite is the first step before any framework, and which metrics actually prove value to a board. We draw a clear line between due care (policies, accountability, legal alignment) and due diligence (testing, verification, audits), and we show why insurance can transfer residual risk but can never replace sound governance.
We also get specific about executive communication. A new CEO wants alignment, accountability, and outcomes—not weekly patch timelines. Learn how to map security objectives to corporate strategy, prioritize by business risk, and present measurable progress that earns budget and buy‑in. If you’re preparing for the CISSP or leading a program under pressure, these principles help you think like a strategist and act with confidence.
Want more? Explore the free resources and growing library at CISSP Cyber Training, and grab the 360 free CISSP practice questions. If this episode helps you think clearer about governance and AI, subscribe, share it with a teammate, and leave a quick review to help others find the show.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security governance represents one of the most misunderstood yet critical components of any cybersecurity program. As we explore Domain 1.3 of the CISSP exam, we unpack how proper governance creates accountability and structure that protects both your organization and your career.
We begin with a startling real-world example: the "Red November" campaign, where Chinese state-sponsored hackers exploited vulnerable internet-facing appliances and VPNs across defense, aerospace, and government sectors for a full year. This sophisticated operation highlights why casual approaches to security governance leave organizations exposed to devastating attacks.
Security governance isn't merely a theoretical concept – it's a practical framework that defines who's responsible for what across your security landscape. We break down the crucial roles every organization must establish: from Senior Managers who hold ultimate responsibility, to Data Owners who classify information, to Data Custodians who implement protections, and the often-overlooked role of Auditors who verify everything works as intended. Understanding these distinctions protects security professionals from becoming scapegoats when incidents occur.
The real value emerges when we examine how security control frameworks like NIST CSF, ISO 27001, and CRI provide structured approaches to managing risk. These aren't one-size-fits-all solutions, but rather customizable blueprints that help you systematically identify, implement, and monitor security measures appropriate to your specific needs. Framework mapping allows you to align multiple requirements efficiently, making compliance less burdensome and more effective.
Finally, we demystify the concepts of due care and due diligence – the practical actions that demonstrate you've taken reasonable steps to protect your organization. These aren't just legal defenses; they're the fundamental building blocks of a mature security program that aligns with business objectives while meaningfully reducing risk.
Whether you're preparing for the CISSP exam or building a more robust security program, this episode provides the practical knowledge you need to implement effective security governance that executives will support and auditors will approve.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Dive into the critical world of software development security with Sean Gerber as he tackles Domain 8.3 in this knowledge-packed CISSP Question Thursday episode. We examine fifteen challenging questions that address the security controls essential for protecting code throughout the development lifecycle.
Discover why static application security testing integrated directly into your CICD pipeline stands as the gold standard for catching vulnerabilities early, and why developer arguments about "unlikely" buffer overflow exploits should never persuade you to leave vulnerabilities unaddressed. The podcast breaks down the crucial difference between partial mitigations and proper vulnerability elimination, providing you with the decision-making framework you'll need both for the CISSP exam and real-world security leadership.
The episode doesn't shy away from controversial topics, including the persistent myth of "security through obscurity" and why it fails as a protection strategy. You'll learn why security code reviews by senior developers remain irreplaceable for identifying business logic vulnerabilities, while generic security checklists prove ineffective against sophisticated threats. For those working with cloud platforms, open-source libraries, or outsourced development, Sean offers targeted guidance on the controls that matter most in each scenario.
Beyond the technical content, Sean shares his passion for helping adoptive families through the nonprofit initiative supported by purchases at CISSPCyberTraining.com. Every training package purchased contributes to providing grants and low-interest loans to families looking to adopt children who need loving homes.
Ready to strengthen your understanding of software security while preparing for your CISSP certification? This episode delivers actionable insights, exam-ready knowledge, and the confidence to tackle Domain 8.3 questions with expertise. Listen now and take another step toward mastering the crucial intersection of development and security that today's organizations desperately need.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Ready to master the critical domain of Identity and Access Management for your CISSP exam? This comprehensive rapid review demystifies Domain 5, which accounts for 13% of all exam questions—knowledge you absolutely cannot skip.
Dive deep into the fundamentals as we explore controlling physical and logical access to assets—from information systems to facilities. Discover how properly implemented controls protect your most sensitive data through classification, encryption, and permissions. As one cybersecurity veteran wisely notes, "It's all about the data," and this episode equips you with the frameworks to protect it.
The podcast meticulously unpacks identity management implementation, breaking down authentication types, session management, and credential systems. You'll grasp the differences between single-factor and multi-factor authentication and understand why accountability through proper logging and auditing is non-negotiable in today's security landscape.
We explore deployment models that fit various organizational needs—from on-premise solutions offering complete control to cloud-based options providing scalability, along with the increasingly popular hybrid approach. The episode clarifies authorization mechanisms including role-based access control (RBAC), rule-based access control, mandatory access controls (MAC), and discretionary access controls (DAC)—essential knowledge for implementing proper security boundaries.
Particularly valuable is our breakdown of authentication systems and protocols—OAuth, OpenID Connect, SAML, Kerberos, RADIUS, and TACACS+—demystifying their purposes and applications in real-world scenarios. Whether you're a seasoned security professional or preparing for your certification, this episode delivers the practical knowledge you need.
Ready to accelerate your CISSP journey? Visit CISSPcybertraining.com for free resources including podcasts, study plans, and 360 practice questions—plus premium content with over 50 hours of focused training. This episode isn't just exam prep; it's a masterclass in identity and access management principles you'll apply throughout your cybersecurity career.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The cybersecurity landscape is evolving rapidly with AI development creating unprecedented challenges for organizations, security professionals, and insurance providers alike. How do we manage these emerging risks while maintaining fundamental security governance principles?
Sean Gerber tackles this question head-on by examining why liability insurance alone won't solve the AI security equation. Drawing from a fascinating Lawfare article, he unpacks how cyber insurance has failed to drive meaningful security improvements due to poor data collection, shallow assessments, and inadequate risk measurement. As AI systems increasingly generate their own code, determining liability becomes extraordinarily complex. Insurance companies may soon require more rigorous security evaluations before providing coverage for AI implementations, placing additional burden on businesses to demonstrate robust security practices.
Moving from theory to practice, Sean delivers five deep-dive questions on CISSP Domain 5.5 that demonstrate how security professionals must "think like managers" rather than just memorizing answers. Each scenario—from dealing with orphaned accounts after mergers to implementing role-based access controls in healthcare—illustrates the critical importance of governance, proper access management, and security process improvement. The questions challenge listeners to move beyond tactical thinking and embrace strategic security management approaches that balance business needs with risk mitigation.
The episode also unveils Sean's upcoming 7-day and 14-day CISSP bootcamp blueprints—intensive training plans designed for candidates who need to prepare efficiently without spending thousands on traditional bootcamps. These structured approaches provide a cost-effective alternative while still covering the comprehensive knowledge required to pass the challenging CISSP exam.
Ready to strengthen your CISSP preparation? Visit CISSPCyberTraining.com for free practice questions, video content, and specialized training materials designed to help you pass the exam on your first attempt. The combination of conceptual understanding and practical application demonstrated in this episode is exactly what distinguishes successful CISSP candidates from those who merely memorize practice tests.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The effective management of digital identities throughout their lifecycle is perhaps the most crucial yet overlooked aspect of organizational cybersecurity. This episode dives deep into CISSP Domain 5.5, offering practical insights on building robust identity and access management (IAM) governance frameworks that protect against insider threats while streamlining compliance efforts.
We begin by examining a real-world case study of how one company transformed its third-party risk management using AI-driven consolidation of security alerts, establishing clear accountability through a security champions program. This approach demonstrates how proper governance structures can turn overwhelming data into actionable intelligence.
The heart of our discussion centers on the identity lifecycle – from provisioning to deprovisioning and everything between. Learn why automated account creation processes dramatically reduce security risks while improving operational efficiency. We share cautionary tales, including one where improper deprovisioning allowed an ex-employee to deploy a devastating logic bomb costing millions in damages and legal fees.
Role-based access control (RBAC) emerges as a critical strategy for maintaining least privilege principles at scale. However, we warn against common pitfalls like overly complex role structures that become unmanageable or so simplified they create security gaps. The episode provides clear guidance on achieving the right balance for organizations of any size.
Perhaps most importantly, we expose the hidden dangers of service accounts – those often-forgotten credentials with extensive privileges that rarely change and receive minimal monitoring. These accounts represent prime targets for attackers seeking to escalate privileges, yet many organizations fail to properly secure them.
Whether you're studying for the CISSP exam or implementing IAM best practices in your organization, this episode delivers actionable strategies to strengthen your security posture through proper identity lifecycle management. Visit CISSPCyberTraining.com for additional resources to support your cybersecurity journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Dive into the complex world of security models as we unpack Domain 3.2 of the CISSP exam in this knowledge-packed episode. We begin by examining how the generative AI boom is creating significant privacy and cybersecurity challenges for organizations worldwide. Security professionals must now navigate data ownership questions, changing terms of service, and the risks of shadow AI usage – all while developing governance strategies that balance innovation with protection.
The spotlight then turns to the Chinese Wall model (Brewer-Nash), a fascinating security approach that originated in financial and legal industries. Unlike static models, this dynamic access control system creates metaphorical barriers between competing clients to prevent conflicts of interest. When a consultant accesses one company's sensitive data, they're automatically blocked from accessing a competitor's information – a concept every CISSP candidate needs to understand thoroughly.
The heart of the episode features five challenging practice questions that explore critical security models: Bell-LaPadula's simple security property for preventing unauthorized access to classified information; Clark-Wilson's transaction integrity controls for financial systems; Brewer-Nash for managing consultant access to competing clients; the Non-Interference model for preventing covert channel leaks; and the Take-Grant model for controlling rights distribution. Each question comes with detailed explanations that clarify these concepts in practical, real-world contexts.
Whether you're preparing for the CISSP exam or expanding your cybersecurity knowledge, this episode provides valuable insights into how different security models address specific protection requirements. Ready to strengthen your understanding of these essential security frameworks? Visit CISSP Cyber Training for 360 free practice questions and additional resources to support your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security models can be one of the most challenging concepts for CISSP candidates to grasp, yet they form the bedrock of how we implement and understand security controls. In this comprehensive episode, we break down Domain 3.2's security models in plain, accessible language with real-world examples that will finally make these abstract concepts click.
We start with an analysis of the recent TransUnion data breach affecting 4.4 million individuals, using it as a practical reminder of why proper security architecture matters. This breach, occurring through a third-party application, perfectly illustrates the dangers when security models aren't properly implemented.
The episode then demystifies the Trusted Computing Base (TCB), explaining its role as the foundation of creating secure code. We explore key components including the Security Kernel, Reference Monitor, Trusted Path, and TCB Boundary, translating these complex concepts into understandable terms.
The heart of the episode focuses on the "Big Eight" security models you need to know for the CISSP exam. From Bell-LaPadula's "no read up, no write down" confidentiality focus to Biba's integrity-centered approach, we provide clear explanations and memorable scenarios for each model. You'll learn how Clark-Wilson enforces business integrity through separation of duties, how Brewer-Nash prevents conflicts of interest, and how the remaining models address specific security concerns.
Rather than simply memorizing names and concepts, this episode gives you a framework for understanding each model's purpose, category (confidentiality, integrity, information flow, or access), and practical application. We conclude with exam preparation tips, highlighting which models deserve the most attention during your studies.
Whether you're preparing for the CISSP exam or simply want to deepen your cybersecurity knowledge, this episode transforms abstract security models into practical tools you can apply to real-world security challenges. Visit CISSPCyberTraining.com for free questions and additional resources to support your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Dive into the multifaceted world of data security controls with Sean Gerber as he unpacks CISSP Domain 2.6. The episode opens with a fascinating glimpse into the creative ingenuity of technology users—a student who managed to hack a TI-84 calculator to access ChatGPT during exams. This real-world example perfectly illustrates why robust data security controls are more crucial than ever in our interconnected world.
Sean meticulously breaks down the three fundamental data states—data at rest, data in transit, and data in use—providing clear explanations of the unique protection mechanisms each requires. You'll discover why data is rarely truly "at rest" unless completely powered off and disconnected, and why this understanding is vital for comprehensive protection strategies. The discussion extends to emerging technologies like homomorphic encryption, which promises to keep data encrypted throughout all states, though it's still evolving.
The heart of effective data protection lies in classification and labeling, and Sean offers practical advice on implementing these systems. Starting small with clearly defined data sets, standardizing nomenclature, and utilizing visual cues like color-coding are just a few of the actionable strategies shared. You'll gain insights into Digital Rights Management (DRM), Data Loss Prevention (DLP), and Cloud Access Security Brokers (CASBs)—three critical components of a comprehensive data security framework.
Perhaps most valuable is Sean's emphasis on understanding organizational risk tolerance. As he eloquently puts it, "If you don't know the risk for your company, find out somebody who does." This perspective shift from pure protection to risk-aligned security can transform how security professionals approach their role and communicate with leadership.
Whether you're studying for the CISSP exam or looking to enhance your organization's data protection strategy, this episode delivers practical wisdom drawn from real-world experience. Visit CISSP Cyber Training for additional resources, and remember—understanding data security isn't just about passing an exam; it's about becoming a more effective guardian of your organization's most valuable assets.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
From insecure code causing breaches to proper data destruction, this episode dives deep into the critical world of data lifecycle management—a cornerstone of the CISSP certification and modern cybersecurity practice.
A shocking 74% of organizations have experienced security incidents from insecure code, highlighting why proper data management matters more than ever. Whether you're preparing for the CISSP exam or strengthening your organization's security posture, understanding who's responsible for what is essential. We break down the sometimes confusing differences between data owners (who bear legal liability), data custodians (handling day-to-day operations), data controllers (determining what gets processed and how), and data processors (who handle the actual processing).
The stakes couldn't be higher. With GDPR violations potentially costing organizations up to 4% of global annual revenue, misunderstanding these roles can lead to catastrophic financial consequences. We explore the eight principles driving transborder data flows and why understanding your data's journey matters for compliance and security.
When it comes to data destruction, I share practical wisdom about what really works. While methods like degaussing and various overwriting techniques exist, I explain why physical destruction (the "jaws of death" approach) often makes the most practical and economic sense in today's world of inexpensive storage media.
Throughout the episode, I provide real-world examples from my decades of experience as a CISO and security professional. Whether you're dealing with classified information requiring specialized handling or simply trying to implement sensible data governance in a commercial environment, these principles will help protect your organization's most valuable asset—its information.
Ready to continue your cybersecurity journey? Visit CISSP Cyber Training for free resources, sign up for my email list, or check out my YouTube channel for additional content to help you pass the CISSP exam the first time.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The digital world has opened up unprecedented opportunities for scammers, and seniors have become prime targets. In this alarming and informative episode, we dive deep into the FBI's recent warning about AI-driven "Phantom Hacker" scams that have already stolen over a billion dollars from American seniors through sophisticated three-stage attacks.
What makes these scams particularly devastating is the deployment of AI voice cloning technology. With just a small sample of someone's speech, scammers can create perfect voice replicas that sound exactly like trusted family members or financial advisors. This technology has advanced to the point where distinguishing between real and AI-generated voices is nearly impossible for most people. As cybersecurity professionals, we have a responsibility to protect vulnerable populations through education and clear verification protocols.
The episode transitions into a comprehensive review of CISSP Domain 4, covering essential communication and network security concepts. We explore voice communications security for both traditional telephone networks and modern VoIP systems, email security protocols including SPF, DKIM, and DMARC, and remote access considerations with VPNs. The discussion covers critical decisions between split and full tunneling, network address translation complexities, and third-party risk management through formal agreements and vendor assessments.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's communication security posture, this episode provides actionable insights on protecting against today's most sophisticated threats. The convergence of AI technology with traditional social engineering tactics demands a new approach to security awareness and technical controls—one that acknowledges voice is no longer a reliable authentication factor on its own.
Ready to continue your CISSP journey? Visit CISSPCyberTraining.com for free resources including practice questions, rapid review videos, and a comprehensive study plan designed to help you pass the exam on your first attempt.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Network security is the cornerstone of modern cybersecurity, and understanding its intricacies is essential for anyone preparing for the CISSP exam. In this comprehensive episode, Sean Gerber delivers a rapid review of Domain 4: Communications and Network Security, which constitutes 13% of the CISSP exam questions.
The episode opens with a cautionary tale about a disgruntled Chinese developer who received a four-year prison sentence for deploying a logic bomb that devastated his former employer's network. This real-world example underscores the critical importance of proper employee termination procedures and privilege management—especially for technical staff with elevated access. As Sean emphasizes, "The eyes of Sauron" should be on any high-privilege employee showing signs of discontent.
Diving into Domain 4, Sean expertly navigates through foundational concepts like the OSI and TCP/IP models, explaining how they standardize network communications and why security professionals must understand them to implement effective defense strategies. The discussion progresses through IP networking (both IPv4 and IPv6), secure protocols, multi-layer protections, and deep packet inspection—all crucial components of a robust security architecture.
Particularly valuable is Sean's breakdown of modern network technologies like micro-segmentation, which divides networks into highly granular security zones. While acknowledging its power to limit lateral movement during breaches, he cautions that implementation requires sophisticated knowledge of software-defined networking (SDN) and careful planning: "It's better to start small than to go out and think of and get too big when you're dealing with deploying these SDN type of capabilities."
Wireless security, content delivery networks, and endpoint protection receive thorough examination, with Sean emphasizing that endpoints are "your first line of detection" and advocating for comprehensive endpoint detection and response (EDR) solutions that go beyond traditional antivirus. The episode concludes with insights on voice communication security, contrasting traditional telephone networks with modern VoIP systems and their unique vulnerabilities.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's network security posture, this episode provides actionable insights backed by real-world experience. Ready to deepen your understanding of cybersecurity fundamentals? Subscribe to the CISSP Cyber Training Podcast and check out the free resources available at cisspybertraining.com to accelerate your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A catastrophic data loss incident involving South Yorkshire Police serves as a powerful security lesson in today's episode. We examine how 96,174 pieces of body-worn video evidence vanished during an IT upgrade, affecting 126 criminal cases. This real-world security failure highlights the critical importance of proper data management, backups, and third-party oversight—fundamental concepts that directly apply to your CISSP exam preparation.
The heart of this episode tackles five challenging CISSP exam questions spanning multiple security domains. We methodically work through complex scenarios involving encryption algorithm selection, mitigating Single Sign-On risks in healthcare environments, containing Advanced Persistent Threats, addressing cross-border data protection compliance, and handling SQL injection vulnerabilities in government applications.
For each question, I break down the critical thinking process that helps you eliminate incorrect answers and identify the best solution. You'll understand why AES-256 balances security and performance for financial data, how multi-factor authentication strengthens SSO implementations, when network segmentation becomes crucial for APT containment, why Data Loss Prevention systems address insider threats, and the importance of parameterized queries in secure software development.
This episode demonstrates how to approach scenario-based questions methodically, turning what seems overwhelming into manageable decision points. By breaking down complex questions step-by-step, you dramatically improve your chances of success on the CISSP exam while building practical security knowledge that translates directly to real-world challenges.
Visit CISSP Cyber Training for more resources, including 360 free practice questions to accelerate your certification journey. Remember, a methodical approach to security problems is your path to passing the CISSP exam the first time.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The core principles of cybersecurity aren't just theoretical concepts—they're the practical foundation every security professional needs to master. In this deep-dive episode, Sean Gerber breaks down the critical components of Domain 1.2 of the CISSP exam, unpacking confidentiality, integrity, availability, authenticity, and non-repudiation in clear, actionable terms.
Starting with breaking news about Microsoft ending Windows 10 support on October 14th, Sean highlights the urgent security implications for organizations still running this widely-embedded operating system. He emphasizes the importance of comprehensive inventory management—especially for IoT devices that may contain embedded Windows components—and the available extension options for critical systems.
The heart of the episode delivers a comprehensive exploration of the CIA triad. Sean walks through each element with real-world examples: confidentiality through encryption and access controls; integrity via change management and validation processes; and availability through redundant systems and business continuity planning. But he doesn't stop there. The discussion expands to cover the DAD triad (Disclosure, Alteration, Destruction) which helps identify security failures, and the AAA framework (Authentication, Authorization, Accounting) that provides essential security controls.
What makes this episode particularly valuable is Sean's practical advice drawn from 25 years of cybersecurity experience. He emphasizes the importance of defense-in-depth strategies, network segmentation, and prioritizing critical systems rather than attempting to fix everything at once—"eating the elephant one toenail at a time." His methodical approach helps listeners understand not just the concepts themselves, but how to implement them effectively in real-world environments.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's security posture, this episode provides the foundational knowledge and practical strategies you need. Visit CISSP Cyber Training for free study materials, practice questions, and mentoring options to accelerate your cybersecurity career.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Dive deep into the critical world of configuration management with Sean Gerber as he unpacks Domain 7.3 of the CISSP exam. This episode balances theoretical knowledge with hard-earned practical wisdom, helping you not only pass your certification exam but implement effective security controls in real-world environments.
Sean begins by exploring recent IT employment trends, highlighting the growing importance of specialized skills in networking, cloud, and software development. He notes how employers are increasingly valuing practical skills and certifications over traditional four-year degrees, creating new opportunities for security professionals.
The heart of the episode examines the foundational elements of configuration management – from asset discovery to change control processes. Through relatable examples, Sean illustrates how unauthorized devices create security blind spots and why automated tools like SCCM are essential for maintaining secure environments. He breaks down the four key activities of security configuration management: identification, control, status accounting, and verification/audit.
Perhaps most valuable is Sean's candid discussion of implementation challenges. Rather than presenting idealized scenarios, he acknowledges the messy reality of managing configurations in complex organizations with legacy systems. His practical advice includes focusing on operating systems and devices first before tackling the more challenging application landscape, and implementing changes through a multi-year approach rather than attempting overnight transformation.
Ready to master configuration management and move closer to CISSP certification? Visit CISSPcybertraining.com where you can access training resources on a pay-what-you-wish basis. What makes this program truly special is that all proceeds support adoptive families through Sean's nonprofit foundation. Learn essential cybersecurity skills while contributing to a meaningful cause!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A sophisticated banking network breach using tiny Raspberry Pi devices sets the stage for our comprehensive examination of CISSP Domain 3 Security Architecture fundamentals. The attack—which gave hackers persistent remote access to ATM systems—demonstrates how physical security failures can lead to devastating network compromises, perfectly illustrating why Domain 3's holistic approach to security is critical in modern environments.
We systematically explore the security requirements for diverse system architectures—from traditional client-server setups to cutting-edge containerization and serverless deployments. You'll gain clarity on why different systems demand specialized protection strategies: how industrial control systems prioritize availability over confidentiality, why cloud environments operate under shared responsibility models, and what makes IoT devices particularly vulnerable to compromise.
The cryptographic section demystifies key management practices, explaining why even mathematically sound algorithms fail when implementation is flawed. We break down symmetric versus asymmetric encryption, digital signatures, and hashing techniques essential for data integrity. More importantly, you'll understand the complete cryptographic lifecycle from generation through destruction—knowledge directly applicable to real-world security operations and exam scenarios alike.
Our detailed examination of attack methodologies covers everything from brute force attempts to sophisticated side-channel attacks that extract secrets through power consumption analysis. The physical security portion reveals why facility design, environmental controls, and power management form essential layers in your defense strategy.
Whether you're preparing for the CISSP exam or strengthening your organization's security posture, this episode delivers actionable insights into creating robust, multi-layered security architectures. Ready to build stronger defenses? Visit CISSPCyberTraining.com for free practice questions and additional resources to accelerate your cybersecurity mastery.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
We begin by exploring foundational security principles that drive effective system design. Threat modeling emerges as a proactive approach for identifying vulnerabilities before implementation, while least privilege ensures users have only the access they absolutely need. Defense in depth creates those crucial security layers that prevent single points of failure from becoming catastrophic breaches. The podcast clarifies how secure defaults and fail-secure mechanisms ensure systems remain protected even during unexpected circumstances.
The security models section demystifies complex concepts like Bell-LaPadula (no read up, no write down) and Biba (no read down, no write up), providing clear distinctions between these often-confused frameworks. You'll gain clarity on when and why each model applies to different security priorities—whether confidentiality in Bell-LaPadula or integrity in Biba. Other essential models covered include Clark-Wilson, Brewer-Nash (Chinese Wall), and State Machine models.
Memory protection emerges as a crucial technical component, with explanations of buffer overflows, dangling pointers, and other vulnerabilities that can compromise system integrity. The practical countermeasures discussed—Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and secure coding practices—provide actionable knowledge for preventing memory-based attacks.
The episode also highlights the NSA's recent release of "Elite Wolf," a repository of signatures and analytics for operational technology networks. This timely information underscores the growing importance of securing industrial control systems, which have historically received less security attention despite their critical nature.
Whether you're preparing for the CISSP exam or looking to strengthen your security architecture knowledge, this episode provides the structured approach and key concepts you need. Ready to master the most heavily weighted domain on the CISSP exam? Visit CISSP Cyber Training for additional resources, practice questions, and comprehensive exam preparation materials.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The cybersecurity landscape grows more complex each day, especially when it comes to protecting critical infrastructure. In this essential episode of the CISSP Cyber Training Podcast, Sean Gerber breaks down Domain 2 of the CISSP certification - a vital area representing approximately 10% of the exam questions that every security professional must master.
Sean begins with a timely discussion of the recently discovered Honeywell Experion PKS vulnerability that could allow remote manipulation of industrial processes. This real-world example perfectly illustrates why understanding industrial control security is crucial across all sectors - from energy and water treatment to manufacturing and healthcare. The vulnerability serves as a sobering reminder that patching isn't always straightforward in environments that operate 24/7/365.
Diving into Domain 2.1, Sean meticulously explains data classification fundamentals - how sensitivity levels are assigned based on business value, regulatory requirements, and potential compromise impact. He walks through the relationship between classification levels (public through highly confidential) and corresponding handling procedures. The podcast builds logically through ownership concepts, introducing essential roles like data owners, custodians, stewards, and asset owners.
Perhaps most valuable is Sean's practical exploration of asset inventory management. Drawing from his extensive experience, he shares surprising stories of servers found in bathroom closets and emphasizes why knowing your asset locations isn't just good practice - it's essential for incident response and vulnerability management.
The episode thoroughly covers the complete data lifecycle from collection through destruction. Sean explains data minimization principles, location considerations for sovereignty compliance, maintenance requirements, and proper destruction techniques. His discussion of data remnants highlights why simply deleting files is never sufficient for sensitive information.
Sean wraps up with crucial insights on end-of-life system management and data protection technologies including encryption, DRM, DLP, and Cloud Access Security Brokers. His rapid review approach efficiently condenses critical knowledge while maintaining depth where it matters most.
Whether you're preparing for the CISSP exam or seeking to strengthen your security program, this episode delivers actionable knowledge you can immediately apply. Visit CISSP Cyber Training for free study resources and take the next step in your cybersecurity journey today!
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Securing SaaS environments and mastering security assessment techniques are critical skills for today's cybersecurity professionals. This episode delivers a powerful examination of Domain 6.3 of the CISSP certification, focusing on security testing methodologies that can make or break your organization's defensive posture.
Sean Gerber begins with a startling statistic: 96.7% of organizations now use at least one SaaS application, yet many fail to properly secure these cloud-based services. When you migrate from on-premises solutions to SaaS offerings, your sensitive data moves from environments protected by your security infrastructure to those secured by third parties. This fundamental shift demands rigorous risk assessment processes. Sean provides practical guidance on evaluating SaaS providers, emphasizing critical areas like data encryption practices, multi-factor authentication implementation, account access controls, and comprehensive backup strategies.
The heart of this episode explores essential testing methodologies every security professional should master. Black box testing techniques like penetration testing simulate real-world attacks without prior knowledge of system internals. Vulnerability assessments evaluate risk exposure by systematically identifying weaknesses. Dynamic analysis tests systems during operation, while code reviews catch vulnerabilities before deployment. Each approach serves a unique purpose in a comprehensive security program. Sean clarifies the crucial distinction between false positives (incorrectly identified vulnerabilities) and false negatives (missed vulnerabilities), explaining why the latter pose a significantly greater risk to organizations.
Whether you're preparing for the CISSP exam or strengthening your organization's security posture, this episode provides the knowledge you need to implement effective security assessment strategies. Join our growing community of security professionals at CISSP Cyber Training, where you'll find additional resources to accelerate your cybersecurity journey while supporting a worthy cause – all proceeds go to a nonprofit supporting adoptive families. Take your security knowledge to the next level and make a difference!
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A shocking cybersecurity case recently hit the headlines—a 50-year-old IT contractor sentenced to over 8 years in prison for acting as a mule for North Korean hackers. What makes this story particularly alarming? Companies were unknowingly shipping laptops directly to her, providing legitimate access credentials that she then shared with foreign adversaries. This case serves as a powerful reminder of why third-party risk management isn't just a compliance exercise but a critical security function.
Diving into CISSP Domain 6.3, we explore the fundamental security processes that could prevent such compromises. User account lifecycle management forms the backbone of organizational security, from proper identity verification during onboarding to the principle of least privilege and role-based access controls. We examine the critical differences between disabling and deleting accounts during deprovisioning, and why service accounts deserve special attention as high-value targets for attackers.
Security assessments and audits provide the verification mechanisms needed to ensure your controls are both properly designed and effectively operating. Understanding the distinction between vulnerability assessments, penetration tests, and formal audits helps you build a comprehensive evaluation strategy. We clarify the differences between SOC Type 1 and Type 2 reports when evaluating service providers, and explain why metrics must be measurable, actionable, relevant, timely, and attributional (SMARTA) to drive meaningful security improvements.
Perhaps most critically, we address backup verification strategies—because discovering your backups are corrupted during a recovery situation is a career-limiting event. Through practical guidance on security training approaches, enforcement mechanisms, and measurement techniques, this episode provides both CISSP candidates and practicing security professionals with actionable insights to strengthen their security programs. Ready to transform your security posture? Listen now, then visit CISSPCyberTraining.com for more resources to accelerate your cybersecurity journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The cybersecurity landscape is rapidly evolving, and AI stands at the forefront of this transformation. In this thought-provoking episode, Shon Gerber explores the projected $450 billion impact AI will have by 2028 and what this means for security professionals today.
With only 2% of companies having fully deployed AI solutions and 39% not yet exploring them, we're at the beginning of a massive shift that will fundamentally change how organizations approach security. Shon provides a candid assessment of why cybersecurity roles haven't yet been automated (risk aversion) and why this protection is temporary—predicting significant changes within the next five years.
For CISSP candidates, the episode delivers exceptional value through a detailed breakdown of five Domain 1 questions. Rather than simply providing correct answers, Shon dissects each question to reveal the underlying principles and reasoning. This approach helps listeners develop the critical thinking needed to succeed not just on the exam, but in real-world security scenarios.
The questions cover essential security concepts including risk treatment strategies, due diligence versus due care, professional ethics, policy versus procedure distinctions, and governance structures. Each explanation includes common points of confusion and practical workplace applications, bridging the gap between exam preparation and professional practice.
Perhaps most valuable is Shon advice on navigating ethical dilemmas in security consulting. His guidance on how to inform clients of regulatory violations while maintaining professional relationships demonstrates the nuanced people skills that separate truly effective security leaders from technical practitioners.
Ready to future-proof your cybersecurity career while preparing for CISSP certification? This episode delivers actionable insights for both immediate exam success and long-term career viability in an AI-transformed landscape. Check out CISSPCyberTraining.com for additional resources, including 360 free practice questions to accelerate your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Looking to strengthen your organization's defenses against unauthorized access? This episode dives deep into CISSP Domain 5.1, exploring the critical components of physical and logical access controls that protect your most valuable assets.
We begin with a startling discussion about China's "Maciantool" - sophisticated software secretly deployed at security checkpoints to extract SMS messages, GPS data, and images from travelers' phones. You'll learn practical strategies for protecting executive devices during international travel, including recommendations for burner phones and proper security protocols at checkpoints.
The foundation of effective access control starts with proper identity proofing and registration processes. We examine how to match verification rigor with resource sensitivity and explore the four authentication factors: something you know (passwords), something you have (tokens), something you are (biometrics), and something you do (keystroke patterns). Understanding how multi-factor authentication leverages these factors is essential for building robust security layers.
From preventative controls that stop unauthorized actions before they occur to detective measures that identify incidents after the fact, we break down each access control type with real-world examples. You'll discover how physical barriers like fences and man traps work alongside compensating controls when primary measures aren't feasible, plus strategies for implementing corrective actions after security breaches occur.
The principle of least privilege emerges as a central theme throughout our discussion - granting users only the minimum access necessary prevents credential creep while maintaining operational efficiency. We also emphasize the critical importance of documentation, regular testing, and effective communication channels for all access control measures.
Visit CISSP Cyber Training for free resources including practice questions, study plans, and additional podcasts. Ready to advance your cybersecurity career? Check out our mentoring programs designed to help you maximize both job fulfillment and income potential.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security vulnerabilities lurk in the most unexpected places – even in your home internet modem. Today we kick off with breaking news about a security flaw discovered in Cox modems that could potentially allow unauthorized access to run malicious commands on connected devices. While Cox reports fixing the issue within 24 hours, this real-world example perfectly illustrates a critical concept we explore further: how exposed APIs often become significant data exfiltration points because organizations fail to track and manage their connections properly.
Diving into our CISSP Question Thursday, we tackle fifteen practice questions specifically targeting Domain 3.1.2 and 3.1.3 concepts. These questions explore fundamental security principles including encryption standards (why AES-256 trumps proprietary algorithms), access controls (how custom APIs demonstrate both abstraction and access restriction), and defense in depth strategies (protecting data across multiple states). Each question builds practical understanding of how these principles apply in real-world scenarios – from secure boot configurations that hide complexity from users to the dangers of storing all encryption keys on a single, inadequately protected server.
The beauty of these practice questions lies in their practical applications. We examine how stenography conceals data within other files, how security defaults strengthen systems through pre-configuration, and how patching vulnerabilities relates to maintaining secure environments (while acknowledging that patches themselves can sometimes introduce new issues). Whether you're actively preparing for the CISSP exam or simply looking to strengthen your cybersecurity knowledge, these practice scenarios provide valuable training in identifying and addressing common security challenges. Visit cisspcybertraining.com to access this episode's questions and many more resources to support your cybersecurity journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The medieval castle with its moat, high walls, and sentries provides the perfect metaphor for modern cybersecurity. Just as each defensive element served a specific purpose in protecting the castle, today's information security requires multiple layers working in concert to safeguard digital assets.
Shon Gerber opens this episode with a timely discussion of the UnitedHealthcare ransomware attack, which reportedly cost $22 million and sparked controversy around the CISO's qualifications. This real-world example perfectly frames the importance of defense in depth strategies that could have prevented such a catastrophic breach.
The core of defense in depth involves implementing multiple security controls that protect various aspects of information systems. Shon walks through each layer, starting with perimeter security (firewalls, IDS/IPS systems), moving to access controls and data security (encryption, DLP), and continuing through system hardening and detection mechanisms. Each layer serves two crucial purposes: stopping attackers altogether or, at minimum, slowing them down enough that they move on to easier targets.
Particularly enlightening is Shon's breakdown of abstraction in security - how operating systems, networking protocols, databases, and APIs hide complexity from users while maintaining protection. This concept extends to data hiding techniques like steganography, tokenization, and encryption that conceal sensitive information from prying eyes.
The episode concludes with an examination of secure defaults - the principle that systems should ship with security enabled rather than requiring manual configuration. Shon provides practical guidance on implementing secure defaults and overcoming common challenges like vendor limitations and legacy systems.
Whether you're studying for the CISSP exam or looking to strengthen your organization's security posture, this episode delivers actionable insights on building robust, multi-layered defense strategies that balance protection with usability. Visit CISSP Cyber Training for additional resources, including practice questions and comprehensive study materials.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Microsoft recently released 137 security patches, with 14 critical vulnerabilities that could allow attackers to seize control of Windows systems with minimal user interaction. Among these, the Windows authentication negotiation flaw rated at 9.8 severity poses a significant threat to all current Windows versions. For security professionals, this underscores the crucial importance of effective patch management strategies—balancing timely updates against thorough testing procedures.
When approaching CISSP certification, understanding different investigation types provides essential context for security operations. Administrative investigations address potential policy violations and inappropriate resource usage, while criminal investigations gather evidence when laws are broken. Civil investigations resolve disputes between parties, regulatory investigations examine compliance with industry mandates, and standards investigations assess adherence to best practices like ISO 27001. Each investigation type requires distinct approaches and yields different outcomes, from disciplinary actions to legal proceedings.
The security documentation hierarchy—policies stating high-level objectives, standards specifying mandatory requirements, procedures providing step-by-step instructions, and guidelines offering flexible recommendations—creates a comprehensive framework for organizational security. However, these documents must use clear, accessible language that employees can understand and apply, not just legal jargon that looks impressive but goes unread.
Business continuity planning begins with a thorough Business Impact Analysis that identifies critical functions and establishes recovery objectives. This foundational work must involve stakeholders from across the organization to ensure operational reality aligns with security requirements. Similarly, personnel security extends beyond employee screening to include robust onboarding, transfer, and termination procedures—with equivalent controls for third-party relationships.
Risk management concepts form the core of security operations, from identifying threats and vulnerabilities to selecting appropriate controls. Understanding the distinction between preventative, detective, corrective, deterrent, and compensating controls enables security professionals to build comprehensive protection strategies. Combined with threat modeling methodologies like STRIDE and PASTA, these concepts create the framework for proactive security postures.
Ready to deepen your CISSP knowledge? Visit CISSP Cyber Training for both free resources and comprehensive paid training options that will help you pass your exam the first time while building practical security expertise.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ready to conquer CISSP Domain 1? This rapid review episode delivers essential knowledge on security and risk management fundamentals that form the cornerstone of information security practice.
We begin with a timely discussion on preventing ransomware through exfiltration controls, noting the alarming shift where 90% of ransomware attacks now involve data theft. The practical advice on implementing zero trust architecture acknowledges real-world challenges while providing actionable steps for gradual deployment.
Diving into Domain 1, we explore the ISC² Code of Professional Ethics and its four critical canons: protecting society and infrastructure, acting honorably, providing competent services, and advancing the security profession. The CIA triad (Confidentiality, Integrity, Availability) is thoroughly unpacked alongside the critical concepts of Authenticity and Non-repudiation, with practical examples of how these manifest in organizational security.
Security governance emerges as a crucial topic, emphasizing the necessity of aligning security efforts with business objectives rather than operating in isolation. Practical guidance on establishing effective governance committees, defining clear roles, and implementing proper segregation of duties provides real-world context beyond theoretical concepts.
The complexity of compliance requirements is demystified as we navigate legal regulations, industry standards, contractual obligations, and escalating privacy requirements. Particular attention is given to data breach notification timelines, evidence collection procedures, and transborder data flow considerations – all essential knowledge for modern security professionals.
Whether you're preparing for the CISSP exam or seeking to strengthen your security program, this rapid review provides the comprehensive foundation you need. Visit cisspcybertraining.com for additional resources including practice questions and study materials to support your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Ready to master data classification for your CISSP exam? This episode delivers exactly what you need through fifteen practical questions that mirror real exam scenarios, all focused on Domain 2.1.1.
The cybersecurity world is constantly evolving, and our discussion of the newly formed ARPA-H demonstrates this perfectly. Modeled after DARPA but focused on healthcare innovation, this agency represents a $50 million opportunity for security professionals to tackle the persistent ransomware threats plaguing the healthcare industry.
Diving into our practice questions, we explore how marketing materials receive "sensitive" classifications, while revolutionary battery technology blueprints warrant "class three severe impact" protection. We clarify why social security numbers in healthcare settings fall under Protected Health Information rather than just PII, and why government agencies use distinctive classification schemas including terms like "top secret" that aren't merely arbitrary labels.
The episode tackles complex scenarios including cloud storage responsibilities (you retain ownership of customer data even when stored by third parties), the limitations of DLP solutions for printed documents, and proper breach response protocols. Each question provides context-rich explanations that go beyond simple answers to build your understanding of the underlying principles.
Perhaps most valuable is our exploration of classification system design - revealing why simply labeling all non-public information as "sensitive" creates security vulnerabilities by failing to distinguish between different impact levels. This practical insight helps you not just memorize concepts but understand how to implement effective classification in real-world environments.
Whether you're studying for your CISSP exam or wanting to strengthen your organization's security posture, these fifteen questions provide the perfect framework for mastering data classification principles. Visit cisspcybertraining.com to access our complete blueprint and mentoring services guaranteed to help you pass the CISSP exam on your first attempt.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Effective data classification isn't just about regulatory compliance—it's the foundation of your entire security program. Whether you're preparing for the CISSP exam or leading security initiatives at your organization, understanding how to identify, categorize, and protect sensitive information is critical to your success.
This episode dives deep into the world of sensitive data management, breaking down the fundamental frameworks and approaches you need to master. Data classification might seem deceptively simple on the surface, but implementing it effectively requires navigating complex regulatory environments, understanding technical controls, and driving cultural change within your organization.
We begin by exploring what constitutes sensitive data across different industries—from financial institutions prioritizing monetary data to healthcare organizations safeguarding patient information. You'll learn about key regulatory frameworks like GDPR and HIPAA, their specific requirements, and the substantial penalties for non-compliance. The episode provides a practical breakdown of classification schemes in both government and private sectors, with actionable advice on simplifying these systems to improve employee compliance.
Most importantly, we address the critical human element of data protection. Without clear ownership and responsibility, sensitive information falls victim to the "tragedy of the commons"—accessible to everyone but protected by no one. The episode outlines strategies for assigning data ownership and implementing controls throughout the entire information lifecycle, from creation through disposal.
Along the way, we examine an emerging privacy concern with Microsoft's Copilot "recall" feature that captures screenshots of everything you do on your computer. This real-world example perfectly illustrates the constant tension between innovation and privacy that security professionals must navigate daily.
Whether you're just starting your security journey or looking to refine your approach as a seasoned professional, this episode provides the practical knowledge you need to build robust data protection strategies that balance security requirements with business needs. Subscribe now to continue building your cybersecurity expertise and prepare for the challenges of tomorrow's threat landscape.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Check us out at: https://www.cisspcybertraining.com/
Ethical dilemmas lurk around every corner in cybersecurity, ready to challenge even the most technically competent professionals. Sean Gerber tackles these moral minefields head-on in this thought-provoking episode focused on CISSP Domain 1.1, presenting fifteen real-world ethical scenarios that will test your professional judgment.
The episode opens with crucial context about the New York Department of Financial Services (NYDFS) and its significant influence on cybersecurity standards in the financial sector. Sean explains how their recent bulletin addressing Iranian threats emphasizes essential security controls including multi-factor authentication and third-party risk management - requirements that extend well beyond the financial industry.
Diving into the ethical scenarios, listeners will confront challenging questions: What would you do upon discovering a concealed data breach orchestrated by previous leadership? How should you handle a zero-day vulnerability when the vendor is notorious for slow responses? Is it ever appropriate to modify security logging standards when employees resist what they perceive as surveillance?
Through each scenario, Sean walks through multiple possible responses, highlighting the correct ethical choice while acknowledging the complex organizational dynamics at play. The discussions reveal that ethical practice isn't just about knowing the right answer—it's about effectively implementing ethical decisions through proper channels, documentation, and constructive solutions.
The episode offers invaluable guidance for anyone preparing for the CISSP exam or working in cybersecurity, demonstrating that while technical competence opens doors in this field, ethical judgment keeps those doors from slamming shut. As cyber threats evolve in complexity, the moral compass of security professionals becomes an increasingly critical asset in protecting organizations and their stakeholders.
Ready to test your ethical judgment against CISSP standards? Visit CISSPcybertraining.com for 360 free practice questions and additional resources to strengthen both your technical knowledge and ethical reasoning.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ethical leadership lies at the heart of effective cybersecurity practice. In this episode, we dive deep into Domain 1.1 of the CISSP certification, exploring professional ethics and their critical importance for security professionals.
The episode opens with a sobering look at the current landscape of cyber warfare, examining how Israeli-linked hackers are actively targeting Iran's financial systems. This real-world example serves as a stark reminder that cyber conflicts aren't theoretical—they're happening now, with devastating consequences for both government systems and ordinary citizens. For security professionals, this underscores the urgent need for robust resilience planning and strategic preparation for highly targeted attacks.
We then unpack the ISC² Code of Ethics through its four foundational canons: protecting society and the common good, acting with integrity, providing competent service, and advancing the profession. Each canon is explored with practical examples and real-world implications. The message becomes clear—security professionals possess extraordinary power through their knowledge and system access, and with this comes profound responsibility.
Throughout the discussion, we emphasize that ethical considerations extend beyond compliance requirements. They touch everything from handling sensitive data and discovering vulnerabilities to implementing AI systems and creating organizational cultures where ethical concerns can be safely raised. The principle of "do no harm" stands paramount, recognizing that security decisions impact not just organizations but the individuals who rely on these systems for their livelihoods.
Whether you're preparing for your CISSP certification, already working in the field, or leading security teams, this episode provides crucial insights into the ethical framework that must guide cybersecurity practice. Because in information security, ethics isn't just about following rules—it's about protecting people and building trust in the digital systems that increasingly power our world.
Ready to strengthen your ethical leadership in cybersecurity? Visit our website for resources including practice questions, mentorship opportunities, and comprehensive CISSP exam preparation materials.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The pursuit of AI expertise has reached staggering heights in the cybersecurity world. Meta reportedly offering "billion-dollar salaries" and $100 million sign-on bonuses to lure OpenAI talent reveals just how valuable the intersection of AI and security has become. This episode explores why security professionals should seriously consider developing AI skills while highlighting that most organizations are still figuring out their AI security strategy – creating massive opportunity for those who can help bridge the knowledge gap.
Transitioning to our main feature, we dive deep into Domain 8.5 of the CISSP with 15 critical questions covering secure coding practices. From preventing XML External Entity attacks to understanding race conditions in concurrent applications, each question unpacks vital security concepts through practical scenarios. Learn why disabling DTDs in XML parsers, implementing proper input validation for APIs, and using prepared statements with parameterized queries are fundamental to building secure applications.
The episode explores modern security challenges including infrastructure as code, OAuth 2.0 implementation, and the importance of implementing proper code review processes. Whether you're preparing for the CISSP exam or expanding your practical security knowledge, these questions provide valuable insight into how security vulnerabilities manifest and how to properly mitigate them. Each explanation goes beyond simple answers to help you understand the underlying principles that make certain practices more effective than others.
Ready to accelerate your CISSP journey? Visit CISSP Cyber Training for access to hundreds of practice questions, video content, and resources designed to help you pass the exam on your first attempt. Leave a review and let us know what topics you'd like covered next!
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Cybersecurity vulnerabilities continue to emerge in unexpected places, as evidenced by the recent Iranian-backed attacks on U.S. water treatment facilities through poorly secured Unitronics PLCs. This alarming development sets the stage for our deep dive into API security - a critical yet often overlooked aspect of modern cybersecurity strategy.
APIs form the connective tissue of our digital world, enabling seamless communication between different software systems. However, this interconnectivity creates numerous potential entry points for attackers. From RESTful APIs with their statelessness to enterprise-focused SOAP protocols and the newer GraphQL systems, each implementation brings unique security challenges that must be addressed proactively.
We explore the most common API security threats facing organizations today: injection attacks that exploit poorly coded interfaces, broken authentication mechanisms that enable unauthorized access, sensitive data exposure through improper configurations, and man-in-the-middle attacks that intercept communications. Understanding these threats is just the beginning - implementing robust countermeasures is where real security happens.
Authentication and access controls form the foundation of API security. OAuth, OpenID Connect, and token-based authentication systems provide powerful protection when implemented correctly. However, token management practices - including secure storage, proper revocation procedures, and regular refreshing - are equally critical yet frequently overlooked components of a comprehensive security strategy.
API gateways emerge as perhaps the most valuable security control in your arsenal. Acting as centralized checkpoints, they provide enhanced visibility, consistent authentication enforcement, traffic throttling capabilities, and simplified management across numerous API connections. Cloud-based API gateways from major providers offer scalability and robust features that on-premises solutions struggle to match.
Beyond the technical controls, we discuss the human element of API security. The most secure implementations balance protection with functionality while fostering collaboration between security professionals and developers. As I emphasize throughout the episode, effective security isn't about forcing compliance - it's about building bridges of understanding between teams with different expertise.
Ready to strengthen your API security posture or prepare for your CISSP exam? Visit cisspcybertraining.com for free questions, comprehensive courseware, and a proven blueprint for certification success.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security professionals face a constant battle to keep up with evolving threats, and our latest CISSP Question Thursday podcast delivers critical insights into one of the most fundamental cybersecurity capabilities: effective logging and monitoring.
The episode begins with a warning about a sophisticated attack campaign targeting recruiters. The hacker group FIN6 (Skeleton Spiders) has been creating fake candidate profiles with malware-laced resume attachments, tricking HR professionals into downloading zip files containing the "More Eggs" JavaScript backdoor. This social engineering tactic exploits normal recruiting workflows to steal credentials and gain network access. We discuss why security teams must partner with recruitment departments to develop specialized awareness training and technical controls to address this growing threat.
Diving into CISSP Domain 7.2, we explore fifteen practical questions about logging and monitoring implementations. We cover critical distinctions between detection and prevention technologies, explaining why deep packet inspection is essential for identifying encrypted command and control communications over HTTPS. We examine why log integrity and non-repudiation are paramount when logs may serve as legal evidence, and why HR data provides crucial context for User and Entity Behavior Analytics (UEBA) systems trying to identify insider threats.
For those implementing Network Intrusion Prevention Systems, we emphasize the importance of deployment in detection-only mode for extended tuning periods before enabling blocking capabilities. We examine why mean time to respond (MTTR) to critical incidents provides the most holistic metric for evaluating security operations effectiveness, and why automated ingestion of threat intelligence feeds delivers the most value for continuous monitoring objectives.
This episode balances technical depth with practical implementation guidance, making it valuable for both CISSP candidates preparing for the exam and practicing security professionals looking to strengthen their monitoring capabilities. Visit CISSP Cyber Training for access to all our training materials and sign up for 360 free practice questions to accelerate your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Dive deep into the critical world of security logging and monitoring as we explore Domain 7.2 of the CISSP certification. This episode unpacks the strategic considerations behind effective logging practices that balance comprehensive visibility with practical resource management.
We begin with a thought-provoking look at Anthropic's new AI chatbot designed specifically for classified government environments. Could this be the beginning of something like Skynet? While AI offers tremendous capabilities for processing classified data, these developments raise important questions about reliability, oversight, and unintended consequences.
The heart of this episode focuses on building a robust logging and monitoring strategy. We examine the various types of logs you should consider—security logs, system logs, application logs, network logs, and database logs—while emphasizing the importance of starting small and focusing on critical systems. You'll learn why centralized logging through SIEM platforms has become the industry standard, and how to approach log retention policies that balance regulatory requirements with storage costs.
Active monitoring, passive monitoring, and the correlation of events each serve distinct security purposes. We explore how techniques like log sampling and clipping levels can help manage the overwhelming volume of data modern networks generate, while highlighting the risks of missing critical security events if these techniques aren't properly implemented.
Special attention is given to egress monitoring—watching what leaves your network—as a crucial but often overlooked security practice. Since attackers ultimately need to extract data from compromised systems, monitoring outbound traffic can catch breaches even when the initial compromise was missed.
The episode rounds out with discussions on emerging technologies transforming the security monitoring landscape: SOAR tools that automate security operations, the integration of AI and machine learning for threat detection, and the strategic use of threat intelligence to understand attacker methodologies through frameworks like the cyber kill chain.
Whether you're preparing for the CISSP exam or working to strengthen your organization's security monitoring capabilities, this episode provides both the conceptual understanding and practical considerations you need. Connect with us at CISSP Cyber Training for more resources to support your certification journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The boundaries between digital vulnerabilities and physical warfare are dissolving before our eyes. Ukrainian forces have dramatically shifted military paradigms by marrying cybersecurity breaches with commercial drone attacks against strategic Russian targets like Tupolev aircraft manufacturers. This evolution demands security professionals develop capabilities far beyond traditional network defense – a stark reminder that our field continues expanding into unexpected territories.
Security testing forms the foundation of effective defense, and distinguishing between key methodologies is crucial both for the CISSP exam and real-world implementation. Vulnerability assessments detect weaknesses, while penetration tests exploit them to demonstrate actual impact. When evaluating your security testing approach, consider the perspective advantage: internal testing reveals different vulnerabilities than external probing, each simulating distinct attacker vantage points. False negatives represent perhaps the greatest danger in security testing – providing a dangerous illusion of safety while leaving actual vulnerabilities unaddressed.
Testing approaches vary in depth and disclosure level. Black box testing simulates external attacks with no prior system knowledge. White box testing grants complete access to internal architecture. Gray box testing offers a middle ground with partial system information – a cost-effective approach for organizations with tighter budgets. Red teams validate incident response plans through realistic attack simulations, while authenticated scans reveal vulnerabilities that exist beyond login barriers. By mastering these concepts for Domain 6.2, you'll build essential knowledge that translates directly to creating more secure environments and passing your CISSP exam the first time. Join us at CISSP Cyber Training for free practice questions and comprehensive preparation resources to accelerate your cybersecurity career.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Vulnerability assessments serve as the frontline defense against cybersecurity threats, yet many professionals struggle to understand the terminology and methodologies that make them effective. In this comprehensive episode, we demystify the critical components of vulnerability management that every security practitioner should master – whether you're preparing for the CISSP exam or strengthening your organization's security posture.
We begin by examining recent ransomware attacks targeting municipal governments across the United States, highlighting how 28 county and tribal governments have already fallen victim in 2024 alone. These incidents underscore why vulnerability management isn't just theoretical knowledge but an urgent practical necessity for protecting critical infrastructure and services.
Diving into the technical foundations, we explore how the Common Vulnerability and Exposures (CVE) system works, from discovery to disclosure, and how the Common Vulnerability Scoring System (CVSS) helps prioritize remediation efforts through its base, temporal, and environmental metrics. You'll gain clarity on related frameworks including CPE, CCE, and OVAL, understanding how these pieces fit together to create a comprehensive vulnerability management approach.
The episode also provides a practical breakdown of network scanning techniques essential for vulnerability discovery, including SYN scans, TCP connect scans, ACK scans, UDP scans, and Christmas tree scans. We explain the intricacies of the TCP handshake process and how different scanning methods leverage various aspects of this protocol to identify potential vulnerabilities while avoiding detection.
We also examine how AI-assisted code generation is transforming development practices, with 70% of professional developers expected to use these tools by 2027. While this technology promises significant productivity gains, it creates new security challenges that vulnerability assessment processes must address.
Whether you're studying for the CISSP exam or looking to strengthen your organization's security practices, this episode equips you with the knowledge to implement effective vulnerability management. Visit CISSP Cyber Training for additional resources to support your cybersecurity journey.
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ransomware attacks are surging at an alarming rate - a Scottish non-profit recently reported a 100% increase year-over-year, with fraud cases expected to exceed $33 million. Even more concerning, businesses report feeling less resilient against these threats than in previous years. As cybersecurity professionals, we have a responsibility to help organizations understand and mitigate these risks before they become existential threats.
Today's CISSP Question Thursday dives deep into Domain 5 concepts that directly address these challenges. We explore fifteen carefully crafted practice questions covering user account provisioning, deprovisioning, the principle of least privilege, Privileged Access Management (PAM), and identity governance. Each question targets critical knowledge areas you'll need to master for exam success while providing practical insights you can immediately apply to strengthen organizational security postures.
The practice questions reveal important security principles: collecting user information must precede role assignment in the provisioning process; deprovisioning should occur immediately upon employment termination; personal preferences should never determine access rights; and PAM tools are essential for securing privileged accounts. We also examine why multi-factor authentication enhances security through multiple verification forms while Single Sign-On improves user experience by simplifying authentication processes.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's security practices, this episode provides actionable knowledge to protect against today's evolving threat landscape. Visit CISSPCyberTraining.com to access our comprehensive blueprint and additional resources designed to help you pass your exam the first time. Share your thoughts on today's questions and let us know what topics you'd like us to cover in future episodes!
Support the show
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Navigating the complex landscape of authentication frameworks is essential for any cybersecurity professional, especially those preparing for the CISSP exam. This deep-dive episode unravels the intricate world of authentication systems that protect our digital identities across multiple platforms and services.
We begin by examining OAuth 2.0 and OpenID Connect (OIDC), exploring how these token-based frameworks revolutionize third-party authentication without exposing user credentials. When you click "Login with Google," you're experiencing these protocols in action—reducing password reuse while maintaining security across digital services. Learn the difference between authorization flows and how these systems interact to verify your identity seamlessly across the web.
The podcast then transitions to Security Assertion Markup Language (SAML), breaking down how this XML-based protocol establishes trust between identity providers and service providers. Through practical examples, we illustrate how SAML enables web single sign-on capabilities across educational institutions, corporate environments, and cloud services—creating that "connective tissue" between disparate systems while enhancing both security and user experience.
Kerberos, MIT's powerful network authentication protocol, takes center stage as we explore its ticketing system architecture. Named after the three-headed dog of Greek mythology, this protocol's Authentication Service, Ticket Granting Service, and Key Distribution Center work in concert to verify identities without transmitting passwords across networks. We also discuss critical considerations like time synchronization requirements that can make or break your Kerberos implementation.
For remote authentication scenarios, we compare RADIUS and TACACS+ protocols, highlighting their distinct approaches to the AAA (Authentication, Authorization, and Accounting) framework. Discover why network administrators choose UDP-based RADIUS for general network access while preferring the TCP-based TACACS+ for granular administrative control with command-level authorization and full payload encryption.
Whether you're studying for the CISSP exam or looking to strengthen your organization's security posture, this episode provides the knowledge foundation you need to implement robust authentication systems in today's interconnected world. Visit CISSP Cyber Training for additional resources to support your cybersecurity journey.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A shocking incident in Spain recently left 60% of the country's power grid dark in less than five seconds. Was it a cyber attack? The jury's still out, but this real-world event perfectly illustrates why understanding access controls and security mechanisms is critical for today's cybersecurity professionals.
Sean Gerber, despite battling a cold that affects his voice, delivers a compelling analysis of the Spanish power grid incident before diving into essential CISSP domain four content. He highlights how smaller electrical providers might have fewer security resources, making them attractive targets, and emphasizes the growing importance of professionals who understand both operational technology and information technology security.
The episode then transitions into practical CISSP exam preparation, exploring various types of access controls through real-world scenarios. Sean expertly distinguishes between preventative, detective, corrective, and deterrent controls, while also clarifying the differences between physical and logical security mechanisms. Particularly valuable is his breakdown of biometric authentication methods, pointing out how voice recognition (ironically demonstrated by his own cold-affected voice) proves less reliable than alternatives like iris scanning or fingerprinting.
Understanding the nuances between Mandatory Access Controls (MAC) and Discretionary Access Controls (DAC), implementing proper identity proofing processes, and recognizing when compensating controls are needed are all critical CISSP concepts covered in this content-rich episode. Whether you're preparing for certification or working to strengthen your organization's security posture, these lessons apply directly to building effective defense-in-depth strategies. Ready to master these concepts and pass your CISSP exam? Visit CISSP Cyber Training for a proven blueprint guaranteed to help you succeed.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What happens when a former Air Force weapons loader transforms into a cybersecurity expert? Clint Stevens from Physics joins us to share his remarkable journey through military intelligence, special operations support, and cyber warfare before founding his own security consultancy.
This conversation peels back the layers of cybersecurity consulting to reveal what truly matters for organizations trying to improve their security posture. Clint explains why expensive security tools often become glorified "paperweights" when organizations fail to understand their specific threat landscape first. His practical approach focuses on identifying business-specific risks rather than implementing generic solutions that waste resources without addressing real vulnerabilities.
For aspiring cybersecurity professionals, Clint offers refreshingly honest career advice that contradicts common assumptions. Rather than accumulating certifications without purpose, he emphasizes finding your passion within the vast cybersecurity landscape and developing hands-on experience. "Find what you're most interested in," he advises, noting that true expertise requires thousands of hours of dedication—something only sustainable when you genuinely enjoy the work.
Perhaps most valuable is Clint's insight into the crucial skill of translating technical findings into business impacts. This ability to communicate effectively with everyone from system administrators to CEOs—what Sean calls speaking "dolphin to shark"—often determines whether security recommendations are implemented or ignored. The conversation highlights why understanding both the technical and business perspectives is essential for career advancement in cybersecurity.
Whether you're preparing for the CISSP exam or exploring career opportunities in information security, this episode delivers practical wisdom from someone who's successfully navigated multiple roles in the field. Visit phycyx.com to learn more about Physics' approach to cybersecurity consulting.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Cybersecurity professionals need a solid understanding of secure communication protocols, not just for exam success but for real-world implementation. This episode unpacks the essential protocols covered in CISSP Domain 4.1.3, providing clear explanations of how each works and when to use them.
We begin with a timely discussion of the recent UnitedHealthcare hack, examining how ransomware crippled Change Healthcare systems nationwide. This case study highlights the critical importance of understanding security protocols and being able to articulate potential business impacts to leadership. Sean shares practical approaches for estimating downtime costs to help justify security investments.
The heart of this episode explores crucial security protocols including IPsec tunnels, Kerberos authentication, Secure Shell (SSH), and the Signal protocol. Each section covers how these technologies function, their ideal use cases, and their respective strengths and limitations. The discussion extends to transport layer security (TLS), layer 2 tunneling protocol (L2TP), and lesser-known protocols like secure real-time transport protocol (SRTP) and Zimmerman real-time transport protocol (ZRTP).
Sean breaks down complex technical concepts into accessible explanations, perfect for both CISSP candidates and practicing security professionals. Understanding these protocols isn't just about passing an exam—it's about making informed decisions when implementing security architecture in your organization. Whether you're preparing for certification or looking to strengthen your organization's security posture, this episode provides valuable insights into the fundamental building blocks of secure communications.
Check out cisspcybertraining.com for free resources including practice questions, training videos, and blog posts to support your cybersecurity learning journey.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Security regulations are changing dramatically in response to major breaches, and the implications for cybersecurity professionals are profound. Sean Gerber kicks off this episode with a career announcement, sharing his transition to independent consulting after 13 years with his previous employer—a move that highlights the evolving opportunities in the cybersecurity field.
The heart of this episode examines the recent UnitedHealthcare breach, where attackers targeted Change Healthcare, a critical system processing 15 billion healthcare transactions annually. The February ransomware attack led to a $22 million ransom payment and disrupted approximately half of all pharmacy operations across the United States. This incident serves as a perfect case study in critical infrastructure vulnerability and has triggered a significant regulatory response from the Biden administration, which is now promising "tough, mandatory cybersecurity standards" for the healthcare industry.
What does this mean for security professionals? Potentially stricter oversight, increased financial penalties, and perhaps most concerning—explicit executive liability for security failures. As Sean notes, these developments create an increasingly complex landscape where CISOs must navigate not just technical challenges but also regulatory expectations that might lack technical nuance.
The episode transitions into a comprehensive examination of CISSP exam questions covering Domain 3.6, focusing on message integrity, digital signatures, and cryptographic hashing functions. Through fifteen detailed questions and answers, Sean breaks down essential concepts like the difference between checksums and hashing functions, the evolution from SHA-1 to more secure algorithms, and the role of certificate authorities in public key infrastructure. These technical foundations aren't just academic—they're the building blocks of systems that, when implemented correctly, prevent exactly the kind of breach that hit UnitedHealthcare.
Ready to deepen your understanding of message integrity and prepare for the CISSP exam? Visit CISSP Cyber Training for videos, transcripts, and additional practice questions to help you master these critical concepts and advance your cybersecurity career.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ever wondered how your sensitive messages stay secure in an increasingly dangerous digital landscape? The answer lies in message integrity controls, digital signatures, and certificate validation – the core components of modern cybersecurity we tackle in this episode.
We begin with a timely breakdown of Microsoft's recent security breach by Russian hackers who stole source code by exploiting a test environment. This real-world example perfectly illustrates why proper security controls must extend beyond production environments – a lesson many organizations learn too late.
Diving into the technical foundation of message security, we explore how basic checksums evolved into sophisticated hashing algorithms like MD5, SHA-2, and SHA-3. You'll understand what makes these algorithms effective at detecting tampering and why longer digests provide better protection against collision attacks.
Digital signatures emerge as the cornerstone of secure communication, providing the crucial trifecta of integrity verification, sender authentication, and non-repudiation. Through practical examples with our fictional users Alice and Bob, we demonstrate exactly how public and private keys work together to safeguard information exchange.
The episode culminates with an exploration of digital certificates and S/MIME protocols – the technologies that make secure email possible. You'll learn how certificate authorities establish chains of trust, what happens when certificates are compromised, and how the revocation process protects the entire ecosystem.
Whether you're preparing for the CISSP exam or simply want to understand how your sensitive communications remain protected, this episode provides clear, actionable knowledge about the cryptographic building blocks that secure our digital world.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What happens when a security professional falls victim to malicious AI? The consequences can be devastating, as demonstrated by our analysis of a recent high-profile breach where a Disney security engineer downloaded AI-generated artwork containing hidden malware. This sophisticated attack led to the theft of 1.1 terabytes of sensitive corporate data and resulted in criminal charges for the attacker and career devastation for the victim. We break down exactly how it happened and the critical lessons for security professionals.
After exploring this cautionary tale, we dive into comprehensive practice questions focused on CISSP Domain 2: Asset Security. These challenges take you beyond textbook scenarios into the complex realities of modern information security governance. From metadata exposure risks and virtualization security to data sovereignty compliance and privacy protection, each question tests your ability to identify the most effective security controls and strategies in diverse enterprise environments.
The questions tackle particularly relevant security challenges including proper handling of sensitive data in cloud environments, managing security risks in mobile applications, and implementing responsible data sharing practices for research purposes. We emphasize crucial principles like data minimization, appropriate anonymization techniques, and breach notification requirements across multiple jurisdictions. Each question and explanation reinforces foundational CISSP concepts while developing your critical thinking skills for real-world implementations.
Ready to accelerate your CISSP preparation? Our Bronze package provides the comprehensive self-study blueprint you need to systematically master all CISSP domains. Visit CISSPCyberTraining.com today to access our complete library of resources designed specifically to help you pass the exam on your first attempt and advance your cybersecurity career.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Four million people affected by a single data breach. Let that sink in. This sobering reality frames today's deep dive into Domain 2 of the CISSP exam: Asset Security. As cybersecurity professionals, understanding how to establish proper information and asset handling requirements isn't just academic—it's essential for preventing exactly these types of incidents.
The podcast tackles the complete data security lifecycle, beginning with the foundations of asset security and the vital importance of having documented processes from data creation through destruction. Sean emphasizes repeatedly that security professionals must work hand-in-hand with legal and compliance teams when developing these frameworks to ensure proper protection for both the organization and themselves professionally.
Data Loss Prevention (DLP) strategies take center stage as we explore different approaches—from content-aware systems that analyze specific data patterns to endpoint protections that stop information from leaving devices unauthorized. The discussion moves into practical application with data classification schemes, where Sean advises starting small and building gradually to prevent overwhelming complexity. Physical markings, electronic tagging, and watermarking all serve as methods to identify sensitive information, but these tools only work when paired with comprehensive employee training.
Perhaps most compelling is the straightforward approach to data retention and destruction. "Don't be a data hoarder," Sean cautions, highlighting how unnecessary retention increases both storage costs and legal liability. The podcast outlines specific destruction methods including clearing, purging, degaussing, and crypto erasure—each with particular applications depending on data sensitivity and storage media. Throughout the episode, practical examples from real-world scenarios illustrate how these principles apply in actual cybersecurity practice.
Ready to master these essential CISSP concepts? Visit CISSP Cyber Training to access Sean's comprehensive blueprint for exam preparation and explore mentorship options to accelerate your cybersecurity career. Whether you're preparing for certification or strengthening your organization's security posture, these methodical approaches to asset security provide the foundation you need.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The cybersecurity talent gap is widening at an alarming rate. According to the 2023 ISC² Global Workforce Study, we're facing a shortfall of 5.5 million cybersecurity professionals by 2024, with the workforce needing to grow 12.6% annually just to keep pace with demand. Yet growth is stalling at only 8.7%, creating both challenges and unprecedented opportunities for those pursuing cybersecurity careers.
What might surprise aspiring security professionals is that technical skills alone won't secure your future. As Sean Gerber emphasizes, "You can give me the smartest person in the world that understands security, and if they don't have critical thinking skills and communication skills, it makes it extremely challenging to put them in front of somebody to explain what's going on." This insight reveals why soft skills have become the hidden differentiator in cybersecurity hiring. While certifications like CISSP remain essential credentials, employers increasingly seek professionals who can translate complex technical concepts into business language.
This episode dives deep into Domain 1.5 of the CISSP exam, exploring the complexities of breach notification and trans-border data flows. Through practical examples and challenging questions, we examine how to navigate conflicting international regulations like GDPR and China's data localization laws, implement appropriate anonymization techniques to prevent re-identification attacks, and develop strategic approaches to vulnerability management across global operations. Each scenario challenges listeners to think beyond technical solutions to consider legal, ethical, and business implications – precisely the mindset required to excel as a cybersecurity leader.
Whether you're preparing for the CISSP exam or looking to advance your security career, this episode provides actionable insights on balancing compliance requirements with business objectives in our increasingly interconnected world. Join us to strengthen both your technical knowledge and the crucial soft skills that will set you apart in a competitive job market where communication might be your most valuable security asset.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The rapid evolution of artificial intelligence and machine learning has created a pivotal moment for financial institutions. As these organizations race to implement AI solutions, they face both transformative opportunities and significant cybersecurity challenges that demand immediate attention.
Sean Gerber draws from over 20 years of cybersecurity experience to demystify the complex intersection of AI, machine learning, and financial security. With his straightforward approach, Sean breaks down the fundamental differences between AI (the broader field) and ML (the subset that enables systems to learn from data without explicit programming), making these concepts accessible even to those without technical backgrounds.
The central message resonates clearly throughout: AI must be developed and employed with a secure design approach from day one. Financial institutions that implement security as an afterthought rather than a foundation will inevitably face costly remediation down the road. Sean outlines practical security considerations including data anonymization, network segmentation, intellectual property protection, and AI-specific policies that organizations should implement immediately.
Through real-world examples from JP Morgan, Bank of America, and Capital One, we see how leading financial institutions are already leveraging AI for legal contract reviews, fraud detection, customer engagement, and risk assessment—all while implementing varying degrees of security controls to protect their systems and data.
Looking toward the future, Sean previews emerging trends including generative AI for threat analysis, federated learning approaches, and quantum-aware AI security that will reshape financial cybersecurity within the next five years. His practical action items emphasize building multidisciplinary teams spanning AI, cybersecurity, legal and business domains to ensure comprehensive implementation.
Whether you're a CISO at a major bank or a security professional preparing for emerging challenges, this episode provides the strategic framework needed to navigate AI implementation securely. The message is clear: investing time and resources in proper security foundations now will determine whether AI becomes your competitive advantage or your greatest vulnerability.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ever wonder why organizations with robust cybersecurity teams still fall victim to devastating attacks? The answer often lies not in fancy technology but in something far more fundamental: documentation.
In this eye-opening episode, Shon Gerber takes listeners into the critical world of cybersecurity documentation hierarchy, revealing how properly structured policies, standards, procedures, and guidelines form an organization's first and most important line of defense against threats.
The stakes couldn't be higher. As Shon reveals, cybercriminals stole a record-breaking $6.6 billion from US entities last year - a shocking 33% increase from the previous year. Business Email Compromise alone accounted for $2.7 billion in losses, while individuals over 60 remain the most vulnerable demographic.
What separates organizations that survive these threats from those that don't? Proper documentation that actually works rather than gathering digital dust. Shon breaks down the hierarchical relationship between different types of security documentation, providing real-world examples from healthcare and financial institutions to illustrate how these documents should build upon each other to create comprehensive protection.
You'll learn why policies should represent management intent, standards should specify requirements, procedures should provide step-by-step guidance, and guidelines should offer flexibility - all while avoiding common pitfalls that render documentation useless. Shon provides practical advice on creating documentation that's clear, accessible, and actually used rather than just created to appease auditors.
Whether you're preparing for the CISSP exam or working to strengthen your organization's security posture, this episode provides invaluable insights into creating documentation that transforms from a bureaucratic burden into powerful protection. Subscribe to CISSP Cyber Training for more expert guidance on mastering cybersecurity essentials and advancing your career in the field.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Cybersecurity isn't just for enterprises—small and medium businesses face increasingly sophisticated threats with fewer resources to combat them. In this information-packed episode, Shon Gerber explores why cybersecurity matters critically for SMBs while delivering practical CISSP exam questions focused on Domain 8.3.
Shon begins by examining how even non-tech businesses rely heavily on digital systems, making them vulnerable to attacks that could devastate operations. A ransomware incident targeting inventory management or employee scheduling could cripple a small business just as effectively as one targeting a financial institution. Business continuity planning—often overlooked until disaster strikes—becomes a critical safeguard that many small businesses simply don't consider until it's too late.
The economic reality of cybersecurity for small businesses creates a challenging landscape. While virtual CISO services and managed security operations centers offer potential solutions, many remain financially out of reach for smaller organizations. This creates a significant vulnerability gap in our business ecosystem that security professionals must work to address.
The episode then transitions into fifteen carefully crafted CISSP practice questions focusing on Domain 8.3, covering essential concepts like API security, content security policies, message queue poisoning, and the principle of least privilege in containerized environments. Each question explores real-world vulnerabilities while providing clear explanations about proper security approaches.
Whether you're studying for the CISSP exam or working to improve your organization's security posture, this episode delivers actionable insights on identifying and mitigating common application security vulnerabilities. Subscribe to the CISSP Cyber Training podcast for weekly deep dives into cybersecurity concepts that will help you pass your certification exam and become a more effective security professional.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Software security assessment can make or break your organization's defense posture, yet many professionals struggle with implementing effective evaluation strategies. This deep dive into CISSP Domain 8.3 reveals critical approaches to software security that balance technical requirements with business realities.
The recent funding crisis surrounding CVEs (Common Vulnerability Exposures) serves as a perfect case study of how fragile our security infrastructure can be. When the standardized system for cataloging vulnerabilities faced defunding, it highlighted our dependence on these foundational systems and raised questions about sustainable models for critical security infrastructure.
Database security presents unique challenges, particularly when managing multi-level classifications within a single environment. We explore how proper implementation requires strict separation between classification levels and how technologies like ODBC serve as intermediaries for legacy applications. The key takeaway? Data separation isn't just a technical best practice—it's an essential security control.
Documentation emerges as a surprisingly critical element in effective security. Beyond regulatory compliance, proper documentation protects security professionals when incidents inevitably occur. As one security leader candidly explains, when breaches happen, fingers point toward security teams first—comprehensive documentation proves you implemented appropriate controls and communicated risks effectively.
The most successful security professionals step outside their comfort zones, collaborating across organizational boundaries to integrate security throughout the development lifecycle. Static analysis, dynamic testing, vulnerability assessments, and penetration testing all provide complementary insights, but only when security and development teams maintain open communication channels.
Ready to strengthen your software security assessment capabilities? Join us weekly for more insights that help you pass the CISSP exam and build practical security knowledge that makes a difference in your organization.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Wondering how to tackle incident response questions on the CISSP exam? This episode delivers exactly what you need, walking through fifteen essential incident management scenarios that test your understanding of this critical domain.
Sean Gerber breaks down the fundamentals of incident management, exploring how security professionals should approach detection, response, mitigation, and recovery. From distinguishing between legitimate security incidents and routine activities to prioritizing response efforts based on severity, each question targets a specific aspect of incident management that CISSP candidates must master.
The questions systematically cover the incident response lifecycle, highlighting the importance of proper processes rather than blame-focused reactions. You'll learn why activating the incident response team should be your immediate priority upon detection, how to effectively categorize and prioritize incidents, and what constitutes valid mitigation strategies versus ineffective approaches. The episode also emphasizes the documentation requirements for incident reports and the value of capturing lessons learned for continuous improvement.
What makes this episode particularly valuable is how it reinforces the CISSP mindset—understanding not just the technical aspects but the thought processes behind effective security management. Whether you're preparing for certification or looking to strengthen your practical knowledge of incident response, these question scenarios provide the framework you need to approach real-world security events with confidence. Check out the special offer at CISSPCyberTraining.com to continue your certification journey with expert guidance.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Cybersecurity incidents aren't a matter of if, but when. Are you prepared to respond effectively?
Sean Gerber takes us through the complete incident response lifecycle, breaking down the seven essential phases every security professional must master. From developing comprehensive response plans to conducting effective post-incident analysis, this episode provides actionable guidance for both CISSP candidates and working cybersecurity practitioners.
The stakes couldn't be higher for small and medium-sized businesses, with a staggering 43% of cyber attacks specifically targeting SMBs. Most lack adequate protection due to limited budgets and resources. Sean explores practical solutions including leveraging AI tools to develop baseline response plans, implementing critical security controls like multi-factor authentication, and establishing clear communication protocols for when incidents occur.
What sets this episode apart is Sean's emphasis on the human element of security. "Every employee is a sensor," he reminds us, highlighting how proper training and awareness can transform your workforce into your first line of defense. He balances technical recommendations with strategic insights, including how to approach different types of incidents from ransomware to insider threats.
Whether you're preparing for the CISSP exam or strengthening your organization's security posture, this episode delivers the perfect blend of theoretical knowledge and real-world application. The incident response process outlined here will not only help you pass certification exams but could mean the difference between a minor security event and a catastrophic breach.
Ready to transform how you prepare for and respond to cybersecurity incidents? Listen now and discover why having a tested, comprehensive incident response plan is your best defense against the inevitable attack.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The collision of artificial intelligence and cybersecurity takes center stage in this episode as we explore how Agentic AI is revolutionizing Security Operations Centers. Moving beyond simple assistant AI or co-pilots, this new generation of autonomous systems proactively investigates alerts, follows structured playbooks, and performs triage at scale—potentially liberating human analysts from the crushing weight of alert fatigue.
For security professionals and organizations struggling with overwhelming SOC alert volumes, this technological advancement offers a glimpse into a future where human expertise can be directed toward high-value analysis while routine investigations happen autonomously. The potential efficiency gains are substantial, though implementation requires careful consideration and perhaps starting with a proof of concept.
Following this forward-looking discussion, we dive deep into CISSP domain 6.2 with fifteen targeted questions covering essential security testing methodologies. From misuse case testing and manual code review to vulnerability assessments and penetration testing, we examine the strengths and limitations of each approach. Learn why manual code review remains superior for detecting race conditions, how behavioral anomaly detection outperforms other methods for identifying lateral movement, and the critical distinctions between various testing approaches.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's security posture, this episode delivers practical insights into both emerging technologies and fundamental security testing principles. Join us to enhance your understanding of how these methodologies can be effectively deployed to protect critical systems and data in increasingly complex environments.
Visit CISSP Cyber Training today to access free practice questions, additional resources, or comprehensive training materials to support your cybersecurity journey.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Digital signatures are coming to AI models as cybersecurity evolves to meet emerging threats. Google's collaboration with NVIDIA and HiddenLayer demonstrates how traditional security controls must adapt to protect machine learning systems vulnerable to new forms of tampering and exploitation. This essential evolution mirrors the broader need for robust security validation across all systems.
Security control testing forms the foundation of effective cybersecurity governance. Without proper validation, organizations operate on blind faith that their protections actually work. In this deep dive into Domain 6.2 of the CISSP, Sean Gerber breaks down the critical differences between assessments, testing, and audits while exploring practical approaches to vulnerability scanning, penetration testing, and log analysis.
Vulnerability assessments serve as your first line of defense by systematically identifying weaknesses across networks, hosts, applications, and wireless infrastructure. The Common Vulnerability Scoring System helps prioritize remediation efforts, but understanding your architecture remains crucial - a low-scoring vulnerability in a critical system might pose more risk than a high-scoring one in an isolated environment. Meanwhile, penetration testing takes validation further by simulating real-world attacks through carefully structured phases from reconnaissance to exploitation.
As organizations increasingly embrace APIs, ML models, and complex software architectures, security testing must evolve beyond traditional boundaries. Code reviews, interface testing, and compliance checks ensure that security is built into systems from the ground up rather than bolted on afterward. The shift toward "security left" integration aims to catch vulnerabilities earlier in the development lifecycle, reducing both costs and risks.
Ready to master security control testing and prepare for your CISSP certification? Visit CISSPCyberTraining.com to access comprehensive study materials and a step-by-step blueprint designed to help you understand not just the exam content, but the practical application of cybersecurity principles in real-world scenarios.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Cybersecurity professionals know that mastering identity and access management concepts is essential for CISSP certification success. This deep dive into Domain 5.2 tackles fifteen carefully crafted questions covering everything from just-in-time provisioning to federated identity systems and session security.
We begin by examining the accelerating adoption of generative AI in healthcare organizations, where approximately 85% are investigating or implementing these technologies. This trend spans industries from manufacturing to financial services, creating both opportunities and serious security challenges for professionals who must balance innovation with appropriate safeguards.
The heart of our discussion focuses on critical IAM concepts, including how just-in-time provisioning minimizes attack surfaces by limiting standing privileges, particularly vital in cloud environments. We explore SAML as the primary protocol enabling federated architectures, while highlighting their potential single point of failure risks. Session management security receives special attention, emphasizing secure token storage with appropriate expiration times, and protection against cross-site scripting attacks that target cookie theft.
Throughout our exploration, practical security principles are reinforced: the dangers of shared credentials, the necessity of multi-factor authentication, and the security benefits of automated access revocation. Whether you're preparing for the CISSP exam or looking to strengthen your security knowledge, these concepts represent core knowledge every practicing security professional must internalize.
Ready to accelerate your CISSP journey? Visit CISSP Cyber Training for additional resources and guidance from experienced security professionals who understand the practical applications beyond theoretical knowledge. Let's grow your cybersecurity expertise together!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Identity management sits at the core of effective cybersecurity, yet many organizations still struggle with implementing it correctly. In this comprehensive breakdown of CISSP Domain 5.2, we dive deep into the critical components of managing identification and authentication systems that protect your most valuable assets.
Starting with a timely examination of the risks involved in the proposed rapid rewrite of the Social Security Administration's 60-million-line COBOL codebase, we explore why rushing critical identity systems can lead to catastrophic failures. This real-world example sets the stage for understanding why proper authentication management matters.
The episode walks through the essential differences between centralized and decentralized identity approaches, explaining when each makes sense for your organization. We break down Single Sign-On implementation, multi-factor authentication best practices, and the often overlooked importance of treating Active Directory as the security tool it truly is—not just an open database for anyone to query.
For security practitioners looking to level up their authentication strategy, we examine credential management systems like CyberArk, Just-in-Time access models, and federated identity frameworks including SAML, OAuth 2.0, and OpenID Connect. Each approach is explained with practical implementation considerations and security implications.
Whether you're studying for the CISSP exam or working to strengthen your organization's security posture, this episode provides actionable insights on establishing robust authentication controls without sacrificing usability. Don't miss these essential strategies that form the foundation of your security architecture.
Ready to master CISSP Domain 5.2 and all other CISSP domains? Visit CISSPCyberTraining.com for structured learning materials designed to help you pass the exam the first time.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Cybersecurity professionals, alert! A dangerous Chrome zero-day vulnerability demands your immediate attention. In this action-packed episode, Sean Gerber breaks down CVE-25-2783, a critical security threat that allows attackers to execute remote code simply by having users click malicious links. Though initially targeting Russian organizations, this exploit threatens Chromium-based browsers worldwide—including Chrome, Edge, Brave, Opera, and Vivaldi. Don't wait—patch immediately!
The heart of this episode delivers 15 expertly-crafted CISSP practice questions focusing on Domain 4.2 network security concepts. Sean methodically explores essential topics including router load balancing capabilities, electromagnetic interference vulnerabilities, NAC implementation benefits, and optimal firewall configurations. Each question peels back another layer of network security knowledge, from identifying mesh topologies as offering superior fault tolerance to understanding how protocol analyzers diagnose VLAN performance issues.
Advanced concepts receive equal attention with clear explanations of UDP timeout values in stateful firewalls, proper NIPS deployment strategies, VPN protocol security comparisons, broadcast storm mitigation techniques, and wireless security standards. Sean's straightforward breakdown of why WPA3 Enterprise provides superior protection and how ARP poisoning facilitates man-in-the-middle attacks transforms complex technical material into accessible knowledge that sticks.
Whether you're actively studying for the CISSP exam or simply looking to strengthen your network security fundamentals, this episode delivers precision-targeted information in an engaging format. Visit CISSP Cyber Training for complete access to all practice questions covered and accelerate your certification journey today!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The unexpected convergence of consumer technology and warfare takes center stage as Sean Gruber explores how Chinese e-commerce giants now sell drone accessories that transform $300 toys into semi-autonomous weapons. This eye-opening discussion reveals how modern drones with AI guidance modules and fiber optic tethers mirror strategies from World War I—except today's technology is far more accessible and difficult to defend against.
Against this backdrop, Sean delivers a comprehensive breakdown of Domain 4.2 (Secure Network Components) for the CISSP exam. He methodically examines transmission media vulnerabilities across legacy and modern infrastructure—from coaxial cables still found in specialized environments to the fiber optic networks revolutionizing global communications. Each technology receives detailed security analysis, with Sean highlighting how even supposedly "secure" media like fiber optic remain vulnerable to sophisticated tapping techniques.
The podcast ventures deep into wireless security territories, examining radio frequencies, Bluetooth vulnerabilities, Wi-Fi standards, and the substantial security improvements in 5G cellular networks. Sean explains how technologies like network slicing and zero-trust architecture are transforming mobile security, while also providing practical insights into endpoint protection strategies and the often-overlooked importance of hardware warranty management during security incidents.
For CISSP candidates, this episode delivers the perfect blend of exam-critical technical details and real-world context showing why these concepts matter in today's security landscape. The discussion effectively demonstrates how physical and cyber domains increasingly overlap, requiring security professionals to maintain broad knowledge across multiple disciplines.
Whether you're preparing for the CISSP exam or looking to strengthen your organization's network security posture, visit CISSPCyberTraining.com to access Sean's specialized preparation materials, including study blueprints tailored to various timeframes based on your personal schedule and learning needs.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Today's cybersecurity landscape demands vigilance on multiple fronts, something Sean Gerber demonstrates masterfully in this information-packed episode focused on CISSP Domain 3 security principles.
The episode opens with a critical security alert regarding Cox modems—a vulnerability potentially affecting millions of American households and businesses. While quickly patched by the company, this real-world example perfectly illustrates one of Gerber's key points: exposed APIs represent a massive blind spot in organizational security posture. "Many organizations truly do not understand how many API connections they have leaving their organization," Gerber warns, identifying this as a primary vector for data exfiltration.
Moving into the heart of the episode, Gerber walks listeners through fifteen challenging CISSP exam questions covering encryption standards, security principles, and practical implementation scenarios. Each question reveals essential security concepts—from why AES-256 should be prioritized over proprietary encryption algorithms to how abstraction and access controls function together in database security. The explanations break down complex topics into digestible, exam-ready knowledge while providing practical context for real-world application.
Perhaps most valuable is Gerber's focus on security principles working in concert rather than isolation. Defense-in-depth, secure defaults, data hiding, and integrity verification through hashing are explained through scenarios security professionals encounter daily. Whether you're preparing for the CISSP exam or looking to strengthen your organization's security posture, this episode delivers actionable insights and critical thinking frameworks to elevate your cybersecurity approach. Visit cissp cyber training.com to access these questions and additional resources that will help you pass the CISSP exam on your first attempt.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The cybersecurity landscape is constantly evolving, with even major corporations falling victim to devastating attacks. A recent UnitedHealthcare ransomware incident cost the company $22 million, with fingers pointing at leadership for allegedly appointing an unqualified CISO. This sobering reality highlights why defense in depth strategies aren't just theoretical concepts—they're essential protective measures for organizations of all sizes.
Defense in depth implements multiple security layers that work together like a medieval castle's defenses. When one layer fails, others remain to protect your assets. This approach serves two crucial functions: frustrating attackers enough that they move to easier targets, and creating trigger points that alert your team to potential breaches. From firewalls and IDS/IPS systems to role-based access controls and encryption, each layer contributes to a comprehensive security posture.
Beyond implementing multiple controls, we explore the critical concept of secure defaults—ensuring systems are configured securely from the moment they're deployed. Unfortunately, many products arrive with functionality prioritized over security, requiring security teams to implement proper configurations before deployment. This includes setting up strong password requirements, disabling unnecessary services, configuring automatic updates, and establishing proper network rules.
Balancing security with usability presents ongoing challenges. Each additional security layer adds complexity, impacts performance, and potentially frustrates users. The most effective security professionals find that sweet spot where protection is robust without driving users to circumvent controls. Documentation, regular reviews, and automated configuration management form the foundation of sustainable security practices.
Ready to enhance your security knowledge and prepare for your CISSP certification? Visit CISSPCyberTraining.com for my comprehensive blueprint and sign up for 360 free practice questions to help you pass your exam the first time.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
A seemingly simple company restructuring at Eaton triggered a devastating cybersecurity incident when software developer Davis Liu planted a logic bomb on their systems after learning his responsibilities would be reduced. This cautionary tale kicks off our deep dive into CISSP Domain 1 concepts, showing exactly why understanding security governance and risk management principles matters in real-world scenarios.
The logic bomb—crafted in Java code to create infinite loops crashing servers—activated upon Liu's termination, causing global disruption and hundreds of thousands of dollars in damage. Now facing up to 10 years in prison, Liu's poor decision perfectly illustrates why organizations must implement robust controls against insider threats.
Through a series of challenging Domain 1 practice questions, we explore how access controls serve as critical technical safeguards for data privacy, and why establishing risk management programs that incorporate legal, regulatory, and industry standards forms the foundation for aligning security with business objectives. We also tackle the complexities of regulatory compliance across healthcare, financial services, and multinational organizations, emphasizing the value of centralized data protection offices and contractual safeguards for cloud services.
The episode provides practical guidance for security professionals facing common challenges: how to handle budget constraints when addressing high-risk vulnerabilities (prioritize based on business impact), what makes ISO 31000 valuable as a risk management framework (its focus on integrating risk into business processes), and why executive sponsorship represents the most important factor for successful security governance implementation.
For CISSP candidates, we clarify essential concepts including the purpose of information security policies (establishing management's intent), the principle most likely to determine liability after a breach (due care), and the most effective controls against insider threats (least privilege combined with activity monitoring).
Ready to accelerate your CISSP preparation? Visit cissp-cyber-training.com for comprehensive training materials, practice questions, and mentorship options tailored to your certification journey.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
The traditional boundaries between physical and cyber security are rapidly disappearing, creating both risks and opportunities for organizations of all sizes. This eye-opening conversation with Casey Rash from Secure Passage explores the critical intersection where these two domains meet and the innovative solutions emerging to bridge this gap.
Casey brings his fascinating journey from Marine Corps signals intelligence to fintech security to the partner side of cybersecurity, sharing valuable insights about career development along the way. His key advice resonates deeply: build a strong professional network and be open to exploring different security domains before finding your niche.
The conversation dives deep into how everyday physical security devices have evolved into sophisticated data collection points. Today's smoke detectors can identify THC in vape smoke and detect distress calls. Modern security cameras perform advanced detection functions like tracking objects, identifying crowd formations, and reading license plates. All this creates valuable security telemetry that remains largely untapped in most organizations.
What makes this discussion particularly valuable for security professionals is understanding how Secure Passage's solutions—Haystacks and Truman—map to specific CISSP domains including Security Operations, Security and Risk Management, and Asset Security. Their "Physical Detection and Response" (PDR) approach applies cybersecurity principles to physical security data, creating a more holistic security posture.
Perhaps most telling is the organizational disconnect Casey highlights between physical and cyber teams. As he notes, "If you talk to CISOs today, it's a crapshoot who's managing physical security." This division creates significant risk, as threats in one domain frequently impact the other—from terminated employees becoming both physical threats and insider cyber risks to non-human identities outnumbering human identities 10-to-1 in most environments.
Ready to rethink your approach to comprehensive security? This conversation provides the perfect starting point for bridging the gap between your physical and cyber security programs. Check out securepassage.com to learn more about their innovative solutions.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
The $150 million cryptocurrency heist linked to the 2022 LastPass breach serves as a powerful wake-up call for cybersecurity professionals. As Sean Gerber explains in this comprehensive breakdown of CISSP Domain 2.1, even security-focused tools can become vulnerability points when housing your most sensitive information.
Dive deep into the pyramid structure of data classification, where government frameworks (Unclassified, Confidential, Secret, Top Secret) and non-government equivalents (Public, Sensitive, Private, Confidential/Proprietary) provide the foundation for effective information protection. This systematic approach to identifying and classifying information and assets isn't just theoretical—it's a practical necessity in today's complex regulatory landscape.
The episode meticulously examines classification criteria, benefits, and implementation challenges. You'll discover why identifying data owners is non-negotiable, how classification enhances security while optimizing resources, and why enterprises without leadership buy-in are fighting a losing battle. Sean provides actionable insights for protecting data across all three states: at rest, in transit, and in use.
Security professionals will appreciate the comprehensive review of industry-specific regulations requiring data classification, from GDPR and HIPAA to sector-specific frameworks like Basel III for banking and NERC SIP for energy infrastructure. Understanding these requirements isn't just exam preparation—it's career preparation.
Whether you're studying for the CISSP exam or implementing security controls in your organization, this episode delivers practical wisdom you can apply immediately. Connect with Sean at CISSPCyberTraining.com for additional resources to ace your exam on the first attempt, or reach out through ReduceCyberRisk.com for consulting expertise in implementing these principles in your enterprise.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Ransomware attacks are a growing concern for both businesses and individuals, as the frequency and sophistication of these threats continue to escalate. In this episode, we take a closer look at this alarming trend and introduce six effective methods for recovering critical data that's been locked away due to ransomware encryption, specifically focusing on encrypted virtual machines.
We begin by dissecting the mechanisms behind ransomware and discussing its increasing prevalence in today's cyber landscape. Listeners will learn practical insights on utilizing recovery methods such as mounting drives and specialized extraction tools, empowering them with the knowledge to take action in the event of an attack. Each strategy comes with its unique challenges, yet crucial insights on how to handle these situations are shared, ensuring that a comprehensive guide is at your fingertips.
Given the chaotic nature of ransomware incidents, we also emphasize the importance of having a disaster recovery plan tailored to your specific cyber resilience requirements. We'll delve into business continuity strategies that highlight data prioritization and securing essential functions, aiming to minimize downtime and enhance recovery outcomes.
In addition to our ransomware-focused conversation, we include a Q&A portion that addresses listeners' most pressing cybersecurity questions, offering guidance on business impact assessments and best practices for preparedness.
Join us for this enlightening discussion that not only aims to inform but also empowers you to take proactive steps in protecting your data. Make sure to tune in, engage with our insights, and don’t forget to subscribe, share, and leave a review if you find our content valuable!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Welcome to a compelling exploration of the crucial importance of Business Impact Analysis (BIA) in ensuring cybersecurity resilience, especially for those preparing for the CISSP exam. In this episode, we dive deep into the essentials of BIA, breaking down both qualitative and quantitative impact assessments that help organizations evaluate the potential repercussions of cybersecurity incidents. With recent ransomware attacks making headlines, organizations face unprecedented challenges in safeguarding critical infrastructure. Throughout our discussion, we underscore the pressing need for cybersecurity professionals to understand both the technical and strategic elements of BIA and how its effective execution can significantly influence organizational outcomes.
We also address the emerging complexities introduced by cloud technologies, emphasizing the need to scrutinize third-party providers' security practices and regulatory compliance adequately. As attackers become more sophisticated, a robust BIA not only prepares organizations to respond effectively to incidents but also empowers them in their overall risk management strategy.
Join us for this insightful episode filled with expert insights, real-world examples, and actionable takeaways that will not only help you ace your CISSP exam but also make you an invaluable asset to your organization’s cybersecurity efforts. Don’t miss out on these critical skills – your future in cybersecurity depends on it. Subscribe now, and let’s together navigate the intricate world of cybersecurity!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Get ready for an eye-opening deep dive into the world of cybersecurity! This episode reveals the alarming speed at which hackers adapt and exploit vulnerabilities, with over 61% of them leveraging new exploits within 48 hours of discovery. We discuss enlightening insights from InfoSecurity Magazine and showcase the new Netflix documentary "Zero Day," which delves into the insidious realm of malware and cyberattacks.
Things take a darker turn as we recount a chilling story about a local priest whose voice was hijacked by criminals using AI to swindle desperate individuals claiming to need exorcisms. This event highlights the surreal intersections of faith, vulnerability, and technology in today’s world.
For small and medium-sized businesses, the conversation explores the additional risks posed by ransomware, which accounts for a staggering 95% of healthcare breaches. We dissect the unique challenges these entities face and the importance of investing in robust security measures.
We also bring you a series of CISSP questions that challenge listeners to consider their knowledge and preparedness in combating emerging cyber threats. These questions encompass important topics, including risk mitigation, insider threats, and security protocols.
Join us on this critical journey through today's cybersecurity landscape, and make sure to take proactive steps for your safety. Don’t forget to subscribe, share, and leave a review to keep the conversation going!
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Unlock the secrets to fortifying your software development practices with expert insights from Shon Gerber. As we navigate the complex landscape of cybersecurity, we delve deep into the urgent risks posed by TP-Link routers, used by a staggering portion of U.S. households. Discover practical strategies for protecting your network, like firmware updates and firewall configurations, and learn how potential geopolitical threats could reshape your tech choices. This episode arms you with the knowledge to safeguard your digital ecosystem against looming threats and prepares you for possible shifts in government regulations.
Venture into the vibrant world of programming languages and development environments, tracing their evolution from archaic beginnings with BASIC and C# to today's dynamic platforms like Python and Ruby on Rails. Shon unravels the intricacies of runtime environments and libraries, emphasizing why sourcing trusted libraries is non-negotiable in preventing security breaches. For those new to programming, we demystify Integrated Development Environments (IDEs) and offer insights into why securing these tools is paramount, especially as AI makes coding more accessible than ever before.
As we wrap up, Shon guides you through best practices for securing both your development and runtime environments. From addressing vulnerabilities inherent in IDEs to ensuring robust CI/CD pipeline security, we cover it all. Learn about the pivotal role Dynamic Application Security Testing (DAST) plays and how to seamlessly integrate it within your development processes. This episode is a trove of actionable advice, aimed at equipping you with the skills and foresight needed to enhance your cybersecurity strategies and development protocols. Don’t miss this comprehensive guide to making informed decisions and fortifying your software’s security posture.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Curious about the latest tactics cybercriminals are using to exploit vulnerabilities in messaging apps? Join me, Shon Gerber, on the CISSP Cyber Training Podcast as we unravel how Russian hackers are leveraging malicious QR codes to breach platforms like Signal, Telegram, and WhatsApp. We'll dissect this alarming trend that targets high-profile individuals including politicians and journalists, and underscore the importance of staying vigilant when interacting with QR codes. Despite fighting off a cold, I share a heartening story of collaboration with a student who helped correct errors in our study materials, reminding us all of the power of continuous learning and positive contributions to the cybersecurity community.
Ever wondered how digital forensics can help you get ahead of potential cybersecurity incidents? Discover essential techniques for conducting thorough investigations as we unpack the art of digital forensics and incident response. From using static analysis to safely examine suspicious files, crafting incident reports with precision, to tackling insider threats with comprehensive artifact collection, this episode covers it all. Learn about the role of tools like Cellebrite in mobile device analysis and the critical importance of maintaining a chain of custody to safeguard evidence integrity. We also highlight root cause analysis as a key strategy for dissecting malware outbreaks and fortifying your organization’s defenses.
Looking to deepen your cybersecurity expertise? We’ve got you covered with a treasure trove of resources, including video content on our CISSP Cyber Training blog and consulting services through partnerships like NextPeak. Whether you’re a seasoned expert or just beginning your journey, these tools are designed to enhance your skills and provide specialized guidance. Explore how anomaly-based detection aids in spotting malicious network activity and why clear, jargon-free reporting is crucial in post-incident reviews. This episode promises to equip you with the insights needed to navigate the evolving landscape of cybersecurity challenges and opportunities.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Uncover the secrets to mastering firewalls and advancing your cybersecurity career with insights from the CISSP Cyber Training Podcast. Ever wondered how a simple firewall can be your strongest ally against a $12 billion threat that financial firms have faced over the past two decades? Join me, Sean Gerber, as we navigate the indispensable role of firewalls within cybersecurity, especially for those gearing up for the CISSP exam. This episode promises an enriched understanding of firewalls, from regulatory compliance to integrating next-generation firewalls in cloud environments like Azure and AWS.
The discussion extends beyond technicalities, emphasizing the importance of understanding the entire security chain for effective implementation and maintenance of firewalls. By exploring real-world scenarios, such as the implementation of government-mandated firewalls in Sri Lanka, we highlight how robust logging systems and regulatory compliance are vital in shaping a secure network architecture. The complexities of handling advanced intrusion attempts with next-generation firewalls are unraveled, showcasing their application-layer protection and their importance in achieving a resilient security posture.
Engage with practical advice on marketing your cybersecurity expertise within your organization and strategies for transitioning into security roles. We also touch on key managerial concepts essential for conquering the CISSP exam. From tackling practice questions to understanding the nuances of firewall architecture, this episode serves as a comprehensive guide to excel in your cybersecurity journey. With a focus on balancing innovative technology with organizational needs, listeners are encouraged to think beyond binary solutions and embrace a managerial mindset in their path to becoming cybersecurity leaders.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the future of cybersecurity as we unravel the complexities of AI, quantum computing, and network security. Ever wondered how AI could transform your corporate security measures? Explore its dual nature, both as a defender against threats and a potential tool for cybercriminals. Discover what 63% of IT pros at Google foresee about AI’s role in cybersecurity, and prepare for the seismic shifts quantum computing promises in just a few years, as warned by the NSA. Equip yourself with strategic insights on leveraging these advancements, ensuring your defenses are not just reactive but proactively fortified.
Dive into the nitty-gritty of network security methodologies crucial for your CISSP exam preparation. Learn the secrets behind TCP SYN scans and the infamous Christmas scan, and understand how CVE identifiers and CVSS metrics play into your security strategy. We’ll guide you through the nuances of the Common Platform Enumeration scheme and the findings of a TCP-ACK scan on unfiltered ports. Enhance your study arsenal with resources from CISSP Cyber Training, offering a curated mix of free and premium content to turbocharge your learning. Whether you're on the move or at your desk, the strategic blueprint will ensure your exam success. Explore how these tools and techniques can shape your mastery of cybersecurity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to safeguarding your cloud storage from becoming a cyber attack vector in our latest episode of the CISSP Cyber Training Podcast with Shon Gerber. Discover how neglected AWS S3 buckets can pose significant threats akin to the notorious SolarWinds attack. Shon breaks down the importance of auditing and access controls while providing strategic guidance aligned with domain 6.1 of the CISSP to fortify your knowledge for the exam. This episode promises to equip you with the essential tools to protect your cloud infrastructure and maintain robust security practices.
Transitioning to security testing, we explore various methodologies and the vital role they play in incident readiness and data integrity. From vulnerability assessments to penetration testing and the collaborative efforts of red, blue, and purple teams, Shon sheds light on the automation of these processes to enhance efficacy. We also demystify SOC 1 and SOC 2 reports and discuss their criticality in vendor risk management and regulatory compliance. With insights into audit standards like ISO 27001 and PCI DSS, this episode is your comprehensive guide to understanding and applying security measures across diverse sectors.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to cybersecurity success with Sean Gerber as your guide, promising not just knowledge but mastery of domain five for your CISSP exam. Will you be the one who finally understands the intricacies of identity and access management, or the latest defense tactics against the alarming rise of ransomware attacks? These are just a few of the critical insights we explore, providing you with the practical tools needed to safeguard organizations and ensure business resilience in today's digital battleground.
As we navigate the complex world of identity governance and privileged access management, Sean unpacks the transformative power of multi-factor authentication and single sign-on in solidifying security protocols. Discover how the principle of least privilege can be your organization’s best friend in minimizing breach risks and achieving compliance. Beyond just passing an exam, this episode arms you with insights that will make you an indispensable force in cybersecurity. Plus, explore the robust resources available through CISSP Cyber Training, designed to propel you towards certification success. Don’t miss your chance to become an asset in the ever-evolving world of cybersecurity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Discover the game-changing strategies to strengthen your company's cybersecurity posture with our latest episode on CISSP Cybersecurity Training and Board Expertise. We reveal shocking insights: only 5% of company boards have cybersecurity expertise, a glaring gap that can jeopardize risk management and financial stability. Listen as we advocate for the integration of cybersecurity professionals into risk committees, a move proven to enhance security measures and boost shareholder confidence. Get ready to transform your board's approach to cybersecurity.
Unlock the secrets to effective Role-Based Access Control (RBAC) and learn how to shield your organization from credential creep threats. Long-term employees and contractors like Sean are especially vulnerable, but with well-defined roles and responsibilities, you can assign privileges with precision and prevent conflicts of interest. This episode unpacks the complexities of role hierarchy and the importance of role lifecycle management, emphasizing regular audits and compliance to keep your security framework airtight and aligned with business needs.
Managing employee transitions is a critical challenge, and we discuss how deprovisioning and offboarding are vital components in maintaining security integrity. Prompt account deactivation, asset retrieval, and data retention management are just the beginning; delve into the role of identity and access management tools like single sign-on systems and multi-factor authentication. Discover how adaptive authentication and compliance considerations ensure your protocols meet regulatory standards while safeguarding your company's digital assets and data. Prepare to step up your cybersecurity game with expert insights and proven strategies from our podcast.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ready to unlock the secrets of cybersecurity and ace your CISSP exam? Tune in to the latest episode of the CISSP Cyber Training Podcast, where I, Shon Gerber, guide you through the complexities of a groundbreaking malware discovery by Black Lotus Labs. Unearthed in Juniper routers within critical sectors, JMAGIC poses a stealthy threat by lingering in memory and potentially exfiltrating data. As we dissect this sophisticated malware, we'll also address pivotal CISSP exam questions, offering insights into defending against unauthorized access to SS7 signaling systems and the risks associated with unauthorized VoIP calls to premium rate numbers.
Prepare to fortify your telecommunication systems as we uncover strategies to combat vishing, unauthorized PBX call forwarding, and the vulnerabilities of SS7 protocols. You'll learn about leveraging Secure Real-time Transport Protocol (SRTP) for encrypting VoIP communications and employing robust spam filters to counter SPIT. As we wrap up, I’ll provide a tried-and-true CISSP exam preparation blueprint to bolster your confidence and readiness. Whether you're keen on enhancing your cybersecurity prowess or ensuring exam success, this episode is packed with essential knowledge and strategies designed to help you thrive in the ever-evolving cybersecurity landscape.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of voice security and communication evolution with Shon Gerber on the CISSP Cyber Training Podcast. We tackle the intriguing issue of Subaru's Starlink vulnerability, which Wired Magazine recently spotlighted. This flaw, affecting about a million vehicles, highlights the growing security challenges of IoT and connected vehicles, echoing similar vulnerabilities in other brands like Acura and Toyota. Tune in to discover how these incidents shape the landscape of cybersecurity in the automotive industry.
Journey through the fascinating history of communication systems, from the hands-on days of telephone operators to the seamless digital networks we rely on today. Explore the transformation of circuit switch networks and the critical role played by SS7 systems, all while navigating the complex security risks they introduce, such as interception and eavesdropping. Gain insight into how technological progress has bridged global communication gaps and the essential awareness required to address the concomitant security implications.
Our conversation takes a deep dive into the world of secure voice communications, examining the transition from traditional analog methods to modern VoIP technology. With threats like eavesdropping, man-in-the-middle attacks, and denial of service on SIP protocols, understanding the nuances of VoIP security is crucial. We also demystify social engineering tactics like vishing and phreaking, offering strategies to bolster defenses against these manipulative threats. Prepare to enhance your cybersecurity expertise and safeguard your systems with practical advice and cutting-edge information.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to robust cybersecurity with our latest episode, where we explore the critical importance of organizational resilience in the face of inevitable cyber threats. We promise you'll gain a comprehensive understanding of the Digital Operational Resiliency Act (DORA) and its profound implications for financial institutions across the UK and EU. Discover why ICT risk management, incident reporting, and information sharing are not just regulatory obligations but vital components to safeguarding your business. Learn from the proactive strategies employed by financial giants like JP Morgan and understand the hefty penalties at stake for non-compliance. Join us as we illuminate the path financial services are taking to address these urgent challenges, ensuring both compliance and resilience.
Shifting gears, we dive into essential cybersecurity concepts that every CISSP aspirant should know. From safeguarding against the sinister VM escape attacks to harnessing the power of ECC memory in high-security environments, this episode covers it all. We dissect vulnerabilities like Meltdown and explore how technologies like Intel SGX can protect your data within a CPU's enclave. Plus, find out about our exciting developments in CISSP Cyber Training and consulting services with Reduce Cyber Risk, designed to empower businesses of all sizes. Whether you're just starting out or looking to fortify your existing knowledge, this episode is your gateway to mastering cybersecurity like never before.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to fortified cybersecurity with our latest episode, promising to equip you with the knowledge to safeguard your digital infrastructure. We explore the vital role memory protection plays in maintaining system stability and integrity, emphasizing the need to shield it from unauthorized access. Discover the strategies for defending against notorious vulnerabilities like Meltdown and Spectre and learn why it's crucial to address zero-day threats, such as those recently identified in Fortinet firewalls.
Venture into the realm of virtualization with a comprehensive comparison of type one and type two hypervisors. Whether you're a large enterprise or a small business, understanding the nuances of these technologies is crucial for maximizing performance and security. We'll dissect memory isolation techniques and delve into potential threats, including VM escape and side-channel attacks. Our discussion extends to Trusted Platform Modules (TPMs) and their critical contribution to cryptographic security, navigating regulations across different regions.
As we conclude, explore the importance of Trusted Platform Modules (TPMs) and Hardware Security Modules (HSMs) in forming robust cybersecurity strategies. We'll break down the types of TPM 2.0 and guide you in selecting the best fit for your organization's needs. Discover how to mitigate risks associated with direct memory access attacks and ensure fault tolerance through memory protection techniques. Finally, gain insights into crafting a successful path through the CISSP exam, and learn about the consulting resources available at reducecyberrisk.com to bolster your security posture.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to acing your CISSP exam with insights that blend real-world cybersecurity wisdom and innovative study strategies. Ever wondered how a data breach, like the one at SuperDraft, can teach you crucial lessons about protecting your information? We'll explore how securing your data and freezing your credit are essential steps in the fight against password reuse risks. Join Sean Gerber as we unpack the vital role of asset owners in defining access control policies and delve into the challenges of managing virtual assets in cloud environments, where virtual machine sprawl poses significant threats. Plus, get excited about potential new tools and a gamified platform that could revolutionize your CISSP study experience.
Prepare to navigate the complex realm of data security and asset management as we spotlight the critical need for security and compliance in handling both tangible and intangible assets. Discover the hidden risks of inadequate encryption and learn why regular audits of hardware and software inventories are non-negotiable. We’ll emphasize the importance of tagging cloud resources for cost management and explore the secure disposal of sensitive data. With discussions on data classification schemes, configuration management systems, and the dangers of shadow IT, you’ll gain the insights needed to maintain consistent configurations and ensure license compliance, all while reducing security vulnerabilities. Tune in to arm yourself with the knowledge that will propel your cybersecurity career forward.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of data security and asset management with Shon Gerber as your guide. Ever wondered how to navigate the intricate world of CISSP cyber training and protect your organization from data breaches? This episode promises to equip you with essential strategies to conduct security assessments, especially when third-party vendors like Gravy Analytics come into play. Learn why educating your employees on location tracking dangers is crucial and how mobile device control systems can fortify your data privacy defenses.
Dive deep into the roles of information and asset owners within organizations, and discover how effective data classification and collaboration can safeguard your most sensitive information. Shon discusses the critical nature of aligning responsibilities and understanding data ownership for compliance with regulations such as GDPR and HIPAA. With a clear plan and defined roles, your organization will be better prepared for audits and risk management. Understand the distinction between data creation and usage responsibility, and transform your approach to asset lifecycle management.
As we touch upon the challenges of managing virtual sprawl and cloud environments, Shon shares insights into tackling unchecked growth and escalating costs. Explore the nuances of cloud-based asset management across platforms like AWS, Azure, and Google Cloud. Learn the importance of resource visibility, cost management, and how to handle data residency and sovereignty issues. Finally, grasp the complexities of cloud environments, from encryption to rogue device identification, and forge a robust plan to mitigate vulnerabilities and compliance violations.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to mastering cybersecurity and prepare yourself for the CISSP exam with our latest episode of the CISSP Cyber Training Podcast. Ever wondered how a simple API misstep could lead to a major breach? We dive into a recent incident involving the Department of Treasury and Beyond Trust, showcasing the critical importance of API security. As we navigate through domain 1.6, we promise to enhance your understanding of key concepts like the preponderance of evidence in civil investigations and the main objectives of regulatory probes. This episode is packed with insights that are not only essential for your exam preparation but also invaluable for your cybersecurity strategy.
Join us as we unravel the complexities of legal and regulatory investigations. From understanding why reviewing an organization's policies is the cornerstone of internal administrative investigations to dissecting the GDPR framework for data protection, we cover it all. Learn the nuances between civil and criminal investigations and how insider trading is scrutinized by financial regulators while non-compete violations are typically handled administratively. Whether you're gearing up for the CISSP exam or looking to bolster your cybersecurity knowledge, this episode offers comprehensive insights that will certainly enrich your perspective and expertise.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to mastering the CISSP exam with insights that could transform your cybersecurity career. Have you ever considered how failing to change a default router password could be your greatest vulnerability? Join me, Sean Gerber, as I guide you through the essential topics that every aspiring security professional needs to understand as we step into 2025. From administrative to regulatory investigations, this episode covers the diverse landscape of investigation types and underscores the importance of staying vigilant against cyber threats like man-in-the-middle attacks and DDoS attacks.
In this episode, we unravel the complexities of digital evidence and the crucial role of e-discovery in legal proceedings. Learn about the Electronic Discovery Reference Model (EDRM) and how it serves as a cornerstone for managing electronic evidence. We dive into the nuances of maintaining evidence integrity, the legalities of digital forensics, and the critical importance of a robust data retention strategy. As we dissect computer crimes and their impacts, you'll gain a deeper appreciation for the challenges and intricacies involved in handling cybersecurity incidents.
Concluding with a rich discussion on ethical and legal investigation procedures, we highlight key regulatory frameworks such as GDPR and CCPA. Understand the importance of obtaining consent for monitoring and maintaining a chain of custody for evidence. With practical tips and resources, including those from ReduceCyberRisk.com, this episode equips you with the knowledge to not only pass the CISSP exam but to thrive in an ever-evolving cybersecurity landscape. Whether you're a seasoned professional or new to the field, you'll find valuable insights to bolster your defense against the relentless advance of cyber threats.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
This episode underscores the rising threat of cross-domain attacks and the critical importance of identity management in cybersecurity. We discuss evaluating software risks, the nuances of open-source versus COTS solutions, and the necessity of robust SLAs in managed services.
• Importance of understanding cross-domain attacks and their implications
• Role of identity and access management in mitigating vulnerabilities
• Evaluating open-source software based on community engagement
• Challenges of commercial off-the-shelf software in security assessments
• Importance of managed services SLAs in establishing expectations
• Distinction between pen testing and static code analysis in evaluations
• Shared responsibility model clarifying security task divisions
• Ongoing reassessments as a response to evolving risks and threats
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Could you navigate the complexities of cybersecurity like a pro and walk confidently into the CISSP exam? Join us as Sean Gerber shares his expert insights on conquering common test pitfalls and emphasizes the crucial strategy of thinking like a manager. From mastering the art of pacing to trusting your instincts, you'll gain valuable knowledge on how to read questions methodically and manage your time effectively. Plus, we're not just examining theoretical knowledge—Sean breaks it down into practical applications, particularly when assessing the security risks associated with commercial off-the-shelf software.
In today's cloud-reliant world, understanding service evaluation best practices is essential. We explore the critical considerations in managing services like SaaS, IaaS, and PaaS. Learn which questions to prioritize when engaging with service providers, such as inquiring about their data protection strategies, encryption standards, and compliance with essential frameworks like SOC 2 and ISO 27017. Discover how the shared responsibility model for IaaS impacts your security measures, and unlock the secrets to secure API configurations. We also stress the importance of thorough risk assessment, threat modeling, and adhering to secure development standards like ISO 27034 and IEC 62443.
Software selection is a major decision, and due diligence can make all the difference. This episode unravels how to rigorously evaluate software vendors, focusing on credibility, security assessments, and compliance with industry standards. With Sean's guidance, you'll learn to conduct comprehensive code reviews, penetration tests, and evaluate vendor support. We also highlight strategic deployment planning, emphasizing API security, threat modeling, and a robust mitigation plan. Finally, we unveil the extensive cybersecurity services offered by Reduce Cyber Risk, paired with exciting news about an upcoming podcast designed to bolster your cybersecurity knowledge even further.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of cybersecurity mastery with me, Sean Gerber, on this week's episode of the CISSP Cyber Training Podcast. Discover why the U.S. government is investing a staggering $3 billion to replace TP-Link routers and the strategic implications for telecom companies nationwide. We'll also dissect the National Defense Authorization Act, which aims to fortify AI adoption and tackle emerging threats through an AI Security Center. This isn't just a glimpse into current events—it's your roadmap to staying ahead in the ever-evolving world of cybersecurity.
Explore critical security practices, like the nuances of service level agreements and the essentials of privileged access management, tailored to elevate your cybersecurity strategies. Learn how to balance regulatory compliance with productivity by refining need-to-know policies and harness the power of data classification. Additionally, consider the wide array of consulting services from ReduceCyberRisk.com, including penetration testing and virtual CISO services, for those seeking to deepen their expertise or find mentorship. As we close, I extend warm holiday wishes and share enthusiasm for the opportunities ahead in 2025. Don’t miss out on these valuable insights—your future in cybersecurity starts here.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to a more secure digital environment as we dissect the potential impact of a TP-Link router ban in the U.S., spurred by security vulnerabilities and foreign influence concerns. How will this affect consumers, businesses, and ISPs reliant on these budget-friendly devices? Tune in to discover the broader implications of a shift towards U.S.-manufactured electronics and what it means for cybersecurity practices nationwide.
Explore the intricate balance of power and security through the principle of least privilege (POLP) and the need-to-know principle. We decode the strategies to implement POLP successfully, reducing attack surfaces while maintaining efficiency, and align these techniques with essential regulatory standards such as GDPR and HIPAA. Discover how the military's compartmentalization tactics can be mirrored in the corporate world to safeguard sensitive information.
Finally, we unravel the complexities of insider threats and privileged account management. From job rotations to mandatory vacations, learn how these innovative strategies can help mitigate fraudulent activities and insider risks. We emphasize the crucial role of Privileged Account Management systems in enhancing security, despite their setup complexities and costs, providing invaluable tools for IT professionals seeking to bolster their cybersecurity measures. Don't miss this comprehensive guide designed to fortify your cybersecurity defenses.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Can AI-driven technologies reshape the way we secure our digital world? Join me, Sean Gerber, as we navigate the fascinating landscape of cybersecurity challenges anticipated by 2025. Our latest podcast episode promises to shed light on the emerging threats posed by AI, particularly within the finance and e-commerce sectors. We explore the necessity of incorporating AI into security frameworks and examine the shifting dynamics of cybersecurity insurance powered by AI-driven risk assessments. The conversation takes a thought-provoking turn with the exploration of quantum-resilient encryption's impact on global privacy laws and an increased focus on DevOps security, zero trust models, and the ever-looming threat of nation-state cyber warfare.
What strategies are essential when dealing with stubborn vendors and critical vulnerabilities? We'll tackle this and more in a segment dedicated to vulnerability management and its ethical considerations. Learn the significance of documenting exceptions, deploying compensating controls, and the vital role of private collaboration and escalation in managing vendor reluctance. We also provide insights into handling false positives from vulnerability scans and the art of communicating risks to stakeholders under budget constraints. This discussion places a spotlight on strategic communication and ethical decision-making as cornerstones of effective cybersecurity risk management.
Uncover the secrets to mastering vulnerability management with a strategic flair. We'll guide you through scenarios where high-severity issues persist despite a reduction in overall vulnerabilities, emphasizing coordinated efforts within multi-cloud settings. You'll gain insights into best practices for risk mitigation when immediate patching isn't feasible and the ethical and legal intricacies of vulnerability disclosure. In addition, there's a focus on presenting a risk management approach that balances cost with potential impact to senior leaders. As a bonus, we offer resources for those gearing up for the CISSP exam and seeking cybersecurity consulting, equipping you with the knowledge to fortify your defense against cyber threats.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to safeguarding your organization against cyber threats as we explore critical components of cybersecurity. Join me, Sean Gerber, on this enlightening episode of the CISSP Cyber Training Podcast, where we dissect domain 6.4 of the CISSP exam. Discover the latest insights into cyber threats that target U.S. critical infrastructure, with a particular focus on an Iranian-linked group's custom cyber weapon. Learn how understanding your organization's technology, both hardware and software, can be pivotal in mitigating potential threats, especially in industries like oil and gas.
Navigate the labyrinth of vulnerability scan reporting and analysis as we dive into the challenging yet rewarding art of communicating security assessment findings. Whether done internally or through third-party services, the objective is to translate technical data into actionable insights for technical teams. We tackle the complexities of overwhelming scan results and highlight the value of automated reporting, ensuring an efficient and effective approach to vulnerability management. Learn how to prioritize risks, provide clear remediation recommendations, and utilize trend analysis to track progress and tackle recurring vulnerabilities.
Finally, explore the strategies needed for executing effective internal and external security scans. Discover the importance of thorough preparation and strategic planning, managing insider threats, and safeguarding public-facing assets. We delve into the complexities of third-party scans, emphasizing the need to understand and manage network connections to prevent unauthorized access. Throughout this episode, we stress the critical role of alignment and collaboration in cybersecurity efforts, providing you with the tools and guidance needed to enhance your security posture in today's complex landscape.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Could the lack of hardware and firmware knowledge be the Achilles' heel of today's cybersecurity efforts? Join me, Sean Gerber, on the CISSP Cyber Training Podcast as we unpack the critical challenges faced by IT and security leaders, particularly in hardware-intensive sectors like manufacturing. We expose the concerning gaps in understanding that are leaving organizations vulnerable, and propose actionable solutions like fostering stronger collaboration between IT teams, security personnel, and suppliers. Tackling the prevalent issue of BIOS password sharing, we recommend secure password management tools, like CyberArk, and advocate for a shift from the culture of replacing devices to one of repair and repurposing, all while ensuring data is securely erased to prevent breaches.
Shifting focus to authentication and password security, this episode dives into the essentials of Role-Based Access Control (RBAC), two-factor authentication, and the power of identity federation with protocols like SAML or OAuth. We dissect the benefits of Single Sign-On (SSO) for seamless multi-application access, while highlighting the necessity of identity proofing during onboarding. Finally, we take a hard look at common password pitfalls, stressing the importance of robust security practices. Our mission? To empower listeners with the knowledge and resources they need to bolster their cybersecurity measures—visit CISSP Cyber Training and ReduceCyberRisk.com for a deeper dive into fortifying your defenses.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of safeguarding your digital empire with an urgent cybersecurity update from Sean Gerber on the CISSP Cyber Training Podcast. Imagine a vulnerability so severe it's rated at a critical level of 10—this is the reality for Atlassian Confluence users, and immediate action is non-negotiable. Arm yourself with strategies from CISSP domain 5.5.1 that shape the provisioning, onboarding, and maintenance of systems. Learn how to craft robust account management plans that are the keystone in your organization's defense against breaches.
Transform your team into a frontline defense force with our insights on creating impactful employee security awareness training. We tackle the power of a simple one-page document to revolutionize your approach, especially if you're the lone security warrior in your firm. Discover how understanding industry standards like GDPR and CMMC can empower your workforce to act as vigilant sensors against potential threats. We also touch on how to navigate the complexities of multinational teams, ensuring inclusive and effective cybersecurity dialogues.
Close the doors on security threats by mastering the deprovisioning and offboarding processes. Elevate your knowledge with the significance of automating the removal of stale accounts, reducing the risk of hackers exploiting overlooked credentials. Dive deep into Role-Based Access Control (RBAC) and password management strategies that align permissions with job roles, simplifying security while mitigating risks. With compelling insights into password policies and the need for senior leadership buy-in, you'll be equipped to advocate for enhanced security measures that protect your organization.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Discover how a ransomware attack nearly brought vodka titan Stoli to its knees, pushing the company to the brink of bankruptcy with a staggering $78 million debt. This episode promises a compelling exploration of the catastrophic impact on their ERP systems and the urgent need for a solid business resiliency plan. Join me, Sean Gerber, as we unravel the complexities of managing IT risks, the geopolitical challenges faced by companies like Stoli, and the critical importance of conveying these risks to senior leadership—especially when regulatory deadlines loom.
On a technical front, we'll demystify the nuances between IPsec transport and tunnel modes, breaking down misconceptions and shining a light on potential vulnerabilities such as outdated TLS versions. Learn why HSTS and DNS over HTTPS might not be the silver bullets they appear to be, and how HTTPS, while robust, isn't immune to phishing threats. This episode is an essential guide for cybersecurity professionals keen on fortifying their defenses against the relentless and evolving threats in today's digital landscape. Tune in for a rich blend of analysis and insights that underscore the vital role of awareness and technical knowledge in safeguarding our digital world.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to mastering core networking concepts crucial for your CISSP exam and cybersecurity career with Sean Gerber on the CISSP Cyber Training Podcast. Ever wondered how the intricate dance between IPv4 and IPv6 affects your daily online interactions? Get ready to explore these foundational Internet protocols, their histories, and the innovative transition mechanisms bridging them. We kick off with a discussion on the eye-opening Mega Breach Database, spotlighting the staggering exposure of around 26 billion records. This breach serves as a cautionary tale of our digital age, underscoring the necessity for robust password management and multi-factor authentication.
Journey through the complex landscape of IP addressing as we untangle the web of IPv4 and IPv6 structures. We'll break down IPv4's network and host partitions, the role of TCP and UDP protocols, and the creative, albeit temporary, fix provided by NAT routing. With a shift towards IPv6, discover the implications of its advanced hexadecimal notation and the flexibility offered by CIDR in IP address allocation. If you're grappling with the divide between the old and new, Sean shares insights on key transition strategies, ensuring you comfortably adapt to the evolving technological environment.
Lastly, we tackle essential networking protocols like ICMP, IGMP, and ARP, which are indispensable for anyone eyeing the CISSP certification. Learn how to apply these concepts to real-world scenarios, such as identifying potential man-in-the-middle attacks. Whether you're a cybersecurity novice or a seasoned expert, our discussion will equip you with comprehensive knowledge and sharpen your skills, helping you excel in the CISSP exam and beyond. Join us for this enlightening episode, and walk away with the confidence to navigate the complex world of networking.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
What if quantum computing could unravel today's most secure encryption methods? Discover the potential future of cryptography on the CISSP Cyber Training Podcast, as we explore the profound impact of advanced quantum capabilities on public key systems like RSA and elliptic curve algorithms. This episode breaks down the "harvest now, decrypt later" strategy, revealing how adversaries might exploit encrypted data in the future. Cybersecurity professionals will gain essential insights into transforming their organization's cryptography practices to anticipate and counteract these emerging threats effectively.
Our deep dive into cryptographic concepts and best practices offers a comprehensive Q&A session that highlights AES as the gold standard of symmetric encryption and examines the vulnerabilities of legacy algorithms like MD5. Get to grips with the advantages of ECC for devices with limited resources and unravel the complexities of asymmetric cryptography, from key exchanges to the power of digital signatures. We also unveil a tailored mentoring and coaching program, designed to guide you through passing the CISSP exam and mapping a successful career path in cybersecurity. Tune in for expert insights and strategies that equip you to excel in the ever-evolving world of cybersecurity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of robust cybersecurity defenses as we navigate through the intricate landscape of the CISSP exam content, zeroing in on vulnerability mitigation within security architectures. Explore an eye-opening case study of the Russian GRU's audacious use of Wi-Fi networks for credential stuffing attacks, revealing the critical need for multi-factor authentication. As we dissect the complexities of these cyber-attacks, the episode promises to arm you with the knowledge to stay one step ahead of evolving threats.
Our journey takes a broader look at the myriad of cybersecurity threats lurking in the digital realm. Discover practical strategies to shield your organization from phishing, malware, and man-in-the-middle attacks. Learn about the vital role of password managers, regular system updates, and the implementation of sandboxing to protect against outdated applets. The episode provides actionable insights to fortify your security posture, ensuring sensitive data remains uncompromised.
Rounding out the discussion, we delve into the critical aspects of database security and the unique challenges faced by industrial control systems. Gain an understanding of database architecture, key security practices, and the significance of multi-level classification in military contexts. From access control to encryption and SQL injection prevention, we cover it all. Finally, we shine a spotlight on the mission of CISSP Cyber Training, highlighting how proceeds from the program support adoptive families through Shepherd's Hope, reinforcing the episode's commitment to making a positive impact beyond cybersecurity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Ever wondered about the hidden dangers lurking in outdated systems? Join me, Sean Gerber, as we tackle the pressing issues surrounding end-of-life assets on the CISSP Cyber Training Podcast. This episode unpacks the critical risks of holding onto systems that no longer receive manufacturer support and the security implications that follow. We'll explore the fine balance between managing costs and ensuring compliance when extending the life of these aging systems, all through a risk-based approach. Discover why secure data disposal should be at the forefront of your strategy, and learn about the industry regulations that you must navigate to maintain a robust security posture.
Eager to expand your cybersecurity prowess? I invite you to explore cisspcybertraining.com, your go-to resource for preparing for the CISSP certification and enhancing your cybersecurity knowledge. This episode wraps up with a reminder of the importance of continuous learning and professional growth in this ever-evolving field. Tune in for insights that will not only bolster your understanding but also empower you to excel in your cybersecurity career.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets to mastering cybersecurity management with insights from Sean Gerber. How can businesses effectively handle the risks of outdated technology and safeguard their assets? Join us as we explore Domain 2.5 of the CISSP exam and unravel the complexities behind end-of-life and end-of-support for assets, a critical area for anyone aiming for exam success. Drawing on expert guidance from leading organizations like NCSC, NIST, and CISA, this episode highlights the vulnerabilities of small and medium-sized businesses and offers strategies to fortify their defenses.
Navigate the treacherous waters of managing outdated software and hardware. Discover how these old systems can disrupt operations and what security professionals must communicate to leadership to prevent financial losses. We share actionable strategies for inventory management and risk assessment, helping organizations prioritize and mitigate challenges based on risk tolerance. Whether you're facing the end of support for a high-stakes asset or deciding to repurpose older equipment, this episode equips you with the knowledge to devise an effective asset retirement strategy.
Before you tackle the CISSP exam, arm yourself with the tools and resources to ensure a smooth journey. We discuss the importance of compliance, business continuity, and disaster recovery plans, alongside exploring third-party support and open-source alternatives. Don't miss out on the chance to enhance your preparation with the CISSP Cyber Training program, where my Blueprint sets a clear path to help you succeed on your first attempt. Get ready to embrace the wealth of information and prepare for the next chapter of your cybersecurity career.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Check us out at: https://www.cisspcybertraining.com/
Get access to 360 FREE CISSP Questions: https://www.cisspcybertraining.com/offers/dzHKVcDB/checkout
Get access to my FREE CISSP Self-Study Essentials Videos: https://www.cisspcybertraining.com/offers/KzBKKouv
Unlock the secrets of cybersecurity mastery as Sean Gerber unpacks the importance of CISSP certification amidst a looming gap of over 5 million unfilled cybersecurity positions by 2024. This episode promises to equip you with insights from the latest ISC² global workforce study, emphasizing the blend of technical prowess and essential soft skills employers crave, such as communication and critical thinking. Dive into expert advice on acing CISSP exam questions, especially those tricky legal scenarios involving data transfer you might face.
Explore comprehensive strategies for safeguarding data and ensuring compliance in today’s complex digital landscape. Sean discusses the implementation of data loss prevention solutions, the nuances of trans-border data flows, and the challenge of meeting GDPR requirements amidst data localization demands. Discover how endpoint encryption, data classification, and mobile app push notifications play pivotal roles in protecting intellectual property while maintaining user convenience. Learn why collaboration with vendors is critical when investigating potential data breaches.
Navigate the intricate world of global security compliance as we delve into the decision-making processes essential for managing international cybersecurity obligations. Sean highlights the necessity of consulting legal counsel and employing a risk-based approach to maintain a uniform security posture across diverse regions. Uncover strategies for addressing critical vulnerabilities and aligning security frameworks with new international data privacy treaties. This episode lays out a holistic security design, integrating every aspect of the CISSP domains to prepare you for a successful career in cybersecurity. Join us for this invaluable journey into the future of cybersecurity.
Gain exclusive access to 360 FREE CISSP Practice Questions delivered directly to your inbox! Sign up at FreeCISSPQuestions.com and receive 30 expertly crafted practice questions every 15 days for the next 6 months—completely free! Don’t miss this valuable opportunity to strengthen your CISSP exam preparation and boost your chances of certification success. Join now and start your journey toward CISSP mastery today!
Send us a text
Is your organization equipped to combat the latest cybersecurity threats as we enter 2024? Join me, Sean Gerber, as we explore the critical cybersecurity issues affecting both local and international landscapes. We'll unpack the recent ransomware attacks that have disrupted essential services, ranging from the Kansas court system in the U.S. to sensitive children's court hearings in Australia. These incidents highlight the urgent need for enhanced security measures, especially as cybercriminals reportedly target vital infrastructure like U.S. wastewater treatment facilities.
The legal ramifications of cyber crimes are as complex as they are severe. In our discussion, we explore the intricacies of data breaches and transborder data flows, examining how different countries handle data flow regulations and the consequences for offenders—from hefty financial penalties to potential life imprisonment. Real-world examples, such as swatting incidents, illustrate the dual nature of legal liabilities that cybercriminals face. Our conversation aims to shed light on the multifaceted legal landscape, preparing cybersecurity professionals for the challenges ahead.
Understanding global breach notification regulations is crucial for any organization. We'll discuss the challenges of navigating different timelines, such as the EU's 72-hour requirement under GDPR, and the importance of having pre-defined protocols for incident management. We also emphasize the significance of international data privacy regulations, highlighting the need for data classification, encryption, and anonymization to protect sensitive information. Whether you're a seasoned security professional or just starting out, this episode offers invaluable insights to enhance your cybersecurity skills and readiness.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Discover the hidden threats lurking in your kitchen appliances and learn why your next air fryer might be spying on you. On this episode of the CISSP Cyber Training Podcast, we unravel the alarming findings from Infosecurity Magazine about Chinese IoT devices and their potential to invade your privacy. We emphasize the critical importance of educating ourselves and others about the risks of IoT devices and the vast amounts of data they can collect. Additionally, we highlight new ICO regulations that aim to bolster data protection, especially for international companies, ensuring they uphold stringent privacy standards.
But that's not all! We shift gears to explore Agile development practices, diving into the adaptability and feedback loops of Scrum and the high-security approach of the spiral model. Discover how the Capability Maturity Model's pinnacle stage fosters continuous improvement and learn the essentials of integrating security into the DevSecOps CI/CD pipeline without sacrificing speed. We also delve into the nuances of pair programming for enhanced code quality and clarify the distinct approaches of Scrum's time-boxed sprints versus Kanban's work-in-progress limits. Tune in for a comprehensive look at modern software development practices and the indispensable role of security in our digital world.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets of integrating security within every phase of software development as we tackle Domain 8 of the CISSP exam. Our exploration begins with a deep dive into the software development lifecycle (SDLC) and its various methodologies like Agile, Waterfall, DevOps, and DevSecOps. Through a gripping tale of a Disney World IT insider's digital manipulation, we underscore the critical importance of safeguarding systems, especially when skilled employees exit the stage. This episode promises to arm you with the knowledge to fortify your organization's cybersecurity posture effectively.
We then navigate the contrasting landscapes of software development models, weighing the structured order of the Waterfall model against the adaptive flexibility of Agile and the risk-focused Spiral model. Each approach comes with its own set of challenges and benefits, particularly concerning security integration and usability. Through the lens of iterative feedback and prototype development, we highlight how these methodologies can help refine requirements and minimize ambiguities, ensuring that security and functionality walk hand in hand.
Finally, explore how the IDEAL model can transform your organization's security practices. Designed to improve cybersecurity and risk management, this structured improvement approach offers clear phases: Initiating, Diagnosing, Establishing, Acting, and Learning. We also discuss the impactful mission behind CISSP training, where proceeds support a nonprofit for adoptive children. This initiative not only enhances your cybersecurity skills but also contributes to a cause greater than yourself. Join us as we unpack these strategies, providing insights that could significantly shape your cybersecurity career.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the keys to safeguarding the future of our global supply chains as we tackle the formidable intersection of IT and OT environments in cybersecurity. Imagine the chaos if operational technology systems on ships and cranes were compromised. Discover how the notorious Maersk hack serves as a cautionary tale illustrating the potential for worldwide disruption. We introduce PrivX OT Edition, a game-changing platform ensuring secure remote access to vital systems on container ships, emphasizing the delicate balance between operational integrity and cybersecurity. Your systems' resilience against cyber-threats starts with understanding the vital distinctions between IT and OT networks.
In our exploration of incident response, we highlight the paramount importance of learning from each security breach. Unusual outbound network traffic is a red flag not to be ignored, and the role of a well-prepared Computer Security Incident Response Team (CSIRT) cannot be overstated. We delve into proactive measures that keep your systems one step ahead, from regular software updates to rigorous incident response planning. Emphasizing documentation and the chain of custody, this episode equips you with the foresight and strategies needed to maintain a secure and reliable cybersecurity posture. Join us in this essential discussion as we pave the way to a more secure future.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Ready to elevate your cybersecurity acumen and conquer the CISSP exam? Tune in to our latest episode, where we unravel the intricacies of a significant ransomware attack that exploited a supply chain vulnerability, impacting 60 US credit unions via the Citrix bleed vulnerability. This real-world scenario stresses the necessity of securing third-party relationships and maintaining a robust security posture. We shift gears to dissect Domain 7.5 of the CISSP, offering insights into effective resource management and safeguarding a variety of media within an organization. From defining stringent policies for handling CDs, DVDs, USBs, and mobile phones to deploying physical security measures, we cover it all to ensure data integrity.
Our journey continues into the world of tape backup security and management, often considered a last-resort data storage solution. We spotlight the importance of implementing check-in/check-out policies and using climate-controlled environments, such as salt mines, to preserve these backups. Secure transport is another key focus, with encryption and regular inspections recommended to safeguard your data. As we navigate the lifecycle of different media types, from acquisition to disposal, you'll learn about tailored security measures for each stage. We wrap up this segment by stressing compliant disposal methods, where professional shredding services take center stage to guarantee data destruction.
Finally, we pivot to exploring the critical aspects of data disposal and hardware reliability. Discover why shredding is preferred over degaussing, particularly for SSDs, and the importance of comprehensive staff training to avert data leaks during site closures. We delve into the metrics of Mean Time to Failure (MTTF) and Mean Time Between Failures (MTBF), essential for planning hardware reliability and lifecycle management. These metrics are not just numbers; they play a pivotal role in risk management and business continuity planning. As we prepare you for success, stay tuned for our upcoming episode, where CISSP exam questions take the spotlight, and hear a success story that illustrates the power of commitment and the right resources.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Can cheaply made smart devices compromise your security? Uncover the hidden risks of AI and hardware hacking as we explore the vulnerabilities in these devices that make them prime targets for cybercriminals. Learn how secure coding practices and proper device isolation can serve as critical defenses, and consider the implications of AI misconfigurations that could lead to remote code execution. Through engaging discussions, we shed light on the growing threat landscape and the necessity of protecting both personal and business environments from these emerging challenges.
We dig into the world of audits and compliance, dissecting internal, external, and third-party audits to reveal their unique roles and shortcomings. Discover the dangers of leaning solely on internal audits and why third-party assessments are vital in evaluating vendor and partner security controls. This understanding is key for organizations to effectively manage risks and enhance supply chain security. Our insights will arm you with knowledge on how to navigate these audits and make informed decisions that bolster your cybersecurity posture.
Lastly, we navigate through the essential elements of cybersecurity audits, from security policies to incident response plans. Learn about the auditor's role in ensuring compliance and the importance of follow-up audits to verify the implementation of recommendations. We emphasize the critical nature of documented incident response procedures in maintaining business resilience, underlining regulations like HIPAA that protect sensitive health information. Tap into our rich resources and elevate your understanding of cybersecurity to safeguard your operations against an evolving threat landscape.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets to enhancing your organization's security posture by mastering the art of security audits. Tune in to discover how security audits play a pivotal role in both the CISSP exam and real-world scenarios. Through personal anecdotes and expert insights, we explore how conducting effective audits with departments like finance can transform your approach to cybersecurity. We also introduce Vuln Hunter, an innovative open-source tool showcased at the No Hat Security Conference, designed to detect Python zero-day vulnerabilities. Learn how this tool could be a game-changer for your development team by catching issues like cross-site scripting before they make it into your live code.
Navigate the complexities of security assessments versus audits as we break down these critical processes. With a focus on setting clear parameters to ensure efficiency, we explore the importance of understanding potential risks and planning effective responses. Through discussions on the roles of internal, external, and third-party audits, we highlight the necessity of senior leadership buy-in for successful internal audits and the strategic value of aligning your security efforts with regulatory compliance frameworks such as PCI DSS, NIST, or ISO 27001.
Finally, join us as we spotlight the charitable mission of the CISSP Cyber Training program. Every dollar from this initiative goes toward supporting a nonprofit organization dedicated to helping adoptive children and their families. Driven by a personal passion for making a difference, we're dedicated to using this platform to foster both cybersecurity knowledge and positive social impact. Help us spread the word by rating us on platforms like iTunes and YouTube, and be part of a cause that matters.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets to mastering access control models essential for conquering the CISSP exam and advancing your cybersecurity expertise. Imagine having a comprehensive understanding of how discretionary, mandatory, role-based, risk-based, rule-based, attribute-based, and hybrid models function in various scenarios. This episode features Sean Gerber as he navigates the complex world of access control frameworks, offering insightful questions and real-world applications. Whether you're dealing with military security labels or defining access based on job responsibilities, gain the clarity needed to apply these models effectively in your cybersecurity practice.
Get ready to transform your CISSP exam preparation with unparalleled support from CISSP Cyber Training. Sean shares an exciting opportunity for exam success, emphasizing the power of dedicated study using a suite of comprehensive videos and guides. By committing to the program's blueprint, you can approach your certification journey with confidence and assurance. Join us and embrace this empowering learning experience that promises not just knowledge, but the keys to certification success.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets of cybersecurity in our latest episode where we promise to transform your understanding of access control mechanisms. We kick things off by dissecting the discretionary access controls (DAC) and the power dynamics behind resource ownership. Discover why assigning ownership is crucial to sidestep security pitfalls and how to tackle the double-edged sword of permission propagation and creep. We also unveil strategies for seamless security management, including the potential of document-level protections and data loss prevention tools.
Transitioning to role-based and rule-based access control, we unravel their significance for those eyeing the CISSP certification. Picture a world where credential creep and role explosion are mitigated through strategic central management and diligent reviews. Learn how Segregation of Duties (SOD) safeguards against conflicts of interest, and grasp the fine line between roles and rules, arming you with the insight needed to choose the right strategy for your organization. Whether you’re in finance or tech, these access controls are essential for preventing systemic risks.
Finally, explore the future of security with adaptive authentication systems and non-discretionary access controls. Real-time risk assessment becomes a reality as we delve into adaptive authentication, incorporating contextual cues and threat intelligence. Meanwhile, non-discretionary access controls centralize authority, yet beware of potential bottlenecks and user frustration. Balancing these sophisticated systems is key to maintaining integrity and consistency on a large scale. Tune in as we navigate these intricate mechanisms to keep your cybersecurity robust and dynamic.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets of the OSI and TCP/IP models with Sean Gerber as your guide on the CISSP Cyber Training Podcast. Ever wondered how the presentation layer manages to format and translate data seamlessly for the application layer? Or how the network layer deftly routes packets across networks? Prepare to gain a comprehensive understanding of these essential concepts, crucial for acing the CISSP exam. Plus, dive into the intriguing details of the TCP/IP model's transport layer, from error checking to flow control, all while uncovering the mystery of the SYN flag in the TCP three-way handshake. Equip yourself with vital knowledge that will bolster your cybersecurity expertise.
Our journey doesn't stop there. We delve deeper into the intricacies of the TCP three-way handshake, spotlighting the often-overlooked role of the ACK (Alpha Charlie Kilo) in maintaining reliable communication. Sean shares insightful analysis on how acknowledging data receipt and indicating the next expected sequence number ensures network stability. Looking to expand your cybersecurity knowledge even further? Sean offers exclusive access to additional content and resources through his platforms, inviting you to join his email list for valuable materials. Empower your CISSP exam preparation and cybersecurity understanding with these crucial insights.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets of cybersecurity mastery with Sean Gerber as we embark on a journey through Domain 4 of the CISSP exam. Ever wondered how AI could transform the chaotic world of Security Operations Centers (SOCs)? Discover the potential of artificial intelligence to streamline alert management and enhance detection efficiency, a much-needed solution for the 60% of SOC professionals swamped by alert overload. Stay ahead of the curve by understanding the rapid rise of AI startups and the strategic importance of future investments in SOC capabilities.
Venture into the realm of Voice over IP (VoIP) and unravel the intricacies of RTP and SRTP protocols that power real-time communication. Learn how these protocols ensure optimal data transmission while safeguarding against common threats like phishing and session hijacking. Dive into the revolutionary shift from traditional PSTN to VoIP, and explore the role of converged protocols like MPLS that simplify network integration. With a focus on security enhancements, this episode offers vital insights into maintaining robust communication systems in the face of evolving threats.
Explore advanced networking concepts like Software-Defined Networking (SDN) and network virtualization, which are reshaping data transfer efficiency. Delve into wireless encryption protocols, including the transformative WPA3, and emerging technologies such as Li-Fi and Zigbee. Addressing cellular network encryption challenges with LTE communications, we provide a comprehensive guide to navigating the ever-evolving landscape of wireless standards. Wrap up your cybersecurity education with a spotlight on CISSP Cyber Training resources, designed to support your certification journey and contribute to a meaningful cause.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Crack the code of security architecture and engineering with this episode of the CISSP Cyber Training Podcast! Ever wondered how different security models apply to real-world scenarios? We'll give you the insights and knowledge you need to discuss these models confidently with senior leaders and implement robust security controls. We promise you'll walk away with a mastery of foundational models like Bell-LaPadula and Biba, essential for any cybersecurity professional.
Join us as we dissect the origins and key principles of these models, highlighting "no read up" and "no write down" from Bell-LaPadula and the unwavering focus on data integrity in Biba. We also spotlight the Clark-Wilson model's approach to preventing fraud through transaction rules and separation of duties. These discussions are backed by real-world examples from military and governmental contexts, providing a tangible understanding for those preparing for the CISSP exam.
The conversation doesn't stop there. We delve into distributed systems, unpacking the trade-offs outlined by the CAP theorem, and illustrate its application using Office 365 and IoT networks. Finally, we simplify the Take-Grant model for access control scenarios, ensuring you grasp the critical concepts like the simple security property and the star property. This episode is your ultimate guide to mastering CISSP Domain 3 and staying ahead in the ever-evolving field of cybersecurity.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
What if your organization's security posture could withstand any cyber threat? This episode of the CISSP Cyber Training Podcast promises to equip you with actionable insights from CISSP Domain 3, emphasizing the critical principle of failing securely. We tackle the intricacies of separation of duties, zero trust, and the benefits of maintaining simplicity in your systems. Plus, I share my firsthand experience with virtual CISO roles, providing a roadmap for hiring a security professional, from conducting gap assessments to understanding risk profiles and developing robust mitigation strategies.
Next, we dive deep into data security and management essentials. Discover why data classification and separation of duties are paramount in preventing fraud and protecting sensitive information. We'll cover the importance of data loss prevention measures, network segmentation, and change management to safeguard your systems from unauthorized modifications. Learn the significance of monitoring, logging, and process isolation techniques like virtualization and sandboxing to detect anomalies and limit the damage from breaches. And don't miss our discussion on capability-based security, application whitelisting, and the strategic application of these controls based on thorough gap assessments.
Lastly, we explore the facets of system resilience and security measures that ensure reliability. Understand the concept of graceful degradation and the pivotal role of error handling and logging in troubleshooting. We highlight the importance of redundancy, fault tolerance techniques, and the principle of security by design. Proper testing and auditing are emphasized to ensure systems fail securely, and we provide strategies for addressing both soft and hard failures. Additionally, the roles of job rotation, dual control, and mandatory vacations in error detection and risk management are examined, along with a comparison of on-premise versus cloud networks to help you maintain critical servers and applications. This episode is a treasure trove of practical knowledge to elevate your cybersecurity readiness.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Ever wondered about the real difference between a data leak and a data breach? Join me, Sean Gerber, on the latest episode of the CISSP Cyber Training Podcast as we unpack the nuances between these two critical cybersecurity concepts. Learn how data leaks often result from human mistakes like weak passwords, while data breaches involve deliberate cyber attacks. We'll walk through different types of sensitive data—including PII, financial information, PHI, and intellectual property—and emphasize the need for precise language to help cybersecurity leaders communicate more effectively and avoid unnecessary panic. Plus, get a sneak peek into a CISSP exam question focusing on the stringent security controls required for data in use.
Choosing the right Data Loss Prevention (DLP) solution doesn't have to be a headache. In this episode, we tackle cost-effectiveness and real-world challenges that come with selecting DLP solutions. Hear about the compatibility hurdles of Digital Rights Management (DRM) solutions, including the struggles between Adobe and Microsoft's products. Discover how DLP and DRM technologies sometimes clash, and learn what to look for to ensure seamless integration. Don't miss these invaluable insights designed to sharpen your cybersecurity acumen and prep you for the CISSP exam.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Ever wondered how a TI-84 calculator can be transformed into a powerful tool for ChatGPT? Join me, Sean Gerber, on this thrilling episode of the CISSP Cyber Training Podcast as we uncover this fascinating tale and explore the evolving landscape of data security. We'll dissect the crucial elements of Domain 2.6 of the CISSP exam, from protecting data-at-rest to data-in-motion, and delve into the significance of Digital Rights Management (DRM) and Data Loss Prevention (DLP). This episode promises to enlighten you on the challenges and solutions of safeguarding data in today's tech-driven world.
Next, we'll explore the meticulous process of establishing a robust labeling schema for data within an organization. Learn how to effectively implement physical and digital labels—such as unclassified, secret, top secret, and confidential—using color coding for easy identification. We'll stress the importance of consistent terminology, well-documented procedures, and controlled access to data classification changes. Discover how to tailor security controls to fit various organizational needs and the pivotal role of IT security leaders in guiding departments to enhance their security measures.
Finally, we address the critical task of aligning IT security controls with an organization's risk tolerance and operational needs. Understand how focusing on critical assets can optimize data protection without spreading resources too thin. We'll highlight the importance of adhering to security frameworks like NIST, GDPR, or PCI DSS, and the role DRM and DLP play in preventing unauthorized data exfiltration. Plus, we'll introduce Cloud Access Security Brokers (CASBs) and discuss their crucial function in enforcing security policies between organizational networks and cloud service providers. This episode is packed with invaluable insights to prepare you for the CISSP exam and elevate your cybersecurity knowledge.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
How can we effectively bridge the cybersecurity skills gap and protect sensitive data in the cloud? In this action-packed episode of the CISSP Cyber Training Podcast, we kick things off by analyzing insights from a recent UK international cyber skills conference. We discuss the UK's innovative initiatives to enhance cybersecurity education and talent, including support schemes and competitions, and emphasize the importance of gaining practical experience, even through pro bono work. We also delve into a critical CISSP practice question, exploring the best methods to prevent unauthorized access to sensitive data in cloud environments, spotlighting the significance of strong encryption.
Shifting gears, we tackle best practices in identity management, dissecting the risks associated with Single Sign-On (SSO) and the crucial role of least privilege access controls. We unravel the hidden costs of cloud-based identity and access management solutions and expose how phishing emails are a prevalent social engineering threat. Furthermore, we dive into managing vendor access and the complexities of adopting a zero-trust security model, offering practical tips for gradual integration. We wrap up by highlighting the importance of non-disclosure agreements (NDAs) in safeguarding intellectual property and confidential information, providing essential cybersecurity insights and actionable advice for our listeners. Tune in and elevate your cybersecurity expertise!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Are you ready to uncover the secrets behind successful candidate screening and robust employment agreements in cybersecurity? Join us on this episode of the CISSP Cyber Training Podcast, where we promise to equip you with essential techniques to vet the right candidates for sensitive security roles. From structured interviews to behavioral questions and technical assessments, we cover the full spectrum of best practices. Plus, we'll discuss the critical importance of maintaining up-to-date systems and managing end-of-life devices, spotlighting recent vulnerabilities in the Ivanti Cloud Services Appliance.
Next, we tackle the nuanced world of employment background checks and onboarding security. Discover why separation of duties and the principle of least privilege are non-negotiable in safeguarding sensitive information. We explore the complexities of background checks, including criminal history, credit checks, and education verification, to help you navigate the legal and HR hurdles effectively. Learn how to secure candid feedback from professional references to mitigate insider risks and bolster your organization's defenses.
Finally, we delve into the intricacies of employee transfers and contractor agreements, addressing the significant risks of credential creep and unauthorized data retention. Our discussion emphasizes the importance of a well-structured termination process and automated access removal to protect your data. We wrap up with a simplified approach to preparing for the CISSP certification, offering a step-by-step plan to help candidates succeed on their first attempt and enhance their skills in their security roles. Don’t miss these invaluable insights and strategies designed to elevate your cybersecurity practices!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Can API gateways really be the ultimate shield against cyber threats? Prepare to uncover the secrets of API security as we dissect CISSP Domain 8.5 in this episode of the CISSP Cyber Training Podcast. We'll walk you through practice questions that decode the most common API vulnerabilities and why denial of service isn't always the primary threat. Discover how an API gateway centralizes security and learn about essential authentication mechanisms like OAuth for secure token-based exchanges. We’ll also discuss best practices for securely managing API keys and the critical role of input validation in fending off SQL injection attacks.
Ever wondered how to forge strong alliances to combat cyber threats? Explore the extensive capabilities of Reduce Cyber Risk in our segment on Cyber Risk Reduction Partnerships. With our deep-rooted experience in IT, we detail how our tailored cybersecurity solutions, from penetration testing to insider risk training, can fortify your defenses. Learn how our strategic partnerships with IT professionals enhance our service offerings, providing customized security assistance and training. Tune in and elevate your cybersecurity game with actionable insights and expert advice.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Want to stay ahead in the rapidly evolving world of IT? Join Sean Gerber on the CISSP Cyber Training Podcast as he discusses the essential skills you need to thrive in this dynamic field. You'll get a personal peek into Sean's consulting career and his family business ventures before diving into the nuts and bolts of Domain 8.5 with a focus on Application Programming Interfaces (APIs). Learn how APIs serve as the backbone of modern software applications, facilitating seamless data exchange and communication, and discover why mastering this technology can be a game-changer for your career.
Explore the intricate world of APIs with real-world examples, such as how ride-sharing apps integrate with Google Maps for optimal functionality. Sean breaks down the three types of APIs—public, partner, and private—explaining their unique benefits and specific uses. With practical insights, you'll understand how APIs can enhance productivity and efficiency within organizations. But it’s not all about benefits; this episode also tackles the critical issue of API security. Sean delves into common security vulnerabilities like API abuse, key theft, and injection attacks, providing best practices to safeguard your systems against these threats.
Finally, the episode outlines effective strategies for API key management and security. Sean emphasizes the importance of treating API keys with the same level of caution as passwords, offering tips on key rotation, limiting permissions, and employing API gateways for added security. To wrap things up, discover how you can benefit from and contribute to the CISSP Cyber Training Donation Program, which supports children and financially challenged parents through flexible training packages. Tune in to not only advance your cybersecurity knowledge but also make a positive impact on society.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets to safeguarding your organization's most sensitive data and enhance your cybersecurity acumen. Join us on the CISSP Cyber Training Podcast as I, Sean Gerber, break down the critical importance of managing secrets within popular collaboration tools like Slack, Jira, and Confluence. Discover practical methods such as real-time monitoring and swift remediation to secure API keys and encryption tokens. Learn how fostering a culture of security awareness through educational initiatives can significantly mitigate risks and enhance overall security posture.
Next, we turn our attention to data sanitization and media destruction—essential processes for maintaining confidentiality and regulatory compliance. I’ll guide you through various methods of data sanitization and media destruction, from degaussing to shredding and pulping, while also demystifying the concepts of MTBF and MTTF. We'll delve into the challenges of data classification and the importance of proper data labeling. Whether you’re prepping for the CISSP exam or simply looking to deepen your cybersecurity knowledge, this episode is rich with actionable insights and expert guidance. Tune in and elevate your cybersecurity skills to the next level!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
What if AI could be your company's best asset—and its biggest risk? Join me, Sean Gerber, on this enlightening episode of the CISSP Cyber Training Podcast, where we journey through the essentials of cybersecurity with a particular focus on media protection techniques from Domain 7.5 of the CISSP ISC² training manual. We’ll also navigate the secure-by-design principles crucial in the age of artificial intelligence. With AI transforming large enterprises, I’ll share eye-opening statistics on its adoption and delve into the risks it brings, such as cloud misconfigurations leading to severe breaches. Plus, we’ll discuss the alarming rise of deepfake scams with a real-world example that shook a UK energy firm to its core.
Ever wondered how to choose the best data encryption method for your needs? This episode has got you covered! We’ll discuss various encryption techniques like AES, RSA, and ECC, and why it's essential to select the right one based on media type. Trust me, understanding key management and rotation is vital for maintaining data integrity, especially when dealing with cloud storage and third-party providers. I’ll also walk you through secure erasure methods, from the DOD 5220.22-M standard to physical destruction techniques like shredding and degaussing, ensuring your data truly becomes irretrievable.
Lastly, don’t miss our deep dive into mobile device protection. I’ll highlight the critical software and physical security measures necessary to defend your devices against threats, emphasizing the importance of regular updates and robust antivirus solutions. We’ll explore strategies for data encryption, backup, and recovery, and clarify the differences between MTBF and MTTF and their relevance to your systems. Wrapping up with the environmental factors affecting device usage and data management, this episode is packed with actionable insights to elevate your cybersecurity game. Tune in now to arm yourself with the knowledge necessary to protect your digital world!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Unlock the secrets to mastering the CISSP exam and bolster your cybersecurity prowess with Sean Gerber in this action-packed episode of the CISSP Cyber Training Podcast! Ever wondered which assessment type is crucial for ensuring ISO 27001 compliance? Discover why internal audits are the gold standard. We'll also cover the key considerations for selecting the right security assessment for your organization, focusing on the pivotal role of aligning with your risk profile and available resources.
Regularly updating your security testing strategies is vital, but do you know why? Learn how to stay ahead of evolving security needs and what factors to prioritize when incorporating cloud security assessments into your strategy. From understanding your cloud service provider’s policies to ensuring your testing remains relevant, this episode is brimming with insights designed to help you ace the CISSP exam and elevate your cybersecurity expertise. Don't miss out on this valuable information!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Ever wondered how to ensure your organization's cybersecurity measures meet international standards? Join us for an action-packed episode as we unpack Domain 6.5 of the CISSP exam, exploring crucial assessments, tests, and audit strategies every cybersecurity professional should master. Learn the importance of choosing a consistent framework like ISO 27001 or the NIST Cybersecurity Framework to steer your audit processes. We'll dive into internal and external audits and the pivotal role they play in aligning security measures with legal and regulatory compliance.
Discover the essentials of security control testing within your organization. We discuss various mechanisms such as vulnerability assessments, penetration testing, and log review analysis, focusing on their significance in pinpointing and mitigating potential security threats. Highlighting tools like Nessus and Qualys, we examine their effectiveness in regular vulnerability scanning, along with the importance of log reviews to detect malicious activities. From black box testing on web applications to understanding how hackers manipulate logs, we cover all the bases to fortify your defenses.
In our cloud security management segment, we tackle the risks associated with orphaned accounts and offer best practices for managing cloud-based accounts. Regular management audits, multi-factor authentication, and semi-annual reviews are just a few of the key strategies we discuss to ensure robust cloud security. We also emphasize the importance of cybersecurity audit planning and reporting, sharing practical examples and tips for creating actionable reports for different stakeholders. Finally, we underline the value of mentorship and the importance of certifications like CISSP for advancing your career in cybersecurity, highlighting the critical role certified professionals play in safeguarding our global economy from cyber threats.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a text
Can quantum computing break your encryption overnight? Discover the profound impact of this emerging technology on cybersecurity as we decode the recently introduced FIPS 203, 204, and 205 standards. Join me, Sean Gerber, on this week's electrifying episode of the CISSP Cyber Training Podcast to understand how the US government is preemptively tackling "harvest now, decrypt later" threats. Learn why these standards are crucial for federal entities and contractors and why mandatory adoption by 2035 is a game-changer for cybersecurity professionals, especially those engaging with the Cybersecurity Maturity Model Certification (CMMC).
Unlock the secrets to mastering access control models essential for fortified cybersecurity. We'll explore the nuanced features and ideal applications for Attribute-Based Access Control (ABAC), Discretionary Access Control (DAC), Role-Based Access Control (RBAC), and Mandatory Access Control (MAC), as well as the fine-grained Rule-Based Access Control (RBAC). Beyond the technical knowledge, we dive into the critical mindset required for true CISSP mastery—one that transcends the exam and empowers real-world application. Plus, your participation supports adoptive families, making our journey together even more impactful. Tune in and transform your cybersecurity strategy today!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
What would you do if your social security number was compromised in a massive data breach affecting billions? In our latest episode of the CISSP Cyber Training Podcast, we unpack the alarming reality of a recent breach that exposed the personal records of 3 billion people. We provide critical advice on how to protect yourself using tools like "Have I Been Pwned," setting up credit freezes, and enabling multi-factor authentication. It's not just about safeguarding your data; it's about arming yourself with the knowledge to navigate these digital threats effectively.
Next, we dive into the realm of access controls with a keen focus on discretionary and non-discretionary systems. Discover why discretionary access control (DAC) might be a double-edged sword for smaller setups and how non-discretionary models such as mandatory access control (MAC), role-based access control (RBAC), and rule-based access control provide a structured, scalable framework for larger organizations. With real-world examples, we breakdown the benefits and challenges of each system, helping you understand which control model best suits your organization's needs.
Finally, we explore the complexities of RBAC and rule-based access controls, emphasizing the necessity of efficient access management in large enterprises and regulated industries. Learn about the principle of least privilege, the intricacies of role assignment, and how predefined static rules can simplify or complicate access management. We also delve into mandatory access controls, using high-security environments like military clearances to illustrate their importance. Whether you're an industry professional or just passionate about cybersecurity, this episode brings essential insights right to your ear.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
How would a massive data breach at a major corporation like Boeing affect the global cybersecurity landscape? Join us on this episode of the CISSP Cyber Training Podcast, where we dissect this alarming 50GB ransomware attack and its profound implications on the industry. Additionally, we unpack the serious data compromise in Maine due to the MoveIt file transfer tool hack, which impacted 1.3 million people, and explore Google's bold move to delete old, inactive account data to manage storage costs effectively.
Improve your organization's security posture with actionable strategies for effective patch management. This episode offers valuable insights into the importance of thorough testing in staging environments and prioritizing patches based on risk and business impact. We'll discuss how to deploy scalable patch management solutions that integrate seamlessly with existing security systems. By combining vulnerability scanning with automated patch tools, you'll learn how to enhance your patch management program's efficiency and measure its success accurately.
Finally, we address the critical first steps to take following a data breach caused by an unpatched vulnerability, emphasizing root cause analysis and patch categorization by relevance and criticality. Tackling the challenge of managing patches in environments with a mix of legacy and modern systems, we suggest a phased deployment approach to ensure compatibility and effectiveness. To end on a high note, we introduce CISSPcybertraining.com—a comprehensive program guaranteed to help you conquer the CISSP exam with a structured and diligent study approach. Tune in and arm yourself with the knowledge to excel in the fast-evolving field of cybersecurity!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered why your SOC team spends so much time on routine tasks rather than addressing critical threats? Discover the 80-20 rule in security operations and see how automating 80% of routine tasks can free up your team to focus on the complex incidents that truly matter. In our latest episode, host Sean Gerber shares his firsthand experiences leading a SOC and provides actionable insights on how to balance automation and customization for an efficient and responsive security operation.
Navigate the complex world of network security with confidence as we unpack the differences between penetration testing, vulnerability scanning, and wireless scanning. Learn why stealth is vital during internal scans, the critical nature of pre-deployment testing, and the importance of post-remediation retesting. You'll gain a deeper understanding of targeted penetration tests versus comprehensive scans and how tools like Qualys can aid in internal assessments. Plus, discover the crucial steps to detect and manage unauthorized access points with a robust incident response plan.
Ready to master vulnerability management and risk mitigation? We'll guide you through clear procedures and prioritizing vulnerabilities based on business-critical criteria. Explore how to handle outdated systems that can't be scanned or fixed, and get tips on maintaining an effective risk management plan. Plus, prepare for the CISSP exam with practical advice on revisiting content and utilizing resources to boost your cybersecurity expertise. Join us for an insightful episode that promises to elevate your cybersecurity career and help you ace the CISSP exam.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered how CPUs juggle multiple tasks seamlessly? On this week's CISSP Cyber Training Podcast, we decode the art of CPU processes and multi-threaded environments. I'm Sean Gerber, and together, we'll navigate the maze of system architectures, from the running state of a CPU process to the marvels of symmetric multiprocessing. Dive in as we unravel the complexities of computing, making even the most intricate concepts accessible and engaging. Whether you're prepping for your CISSP exam or simply hungry for cybersecurity wisdom, this episode is your treasure trove of knowledge.
Have you ever been curious about the real difference between block state and suspended state processes? Let's break it down together, focusing on how clustered systems and microkernel-based architectures efficiently manage their resources and tasks. Discover the answers to pressing questions like which architecture best handles smaller, independent tasks, and what type of execution allows multiple threads to run simultaneously. This episode promises to arm you with the insights needed not just to pass your CISSP exam, but to deepen your understanding of the cyber world. Tune in and transform your cybersecurity expertise!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered how mastering process states and system architecture can be as straightforward as organizing your child's toy box? Join me, Sean Gerber, on the CISSP Cyber Training Podcast as we unpack the complexities of these crucial concepts to help you ace the CISSP exam. Drawing from my personal journey and the hurdles I faced, I'll share practical tips and relatable analogies that make even the most daunting topics accessible. We start by breaking down the initiation of processes in computer systems and the significance of modular development in application design.
Transitioning from theory to practice, we'll explore the importance of resource allocation and process switching. By comparing familial inheritance with computing, I'll demonstrate how permissions and capabilities are passed down within systems. Recalling my experiences with older technology like the B-1 bomber, we'll examine the challenges and strategies for integrating outdated systems with modern applications. We'll delve into the functions of process control blocks (PCBs), security contexts, and the critical role of process scheduling for optimal system performance.
Lastly, we'll focus on the intricacies of process states and kernel mode operations. Understanding how processes transition between states—ready, running, and waiting—can help mitigate cybersecurity risks such as code injection and privilege escalation. We'll discuss why kernel mode is a prime target for attackers and the importance of context switches, comparing how Windows and Linux handle these operations. Wrapping up, we'll emphasize the need for robust protection mechanisms and running operations in restricted states to ensure system stability and security. Tune in to equip yourself with the knowledge needed for effective decision-making in your cybersecurity career.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Are you ready to ace your CISSP exam and propel your cybersecurity career to new heights? This episode of the CISSP Cyber Training Podcast promises to equip you with critical insights on data roles and regulations. From demystifying the responsibilities of data processors under GDPR to unpacking the PCI DSS framework essential for the financial sector, we leave no stone unturned. We'll also clarify the distinctions between asset owners and data owners, and explain who holds accountability for data classification under HIPAA. Plus, you'll get the lowdown on COPPA guidelines for protecting children's data and the intricacies of Singapore's PDPA regulation.
But that's not all! Our deep dive into Security Roles and Responsibilities will provide clarity on the essential positions within the cybersecurity realm. Learn how administrators tackle system hardware and software, why data owners hold paramount accountability, and the specialized skills data custodians bring to the table. We also emphasize the significance of business and mission owners understanding SOX compliance, and the pivotal role of administrators in controlling access rights to data. To top it off, we offer career-boosting strategies—from enhancing resumes to negotiating contracts—designed to elevate your cybersecurity career to unparalleled heights. Don't miss this chance to gain knowledge and skills that will set you apart in this dynamic industry!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Unlock the secrets to mastering Domain 2 of the CISSP exam and navigate the paradox of the booming yet financially strained cybersecurity field. Despite the staggering 4 million global job openings, recent budget cuts and layoffs are reshaping the landscape. Learn how economic challenges are clashing with the rising demand for cybersecurity skills, the increasing pressures of governmental regulations, especially in AI security, and combatting the burgeoning threat of insider attacks. If you're gearing up for CISSP certification, this segment is packed with critical insights you won’t want to miss.
Ever wondered who the gatekeepers of your data truly are? We break down the crucial roles of data owners and asset owners, shedding light on their pivotal responsibilities within an organization. Referencing CISSP and NIST frameworks, discover how these high-ranking individuals play an essential part in data classification, access control, and lifecycle management. Our discussion emphasizes the vital importance of clearly defining these roles to maintain data confidentiality, integrity, and availability—cornerstones of robust cybersecurity practices.
Finally, get acquainted with the essential tools and roles that keep your data fortress secure. From asset management solutions like Intune to the meticulous duties of data processors and controllers, this chapter provides a thorough overview of effective data management. Learn about developing and implementing critical policies and procedures including patch management and usage guidelines. Plus, get the scoop on our new specialized CISSP mentorship program, designed to offer you personalized coaching and career guidance in your cybersecurity journey. Tune in for a comprehensive guide that will bolster your CISSP preparation and career development.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered what the GDPR and the Economic Espionage Act of 1996 have in common? On this episode of CISSP Cyber Training Podcast, I break down the complexities of essential cybersecurity legislation, both in the U.S. and Europe. We'll uncover what you need to know about the Identity Theft and Assumption Deterrence Act, the Wiretap Act, and the UK Computer Misuse Act. Additionally, we'll discuss the intricacies of civil law, HIPAA, and the critical role of administrative law. From the DMCA to COPA, you'll learn how these laws protect digital content and children’s online privacy, and how the RICO Act is instrumental in punishing organized crime activities.
I'm excited to share a significant update with our listeners—a brand new coaching and mentoring program designed to elevate your cybersecurity career. Drawing from my two decades of experience, including serving as a CISO, I'll provide invaluable guidance on career planning, resume preparation, and interview skills. Hear my personal journey from flying B1 bombers to becoming a cybersecurity expert, and gain insights to chart your own successful career. Head to cisspcybertraining.com to explore these new resources and take a definitive step towards achieving your professional goals.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
How does understanding the legal landscape in cybersecurity elevate your professional game? Join us on this episode of the CISSP Cyber Training Podcast as we unpack the complexities of civil, criminal, administrative, and contractual law. Learn how each legal category influences risk assessments, organizational policies, and legal prosecutions. We'll guide you through the nuances of civil law's role in resolving non-criminal disputes, the severe implications of criminal law, and the critical importance of maintaining proper logs for legal conformance.
Discover why precise contractual language is essential for protecting your organization in the event of a data breach. We delve into the importance of collaborating with legal experts when drafting contracts and examine key intellectual property areas like trademarks, patents, and trade secrets. Protect your brand from domain name scams and safeguard valuable business information from impersonation and counterfeiting with practical steps and real-world examples.
Finally, we delve into the pivotal laws that shape cybersecurity practices today. From the Computer Fraud and Abuse Act (CFAA) to the Electronic Communications Privacy Act (ECPA), understand how these laws aid in prosecuting unauthorized access and fraudulent activities. Explore the significance of the Economic Espionage Act, the Electronic Funds Transfer Act, and the UK GDPR in modern transactions and international business operations. Don't miss this comprehensive episode packed with invaluable insights for your CISSP preparation and professional growth in the cybersecurity field.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ready to fortify your software development practices against security risks? Join us as we unearth critical strategies for mitigating vulnerabilities in your code. From the seamless integration of Static Application Security Testing (SAST) into your CI/CD pipelines to refactoring code to eliminate buffer overflow issues, this episode is packed with essential insights. Discover the must-have security controls for cloud-based SaaS platforms, such as robust access controls and code obfuscation techniques. We also delve into risk assessment methodologies like FMEA, STRIDE threat modeling, and OWASP’s top 10 web application security risks, equipping you with the tools to identify and prioritize threats effectively.
But that's not all—our conversation extends into the realm of secure coding best practices within a DevSecOps environment. Timely feedback on vulnerabilities is crucial, and we’ll show you how to integrate SAST tools into your continuous integration pipeline effectively. Learn why relying on security through obscurity is a pitfall and why thorough security assessments are vital when outsourcing software development. We emphasize the importance of automated code reviews and proper developer training to enhance software security. Finally, we share a heartfelt segment on the impact of adoption and the invaluable support our non-profit organization offers to adoptive families. Tune in for an episode that blends technical prowess with a commitment to making a positive social impact.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered how a data breach could impact cloud security, or what measures you need to take to secure sensitive information? Join us in this episode of the CISSP Cyber Training Podcast as we break down the recent AT&T data breach and its implications on cloud environments like AWS and Snowflake. Discover how attackers gained access to critical phone records and network topology, and why staying up-to-date with cloud security is more critical than ever.
We also cover the intricacies of multi-level database security and concurrency fundamentals. Learn why separating data with varied classification levels—like top secret and secret—is essential for preventing unauthorized access and ensuring data integrity. We dive into the challenges of non-greenfield environments, offering practical migration and separation strategies. We also shed light on the benefits of NoSQL databases and how they compare to traditional SQL systems, focusing on their advantages for faster queries and simpler design.
Finally, we turn our attention to best practices for data management and risk mitigation. Explore the three major classes of NoSQL databases: key-value stores, document stores, and graph databases, and understand their unique advantages. We'll guide you through setting up robust logging and monitoring systems, and stress the importance of tamper-proofing logs and defining retention periods. Additionally, we discuss the vital role of stakeholder involvement in risk management and provide actionable strategies for identifying critical assets and mitigating risks effectively. Plus, learn how your participation in our cyber training supports the philanthropic mission of the Adoptus Foundation, helping families afford adoption. Join us for this informative episode packed with insights to elevate your cybersecurity expertise.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Can AI revolutionize your cybersecurity career? Join me, Sean Gerber, on today's thrilling episode of the CISSP Cyber Training Podcast as we uncover the transformative impact of artificial intelligence on cybersecurity jobs, based on a revealing article by Joe McKendrick from ZDNet. With 88% of cybersecurity professionals predicting AI will change their roles and 82% believing it will enhance efficiency, it's clear that adaptation is key. We'll also discuss the alarming report on 10 billion leaked passwords and why password managers are now more crucial than ever for maintaining robust security.
But that's not all—prepare yourself for an in-depth exploration of incident response and digital forensics, from identifying breaches to system recovery. We'll talk about the importance of data acquisition, the strategic use of honeypots, and the necessity of write blockers in maintaining evidence integrity. Plus, discover the pivotal role of log files in tracking malicious activities. Finally, I'll share my personal journey with the CISSP exam and the invaluable CISSP Cyber Training Blueprint, designed to help you conquer the certification with structured and tailored study plans. This episode is a goldmine of insights and practical advice for anyone looking to elevate their cybersecurity career.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Is a four-year college degree necessary to break into the world of cybersecurity? Discover why practical experience and industry certifications might just be your golden ticket to a thriving career in IT. In this episode of the CISSP Cyber Training Podcast, host Sean Gerber unpacks Domain 7.3 of the CISSP exam, emphasizing the significant shift in the job market. With over 7,500 new IT roles added in June alone, Sean discusses how transitioning from general IT to specialized cybersecurity roles can open doors to better opportunities and career growth. He also highlights the growing importance of networking knowledge and the benefits of pursuing roles in architecture and networking.
Ever wondered how to avoid security vulnerabilities associated with unmanaged device additions? Explore best practices for security configuration management as Sean underscores the essence of having a well-defined asset discovery and configuration management plan. Delve into the risks and benefits, from establishing security baselines to adopting scalable solutions for large networks. By referencing NIST 800-128 and tools like Microsoft’s SCCM, Sean provides actionable insights to help you secure operating systems, devices, and applications, thereby reducing your organization's attack surface.
Effective change and communication management can be the backbone of a secure IT environment. Sean breaks down the complexities of these processes, highlighting the value of automation, structured change control, and clear communication strategies. Learn about the importance of having a canary group to test changes before full deployment and the critical role of training both new hires and seasoned IT professionals. Finally, Sean wraps up with the vital importance of comprehensive study and preparation to ace the CISSP exam, offering resources that support not just your career, but also a nonprofit dedicated to adoptive families. Join us for an episode packed with insights, practical advice, and a roadmap to cybersecurity success.Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered how to secure your SaaS environment while mastering essential security testing techniques? Join me, Sean Gerber, on the CISSP Cyber Training Podcast as we navigate the complexities of cybersecurity, starting off with some personal July 4th reflections and an insightful Forbes article on the pressing threats and strategies in the SaaS landscape. With a staggering 96.7% of organizations relying on SaaS applications, the stakes have never been higher. You'll learn about conducting thorough risk assessments, the necessity of data encryption, and why multi-factor authentication is a must-have for safeguarding sensitive data.
In the subsequent chapters, we delve into the nuances of security testing—from the intricacies of black box and penetration testing to the importance of dynamic analysis and code reviews. Discover how fuzz testing can unearth hidden vulnerabilities and the critical role of false positive management in security assessments. We'll also dissect the purpose of threat modeling exercises, providing you with the tools to design robust security controls tailored to your organization's unique threat landscape. Tune in and fortify your cybersecurity arsenal with actionable insights and expert advice to ensure your SaaS environments are secure and resilient.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ever wondered how to fortify your organization against cyber threats? Join Sean Gerber as we uncover the essentials of Domain 6.3 of the CISSP exam, from security assessments to account management and backup verification. Learn about tools like Nessus and Qualys and the role of ethical hacking in identifying vulnerabilities. Discover the critical differences between authenticated and unauthenticated scanning, and how red teams elevate your security measures to the next level.
What sets SOC 1, SOC 2, and SOC 3 reports apart, and why do they matter? We break it all down, revealing how these reports demonstrate adherence to security standards. Understand the distinctions between Type 1 and Type 2 reports, with Type 1 focusing on control design and Type 2 evaluating operational effectiveness. Plus, we delve into the fundamentals of account management, emphasizing the importance of integrating with identity and access management programs and conducting routine audits for compliance and security.
Don't overlook the critical importance of backup data management and verification. Learn best practices for storing backups—whether on-site, off-site, or in the cloud—and ensure your restoration process is both reliable and efficient. We discuss how regular testing and cost-effective strategies enhance organizational resilience and highlight why training and awareness are crucial for both leadership and employees. Additionally, Sean introduces Reduce Cyber Risk, his consulting business, offering a range of cybersecurity services and valuable resources for those preparing for the CISSP exam.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Could a seemingly minor breach at a smaller bank signal bigger vulnerabilities in our financial system? On this episode of the CISSP Cyber Training Podcast, we deliver eye-opening insights on a recent cybersecurity incident involving the notorious ransomware group LockBit. While the U.S. Federal Reserve remained untouched, Evolve Bank and Trust became their latest target. We'll break down what happened, why it matters, and what it means for the cybersecurity landscape. But that's not all – we also dive into critical CISSP practice questions from Domain 5, focusing on essential concepts like identification, two-factor authentication, and the "something you are" factor in multi-factor authentication (MFA). Sharpen your skills and prepare for your CISSP exam with our expert guidance.
Shifting focus in the latter half, we explore the transformative impact of machine learning algorithms and geofencing policies on cybersecurity. From detecting phishing attempts to adjusting security policies based on geolocation, we delve into how these technologies are revolutionizing threat detection and response. We also tackle the challenges of authenticating IoT devices and discuss the innovative concept of device trustworthiness scores. Plus, the balance between the high-security benefits and privacy concerns of biometric technology is a hot topic. By treating individuals as sensors and leveraging real-time alerts, these advancements are not just enhancing security but also reshaping the very fabric of cybersecurity. Join us as we unpack these complex yet fascinating topics to give you actionable insights for your cybersecurity journey.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Want to ensure your organization's sensitive data remains secure in today's mobile-centric world? Tune in to our latest CISSP Cyber Training Podcast episode, where we unravel the complexities of federated identities and robust credential management. Learn from the high-profile data breach involving Change Healthcare and discover how multi-factor authentication could have prevented such a disaster. We promise you'll gain essential insights into how federated identities streamline authentication processes, making your digital life both secure and efficient.
We'll also explore the pros and cons of centralized versus decentralized identity management, highlighting real-world examples like Google and Facebook authentication. Curious about just-in-time credentials? We explain how temporary, on-demand access can significantly reduce security risks, and examine top credential management systems like CyberArk, Keeper Security, and LastPass. To cap it all off, hear about our exciting new non-profit initiative supporting adoptive families. Don't miss out on this comprehensive guide to mastering domain 5, section 5.3 of the CISSP curriculum!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ready to conquer the CISSP exam? This episode promises to arm you with crucial insights into the OSI model and its real-world applications. We kick things off by unraveling the intricacies of VPN tunnels and the pivotal role the data link layer plays in encapsulating data packets for secure internet travel. Next, you'll grasp how a significant Border Gateway Protocol (BGP) security breach zeroes in on the network layer. We then dissect the limitations of firewalls at the transport layer, ensuring you understand which types of traffic remain beyond their reach.
Switching gears, we tackle the security hurdles of converged networks and VLAN segmentation. Discover why adaptive security measures are essential in environments where voice and data traffic coexist and how misconfigurations can open doors to unauthorized access. We also highlight the havoc DDoS attacks wreak across multiple OSI layers and the vulnerabilities of VoIP over wireless LAN. By the end, you'll appreciate the necessity of detecting IP spoofing at the network layer and how VLANs bolster security through tailored policies and isolated broadcast domains. Join us as we not only aim to boost your CISSP readiness but also ignite your passion for a thriving career in cybersecurity.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Are multi-layer protocols the key to safeguarding our digital world amidst the rising tide of cyberattacks? Join me, Sean Gerber, as I unravel the complexities of these protocols and their vital role in cybersecurity, drawing from the CISSP ISC² domains 4.1.4 and 4.1.5. By sharing my firsthand experiences and highlighting the alarming $22 million ransomware payout by Change Healthcare, I underscore the urgent need for redundancy in critical systems, especially within vulnerable sectors like healthcare.
Let’s decode the layers of data encapsulation, from the basic principles of TCP/IP to the robust security offered by TLS and IPsec. We'll discuss how VPN tunnels enhance security and tackle the sophisticated challenge of attackers concealing their activities within encrypted traffic. Discover methods to unmask these covert channels using decryption appliances and targeted traffic inspection, and explore the fascinating realm of steganography for data concealment.
The journey continues with a deep dive into data exfiltration techniques, including EDI communication and low-level network protocols like ICMP and DNS. Learn how malicious actors bypass detection and how network administrators can stay vigilant. Finally, I’ll share my passion for mentorship in cybersecurity, highlighting the enriching experiences and opportunities available through CISSP Cyber Training and my own platforms. Whether you’re a seasoned professional or an aspiring expert, this episode offers valuable insights and resources to bolster your cybersecurity knowledge and career.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Send us a Text Message.
Ready to conquer the CISSP exam? Unlock the secrets of threat modeling with our latest episode! Join me, Sean Gerber, as we break down the STRIDE methodology—Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. Learn how to decode these critical security concepts and master the art of eliminating wrong answers in multiple-choice questions. This episode is your ticket to not only understanding but excelling in one of the most vital areas of cybersecurity.
But we’re not stopping there! We’ll also dissect the main components of a threat model, helping you identify and analyze assets, adversaries, threats, and mitigations with precision. By comparing different sets of terms, you'll sharpen your test-taking strategies and gain a deeper understanding of how to approach the CISSP exam. Whether you’re driving, at the gym, or relaxing at home, this episode is packed with practical, actionable insights designed to elevate your cybersecurity expertise and ensure you ace that exam. Tune in and let's make cybersecurity mastery a reality!
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
What if you could transform your cybersecurity skills and become an expert in threat modeling? Join me, Sean Gerber, on the CISSP Cyber Training Podcast as I guide you through the critical elements of threat modeling, a key topic for any cybersecurity professional gearing up for the CISSP exam. We'll discuss why grasping the nuances of threats is essential to safeguarding your organization's data and systems. From system and threat identification to vulnerability assessments and risk evaluations, this episode is a treasure trove of strategies to fortify your cybersecurity defenses.
Ever wondered how to stay one step ahead of ransomware like CLOP or vulnerabilities in tools like MoveIt? In this episode, we tackle the complex world of threat and risk management, exploring how malicious actors operate and the importance of securing your software, hardware, and human processes. We highlight the necessity of protecting code repositories against unauthorized access and assess the financial implications of potential disruptions. You'll gain insights into aligning security measures with your organization's risk tolerance and learn practical strategies to mitigate these ever-evolving threats.
Finally, we demystify the STRIDE and TRIKE threat modeling frameworks, comparing their unique approaches and applications. You'll hear about each component of STRIDE, from spoofing to elevation of privilege, and learn the benefits and challenges of using this framework. On the other hand, TRIKE's methodical, risk-centric approach offers a holistic view of integrating security throughout the software development lifecycle. We also delve into defense-in-depth strategies and the importance of robust logging and monitoring. To cap it off, I share valuable tips on preparing for the CISSP exam, emphasizing the effectiveness of my comprehensive blueprint available at CISSP Cyber Training. Make sure you tune in and equip yourself with the knowledge to excel in your cybersecurity career.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
What if your organization's data could be breached through an exposed API in your modem? Join me, Sean Gerber, in this week's CISSP Cyber Training Podcast as we unravel the hidden dangers of API connections and dive into the latest security flaws found in Cox modems. We'll also kick off our thrilling CISSP Question Thursday, tackling complex queries from domains 3.1.2 and 3.1.3. Plus, discover why AES-256 stands as the gold standard for cloud data encryption and how implementing custom APIs with complex database schemas can fortify abstraction and access controls within your systems.
In another gripping segment, we break down the pillars of network segmentation and data protection, showcasing their critical roles in crafting a robust cybersecurity framework. Understand the nuances of data hiding through network segmentation, the essentiality of encrypting data at every stage, and the profound impact of secure boot in maintaining system integrity. We also discuss the pitfalls of storing encryption keys on poorly secured servers and the vital function of hashing algorithms for software verification. Wrap up with a detailed exploration of the dual-edged sword of patching vulnerabilities, ensuring you leave equipped with actionable insights for your CISSP exam and your cybersecurity career.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Curious about how to implement robust cybersecurity measures and avoid costly breaches? In our latest episode of the CISSP Cyber Training Podcast, we unravel the intricacies of defense in depth and secure defaults as outlined in domains 3.1.2 and 3.1.3 of the CISSP exam. Starting with a weather update from Kansas, we shift gears to dissect a critical incident at UnitedHealthcare, revealing the repercussions of appointing a CISO lacking specific security expertise. We emphasize the essential role of multi-factor authentication and discuss the internal politics that can shape security decisions in large organizations.
Ever wondered how to shield your data from unauthorized access effectively? Join us as we outline comprehensive data security strategies, including encryption, data loss prevention, and the often-neglected practice of system hardening. Learn how encryption safeguards data across different stages and how data loss prevention tools limit unauthorized channels. We also highlight the critical importance of Security Information Event Management (SIEM) tools for a centralized security overview, and introduce you to the concept of abstraction—simplifying user interactions while minimizing security risks.
To wrap things up, we dive into practical tactics for implementing secure defaults. We'll cover the essentials: strong passwords, disabling unnecessary services, and automatic security updates. Discover the best practices for configuring application settings, network devices, and security tools to enhance your security posture. We also tackle real-world challenges like vendor flexibility, usability concerns, and legacy systems. Finally, we offer invaluable tips and resources to help you set and achieve your CISSP goals with confidence. Don't miss out on these actionable insights to elevate your cybersecurity expertise!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wondered how to navigate the complexities of data classification within your organization? Get ready to sharpen your cybersecurity skills and elevate your knowledge as we dissect CISSP Question Thursday, focusing on domain 2.1.1. This week, we also bring you an intriguing piece of news about ARPA-H, a groundbreaking new agency inspired by DARPA but aimed at revolutionizing healthcare through cutting-edge technology. With a starting fund of $50 million, ARPA-H is set to tackle critical issues like ransomware in the healthcare sector, presenting immense opportunities for those in the cybersecurity field.
We go beyond the basics as we cover crucial aspects of data classification and security protocols across diverse organizational contexts. Learn how to classify different types of data, from marketing campaign materials to sensitive patient information, and understand why encryption is essential for protecting data at rest. We also discuss the limitations of Data Loss Prevention (DLP) solutions and offer key security considerations for managing user geolocation data in mobile apps. This episode is a must-listen for anyone preparing for the CISSP exam or looking to enhance their cybersecurity expertise.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
As we honor the memory of those who have served and sacrificed, we also acknowledge the ever-present battlefield of cybersecurity. Today, we dissect the essentials of data classification, an integral aspect of Domain 2 in the CISSP exam, while paying tribute to Memorial Day. Join me, Sean Gerber, for a candid conversation where we unwrap the layers of Microsoft Copilot's recall feature and its privacy concerns, and we address how these advanced AI technologies intersect with the need for robust data protection strategies.
The safeguarding of sensitive information, particularly PHI and PII, is not just a compliance matter but a moral imperative. This episode offers an in-depth look at the administrative, technical, and physical controls that form the backbone of HIPAA regulations. We navigate through the critical elements of data security, from compliance training to incident response plans, and reveal why regular risk assessments are not just a checkbox on an auditor's list but a rehearsal for the unforeseen, ensuring your organization is primed for any eventuality.
In reflecting on my own two-decade journey through the trenches of cybersecurity, from orchestrating red team operations to my tenure as a CISO, I share a treasure trove of stories and insights. I delve into the services I offer, all aimed at fortifying your company against the relentless onslaught of digital threats. For aspiring CISSP candidates or seasoned professionals looking to reinforce their cybersecurity posture, this discussion is an opportunity to glean from my experiences and chart a course for a more secure digital horizon.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the doors to a fortified cybersecurity career with me, Sean Gerber, as we navigate the complex landscape of CISSP concepts tailored for those aspiring to conquer the CISSP exam. We're not just scratching the surface; we're burrowing into the depths of what it takes to understand and tackle real-world security challenges. From the perils of unprotected customer data on cloud servers to the intricacies of managing employees who sidestep DRM for convenience, this podcast equips you with the knowledge to address these issues head-on. Get ready to absorb strategies that fortify your cybersecurity defenses and master the controls that thwart unauthorized data exposure.
As we march through the eight domains of CISSP, we dissect the fine balance between security measures and operational complexity, ensuring your policies don't just check boxes but actively protect your enterprise. Together, we'll decrypt the importance of encryption for portable devices and debate the merits of DMZs for bridging the gap to secure cloud interactions. Entering the realm of remote desktop access, I'll champion the cause for SSH protocols fortified by robust authentication methods. By the close of our session, you'll not only have unraveled the blueprint for CISSP success but also be primed to pepper your systems with penetration tests to uncover hidden vulnerabilities. Join me for a session that promises to elevate your cybersecurity prowess to meet the CISSP challenge with confidence.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Dive deep into the legal intricacies of cybersecurity with me, Sean Gerber, as I guide you through the maze of laws and scams impacting our digital world. Prepare to arm yourself with knowledge that stretches far beyond the CISSP exam, as we tackle the multi-million-dollar repercussions of cybercrimes and the collaborative global efforts to combat them. This episode lays down the framework of civil, criminal, administrative, and contractual law, providing a comprehensive understanding crucial for every cybersecurity professional's arsenal.
Unveil the complexities of intellectual property in the era of endless digital replication. From the subtleties of trademarks to the battleground of domain names, I'll share insights on the essential partnership between cybersecurity experts and legal teams. Real-life scenarios, such as the proprietary connectors dilemma, exemplify how patents can serve as a double-edged sword, propelling innovation while stirring up legal challenges. Our conversation is a stark reminder of the weighty responsibilities we bear in protecting the lifeblood of enterprises: their intellectual assets.
In our final segment, we shift focus to the individual, dissecting laws like the ECPA and the Identity Theft and Assumption Deterrence Act that shield personal data against the prying eyes of cyber thieves. I'll also spotlight the cutting-edge CISSP Cyber Training career coaching program, designed to propel your cybersecurity career forward by ensuring your actions within the industry are as legally sound as they are technically proficient. Whether you're safeguarding bank transactions or navigating the nuances of GDPR, this episode is your guide to the legal obligations that come hand-in-hand with the title of cybersecurity professional.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Fend off cyber extortionists with cutting-edge insights from our latest cyber training podcast, where Sean Gerber and I dissect the sophisticated methods to recover data from ransomware's icy grip. Inspired by a Sophos News article, we navigate through six data retrieval strategies that could save your business in a pinch, emphasizing that while there's no magic bullet, prioritizing certain file types could make all the difference in your recovery efforts. And because we know your time is valuable, we've dedicated a segment to CISSP Question Thursday, ensuring you're armed with the knowledge to conquer the CISSP exam with confidence.
The digital battlefield is fraught with risks, but we've got your six with a deep dive into the alignment of Recovery Point Objectives with backup frequencies—get this wrong, and it could spell disaster. Calculating your Annual Loss Expectancy isn't just about crunching numbers; it's about understanding when to shield your assets and when to strategically embrace risk, striking that delicate balance that keeps costs in check. We'll unveil some hidden facets of Business Continuity Plans, including the curious role of marketing strategies, and pull back the curtain on cold sites' function in disaster recovery. As we dissect incident response, we spotlight the crucial identification phase and map out how to calculate the financial impact of security breaches, ensuring you're never left in the dark when crisis strikes.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the mysteries of cybersecurity and business continuity with me, Sean Gerber, as we navigate the treacherous waters of cyber threats, including the dark reality of ransomware's impact on our critical infrastructure. Tune in for an intricate look at the geopolitical cyber chessboard, where nations could be gearing up for digital warfare. We'll assess the fine line between cyber vandalism and an act of war, and explore how to arm yourself with knowledge and strategies to protect your organization's sensitive data and systems.
Step into the world of risk assessment as we unravel both the quantitative and qualitative methods crucial for business continuity planning. You'll gain insights into the art of calculating potential financial loss and discover the inherent challenges of valuing intangible assets, such as customer trust and brand integrity. I'll walk you through the complexities of these assessments, offering foundational knowledge that transforms theory into practical wisdom for effective leadership and decision-making in times of crisis.
Prepare to become a bulwark against cyber threats as we discuss the nuts and bolts of aligning business continuity plans with organizational goals, and the significance of constant adaptation. I'll break down disaster recovery jargon, rendering MTD, RTO, and RPO no longer cryptic, but clear markers to guide your recovery strategies. Join us for this vital conversation, and learn how we're supporting a noble cause through the CISSP Cyber Training initiative, empowering future cybersecurity defenders. Your questions and engagement are not only welcomed but essential, as we collectively strengthen our cyber resilience.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Cybersecurity isn't just about the tech; it's about making tough calls under pressure, and this episode is your field guide to navigating those high-stakes scenarios. I'm Sean Gerber, and today we dissect not only the ins and outs of crucial security measures like multi-factor authentication—underscored by the UnitedHealthcare ransomware fiasco—but also the contentious debate surrounding ransom payments during cyber-attacks. Get ready to gain managerial insight that could be the difference between a contained incident and a full-blown crisis, all while contributing to a cause that's reshaping lives—one adoption at a time.
We take a deep dive into the intricacies of Annual Loss Expectancy, Digital Rights Management, and why fault tolerance isn't just a buzzword—it's a lifeline. But it doesn't end there; we scrutinize the importance of weaving security into the very fabric of software development and tailor defenses against modern digital threats. From the nitty-gritty of end-to-end encryption to the frontline defenses against SQL injection, this episode isn't just a conversation—it's an arsenal of knowledge that'll arm you for the cybersecurity battles ahead, and a step on your path to CISSP certification.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on a transformative journey into the world of cybersecurity with me, Sean Gerber, as your guide. Discover how to fortify your career foundations and traverse the evolving landscape of digital protection. Our latest episode delves into the crucial timelines for mastering cybersecurity, with a special look at Dragos' role in safeguarding operational technology—think electricity and water, the lifeblood of our community.
Navigating the educational routes towards a cybersecurity career can be as intricate as the firewalls we swear by. I cover everything from the pragmatic approach of community colleges to the intense dedication required for boot camps like the University of Kansas. Alongside this, I share personal insights into selecting the right certification and the perpetual journey of learning, ensuring you're equipped to climb from an entry-level analyst to the strategic heights of a CISO.
But it's not all algorithms and code; it's about giving back too. Tune in as I reveal our CISSP Cyber Training initiative that goes beyond knowledge sharing. Profits are funneled into a foundation supporting adoption funding—a cause that personally resonates with me as a parent of four adopted children. By joining our training, you're not only securing your future in cybersecurity but also unlocking doors for families to grow through adoption. It's an episode that marries professional advancement with heartfelt philanthropy, and it's one you won't want to miss.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the vault of cybersecurity wisdom and ace the CISSP exam with the guidance of Sean Gerber on the CISSP Cyber Training Podcast. Prepare to transform your approach to cyber studies as we emphasize understanding over rote memorization, with a treasure trove of 3,000 to 5,000 practice questions to arm you for battle. We'll tackle the complexities of integrating Multi-Factor Authentication seamlessly into current systems, and when facing the specter of data exfiltration, we'll arm you with the essential first steps to take control of the situation. Sean also sheds light on the nuances of ensuring data confidentiality amidst the tempest of cloud migrations, making this episode a fortress of knowledge for cybersecurity professionals.
This episode doesn't just stop at exam prep; it's a full-fledged crusade into the heart of a robust cybersecurity incident response. From the swift action required to quarantine a malware outbreak to the deft maneuvers needed to curb privilege creep with the principle of least privilege, you'll be equipped to defend your digital realm. We'll reveal the critical features of SIEM systems that make them the sentinels of your cyber domain, and when it comes to safeguarding the vaults of cloud data or fortifying the ramparts of online banking platforms, you'll learn the cornerstone strategies for unshakeable security. As we hoist the banner of secure coding practices, you’ll be ready to champion organizational security policy compliance, making this session an indispensable ally in your quest for cybersecurity mastery.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on a journey through the intricate world of cybersecurity certifications with me, Sean Gerber, and discover how to transition from tech enthusiast to CISSP-ready specialist. If you're looking to solidify your place in the cybersecurity realm, this episode is the map you need to navigate the terrain of essential certifications. We begin with the cornerstone certifications like CompTIA's A+ and Network+, examining their price tags, the time commitment for study, and the expansive knowledge they provide. Knowing these can craft a formidable foundation for your cybersecurity expertise.
As we forge ahead, the episode carves out the pathway to more advanced certifications, including CompTIA's Security Plus and the Certified Ethical Hacker (CEH). These are the milestones for anyone lacking the five-year experience but aiming for the CISSP pinnacle. Here, the discussion illuminates the significance of each certification, how they dovetail with CISSP prerequisites, and the practicality of options like the GIAC Security Essentials. My insights aim to steer you clear of costly detours and equip you with the knowledge to prioritize and select the certifications that will truly amplify your cybersecurity career.
Finally, we approach the summit: preparing for the CISSP exam. I lay out the CISSP cyber training blueprint from my website, a structured study guide to keep your preparation on track and your goal within reach. The blueprint is your accountability partner, ensuring your focus as you tackle each domain necessary for the exam. As our session wraps, I leave you with a wave of encouragement for the week ahead and the anticipation of diving into the first domain of the CISSP in our next gathering. Let's fortify your cybersecurity career, step by certified step.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to conquer the CISSP exam with flying colors? This week, we've zeroed in on Domain 8 – the soul of software development security! I'm Sean Gerber, your cybersecurity compatriot, and I'm here to guide you through the labyrinth of securing software right from its architectural blueprint to its final lines of code. We kick things off with a bang, dissecting the crucial role of design and architecture in embedding security into your SDLC. It's not just about building software; it's about fortifying it from the foundations!
As we navigate through this treasure trove of knowledge, we'll demystify the enigmatic world of application security testing. You'll learn to distinguish your SAST from your DAST, and why a meticulous code review can be your best defense against hidden vulnerabilities. Plus, we decode the wisdom of OWASP, ensuring you're armed with the latest strategies to safeguard your applications against cyber threats. And for those exhilarating runtime challenges? We shine a spotlight on vulnerability scanning – your dynamic sentinel in the ever-evolving battleground of cybersecurity. Join me for an episode that's not just informative, but a strategic playbook for your CISSP triumph!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets of weaving impenetrable security into the fabric of software development, as we dissect the Software Development Life Cycle and its crucial role in cybersecurity. We're not just coding; we're crafting digital fortresses that stand resilient against the onslaught of cyber threats. From the strategic implementation of least privilege to the complexity of secure code repositories, this episode is your masterclass in transforming functional software into fortified security champions.
Step into the dynamic battlefield of DevOps and security testing, where collaboration meets conflict and continuous integration is king. I share the ins and outs of various testing methodologies—each a critical piece in the puzzle of proactive defense. Discover how to navigate the treacherous waters of third-party components and API calls, ensuring your ship remains unsinkable amidst the ever-present threat of security breaches. Remember, it's not just about patching up vulnerabilities; it's about charting a course through the storm with airtight strategies.
Finally, we tackle the repercussions of weak security controls, the dire consequences for businesses skirting the edge of compliance cliffs, overlooking data protection. GDPR, HIPAA, PCI—three acronyms that should send a shiver down the spine of any company not taking cybersecurity seriously. I stress the importance of embedding security into every line of code, every policy, and every practice. Tune in and arm yourself with the knowledge to shield your organization's reputation and fortify its digital presence.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets of cutting-edge cybersecurity as we navigate the revolutionary impact of drone technology in the insurance industry and delve into the critical components of network security essential for CISSP certification. Sean Gerber here, and I'm eager to guide you through the complex landscape of firewalls, from the fundamentals to next-generation marvels. We'll dissect packet filtering and the indispensable roles these digital gatekeepers play in safeguarding our networks. Prepare to emerge with a fortified understanding of these pivotal cybersecurity tools.
Embark on a journey through the latest advancements in firewall technologies, where we dissect the importance of Web Application Firewalls (WAFs) and their arsenal against web-based threats. We peel back the layers of circuit-level gateways, proxy servers, and the integrated prowess of next-generation firewalls, armed with AI and deep packet inspection. This episode is designed to be your companion in mastering Network Security for the CISSP exam, complete with a treasure trove of resources at CISSP Cyber Training. Whether you're a seasoned pro or a newcomer to the field, this deep dive will equip you with the knowledge to stand at the forefront of the cybersecurity battlefield.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Dive into the digital trenches with me, Sean Gerber, and ward off cyber threats as we dissect the intricate design of firewalls. Cybersecurity isn't just tech jargon; it's a barricade guarding our financial fortresses from trillion-dollar breaches. In this comprehensive session, we don't just skim through firewall types and setups; we equip you for the frontlines of data protection and cybersecurity leadership. Whether you're a CISSP candidate or a seasoned pro looking to sharpen your skills, this episode promises insights that blend exam prep with real-world network defense strategies.
Imagine safeguarding a hypothetical nuclear plant in Sri Lanka; it's a gargantuan task that parallels the complex compliance and architectural challenges we unpack here. Firewalls serve as the bulwark for critical infrastructure, and we delve into the art of balancing stringent government mandates with the innovative architecture of firewall systems. From log management to scaling secure network environments, we address the technicalities and managerial acumen needed to navigate these waters successfully. This episode is a treasure trove for anyone in the cybersecurity field, brimming with knowledge on how to align security tools with organizational needs and capabilities.
As we wrap up, I lay out the roadmap for conquering the CISSP exam. It's not just about mastering the material; it's about embracing a strategic mindset to tackle the broad spectrum of concepts. With CISSPcybertraining.com in your arsenal, we prepare you to face your Achilles' heel head-on. Our conversation is more than a study session; it's a call to arms for cybersecurity warriors ready to rise through the ranks and shield their networks from the onslaught of cyber threats. Tune in, fortify your knowledge, and transform your understanding of cybersecurity with every minute of this episode.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Cybersecurity's battleground is evolving with AI and quantum computing at the forefront. Are you prepared for the oncoming digital storm? Join me, Shon Gerber, as we reinforce crucial skills for vulnerability assessments and network scanning, and delve into the promising yet perilous world where artificial intelligence meets digital defense. With insights gleaned from a recent Google survey, we discuss the bright future of AI in enhancing security protocols and its darker potential to empower hackers. Furthermore, I shed light on the NSA's forewarning of practical quantum computing's arrival, its implications for today's encryption, and the strategic importance of planning for a quantum future. This conversation will arm you with the foresight to ensure your networks are ready to weather tomorrow's challenges.
Draw back the curtain on the arcane workings of network protocols and enhance your CISSP exam readiness with our comprehensive Cyber Training Overview. We begin by dissecting the intricacies of TCP network protocol identification and scanning techniques, illuminating the critical function of CVE identifiers, and unraveling the role of XML in automated vulnerability assessments. Then, transition to an examination blueprint with our CISSP Cyber Training, where we offer a wealth of resources - from podcasts to mobile-friendly audio materials - to streamline your study process. Whether you're in search of strategies to pass your certification or insights to fortify your organization's security posture, this episode provides the guidance and tactics you need to excel.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Join me, Shon Gerber, on a journey that cuts through the complex undergrowth of cybersecurity's vulnerability assessments. This week's episode is a treasure trove for CISSP exam candidates and professionals alike, as we unpack the intricate details of CVEs, CVSS scores, and the acronyms that are the bread and butter of our industry. Discover how the technical handshake of a TCP connection can reveal your system's soft spots and why a recent ransomware attack in Missouri is a stark reminder of our critical role in safeguarding municipalities.
Strap in as we navigate the four crucial stages of vulnerability assessment. I lay out the roadmap from planning to remediation, highlighting the necessity of both automated and manual techniques to unearth security gaps. It's a game of cat and mouse where patches and updates are your best defenses, and I'll shed light on how an iterative approach to reassessing vulnerabilities keeps your security posture robust. We'll also tackle the CVSS and its role in painting a clear picture of vulnerability severity – knowledge that's invaluable when making those tough calls between business needs and risk management.
Finally, for those gearing up for the CISSP exam, I've got your back. Hear how my own hurdles turned into a blueprint for success and how you can leverage my structured approach to not just pass, but excel. I'm dishing out the comprehensive resources and step-by-step guidance that you'll need in your arsenal to conquer the CISSP with confidence. So, tune in, absorb, and arm yourself with the strategies that will elevate your cybersecurity expertise to new heights.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Cybersecurity isn't just a buzzword—it's the fortress between your data and a barrage of cyber threats. I'm Sean Gerber, and in this deep-dive session, we confront the stark reality of a world where ransomware attacks have soared, as per a Scottish non-profit's alarming statistics. Doubling down on the urgency for cyber resilience, we underscore the critical need for skilled professionals in this high-stakes domain. Prepare to navigate through the gritty nuances of user account provisioning, from the pivotal inception of user data collection to the often-overlooked, yet crucial final steps in deprovisioning. This isn't just theory; it's the practical know-how that fortifies businesses against the ever-present specter of cybercrime.
Shift gears and join the frontline of digital defense as we dissect identity governance and access management—pillars of a secure online infrastructure. Drawing from the CISSP playbook, we unravel the sophisticated layers of multi-factor authentication, the streamlined efficiency of single sign-on solutions, and the wisdom in wielding the principle of least privilege. Whether you're gunning for CISSP certification or just have a vested interest in cybersecurity, our conversation is the ammunition you need to guard against the human errors that often lay organizations bare to attacks. Tune in for a session that promises to arm you with the insights and strategies to safeguard our digital world.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Could your company's board benefit from cybersecurity expertise? Discover the untold impact security professionals can make in risk mitigation and financial stability. This week on the CISSP Cyber Training Podcast, I, Sean Gerber, navigate the critical intersection of cybersecurity and corporate governance, underscoring a need for expertise that's often overlooked. We dissect the lifecycle of role management, from the precise art of onboarding to the essential processes of deprovisioning and offboarding. Ensuring your organization's digital fortress is impenetrable requires immediate action and smart tools, which we'll cover in detail.
Struggle with managing permissions in your organization? You're not alone. We'll break down Role-Based Access Control, a system that not only fortifies your security but streamlines your access management too. By understanding the risks of credential creep and the benefits of roles defined by job functions, you'll see how a robust RBAC system can prevent conflicts of interest and align with evolving business processes. And for those in the trenches of cybersecurity, I'll outline how the synergy between compliance and security teams forms the backbone of a solid role management plan.
Finally, we turn our focus to the CISSP exam, providing a beacon for those charting a course through the vast sea of cybersecurity knowledge. With strategic guidance and essential resources, I'll steer you towards not just passing the exam, but mastering it. Ensure you're equipped with the right identity and access management tools like single sign-on, multi-factor authentication, and Identity Governance and Administration. Remember, your journey doesn't end with certification. Stay connected for continued support as we build your cybersecurity expertise into a powerhouse skill set for any organization.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on an exciting foray into the ever-evolving world of cybersecurity with me, Sean Gerber, as I chart a new course into independent consultancy. The waters are rough, with the UK's critical infrastructure facing an unprecedented OT threat landscape, exacerbated by global geopolitical unrest. Uncover how seemingly secure supply chains and legacy OT systems can become a playground for cyber adversaries, and why protecting energy and utilities has never been more vital. Gain insight into the Purdue model's crucial role in network segregation, and realize how these strategies are essential defenses against the sophisticated threats of today.
Transitioning to the educational side of cyber defense, this episode serves as a beacon for CISSP aspirants. We tackle domain 4.1.3 head-on with a CISSP question session that challenges and hones your understanding of essential security protocols like IPsec and Kerberos. I also unveil the extensive arsenal of resources available at cispsybertraining.com, providing everything from free videos to a meticulously crafted blueprint for acing the CISSP exam. Whether you're a seasoned pro or just starting, this podcast is your ally in the quest for certification and mastery in the digital security realm.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on a cybersecurity odyssey with Sean Gerber as he reveals his leap into the consultancy realm, navigating the precarious balance between the thrill of independence and the stark realities of forging a new path. This episode offers an insider's perspective on secure communication protocols, a fundamental aspect of the CISSP exam, and a critical component of any robust cybersecurity defense. As we dissect the repercussions of the United Health Care hack and its jaw-dropping $22 million ransom, we'll equip you with the acumen to convey the financial stakes of cyber incidents to those who hold the purse strings.
As the digital world's intricacies unravel, we delve into the heart of network security with a focus on IPsec configurations and Public Key Infrastructure's role in authentication. You'll gain insights into the synergy between Kerberos and Active Directory, and the critical trade-offs between ease of access and ironclad security. Our journey also scrutinizes the pressing need to abandon outdated algorithms in favor of more resilient encryption standards, ensuring that your remote access remains a bastion against ever-evolving cyber threats.
Rounding off our excursion, we examine SRTP and ZRTP, protocols that stand at the vanguard of securing real-time communications like VoIP. Assess the benefits of these protocols against potential hurdles and system intricacies. Moreover, we'll discuss the intersection of the ZRTP with the widely recognized Signal protocol, providing you with a comprehensive understanding of the landscape of secure communications. Join us for a deep dive into the technologies that safeguard our digital interactions and arm yourself with knowledge that transcends the theoretical, ready to be applied in the practical world of cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on a transformative journey with me, Sean Gerber, as I share the pivotal moment of venturing into full-time cybersecurity consulting after a significant chapter of my career. It's a time of change and opportunity, not just for me but for the entire cybersecurity landscape, as we witness the shockwaves of a ransomware attack on Change Healthcare and its repercussions on entities like UnitedHealthcare. In this episode, we peel back the layers of this incident to reveal the harsh realities and potential regulatory upheavals that could redefine industry standards and hold executives' feet to the fire. Get ready for an essential discussion on the intersection of cybersecurity and accountability and how it impacts us as professionals in the field.
As we navigate these turbulent waters, we also unravel the complexities of checksums and cryptographic hash functions. Understand why CRCs can't keep your data under wraps and the vital importance of collision resistance in hashing algorithms. We go beyond basic error detection and step into a world where digital signatures and certificates are the sentinels guarding our digital identities. This deep dive into the technical underpinnings of cybersecurity doesn't just prepare you for the CISSP exam; it arms you with the knowledge to fortify your data against the evolving threats in the cyber realm. Tune in and bolster your defenses with insights from the forefront of cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Could your passwords withstand a cyber siege by expert Russian hackers? My latest podcast episode serves as a wakeup call to the cyber threats looming over us, showcasing the recent breach of Microsoft's test environment. As Sean Gerber, I dissect the pivotal missteps in password management and underscore the lifesaving grace of multi-factor authentication. We then shift gears to the bedrock of cyber training, examining message authenticity and integrity controls. By unpacking the intricacies of message digests and hashing algorithms, I highlight how they are the unsung heroes in maintaining data sanctity from sender to receiver.
The digital realm's trust hinges on the integrity of digital signatures and certificates—crucial allies in the war against data manipulation. Tune in as I break down how hash functions like MD5 and SHA are your first line of defense on file-sharing platforms. But there's more: I pull back the curtain on the encrypted world of digital signatures, revealing their role in sender verification and message security. Diving into the complex trust web spun by Certificate Authorities and the X.509 standard, we explore how digital certificates serve as digital passports in the online world. Brace yourself for an enlightening journey through the landscape of email protection with S/MIME, ensuring that your virtual conversations are sealed, secure, and verifiably authentic.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Confront the cyber siege that has the healthcare industry on high alert; this episode sees me, Sean Gerber, dissecting the harrowing United Healthcare ransomware crisis that's rocked our nation. We're not just crunching numbers here—$22 million in ransom to Black Cat hackers signifies more than a hefty payout, it's a stark reminder of our critical infrastructure's fragility in the face of cyber threats. The recent episodes have armed us with knowledge, and now, it's time to put that to the test with CISSP Question Thursday, giving you the tactical edge to conquer the CISSP exam and fortify your cybersecurity defenses.
As we navigate the Cybersecurity Concepts and Questions segment, prepare for a thorough breakdown of the digital security toolkit—from honeypots that dupe attackers to the emerging realm of Post-Quantum Cryptography. We'll unravel the essentials of digital signatures with RSA, scrutinize the steadfastness of SIEM systems, and demystify access control models that stand guard over our data. By the end of our journey, you'll not only be versed in preventing cross-site scripting catastrophes but also equipped with a CISSP Blueprint for Success, your very own strategic study companion stocked with invaluable resources to guide you through the certification labyrinth. Join me, and together let's transform these insights into an unbreachable cybersecurity stronghold.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embarking on a new chapter in my cybersecurity journey, I can't wait to share the depth of insights that come with stepping into the consulting realm. The world of cybersecurity is ever-evolving, and I'm here to navigate this complex landscape with you, offering the expertise you need to protect your data in today's digital battleground. From deciphering the states of data to unveiling the encryption methods that keep your information safe, this episode is a goldmine for anyone serious about mastering cybersecurity, whether for the CISSP exam or the harsh realities of the industry.
Have you ever considered how data encryption and loss prevention go hand-in-hand? We dissect the nuances of data in transit, weighing the benefits of end-to-end encryption against the relative vulnerabilities within internal networks. Furthermore, exploring the Tor network opens up a discussion about the trade-offs between user anonymity and the potential for identity exposure. Tackling these complex issues, we also touch on the intricacies of managing digital rights and information access, with real-world examples that bring these concepts to life for our listeners.
Wrapping up, we pull back the curtain on the shadowy realm of code obfuscation, a technique that keeps the prying eyes of attackers at bay, yet can be a double-edged sword in malware defense. I share my thoughts on the careful balance required to implement obfuscation effectively, without falling into a labyrinth of confusion that could stifle your team's productivity. Join us for this deep dive into the world of cybersecurity, where practical knowledge meets real-world applications, all aimed at fortifying your defenses in the digital age.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Imagine your Ubiquiti router as an open treasure chest amidst cyber pirates—how long before it's plundered? This episode throws you a lifeline, urging IoT and critical infrastructure pros to safeguard their digital booty by updating those default credentials, stat! But it's not all about fending off Russian cyber threats; we also turn the tables with CISSP Question Thursday, sharpening your cybersecurity smarts. We dissect the anatomy of a bulletproof security policy, navigate the waters of compliance, and tailor guidelines fit for the remote access odyssey. For those mapping their course through the CISSP certification, this treasure map of insight isn't just for exam prep, it's your compass to mastering the cybersecurity seas.
Hoist the sails to the cloud and set a course for the uncharted realms of security standards. This episode's horizon teems with ISO 27001 and ISO 27018—beacons of security in the nebulous cloud. You'll learn to detect anomalies with the sextant of configuration baselines and craft password management protocols as unique as your crew's roles. By charting the tricky waters of BYOD policies and weighing the merits of government-recommended frameworks, we ensure your vessel is shipshape for whatever digital squalls may come. Remember, my cyber training blueprint is your trusty first mate, here to guide you to that CISSP certification, with a trove of resources for every buccaneer, whether ye be sailing solo or with a fleet.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Get ready to fortify your cybersecurity knowledge base, as I, Sean Gerber, guide you through the labyrinth of security policies and the pivotal Business Impact Analysis (BIA). Our latest CISSP Cyber Training Podcast episode is a treasure trove of insights, where we unravel how security policies aren't just documentation—they're the shields guarding your organization's data. With the revolution of AI, crafting these crucial policies has become more intuitive, ensuring that roles, responsibilities, and data protection measures are crystal clear to keep sensitive information under lock and key.
Venture beyond the basics as we scrutinize the meticulous process of creating security policies that stand as the vanguard against legal risks and define the line between acceptable and unacceptable behaviors. Discover the art of balancing specificity with flexibility in setting security standards and guidelines, maintaining high-quality protection while adapting to the evolving landscape of IT. This episode isn't just about setting rules; it's about building a resilient fortress through Business Continuity Planning, with BIA as your strategist to quantify risks and prep your business to withstand the unexpected.
Aspiring CISSP candidates, this is your beacon in the night. Take a comprehensive journey with us as we lay out a roadmap of resources designed to navigate the complexities of the CISSP curriculum. From in-depth video lectures to tailored courseware, we're here to equip you with the armor and sword to conquer the CISSP exam. Step into the arena with confidence, knowing that you're part of the vanguard defending our digital world from the onslaught of cyber threats. Join us, and let's advance your cybersecurity expertise together.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets to crafting impenetrable software as we delve into Domain 8 of the CISSP exam, where design and architecture reign supreme in the security integration battle. Prepare to have your coding paradigms shifted and your architectural blueprints fortified in this episode, which is nothing short of a cyber-fortification masterclass. We tackle the most critical phase of the SDLC and reveal how a well-laid foundation can make or break your software's defensive capabilities. Whether you're a seasoned professional or just starting, the insights shared here will be the cornerstone of your cyber defense strategy.
This week, we're not just passing along knowledge; we're equipping you with the tools to revolutionize your approach to software development and security. We unpack SAST techniques, emphasizing the importance of meticulous code reviews in sniffing out potential vulnerabilities. Additionally, we demystify OWASP, providing a treasure trove of resources for web application security that's ripe for the taking. And if you're intrigued by the concept of integrated product teams, you'll find our exploration into their role in software development to be invaluable. By the end of this podcast, you'll understand why these teams are integral to fostering collaboration and innovation in the pursuit of unbreakable software. Join us on this journey to elevate your CISSP readiness and cybersecurity prowess.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you prepared to navigate the intricate maze of software development and cybersecurity? This week's episode guarantees to arm you with the expertise to conquer the CISSP exam and apply these vital skills in the real world. We delve into the structures and strategies that define successful software projects, comparing the precision of the waterfall model to the flexibility of agile, scrum, and the hybrid vigor of the spiral approach. Our foray into recent cyberattacks on US pharmacies serves as a stark reminder of the omnipresent cyber threats and the critical role third-party providers play in cybersecurity risk management.
This journey through the software development lifecycle shines a spotlight on the crucial stages, from system requirements to operations, all while emphasizing the significance of aligning with customer and stakeholder needs. I also share insider tips on selecting the right programming languages and development tools to match project needs and developer expertise. For those who favor visual learning, we've got you covered with insightful resources from my blog and CISB cyber training that paint a clear picture of these methodologies in action.
Finally, we cap off with an exclusive offer for our listeners pursuing CISSP certification: a treasure trove of 360 free practice questions, available over six months to elevate your study game. Sign up today to receive the first set of questions and unlock a personalized learning experience with tailored content that will guide you through the cybersecurity domain. Whether you're a seasoned pro or a CISSP aspirant, this episode is your gateway to mastering the ever-important intersection of software development and cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets to expert incident response with me, Sean Gerber, in this week’s CISSP Cyber Training Podcast. We're crunching down on the essential steps to effectively detect, respond to, mitigate, and recover from cybersecurity incidents. If you're serious about acing the CISSP exam and expanding your cybersecurity acumen, this episode is your study hall. We'll sift through real-world scenarios, dissecting the types of technologies that keep a vigilant eye on your network's pulse.
This isn’t just another lecture; it's a hands-on guide brimming with the kind of quiz-style interaction that sharpens your reflexes for test day and beyond. No guest, just you and me, tackling the questions that can make or break your understanding of incident management. From identifying false alarms to responding to genuine threats, this episode isn’t about pointing fingers—it's about empowering you with the know-how to keep your organization running smoothly. So, gear up for an insightful ride through the landscape of cybersecurity incidents and emerge more prepared than ever for the challenges of the digital world.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Prepare to elevate your cybersecurity savvy to new heights! Join Sean Gerber as we dissect the nuts and bolts of the incident response process, an indispensable asset for acing the CISSP exam and bolstering your organization's digital defense. This episode is a treasure trove of strategies, focusing on crafting top-notch incident response plans and fostering a security culture that can withstand the toughest cyber challenges. Whether you're a part of a burgeoning small business or a sprawling enterprise, you'll uncover tailored advice on utilizing firewall and DNS protection, embracing multi-factor authentication, and more. Don't forget to catch the unveiling of "Reduce Cyber Risk," the podcast set to empower SMBs with state-of-the-art cybersecurity tactics.
Imagine if your cross-departmental team could seamlessly orchestrate their cyber defense responses. We've got you covered with a deep dive into the art of conducting tabletop exercises, bringing together the brightest from management, IT, HR, and public relations to fortify incident response strategies. Sean illuminates real-world scenarios, from ransomware to insider threats, and emphasizes the importance of tools like SIEM systems and firewall log monitoring. By adopting the perspective of an ethical hacker, you'll gain a competitive edge, learning to set up formidable defenses that keep potential threats at bay.
Wrapping up the cyber odyssey, we navigate through best practices for managing infected machines and minimizing cyber threats. You'll learn about the tightrope walk of containing malware while keeping the business gears turning, especially when critical servers come into play. Sean walks you through a litany of recovery methods, from leveraging third-party services to tackling zero-day exploits. As we broach the subject of regulatory repercussions following data breaches, the conversation turns to the art of remediation, the importance of patch management, and embedding a proactive security mindset throughout your corporate culture. With this episode, your data—and your trust—will never be more secure.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Embark on a journey to cybersecurity mastery as I, Sean Gerber, unveil the intricacies of security assessments and testing in the realm of CISSP. Guaranteeing a deeper comprehension of domain six, this episode meticulously dissects the objectives of evaluations, zeroing in on vulnerability detection and the verification of security measures. Imagine possessing the acumen to craft test data with utmost confidentiality, navigating the nuances of the audit process, and understanding the value external auditors bring to the table. Elevating your expertise beyond the CISSP exam, our dialogue stands as a beacon for those seeking to fortify their professional capabilities in information security.
As we traverse the ever-evolving cybersecurity landscape, I offer a robust arsenal of 15 practice questions to bolster your exam readiness, along with directing you to premier resources like CISSPcybertraining.com and FreeCISSPQuestions.com for an expanded array of challenges. These tools are designed not simply for passing an exam but for propelling your career forward, providing continuous opportunities for growth and advancement in the dynamic world of cybersecurity. With each query and explanation, we build a strong foundation, preparing you to excel as a Certified Information Systems Security Professional and emerge as a leader in the field.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are your organization's cybersecurity measures battle-tested against real threats? Let's unravel the complex tapestry of security assessments and audits together. As your host, Sean Gerber, I bring my red team experience to the forefront, dissecting the various layers of security evaluations that go far beyond simple box-ticking exercises. In this week's CISSP Cyber Training Podcast, we focus on the importance of rigorous, unbiased evaluations, not only to adhere to industry standards but also to solidify your company's defenses and uphold the trust of your clientele. Discover how internal, external, and third-party assessments each play a pivotal role in an organization's security strategy.
Ever wondered how an external perspective can transform your organization's security posture? I'll navigate you through designing a bulletproof assessment strategy, emphasizing the necessity of a methodical approach to spotlight and prioritize vulnerabilities. The episode peels back the curtain on various techniques and methodologies—from vulnerability scanning to security auditing—each vital in safeguarding your company's assets. By meticulously planning and documenting the assessment process, we ensure that every security measure aligns seamlessly with the overarching goals of your organization, and I'll show you precisely how to achieve that synergy.
Closing out, we tackle the crucial distinctions between security assessments and audits, and why audits are not simply reports gathering dust but are influential documents that command the attention of senior leadership. This episode not only primes you for the CISSP exam but also equips you with actionable insights necessary for making informed decisions post-audit. As a guiding light for your cybersecurity journey, I also highlight the treasure trove of resources available at CISSPcybertraining.com to bolster your exam preparation and practical knowledge. Stay sharp and join me for a deep dive into the world of security assessments and auditing, where every detail matters.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets of effective account provisioning and maintenance with us, as we ensure you're equipped to face the cyber battleground head-on. This episode, tailored for aspiring CISSP aces and cybersecurity aficionados alike, promises a treasure trove of actionable insights on user authorization, a cornerstone of securing your digital realm. Sean Gerber leads the charge in this week's CISSP Cyber Training Podcast, dissecting the intricacies of account provisioning—because who wouldn't want to be the master of assigning just the right access levels for every role within an organization?
As we march through the cyber trenches, Sean dissects the onboarding and offboarding processes, spotlighting the implementation of the least privilege principle and the art of seamless account termination to shield against security breaches. But there's more than just locking down accounts; we're examining the profound impact of exit interviews and how they can defuse potential threats, especially from those not-so-happy campers leaving the company. Tune in for a session that's not just about prepping for the CISSP exam but fortifying your cybersecurity frontlines with expertise that could make all the difference.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Prepare to be armed with the knowledge to secure your digital fortress as we confront the ATLASEN Confluence Data Center and Server Template injection bug, a critical vulnerability that could undermine your cybersecurity defenses. With a severity level that's maxed out the scale, I'm here, Sean Gerber, to ensure you're not left exposed to CVE 2023 22527. Transitioning from defense to offense, we'll unpack CISSP's domain 5.5.1, delivering best practices for onboarding systems and provisioning user accounts - an essential strategy in an age where data breaches are as common as coffee breaks.
Empowering your workforce is just as critical as fortifying your systems. In this episode, we tackle the nuances of creating a security awareness training program that doesn't just tick boxes but transforms every employee into a vigilant guardian of your organization's assets. From discussing cybersecurity threats with the delicacy they deserve to equipping new IT staff with the armor of encryption and multi-factor authentication, we ensure that your team is your strongest asset - not your weakest link.
Lastly, let's talk about exits. The offboarding process is a minefield of potential security breaches, but it doesn't have to be. We'll explore how automated systems and credential management can be your allies in ensuring that once someone says goodbye, their access to your network does the same. And for those in the know, the importance of discreetly handling access removal for sensitive positions cannot be understated. So join me, and let's navigate the complexities of cybersecurity together, ensuring your organization remains a fortress amidst a sea of threats.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Get ready to fortify your cyber defenses and unwrap the complexities of internet protocols with me, Sean Gerber, in a week charged with cybersecurity insights. We’re dissecting the digital fabric of IPv4 and IPv6, from the nuances of subnetting to the stealthy signals of ICMP, ensuring you walk away with a fortified understanding of the cyber terrain. Don't miss the pivotal segment where I unravel the CIDR notation—a cornerstone concept for network professionals—and how recognizing a Class C address, such as 192.168.1.1, can be the key to differentiating your network strategy.
As the shadow of ransomware looms over our critical infrastructure, I delve into the harrowing onslaught of attacks plaguing wastewater treatment facilities, bringing to light the urgent call for cyber vigilance. Discover the significance of link-local addresses and the potential pitfalls of rogue IPv6 devices in your network. The world of cybersecurity is a battleground, and this episode is your armory—equip yourself with the knowledge to lead the charge against the digital threats of today and tomorrow.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wondered how the invisible threads of the internet hold together the vast tapestry of global communication? Join me, Sean Gerber, as we unravel the mystique behind internet protocols, where the transition from IPv4's limited landscape to IPv6's boundless horizons marks a revolution in digital connectivity. Illuminating the depths of IP classes, address schemes, and the critical importance of understanding these concepts, we equip you with the essential know-how to navigate the cybersecurity realm with confidence.
The digital era's Achilles' heel—cybersecurity—is laid bare as we dissect the harrowing Mega Breach Database incident, a stark reminder of our shared vulnerability in this interconnected world. Together, we shed light on the armor of password management and the shield of multi-factor authentication, forging strategies to fortify our defenses against cyber threats. By imparting this knowledge to peers and loved ones, we join forces in the ongoing battle to secure cyberspace for generations to come.
As we chart the course toward the coveted CISSP certification, grasp the significance of every concept, from ARP tables to potential vulnerabilities lying in ambush for the unwary. This episode isn't just about passing an exam; it's about instilling a foundation of cybersecurity comprehension that stands firm against the tides of technological advancement. Whether you're setting foot on the path of a cybersecurity career or already marching through the ranks, this journey through the landscape of cyber defense is tailored to keep you one step ahead.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the mysteries of modern cryptography and quantum computing's future impact on security protocols with your guide, Sean Gerber. Our CISSP Cyber Training Podcast takes you through an intricate journey, ensuring you're armed with the expertise needed to conquer the CISSP exam and remain ahead in the ever-evolving landscape of cybersecurity. We promise to transform your understanding of cryptographic concepts, from the supremacy of AES in symmetric encryption to the vulnerabilities plaguing older algorithms like MD5 and DES. Prepare to grasp the significance of ECC for devices with limited resources, and the pivotal roles of RSA and hashing algorithms in maintaining the integrity and authenticity of digital communications.
Step up your career with the guidance and insight offered in our dedicated mentoring program chapter, a treasure trove for those navigating the complex paths of cybersecurity. Through CISSPcybertraining.com, we celebrate real success stories—like the one who aced the CISSP exam on their first attempt—attributing triumphs to the tailored mentoring and coaching strategies drawn from years of security experience. You'll get exclusive access to comprehensive CISSP training resources and one-on-one conversations with me, all designed to steer you towards a successful and fulfilling cybersecurity career. Embrace this episode as your beacon to a quantum-safe future and a robust understanding of digital security's best practices.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the latest CISSP exam insights and elevate your grasp on the cryptographic landscape with your host, Sean Gerber. Wichita's thawing frost mirrors the CISSP exam's refreshing changes, and we've got the scoop you need to stay on track. Rob Witcher joins in to dissect domain weight adjustments and new focal points in risk management and security architecture. With an eye towards the updated exam format, we assure you that these shifts are no cause for alarm but rather an opportunity to fine-tune your study strategy.
Wander with us through the enigmatic realm of cryptography as we clarify its integral role in securing digital communications. Our conversation illuminates the complexities of encryption algorithms, the pivotal distinction between symmetric and asymmetric key cryptography, and the non-negotiable imperative of protecting private keys. We draw relatable analogies to make these intricate concepts resonate, ensuring you're well-equipped to manage the cryptographic challenges you'll face in cyberspace.
Celebrating the transformative journey towards CISSP certification, we spotlight CISSP Cyber Training's contributions to your arsenal of security knowledge. As you gear up for the CISSP exam, remember it's not just about earning a credential—it's about fortifying a knowledge base for a thriving career in cybersecurity. With future episodes on the horizon, check out CISSPCybertraining.com to reinforce your expertise and stay ahead of the curve in this dynamic field.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Is your organization's cybersecurity teetering on the edge with outdated technology? Find out how to fortify your defenses as I, Sean Gerber, navigate the treacherous landscape of end-of-life (EOL) and end-of-service (EOS) assets in the latest CISSP Cyber Training Podcast episode. We explore the harsh realities of increased vulnerabilities and compliance challenges that come with clinging to aging systems. Say goodbye to the misplaced hope of squeezing performance from obsolete technologies and hello to practical strategies for managing the inevitable twilight of critical systems. Listen in for a comprehensive breakdown of manufacturers' end-of-support announcements, secure data disposal, and risk prioritization that keeps your organization both secure and cost-effective.
Venturing further, we tackle the importance of crafting personalized plans for technology EOL and EOS, transcending beyond the vendor-driven advice that's all too common in the industry. As your guide, I stress the significance of self-sufficiency in asset reviews and support strategies, ensuring decisions are uniquely suited to your organization's needs. For those hungering for more than just a taste of cybersecurity expertise or aiming to conquer the CISSP certification landscape, CISSPcybertraining.com stands ready with a treasure trove of resources. Join us on this journey of enlightenment and leave equipped with actionable insights to outmaneuver the ticking time bomb of technological obsolescence.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to bulletproof your business against cyber threats that never take a day off? This week, Sean Gerber steers you through the murky waters of cybersecurity for small and medium-sized businesses, with a treasure trove of wisdom on asset management and the art of gracefully retiring your tech relics. We're not just talking about keeping the digital lights on—we're talking full-fledged, fail-proof fortresses.
Ever wondered what happens when the 'Billy Bobs' maintaining our legacy systems ride into the sunset of retirement? We're tackling the gritty reality of end-of-life assets, sharing war stories, and practical tips on preserving operational continuity amidst the technological twilight zone. With an approach that balances performance with risk management, you'll learn how to assess and prioritize your cybersecurity efforts like a pro, tailoring your organization's risk tolerance to the uncertain terrain of the cyber landscape.
But wait, there's more than just keeping the old gears grinding! We're crafting an asset retirement plan that's more Iron Man suit upgrade than 401k portfolio. From seamless transitions to savvy extended support strategies, you'll discover how to navigate the endgame of tech asset life cycles. And for those sharpening their blades for the CISSP exam battlefield, we've got a strategic blueprint to help you emerge victorious. Tune in, fortify your digital dominion, and join me, Sean Gerber, as we turn cybersecurity challenges into triumphs.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are cyber attacks and data breaches keeping you up at night? You're not alone, and today's episode is your ally in conquering the CISSP exam and upping your cybersecurity game. Sean Gerber is here to dissect the looming shortage of cybersecurity professionals and the power of soft skills that go beyond the technical expertise. With an anticipated gap of 5.5 million roles by 2024, Sean discusses the necessity of growing our cybersecurity workforce and the critical role certifications like CISSP play in this expansion. He also highlights the importance of upskilling and resources from CISA and ISC² that are instrumental in nurturing your journey from novice to expert.
When customer data faces the abyss of a breach, especially on foreign cloud servers, knowing the next move is crucial. This episode walks you through the steps to take, stressing the importance of swift reporting to your cloud service provider and examining robust alternatives to hardware tokens for multi-factor authentication. Sean's pragmatic advice doesn't stop there; he explores the fine line between collaboration and confrontation with vendors in the event of a data breach, offering strategies to balance security imperatives with maintaining business relationships.
We round off with an exploration of the intricate dance between cloud service risks and international compliance. Sean imparts wisdom on encryption, contractual safeguards, and security testing to navigate the patchwork of global data privacy laws. The conversation shifts to practical tips for adapting security frameworks in light of new international treaties, ensuring your incident response procedures are treaty-compliant. For listeners passionately pursuing CISSP certification, Sean reiterates the mission of CISPCybertraining.com to guide and support you every step of the way. Tune in for a deep dive into the cybersecurity landscape, where Sean equips you with the know-how to face the digital challenges of our time.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Cybersecurity isn't just about technology; it's a battleground where legal expertise and international laws become as crucial as firewalls and encryption. Brace yourself as we navigate the tumultuous waters of cyber attacks, from the shocking breaches in Kansas and Australia to the alarming targeting of US infrastructure by Iranian hackers. Our conversation isn't just a rundown of threats; it's an essential guide through the labyrinth of legal consequences for those at the keyboard's dark side, the life-altering dangers of 'swatting', and the pivotal role legal teams play when digital walls are breached. If you've ever wondered about the balance between sharing information and protecting an organization's reputation during a crisis, this episode lays it bare with the precision of a scalpel.
Transparency and privacy—two sides of the same coin that can make or break trust in this digital era. We explore the intricate dance between these two forces within the context of a 12-week year strategy that reshapes how cybersecurity goals are pursued. You'll get insider tactics on breach notification, navigating the choppy seas of transborder data flows, and adhering to a mélange of international privacy laws. For those who hold the keys to sensitive data, we dissect the importance of data classification and the ethical impetus to uphold privacy, all while ensuring that the data complies with the variegated tapestry of global regulations from GDPR to CCPA.
As we gear up to close the curtain on this episode, we shift our focus to empowering cybersecurity professionals with the knowledge and skills to not just pass the CISSP exam, but to thrive in their careers. Whether through self-study programs or the personalized touch of one-on-one training options, cybertraining.com stands ready to equip you for the challenges that lie ahead. Join us on this journey to fortify our defenses against the cyber threats lurking in the shadows, ensuring that our digital future is secured by the best in the business.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the secrets to conquering the CISSP exam as I, Sean Gerber, take you by the hand in our powerhouse 102nd episode, guiding you through the labyrinth of cybersecurity knowledge. Imagine stepping into the exam room equipped with the ultimate blueprint, the same one that has become the hallmark of success for our students. It’s holiday season and we’re serving up a festive feast of CISSP insights, sprinkled with a preview of the upcoming changes to the CISSP exam slated for April 2024.
This episode is not just about celebration but also preparation, as I tease out thought-provoking exam questions that will fine-tune your understanding of what lies ahead. We’ll resume our domain-by-domain mastery sessions post-new year, but for now, let the spirit of learning be your guide through the discussion on incident response teams and secure software design. Whether you’re tuning in during your morning jog, the evening commute, or as the day unwinds, prepare to have your cybersecurity skills sharpened to a gleaming edge. Join us on this journey, and let's tackle the challenges of the security landscape, one question at a time.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wondered if those hefty CISSP certification costs could actually catapult your cybersecurity career to new financial heights? We crack the code on how balancing certification with real-world experience and the right job role can significantly impact your earning potential. Our latest conversation takes a deep dive into the geographical salary differences for security professionals, shedding light on the variance between regions like the Asia Pacific and North America. But don't be fooled—while CISSP may sparkle with promise, it's your dedication to the craft that truly counts. Let's explore how this certification, blended with seasoned expertise, can serve as a robust foundation for a thriving career in cybersecurity.
Prepare to be enlightened by the tales of trials and triumphs in the journey to CISSP certification. I get personal, recounting the struggles with the rigorous exam—a testament to the importance of a strategic study plan. We dissect the prerequisites, the broad spectrum of knowledge it encompasses, and the 'sweat equity' required to master topics from security management to regulatory compliance. It's not just about passing the test; it's about gaining a wide range of skills that enrich both your professional capabilities and perspectives. So buckle up and join us for an episode that promises to arm you with the insights needed to navigate the complex path to CISSP certification and beyond.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you prepared to level up your cybersecurity expertise and ace the CISSP exam? That's exactly what we're here for! I'm Sean Gerber, and this episode of the CISSP Cyber Training Podcast is a treasure trove of knowledge, from unraveling the intricacies of the STRIDE methodology to understanding the subtleties of 'repudiation' versus 'replication'. Get ready to delve into the depths of the Mandatory Access Control model and discover why 'Top Secret' isn't just a phrase out of a spy novel. We'll also decode the critical role of data classification for compliance, and I'll shine a spotlight on the nuanced differences between stateful and stateless firewalls that could make or break your security policy.
But the learning doesn't stop there. I'll take you behind the scenes of conducting a thorough Business Impact Analysis, illustrating its undeniable importance in maintaining operational integrity in the face of threats like a ransomware epidemic. As we explore the art of calculating downtime impacts and the construction of robust recovery strategies, you'll gain invaluable insights that will not only prep you for the CISSP exam but also fortify your organization's risk mitigation framework. And for those fascinated by the covert operations of cybersecurity, I reveal the secret weapon of Perfect Forward Secrecy in VPNs – a must-have for any security-conscious network. Join me in this podcast chapter where we unpack these topics with precision, leaving you enriched and exam-ready.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Unlock the true potential of your cybersecurity career with insights on how CISSP certification can amplify your earning power—beyond just a fancy title. As your guide, Sean Gerber, I'm taking you through a deep dive into the world of cybersecurity salaries, where your locale plays as big a role as your skills. From the bustling markets of Asia Pacific to the economic hubs in North America, we're mapping out the financial landscape and the real impact of cost of living on what you pocket. You'll learn why it's not just about having that CISSP badge, but also the years of experience you bring to the table that define your paycheck in roles across the spectrum, from security analysts to the coveted seat of a CISO.
Brace yourselves for an honest take on the CISSP journey, with the hard truths about the challenging pass rates and the significant investment of both time and money needed. Sharing from my own trials and tribulations with the exam, I shed light on the relentless preparation needed to conquer this beast and the strategic moves to make it worthwhile. But it's not all about the grind—this episode also highlights how this sought-after certification can unlock doors, bringing moonlighting opportunities into your grasp and adding a competitive edge to your resume. Join me as we unpack the rewards that come with the CISSP's demanding pursuit, and the professional growth that justifies your "sweat equity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you prepared to crack the code on API security and sail through your CISSP exam? If yes, then embark on this enlightening journey with me, Sean Gerber, as we decipher the intricacies of API and REST API security. We’ll tackle questions about securing API keys, delve into the pivotal function of an API gateway, and demystify common API security threats. You’ll also get a grip on the role of OAuth 2.0 and input validation in protecting APIs.
Hold on to your seats as we traverse the digital landscape, picking up REST API security best practices along the way. We’ll delve into the gravity of TLS and SSL, and shed light on the significance of OAuth 2 in RESTful APIs. You'll gain insights on secure API design and learn about data masking, the principle of least privilege, and secure endpoint design. But that's not all - we'll discuss API logging and how an API gateway can beef up security in a microservices architecture. We’ll round off with a sprinkle of career counseling to guide you in your cybersecurity journey. Tune in, soak up the knowledge, and let's ace that CISSP exam together!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you ready to unlock the secrets of API security? Prepare to be enlightened, as we tackle the burning issue of cybersecurity, with a special focus on recent hacker attacks targeting US water treatment facilities. Join us in a critical dialogue on fortifying our defenses and the role of cybersecurity education in our communities. Learn how to navigate the complexities of API security, from managing authentication to role-based access and the handling of tokens and API keys.
Brace yourselves for a grand tour of the API ecosystem, where we demystify API gateways and their pivotal role in enhancing security. Discover the intricacies of managing authorized connections, safeguarding against denial of service attacks, and navigating the risks of exposing cloud infrastructure to the internet. We also delve into the importance of robust API usage policies and discuss the pros and cons of IP whitelisting and blacklisting.
To put a cap on our security pilgrimage, we journey into the realm of API security testing practices. Familiarize yourself with various testing methods, the importance of keeping abreast with evolving threats, and the balance of security and functionality. Plus, for those of you preparing for the CISSP exam, we share a wealth of resources to aid in your success. So, gear up for an enriching experience that is sure to bolster your cybersecurity knowledge and equip you to ace the CISSP exam!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to become a CISSP expert? With this episode, we're going to decode the complex subject of CISSP domain 7.5 - protection of media types, as we sail through its tricky waters. A special highlight of this week's episode is the CISSP Question Thursday segment, featuring targeted questions designed to sharpen your skills and make your CISSP exam prep a walk in the park. You'll also get an insider's view of how a study blueprint can be your compass, guiding you towards your CISSP exam success.
Hear firsthand accounts from past learners who achieved their CISSP goals by following this strategy. The episode doesn't stop at the blueprint though. We'll also delve into secure practices for offsite media storage and why you should not be storing all backups in one location. So join me, Sean Gerber, on this enriching exploration of media types, and let's ace this exam together!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
You know how critical resource management is to protect your organization's media, but do you fully understand how to implement it effectively? We're here to ensure you do. In our latest CISSP Cyber Training Podcast episode, we shine a light on the recent ransomware attack that hit 60 US credit unions, exposing severe vulnerabilities in the supply chain. We discuss the significance of physical security measures, especially during investigations, and various forms of physical media including CDs, DVDs, and USB drives.
What if there was a foolproof way to ensure the safe transportation and storage of data backup devices? We delve into the importance of encryption, potential risks of theft, and the necessity of regular maintenance. Get to grips with the different phases of media management, from acquisition to disposal, and discover why compliance with laws, regulations, and industry standards is non-negotiable. We also share an inspiring success story of a diligent listener who aced the CISSP exam by following our training blueprint to the letter. Tune in, stick to the plan, and set yourself on the path to CISSP exam success.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to unlock the secrets of cybersecurity and ace that CISSP exam? Strap in as we delve into the intriguing realm of ISO 27001 standards, exploring their critical role in safeguarding key infrastructure such as our municipal water facilities. Learn how to assess, comply with, and improve upon these standards, and get a sneak peak at potential exam questions you'll find on our website.
But it doesn't stop there. We're pushing the envelope further by integrating cloud security assessments into your testing strategies. Get to grips with your cloud service provider's security policies and controls, and understand why legal and regulatory compliance is non-negotiable. Discover valuable tools like Nessus for vulnerability assessments and the importance of black box tests on new web applications. We'll also discuss the crucial role of account management audits and management reviews in ensuring your security policies are not just effective, but adhered to. Stay tuned for a fascinating deep-dive into the world of cybersecurity!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wonder how safe your data really is in the cloud? Or what steps are necessary to ensure your organization's compliance with critical cybersecurity standards? You won't want to miss our latest episode where we tackle these tough questions head-on, promising to leave you more informed and prepared to safeguard your organization's valuable digital assets. We dive into the complexities of compliance assessments and audit strategies, exemplified by Japan's Space Agency's recent cyber attack. We also unpack the nuanced differences between internal and external audits, all while guiding you through the often confusing maze of legal and regulatory compliance.
In a world where cyber threats are an everyday reality, understanding how to identify vulnerabilities within your organization's systems has never been more crucial. We'll take you through the practicalities of penetration testing, and break down the differences between black box and white box tests. You'll learn how hackers use methodical, stealthy approaches to bypass your security measures, while gaining insights into how log reviews, synthetic transactions, and code testing can help bolster your defenses. Speaking of defenses, we'll also reveal why third-party involvement in website checkout processes can be a game-changer in preventing SQL injections and input flaws.
But, complexities don't end there. We also explore the perils of account management in the cloud - a topic that's indeed a double-edged sword. While the ease and accessibility of cloud services are undeniable, so are the risks. We delve into strategies for managing these risks, such as how to deal with unused or unremoved user accounts that can be easily exploited by malicious actors. We underline the importance of regular audits and management reviews, and the necessity to comply with third-party agreements and Service Level Agreements (SLAs), to ensure your cloud services are not just convenient, but secure. So, tune in to our latest episode, and take a step towards securing your digital assets like a pro.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wondered how to build a fortress around your digital estate? Well, you're about to add a host of techniques to your arsenal. I, Sean Gerber, will take you through an enlightening exploration of access control models, examining prominent types including discretionary, mandatory, role-based, and risk-based models. We'll unlock the secret behind hybrid access controls and their role in reinforcing security layers. Plus, we won't skip the practical side of things, we’ll dive deep into how to implement these controls in real-life scenarios like setting up access control lists in firewalls.
But that's just the beginning. I'll be your guide through the challenging CISSP Cyber Training, showing you how to utilize it to its fullest to ensure you're well-equipped for the CISSP exam. It's not just about passing the test, it's about gaining a robust understanding of cybersecurity. We'll wrap up our episode with a strong call to action. Don't just satiate your curiosity, make the leap and check out the CISSP Cyber Training. Get ready to redefine your cybersecurity skills and ace that CISSP exam!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
What happens when ransomware strikes a big corporation like Clorox? Imagine the chaos and the panic that ensues - not to mention, the significant impact on revenue and leadership. That’s where we kick off our conversation with Sean Gerber, who delves deep into the Clorox ransomware attack and why having a strong resiliency plan is imperative. We also shed light on the importance of authorization and discretionary access controls in maintaining organizational security.
We navigate the complex world of role-based access controls (RBAC), discussing how it can efficiently handle access permissions and even prevent fraud within an organization. But it’s not a bed of roses; role explosion and initial setup overhead are just a couple of issues when adopting RBAC. Moving forward, we unpack different types of access controls, their advantages, and challenges - think attribute-based, mandatory, and risk-based controls. You'll be surprised by their impact on enterprise security.
Wrapping up, our attention shifts towards CISSP cyber training and how it bolsters your chances of acing the CISSP exam. We share stories of triumph, tips, and tools to help you succeed. Whether you're a cybersecurity professional or just interested in staying one step ahead of cyber threats, this episode is bursting with insights and discussions that you simply can't ignore. So, forget your regular playlist; it's time to plug into some serious cyber talks!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you armed with the right strategies to handle a business-altering ransomware attack? How would you navigate the evolving landscape of cyber threats like the recent Boeing lock bit ransomware incident or the Maine move it debacle? Prepare to sink your teeth into these juicy cybersecurity happenings while also getting a breakdown of Google's new strategy on deleting files from inactive accounts.
Join us as we shift gears, focusing on CISSP exam questions, particularly the automated patch management system's nuances. We delve into the critical considerations, walk you through the options, and reveal the correct answers. We don't stop there; we also take a deep dive into effective patch management strategies, discussing automated compliance reporting, compatibility considerations, risk mitigation, and patch prioritization based on risk assessment. Ever thought of integrating vulnerability scanning with automated patch management tools? Well, we've got that covered too, with a bountiful discussion on the subject and a look at the most indicative metric of success for patch management programs.
Finally, we'll unpack ways of improving patch management and prioritizing patches. Root cause analysis, patch categorization, and designing a patch management process for mixed-system organizations all come under scrutiny. As we draw the curtains, we'll examine the CISSPCybertrainingcom program and demonstrate how taking the time to digest information can set you up for success in your CISSP exam. We promise a compelling conversation that will leave you well-equipped to tackle your cybersecurity challenges head-on.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to elevate your cybersecurity knowledge? Buckle up as we, your hosts, dig deep into the realm of security operations, focusing on the time-saving 80-20 rule. We're discussing how automation can handle 80% of benign events, leaving your SOC teams to tackle the crucial 20%. We also delve into the intriguing concept of detection as a code and the role of scalable business context in data ingestion.
How about understanding the essence of penetration testing and vulnerability scanning? We'll guide you through the diverse types of penetration tests - pre-deployment and post-engagement retesting. You'll get a handle on the criticality of both internal and external vulnerability scanning, as well as the need for an incident response plan to uncover unauthorized devices in your environment. That's not all! We'll explore how to leverage external resources for vulnerability scanning efficiently, highlighting threat intelligence services, vendor communication, and applicability assessments.
As we wind up, we'll share effective strategies for risk mitigation, emphasizing the need for documentation and risk-based decision-making in creating robust defense layers. You'll gain insights into the importance of service level agreements and proper management of expectations with service providers, verifying patches before deployment, and regular review of documentation. And because we believe in your growth, we cap it off with some essential tips for acing your CISSP exam and identifying top-notch content to excel in your cybersecurity role. This episode is packed full of expert insights and practical tips to help you step up your cybersecurity game!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to crack the code on runtimes and CPUs? Grab your gear and join our host, Sean Gerber, on this thrilling expedition of knowledge. We've got a jam-packed session lined up for you as we navigate through a series of 15 thought-provoking CISSP questions that will equip you with the insights needed to ace your CISSP exam. From dissecting the role of a process in a CPU, to shedding light on the intricacies of multi-threaded environments, we're turning every stone to ensure you leave nothing to chance.
Today we're going off the beaten path as we explore topics that range from the state of processes in a CPU, to system architecture and its suitability for processing tasks. You'll be at the edge of your seat as we unpack each question, delivering clear and succinct explanations of the correct answers. But it's not all about the answers, it's about understanding the journey that takes us there. That's why we're diving deep into the realms of various types of execution, system architectures, and process states. Are you ready to master the maze of CISSP? Let's go!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to decode the enigma of process states, execution types, and system architecture? We promise you'll walk away with a newfound understanding of how processes are initiated in a computer system in our latest episode. Discover the efficiency of modular application development and unravel how this foundational knowledge can fast-track your success in the CISSP exam and deepen your cybersecurity proficiency.
Moving on, we unpack the intricacies of process scheduling and the nuances of CPU utilization. Get a grip on the transformation of processes between user and privileged modes, and learn about process states in detail. We'll delve into the world of kernel mode, where we'll discuss its crucial role in the security of computer systems. We'll also discuss how memory management units are used to protect the kernel's memory space and the differences in the handling of user and kernel modes by Windows and Linux. This episode is a treasure trove of insights into process isolation and rings of protection in CPU security. Tune in to expand your knowledge horizon!Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Brace yourselves for an insightful journey into the omnipresent world of cybersecurity. We're cracking open the complexities of data classification, HIPAA, and child data protection. We'll also be taking a hard look at international regulations from the lens of Singapore, China, and the US healthcare sector. But who's really responsible for your data? And what happens if they fail to protect it?
As the gavel drops on Solar Winds in the wake of the SEC action, we dissect its implications for businesses and security professionals alike. We also tackle the repercussions of 40 countries pledging not to pay cybercrime ransoms. But we're not just about updates; we're about empowerment. Whether you're just dipping your toes into the cybersecurity pool or are a seasoned professional, we've got something for you. Navigating your career path, tips for building a killer resume, negotiating contracts like a boss, and strategies to boost your earning potential - it's all here. Come, expand your cybersecurity horizons with us!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wondered why there's such a massive gap in cyber skills, particularly in this era of economic slowdowns? As we juggle an increasing number of job roles, budget cuts, and layoffs, now is the time to polish off your cybersecurity skills. We tackle the Biden administration's latest push for knowledge on security gaps, the increasing insider threats, and the surprising dearth of AI skills in the industry.
Navigating the cybersecurity landscape has never been more crucial. We demystify the role of a data owner and the responsibilities it entails - data classification, setting access controls, and managing the data life cycle. The conversation doesn't stop there. We also delve into the roles of data controllers, processors, custodians, and administrators, all crucial players in data protection. We also take a deep dive into the NIST Cybersecurity Framework and its implications for these roles.
It's not all about the professionals. Users also play a pivotal role in data protection, and we shed light on the various responsibilities that come with it. We explore topics from authentication and authorization to awareness and training. We also touch on key regulations and laws that apply to data owners, custodians, and users. Wrapping up this insightful conversation, we discuss the significance of specialized cybersecurity coaching and mentorship programs. Whether you're a seasoned professional or a novice in the cybersecurity world, this episode promises to equip you with valuable insights to help you thrive. Tune in for a riveting exploration of the cybersecurity landscape.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Imagine a world where your private medical records are no longer private, where unscrupulous cybercriminals are ready to exploit your personal data for blackmail. That's the chilling reality we explore as we uncover an alarming trend of cybercriminals targeting plastic surgeons, highlighting the increasing importance of cybersecurity across diverse industries.
This episode also serves as a treasure chest of insights for those pursuing a CISSP certification. Grappling with complex legalities of contractual law, understanding cybersecurity legislation, and interpreting computer crime acts can be daunting. We aim to demystify these intricacies and navigate you through important CISSP topics. Hear about how coaching and mentoring can supercharge your CISSP journey and learn strategies for preparing impactful resumes and tackling interview questions effectively. Tune in and gear up to bolster your cybersecurity knowledge and career prospects.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Discover the world of CISSP Cyber Training in a thrilling exploration that unravels the complex web of cybersecurity legislation, contractual law, and computer crimes acts. We'll begin our journey by studying recent cybercrimes, with a focus on the Singapore government and the US pledge to fight scams through cross-border cooperation. With the alarming statistic of scam losses in the US reaching around $10.3 billion last year, we aim to illuminate the critical importance of understanding these laws for your CISSP exam.
Intrigued about how various laws affect the protection of intellectual property? We've got you covered. We'll decipher the intricacies of civil, criminal, administrative and contractual law, and their implications on protecting trademarks, patents, and trade secrets. You'll be privy to in-depth conversations about working with attorneys when drafting contracts, and understand the legal recourse available if a vendor misplaces information. We'll also guide you through the steps to tackle issues such as domain name scams.
But that's not all. We venture into computer crime laws and their implications, focusing on the Computer Fraud and Abuse Act (CFA) and the Electronic Communications Privacy Act (ECPA). We'll examine the Electronic Funds Transfer Act of 1978, the Stored Communications Act, and discuss their impact on privacy and legal considerations related to accessing or disclosing electronic data. We'll also probe the Data Protection Act in the UK and the Identity Theft and Assumption Deterrence Act. To top it off, we have a unique segment on career coaching for CISSP Cyber Training. We'll share with you, invaluable tips on acing the CISSP exam, crafting compelling resumes and acing interviews. So, get ready to embark on a thrilling journey that will equip you with the essential training to excel in your cybersecurity career!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Do you consider change management as a lifeline for your organization? Or are you aware of the magic a 'get out of jail free card’ can cast in legal situations? Buckle up, because this episode of CISSP Cyber Training Podcast is going to take you on a journey where you'll learn to balance these and more. We kick off with an analysis of the latest Patch Tuesday updates, and discuss how you can streamline risk valuation and change management processes to shield your organization from zero-day vulnerabilities. You'll discover how tools like Skype for Business and WordPad can be secured, and the significance of setting up systems for automatic updates.
Then, we pivot to the realm of planning and authorization in cyber training, highlighting the indispensable role of a 'get out of jail free card' when running penetration tests. We focus on helping you sidestep potential legal roadblocks and smoothly drive your cybersecurity efforts. To help you excel in the CISSP exam, we also dissect several exam questions, offering deep insights into domains such as risk management, incident response, data classification, and encryption methods. This podcast is not just about acing an exam; it's about empowering you with a wide array of cybersecurity knowledge. Brace yourself for an enriching encounter.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Promise to learn and a personal story: "You're about to unlock the complexities of cybersecurity and the CISSP certification, a sought-after credential in our industry. Walking you through this journey is me, your host Sean Gerber, sharing my two-decade-long adventure navigating the ever-evolving landscape of cyber warfare."
Painting a vivid picture of the cybersecurity landscape, we delve into the increasing involvement of hacktivists in geopolitical conflicts. We dissect the industry roles from Information Security Analysts, security consultants to Chief Information Security Officers, outlining their duties and scopes. The pivotal role of CISSP certification, its extensive security topics and best practices is explored in-depth to equip you with the knowledge needed to ace it. It's a dynamic, fast-paced episode that leaves no stone unturned - we've got everything from the technical aspects of security systems engineering to the skills required to be a successful security architect. Brace yourself for a deep dive into the world of cybersecurity, a journey that promises to be as enlightening as it is exciting.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Can you decipher the jargon of cybersecurity and ace the CISSP exam? Get ready to take notes as host Sean Gerber, a maestro of cybersecurity, breaks down the baffling world of libraries, ides, compilers, and object-oriented programming. With an emphasis on mastering the CISSP exam, Sean meticulously dissects complex concepts and questions, focusing on domain 8.1, and delivers a comprehensive understanding of the management thought process behind it.
This week, we're peeling back the layers of cybersecurity! Sean expertly navigates topics such as inheritance in object-oriented programming, the cardinal role of redundancy in avoiding system failures, and the significance of assurance levels. Delve into the intricate world of secure authentication and session management for web applications, and discover what critical elements to prioritize. Plus, learn the ins and outs of error handling, and how polymorphism, cohesion, and coupling are vital in object-oriented application development. This episode is a must-listen if you're preparing for the CISSP exam or looking to expand your cybersecurity knowledge!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to level up your cybersecurity knowledge and coding prowess? We promise to elevate your understanding of CISSP development and libraries, as we venture into the world of code collections. Get a firm grip on the different types of libraries, from standard to custom, and learn about the potential dangers associated with cryptographic libraries. We also delve into the intriguing world of language-specific libraries and the pivotal role of packaging in the development realm.
We then shift gears towards the dynamic field of development tools. From the nitty-gritty of integrated development environments to the intricacies of chat GPTs, we discuss their pros and cons, and the significance of understanding the code. Get a closer look at compilers and version control systems, your crucial allies for translating and tracking changes in source code. Finally, we tackle the key concepts of Object-Oriented Programming (OOP), their practical implications in cybersecurity, and the power of encryption algorithms. So buckle up and prepare to enter a world of code, cybersecurity, and essential development tools.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to conquer the CISSP exam? Let's take a deep dive into the world of cybersecurity operations, breaking down complex concepts into easy-to-understand explanations. We'll explore how 'need to know access,' 'least privilege,' 'separation of duties' are vital defenses in the cybersecurity landscape, offering insights from real-life scenarios like the pricey MGM hack and a critical flaw in Cisco routers. Get ready to challenge yourself with CISSP questions tied to domain seven, focusing on access granted based on job descriptions, least access required, separation of duties, two-person control, and the benefits of job rotation.
Looking to level up your security team's skills? Cross-training could be the golden ticket. We'll narrow down how cross-training embeds versatility into your team, enabling them to deal with a diverse set of roles and smoothly execute two-person control. We'll also touch on why earning a CISSP certification can be a game-changer for your career, and share the exhilaration of acing the exam. We'll also tackle 15 vital CISSP questions, offering comprehensive answers and explanations to enrich your understanding. Pop in those earbuds, and let's boost your cybersecurity prowess and CISSP exam readiness!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Do you really know who has access to your sensitive data? Let's unravel the veil of cybersecurity, highlighting a ransomware incident that cost Caesar's and MGM a staggering $15 million. Tune in as we explore CISSP domain 7.4 and the critical need-to-know principle that insists on access to sensitive data only for those who genuinely need it. We'll also touch on the invaluable resources available on CISSP Cyber Training that can aid in your exam preparation.
In this fascinating dialogue, we venture into the world of zero trust architecture, least privilege principles, and identity and access management. We reveal how these strategies can fortify your company's network. We'll also discuss GRC, an essential part of SAP that assists in managing user access and the division of duties. We walk you through the financial industry's use of instant approval for high-level transactions and the concept of just-in-time privileges.
Ever wondered about the risks of granting too much privilege? We'll break it down for you. We'll also shed light on the role of a managed service provider during a security incident and the importance of using pre-set, securely stored credentials. Learn about situations where temporary privilege elevation becomes vital, such as software patch installation, data migration, and compliance auditing. And let's not forget about time-bound access, multi-factor authentication, and separation of duties. So, strap in and prepare to arm yourself with vital cybersecurity knowledge.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ready to step deep into the trenches of cyber security? This episode promises a riveting examination of pertinent cyber security concepts, backed by real-life case studies. First up: a chilling real-world scenario of a Nigerian individual making waves in the news for their involvement in a multi-million dollar business email compromise scheme - an in-depth look at this will make you rethink your transactions! In addition, we shed light on the nitty-gritty of disaster recovery concepts and the invaluable role of a positive control path when transferring money between companies.
Buckle up as we take flight to the intersection of aviation and cybersecurity. Borrowing lessons from aviation debriefing, we delve into how potential issues can be identified and rectified when it comes to cyber threats. We also offer a critical examination of Business Impact Analysis and various data backup systems, aiming to help you arm your organization against potential cyber threats. Whether you're preparing for the CISSP exam or simply looking to fortify your knowledge in the cyber space, this episode is a rich trove of insights!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you armed with the knowledge to interpret the health of an organization's operations? Can you differentiate between performance indicators (KPIs), operational performance indicators (OPIs), and risk indicators (KRIs)? This episode of CISSP Cyber Training Podcast is your key to unlocking these concepts. We dissect the purpose and applications of these metrics, laying bare their role in assessing operational efficiency and effectiveness. Additionally, we emphasize the importance of a robust mobile device management strategy in protecting against the ever-evolving cyber threats.
Have you ever considered the vital role of the 3211 backup strategy in data protection? This episode unravels this strategy, highlighting the need for three separate copies of data, stored on two different media, with one stored offsite. We explore the concept of air-gapped or offline storage copy, and discuss the best practices for monitoring and auditing backup procedures.
Finally, we wander into the territory of backup and recovery training best practices. We explain why regularly scheduled backups, verification tasks, audit trails, role-based access control, and isolated environments for testing are all crucial. We touch on the significance of multi-location storage, policy review and updates, and training for IT staff. Wrapping up the tour, we briefly overview Disaster Recovery and Business Continuity standards and programs. Join us to stay informed and ahead of emerging threats with our educational and practical guide for cybersecurity professionals. This is your chance to dive into the world of cybersecurity with us. Let's get started!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Are you ready to unlock the secrets of cybersecurity? Buckle up as we journey into the intriguing world of CISSP Cyber Training. Imagine the shock when Microsoft AI researchers accidentally leaked up to 38 terabytes of data due to a slip-up in their Azure environment! We're diving deep into this incident, unpacking all its layers. But that's not all. We’re shedding light on the complexities of Multi-Factor Authentication (MFA) and the unique challenges of Single Sign-On (SSO). Plus, get ready to demystify the 'something you are' factor in biometrics and understand the real objective of identification - hard facts.
The journey continues as we navigate the tricky waters of machine learning and IoT devices. Ever wondered what happens when a machine learning algorithm sniffs out a phishing attempt? Or how dynamic policies keep the ship afloat in geofencing? We've got answers! We're cracking the code on pattern recognition algorithms in credential stuffing prevention, and taking a hard look at IoT device trustworthiness. But we're not stopping there. We'll wrap things up with a treasure chest of resources for CISSP Cyber Training - think YouTube channels, websites, and more. So, are you ready to level up your cybersecurity game? Your expedition into the exciting realm of cybersecurity starts here. Tune in, take notes, and transform your understanding of the digital world!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
How prepared are you for a ransomware attack? Buckle up as we navigate through a thrilling ride into the world of cybersecurity, drawing lessons from the recent ransomware attacks on Caesar's Palace and MGM casinos. We'll walk you through the importance of having a robust disaster recovery and business continuity plan, as evidenced by these high-profile breaches. But that's not all - we're also diving into the future of identity and access management, touching on exciting trends like blockchain, AI, and IoT.
Ever wondered how single sign-on and multi-factor authentication could be your secret weapon against security threats like password reuse? We're going to shine a spotlight on these protective measures and explore global data privacy laws such as GDPR, HIPAA, and PCI DSS. With the recent ransomware attacks, we'll discuss the potential compliance implications and the critical role of internal and external audits in identifying security gaps.
Finally, we'll delve into the transformative potential of AI and machine learning in boosting security. From facial recognition to voice recognition and blockchain, we're going to peel back the layers of these cutting-edge technologies. We'll also offer you a sneak peek into the world of CISSP Cybertraining and how it can be your ticket to cybersecurity mastery. So, don't miss this opportunity to embolden your cybersecurity knowledge and stay ahead of the curve.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Have you ever wondered what it takes to crack the CISSP exam? Dreamt of enhancing your cybersecurity expertise? Welcome to an action-packed episode that pulls back the curtain on your path to success. With a focus on CISSP questions and key testing strategies, this episode aims to make you a proficient test taker. We dig into intriguing topics like hypervisor technology, the CIA triad, encryption types, and the main role of CASBs. To spice things up, we also throw in the main security concern that plagues the utilization of cloud technology.
Now, let's journey through the vast realm of Cloud Computing. Understanding this is paramount for acing the CISSP exam, and we're here to guide you every step of the way. To make this journey exciting, we've lined up an array of CISSP questions that will help you grasp concepts like container orchestration platforms, the essence of elasticity and resource pooling, and the IAA model's intricacies. We also delve into data integrity within a SAS model, the phenomenon of cloud bursting, and the trials of managing cloud environments. So, buckle up as we navigate through this maze of knowledge, ensuring you're well-equipped to not just pass the CISSP exam but truly master it.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Eager to demystify the cloud environment and its cost-effectiveness compared to an on-premise setup? Well, gear up, because today, we're taking you on an enlightening journey through the world of cloud networking. We will be tackling everything from cloud security and its various models to the critical role of cloud security posture management (CSPM) in AWS deployment. So, whether you're a budding IT professional or an established one looking to enhance your CISSP knowledge and expertise, this episode has something for you.
Ever wondered how security groups, network ACLs, platform as a service, and software as a service work in tandem to uphold cloud security? Or perhaps, you've been intrigued by the utilization of VLANs and traffic shaping for prioritization and quality of service. Well, curiosity ends here as we uncover these topics and more. And we'll also be spilling the beans on cloud access security brokers (CASBs), the pros of data loss prevention, tokenization, and the different types of cloud storage. Rest assured, by the end of the conversation, your understanding of cloud storage technologies and security will be second to none.
In the grand finale of the episode, we unravel the secrets of cloud connectivity and the costs associated with it. We'll enlighten you on the importance of service endpoints, routing tables, and DNS resolution. Plus, we'll share a real-world use case of a public service endpoint. And of course, we touch upon the role of CSPM in maintaining a secure AWS deployment. So, buckle up and get ready to be armed with the knowledge and expertise that can take your CISSP skills to the next level.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Ever wonder how safe your passwords really are? Brace yourself as we unravel the shocking details of the LastPass breach from August 2020, where countless customer credentials were stolen. We'll expose the vulnerabilities that allowed this to happen and advise on the necessary steps to preserve your digital security. You'll gain insights into reliable security measures, like the Harrison-Ruzel-Ohlmann model and Trusted Computing Base, and grasp how they can prevent data degradation.
Prepare to step into the intriguing world of unauthorized information flows. Our discussion aims to spotlight these silent threats and arm you with the knowledge to prevent them. We'll navigate through the complex maze of the Bell Laploula, BIBA, HRU, and Noninterference models, helping you understand their role in securing information. And if you're studying for the CISSP exam, you'll find our coverage of 20 questions on these topics an invaluable resource. Don't forget to check out CISSPcybertraining.com for more free CISSP questions, videos, and audio files. Join us for an episode that is more than just a conversation - it's a comprehensive guide to cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Bold Statement: "Your company's security depends on more than just your own vigilance. It also hinges heavily on third parties. In today's episode, we tackle that reality head-on, using a case study of a Windows 7 PC from a high-security fencing company that was hacked to infiltrate sensitive military and research sites. This real-life example serves as a stark reminder of the need for constant assessment and monitoring of third parties to safeguard your firm. Additionally, we shed light on the trusted computing base and its key components like the system kernel and hardware, the security kernel, and mandatory access controls, which are all essential in fortifying your environment against threats.
Tantalizing Teaser: "Trust us, you won't want to miss our deep-dive into trusted computing for data integrity and security. We lay bare the distinctions between TPM and HSM and illustrate how the trusted computing base (TCB) can be harnessed to craft a robust multi-level security system. We also illuminate the TCB's applications for financial systems, device identification and verification, and the Internet of Things. Towards the end, we unravel the HRU Model for Access Control, breaking down its components, outlining its practical applications, and discussing its limitations. This episode is designed to demystify complex cybersecurity concepts, so tune in and prepare to ace the CISSP exam.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 60 FREE CISSP Practice Questions each and every month for the next 6 months by going to FreeCISSPQuestions.com and sign-up to join the team for Free. That is 360 FREE questions to help you study and pass the CISSP Certification. Join Today!
Imagine a world where a simple radio command halts an entire railway system. That's exactly what happened in Poland recently, and we're here to break down the intricate details of this cyber-attack. We'll reveal how the Polish radio stop command system was exploited, unraveling the mystery behind this major disruption. From there, we'll navigate the tricky waters of personal identifiable information (PII), data destruction, and data sovereignty, arming you with insights and strategies to protect your data. Ready to ace your CISSP exam? We've got your back with a series of exam-style questions and discussions around critical topics like data encryption and degausing a tape.
Switching gears, we'll venture into the realm of CCPA Compliance and data security. If you've been wondering how to determine the scope of consumer data, or puzzled over the features of GDPR, fret no more as we demystify these concepts. And let's not forget about the importance of secure data transmission, especially when dealing with financial data. We dive into the best practices for transmitting sensitive data, address API security, and explore secure data destruction methods. To cap off the episode, we'll tackle data scraping and the perils of unauthorized data collection. So, buckle up for an exhilarating ride through the landscape of cybersecurity!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to decode the mystery of AI in digital forensics? I'm your host, Sean Gerber, and in this stimulating conversation, we're peeling back the layers on how AI is revolutionizing the digital forensics landscape. From automating log analysis and malware detection to reshaping image and video analysis, we're talking about it all. So, buckle up as we navigate the potential legal implications of this rapid technological evolution.
Dive deeper into the tangled web of data protection and classification in the second part of this riveting episode. We'll guide you through the labyrinth of laws, such as Sarbanes Oxley and PCI DSS, that govern personal identifiable information (PII), intellectual property (IP), financial data, and health records. Learn the ropes of securing your data via encryption, access controls, and periodic audits. Let's get ready to demystify the laws and methods that protect your digital footprint.
Finally, prepare to be fascinated as we explore the complexities of health data storage, compliance requirements, data mapping, and destruction methods. We'll shine a light on regulations like SEC, FFIEC, NERC and how they relate to the CISP exam. We'll also discuss data sovereignty, jurisdictional risks and the pros and cons of physical data centers versus cloud storage. We're arming you with knowledge to navigate the increasingly complex world of data destruction, from physical methods to electronic ones like secure race and cryptographic shredding. Now, let's set sail on this voyage of cyber discovery!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Take a journey into the heart of cybersecurity with us as we unravel Gmail's latest recommendation for multi-factor authentication. Can you guess the three key aspects they propose for heightened security? Stay tuned as we also tackle a pertinent CISSP question on security governance, illuminating the primary purpose of an organization's security governance program. Learn how a balanced scorecard can effortlessly align security controls with business goals, pivotal to any security governance strategy.
Ever wondered about the fundamental principles of security frameworks like SABSA and COVID? We've got you covered. Hear interesting insights about the COSO framework and its prime focus, along with a deep dive into the Risk Matrix Framework (RMF). We also present an intriguing scenario where a financial giant's CEO pushes for rapid technology adoption. Plus, get a dose of reality about the critical importance of investing in cybersecurity training and the potential costs involved. Before we wrap up, we emphasize the value of a robust cybersecurity plan. So, are you ready to fortify your cybersecurity knowledge?
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to fortify your organizational security? We promise to equip you with a deeper understanding of security governance principles - the backbone of any effective information security program. We highlight the pressing need for strategies that align with the mission and vision of the organization, especially in the face of the growing threat of ransomware attacks. We dissect a recent news piece that underscores the importance of safeguarding critical infrastructure. But that's not all, we also reveal the resources that'll help you ace the CISSP certification exam.
Imagine having the power to create a foolproof USB policy. We guide you through the process of crafting a classification schema, handling procedures for each classification level, and constructing an impactful security awareness program. Get the inside scoop on why specialized training for your security personnel could be a game-changer. We touch upon the necessity of consistent feedback and evaluation mechanisms that can instigate continuous improvements in your security initiatives.
Change can be daunting, but what if we told you that embracing security control framework mapping could be transformative? We delve into the pros and cons of security control mapping, the challenges you might face, and the various methodologies at your disposal. We'll also share practical examples of mapping NIST to ISO and HIPAA to COVID to ensure compliance with varying regulations. Navigating GDPR and the ISO 27,000 framework needn't be a nightmare anymore. If you're gearing up for the CISSP test this September, you'll have our best wishes and a wealth of invaluable information.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to turbocharge your cybersecurity prowess? Then buckle up for a thrilling journey through the maze of software development methodologies - Agile, Waterfall, DevOps, Scrum, and Kanban. I, your tour guide Sean Gerber, will dissect each methodology, spotlighting their unique principles, benefits, and potential pitfalls. Get set to grasp the iterative pulse of Agile, the rigid skeleton of the Waterfall model, and the risk-focused heart of the Spiral model.
We're not just about theory - we're about practical insights too. So, listen in as we traverse the symbiotic evolution of software and business documents in Agile, and the art of limiting work-in-progress in Kanban. We're spicing things up with a sprinkle of CISSP exam questions to ensure you're armed and ready for your certification. Embrace the principles of DevOps, the merits of Scrum over traditional methods and the core attributes of the Spiral model. This is a must-listen for anyone eager to elevate their understanding of software development methodologies and skyrocket their cybersecurity career!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you ready to navigate the maze of software development methodologies and their security implications? Well, that's exactly what we're about to do! We're unpacking everything from the waterfall development model, with its linear steps, to the agile model's flexible and adaptable nature, perfect for managing complex projects in an evolving landscape of threats and challenges.
In this captivating cyber training episode, we also dissect the scrum methodology, providing insights into the roles within a scrum team and the concept of 'shifting left' – a strategy to integrate security into the development process. We discuss the importance of the security professional's role, emphasizing the necessity of spearheading security efforts within an organization. Plus, we also examine the pros and cons of the scrum methodology and its role in agile development.
But we won't stop there. We're ushering in DevOps into the conversation, highlighting how its security implications can foster a culture of collaboration, automate tasks, and measure application performance. We'll also be venturing into the intricacies of the spiral development methodology, an approach used for larger, complex projects. And let's not forget about the kanban development method, a visually engaging approach to workflow management and bottleneck identification in security-related tasks. Buckle up, folks! We promise it's going to be a thrilling ride into the depths of cybersecurity knowledge.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever wonder which types of evidence are considered most reliable in court? Or why using a write blocker is crucial during a forensic analysis? Well, you're in for a treat! Join me, Sean Gerber, as we unravel the intricacies of the CISSP exam. We'll shed light on concepts like digital forensics, chain of custody, and the crucial role of data acquisition. Not just that, we'll also demystify the workings of a honeypot and its role in diverting attackers from critical systems.
But that's not all! We will step into the realm of CISSP Cyber Training, and provide you with tips and guidance that could be a game changer for your success. We'll walk through the formulation and execution of a well-structured plan, discussing three, four, and five-month plans specifically designed to keep you on track. So if you're feeling lost or overwhelmed with your exam prep, don't fret! Let's navigate the CISSP exam labyrinth together, armed with knowledge and a solid plan.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to demystify the world of digital evidence in cybersecurity? What if you could easily navigate the complex protocols that safeguard system logs, network logs, and files? This episode promises to enhance your understanding of digital evidence, and its undeniable fragility. We deep-dive into why maintaining the chain of custody matters and the key to ensuring the integrity of these critical pieces of information.
Ever thought about the art and science of digital forensics? We break it down, from data collection that leaves the original form untouched, to the vital role of analysis in reconstructing incidents. We share insights on creating comprehensive reports for all audiences, and the best practices for presenting findings to all relevant parties. Listen in as we guide you through the four key phases of digital forensics: acquisition, analysis, reporting, and presentation.
But that's not all. We also delve into the legal and ethical minefield of digital evidence collection. We dissect the Computer Fraud and Abuse Act, the Electronic Communications Privacy Act, Data Breach Notification Laws, and the importance of Chain of Custody. We expose how these considerations play out in real-world scenarios. Towards the end, we focus on the significance of digital evidence in CISSP domain seven, seven dot one, and offer free resources to help you ace your CISSP exam. Make sure you've got your pen and paper ready for this information-packed episode.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
What if you had the power to spot vulnerabilities before they become a major security threat? That's exactly what we are offering in this insightful episode of the CISSP Cyber Training Podcast. Your host, Sean Gerber, unzips the world of security assessments and testing, exploring the nuances of data confidentiality during the process. He delves into the role of external auditors and discusses why continuous improvement is the key to successful assessment processes.
For those of you gearing up for the CISSP exam, or if you're just seeking to expand your knowledge in cybersecurity, you're in for a treat. Sean shares invaluable tips on exam preparation, highlighting the free resources you can utilize. This episode isn't just about helping you pass the CISSP exam; it's about equipping you with the right tools to succeed in your cybersecurity career. Don't miss out on this highly informative episode, packed with the insights and strategies you need to stay ahead in the fast-evolving world of cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever feel like you're walking in a cyber labyrinth, trying to protect your data but unsure where the vulnerabilities lurk? Our latest CISSP Cyber Training Podcast is the compass you need. We dissect the essentials of security assessments and auditing strategies, illuminating how these risk-busting practices can fortify your systems, reassure your customers, and fulfill due diligence requirements. All of this while also priming you for the powerhouse CISSP exam!
Immerse yourself in our practical guide to developing a comprehensive assessment plan. From vulnerability scanning to penetration testing, and from security auditing to risk assessments, we navigate through the maze of methods to help you master the best fit for your needs. Understand the significance of meticulous planning and documentation, and the critical roles of the leaders in these assessments. Our conversation will empower you with the knowledge to ascertain objectives, scope, timeline, methods, tools, and techniques that shape a robust testing plan.
Our exploration doesn't stop there. We dive deeper into the realm of security assessment and testing validation strategies. We discuss why the right tool for the right job is not just an adage, but a game-changing practice. Grasp the importance of adhering to industry standards and regulatory requirements like ISO 27001, NIST, CIS benchmarks, and PCI DSS, and the impact of quality assurance and control. Also, find out why certified assessors are worth their weight in cyber gold. And finally, we bring you a wealth of resources for CISSP exam preparation! Tune in and transform your cyber strategy with our expert insights.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
What if you could confidently face the CISSP exam knowing you've got a strong grasp of crucial topics like SAML and Identity and Access Management? Join me, Sean Gerber, your guide through the maze of CISSP exam preparation, as I tackle a series of exam-related questions that will significantly bolster your study routine. Together, we'll unpack concepts like the primary purpose of SAML, OAuth2's main function, and the characteristics of multi-factor and biometric authentication.
Prepare to have your understanding deepened as we delve into the subtle differences between user authentication and user authorization. We'll dissect the concept of single sign-on, and separate the wheat from the chaff in terms of what constitutes biometric authentication. Whether you're an auditory learner or prefer to watch, don't worry - I've got you covered. You can also head to CISSP Cyber Training, where all these questions are available in video and audio format. So, gear up and let's step up your CISSP exam preparation!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever get tangled up in the complexities of identity and access management? Tired of letting confusion rob you of effective cybersecurity strategies? Well, it's time to tune in and simplify it all! As your resident cybersecurity expert, Sean Gerber, I'll be taking the reins in this exciting journey into the heart of identity and access management. We'll tackle the big three – identity management, federated identity management, and credential management systems. Believe me when I say, by the end, you'll be navigating these concepts like a pro!
Are you ready to discover the true value of identity and access management? We all know security is paramount, but have you considered the benefits to productivity, user experience, and cost savings? Let's uncover these hidden perks together! The aim isn't just to understand but to utilize this knowledge effectively. We'll discuss the crucial importance of timely user removal and how to tackle challenges head-on when the system breaks. The big bonus? We'll also dig into how IAM aids in meeting those pesky compliance requirements and how automating processes can really save you a penny or two.
No cybersecurity journey would be complete without a deep dive into SAML, OAuth2, and OpenID Connect. Sounds complicated? Not for long! I'll be your guide as we examine these protocols and their roles in transferring authentication and authorization data. By the end, you'll understand SAML assertions, OAuth2's tokens, and how OpenID Connect is built on top of OAuth2. And, because we believe in value beyond theory, we'll explore real-world examples too. But that's not all! Stick around as I share how you can access free CISSP questions online and why joining the CISSP cyber training community is a game-changer. So, are you ready to revolutionize your understanding of identity and access management? Let's rock and roll!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever wondered how to ace the CISSP Cyber exam's domain four? Or, perhaps, you're merely intrigued by the intricate world of Voiceover IP (VOIP)? Either way, this episode is packed with the insights you've been seeking! Join me, Sean Gerber, as we dissect the key protocols that VOIP uses for multimedia transmissions. Together, we'll unravel the complex intricacies of Session Initiation Protocol (SIP) messages and how sessions kick off in a VOIP implementation. You'll also gain an understanding of the differences between Real-Time Transport Protocol (RTP) and Real-Time Transport Control Protocol (RTCP) and how they're applied.
As we journey deeper into this episode, we'll explore the fascinating world of Internet Small Computer Systems Interface (iSCSI), focusing on its functions and default ports. Fear not, the mystery of SCSI command encapsulation will no longer be a mystery to you! We'll then shift our attention to the security aspects of SIP-based VOIP traffic, scrutinizing SIP-aware firewalls and the implementation of Transport Layer Security (TLS). Finally, we'll round off our discussion by examining RTCP's role in providing quality of service feedback in a VOIP implementation and wrapping up with an understanding of block-level transport in iSCSI. Prepare to expand your cybersecurity knowledge in a way you never thought possible!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever wish you could decrypt the mysteries of cybersecurity and ace your CISSP exam? This episode is your treasure map to success, guiding you through the labyrinthine layers of the OSI model, starting with the physical transmission of data and the crucial role of physical access controls. We also enlighten you about MAC address filtering and how it fortifies network security.
As we move deeper, we unlock the secrets of encryption, digital signatures, and secure coding practices. We delve into the heart of the session and presentation layers, spotlighting the importance of input validation and secure API design. Get to appreciate the role of protocols like Session Initiation Protocol and Real-Time Transport Protocol in VoIP. We also bring to light the security risks associated with VoIP and iSCSI, introducing you to the sinister world of call hijacking, eavesdropping, and toll fraud.
Finally, we don our armor and arm you with the best security controls for VoIP, such as encryption, authentication, and access control. And just when you thought it couldn't get better, we guide you on how to hit the bullseye in your CISSP exam. Exploring the benefits of a CISSP Cyber Training membership and how it sets you up for a triumphant win in the exam. So, gear up for a thrilling voyage into the captivating realm of cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to conquer the CISSP exam? Join me, Sean Gerber, as I break down complex concepts and guide you through an in-depth exploration of threat models, including their components and the crucial role they play in identifying and mitigating potential threats. You'll not only get an understanding of the TRITE methodology and when to use STRIDE or DREAD, but also learn to pinpoint which threats in STRIDE refer to an act that modifies data or system configurations.
We'll unravel the secrets of successful threat modeling and the key steps involved - leaving no stone unturned. Unearth how to interpret multiple choice questions, and understand the nitty-gritty of the TRITE methodology. In addition, we'll shed light on the importance of updating and maintaining threat models as an ongoing process. This episode is guaranteed to leave you feeling prepared and confident for the CISSP exam. Don't just take the exam, ace it! Tune in to this episode and get set to become a pro at threat modeling.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you prepared to defend your organization from cybersecurity threats? I'm Sean Gerber, and this week I'm unraveling the intimidating world of threat modeling. Get ready to supercharge your cybersecurity knowledge as we dissect threat identification, risk assessment, and mitigation strategies. This isn't just for acing your CISSP exam, it's for becoming an indispensable security professional who can effectively safeguard your organization.
We'll embark on a journey through the labyrinth of regulatory compliance, and work towards mastering the art of threat modeling. We’ll highlight the importance of robust communication, continuous education, and the strategic role of stakeholders in countering threats, vulnerabilities, and concealed secrets buried in code repositories. Expect to gain a comprehensive understanding of Stride and Trike threat modeling, underlining the significance of tackling repudiation, information disclosure, denial of service, and elevation of privilege to safeguard sensitive information.
As we delve deeper, we'll expose the vulnerabilities and considerations of Trike security, emphasizing the criticality of well-defined security requirements, cost implications, and essential automated tools. I'll also divulge my blueprint for the CISSP exam available on CISSP cyber training. This is more than just a tutorial - it's your stepping stone to becoming a proficient cybersecurity professional. So, brace yourself for an episode teeming with insights and tactical strategies that you can't afford to miss.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to unlock the secrets of data classification and pass your CISSP exam in one go? That's right! Your host, Sean Gerber, is here to guide you through an insightful exploration into the world of data classification. From the intricacies of content-based and context-based data classification to the various stages of the information life cycle, this episode promises to be a goldmine of information. We'll dissect the appropriate levels of data classification suitable for different types of data and unravel the efficiency of various asset classification methods.
Ever wondered when user-based classifications would come in handy or how assets are effectively grouped into categories like finance, HR, and IT departments? We've got you covered! This episode dives deep into the asset life cycle stage and the sophisticated tools that analyze unstructured data. On top of that, we also demystify the commonly utilized levels of data classification like public, internal use, highly confidential, and restricted. As we delve into these layers, we'll differentiate between them and shed light on why the secret level is rarely used in commercial entities. Join us and boost your CISSP exam preparation while developing a broader understanding of data classification.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to make your digital assets and information impenetrable? Well, we're here to navigate you through the maze of understanding and protecting your most valued digital treasures. This episode is packed with a wealth of knowledge, as we discuss the intricacies of information and asset protection. We highlight the vitality of data classification, and the importance of effectively training your team to attach the right labels.
Your senior team needs to be on the same page with you when it comes to data security. We uncover the crucial link between information and assets and how they are dependent on each other. Mobile devices often carry valuable data, making them susceptible to threats. To avoid a compromise, it's important to understand the potential risks and impacts of placing sensitive data on such assets. And, should a compromise occur, we discuss the possible repercussions, including reputational damage and lost future earnings.
The journey doesn't stop there. We move on to the defining stages of the information lifecycle, emphasizing the need for secure data collection and sharing processes. Misclassifying data can have dire consequences, hence we delve into various classification types and the importance of having protective policies. Lastly, we give a sneak peek into asset tracking and management tools, and how to choose the right one for your use case. Remember, understanding, protecting, and handling digital assets and information securely is a crucial part of the CISSP domain 2 exam. So, fasten your seatbelt as we take you on this enlightening journey.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you charged with navigating the precarious terrain of supply chain risk management? Then, prepare to sharpen your skills in this action-packed episode! I'm Sean Gerber, and I'll be guiding you through the labyrinth of supplier audits and evaluations, discussing the delicate balance between the two. We'll also delve into strategies for mitigating risk, including the benefits of outsourcing to multiple vendors and having redundant suppliers for those all-important components.
But that's not all! We also take a journey through the CISSPcybertraining.com site, a haven for those gunning for the CISSP certification. I'll unpack the site's blueprint, highlighting how the questions available can be a treasure trove for exam prep. On top of that, you'll hear about the growing popularity of the CISSP exam and how YouTube is buzzing with resources to support candidates. So, whether you’re studying for the CISSP exam, or you’re just hungry to broaden your cybersecurity and risk management knowledge, this episode is your ticket to enlightenment. Tune in!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Prepare to unravel the complexities of supply chain risk management (SCRM) and gain invaluable insights that could safeguard your business from massive disruptions. We're diving into the nerve-wracking challenges of SCRM, emphasizing just how crucial it is for every business in our hyper-connected age. Learn about the nuances of this formidable task as we explore real-life scenarios that underline the dire need for security professionals to lend their expertise to those who find themselves in the deep end of SCRM vulnerabilities.
We're laying out the intricate tapestry of SCRM domains, from hardware and software to third-party services, casting light on the risks associated with outsourcing. We'll guide you through the maze of supply chain elements, helping you identify potential risks and understand the threats looming over your daily operations. It's not all gloom and doom though; we'll also equip you with proven strategies like engaging third-party services such as Showdan and Security Scorecard for supply chain reviews, and the critical role legal and compliance teams play in this intricate dance.
As we wrap up, we'll tackle the ominous reality of ransomware attacks on businesses. Using the chilling example of the 2017 NotPetya attack, we journey into the shadowy underworld of cybercrime, where profit margins are hefty, and the risk to the perpetrators is minimal. With the projected cost of ransomware attacks set to hit a staggering $25 billion by 2025, we explore the dire implications of this trend. As somber as these realities might be, our intent is to arm you with the knowledge and resources to fortify your supply chain and protect your business. Join us, and let's navigate these choppy waters together.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to conquer the CISSP exam with confidence? Join me, Shon Gerber, in this week's CISSP Cyber Training Podcast as we tackle questions from all eight domains to give you the insights and knowledge you need for success. From understanding the purpose of a risk register to exploring the primary security concerns in a microservices architecture, this episode covers a wide range of topics to sharpen your cybersecurity prowess.
We'll dive into essential concepts like data classification, stateless firewalls, and incident response phases. Plus, I'll share valuable tips and strategies to help you handle each question with ease. Don't miss out on this opportunity to deepen your understanding of key CISSP concepts and prepare for the exam like a pro. And don't forget to check out CISSP cyber training for more free questions and resources to support you on your journey.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to level up your cybersecurity career? Wondering which certifications are worth your time and investment? We've got you covered in today's episode, where we break down everything from the entry-level CompTIA A+ certification to the more advanced CISSP. Get an insider's look at the costs, study time, and areas of concentration for each of these valuable certifications.
We don't just stop at CompTIA A+ - we also dive into the Networks Plus and Security Plus certifications, as well as the Certified Ethical Hacker (CEH), GSEC Security Essentials, and CompTIA Cybersecurity Analyst certifications. Learn about the requirements, costs, and expected study times for each one, and find out how these certifications can help you stand out in the job market.
Lastly, we explore the CISSP exam in depth, reviewing the different security domains it covers and how the CISSP Cyber Training Blueprint can keep you accountable for passing the test. Don't miss this informative episode that will set you on the path to success in the world of cybersecurity.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to elevate your cybersecurity knowledge and pass the CISSP exam? This episode is packed with insights on software development, diving into the crucial phase of integrating security into the software development lifecycle (SDLC). We uncover the secrets of design and architecture, as well as static and dynamic application security testing (SAST and DAST) to help you identify vulnerabilities and ensure compliance with coding guidelines and policies. Plus, we explore the open-source OWASP project - a game-changing initiative to improve security within software applications.
But that's not all! User acceptance testing (UAT) is essential for integrating security into the SDLC, and we're here to break it down for you. Learn how UAT empowers stakeholders to validate security controls and assess the effectiveness of software security features. Together, we'll examine secure coding guidelines, standards, and threat modeling - giving you the tools to write secure and robust code. Don't miss this informative episode, and get ready to become a cybersecurity superstar!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to elevate your cybersecurity knowledge and ace that CISSP exam? Join me, Shon Gerber, as we delve deep into the often-overlooked realm of software development lifecycle and the essential security controls within the development ecosystem. We'll unpack the three key secure design principles: least privilege, fail-safe defaults, and defense in depth, helping you build a solid foundation for your cybersecurity expertise.
As we continue our journey, we'll explore the critical importance of secure coding protocols, input limitations, secure code repositories, and development environment controls. Uncover the relationship between different software development methods and potential security risks while learning how to teach developers about these challenges. Our discussions on Agile method, DevOps, and security testing will unveil innovative strategies for more flexible and efficient development.
As we wrap up this insightful episode, we'll discuss the potential consequences of not adhering to proper security configurations, including injection attacks, broken authentication, and the potential reputational, financial, and legal liabilities that could arise from a hack. We'll also go over the importance of security policy for web development teams and what it takes to pass the CISP exam. Don't miss out on this opportunity to enhance your cybersecurity acumen and prepare yourself for the CISSP exam. Listen now!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Do you know the differences between security events and security incidents? Are you confident in your ability to protect log files from unauthorized access? Join me, your host Sean Gerber, in this week's episode of the CISSP Cyber Training Podcast as we explore domain 7 of the CISSP exam and tackle these important questions. Remember, it's all about understanding the concepts, not just memorizing the questions.
I'm also excited to introduce my CISSP blueprint, a product designed to guide you step-by-step through the process of studying for the CISSP exam. This blueprint not only offers a comprehensive study guide but also breaks down each step with links to resources, readings, and tasks to complete. Check out my CISSP blueprint at CISSPcybertraining.com and be sure to tune in next week as we continue our journey through the CISSP exam questions and topics.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to level up your understanding of logging and monitoring in the world of cybersecurity? Join us, your host Sean Gerber, as we take a deep dive into CISSP domain seven, exploring the ins and outs of logging, monitoring, and how they play a crucial part in keeping your system protected. Listen closely as we unravel the challenges of managing vast amounts of data, deploying and disposing of resources, and utilizing cryptographic resources for physical security.
Discover the different types of logs - system, application, and security logs - and how they can be used to detect incidents, operational problems, and policy violations. We discuss the importance of accurate date and time stamps and the role logs play in forensics analysis, compliance, and troubleshooting. Moreover, we tackle the challenges of data overload, false positives, and evading detection.
In this episode, we also discuss the exciting role of Artificial Intelligence (AI) and Machine Learning (ML) in the security world, and how they can be used to enhance protection. Learn best practices when dealing with logging and monitoring, such as encryption, regular monitoring, and backups. By the end of this episode, you'll be well-equipped with knowledge on logging and monitoring that will not only help you pass the CISSP exam but also vastly improve your cybersecurity strategy.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to ace the CISSP exam? Join me in this episode as we explore domain six, focusing on security controls and assessments. You'll not only learn the primary objective of security control testing but also gain insights into various types of tests and the limitations of vulnerability scanners. Together, we'll dive into the nitty-gritty of security control testing, ensuring you're well-equipped to tackle the CISSP exam with confidence.
We'll go beyond just understanding the concepts - I'll provide examples and explanations for each question, so you truly grasp the material. From compliance-based security control tests to manual security control tests, we'll break down the benefits and limitations of each. We'll also discuss the crucial difference between black box security control tests and other types. By the end of this episode, you'll understand why security control testing should be an ongoing process and not just a one-time event in the system development lifecycle. So, let's get started and take that step closer to passing the CISSP exam!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to ace the CISSP exam and level up your cybersecurity knowledge? Together with my background as a former red teamer, we guide you through domain six - security assessments and testing, covering both military and corporate America perspectives. We'll discuss essential concepts such as vulnerability assessments, risk tolerance of companies, and the tools required to identify vulnerabilities.
Join us as we explore the different types of testing, including manual and automated testing, and explain the importance of following security methodologies during a security assessment. You'll learn about penetration testing as a form of surgical strike and its role in gaining long-term access to an organization. Additionally, we'll reveal the importance of securing AWS accounts and API connections to prevent data breaches, and how pen tests can help validate security controls and incident response processes.
Finally, discover the role of automated tools in meeting compliance requirements, like the American Disabilities Act. We'll also examine manual testing, code reviews, and the use of machine learning models and social engineering to manipulate individuals. With our valuable insights and practical examples, you'll be prepared to tackle the CISSP exam and enhance your cybersecurity skills. Don't miss out on this action-packed episode!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to conquer the CISSP exam and advance your cybersecurity career? Join me, Sean Gerber, as we break down identity and access management, exploring the primary benefits of single sign-on systems, session management, and multi-factor authentication. Plus, get insights on the differences between role-based access controls and other access controls, giving you the knowledge and tools to pass the CISSP exam the first time.
Not only will we discuss the importance of passing the CISSP for a successful career in cybersecurity, but we'll also share vital resources to support your exam preparation. Whether you're an experienced professional or just starting in the field, this episode is packed with valuable information to help you achieve CISSP certification and take your career to the next level. Don't miss out on this chance to gain expert guidance and confidence for your exam!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to up your cybersecurity game? Look no further, as I, Sean Gerber, take you on a deep-dive into the world of identity and access management. Together, we'll explore various authentication methods, such as passwords, tokens, biometrics, and multi-factor authentication, and analyze their strengths and vulnerabilities. We'll also tackle the all-important concept of credential creeping and discuss how to prevent unauthorized access to sensitive data.
But wait, there's more! Identity and access management isn't just about security; it's also about compliance. Join me as we examine the role of IDM in regulatory requirements like GDPR, HIPAA, CMMC, and Chinese Cyber Laws. I'll share expert tips on streamlining user management by creating and removing accounts to ensure the safety and security of your organization. Plus, we'll delve into the challenges of granting and denying access to resources based on privileges, helping you combat credential creeping effectively.
To wrap it all up, I'll reveal the best practices for identity and access management, including crafting clear and comprehensive policies, robust authentication and authorization frameworks, and privileged access management solutions. We won't stop there – I'll also discuss the significance of session and federated identity management, touching on aspects like user authentication, session tracking, session timeout, and session termination. So, don't miss this information-packed episode guaranteed to strengthen both your cybersecurity knowledge and CISSP exam preparation!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Join Shon Gerber on the "CISSP Cyber Training Podcast" as he delves into Domain 4 of the CISSP exam, which focuses on Communications and Network Security. In this episode, Shon will cover some of the most challenging CISSP exam questions related to the OSI model, various TCP/IP layers, and protocols such as SYN, SYN/ACK, etc. He will explain the intricacies of each layer and how they work together to provide secure communication channels. Whether you are just starting to study for the CISSP exam or are a seasoned security professional, this episode is a must-listen. Shon will break down complex concepts into easy-to-understand terms and provide tips and tricks for passing the exam. Don't miss this informative and engaging episode of the "CISSP Cyber Training Podcast"!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
In this episode of the CISSP Cyber Training Podcast, we explore Domain 4 of the CISSP exam - Implementing a Secure Channel. We delve into the intricacies of the OSI model and TCP/IP, as well as the four layers of the TCP/IP model, to provide a comprehensive understanding of how to establish and maintain secure communication channels in your network. We discuss the importance of encryption, authentication, and authorization in maintaining network security. Our expert guests share their insights and experiences on best practices for implementing secure channels, including practical examples and real-world scenarios. Whether you're a cybersecurity novice or a seasoned professional, this episode will provide you with valuable knowledge and skills to enhance your cybersecurity expertise. Join us on the CISSP Cyber Training Podcast and stay ahead of the curve in today's constantly evolving cybersecurity landscape.
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Join cybersecurity expert Shon Gerber on the CISSP Cyber Training Podcast as we explore Domain 3 of the CISSP exam, focused on security models. In this episode, we delve into the various security models, including the Bell-LaPadula, Biba, Clark-Wilson, and other models. Our expert guests share their experiences and insights on these models, their applications, strengths, and weaknesses, and how they are used in real-world scenarios. We also provide an in-depth review of the associated CISSP exam questions related to security models, giving you the knowledge and skills you need to succeed on test day. Whether you're a cybersecurity professional looking to enhance your knowledge or a student studying for the CISSP exam, this episode is a valuable resource. Don't miss out on this opportunity to gain a competitive edge in your cybersecurity career. Tune in to the CISSP Cyber Training Podcast with Shon Gerber now!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Description: In this episode, we delve into the fundamental concepts of security models, a critical topic in the CISSP exam. Aspiring CISSP professionals and cybersecurity enthusiasts will gain valuable insights on Domain 3.2, covering key concepts, principles, and best practices related to security models. Join us as we explore various security models, including the Bell-LaPadula model, the Biba model, the Clark-Wilson model, and the Brewer-Nash model, among others. We'll discuss their unique features, strengths, limitations, and practical applications in securing information systems. Whether you're a CISSP candidate preparing for the exam or seeking to enhance your cybersecurity knowledge, this podcast provides comprehensive coverage of security models, supported by practical examples and exam tips. Don't miss this opportunity to expand your understanding of security models and ace the CISSP exam!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Do you struggle with understanding CISSP exam questions related to data ownership in Domain 2?
Tune in to our latest episode of the CISSP Cyber Training Podcast, where we discuss the most challenging CISSP exam questions outlined by Shon Gerber in relation to data ownership.
We cover the legal and regulatory requirements, establishing data ownership policies, and data ownership in the cloud.
Our experts provide insights and tips to help you understand the nuances of these questions, so you can confidently approach them on the exam.
Don't miss out on this opportunity to improve your chances of passing the CISSP exam. Listen now to the CISSP Cyber Training Podcast for valuable insights on Domain 2 of the CISSP Exam.
Podcast Link:
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Welcome to the CISSP Cyber Training Podcast, where we're diving deep into Domain 2 and exploring the importance of data ownership. Join us as we discuss how understanding data ownership plays a crucial role in protecting sensitive information and ensuring compliance with legal and regulatory requirements. Our expert instructors will walk you through real-world scenarios to help you establish proper data ownership policies within your organization. Don't miss out on this valuable opportunity to enhance your knowledge and gain the confidence you need to pass your CISSP exam with flying colors. Tune in now to the CISSP Cyber Training Podcast! #CISSP #CyberTraining #DataOwnership #ExamPrep
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔒 Get Ready to Conquer Domain 2 of the CISSP Exam! 🎧🔍
🎙️ Exciting News for Aspiring CISSP Professionals! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for mastering Domain 2: CISSP Exam Questions! 📚💡
🔐 Boost your exam preparedness with our expert-led podcast episodes focused on Domain 2. From data governance and information lifecycle management to data retention policies and secure data handling, we cover it all! 🎧✨
📌 Dive deep into the complexities of Domain 2 and strengthen your knowledge of data management principles. Gain insights into industry best practices, regulations, and secure data handling techniques required for the CISSP exam. 💼🔒
🌟 Elevate your exam success! Follow us on LinkedIn and Facebook to access valuable resources, tips, and exam strategies tailored specifically for Domain 2. Let's conquer the CISSP exam together! 👉📚
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔒 Master the Data Lifecycle with CISSP Cyber Training! 🎧🔍
🎙️ Attention CISSP Exam Takers! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for mastering Domain 2: Managing Data Lifecycle! 📚💡
🔐 Deep dive into the intricacies of data management and gain expert insights on the lifecycle process through our engaging podcast episodes. From data creation and storage to its secure disposal, we cover it all! 🎧✨
📌 Enhance your understanding of data classification, retention, and encryption techniques. Stay updated with industry best practices and regulatory requirements to ensure the utmost data security throughout its lifecycle. 💼🔒
🌟 Equip yourself with the knowledge and skills to excel on the CISSP exam! Follow us on LinkedIn and Facebook to access valuable resources, tips, and expert advice on mastering Domain 2. Let's conquer the Data Lifecycle together! 👉📊
Podcast Link:
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Welcome to the podcast on CISSP Exam questions related to Domain 1! In this episode, we will dive deep into the world of information security and explore the essential concepts, principles, and best practices that are covered in Domain 1 of the CISSP exam.
As you prepare for the exam, you'll encounter a range of questions related to security and risk management, including topics such as security governance, policies, and procedures, risk assessments, threat modeling, and more. We'll provide detailed insights and expert tips to help you understand these concepts and develop the skills needed to pass the exam.
With this podcast, you'll gain valuable insights into the most critical security concepts and principles covered in Domain 1 of the CISSP exam. Whether you're a seasoned security professional or just starting your journey, this podcast will equip you with the knowledge and confidence to ace the exam and advance your career in information security.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Title: "CISSP Exam Essentials: Understanding Legal and Regulatory Issues in Information Security"
Description: In this episode of the CISSP Exam Essentials podcast, we delve into a crucial topic for information security professionals: legal and regulatory issues. Aspiring CISSP candidates and cybersecurity practitioners alike need a solid understanding of the legal and regulatory landscape that surrounds information security practices. Join us as we explore key laws and regulations such as GDPR, HIPAA, and PCI-DSS, and their implications for organizations and individuals. We'll discuss the legal framework for information security, regulatory compliance best practices, incident response and data breach management, cloud computing and third-party risk management, international legal and regulatory issues, as well as emerging legal and regulatory trends in information security. Our expert hosts will provide practical guidance, insights, and real-world examples to help you prepare for the CISSP exam and enhance your cybersecurity knowledge. Don't miss this essential episode on legal and regulatory issues in information security for CISSP training and cybersecurity professionals.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
In the world of cybersecurity, maintaining professional ethics is paramount. Aspiring CISSP professionals need to understand the importance of ethical behavior and its impact on information security. Join us in this podcast episode as we explore Domain 1 of the CISSP exam, focusing on the fundamental concepts of understanding and adhering to professional ethics.
We'll delve into the ethical principles that guide the cybersecurity industry, including integrity, confidentiality, and professional competence. We'll discuss the significance of ethical decision-making, the implications of unethical behavior, and the consequences of non-compliance with industry standards. With insights from seasoned cybersecurity experts, we'll provide real-world examples and scenarios to help you grasp the relevance of professional ethics in the cybersecurity field.
Whether you're a cybersecurity professional preparing for the CISSP exam or someone interested in the field of cybersecurity, this episode will provide valuable insights into the ethical foundations of the CISSP certification. Don't miss this opportunity to gain a deeper understanding of professional ethics in the context of CISSP certification. Join us for this thought-provoking discussion on cybersecurity ethics and best practices.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Welcome to CISSP Cyber Training, the podcast that delves deep into the world of cybersecurity and provides you with expert insights and strategies for mastering CISSP Domain 8. If you're seeking CISSP training and looking to excel in the field of information security, this is the podcast for you!
Join our experienced hosts as they explore the critical concepts, best practices, and challenges related to software development security, one of the most crucial domains of CISSP certification. From secure coding practices to threat modeling, from secure software testing to secure software deployment, our experts will share their wealth of knowledge and practical tips to help you stay ahead of the game in this rapidly evolving field.
Whether you're a seasoned information security professional or just starting your CISSP journey, this podcast will equip you with the skills and knowledge to excel in software development security. So, tune in, and let's dive deep into the world of CISSP and software development security together!
Keywords: cybersecurity, CISSP training, CISSP.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will be covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will be covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam:
· CISSP Articles – Supporting Investigations
· CISSP Training – Understanding and Supporting Investigations
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
In this episode, Shon will talk about the following items that are included within Domain 8 - Software Development Security of the CISSP Exam:
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Infosec Industry
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/software-development-security/#gref
OWASP
file:///C:/Users/gerbersa/Downloads/SAMM_Core_V1-1-Final-1page.pdf
SYNK.IO
https://snyk.io/blog/ten-git-hub-security-best-practices
National Cyber Security Centre
Transcript:
…Hey all is Sean Gerber again with reduced cyber risk How are you all doing this Beautiful beautiful morning I hope things are going well in your part of the globe in this big shiny blue marble, things are going awesome in Wichita Kansas Yes The small little town of Wichita Kansas. it's going well I can not complain at all It's a beautiful summer day School's getting ready to get started and my kids are getting ready to go back to school which is an awesome thing Very very cool. It a one of those situations in your life when you have 50 if and when you have ever have children out there, kids are great most days other days, not so much And so when it comes to going back to school, most parents will just glee with be or be super happy with glee. Yeah that doesn't really good word there but anyway they're really super happy because of the fact that the kids are no longer at home And they're now focused on school. So yeah it's a it's a good thing. Well today we're going to be talking about software development And how old is this? around that? And you'll see many things that have occurred recently It was just a recent breach that hit with that. capital one here in the United States. And they said there was probably I don't know how many millions of people were affected by that And so therefore what ended up happening is is, there there was an insider threat issue Well the today we're not gonna talk about the insider We're going to talk more about the software development, but in the case of when you're creating apps or crew from a Your websites whether you're creating apps for the app store that go into the Google play or iTunes. All of that needs to have some level of software development security built into it. And so there are some key aspects we're going to go into, as it relates to doing that. Along with that is going to be the main things that you're going to have to know for the CISSP exam as you know reduce cyber risk My ultimate. Plan is is to be able to give you that CISSP training You need to pass the CIS S. The first time again we want go into that If you want to pass this I know this test is a bugger din They're done that We're going to have some next upcoming episodes We're gonna talk a little more about the exam. But bottom line is is this test is a bugger and I failed it The first time I studied my butt off for that test I studied basically three months just self study just to go put, pass the test because at the time there there were bootcamps but I didn't have the funds to be able to go pay for a bootcamp. And so I've studied it. And it was actually good that I studied just because of the fact that, it it helped me get a good knowledge of what I deal with on a daily basis. But the cool part about knowing the CISSP and passing the exam the first time is the fact that you will utilize those skills on a daily basis as a CSO, for a large multinational So those are things that consider is that the good thing is just. Just by taking the test is the first step And the examiner is the first step in the whole road to make becoming a cyber security professional. And so therefore it's it's imperative that you get these foundations and you know, fundamentals. And studying too much. Of test questions is very important you know just to understand what are they going to ask for and how they're going to ask. But those test questions are designed mainly to help you as you go through them. Understand the questions and how would they answer How would they. Question you or how would they provide the information for you so that the answers you provide are the right ones. But again Canada has already addressed but the cool part about studying for the CISSP is the fact that you used to learn a lot of good stuff. Well today we're going to learn about software development and the security that goes into that. So when I talk to my SSP cybersecurity integration This is the area that I grabbed some information from the internet, like an article or so forth. And this one is software development life cycle and we'll get into that And that's an interesting piece that you should understand your software development life cycle from beginning to end So from the beginning when it was conceived, Junior beautiful mind to when it dies and is rotting in the ground. So that's the, in some cases some of these apps. I mean I've got apps that were in our environment that are. the 1970s So they never die They just get a little aged. A CISSP. Training We're gonna talk about integrate security in the software development life cycle high burn integrate that and domain eight. And then the CISSP exam questions are obviously around development security and S D L C. All right Let's get get into it…Yeah So this is CIS S P cybersecurity integration This is the InfoSec Institute reference and I that's the who we're going to be calling up today from their website. And they're going to talk we talk about eight.one software development life cycle This is if you are, have the CISSP. The ISC squared, document that focuses on the different sub chapters around the ISC This is eight.one that's called out in that document. this is software development life cycle. Okay As I talked about in the intro applications are becoming more and more complex and therefore we're seeing these eggs that are tied together Now in the past you would have, you had just an app that let's just I say the past that's so distant past. Where it was. a year just your app store was set up with iTunes or with Google play And you had that was your app, or you had you'd build some sort of application that had a offering a ser saw a software as a service where you'd log into a web portal and you would have access to it that way. Now what ends up happening is as these applications are becoming more complex because you have edge computing that's dealing with Amazon AWS. You have your apps that you put on your phone and your phone. These things are extremely powerful So therefore that is able to come do massive computations So as technology continues to grow and get faster and faster these applications are growing in size and complexity. as well And so security needs to be a key factor in when you're successful implementation. of your application now whether this is an intentional or unintentional, it really doesn't matter The fact of it is you got to do it and you really need to look at how you keep software embedded within your environment. Now software and hardware control are extremely important And so if you're to put any sort of app out there at all, you need to have these controls in place. Now as you're dealing with Sophos. Some development control system development controls that are needed for the CISSP exam. There's some key things you need to keep in mind. Now system development steps need for creating modifying our maximizing information system So you need to have steps in place. That are going to be used to help when you're dealing with creating modifying or maximizing your information system That's a key term that you're going to run into. On the CISSP. And you need to have a formal activities set up for development so that you're heavy Like in case of myself I have a development team. They worked for me. They work out of India. And they do a great job and they do an awesome job and they have a ability to do development. And they're in the process of building out an entire suite of things that they need to do from their initial development products to CIC D to automated testing So on and so forth all that needs to be put in place. Well when you're dealing with that you also need to have some level of security built into it as well. and you need to create development standards around this coding and we've run into this with third parties. So if I have a third party that helps me and they provide some sort of coding than what is the standard by which they're developing their coats. so that's an important piece of this is that what are the aspects from the development standards? How can they do this? Now it could be as simple as a checklist They could be. My naming convention is this, we have we do have, we do fuzz testing on the application when it's done. we have you know all these little steps can be built into their process and they just go through it step by step. now I have noticed the challenges that go into this because the developers are they get paid They're incentivized to develop quickly and to develop, with good code but develop quickly And so therefore, Sometimes we don't want to take the time to do the initial steps to run it through a scanning engine, to make sure that it does that it works So those are those are conditions that you need to help in talk to your people about and ensure that they're connected with it. And then oh wasps Sam core model Now OSP is an organization that's on a that provides development for web applications. And it's basically a web applications And what are the aspects around securing those web applications? So you can go to old wasp and check it out online They have a whole laundry list of things you can use specifically for ensuring that your product is properly secured your application. I mean they have all kits from scanners to best practices I mean it's a really good place If you are a application developer and you're looking to incorporate security within your environment. they have a software assurance model That's the Sam the software assurance maturity model. And it's basically an open framework and we like to talk about frameworks but…realistically it's a guide or a checklist little checklist is a little bit too tight but it's more of a guide to formulate a strategy around applications and events evaluates the organization's existing security practices while puts in well-defined iterations for their software. they did demonstrates concrete improvements and it measures the security. activity So did the bottom line is it breaks it down for you? To be able to put security into your right now your current process. So it's just a good framework and a good checklist to go by. the highly recommend checking out Oh Wass but they have a great product out there and you will be. It will be called upon it on the CISSP. Now they may not call it the old hospice. Specifically, but they're 20 best practices that they have are we'll be we'll be called out specifically within the CIS. Those prac those best practices coding practices You you may see that…Now their top 10 project proactive controls of this is of 2016 first one is verify the security early on often obviously right But you need to stay on top of it. but rather than having something go into production and then have to do scans for it. parametize queries and co data validate all inputs That's a huge one there where you have inputs that are going in for a form field. And you validate that that yeah this I want a date of birth to go in here and I don't want Java code to be put into your I want just date of birth. That needs to be a. Input validation step that needs to be. implement identity and authentication controls huge, implement appropriate access controls protect the data again Now if you're dealing with applications that are just basic wonky data. That may not be such an important step However if you're dealing with any sort of personal data or data for your company that's considered confidential. and if you're building an app that is for somebody else you need to consider that, would that data be, be possibly considered confidential, then you need to look at protecting the data. you need to implement logging and intrusion detection. this is when we had last week from talking about logging. Lever security frameworks and libraries and then air and exception handling. So those top 10 if you did those that would do is dramatically reduce the risk to your sites. and what would end up happening is is you'd put you in a much better position as it relates to your site being affected. Bye. And it hackers are the like, Now as you're dealing with the SDLC there are some key aspects to keep in mind. one is planet our planning and requirement gathering You need to understand when you're dealing with your device. what are the requirements around it? Also architecture and design How do you designing your application and your software out there What is the purpose behind it? And then how do you make sure that it's maintained be updated? How do you update it How is that Is that built into the overall development strategy? test planning How do you test strategy over development code So how do you build that out till you're going to test to ensure that it does not like your input validations What will you put in there to ensure that the wrong input validations don't get put in and they could run potentially run code on your server? Coding and implementation ensuring code is complete by dividing into various modules. Testing and deployment, and that would be product development based on requirements. And then your release and maintenance your final product release and its maintenance and then maintaining that product. but again you have to begin this from the beginning of when they have the light of the application or the software is born to when it dies or it guess what It may not die unless you kill it. Especially we're dealing with software as a service you can kill these things but if you go out individual programs that are going out. That kind of stuff. it stays around forever So just consider that whatever you make. What is the way you're going to be able to update it And do you want to deal with that headache for a long period of time? Now One thing also about the CIS CIS. they talk about SDLC models that are covered in the CISSP. Now the most common are there there's various comments that are old or various models that are open and I'm going to go over some of these right now But, the main one that I deal with is a. scrum and you'll see that model here in just a little bit. I should say agile and that's crumbs a method of doing it It's actually, because scrum is like with a rugby, but no it's agile the agile method And we'll get into that just here in a second. A waterfall model This is the most common model And it's typically been used by many in the past And this basically basically comes down to as you finish one phase and then you go on to the next, but there's not much room for making changes to the waterfall model You have to wait until the whole process is done. Before you can go Meg, go back and make changes So if you notice that there's changes. While you're in the middle of the of the sprint with the waterfall model There's very little leeway to go back and make changes to it And you have to basically come back around after the whole thing is done. the V-shaped model was just very key verification and validation model and it's very similar to the waterfall but each phase has a testing phase. So the good piece of that is you don't wait till the end to find that you have issues. You each phase we'll give you some sort of testing and then you can make you put that in the backlog and then make iterations to that. But it is still though the overall project If you have like five sprints for this one project. you may get all the way through the project and then realize okay now I get you to go back and fix those changes. the iterative model which has repletion and improvement And basically that comes back in it replete rev repeats it. And then it improves it and it takes care of those things It's set of requirements that are tested and implemented. And you basically are You're iterating you're going back and forth back and forth And the new various versions are based on new and inner. versions of the software. So as draft software gets updated. A new iteration as a crooner occurred, then they come back and make changes and it just keeps going on that process. it's a very it gets you a very viable product early So if you're dealing with the VIP which is your VA viable product, that's a very good point It gets you there in a very quick period of time but it may take a lots of resources to do that because there's a lot of things that are going on especially if you're having to iterate it over and over again. And again these models are designed not to be One is the only one you do. the they're designed to depending upon your situation which model would you use The waterfall waterfall model. Oh waterfall the V-shape model, or the inner of model. Now we have the spiral model Now this works in an iterative model basically starts by continually repeating it over and over and over again, but it kind of goes out It allows for improvements on each round So it just you repeat phases, the four phases over and over and over And so you just keep going in a circle. the big bang model typically Good for small prod. a little work being done on planning, and most of the roads sources are for development And with that comes into as you bang you're done you just hit it hard Everybody jumps in all hands on deck and that's the big bang model. but if you're dealing with a small project that is very tiny in nature and that you can do quickly. that would be a really good model to use. The agile model Again this is one of the I use customer interaction and feedback So you're basically reaching out to the product owners getting feedback from them on how the process is going You have a backlog, sprints are usually in two week cycles. And what ends up happening is you'll, you'll go through the backlog you prioritize what you're going to do You do that product. And then at the end of it you the next sprint. anything that is considered a bug that doesn't critical gets thrown back in the backlog and then it gets reprioritized prioritize in the next sprint. it's basically you test it at each iteration. And so there is testing it's put into a testing your production, our staging and production. And so that process is done through the agile model Can it depends on which one works best for you and your organization. So in the past you would test after completion strategy for security And they would typically do this at the end of everything. If and I say that even if the case has many times, they wouldn't even test. but it does leave you vulnerable especially if you're waiting to the end that things have been in production. incorporating security at the beginning does help. Create more secure applications and it reduces your overall risk. Ah, From someone getting access to you And especially during the time when you maybe if you find a mistake, But you know what you fixed. Eight of the 10 but you found two of them that are vulnerable. Well that's good That's I mean at least there's only two versus if you don't add security from the beginning, you now have 10 plus and that causes a lot of issues. you incorporate code review and pen testing and your architecture analysis and there's different SDLC models available Microsoft has a development model. M S S D L and then NIST also talks about it with 800 dash 64 which is a national national national Institute of tech. And this 800 dash 64 does provide security considerations into system development lifecycle. Now there's also another model it's called class which is a comprehensive lightweight application security process class. and this says a set of processes mapped to job roles and allows for early security in stages. So again there's different SDLC models that you have to look at And when it comes to the CISSP they're going to focus on what are some models that are available. And I say when I say that it's going to, it's one of the questions that you could run into doesn't mean that this specific question is on the task No, not saying that at all, but it is a Microsoft development life cycle One question you could potentially see is when considering SDLC models that are available to you. What's one of the following is a model, the model T by Ford, the model. Vega from the car, the model XYZ or the Microsoft security development life cycle model. Or which which a government organization. you with this and that's the NIST 800 dash 64. So those are the questions that you could see on the CISSP exam…Okay That's all I had for the CISSP integration. And now we're going to roll into the CIS is P training eight.one Understand and integrate security in software development life cycle That's the plan We're gonna talk about it in this next objective, As part of the site reduce ever his podcast And there's going to be your CISSP training's going to be available to you. all of the videos that I've created over the time around CISSP are going to be there. The CIS P training manual that's are videos that are focused on the ISA. squared. Exam that are there There's about 129 different, videos that you can watch They'll take you through zero all the way to hero. And the cool part about it is at the end of the day when it's all said and done, it will set you up substantially for to pass the CISSP exam. because it it just really will, you have the knowledge that you get from those videos what you've done on your own. And if you want to go self study for the test you are going to have a subset substantial chance of passing the test. I mean it you'll pass it the first time And that's the ultimate goal is that we want you to help you pass it. The first time. All right so let's roll right into the training. Okay So when we're looking at security again for software environments now this is to all this information I'm providing you is considered out of the ISC square training manuals that have been provided. So what you saw with the original CISSP integration is from InfoSec Institute This is actually out of. My knowledge and working with the also the ISS ISC squared tra official training manual for 2018. Now when you're talking with key aspects you need to avoid developer. even to prevent developers in a work environment from creating an environment that is bad for software. you also need to have the ability to tap apply technical controls where appropriate in your software environment. And it's also important to understand that what could happen if your software development area is compromised. What would somebody get if they got into your code repository? what if they got into your your code and development environment? So what are some key aspects to keep in mind in there? Especially if you're developing apps for your company what kind of credentials could they potentially steal? Did utilize and leverage against you development security considerations You need to have a separate business development functions And this would come into the place where you have email slash document management in a firm should be separate from development. They need to be in separate environments. Not necessarily need to be in separate, completely separate environments but they needed not be work. Your your daily work stuff and your development stuff should be separate. you need to utilize active directory groups and or virtual must. As you're looking at creating, your security environment So those are important things again that separates from the business environment the business network. considered development environment has been compromised So if you look at it from a standpoint of a business are should say most, develop our most networks. You need to consider as you're building out security And as you're looking at what's available to you. The fact that your development environment might be compromised. And that means you just separate your admin and user accounts They can not have the same ability to work on the same things. And you didn't incorporate multifactor as it relates to dealing with security for your environment. it is with your the pin you have like say you go on and you log in you have to enter any multi-factor code. That's on your phone The second token that allows you in, there also would request like multiperson review a good thing is to have someone within your organization review your code before it gets shipped to production. That allows to look for any sort of bugs that may be there. Or something else that may have affected it. also look at trust but verify you need to trust your individuals, but not necessarily their accounts. and that's another thing to consider is that as you are. Dealing with these accounts. Are people, your people are working for you at you need to trust them but their individual network accounts could be compromised and they wouldn't even know it. So it's important that you do trust your people but not there. Your individual accounts. You need to incorporate logging and monitoring which we talked about last week and the importance of doing that. security actions You need to reduce your attack surface And by doing that is that if you have something in production don't have a lot of spurious pages that are sitting out there available for people to go and attack, keep it clean keep it crisp, and you need to protect your assets that your credentials to get into your property It's imperative that you do that secret keys are important as well. And then you also need to understand from an incident response standpoint what is the impact of a compromise and ensure that those controls are in place to limit slash manage the Compromise If it does occur. keep production development environment separate and then ensure again when logging and monitoring isn't is enabled and being monitored. The problem is is turning on logging and monitoring is great but if you don't do anything with it, So much. So it's imperative that you do things like that…Now you're dealing with configuration management as an aspect of secure coding you need to impact the analysis of your change. and you need to request change It needs to be done through the sprint cycle It doesn't mean you go in and just make changes. You should have a sprint cycle set up, whether you're using one of those different waterfall methods and you need to go ahead and put that change in. You also need to have a formal approval process to make that change and put that in the place highly recommended that people are involved in conversations on the phone. And if you have an automated change request process, there needs to be some way to verify that So that if somebody got in a hacker and said Hey add this level of code into your environment please. That would be a bad thing. also approve and reject changes You need to have a formal approach process on how to deal with that. And then ways to test the change, that is in your environment basically a non-production location that you could do through like, you could have it set up on AWS or someplace like that that it has a pipeline where we actually go through and run automated testing. You have that place to check for change. Schedule a time to change the production again come back to when would you do this Have a plan organize orchestrated event, and then document the change Make annotations in the document control. Now you're dealing with versioning. You need to have some level of nomenclature around this You need to have a naming convention and this could come down to some level of late labeling you get your one dot oh your one.one your one dot two so on and so forth And you need to have documentation around your versioning and why you did it. the software configuration management is imperative as it deals with version controls. And the one thing I've learned is that documentation around versioning is definitely a it's an art and and how people do it And then the commenting that goes along with the versioning and labeling. that will cause issues as if you have ineffective version controls, it will cause outages and issues And because what it comes down to is people don't understand. Y you're going from one.one to one.one one one dollar.one one.one one. Yeah I just confused myself. See how easy it is that can happen to anybody. So the point of that is is versioning is important but you needed to have that defined in a written format somewhere. Now your code repositories these are impose very important that you take care of your code repositories. because the fact they keep everything there they act as a central location for developers, your GitHub or Bitbucket your source forge all of those act as a code repository. And so you need to understand the security around that Because again if a hacker gets into those, what's that going to get they're going to get all of your code Well if your code has proprietary information in it, that would be bad. That'll take you out of business Your competitor could get it. And now you're done. you also need to look at a single sign on or multifactor piece to this as well. Avoid the use of API keys in the code repository So the API key basically is set up so that. It will connect to something else and you. API key may have credit is acting as a credential. Well if you have these API keys that are sitting in your code repository, somebody could utilize the API connect into your environment and you wouldn't even know it. unless you have proper logging and monitoring enabled And so odds are high If you have API keys in your codes. You might not have logging and monitoring enabled And then therefore now they're in your environment just like in they're able to pass data in and out without anybody really even seeing it. you need to have security best practices Do avoid remove any sensitive data within the repository and control access by adding removing the, and adding removing process. You also need to have a security.md file which would have your disclosure policies security update policy configurations and gaps and possible enhancements Again that's a message file That's available to talk about security and what could be W what needs to be changed What has been changed? Well how can people disclose it and so forth? You need to rotate your SSH keys and your personal tokens. again those are good best practices Don't keep them the same It's important to move that stuff around. However we do know this people are human and people will if they default to the fact of it's hard to do it they will not do it So something to consider is that many software development companies are many people will not rotate the keys They just won't. And and so therefore you need to look at how do you implement that into your environment? Always consider security when you are developing anything…All right So that's all I have for the CISSP around the ISC square training manual 2018. Let's roll into the CIS. P exam questions. Okay this one's on usernames and passwords. Now considering a development security there are some key considerations you need to be aware of. And I said considering twice considering and considerations those considering. All right So there's some key things that you consider. W a separate business and development functions. Be considered development environment compromised. See trust but verify. D all the above. E none of the above. So when considering development security there are some key considerations you need to be aware of. Separate business development functions. Consider the development environment a compromised. Trust but verify or all the above or none of the above. Answer is B all the above They are all a crucial to thinking around development security. Again separate business environment. You consider your environment compromise you trust but verify you control your. You trust your people but at the same time as you you don't trust their credentials. Those are key things As it relates to username and password in the software development life cycle. Okay this one's on preventative access controls What are the various SDLC development models covered in the CISSP exam? Waterfall. V-shape. Iterative. Agile…spiral and big bang. That was a B. Is waterfall X shaped. Repetitive. Agile. spiral and big bang…See waterfall why shape? He has a lot of letters They're repetitive. Agile. Spiral and big bang. Or D none of the above. So which ones are involved in that are gonna be covered by the CISSP exam. And then now. Number is or the letter is a waterfall V-shaped iterative, agile spiral and the big kahuna bang. All right That's that question right there Again those are important things You need to know the models on the and what are some of the pros and the cons around each of those development models.
Shon Gerber from CISSPCyberTraining.com provides you with the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will cover questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
https://www.isc2.org/Training/Self-Study-Resources
Infosec Industry
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/security-operations/logging-and-monitoring/#gref
Transcript:
…Hey Alice Shon Gerber with reduced cyber risk How are you all doing this wonderful day It's been a beautiful day here in Kansas It's been like scorching hot though. About 100 degrees It was last week So yeah it's pretty pretty toasty outside but other than that it's a wonderful summer's day and I cannot complain at all. And just wanted to call and talk to you today about some great things we've got going on with reduced cyber risk. But in this episode we're going to be talking about domain seven security operations and this is going to be all part of the CISSP exam. And these are some key areas that we cover And this is domain seven. And I try to focus on a specific podcast to go over a specific domain and areas that you need to be concerned about as you're dealing with logging and monitor as you're dealing with the CISSP exam. So in the first part of the CIS piece, Cybersecurity integration. We're going to be talking about logging and monitoring overview. And as far as the CIS is P training specifically about logging and monitoring activities this is domain seven. And if you study the I I S C squared CISSP training manuals, you will know that that's where that falls into. And then the CISSP exam questions are going to be around logging and monitoring and data life cycle domain seven. All right As it relates to the CIS S P cybersecurity integration, we're going to be talking from a article I saw online from the InfoSec Institute, and this is objective seven dot three conduct logging and monitoring activities. The topic is logging and monitoring overview and really what it comes down to is we're going to get into what exactly our logs is The first thing we're going to kind of focus on. And typically people wonder what our log files. Well you know this is riveting stuff I hate to tell you It's just riveting What is the log file? A log files got dated. Oh my gosh Just, just turn the pages It's cannot compel. You cannot hold back the enthusiasm about a log file No it really they're quite boring and quite painful. so therefore we will talk about how you can ingest those log files but bottom line is there an event log something that occurs within an environment? And they are typically called with a computer name. They have creation deletion and records They have all of those pieces that are tied to an event log that may occur. Now most systems Now I will say most because in many older type systems or applications, They may not generate much for log files at all. In newer systems they do They. They generate a plethora of log files which at times can be a bit overwhelming. But log files are an integral part especially as in you're dealing with the CISSP exam and understanding this as a cybersecurity professional. Now there's different types of logs And this comes again from InfoSec Institute and you'll see this in your CISSP exam, but there's types of logs and these are authentication logs or. logs and system logs These are different types of logs that you will see. And they each have a different thing And authentication obviously is when you're logging into something and authenticate you audit log is basically looking at the system itself and finding out if there's an audit trail around those logs. And then your system fought logs are logs that are dealing with specifically with the system that's operating on it. Now there's some different use cases that you need to keep logs for And these these use cases would be regulations that negation or even application debugging. I mean there's many different as situations where you would want log files, but in the today's world especially as a litigious as it is see that's a big $10 word Yeah Litigious. I should I don't even know what that means Cause my third grade education won't let me go any further than that but it's a bad thing I assume being a litigation Litigious Yes. so these use cases around litigation regulations, you have to maintain logs for a period of time. And depending upon the company depending upon the regulations, you may have to keep some of these logs potentially indefinitely were you would then in turn be using products like AWS glacier or someplace like that to store them. That's a different podcast. But bottom line is is that you would have to keep these logs for a period of time and regulations litigations or debugging may, may want you to have some form of logs and be able to keep them for a period…Nausea some key considerations around the log files that you need to be aware of. They start off small and they're really EDBD they're not very big at first. But then you add one device and then another device and another device And next thing you know you got log files coming out of your ears They replicate like a rabbits. And so you go what am I going to do with all these Well, so in realistic realistically here it comes down to log files are only as good as if you even look at them If you don't look at them what's the point You don't need them. And they just take up space and they basically take up processing speed. However, if you were to get sued due to some thing that would be unfortunate such as a breach. and if you don't have log files and you, you. Purpose. did not collect log files. Yeah That's a bad thing for you So I would not recommend doing that. So therefore you need to start off and start off small, but the logs need to be it could be in a situation where they need to be forwarded and moved on. That's a possibility. they also the storage can become a serious challenge as it relates to keeping your log files. You don't know, these things build up and as they build up they store for a long period of time Now if you have to keep them for a long period, You now go from being oh gigabytes to terabytes to whatever it'd be on a terabyte a lot. but multiple terabytes. T to keep these logs Now these logs typically aren't they call a flat file So they're not very big. But as you get lots of systems reporting in they will grow substantially…Now deal life cycle of keeping These should also be considered. How long do you want to keep your logs for you want to keep them for 90 days six months one month one week two days. I don't know He had to decide. Now regulations may dictate what you should and shouldn't do around that. Place but at the end of the day you need to come. how long do you keep that data in your environment? Now as you're dealing with log management you must develop a solid monitoring strategy And this is where it comes into play where you have a, some sort of auto robot type thing a, a Splunk or a some sort of SIM which would be your. A security incident event management system that would, all these things would get dumped into and they would help monitor this. I also need to consider a human machine automation What do you want to give to the computer What do you want to have humans Look at. And you define that from a strategy standpoint what works best for you? You also need to determine what to log. Everything doesn't need to be logged You got to ask yourself do you really need to log it? Well in some cases a banking situation you may need a log almost everything, but another plate may. In other cases you probably don't need to And it's just additional waste is really what it comes down to. Now you need to start off small We talked about that but bill value within your organization there's some devices that you can monitor which would be your intrusion prevention your intrusion detection switches. All the things we're routing goes through some level of traffic Now again comes down to your environment. Comes down to your occupation. Whether how much you should record or should not record with logs. But again you want to look for anomalies That is the key behind all of this. Now when you do on a log review you needed to find criticality of the systems to be monitored I E intellectual property systems they would be the ones the first ones to look at. They have financial data personal data Those systems you'd want to keep logs up. Now do you want to keep logs of the raspberry PI That is just checking? I don't know The people entering and exiting a building. Probably not. it's just one piece of information you probably don't need, but you needed to find the criticality of these systems that you want to be monitored. In to determine a process to handle issues incident response process Do you have one. Is there an automated situations or events that you can click off and have this thing just go for you in the lieu that there is an issue. And you may need a tiered approach when you're handling these events you know how do you want to handle the. A situation where. You've been breached Well that would be a tear. Oh my gosh Kind of tier versus a yeah this guy's computer It doesn't work real well And it's got ransomware on it and it's really not worth anything Well that's like oh yawn not a big deal. So you have to determine which one works best for you and your organization…Now you also need to consider frequency We talked about this as well Do you want 90 days 60 days A hundred days. A hundred? Yeah It could be exactly one. One day. I was at one That's a good one. Now you gotta decide what frequency how often do you want to collect these You want to collect them daily hourly monthly. Minute by minute minutely That's not a real word but it works for me. so you can determine how frequently how frequently you want to collect them. Where do you want to store these Do you have a forward or that fours on your logs Do you have a. CIS log server that basically aggregates collects all your logs. what is the bandwidth of the connection for your logs You may have a situation where that you have bandwidth constrained and therefore these logs just take up extra space that you do not want them to do. Are these systems critical Non-critical. are they scripted or a manual collection What do you how did you work That is it set up that they automatically post at a certain period of time to a certain location? depending upon how you have things set up you can have API APIs set up so that it would have one application would talk to another application and just pitch the logs to a certain location. I said location three times That's pretty cool. You get actually 10 points extra for saying the same word three times in one sentence. Yeah No that's not really a good English so yeah Don't don't listen to what I just said. you need to understand your environment as well Operating systems applications tools external access, third party connections All of those things need to be considered what are going to Keep logs on now as a personal example I've got…where I've got third parties coming into our environment. I want to watch those logs now do I want to watch the ticket meter that allows people in and out of an environment You know like the gate No I really don't care about those but now third party guys and gals coming in Yeah I kinda want to watch those You never know what's gonna be coming in through a third party connection. So you just got to make sure that you keep all of that. Now as you're dealing with log analysis, you need to consider again And we talked about the data life of it and there's various phases of your data life cycle. Here's your collection, your examination your storage your archiving and your deletion. Those are basically five aspects The five phases of cycle of generation. yeah basically those are the things you need to consider yourself as you're dealing with data life cycle collection examination storage, archiving, and deletion. Now there's various quiet requirements that you need to consider in each of these phases Are you dealing with GDPR which is your general data privacy regulation Are you dealing with HIPAA, which is your health insurance portability accountability act I got to say that 10 times socks like the red Sox Yeah That that. Well I'm going to now I can't Sarbanes Oxley That's basically what that comes down to But do you have requirements that focus you in this space that requires you to have a certain amount of collection How much do you examine it Where do you store it Is it encrypted? do you archive it And then what is the process for deleting all these things you may have to define depending upon the environment. or the industry that you are in…now policy decisions will also need to be made to address each of these So it's important that you have it set up, that you have a policy for collection examination storage archiving and deletion. Say that a lot. So. What I'm saying is I'm trying to hint at the fact that she probably didn't know those that that's probably good to know. Probably just good to know. but bottom line is is that you need to have policies that focus on those So because it will help you make your environment much more secure…All right So that's all I have for the CISSP integration was rolled into the training. Now as we're dealing with seven dot three conduct logging and monitoring activities All right moving on All right Sorry to digress. All right so we're getting into seven dot. Three conduct logging and monitoring activities There are some key aspects around logging and monitoring You need to keep them. So we talked about logs right? Well there's security logs there System logs There's application. all these have a log. Now I kind of hint back to the fact that if you have older applications, They sometimes don't have much for logs. and some of them may not have any logs So that's something to consider as you're looking to dump all of this stuff into your security operations center or the tool that tool does. That they may be using. Almost everything though does have some form of log. Again some can be useful. Some not so useful. But the key around this though is you do need to consider protecting the log data that you collect one for a couple of reasons Well if you've got a situation coming up where someone gets hacked, first thing they do is they go to the logs. Well if the logs have been manipulated then people will not trust the logs So then therefore they ended up throwing out that as evidence within, or they will then turn around and use it as a very. More circumstantial evidence that isn't really worth a whole lot. Because they maybe they feel it they're tainted. so the point of it is is you need to protect these logs from attacker so that they don't get access to them So they don't manipulate them. that's a key point around that. You also need to look at where do you want store these things and what kind of repository which we alluded to earlier is that do you have a security incident event management system a SIM. could be CyberArk, not CyberArk dossiers. Now it could be Splunk It could be ArcSight could be other situations You could have a home grown system that you use, but anything that basically manages and collates events that occur within your environment. You also probably need a forwarder and this forwarder will then collect logs from certain locations and forward them on to another location or basically four of them out of the SIM. at this will depend a lot on the size and complexity of your organization. keeping logs We talked about that 30, 60, 90 days is the typical amount that people usually do I've seen it as high as six months. I have seen and heard of people that keep it indefinitely especially as it relates to legal hold. And we've talked about that in a different part of the CISSP but bottom line is is if yours litigation going on in your company and you may have court communications that involve that company that's under litigation you may be required to hold onto this information under a. hold status. Which basically means you can't get rid of stuff you can't delete it. And if you did delete it that would be really really really bad So don't delete it. but bottom line is you may have to keep your logs for an indefinite period of time. Now I do note this destroy them when not being used Okay. Bottom line Don't be a hoarder Just don't do it It's not fun. It's expensive. And you lose a lot of friends over it So just just don't do it. Yeah Yeah You also kind of stink if you're a hoarder. So, I mean I don't know I don't know a lot of hoarders, but I would think so because maybe you hoard so much stuff that you don't take a shower cause you can't take a shower because it's in your shower. Yeah. Okay Moving on, but destroy it when it's not used. Okay Various risks for keeping logs too long There are various risks If you keep it too long, you now open yourself up to litigation say in the event through our legal hold and you kept all the records that go back 18 zillion years. And they are now set up and say Hey by the way do you have those logs Oh yes we do. We have five of them go back 18 gazillion years Oh, great Well we can I could probably figure out something you did wrong So therefore you will go to jail Have a nice day. Don't pass Go just go to straight to jail. it's hell no don't keep those for a long period of time Just, just a bad idea. As a deal with security information and event management to you need to consider the automated or configurable product SIM they are basically have them set up as rule sets they're established to alert or flag on suspicious activity. So if you got lots of suspicious activity going on then you probably don't be probably want to SIM. To to verify and correlate it. Colet court correlated Yeah Okay Third grade education kicking in a range in price depending on bells and whistles you put they can be very very expensive or they can be very very. Not quite as expensive They're still expensive Don't don't anybody fool you. There are a lot of money, but you can get by with some that are small especially if you're a small business that there you can get by with something a little bit less expensive. A typical bullet deployment around these is it there's usually an agent or their agent lists Okay It gives you both ends of the spectrum. The age. ones will take logs directly from the system and they'll ingest those or send those directly to the SIM. And agent one we'll use a software to collect and send the logs to the SIM They may collect them into a certain point and then they'll ship them off to the SIM. agents are deployed to systems being monitored and that's where they get they get shipped off to and they can provide additional functionality with the device So if you basically have a an agent on this system it's allowing you to have insight into that device Well it can give you additional functionality. around that again example would be CrowdStrike CrowdStrike has a great agent works on the systems and it can provide multiple levels of protection as well as log sources as needed. Now Sims are usually quite configurable depending upon the one that you use they are they can be very easy to use pull out of the box and mash a big button and they work, or they may take a lot of configurations to make them really just hum. Now they all will need some level of that If you really want them to hit on all eight cylinders, you're going to need someone to help config. them However, some are better than others that just roll them out of the box and just stick them in your environment and let them run…Now again it may require a very special skillset to do this I warn you They are not cheap. These special skillset people ArcSight Splunk et cetera are very expensive. So if you're going to put that in your environment and you're saying for your CISSP it's one of the questions you will run into, but I'll tell you right now that if you're gonna put that in your environment you better come with a lot of zeros and be prepared to find the right people in the talent Now I will say with India there's a lot of great opportunities that you can outsource that capability, but they're they're not cheap Just. Just just telling you the ain't cheap, expensive. correlation engines and machine learning was also be incorporated into the Sims and a lot of the aspects of of learning that's coming down that path. And you can also incorporate these into other device management systems such as S S C C M It's a Microsoft product I used to manage devices. Now as you deal with continuous monitoring monitoring. You need to con The purpose around continuous monitoring. to provide an audit trail. it's also what we call investigation fodder and I didn't really know what fodder was and I probably just totally butchering this But fodder is the old peasants from the old days that would be marched along to go in front of the. The British red coats And you would basically just go walking to your death. I think that's what they called Fodder cannon fodder You just kind of in the way and you get blown up. That's it So investigation fodder stuff. That's probably totally wrong but Hey it sounds good. without the logs you basically basically have nothing other than the incident So you got to have a logs I mean, You can get some glean some information if you've had an incident but in many cases it's just days old and the logs will give you that trail that paper trail. Virtual paper trail to be able to help you with in the event There's an issue. as a key piece though you need to have a network time protocol capability and TP. And these are synchronized and this basically tells you what's the time that it occurred. If you don't have an NTP server, there's telling you it's sinking your time within your environment Typically you can do this just through the internet but. if you have to a large enterprise you may need that in your enterprise to make everything sync. You got to have that for timestamps If you don't have that that makes it extremely challenging to prove your case. they basically the bottom line is is all this stuff leaves breadcrumbs that you can go out and chase to bring, to help bring justice if somebody does breach your environment. And also it does promote continuous monitoring does promote accountability It lets people know Hey, I'm watching, I'm watching you. Yep Just go ahead. Just do it cross the line Oh you did Okay Now I'm going to beat you know, that that's a promotes some level of accountability. Monitoring techniques as continuous monitoring provides all the data for adequate investigations and log amounts will again we talked about before be quite substantial and large. you do need to invest in some level of automated tools to search these volumes of logs because otherwise you're your puny little brain as much as it's wonderful as it is. we'll have a hard time scouring through gobs and gobs of log files, eagerness monitoring some key aspects of. this is monitoring traffic leaving your network Hence egress ingress is coming in Egress is going out. so there's some key aspects around us You know you monitor the traffic that's leaving your network. It's important because a lot of times you might not know what's actually coming in your environment, but man it all has to go out through the internet in most cases So it's better to watch. Obviously what's coming in but more importantly Hey what's leaving Cause usually when it's leaving that's bad. you need to assume that your internal network has been compromised by some form shape or manner. And this happens all the time. A network will get compromised You won't know the bad guys in the environment for many many months if not years. And so you have to make the assumption that it is compromised. The attacker wants data to leave It wants to get rid of it It wants to be able to send it to wherever it wants to go. It does not want to leave it in your environment So it's got to ship it out some way. USB sticks. Eh that doesn't work so well I mean it can happen but man it takes a lot of sticks to be able to move your data and you gotta have physical access. Well if you're in country X, halfway around the globe. It's kind of hard to get physical access to the server So therefore, yeah they got to ship it out through the internet. tools to assist in stopping this loss You've got web proxies and these are basically rules configured to stop traffic to Noon destinations. there's data loss prevention which is basically network based or endpoint based. And it can be set up so that you can not use USBs. You can't type in specific keywords, you know restrict you from doing certain aspects. Mainly comes down to as you want to go and watch the hairless cats that are on the internet, it will stop you from looking at the hairless cats on the internet. No not really but it could I guess. stenography is basically embedding messages within a message file And it's extremely hard to discover but it is possible Yes, it is quite possible but you gotta know what you're looking for because yeah it's hidden set of picture. And if you don't know that then yeah you ain't gonna find it. file-based DLP as a software that affects all the different vial types Doc dot.dot J. et cetera et cetera. And there's different companies that provide it But Azure has one's called Azure IP. That is a file-based DLP solution. That will help you from getting rid of it. All right That's all I have for the CIS is P aspect. Let us roll in to the CISSP P exam questions. Question number one, as it relates to logging and monitoring what are some of the key purposes behind capturing logs? Provides a provides an adult. Adult. And audit trail allows for illegal actions and promotes accountability. B provides an audit trail keeps employees concern promotes dependability. See allows for compliance to track employees which is what we always want to do. Keep employees concerned which is even better and promotes accountability. Or D none of the above. Which one is it? It is a promotes audit trail Yes. Allows for legal actions Yes. And promote accountability Yes Yes Yes it is a, so again you have to what you want to do is you want to make sure you have an audit trail Danny Danny be able to find to be able to go back and do those breadcrumbs. You gotta have some level of legal action in the event that you could use those logs. And you got to make sure that people are aware of what you're doing so that there's accountability involved…All right the next question. When considering the data life cycle what are the phases slash cycles Not of the moon that be that the data is generated. A collection inspection storage archiving deletion. You remember I mentioned this you mean to pay attention? B Co gathering examination storage archiving deletion. C collection examination backups archiving deletion. I'm seeing a trend here. Collection examination storage archiving deletion. What is it? A B C or D. It is D collection examination storage archiving and deletion. Those are the key considerations when looking at data life.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP Articles – Secure Network Design
· CISSP Training – Cybercrime and Data Breaches
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Peerlyst
https://www.secureops.com/networking/effective-network-security-design/
TechTarget
Shon Gerber from CISSPCyberTraining.com provides you with the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will cover questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Transcript:
…Hey y'all this is Shon Gerber Thanks for listening today But before we get started I wanted to update you on the launch of my CISSP cyber training membership for my listening audience. On March 5th, 2023 I began offering a monthly CISSP membership at 60% off my already low price. This is an introductory offer of $19 a month for the first year. With that insanely inexpensive price you will get all of my CISSP content practice exam questions, all my current and upcoming curated content. And finally me. As I'm growing my products and services for my site you will be on the ground floor to take advantage of an offer that will never ever come back again. So if you're planning on taking the exam in 2023 or if you want to learn more about cybersecurity, this will be the time to make a life and career altering decision for you and your family. There's amazing offer is only available for the next two weeks So I highly recommend that you don't delay and sign up today. All right let's get started. Welcome to the reduce cyber risk and CISSP training podcast, where we provide you the training and tools you need to pass the CISSP exam The first time. Hi my name is Sean Gerbert I'm your host for this action packed informative podcast. Join me each week as I provide the information you need to pass the CISSP exam and grow your cybersecurity knowledge. All right let's get started…Okay Question number seven. What is the security mechanism that is typically put in place to ensure that data is not compromised? Okay answer a honeypots answer B intrusion detection systems, answer C encryption. Answer D host based intrusion detection system or Hibbs That's what I kind of like enough has found like you have a mouth full of marbles who literally. Okay So again the security mechanism that typically is put in place to ensure that data is not compromised. And if you look at all these questions, Which one would keep the data from being compromised. The answer is C encryption. Encrypting is commonly use. to ensure that data is not compromised, both intransigent. And while it's sitting at rest in databases or other locations, Again that is encrypted. Answer C honeypots what do they do They kind of act as something the way that kind of allows people to bite off on something that's there They they become and they look like a. A free. Target intrusion detection systems are looking for intrusions right? Host based intrusion detection systems or something that's based on the host itself. So they're really just looking for other intrusions, but when it comes to ensuring that the data key word data is not compromised, the answer is C encryption…Okay. number eight. When a device ORC slash capability is considered highly available, it means that the system must remain available. A most of the time. Be a large part of the time C only when necessary or D all the time. Okay again question is when a device or capability is considered high availability. It means the system must remain available. A most of the time be a large part of the time. See, only when it's necessary and D all of the time. If high availability is called out and required it must be available all the time. So again by setting this requirement you. can add additional resources or terms in contracts to ensure that this occurs What does that mean? It means if you are requiring this as a company that you must have high availability for those systems. Then at that point you wanted to find that within your statements of work or within your contracts, because that will drive in some respects how much work they have to do, but also how much money it's going to cost. So you have to determine is high availability a necessity for your business…Okay Question number nine. Availability is compromised when a denial of service occurs and is. A mitigated. Be not mitigated I…see adequate protections are implemented. or D a system has non-repudiation enabled. Okay So again…Availabilities compromise when a denial of service occurs and is a mitigated. Be not mitigated I see adequate protections are implemented or D a system is non-repudiation enabled. So if you look at those three questions, really what it comes right down to what is denial of service You need to know that denial of service is something that is denying you access to it So the availability to gain access to the data it's denying it So if it's denying that service to you, Then it hasn't been mitigated. Right So that you're causing issues So adequate protections are implemented that's out because it's not working. C R D a system is non-repudiation. enabled. That's really not. That's talking and not about anything about denial of service So you get rid of that It's an easy one to throw out. And then D mitigate it So C and D are pretty much the same pretty close right? B is not mitigated So if you have denial of service it is not mitigated. And therefore it is causing you disruption. And the answer is B. Thanks so much for joining me today on my podcast. If you like what you heard please leave a review on iTunes as I would greatly appreciate your feedback. Also don't forget the 60% off buy membership at CIS S. Cyber training.com. We'll be ending on the 19th of March. So sign up today for this once in a lifetime sales event. Thanks again for listening.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 6 (Security Assessment and Testing) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Disaster Recovery and Business Continuity
· CISSP Training – Conduct security control testing (Domain 6)
· CISSP Exam Question – CVSS / Scanning Tools
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Disaster Recovery Journal
https://www.drj.com/drj-world-archives/dr-plan-testing/practical-ideas-for-auditing-and-testing-the-disaster-recovery-plan.html
Person IT Certification
http://www.pearsonitcertification.com/articles/article.aspx?p=2931575&seqNum=3
OWASP
Transcript:
Hey all Shon Gerber Again it reduced cyber risk.com and a wonderful day in Kansas I have today and life is good Can't complain at all And it wouldn't do any good anyway because nobody lets listening about your complaints They just want to hear it all the good things in your life. Actually they're not even paying any attention. In most cases people are saying how you doing? I'm doing good How about you I'm good But in reality their lives just really stink. So no. but I'm doing good nonetheless. So I hope everybody thinks going well for everybody else out there in the world and things are great here. from a cybersecurity standpoint. Couldn't get any better There's actually it's interesting how the world keeps changing and getting more and more. connected And as a result, there are lots of threats that are affecting cybersecurity And if you're studying for your CIS SP you as you well know it's actually a great opportunity to get your CISSP There's so many jobs that are coming open. it's it's just blows my mind And but in many cases you have to have a CIS S. To even be able to play in this space. So therefore it's it's a good thing that you're you're working on your. SP. And the fact that you are trying to enhance your cybersecurity career. So what's it's good Life is good All right So let's get into some what our plans are for today. Today we're going to be talking about disaster recovery and business continuity and our CISSP integration. the CISSP training's going to be conducting security control testing It's all part of domain six and the CISSP exam questions are going to be around CV S S. Common vulnerabilities and then the scanning tools that are associated So again those are the CISSP questions. Also listen to the as you continue to listen to the podcast you'll be hearing, I go over domain or exam questions as well on a weekly basis that are just kind of more to brief into the point And the whole point of it is though is they're just kind of a snippet of what I offer on my YouTube courses that you can get yourself. if you want the CISSP training that you can go and study and also use it to augment your CIS. Studying. you go to U two me.com. You can check those out there at And look for Shawn S H O S S H O N Yeah I know My parents are unique so I couldn't spell So they made a phonetic on Yeah I love it It's great. Shon gerber@udemydotcomoryoucangotomysiteatreducecyberrisk.com C I S S P dash training. And you can actually have access to the training. you can go but it's it's it'll take you to you to me where you can purchase that, that training as well So it's awesome stuff. I guarantee you It is a great training I've done There's like probably close to. well I think it was around 19 hours of training that you can get specifically to help you with the CIS SP each of the different domains that are there And honestly it's it is it's bargain basement pricing that you will get at you to me. and it's I mean obviously they get they get a little bit out of it I get a little bit out of it but at the end of the day, you get a lot out of it And that's the ultimate purpose behind doing reduce cyber risk and the CIS. Training. So all right As enough about the plug but anyway check it out. All right Let's move on to the training…Okay The CISSP integration we are going to be talking from a reference of InfoSec Institute and this is off six dot three collect security processes data. And it's focused around disaster and recovery. So as you will know working on your CISSP and studying this space especially if you're a cybersecurity professional disaster recovery is a key part of how you protect your data and ensuring that it is properly protected and available for people And again this comes down to the CIA triangle, as it relates to availability. Having a disaster and recovery plan is a great first step to having a, availability of the data. So testing on a disaster recovery and business continuity plans they should occur You should have these and you should do these and have these in place. and this comes down to you should have a security assessments and testing that are set up to determine which disaster recovery. Or what systems need a disaster recovery plan and which ones need. continuity plans And so to tell it a little bit of background from a disaster recovery point of view, in the event of a disaster, you have to have the ability to bring critical systems backup at a certain period of time. within a, within a few minutes from a week. And we typically call this an RPO, which is your recovery point objective to your recovery time objective, which is part of the disaster piece. And and so therefore you need to have that in place Well you'll have to do an assessment and understand what does that look like? From a standpoint of data recovery. And so you should you can should consider that also So country. Consider security control testing as well in your disaster recovery plans. Now from a business continuity standpoint you need to understand what are certain aspects or certain systems that need business continuity completed I do. So like I say you have a one complete system that needs to be, it needs to operate no matter what in the business it has to be operational has to be ready to go. And so that would fall under the business continuity and that is a individual point system disaster recovery is kind of the more larger broad brush systems that you would deal with. you also need to understand what are the security processes for data collection as it relates to your disaster recur, recovery and business continuity plans. Now there's there's factors that reduce your Dr Plan's effectiveness and these come into new equipment that you have in place like new acquisitions. So if you don't have if you haven't done a really good job of assessing whether these are critical systems or not or whether they should have a good disaster recovery plan. That can limit your effectiveness of your Dr Plan. So in effect, basically comes into this you have a system and you said you have a Dr Plan for this system and its system a…well system B rolls into town and you get rid of system a. But system a had a Dr Plan in place. You now have system B. Okay. ACE gone bees here. Well what ends up happening Well you disaster occurs and you go, oh Pooh. We didn't have a Dr Plan set up for system B. and so therefore it's imperative that it so then the effectiveness is like ah I don't know what to do Do you know what to do No I don't know You know, what are we going to do? those are bad things to have run into especially when things go south. So therefore it's important that any new equipment you bring in you reevaluate the requirements and the criticality. Of that equipment. Also staff changes. When key positions that change how does this affect your organization? So you have your main Dr Person within your company And that person has the keeper of all the knowledge They are the big brain that operates the, the situation And if you've seen wizard of Oz they are the puppet master They're the man behind the curtain or woman behind the curtain. And so therefore, you need to understand well, is that the right at that person's gone now What what do we do I don't know. So again it comes back to that I don't know Do you know I don't know Yeah. It's kind of not good. So the point of it is is that if you have staff changes you need to prepare for that as well and have a plan in place to deal with the issues of individuals leaving your organization especially if they deal with VR…Now Dr Plan effectiveness Another thing that fact a factor that reduces your Dr Plan effectiveness is shifting processing priorities. data center versus cloud processing. And when I say data center obviously and the cloud there they're one of the same there's anonymous It's just, is your data center on prem on prem in your environment that you control or is it in the cloud and somebody else controls it. Or is it your cloud Again these are all different things that you need to consider. when you're dealing with Dr Plan effectiveness And so often people will migrate things to the cloud. Not thinking that well by doing that do I incur some issues with my Dr Plan? And then that kind of comes sometimes can cause a situation, actual application complexity automation and SAS solutions which is software as a service solutions. Do they add complexity Oh yeah they do They do add a lot of complexity and you need to understand if you're adding this new system that's in place that automatically pushes stuff to the cloud. Does that need to be Dr I don't know Does it should it have a good solution place to Dell deal with it Maybe don't know. So those are different aspects you need to consider as you're dealing with application complexity and then legislation channel challenges or changes that happens routinely And if that happens how do you deal with it? Recently there's just been some with the Chinese cyber law They had some requests for Out for comment And that was supposed to be done by the end of June So that has been completed. And now we're waiting on. What is the final ruling on some of these things from the Chinese government. Again legislation changes even though they are slow to operate in some of these changes but they have dramatic impact effects when they do make these changes So. changes in laws in all countries could have a dramatic effect on how you do business especially if you're on a global basis. Or if you are in country and you're trying to come to United States because our data laws may change too As time goes on…Audit preparation you need to prepare the team to meet any regulatory requirements that you may have And this includes, you're ensuring your inspect. Your expectations are set that the team will not enforce the procedures. so you'd need to make sure that they understand what does it take if you do not enforce these procedures how does that affect you? What how does it deal with. What are you going to do about it And do you have a way to document in the event that someone did not follow these procedures? you need to make sure that people are prepared for it And this comes down to the team of the your cybersecurity team It could be just anybody within it could be anybody within the business. I've recently been dealing with all of those things and the cyber legislation. I'm working all the way up to our board of our company because of these changes and they affect not just it they affect the entire company. So those are important pieces to consider. team members need fluency around internal audit data security and data processing. There they need to understand what are the different aspects around that and how do they manage those things So they need to understand the vernacular. And again I've talked about in recent podcasts that main point is understand how to talk to people to level they understand they are They can understand what you're saying. so they need to fluency on the cyber stuff and then be able to transmit that and translate that into words that people can use. outside resources can provide a little or a lot of technical assistance depending upon you If you want that or not from an audit preparation standpoint, that would be your ENY your Deloitte and so forth They can help you with this from a preparation point of view. or they cannot just kind of comes down to what you want them to accomplish for you…Okay That is what the training I had from the InfoSec Institute from cybersecurity integration. And that was over disaster recovery. Section six step three. All right So now we're going to roll into the CIS S P training. And that is objective six dot two conduct security control testing, domain six…Now we're going to talk about vulnerability assessments There's a physical aspect of. Asman that doesn't really work That's not a really good word. What does that word mean? I was a physical aspect…Does aspects of an assessment and these are scanning tools Penetration tests are big key physical aspects around an assessment. And if if you just heard a groaning it's from my dog Sorry my dog's in here and he's not happy that he's actually having to listen to cyber security stuff. there's assessment findings mitigations So these are all the different things you need to be aware of as you're doing an assessment for a vulnerability assessment from those tools to the penetration tests and so forth. Now there's a common set of standards for vulnerabilities and these can be all over the map. as far as the standards for these vulnerabilities and you just need to be aware of those. Now some examples around this are your CVEs and the CVE In this case the example I have is a CVE 20 18 1 2 3 4 5 What that is is that's a nomenclature they have for the common vulnerabilities exposures. And these are what. the governments have come up with that These are some of the vulnerabilities that are out there and this is the exposure to that. Now it talks about a descriptor. of the vulnerability It talks about references and how it got to that exposure A CVE number. these will typically go by the year. 20 18 1, 2, 3, 4, 5 I want to see for 5, 6, 7 and 8, 9, 10, 11 and so on and so forth. and they will then talk about the vulnerability and what are the issues And you can you reference these CVE numbers when you've scanned for vulnerabilities? And a lot of times a scanner will actually reach out and they utilize the database the CVE database. To say well Hey. XYZ vulnerability is tied to…CVE 20 18 1 or 2, 3, 4, 5. and then it'll cut tonic Talk about talk about that a little bit…There's also a common vulnerability scoring system And that's another one So you get CVS yet CVS S this is the principal character of the vulnerability What is it And it also ranks it on a scoring of a CVSs is from zero to 10 being the most secure or most secure. But most severe that was when you really got problems It's the apocalypse. things are coming down asteroids from heaven and plagues locus and all those things is when you hit two range 10. when it's range zero. It's like why bother even wasting my time? So those are the different CVS numbers that they have but they that's how they rank them. There's also many others. As well that kind of talk about this but your CVE and your CVSs are typically the two that are most used…now from a vulnerability scan There's automatic evaluation of systems applications and networks. these automatic evaluations of these systems you will automatically go out there It look at them. Now sometimes it needs to have an authenticated scan. And what that means is it may need credentials to actually do a full scan of what it needs to. So it may as an example of vulnerability scanner may just do a fingerprint of it It may only get the operating system name and may get a version of it It also may not get the most accurate information if it doesn't have an authenticated scan. So that's something to consider If you're doing these. scans within your environment. He has does it have to be authenticated to ensure that it's done properly? And typically set for a routine basis You need to set these up so that they're done on a monthly basis. and in many case cases the the scan is only good as the operator I've seen it where there were a person will match the easy button and they'll smash the button and a scanner will work and they go okay here's your report? Well, that's really useless because sometimes the reports that kick out of these things are like eight Zillion pages long and it's just, it's not useful. So it's important that you have a good operator who understands the scanning piece of this. And there will be need to be some level of interpretation as a release to the scanning and and how what does what's actually occurring within the environment and how does that affect you? So vulnerability scans again they're typically done on a routine basis but you you need to make sure that whoever does it is. And I like to say we I mean I like to focus My company focuses on a thought process around entrepreneurship and that people need to own their product. and you need to, so if you have someone who's doing vulnerability scans for you. if it's an internal resource they need to own their product and be able to provide you good results. If it's a third party that's doing the scans for you due to regulatory requirements, they need to give you a good product and they need to be able to talk to it Not just say here here's your report and have a nice day check box complete. they they need to be able to do a, a good product and give you or give you a good product and do a good job…Now from a network scan standpoint there are four main types You have network discovery. Network vulnerability. Web application and database vulnerability scans…The network discovery scan Now this is basically a different range of techniques around this and it's looking for open systems that are vaguely. Open and potentially vulnerable and ports that go to them So you could have tons of systems that are out there but if the ports are all closed and you can't get access to it that's a good thing. but in many cases that's not the case In many cases when you'll scan a system you'll find out that there's gobs of ports open, which would allow potential attackers to get into your environment. little mini companies typically do not have good knowledge around what other assets on their environment. And so network discovery scans are important Now, something to keep in mind with network discovery scans is that if you have older legacy systems, The news legacy the new network discovery scans that we have today are very they can be a bit. What do you call it? Oh, strong They can cause issues with a, with environments is that they're too much and they can make things tip over because they're just so strong. So there's various scanning options that you need to consider as you're doing it When you're putting these out there, just know that if you have old legacy systems and you're running a scanner you could run into issues So it's better to start small and work your way out. Now there's TCP syn scanning, TCP connect scanning, act scanning and then Christmas scanning. And obviously the TCP San you're looking for a sin. And that will tell you that basically it's alive If you're trying to do a connection it'll actually connect to the device. And then an actual we'll go in and acknowledge that it's even listening on a specific port. your Christmas scanning basically means you'd you you send the scan and it lights up like a Christmas tree and that's usually not good. but those are the different kinds of scanning options that are available for you with a network discovery scan…Network vulnerability scan This is a much deeper than the discovery piece and it was looking for known vulnerabilities. So you based on your CVE C V S S…a S. Aye. Items. it will be looking for those vulnerabilities and it compares a discovery of the data to what's within the database. So if it finds out that there's issues with it it will go and say that there's a problem with it And it'll tell you. these these basic compares a discovery to the data within the database itself specifically. and author unauthorized scans typically are are not as good So therefore an authorized scan gives you a lot more detail when you're dealing with a network vulnerability scan. You just gotta determine if you can put their credentials in place to do that. Now if you have to have certain level of credentials for that. that are elevated Now you need to protect those in a way that it doesn't incur more risk within your. There's various scanners that will help you do this There's Nessus Metasploit rapid seven Nexpose These are all scanners that you can we'll provide you that level of detail. you just have to decide whether you want to use free or you want to use paid versions. the paid versions obviously can get very expensive but they give you a lot more detailed They're more granular Obviously the free versions will give you something, but you got to ask. What do you need now if you just trying to do some basic maintenance and trying to understand your risk. Free scanners will work out well, if you're dealing from a standpoint of you got exposure on the web and you have regulatory requirements compliance requirements. You may want to invest in something different just because. They typically are updated better with the database They also will give you a better support, those kinds of things. So you gotta decide what works best for you As you're dealing with network vulnerability scans for your organization…When vulnerability scanning this scans for vulnerable web applications that are on the internet. it's usually the first line that is attacked because the rest of them they are. to get within your network The webs are out there and forced the webs. The…web the web vulnerabilities are your internet facing websites are typically the first line of attack because it's out there and available for people to go against. and in many cases these provide valuable data on even how you do your nomenclature within your network. So if they can get even if they can't. leverage an attack against that that server. it can give them valuable information of how your network has configured. And so therefore if that's the case if they do get inside your network through a phishing attack of some other kind it can cause issues Right They got more intelligence about your network. The other thing is is that if you get your web server and it gets attacked and they can get access to it. It can cause reputational impact. So you need to develop a process on scanning sites to understand how vulnerable they are. You also need to have a process in place to scan your lab and your production environments from a development standpoint. It's important that you know what your lab environment in your purse. environment looked like from a web point of view. Now if you have a third party that's doing this for you So you have a marketing company that's doing your your web applications and do our doing your front end for your websites. You need to make sure they have a good security program in place And I would have do an assessment of them to make sure they're managing it Appropriately. false positives can and do occur You will get false positives was your scanning engine So just keep that in mind. It's going to happen So you might chase a rabbit that doesn't exist It's very possible And yes it will happen. so therefore it's good to have multiple TA ideas and using good scanners will help you with this But I have seen really good pilot paid scanners are highly expensive Scanners do give me all kinds of false positives. So Thai again having a good operator that knows what they're doing will help you dramatically in this space. Oh wasp has a list of scanning tools that are available for you as well. That you can utilize for your vulnerability scanning…Database vulnerability scanning this typically. some of the most sensitive data within your organization is in a database. and so usually their internal M and a that. That's typically what's kind of buried in the bowels of the beast And also because of that it's internal. What also ends up happening is sometimes you don't even know they exist. So very cloud providers are changing this thought process because now we are getting more databases in the cloud, but you need to consider where do these databases reside And in many cases they are tied to various web applications…All right That's all I have for the CIS S P training today, as we relates to vulnerability scanning. so we're going to now roll right into the CIS. P exam questions. This is for domain six…Okay And this question we are going to be talking about CVSs So when looking at common vulnerability scoring system CVSs, When a vulnerability is ranked 10, what does that mean…It's most open for patching a. It's most severe mumbo-jumbo B. It's least severe not a big deal See. Or it's easily managed. Which one is it? It is B most severe right That's the end of the apocalypse, locusts plagues, big asteroids coming from heaven not hemorrhoids but asteroids coming from heaven. Yes that is the most severe ranked 10 that's bad Okay So CVS score of 10 is most severe which is bad…Vulnerabilities. So what tool is commonly used as a scan engine to find vulnerabilities within an environment? A Nessus…B and map…C. Not the golf club, but pink. D DNS. And the answer is don't dun duh A Nessus is commonly used to look for vulnerabilities within a net. to determine if an exploit can be used against the system Nessus Yes I've used Nessus It's a big monster tool It works like a champ. it gives you all kinds of gobs of information but if you don't know what you're looking at it's just like looking at Greek. And honestly there's people way smarter than me that understand that super well. But Nessus is commonly used to look for vulnerabilities and ping is not a set of golf clubs while that is a set of golf clubs but not for cybersecurity. Now if you like to play golf good on ya. Alright. So moving on. All right This is the links we have and I ISC square training study guide Quizzlet disaster recovery journal. Person it certification and O wasp.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Engineering Secure Design) of the CISSP Exam:
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Peerlyst
https://www.peerlyst.com/posts/how-to-start-looking-for-an-infosec-job-my-list-of-tips-evgeny-belenky-1?utm_source=linkedin&utm_medium=Application_Share&utm_content=peerlyst_post&utm_campaign=peerlyst_shared_post
TechTarget
Transcript:
Hey y'all welcome to the reduce cyber risk podcast This is Shawn Gerber Again calling out to you and hope everybody's doing well This beautiful week. We have a wonderful. Thanksgiving holiday coming up here in the United States And so everything is getting prepared for that. It's a great time to be If you like food it's an awesome time And United States. Is one of the things that we actually trust truly crave It's great Yet turkeys you got a ham you've got everything you could possibly think of. On this Thanksgiving holiday season. And for us it's just a great time. The everybody has been doing well this past couple of weeks. And things have been really busy here at Gerber central here in Wichita Kansas. It's been pretty crazy as I've been working with my wife and her business. We've now bedded that down for the season So that's been a good thing And I'm able to spend a little bit more time on reduced cyber risk podcast and creating some great content around the CIS SP. And so as we know the one thing that we're trying to get into more is. As you view. there self studying for the CIS. it can be a bit of a challenge to do that And I've I've just been paying attention to some people that were in the Wichita area that have been studying for that exam. And it's been kind of interesting talking to them. They they've been having some study groups They've been trying to get that. That going for quite some time now. And they've had some good success but at the end of it it really comes down to is trying to self study for this thing can be a challenge So that's kind of the purpose behind reduced cyber risk podcast and why we've put all this together. So today's podcast we're going to be getting to a couple of key things And as you if you have already known we kind of pull out some CISP articles that are on the web, as well as providing some CISP training that I provide through the courseware that you can go ahead and Google that you'll find it real quickly, but there's also the training that I provide there as well. And then finally some CISP exams will be available to you Quite exam questions are there as well So that stuff that you can do to study for for the exam and that's the one thing I was also reading a recent article on about the CISP is that 50% is knowledge and 50% is based on how you take these exam questions. And I will also say though that the interesting part around that is if you taking. I remember when I studied for this thing it was how many questions can I cram in? How fast can I do it And can I regurgitate it as quickly as I possibly can. And then that's changed a lot over time but at the end of it the questions that they provide in the test banks. We'll not, I mean there probably are some that will go word for word but at the end of it, ISC square puts out questions that you can use. The books have questions you can use. And…you just got to ask yourself though. The ISC is not going to make these questions the same. Now they may make them similar, but they're not going to make them the same So understanding the content is really a great way for you to actually be able to to get do well on this test And at the end of it, when you pass the test, You want the CISP certification You want the ability to get a job? And so you're going to have to know this information You can't just go in and take a test and dump it and go, my kids do that quite frequently They would they would take a test and then they would just dump it And then you'd ask them that same question, not too long later And they would go what are you talking about So it's kind of interesting because. They they don't think about the long-term consequences for just cramming for these tests So it's kind of interesting. All right So let's get into our first question Our first. Comment we're going to have today on this podcast and what it is we're looking for the basically around who's how to start looking for an InfoSec which is information security job. That's going to be the article that we're going to go into today. And and what I'll tell you also as we go into this, you can get some, the free videos that I have available out there. Basically domain one through fours but the CIS is P videos The full length videos that I use for teaching. Yeah you can get a plethora of those through domains One through four, I've got to select a select number of those videos out there available. But if you go and you set up for my email list you'll be able to get 11 videos free just for signing up. So I highly recommend you go out there and you do that as it was also on building other various free content that will be available out there. Podcasts the links to those podcasts are all there as well. And so there's a lot of different aspects you can do by just going to the website. If you want you also can buy my, the full domains one through eight video train that's available@shaundra.com You can get all of that there. There's a really good black pro black Friday pricing here in the United States We have black Friday and that's coming up in June Uh on. I think it's in Yeah it's on Friday. This coming Friday. And so you can pick up all of that content right there and available for you And it's awesome So we're going to have a really reduced price going to be basically 50% off of buy more normal pricing. Okay so let's roll right into the CISP articles. This comes from peer list.com and they have some articles out there about what should you do when you're looking for an InfoSec job? How how should you handle it? And. so here's some key nuggets from this article that they had put out there and you can click you'll have the link will be on my show notes So you can be able to click on that link and go to them directly. And one of the key these are some big bullets but I'll I'll add some context to this as well. They talk about don't be afraid to ask questions Now the one thing I've I've done numerous interviews with people because I'm pretty old. I've been around for quite a while And and so when I first did interviews I one thing I was concerned about as the interview E is what should I ask questions? Being on the opposite end of the table Ask asking the questions of people that want a job. I will tell you flat out right now If you have the ability to ask questions please do it It shows that you actually are interested It shows that you have done some thought into this So asking questions is very important. No I add a little bit of a caveat to that. You need to be very careful about not asking too many questions. So it's, it's kind of one of those things where if you get asked. I'm just using this as an arbitrary number you get asked. Three questions are. questions, then you ask maybe one question. I'd say more like if you ask, if they ask four or five questions then you ask one So about 20%. And so you need to ask some question but they also need to be. Ones that have been thought out not like where's the bathroom…You need it and understanding if the job is going to be. If you're looking for benefits or maybe a benefits question would be good One question around benefits. But the questions need to be focused on around the security piece of this And how would you utilize security within their environment And I would ask them key questions based on the role. What is the role of if it's a security architect role? You know what is can you to explain a little bit more about your enterprise and the role of a security architect within your enterprise? And then that have them say some stuff around that But again you need to make sure you ask the right pertinent questions to the right pertinent people. You also need uh you need to specify the list of positions you're looking to move into and which ones do you want to go So if you are. you have your resume and you already applied for a role and say a security analyst role within a security operation center, you need to be. Understanding Those are the positions that are available. You also need to provide technical details about yourself and what you're trying to achieve. And that this comes under your goals What are you trying to be with your goals your, your bio how are you wanting to get there What did you start How did you end there again There? The employer's trying to pick out a, an aspect about you that they can decide Hey you know what I want to hire this person. Now try not to be too pushy And that's what. When it talks about when asking people for help So that means when you're talking to people that are helping you get in the role don't, don't try to push on them going Hey where am I at What am I what's going on How would I how'd I do. Those kinds of things you don't need to be. Pushing onto people. However you need to be able to to ask questions. So it's that fine balance of people skills. There's a really good book that I recommend and it's super thin It doesn't cost much It's like on Amazon for it's like two to three us dollars. It's called skill with people and it's I think less Gibson and it's a really good book on how to deal with people. If you're in it you probably struggle with this And sometimes a lot of it people do. It's a really good book and I'd highly recommend you go out and buy it. If you're looking for an internship. You but you must really first look at what are the companies out there that are looking for interns. It not all companies are looking for interns in the security space so that's kind of an important area to be there. Also you need to connect with various groups on social networks and engage there. Now key a key piece around that is. If you are a social networking person. Be very careful what you post online. Because again people are watching what you do and if you post some buffoonery out there of online, the interesting part is that never goes away. And as a security professional you should know this that when you put post something out there, it will always be there for avert. It will never go away ever. You can contact recruiters Italo agencies. I've done this as well and been in contact with various recruiters. It's it's a way that you can be…basically having guidance around that Now I also would recommend that one way to help when with recruiters. Is to provide value for them If you can look at ways that you can help them. And and help them find new people. That's always positive too So then the recruiters are helping you to find a role. Now as there are over 2 million jobs. That it's always good to have a recruiter on your side because they will help you kind of fish through or our funnel through some of the stuff that may be a good fit for your role That you're. With your background and or others that may not be a good fit…If it's relevant again look at what your what the opportunities are You need to Polish up your English skills It's always a plus and I would highly recommend that you do this Now I've got a daughter who is speaks English as a second language. And the one thing that I have talked to her on over and over is her Spengler English her Spanglish Now that's not a good word. Her English speaking skills and in the United States or in doesn't really matter what role you're working with. The common language typically used is English So if you have solid English skills and you can make those better that is wonderful. It to also also put it in perspective I said also twice. Geez That's crazy. To put it in perspective as well. One thing to consider is that. Do you need to in this role security roles, they are influencing roles They are roles that will you talk to two different companies You talked to leadership. And so therefore you need to be able to. To provide influence on leadership around what needs to occur Well if your English skills are not very good. It's pretty hard to go. And. Provide influence. So that's why we recommend that you get some level of, of increased knowledge around the English skills. Is it totally required No not at all. Like if you're from China and you're only going to work in the Chinese market. And you. don't want to go anywhere else. Well then your English skills may not be as important. But I will say you work with contractors and you work with vendors. And so having a good English skills would be helpful in that space as well. So just just something to consider. The other thing is one of the bolts they had also down there. Was that you should utilize Grammarly. It's a basically it's when you're dealing with. Writing. Uh content and you want to have the ability for it to to tell it's the grim grammatically correct. Use Grammarly to do that. Now I will say Grammarly is pretty close It does a pretty good job however it's not perfect. So don't rely totally on Grammarly. Also as you are understanding how Grammarly is doing things. You you need to understand as well. What is the sentence structure look like So my daughter, she she's really good at leaving off prepositions. Now she's Chinese So that. That that makes sense Right So I I've, it was all funny when I was. up with a kid I could never understand why. The Chinese would leave off prepositions Well in their language they don't have that. And and so I didn't get it when I was younger and I really actually didn't get it until I adopted a child from China. And now has she speaks I see her leave out those key. Uh prepositions and adjectives that. She just doesn't do it She has doesn't do a very good job with it So it's important that as you were studying Grammarly and that you if it's helping you with your. Uh sentence structure that you understand why you're doing that and pay attention to it because if you do it it will go very well for you It really well. You also need to tweak your message when contacting people based on that what's worked best so far for you. And it's always good to have someone that's personally within a company to help you, because again they are. If they can help walk your resume in it's way easier for you to get a job or at least get an interview. Then if you just start blasting people with emails that just doesn't work out. it may work but you may not get what you may not want what you get And that's really what it, what could happen to you So make sure that you build personal relationships And if you haven't figured it out yet in the world of security, Personal relationships are everything. And that is how everything is built here And so if you build those good relationships the good roles will come to you. And then not so good roles will move on or at least you'll have a heads up on what role is good and what one is not good. You mean to use job boards There's various ones that Peerless talks about once they've had indeed Gaudet not go daddy, monster.com. That dice.com is another one that is for more of technical people. And again that's those are important places to go freelance fiver as well. You need to treat your job search. Basically as your current jobs it's like, again I use my kids as an analogy cause I got so many of them I mean I have I have seven children so it. I see things on a daily basis that most people deal with and you just like really. I mean I had a daughter come in a day. She's 18. She made the comment to my wife. She was going downstairs and they were having a bit of a challenge and basically did this. And these are the scales from Uganda. And you know it didn't, didn't didn't have anything and which, which and the United States it's interesting because you don't necessarily need all the stuff that you get in the United States And so this girl who came from Uganda, Walks down the stairs and she goes, After having a little bit of a TIFF with my wife and says you started this. And you're just like are you kidding me? So that a interesting world So if you have children out there you know what. Yeah they're they're great Or they they're fun when they're little and they're fun when they're middle And then then when they get older they're not so much fun anymore So. It's interesting time. And if those of you who don't have children great uses as an opportunity possibly to think of but think twice about doing that. Wait a little while before you do it That's for sure. So again those are those are important things to consider when you're. at a job. Now I'm going to give you my takeaway So Gerbes is takeaway again Gerbes is my call sign I have on my flu B ones, but I give you my takeaway on all of this. You need to work on your certifications. Uh security plus network plus, and then also the CIS. P associate I think it's very important that you get those certifications done. If you can get the certified ethical hacker I think that helps put a different perspective on how you look at things. So those are those are some key certifications that if you can get those I would highly recommend it. Also if you are in the United States you can join the military or even in your organism in your country They may have this cyber forces that are within your military. If you can join their military I would recommend that. One if you use patriotism towards your country but two, they teach you also the skills you will never ever get anywhere else It's very hard to get those skills. And then basically three is join various local security organizations to help you with introductions to people, with getting some technical knowledge around these different aspects that are going on. So those are great ways to get started And then if you go to college or local university in your area that could also help you with depending upon what kind of security program they have in place. But again you get it's not just the technical pieces that you have to focus on. It's the soft skills as well. So those are very important that you get the right books You study the right. Uh techniques and you get the soft skills you need to be successful in security. All right So let's move on next to our C I S. P training. So overview the security is considered basically at all stages of system development So when you're looking at engineering processes and you're trying to divine. Design a secure environment. You need to have security considered at all stages of the system development. And I say this because I do this on a personal basis daily in my job, I am always dealing with security in the various stages from the beginning of the applications creation all the way to the completion and it could be the application built itself. for a specific process or it could be. A already pre-built application that a vendor's providing a for you. And one of the questions that I asked these vendors that bring us products is your your pro your security people do they are they understanding the secure development life cycle and as our secure software development life cycle which is typically called SDLC. Sometimes you'll see it acronym as just SDLC for software development life cycle, and security is considered one aspect underneath that, but that's it should be considered a basically an all does areas of system development. And following the following one I'll throw out there are really some key items that you'd need to be aware of as you're dealing with secure design. Now you have objects and subjects. An object is a resource that used by a subject. So as an example an object would be a computer system that would be an object subject would be basically the process requesting access. could be We call them an RPA robot process algorithm. Or it could possibly be an individual. It could be a service account It could be anything that is reaching in and using that object or that computer system, that wireless router that whatever that might be. Okay So those are objects and subjects. Now the other key point around this is that as we all know security is based around trust and there has to be trust set up between the objects and the subjects. And so as a user let's say a service account as a user. And then you in this in this scenario You know R and D computer system is the object. Well these two must have a trust between the two. The service account and the R and D computer system. Well the manipulate this could be manipulated by attackers in the fact that attackers would come out and they would go after that R and D computer hoping to get access to it And an example of this would be. It was occurred a while back where the Iranians had a centrifuges that were hacked. Using I think Stuxnet. And and so that's those accounts that acted the. Are activated and worked on those centrifuges. They had they were user access. Well there was a service account or individual user's credentials were compromised. Those are user accounts. So that R and D computer system would be hacked by these attackers So these trusts though, are in place Now if the trust didn't exist well then the attackers wouldn't get anything. So that's why it's important that a trust is set up between these objects and the subjects. Some other key terms is closed and open systems. You hear terms about this but a closed system is designed to work with a, in a very narrow range. So we would have typically in the military we'd have a closed environment network. And what you would do is that they would, it would not be connected to anything else You couldn't do anything other than what's inside that system. So if that system is able to hook to the F 20. To fighter, then what would happen is is that system would be connected to it but it would not be connected to any nit internet, any other network shares nothing. It would be a closed system. And it's really defined by the manufacturer So many of the defense contractors will develop closed systems so that they don't get hacked. The problem with this just to keep in mind is that they take a lot more overhead to ensure that they are protected. These closed systems the manufacturers put things in place but they don't always put the level of security in there as well. And and. Again it can be a little bit more. They are not little. They can be. Significantly more secure. However it's just you need to plan for this You need to make sure that you have people that can manage these systems. Now open systems these are agreed upon on an industry standard So if there's an industry standard set up around these particular environments, These are open systems and they're much easier to integrate with other systems as well. There's more options into the network they're less secure, and this would be a computer current computer system that you would run into would fall into these open systems. And in typical networking and typical computer systems are open So…Now there's close and open source code and a closed source code is proprietary code that is set up specifically for your environment. You may have a a. I don't know a lab. I usually keep kind of gonna go back to the lab environment or you built up just a basic application that maybe working as and I've seen this in like visual basic six right So it was really old, but that application works specifically for whatever you want it to do That would be proprietary code. These can be designed for both open and closed systems but what ends up happening is is. They're not always updated because they rely on the manufacturer for those. If they're a home grown system like I just mentioned with the VB six. You do run into risks where they will get exploited by people. And so these people exploit them. And they're never really updated because one person just made this out of convenience made this application and it works and it doesn't get provides what they want. But it's never updated So therefore over time creates a vulnerability. There's good companies around. this space will be Microsoft Boeing I mean you name it There's software development people everywhere. Here in Wichita Kansas we got to an individual We have Flint Hills group which is another company that does software development for all kinds of contractors You name it They're there all over the place. You also need to have techniques to maintain your confidentiality integrity and availability Now if you're studying for your CIS as P CIA is extremely important and there's various techniques by software developers to do this. And basically you can any of the following that we're going to talk about here. Can be used outside of software development as well. But software development is the primary place where this kind of begins. Now confinement. Is a restricted user you process access and actions to a program So what happens as you restrict the user to, or the process to a specific program or a specific action within a program? Now it does allow the process to read right For specific locations. And that would be just you're confining the capability of what it can cannot do. Now the sandbox also can provide some level of confinement You want that? Applications to run in the sandbox And this is where you place these restrictions. On where they can operate and they must meet or operate areas with a higher sense of security. Now, when it comes right down to is this is like an example I could have for you is only a specified systems can operate against a specified database You get very narrowed on what they can and cannot do. They also have any systems outside of the scope will not be allowed So those are kind of the examples that are in place I use this all the time especially when dealing with higher proprietary systems. You want to make sure that they'll only these ones can talk to certain other ones that didn't really make sense All these ones that's not that's starting to sound like my daughter. No, all of this systems that can to only a certain subset so only a can talk to be It can't talk to see but it can only talk to B. Those are kind of important areas to put in place…Now as we get into bounds bounds are defined process is a given specific authority to operate and there can be many or there can be few. I recommend less is more. Don't do a lot Keep it little. Okay. That doesn't make keep it little. That's really strange by English language His skills are not so good today. When it comes into as you get your user you get your kernel you got administrator. They needed to find these processes for a specific capability So if you need this Colonel the Colonel process to run a certain way, then you define that If you have your administrator to run a certain way, you define that. And these bounds will keep them from doing this from doing more than they should. They operate You also have to put these bounds in place for operating systems memory and hardware. Do you want the kernel to be running in a certain format? Do you want it to have full capability within the entire system up and down the stack? Or do you want the user to have that capability? Those are key things you need to put in place to restrict that kind of use. As an example you'd have a malware utilizes errors wince in setting bounds and basically deals with the Colonel manipulates the curve. you see this fruit routinely in the security space that the. Because what's happening as a user accounts are getting locked out pretty well. So now what are they doing They're going after the system or the use or the Colonel accounts to try to manipulate the overall system themselves…Now process isolation ensure that it only affects specific memory locations. These you mean to make sure you you isolate the processes so that only areas within memory are affected. It's a, it's really a part of a stable system And what'll happen with hackers If they're trying to do a denial of service attack. They will go and mess with these processes and if they can cause them to be unstable while then it causes the system. Not work and and realistically, you don't have to nuke the system to make it not a functional You just have to create unstability in it And it will that will do a huge factor in as well. As an example you could have cut paste Copy You would allow those to transition between the two. You can have macros to run outside to find parameters All of those pieces can be available. So it's just something to kinda keep in mind…As you deal with controls. There's also you need to put in place different controls to limit the access to authorized objects. These rules are in place to limit your access For example, file access You may have only. You may have a lot of people have read only, but you may only want a few that can modify. So again those are the type of controls you would put in place to restrict access to an environment. There's mandatory discretionary access controls, Mack and Dak, and these are designed to limit. Access to objects by subjects So the object are limited in And so there are only certain subjects can talk to these objects which we talked If you start at the beginning of this section on the podcast around, and those what these max and Dax are for a Mac is a subject cannot define the object that can be accessed by the user. So. Basically the saying is that the subject can't define what it was going to go after You have to define that for them So that's a Mac mandatory access controls. And so those are already set. for that user. DAC is flexibility with access. Objects can be accessed by the user So the user has the capability to move things around to decide what he wants He or she wants to have access to. So again mandatory it's defined. Discretionary. It's more, it's more loosey goosey It's more available for you to do be able to do what you need to do. And so an identity of a user may be granted greater access That would be an example of Adak and and that in that space would be. It depends on the situation You may want the user to be able to do that. So those are kind of different access controls Mac and Dak and you'll see these kinds of all these questions are all these terms in various formats within the CIS SP exam…All right so let's move on to the CIS. P exam questions. And we've got three questions for you today. And we're going to go through and find out which ones do you think fit? The mole. All right So this comes from tech target tech target had some different options out there and I like what tech target brings from some different CISP exam questions They pull some of these specifically from ISC squared. So the first one. What are the various SDLC development models covered in the CIS is P exam. Now I didn't talk about these today but they are covered in the exam And if you are dealing with development you will have to deal with these in some form or shape or another. So the first one is waterfall. Second or I should say Hey waterfall, V-shaped iterative, agile spiral and big bang. Now these are the different methodologies on how you do development work So…if you've dealt with development, these are all relatively you know these but if you have never dealt with development which when I first took my CISP As P I'd never dealt with that at all. It was very interesting And uh now I deal with development a lot so. I have a development team that works specifically for me. So those are key pieces right So waterfall V-shaped iterative agile spiral and big bang. Waterfall. Yeah it was a boy. waterfall X shaped So V-shaped X shape. Repetitive agile spiral and big bang. C waterfall Y shaped repetitive agile spiral and big bang. Or D none of the above. Okay So the big difference on all that again if you're taking the CISP exam pick out the ones that kind of stand out which ones you have if you don't know then guests…So in this case here I is a waterfall V it's waterfall V-shaped iterative agile spiral and big bang. All right So that is the first question. Second question attempt to take advantage of how the system handles multiple requests. So if there's an attempt to take advantage of how a system handles multiple requests, what kind of attack is this? So you have aggregation is a. B is a state attack. C is a state machine model. D is a method author, author. The key on. I can't even say it Authorization authentication. code Mack. I can't even say it It's really sad. So aggregation state attacks state machine model and message authentication code. Okay So if you're taking the CISP look for some things that may be similar. So in the case of state of tax and state machine models do you know the difference between the two if you don't know what those two seem to stand out as. They're trying to say the same question twice. Maybe it's one of those. And it is it's state attacks…All right So this involves removal of characteristic from an identity in order to easily. Represent in essential properties. All right So this comes down to is a algorithm. B abstraction. C diffusion. D substitution. So it involves removal of characteristics from an entity in order to easily represent its essential properties. All right So it's taking characteristics away. To basically represent what does it look like? So. It's algorithm. abstraction diffusion, substitution. And it is obstruction So you're removing the characteristics from an entity to try to pull pieces out abstracting pieces out to understand the essential properties of that. Okay so that's obstruction. The core of N O S…and one of its main functions is to provide. Access to system resources which includes the systems hardware and processes. So the core of an oh S and one of its main functions is to provide access to system resources which includes the systems hardware and processes. A system kernel. B state attack C abstraction. D firmware. Okay So if you looked at it listen to the last couple of questions, none of those two of those don't make any sense right Distraction and stare attacks that that doesn't make any sense. So you could narrow it down to two system. Kernel is the answer a.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will cover questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Transcript:
…All right Practice CISSP exam question four. When considering the data owner for an application or the data itself, who would be the best owner of the data again, understand what they're asking for considering the data owner of the application or the data itself So you have two different pieces who would be the best owner of the data. You have a CIO which is your chief information officer. You have a CTO which is your chief technology officer. You have your business. or IP owner? Or you have your it organization as a whole. Now So if you're considering the data or the application well the application could be the CTO or the CIO. but the data itself may be somebody very different and would talk about this@CISSPcybertraining.com. I have this video specifically around this where you really need to get the business owner or the IP owner the individual who owns the intellectual property to be able to be the one that can get you the best control of the data and they should be the individual that owns the data. You don't one common…problem that happens within organizations is they will set up the technology people or the it individuals as the owner of the data. This is not a good practice It's a bad idea because it doesn't really own any of the data In most cases they serve up the data. And what ends up happening as well as when things go sideways which invariably they. at some point. Not having it owner or I specifically a data owner defined. Is an important is can can cause problems and can give you a situation where you when issues go bad, they start pointing fingers saying well it had it. And then the it folks go well it's not my I don't own the data. So there's a back and forth So just it's best right away at the beginning When you were setting up any sort of data classification, You need to set up who is the best owner of that specific data? And in this question the best owner would be the business owner or IP owner Again that is question C.
Shon Gerber from CISSPCyberTraining.com provides the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his extensive expertise in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Identity Governance
· CISSP Training – Manage the identity and access provisioning lifecycle (Domain 5)
· CISSP Exam Question – Username-Password / Preventative Controls
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Infosec Institute
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/identity-and-access-management/#gref
Wikipedia
Transcript:
Hey y'all this is Shon Gerber again from reduce cyber risk And we are in this wonderful state of Kansas and the United States and things are great We just got done with our July 4th weekend here in the United States It's actually been a little while but but Kind of want to talk about that a little bit and had a great time over the July 4th weekend. I had some time with the family and my kids just, I love them but they yeah they drive you crazy So if any of you guys if any of you all have children, you will understand that Yes teenagers are a lot of fun and in my case, They keep me popping Like there is no tomorrow. I've got two that just graduated high school and in the United States that's a big event So one's going off to college So we'd be prepping for college here before long, and then I've got another one who's going to be joining us Probably we're going to be starting up a business My wife is. And so therefore with that with between her business and the kids coming into Scala college and between, I have three others and still in school one more senior. it is a busy busy day. and we've. since we have we we basically have four. Or five, seven children total and of that five of them. our four of them have been adopted And so we are, we're very fortunate It also is add a lot of challenges that are a lot of fun to kind of work through. And I say fun in air quotes so yeah but other than that life is good I cannot complain at all. All right we're gonna get into our training and we get taught today We're going to talk about CISSP cybersecurity integration was going to be identity governance Again this is over domain five. CIS is P training is going to be managing the identity and access provisioning lifecycle. This is. The main five obviously. CIS is P exam question will be usernames and passwords and preventative controls. All right before we get started just want to put out a plug out there for the CIS S P training courses You can get these Yes you can. You can get these in your hands or actually yeah Clicking in your hands or in your eyeballs. Yeah. It's kind of gross actually but in your eyeballs you can get these by going to you to me Dot com that's U D E M y.com. And depends on who you talk to Some people call it. some people call it you to me. It depends how you want to say it but it calls different ways but you can go to your tummy.com or you can go to reduce cyber risk.com C I S S P dash training And that will point you in the right direction. four of the different domains Again we have there's eight different domains You can get those at your leisure and you can get access to all of the CIS S P training that I put out. Along with exam questions you can get those as well. and I also put out exam questions during the week and you can get access to that just by going to reduce cyber risk and becoming part of my email team. And you can get all that as well So you get exam questions you get the CISSP. It's a plethora A cornucopia of information available to you at your fingertips. All right let's get going on into our training. Okay CIS S P in cybersecurity integration. The InfoSec this came from InfoSec. This is the reference. Again the links will all be in the back and, and the final part of the presentation or the podcast I should say. And also in the show notes as well So I'll be there and available for you. jeopardy objective five dot three of your CIS SP managing identity and access provisioning life cycle. And then the topic today will be identity governance. Again this is an article from InfoSec Institute…Now managing the identity and access provisioning life cycle This is crucial to have a effective control over your logical environment And when we talk about different environments, You know you have your your basic physical environment and you have your logical environment which is the the aspects around the technical pieces right That all falls within the logical aspect of your specific environment. And these include operational documentation maintenance. Monitoring reporting, access rules roles and titlements maintenance And we'll get into those Those are big $10 words and obviously InfoSec Institute, his a lot of smart really smart people because they I use these big $10 words and I struggle with $10 words but we'll try to make them simple because that's the whole purpose. The C I S S P training made simple. the operational documentation maintenance this helps develop structure provides oversight and how implement the local access controls. So basically what it comes down to is you want to put in access controls and these are logical right? These are all logical controls but you have to have these documentation around your operational things that you put in place. So you have your your basically your it functions but then you have your operational functions that work within your organization that makes the operations the daily day things go. and so you need to have this documentation in place and then this but it does though is this maintenance aspect is kind of like an assessment piece of this where you go back in and you'll provide oversight on how to do this. and these can be fallen or policies that can fall under different areas as well. But it's it's a basically how it flows into the operational…It also establishes a governance model that helps to ensure compliance And we talk about this quite a bit. In the fact that you need to have some governance model in this. And when we talk about compliance we don't talk about the big C compliance We talk about the little C compliance. this would be your, when you're talking to the big C compliance that means you have regulatory requirements that force you to to do these different aspects with your company, to ensure that you meet their compliance of the government regulations. that may be out there and there's those be state and local regulations It could be other aspects to the little C is that you follow the process that you've provided You've put in place to comply with the aspects that you're wanting to. To accomplish. And it also. So that's the whole purpose of it right Is to have some governance around how to help you get that done. Monitoring reporting. This is a monitoring the compliance with policies and standards Now you're just making sure that you meet and you follow through with what you say you're going to do with the policies and standards you have in place. this provides guidance through executive dashboards and reports. So if you can hit get an executive dashboard and it could be as simple as you have a spreadsheet that's got little green and little red and little orange. That's not really. Green yellow Red Yeah. Green yellow red Yeah stoplight thing. there's not much of an orange there. That's kind of a blend between yellow and red orange, but no So you brought up provide the guidance through executive dashboards and reports That's the whole part sorry. Some weight. measuring how are you doing What are you doing How are you doing it? And are you moving forward or are you falling backwards? We don't want to fall backwards We always want a full fall forward. access rules roles and entitlement maintenance. this B. Basically deals with. And you have exception management and you have definition of the rules and how you're going to follow these different rules for the roles. So do you have how do you bring things on how do you take things off? How do you provide provision and de-provision individuals their devices all of that all falls under the access rules and roles. And it basically is the life cycle from beginning to end How do you start it How do you end it How do you decommission it? and if you have that in place I mean honestly, that's a big deal If you can get your access. That whole life cycle piece going and put it in place and start off simple. That does a lot for your company to ensure that it is secure. It is it really does a great job on that…Another key component is operational readiness advisory Now this begins with various stages around your requirements So once those are defined and you have your design your test and you're doing all the operational onboarding that you need to do this is where this begins Right So it's how do you begin to get ready to go And that's the whole purpose of. I'm getting ready for my operational side I need some assistance. I need to know what I'm going to do All right Let's go. And this provides advisory or consultation to the development of these various systems So it's, it's basically the SMEEs the subject matter expert to help you with. Are you ready to go and give you some guidance around that? Some change management also around the aspects of of change management And this is a process of managing the change around your identities and how do your people, how do they get provisioned deep provision That's the life cycle. but then what is the process process for managing the change with those identities So bill who has access to all these file shares. How do you manage his change So bill has access to these files shares but you know what Now Bill's moved on to a new role. it's still in the same area but we need to reduce the level that he has access to. So how do we manage that? They're also it's how do you deal with the communication piece of this at this built into it Can it be automated and ideally in today's world you can automate so much of this and it can be done if you utilize SharePoint or something along those lines. They it can be. automated within like not Infopass not the right word but flow flows It the product they use now with SharePoint online, you can provide this change management advisory piece to people. and that can be really simple It can be set up in a simple format. That will give you what you need. so again that that's changed management advisory communications…Now as you're dealing with identity operations this includes the access review and reporting and this is access request fulfillment and there's. many other aspects that around this. And this function is focused specifically on your day-to-day access control requests. This is your provisioning your administration all that maintaining maintaining of the life cycle that's associated with it. enforcement of logical access controls is another key component of your identity operations. and again this is the day-to-day stuff This operations is your day to day. Get dirty, get in the weeds kind of thing. and then so that's the whole purpose of that. And in rules are related to ID access requests approvals and so forth. So you have these rules in place to basically deal with your identification. And also anybody who may request access to your specific systems. again this is the it's all responsible for the day-to-day ops and it basically it allows you to provide the capability of bringing people on taking people off. And that's your identity operations function That's kind of what they took called about out there is that you basically need to have governance. Day-to-day operations and you need to have some way to. Deal. the life cycle. That's that's how it all works Those three pieces will go take you a long way. Okay So that is the discussion around from InfoSec Institute. Okay And we're going to move on into the C I S S P training. Okay So in this CISSP training part we're going to again talk about five dot three managing identity and access provisioning, lifecycle domain five So this is going to be a supplemental or. That part that we We saw before a little bit of a supplemental of what we're going to be talking about today and the rest of this podcast. And the basically this refers to change management of accounts So again we talk about creation deletion and management of these accounts. one of the key points is identity is the most commonly used user account So you are you. Basically we're trying to get identity of individuals. And so that's the main part of all this it's the most common part of a user account is how do you identify the individual who they are? are they the right person That's supposed to be accessing it? do they have the right credential? and the ability to do their job. All of those things are part it's the most common part of a user account specifically. Now when you're dealing with access control administration. There are three main pieces that you need to be aware of. One is provisioning. The second is account review. And then count revocation which is basically. The deep provisioning or the turning it off of the account. and and again I will I will tell you I apologize Sometimes these a these big $10 words. I try to make them simple. and so therefore they they use big words but then I'll go to some easy one Like yeah you just had to turn it off and And so it there's a, I will struggle And if you're working on your CIS. With the cybersecurity, career. Here's one thing to keep in mind as you're moving forward. And this don't mean this to offend anybody at all That is not the intent, but it's a lot of times cybersecurity individuals will put these big $10 words out there and they will say big monstrous words, in the thought and hope that it. them look way smarter and then they potentially maybe are. And I'm saying that they're not I'm just saying that a lot of times I've seen this in meetings a lot. Where people will use big $10 words and I am totally confused going what the Dickens are you saying? just just use third grade language I can understand that because it's all I have from a knowledge standpoint. And and so therefore, sometimes I'll use a big word and I'll say it out there and then I'll try to. Bring it down just a little bit because honestly I, I get confused then. Then if I'm confused I only assume that maybe only about 10% of you all are confused, just because you all are probably way smarter than me. so just kind of keep that in mind as we move forward in the C I S P training I challenge you to look for the big $10 words, and then try to make those simple, because here's the point. If you're going to be a Cisco or if you're going to be someone that's going to provide influence for your board or whomever that in your cybersecurity field, you need to know how to do this. You need to know how to break down the $10 word. And put it in terms that the, for a third grade level. Not because you're dealing with third graders because that's not the case So that's one thing The other thing to think about as a cyber I'm on a little bit of a tangent here but. That's one of the things to think about as a cybersecurity professional is do not treat people like they're third graders do not Okay Because I'll tell you right now, most people in, in the world are there's people that are way smarter than all of us Right. and then but if you can talk to people at a level that is easily understood when that's why I say the third grade level because if you can talk at a third grade level to people that's easily understood by most And so therefore if you're talking to your CFO your CEO, any other C levels? You know the board whoever that might be. They're going to want you to talk at that lower level Not because they're stupid or they don't know what the heck they're talking about. It's because it's a language that everybody can understand when you get these big $10 words that are out there. It your $10 word in cybersecurity is very different than the CFO's $10 word and financial. Terms. And so therefore it's important that you bring it to a level where everybody can under. All right. Yeah right We've had a little bit of digress there but the point of it is is just keep it simple, silly. All right. So again provisioning. Account review and account revocation or deep provisioning or turning it off…Provisioning So there's key points about this is creating the new accounts were privileges It's important that you keep it as simple as possible. Do not over-complicate this And I am guilty of all of those of making it way more complicated than it needs to be, thinking And this kind of comes down to the development space where you create this complicated thing Thinking you're going to add features in later on You never really do in all these features ever do from a development standpoint is cause risk. so you need to keep it simple as possible follow specifically defined processes and procedures. If you don't have the processes and procedures defined then define them and then follow them. But keep them simple and then you can move on You can grow onto these simple procedures as time goes on. Oh you need to have a way to confirm the identity of the individual It would be photo ID HR security clearances whatever it might be You need to have that confirmation of their identity in place. this concludes all users contractors employees and so forth. Now sometimes it may be as simple fact that. Who confirms that identity you may rely on the HR person to confirm the identity of it. but you need to keep the process as simple as possible. if it's you that's doing HR and doing a provisioning and everything because you are the person that's, that's going to be doing that. Then obviously you've got a lot to do, but again keep it simple as possible. And keep it the same process. If you have compliance issues to consider as you have PII or personal identifiable information, then you need to con you need to adequately protect that. that also could be, personally identifiable health information as you're dealing with those. Questions as well. So you need as a cybersecurity professional especially studying for your CIS SP you need to understand those key points about this. the China the birth name that's another good issue Is that in China privacy aspects what is the birth name of the individual? like in my daughter's name was you know, okay I mean I can't think of her name. That's not good or Chinese name? Well I'll go with my son So his was a Molly Jo. So that was a Chinese name but we call him Jax. Jax J a X Gerber right That's his that's his name And therefore, his middle name We call him…But in China he was. my wife. As what he was. Actually his middle name's…Somewhere around there Yeah. Anyway, that's the whole purpose around him. and so those are different aspects that you got to be aware of as you're dealing with compliance issues. employees contractors that you need to have way to for them to sign documents as well. how do you confirm that So if they haven't used DocuSign or some other doc document signing technology, that would be extremely valuable…Now your ongoing maintenance around this piece is your. You to audit the accounts you need to provide and, and the access to these accounts you need to have the ability to do that. the process for promotion departures. Based I imply in Berta employee…I can't even say it. Employee transfers you need to keep all of those the same. the the whole new process of anything that you deal with somebody that enters the role or leaves a role you need to keep that actually the same as well. so again these are employee transfers and an ongoing maintenance…Now you're dealing with account review Some other key points to keep in mind is these need to be reviewed periodically. Do not rely on the fact that these are just going to set them and forget them kind of thing. That's where credentials get added in where they'd never go away. I've…seen it in previous lives many many times where I would actually go into a when I was doing the…hacking world, I would go into an account R into a environment I would see if there was accounts that had been there for seven eight years and asked the question was this person still here And the person hadn't it kinda hadn't been used in seven eight years. As I know that person's left but the account was still there act and active. It wasn't even the point where it was turned off it was still active. So you need to have that set up and you also need to ensure that the policies are in place to address audits. now we talk about audits that could be audit or they could be an assessment. Audit typically a formal type of thing is done usually by a third party or at a minimum and outside. Resource either within your company that is specifically designed to do audits or it's actually a third party that, that maybe you have it's a sister company, or it could be a company like E and Y Ernst and young or Deloitte or one of them to do an audit on you…you need to have script you can have scripts to run audit reports on your accounts. so hence no activity logged in for 30 plus days et cetera et cetera. You could have those in place And so those are ways you can look at your different accounts and how to review those. privileges There's excessive privileges You need to know as far as that goes to do someone have more privileges than they need to have. And how do you manage that? do they have the necessary privileges to do their role Do they not have the necessary privileges And do you have a process in place how to add them privileges in easy format? I'll be honest If you can do this, then you're really setting yourself up Well I will say that many of us struggle in this space just because it's there's so many things to do And these are one of the things that gets left behind and it really needs to be one that really needs to be the top priority. privileged creep in the case of individuals of how much. Our Creek how much creeper do they have No, it's not a much They're creeping. It's how many privileges do they have So if you have privileged a and then you move into a new role now you have privileged B, but you now because you move to the new role you have privilege a and B. And then when you moved to a new role you got privileged a B and C that's privileged creep That's a little bit of this a little bit of that And next thing you know you've got a lot. and then audits will help address this as well. Now you need to consider the principle of leaf least privilege What do you need to have to get the job done Do you need it all Well no Okay So in the case of myself I have. Typically, if you're a cybersecurity person you should not have admin rights. You just shouldn't…especially if you're dealing with if you do, because you are the only person left, then that's one thing but then you also need to make sure that you do not use your admin rights obviously for surfing the web and doing those things. I in my role I they they've asked me said what do you want Admin rights I do not see any need for me to have admin rights. the simple fact of it is one. I'll just mess things up to, from a targeting standpoint I'm probably targeted a little bit more than some people, so therefore I don't want to be increase the exposure so I don't have that stuff And I just rely on other people to do that So again the principle of least privilege…Account revocation So someone would pull an employee departs or leaves. This is I E leaves terminated resigns. they depart the fix Okay That's flying term. Depart the fixed and they leave to a different location. that is when you want to have account revocation and you need to have a process in place to address these departures. if you don't not have a process in place to address these departures. Yeah that will be bad because what happens is these people never go away. And then then they're on your books for ever. Okay And if you can tell me the movie there's a bonus question in there for that. For vert. All right And then that's what they're here forever So that's you need to have a process to address the departures I had a lot of coffee this morning Holy cow I'm ready to go. HR is usually the ones that are most connected with account revocation They know who is coming and who's going. And so HR needs to have the ability to to. Basically clean this up. there's an account removal process and there's the account are removed immediately after leaving. so once a person leaves the area then the accounts are shut down and they move away. you remove access is disabled for a period of 30 days and then you delete the counts After those 30 days are over. so those are kind of the process and you need to have that automated where once a person leaves account is removed immediately after leaving So or it's put into a standby mode per. at a minimum. And then you remove access that should be disabled for a period of 30 days So access is denied and you hold onto that. And a lot of times. will hold onto these accounts specifically for a reason that there may be. Documents that they need to get access to. and so therefore it's important that you look at those documents You have your supervisor. Visors look at the documents with those credentials for a period of 30 days. You then go ahead and you can pull out that information Now, once that's done and you have that set up and the credentials are revoked, then at that point in time you can delete them after another 30 days So basically it's a 90 day process. As what kind of well in this case it's 60 days of what I've got called out But as soon as they leave there the counselor the access is removed is disabled I do that for 30 days Once that is done then you go ahead and delete the counts After 30 days, sometimes you may set it up. We may leave access for this thing for a period of a week maybe. but the problem is is when you leave access accounts still active. I've already seen situations where an individual has made backdoor for themselves. They've logged in, from a remote capability And what ended up happening is their accounts are still active and they went in and they caused all kinds of mayhem and destruction. Now granted that was a really stupid idea. 'cause he ends up going to jail for something like that But at the end of the day don't do that. but you should that's why you should remove those accounts access immediately after leaving…Some other additional precautions you're gonna have is audit it personnel with elevated. Permissions that is a big deal So it guess what they touch almost everything and having them with elevated permissions, God permissions. is usually not a good idea and you need to audit those people to make sure they're doing the right thing because they all do have gone prevent for her permissions And so therefore I should say all many of them do. And especially when you start dealing with domain admins and so forth you got to audit them to make sure that they're doing what they say They're not surfing the web with their domain admin credentials. high risk employees your R and D and your senior leaders Those are also ones you need to audit. just because they are typically targeted from a cybersecurity standpoint. hackers will go after these senior leaders, sometimes. they do after him because they have a little bit more information that they wouldn't normal people like myself wouldn't have. So they go after them R and D is because they have intellectual property knowledge that they may go after them as well. So those are some consider. And then the cybersecurity leaders they will go after them as well Because many times they have the list of vulnerabilities that are out there So as working on your CISSP and your cybersecurity space, you need to make sure that you are connected with that. All right So that was all about the CISSP training We had set up for this podcast We're now going to roll into the C I S S P exam questions. We are not talking domain five of the CISSP exams. All right And this question, we're going to get into usernames and passwords. When looking at user logs, the purpose of the username and password provides the following. Which one is it? A identification. B authentication. C accountability. D. authorization. And the answer is. A username It ensures that the correct identification is used when accessing the account. So you want to understand that it's important that you have these you correct username when they're accessing this. And as you're dealing with logs it's also important to ensure that the username is connected because what ends up happening is is if you don't have a username, it's pretty hard to get. And we talk at non-repudiation good $10 word basically. The, and that's a good word It's a really good word too to make something a sentence a little bit more simple but you want to be able to prove that their hacker actually did what they said they were did. And if you don't have usernames or. You don't know who actually what was the account that actually worked at So it's important that you have the username available. And these logs to ensure that you can track it all back to the right. Username or the right device…Alright this question preventative access controls. Which one of the following is a preventative access control type. A CCTV. Me. Matt. checks. See. Mantra. And track. I like that My trip. the none of the above. Which one of those is it preventative preventative access control. See Oh man traps are considered a preventative access control that will limit individuals from a specific facility. CCTV is there and available so that if you want to. And usually the CCTV honestly, there's nobody really, in most many cases, 24 by seven viewing of CCTV does not exist. So therefore it's important that you understand. That's usually a control it's after the fact a background check again is done beforehand and usually it's before the person even enters the area. And then the mantrap is really designed as a preventative for a facility So you. If you're not familiar with a man trap is you walk doors open up you walk in doors closed behind you, and then if it validates your identity it allows you in If it does not it says you are not leave Stand here until security forces come and get you. so yeah there's and then they they're also watching for if you carry your buddy in, carrying your buddy into into a facility. And your back. They have pressure plates going okay this guy weighs 450 pounds. He's really either really big or there's two people. So that's something else that they keep in mind. So th those are again those are preventative access control type is the mantrap. All right So that's all we have for today's podcast These are the links ISC squared training study guide Quizlet, InfoSec Institute and Wikipedia.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Marking of Sensitive Data
· CISSP Training – Protection of Sensitive Data / Labels
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
…Hey all is stronger with reduced cyber risk podcast Hope you all are having a great week This wonderful week actually is since this podcast gets started all of these comes out on a Monday so you're probably just weeks getting just getting started So I hope you had a great week last week. things are going great here and wonderful state of Kansas But outside of that, It it could be better So I hope everybody's doing well and getting ready for the 2020. it should be a great year for a cyber less for sure Especially if you're working on your CIS SP the 2020 it looks like it's just going to be absolutely amazing And it's going to continue to grow and be pretty cool. I was reading an article just a you think it was two days ago and it was talking about. What are the biggest threats and trends for 2020, as it relates to cybersecurity And one of the aspects I should say The other is like seven different topics they had on that. articles specifically and they focused as a five of the seven focused on cloud. And I fully suspect that that's going to be a huge issue coming well it's going to be forever. but especially in the next few years, As people are getting smarter on the cloud is how is it secured and what what are some of the mechanisms that are in place? And so I I've learned with our deployment or with a deployment I've seen with the cloud in my company, that there's a lot of knowledge that needs to be learned. including myself on how much that I don't know And it's really it's been an eye opening experience of trying to work through everything Cause the thing you have this standard foundation with cybersecurity but then when you get into the cloud there are different aspects that will nuances that. in the past you'd have one server could get compromised Well now if you screw up some pretty big aspects that almost anybody can can configure, you could basically compromise a large swath of whatever you put out there So. There's a lot of nuances to it It's gonna be pretty cool I, I at least from my standpoint I like to learn so it's going to be printing kinda neat, but. Well so what's rolling today Today is episode 54 understanding and supporting investigations. And this is going to be domain seven of the security operations piece of this So there's a couple of different articles we're going to come out here And this is one that…people kind of struggle with a little bit as it relates to investigations because you don't really know and it's, it's kind of that legal stuff And how do I handle all that? And this has been, an eyeopening experience for me myself. in the fact that I've had to deal with various other evidence or I should say investigations on activity that's occurred within, various companies and things that I've worked with from the military to my current A company that I'm dealing with right now. And and so it's it's been an interesting thing that I never really expected or anticipated. But if you're going to get your CIS is P one of these are key aspects you need to understand and know the other piece of this is these, the information that I'm going to be going over today is also extremely important. with your career in what you're going to do for other companies. Because the simple fact of it is is that you as a cybersecurity person will be looked upon, in most cases as the person who understands how to deal with cybersecurity evidence and and how to manage it And also you're probably the first person on the scene when the event occurs. So you need to have a good grasp and understanding of what are some of the expectations and what are the pitfalls that go into not doing a good job around this. So let's get started with our first with the online aspect of this and and the article that I pulled up that I found out there online was from InfoSec institute.com And they're talking about Security and how the investigation support the requirements. that the again the show notes will be in the website and you can go check those out at any time. All right So for this was from InfoSec…there they talk they break it out As far as infants. I came and said the word evidence collection and handling. And to kind of break down What does this actually mean Well evidence includes facts items and information to be presented in a court of law to establish the validity or invalidity of a claim or statement. So when you're looking to collect evidence around a cyber security event that occurred. You are going to have to present this. two. It's not going to be like a court of law where you have all these people around you I shouldn't say it won't but it highly unlikely that it will it'll most likely be to a judge and some lawyers that you'll deal with on this statement. But you have to be able to present this sort of information. To them the evidence in a factor in a manner that proves that you just they actually have a case. versus you just looked like a blithering idiot and you have no idea what you're talking about So you're going to have to provide that information in the event that there is an investigation. the evidence is used to prove a person's eye. empty of innocence or guilt Right We know about that. But when you're dealing with cybersecurity pieces of this you really need to have a proper chain of evidence. And that is. It may It's exactly what it sounds like Right You have the…evidence that kind of leads you down the path and points you in a direction. Now this evidence will be more. When I deal with computer security pieces and this is something to CIS is people will probably chat around is the fact that computer, evidence is typically a. circumstantial evidence It's not it's not something that's hard proof that you must. If you have it you are gold rock solid You're going to win no matter what. No because computer evidence obviously it can be tampered with at some point. And so therefore they don't consider it as the rock hard status of evidence that you have to have to put to make the case open and closed. yeah. That's what open and close right where it's basically it will happen Right You If you present this evidence, the game's over we win You lose Done That's not going to happen with cybersecurity or with computer type of evidence, just because like I said before it can be manipulated. Now you're going to have to put out there as far as when you're dealing with the chain of evidence, how it was collected. How has identified and how it was protected That's a key point What did you do once you got it? And how did you protect it? How did you keep it from somebody actually getting a hold of it and messing with it? You also have to break out. And how it was conducted the the whole overall investigation that how will the data was copied cloned What what was that done One of the things to consider what the CISSP is that you should not, be manually. Copying this information over, you would take an a copy of the device and image of the actual. device or evidence itself. So if it's in an operating system you would clone that entire box You wouldn't just go well Hey I'm going to go in here and cherry pick out. Where's the evidence that you'll hear the log files that allowed this to occur. You don't want to do that That that will cause you all kinds of grief down road and what'll end up happening is they'll probably throw out your evidence because you just cherry picked what you wanted. so those are important things to do. And you also got to present how is it presented in court and by whom? So I say this in the fact that why do What are lawyers get paid a lot of money Well it's drama it's theater. And they're putting on a case. If you bring in like the computer nerd that just can't even see straight and just can't put a couple sentence together kind of like this podcast at times. then what's going to end up happening is is there that's going to cause doubt on your overall case. So you're going to have to have someone who is articulate and knows what they're talking about as presenting your that is acting as a witness for your case. so those are important I was talking to a guy that. w is a CSO within our company and he actually sits in. he gets paid to go in and present evidence in courts for P for companies. And the reason is he's a he's an expert on this stuff on this technology. And therefore he is pulled in as an expert witness who can talk to these aspects and because he can talk at the third grade level to people. then what ends up happening is he gets called up a lot to go do it. So there's opportunities there If you ever become a once you get your CISSP and you get into the space and you have some more education and are not going as education but experience, you potentially could be an expert witness. So anyway that's that's all that. So the the pro the other thing is they talk about here and InfoSec Institute is whether the property has been returned to the owner After the investigation you have to define was the, was it brought back to them Was it given back to them? Those are things you'll have to call up…Now when you're also some other aspects around chain of custody is who obtained the evidence who secured it. Where and when was it collected? The basically the wherewithal. Y kind of thing. You gotta be able to call that out and be able to state what that was. now in the case of the evidence storage is typically. in some locked environment. and you know vault or some sort of safe that kind of information that kind of place was where you typically store. this kind of information you wouldn't just leave it in a. huh. A drawer in your desk? Probably not a good idea. an encrypted thumb drive that can walk off Not probably not a good idea What even better into just a thumb drive but that's not encrypted. those would be bad things to do. when you're dealing with evidence you should make sure that it's labeled correctly and then it's protected IE within some sort of encryption, mechanism to ensure that it is not tampered with. And then it also must be conducted with identical clones We talked about the fact that you should have an identical clone of the system You should not just copy the information off of this information. Now the one thing else that you should consider is that when you are messing with the data it's important that there's monitoring occurring and recording what you're doing, that the court's going to want to know how you did that So you can't just say well Hey, I magically found these logs They just kind of show. up one day I don't know where they were before but they're they're here. no that that won't work. They're going to look at that and they're going to frown on that pretty quickly and probably get you thrown out So, the need to make sure that it's recorded monitored and managed, and those recordings are actually available to the court. if they want to have them. so and again it must be presented in court accompanied by testimony and opinion. Those are key pieces around that as well So, those those are all aspects around the chain of custody piece of this. now the other thing that they InfoSec Institute brought out this bullet point is that the property must be returned to the victim after the trial or security story. If the perpetrator is found guilty of a client crime that claim. Is that climbing a mountain, a crime. the perpetrator will forfeit his or her rights to the property in such cases. So not guilty You give it back. If they're guilty they lose access to it. And then they go break big rocks into little rocks So yeah that's our it's a white collar crime They'll probably just go sit at a resort somewhere. drinking Margarita's and relaxing. no that's not really necessarily case but it kind of see that in movies sometimes. Alright reporting. So the reports must be complete detailed and high enough quality to be accepted in a court of law. So you got to provide some level of reporting on this stuff. And so there's something else to consider is that you if you have bad English, okay. It's probably just butchered the English language right there. If you have bad grammar bad English you don't know what you're talking about and you don't know how to write a sentence together, then you probably better have somebody else file the report for you Just just saying it might not be a bad idea to do that. it should include some of the following things. basically how you got to where you are at what was the forensic step and process them What you got to where you were at. copies of your standard operating procedures Again you must have things documented It can't just go. And off the cuff and make things happen. a copy of the checklist that are used for the investigative process What are you using to get there You know step one. copy. Files step two I encrypt files step three So on and so forth. And again you got to have to put this in the third grade level. I don't mean that people are foolish And it's I've said before in some of my CIS is P training. The ultimate goal is to bring this to the third grade level. And why? Because the fifth grade level people can't get it because if you ever play the game you know how are how smart are you or. Who's smarter than you are a fifth grader. most fifth graders are pretty pretty intelligent. Third grade Yeah You can probably talk at that level. Then you're probably going to be okay Most people will understand what exactly you're saying. So it's important to do that. you also need to make sure that you have the you're again you're using the right tech. Technology or terminology and talk in a layman's terms. one thing also you shouldn't deal with when you're dealing with logs make sure they are timestamped on when they actually were taken. Again, all of these things could be manipulated in the right situation. But it helps build your case. Now when you dealing with different techniques you you basically it's important that you have some level of techniques in place to ensure that you get this And this comes down to, forensic principles must be applied to all digital evidence. Evidence must not be altered during the collection phase so on and so forth. you you must make sure that that is and that would be followed up by a checklist that you maybe you have on how do you actually get to this point? I would highly recommend that you don't on your first investigation, especially if it's dealing with something with any significance for your company, you bring in a third party. But when I say that is then you get smart on how does that third party do it? Now if you have time and you haven't had an investigation, maybe it would be wise to go. Find a friend and talk to somebody about how to do a proper investigation. Around the it space and the cybersecurity space. And if you even if it's a regular investigation for criminal investigation such as murder robbery whatever. That same processes can be used. it's just smart for. at working on your CIS As P to be able to understand these pieces of this. All training must be provided to anyone that accesses this digital evidence So if you have someone, the lawyer that needs to access it for whatever reason, you have specific training in place to help them how they access it. I would also recommend you put this data If somebody does need to look at it. You put it in an environment where they can not manipulate it or do anything to it kind of like its own little walled off garden. that all they can see in but they can't touch any of it. I think that would be very important just because, and if you can prove that in the court of law that you did at that situation, that would be very valuable. it must not be altered or the collection phase of the investigation must talk about why, how you didn't alter it during the collection phase. personal that are in possession of evidence or a spousal for it until it's back into storage you must be it's a check-in check-out process Once you have it and you check it in. You are responsible for it until you check it out, then you're responsible for it till you check it back in. and then all personnel entities must be fully certified to work with evidence If the chain of evidence is to be preserved. You got to have a process they gotta be certified They've gotta be trained. You can't just go do it Willy nilly. So you know, it's just got to have a process behind this stuff. So. forensics there's some key aspects around this We got money. I mean it's four in the morning I'm a little tired Sorry. It's media analysts analysis. This includes the analysis of components such as Ram hard drives optical media USB SD cards all that stuff You must have some way of how you analyze all types of media. If you don't have that capability outsource it. it's just important to to have it done right. I will say for investigations that I've dealt with in the past that have been small. I've taken care of those but if they've been of any significance that I think could potentially cost the company a lot of money, Even from not even financial just reputational aspects. I will call it a third party just because…it's better to have that third party who has the quote unquote air quotes. Unbiased opinion about things that can potentially testify in court. What would happen is is that if I went into testify for my company in a large situation, Because I'm the sole investigator. It would probably be looked upon as a not as trustworthy of an investigation that I'm looking in the best interest of my company. So I would highly recommend you bring in a third-party to help you with some of those things. Network analysis is carried out on equipment such as routers modems firewalls all those kinds of things Now the interesting part about this is when we started off the podcast is AWS. Same concept can occur in AWS However, it's not you don't physically have can't physically touch these things Whereas in the past you could physically touch a router You could physically touch, some sort of media You could you could go grab it and bring it and put it in storage. So adding it to the cloud but as a little bit of level of dynamics that I honestly I'm not totally connected with how. I mean the process would be the same. But then I think there's some nuances that you would have to kind of think through And it's probably good to think through those before something bad actually happens. Software analysis, you would potentially have some level of analysis on the software depending upon the situation. And that would come down to, evidence of act. Tivity within the, within the software log files timestamps metadata anything that would add some level of, ability to the investigation. You should consider that when you are looking at the investigation from a software standpoint…Now there's some other factors to consider as you're dealing with this And some things that you need to know when you're, looking at investigations for the CISSP, there's basically four investigation types that are covered in the CISSP and they should be understood by individuals that are taking this test And that would be operational criminal, civil regulatory and e-discovery. And those are the different types of investigations that you will run into especially taking CISSP and you may end up dealing with one or more of those. Once you start working for a company. Now there's other factors to consider as well. And we kind of talked about. What are those yet Electronic inventory, data retention policies recovery data storage data ownership data handling. And having key people tied to all of those. I think is extremely valuable when you're dealing with a, investigation for the data. Okay So that is all of that article had about InfoSec institute.com this is in this episode. Episode 54. You'll be able to find out all that information that you need to be able to be successful or at least at a minimum, understand how an investigation can be completed and what you can do to better do a better job with it. All right So now I'm going to roll into the CISSP training This is based off domain seven.one of the CISSP and the objective seven route one understanding and supporting investigations. And so lot of the things like we talk about in the, the podcast is that you, you will get the information. that will kind of go over to multiple times and the purpose behind that is the fact that, I mean I don't know about y'all but I struggle with just remembering something once If I hear it, if I hear it I kind of reach a little hard back into my back of my cranium to figure out did I really remember that after I hear it three or four times I start to get it. But the, the rule of thumb that I've heard whether or not this is true from marketing folks is that you have to hear something set here or see it seven times before you actually make a move on it for. Buying stuff right So now that we're in the Christmas season. So the question consider is as as you're listening to this reduced cyber as podcast some of these things I go over routinely, they may seem like well Hey dude you just went over this again. there may be a new a different nuance to it but at the end of the day, the more we go over these things the better off you are And when it comes time to take the test. Okay. So when understanding the supporting investigations there. some key aspects which we've talked about with evidence collection and handling. Proper collection of evidence is challenging We've talked about that and what, what you have to deal with and it can surely should be only accomplished by professional technicians. Now that could be you. once you are done with, well you could, I mean obviously when you're dealing with your CISSP you don't have to have, you can be doing this right now as a forensics person, and you probably are people out there doing that who is studying for the CISSP. But if you might want to consider if you have an opportunity especially if you're working it within an organization is go find who could be doing this sort of collection for your organization. Now also to think about if you're the CIS if you see. If you're a maybe the sole cybersecurity person or the sole it person for your organization, start understanding how this would occur and cause you it's going to have to happen as if it does occur You're going to have to visit with third parties and knowing the same language and the same lingo I would be extremely useful in the event. of a incident. So it just kind of considered that. individuals collecting evidence need to be trained on handling, getting the document this train this needs to be important. and proper handling can jeopardize legal cases and it's really really can't. If you don't. have a good case because you did a shoddy job of collecting the evidence. the only person that followed this. Oh I should say the only one of the key contributors to the failure of your case would be potentially you. it's always best to work on a copy of evidence I don't say it's best I say you must, unless there's some reason you have to work on the original, you should never really work on the original document There might be some original data. There might be some reason behind that but at the end of the day, I would stay away from that at all costs. when you're dealing with a media analysis identification and attraction of data is extremely important And this could be media from a device USB stick, digital optical drives. You name it anything that has potentially has access to this data? network analysis This depends much on prior knowledge of the event. it could be various logs porches IPS flow logs firewall logs You name it. So you may have to put a sniffer on the network. to get some of this information as it was going maybe you have a suspicion that there's something going on and maybe you decide to start collecting the logs before an actual event. you may want to, that would be an option to do that as well. when you're dealing with software analysis understand backdoors logic bombs or other vulnerabilities that could be potentially in your software. And you may need to review review the log files of the application for a better picture. Now here's the gotcha with that. Not all of the applications that you work on will have log files I've run into this numerous times where you think they have log files but ah no they don't. So did something to consider I would have a good understanding of the lay of your network. Or of the applications that are in your network way before you need to know that. So something Something to consider on that end. hardware and embedded devices computers phones tablets. Again you may want to have. an expert look at that Now there's various software out there that will help you with your phones. but unless you're a forensics company unless you work for a forensics company most most of most of this. Software is pretty expensive and you wouldn't just typically go out and buy it just to buy it. I know that. The phone software for doing forensics was around 10 to $15,000 a few years ago when I was looking at it Cause I was thinking of opening up a, starting up a business that dealt with this. And then I looked at the legal aspects of. Yeah no I don't think so That's something I really want to get into. when you're dealing with reporting and documentation all investigations need to have a report and the report type will be dependent on the organization's policies and procedures. There's something that if you don't have good policies and procedures in place that also is going to affect your case. and so that's something that I've kind of realized myself in areas that I need to work better at is have a good. situation around policies and procedures. The final report does lay the foundation for potential legal action So again, you gotta know English gotta be able to speak it Gotta be able to. it and it's gotta be discernible at the third grade level. it's imperative that you build relationships with legal counsel. I would do that ahead of time Do not wait until your investigation has occurred. I've been very blessed that I have some really good relationships with some legal counsel. and over the years from when I was a hacker and then also through working through the various enterprises, I have a good understanding and I should say a decent understanding of the legal side aspect. But I have some really good relationships of some awesome lawyers and that's that's extremely helpful. And they talk about it here about building relationships with law enforcement. Something else to consider as you may want to do that. I mean because here's something here's something to think about. So I live in a very small town in the middle of rural Kansas, but I know all the police officers not because I get picked up but because it's small town and they're good friends. So in the event that there would be something bad that would happen locally. I actually would have to start opening investigation with them first. depending upon if it was my company in my small town. So that was something that you may want to build those relationships with them. not get picked up on speeding tickets but at least build the relationships with them ahead of time in the event. That you have an investigation at some point. depending upon now also to keep in mind is when you're dealing with the FBI the FBI will they're law enforcement but they're not the ones that you open up a investigation with locally. You would do that with your local law enforcement. FBI also is not going to help you mitigate any issues They're going to help find the bad guys that did this to you, but they won't help you resolve the challenges you're dealing with So don't look to the FBI to help you. They they just they won't. So when you're dealing with investigative techniques, conducting computer security investigations you'll need a team and then you'll have to follow some sort of incident response policy. That you have in place Again this comes back to the policies and procedures that you have documented. You need to have an incident response process and policy in place. And you should follow it based on your policy So you follow the investigation based on what your incident response policy is saying And then when you do that, what'll end up happening is you will. You're going to build your case in court to make sure that you're doing what you're supposed to be doing. You should have rules of engagement on how you do this how you call in law enforcement who calls in the law enforcement. You don't just have somebody arbitrarily call it the police officers. You may want public affairs involved to do that I highly recommend that. Do not. just go you call them, you need to stay out of the limelight as much as possible with this. You want other people to do it? Whether it's the president the CFO CEO. someone who's wanting the C-level suite people public affairs. They need to take care of this not you, you are the boots on the ground and getting them the information they need, but you should not be the face of this you you want to avoid that at all costs. When you're gathering evidence there's three options You have voluntary surrender subpoena or search warrant Those are the three options that are available. and against voluntary surrenders you provided on request subpoenas a court order by law enforcement and they give you enough notice saying, yo dude you need to bring this data to us please. if you don't then you're in bad trouble or the search warrant is the one just knocks on your door with guns blazing and they say give us her stuff. Okay. but again they have to have credible evidence and a judge needs to approve it unless you're in the United States then you don't need any sort of approval They can just go and lie about it and get a warrant. So that's a little political poo on that So not not good in the United States right now. So. search warrant That's that Alright Digital forensics tools tactics and procedures. adminis admissive evidence This is relevant to determining a fact. it must be Mary Martin Merritt not meritable It must be material related to the case Basically what you gotta be able to, if you provide any admissible evidence it's gotta be material error evident to the case Are related to the case. It must be competent or obtained. Types of evidence There's real evidence documentary evidence and testimonial evidence, real evidence would be DNA or weapons something like that That's like physical. You hit somebody over there. with a USB stick then yes that would be real evidence. documentary evidence is written notes and testimonial is whatever you are saying It's your verbal information. We talked about chain of custody how important that is especially in the cyberspace and this deals with labeling. evidence of logs how you handle it how you sign it in how you sign it out. All of these have to be an unbroken sequence of events If it's broken then you just put your case in jeopardy. So all of those things have to be in place. Okay. So that is from, the CISSP training that I Shon gerber.com that you can get. out there and it's just one of the aspects as domain seven.one, that but I've got all kinds of videos that will tie back to that That will show you this in a little bit. A little bit. It's a little bit slower environment. But at the end of the day that is just four seven.one. A lot of good stuff in there especially as you're dealing with investigations need to do it Right. Don't screw it up. So. Just so that's just saying. Okay So what we're going to roll in. tech target Derek and to some domain questions This comes from tech target This is domain seven. we've got three dope exam questions for you. Based on the, investigations. So question one. A critical step in disaster recovery and contingency planning is which of the following…a a complete business impact analysis. Be determined offsite backup facility or alternatives. C organize and create relevant documentation. D plan testing and drills. Okay So the critical first step in Dr And contingency planning is which of these complete a business impact analysis. Determined offsite backup backup facility alternatives. Organizing create relevant documentation. Plan testing and drills. And the answer is a complete a business impact analysis That's usually the first step when you're dealing with a Dr Plan. Got to understand how's it going to affect your busy…Question two, there are different types of offsite facilities. Either subscription-based or company owned which type of subscription-based backup facility is most often used. A cold. Be warm. C hot. D redundant. Okay So if you go through there you can throw out. One of those right away from you're taking a test de redundant That ain't it. Okay That's not a typical type of offsite I've never heard of that word So I would throw that one out. So now you're dealing with a is cold B is warm C is hot. Okay So if we know anything about these we know that cold is not really being, there's nothing running and they stand it up at a certain amount of time Warm is is actually up and operational and well to some point and you still have to do some more work to get it up and fully going. And di is hot which means it's a. It's a running standby. Okay So if you're looking at this which one of these if you're paying from a subscription-based company owned situation, Which one would it be. A cold be warm See hot D no. Redundancy. Okay. The answer is be warm Okay Cause what the challenges is when you're dealing with you want to have the you're paying for the ability to stand it up quickly because you know that there's some of it's up and ready to go You know there might have to be some work to it, but at the end of the day you want it It's you're doing it to buy some time. If it's cold why pay for something that you're going to have to stand up? You just wouldn't typically do that. Alright question three in a disaster recovery, each level of an employee should have clearly defined responsibilities. Which of the following is a responsibility of senior executives. A test developing testing plans. Be established project goals and develop plans. C identified critical business systems. D oversee budgets and the overall project. Okay So we're now we're talking to disaster recovery. Each level of employees should have clearly defined responsibilities. What is the responsibility of the senior executives? Develop plants now established project goals and develop plans. Probably not. C identified critical business systems, maybe D oversee budgets and the overall project usually deals with money they're involved. Answer is D oversee budgets and the overall project. Okay. That's all we've got for today As far as for the CISSP the game that we were talking about a domain seven. And this is on forensics and investigations.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Infosec Institute
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/communications-and-network-security/secure-communications-channels/#gref
Wikipedia
Transcript:
Hey y'all is Shon Garrigan was her new cyber risk I hope you're all having a wonderful day today It's a great day in Wichita Kansas A Heartland of America. Basically smack dab in the middle of the United States So yeah there's pretty flat here it's pretty hot here but it's July 8th. Hey just wanted to go over We're going to be talking about in our site. OSI CISSP cybersecurity integration. Data communications. And then on our CISSP training where to get into implement secure communication channels. And then in our exam question where to get to point to point, it's not from like point a to point B it's a different kind of point to point. And then the OSI layers. All right before we get started I want to just throw out a plug there for my C I S S P training that you can find on youtube.com. You can check it out there at a Shawn S H O N Gerber. And I have CIS. training CISSP certification training You can find specifically on YouTube or you can go to reduce cyber risk.com at CIS slash C I S S P dash training at. you'll take you to the UME links as well So you check it out It's a lot of great information you're going to have there, all the domain stuff that you're going to have for as it relates to the CIS. P exam. To properly prepare you for that exam It's a great way to augment your training. And as you well know, you to me has some great deals as it relates to training. especially as for what I got So. Some really good things. Also all my CAS is P training. the various domains will be updated on a weekly basis Now some domains may be. Updated one week and then another domain the next week But they all all of my training is updated on a weekly basis So. some great things that are coming out there as far as the CISSP to help you be successful and pass the exam…Okay So the CIS is P integration This is from the InfoSec Institute and we're going to focus on objective four dot three which is implementing secure communication channels. According to design. and the topic will be specifically data communications…Now as you're dealing with different communication protocols we're going to you're going to hear some different terms and it's important to understand what these terms mean. you'll hear these terms thrown out like SSL and TLS and all of that, not TLC which is tender loving care It's different It's transport layer security Yes Security. Now the SSL is secure socket layer and what this is it's a standard security technology to create an encrypted link. it what it does it ensures that data is pat that's data's past remains private. It means specifically for private to individuals. And it does not go out to anybody else And that's the whole purpose of it right Is to have the SSL to protect your data and to ensure that it is private from other people looking over and stealing your information. It is also considered an industry standard to protect online transactions Now. SSL has been moved on It was it's still considered a industry standard. However the new version of SSL is what we call T L S I which is transport layer security. And they have TLS version two as well as one of the key points that are out there. But it's, it is the newest version of encryption of TLS is, and it utilizes symmetric crypto cryptography. basically there's two layers as a TLS record and a TLS handshake. and those are the aspects around the security but so you'll hear a lot of the synonymous…where you see third grade education. the SSL secure socket layer is being used synonymously with TLS, but everybody has moved on In most cases if you are dealing with the next level of security is around TLS and it's the next area. I said that twice. I know it's kind of not really cool but anyway did I did just did. All right then there's another product out there called swipe which is your swipe IP security protocol. and this little S little w capital IP and then he you got to love how they'd make these fun little things Swipe. it provides confidentiality integrity and authentication of network traffic. it does not however handle policy and key management. it that has can handle outside of the specific swipe protocol. so that is those just specifically swipe encapsulates each IP data gram Okay To be secured with inside the swipe packet. So basically the IP datagram which we talk about in the different levels of the OSI model and so forth the IP data gram will be secured inside the overall swipe packet And that's where it encapsulates it and wraps it up in a pretty little boat. But that is the swipe IP security protocol…Set is a secure electronic transaction and what this is at communicates. It's a communication protocol standard for securing credit card transactions…Set is a secure electronic transaction. and it's a communication protocol standard for securing credit card transactions. and so that's what you'll see typically within when you're using credit cards now, as in the United States. Many other countries have just got back from China They don't really use credit cards They use their product called we-chat and or Ali pay And it's the same concept but they it has to be tied to a bank account specifically within China. And but it's what they utilize at least in the United States for secure electronic transactions. it has a set of security protocols and it's set user provides electronic wallet or digital cert that basically puts you who you are. and if that's kind of how the whole. Basically ties you to the individuals through that digital SERP. the digital certificates and signatures are amongst the purchasers the merchant and the purchasers bank. It's just kind of how they the. The digital signature works between them all. But that is utilizing the term. Are the protocols security protocol of set secure electronic transaction…Then there's pap which is the password authentication protocol. Now this is a password based authentication protocol used by point to point protocol or PPP through triple P. you deserve Pippa PPP. it's considered a weak authentication scheme and it's not one that typically is used as much, but it still is used It's just not. you wouldn't want to use it for your main authentication or your main type of authentication scheme that you're working with in your organization. It does transmit un-encrypted passwords over the network So hence that's kind of why it's not utilized as much. there are some others which is the extensible authentication protocol which is EAP. You have your secure remote procedure call which is S dash RPC and then chat which is your challenge handshake authentication protocol. Now as far as the CISSP is concerned I remember seeing all of these you will you will come to some level of understanding around all three of these pieces are all these various levels authentication protocols And so. protocols. They are on the CISSP exam. Garrone T now. Some may not be on it Some will be on it but you do they do cover these in different aspects on the CISSP exam. So it'd be prepared for that…And understand how they are used. the key point around this again in the exam is that you will see they utilize these in ways that are kind of designed to trick you up a little bit and they'll utilize the pap aspect and they'll say password authentication. Protocol is used with set and you go oh yeah yeah PPP or no eight pap Wait. I said oh no And you'll make a mistake So, the goal is is to understand all these protocols and how they all work together. Okay So that is what I have for the CISSP integration And that again was from InfoSec Institute. Let's roll down to this CIS JSP training. Okay And the CISSP training we are gonna focus on objective four dot three implement secure communication channels According to design. Okay Voice. voiceover digital is quickly becoming the standard from teams to Skype to you Name it. Voice is becoming the standard over the digital platform, but this the old business of private branch exchanges or PBX's is going away And that's your typical phone routing switch switches that are out there. Those are all going away to a product called VoIP. Which is by far more flexible and secure. in most cases, Yeah I mean flexible in the fact that sometimes Skype doesn't work so well. But VoIP is a TCP IP network connection And it's configured to be simple, to the more complex depending upon what level of encryption and where that is protected at now standard phone conversations does have encryption built into it. these these do occur. However it depending upon if you want to have secure voice, like in the case of the military there's different levels of, infrastructure that needs to be put in place to ensure that the communication channel can be clear from. somebody over eavesdropping and con and collecting the information. Now there are some problems associated with VoIP A caller ID can be spoofed That is a possibility, and they are susceptible to denial of service attacks Hence the reason is they're on an IP network So if they're on an IP network they can be. denial of service They can basically be that they can flood gates with the network connections with nothing but garbage and therefore your voice connection will go down. Man in the middle. Issues can occur with VoIP and the traffic is not that is not encrypted can be deciphered. so you can listen to these information these conversations. If it's not encrypted. Now in many cases this stuff is encrypted but there are situations there are protocols where it may not be. So therefore you need to be aware that voice is like anything else Now if you do standard PBX where it's right over the wire, those can be listened to as well but they are not susceptible to denial of service tax. Unless you take out a switching environment then yeah Then your voice. You're basically you're. One heart. The line the phone line goes down. That's it? He goes bye. Bye. Goodbye. The next is PBX fraud What does that mean Well basically in the past it used to be where they would do it would take advantage of long distance phone calls and they would call this. Freakers And now I say that because it's still. We usually may have in the CSPs cause it's still a valid attack. And you deal there's there still are lines out there that you can utilize from a freaking standpoint. But it basically was designed to gain unauthorized access to phone systems and they would rack up toll charges for other peoples, that would try to be utilizing Unless your international phone calls or whatever they would then rock up phone call charges for them. This is becoming less and less of a problem because of cell phones and those that capability but it still does exist. that to limit this you'd have logical or technical controls on the network specifically to keep this and this would roll into administrative. that you need to have in place. you want to also avoid securing These are you don't want to avoid securing these older systems. You want to look at what are some of the ways you can secure them and protect them from these type of attacks from a PBX fraud attack. So don't just say well they're all So nobody's going to mess with them I'm not going to worry about it. That's really a bad idea in today's world where everything's interconnected more and more than ever You can be vulnerable to any type of attack that may be out there So again PBX fraud is still existed It still does exist and people still do it, but it is come down quite substantially from the previous days of like, Mitnick and all of them…Multimedia collaboration what this is is working on projects from a distance So now if you are anybody in the cybersecurity space or in it, you realize you know what, there's all kinds of collaboration that occurs through multimedia uses. from you incorporate email video voice you name it It's all there from a multimedia stay. and everybody does it. so therefore you must consider all of these voices security, all of these channels to secure, which becomes a very daunting task as a cybersecurity professional. you will see that this is a problem and it's something we struggle with on a daily basis. these remote meeting concepts and capabilities These are all something that you'll have to go through. And as you'll see they understand that from a multimedia standpoint it is everywhere. Now remote meetings this allows for interacting with remote parties which kind of comes into the collaboration space And it's important that you be able to do this in today's world because guess what? It's everybody's shares it and everybody's working remotely and they're working from dis I can't think of that big $10 word but from remotely geographic remotely separated locations Yeah There was a probably a really cool $10 word that would work well there, but yeah I couldn't think of it. now there's some key concern security considerations As you're dealing with this strong authentication activities are logged and monitored and open and encrypted. So those are key aspects you need to be aware of as you're dealing with remote meetings. And also understanding who's listening in And if there's somebody that logs into your remote meeting, that you don't know who it is, you might want to boot them out and tell you can figure out who they are because guess what? A lot of people drop in I used to do that We would drop in on phone calls. conference calls but see us before Skype where they'd have a phone number pop up. And so therefore they wouldn't know who we are We would just log in and listen. Instant messaging What this does is this allows for real time chatting right So this is the ability for you to have real time chatting through a digital media platform And everybody, everybody does. Instant messaging at some form or another it could be from your, when you're on Facebook it could be in various aspects but allows you to have instant communication back and forth through a texting environment. Now it is possible to do file transfer through instant messaging. And so from a security professional you need to be aware of that And if can you send voices can you send pictures Can you do all of those aspects can be put and they're all done. in potentials. On this security environments. sending social security numbers or PII personally identifiable information over texting is a bad idea Typically. there's some key security considerations that you need to keep in mind That's careful communications on what you put in a text Cause guess what? If you put in a text it's got to come out They always do They never ever not come out They always do. you also need to have records management Cause these records they go everywhere and you will run into them They will they they get legs and they move. So understand the records aspect around this. Also you need to limit your encryption as it relates to. or it has limited encryption I should say. The the aspect of text messaging, some, some text messaging depending upon the application you use does have a little bit of encryption involved with it or does have encryption. But in most cases these do not They the only encryption they have is the encryption through the telephone network the CDMA network. In most cases there are no. encryption from a texting standpoint. many are public services such as slacks Hangouts et cetera. And so when you send this out your text it's going to the cloud which everybody it goes to a server which everybody potentially could have access to. At least at a minimum the administrators have access to it. So there is no privacy There's very limited to new privacy when it comes to texting Snapchat all of those those things do get legs and move. So as a cybersecurity professional it's important for you to make sure that you teach people that this is a situation and working on your CIS. Especially you need to understand how that all plays into the overall game…Security and the email. Do you need to address this with your security policy There are some acceptable policies for email that you need to put in place. And as you're looking to secure your email, there are ways to do this through PKI which is your public key infrastructure You can get digital signatures on your email which will help protect it. but you also can have access controls Do you allow all old w a like is your, outlook web access you and your basically your online capability to your email? Do you have multi-factor in place on your email That's available online. and so those are key considerations And also as you're dealing with privacy around email it's important to consider. How do you protect your company's email as it relates to GDPR? So it's important that you have that in place as well. So you as a cybersecurity professional working on your CIS S. P you need to understand V. Cognizant of these different aspects around privacy. And and what you should do as far as dealing with the email, also understand the security person You should not have access to email You should have or people's emails You should have that all run through your legal and compliance teams If you have them. if not and you are the person then you definitely need to run that through legal before you do anything along those lines. as your backup and records management keeping emails until the apocalypse just a bad idea. so you need to consider getting purging those emails when it's appropriate, do not keep that stuff you're getting from legal considerations It's important to understand that you don't need all that forever. now if your company had puts it on legal hold where you have to maintain it well then obviously you have to keep those emails for whatever reason. But for the most part you you need to make sure that you don't keep any more data than you absolutely have to because, because storage is so cheap everybody keeps everything. It opens you up for a lot of different issues especially legal and litigation issues. so just kind of keep that in the back of your cranium…As we're looking at other email security solutions you need to understand the secure multipurpose internet mail extensions S mime. And privacy enhanced mail which is another term which is PEM. And then you're pretty good privacy which is PGP which you'll see with from an encryption standpoint for your email works typically for most of those providers that provide you some level of. email protection The PGP is typically used for the third party types. and S S. Mine is used for the more like your outlooks and so forth. And then you have your sender policy framework which is the F S. F those are again other email security solutions that you need to be aware of for the C I S S P…Okay C I S S P exam questions domain four…All right So in this question we're going to be talking about point to point. What layer formats packets from network layer for transmission and is commonly used point to point protocol and the integrated services digital network ISD N. Session layer. That's a…data link layer. That's B. Application layer. At sea. Network layer. That's D. And the, and the winner is B the data link layer is responsible for formatting packets from the network layer to be used in the transmission of data. So yes as the data link layer that is one that puts them all together And when you're dealing with the OSI model the seven layer burrito and puts it all together to get it shipped out the door. All right So now this question is about the OSI model. What layer which will you almost last minute about those I model too. Well what is the layer three? Of the OSI model…A transport layer. B data link layer. See physical layer. Or D the network layer. And the answer is D the network layer is the layer three of the OSI model situated between the data link which is layer two Okay So you guys see the video. Got layer two or I'm actually a layer two is down here And our toe, and then you have layer three which is the data link layer And then you have transport layer which is above that. Okay. That is the different models of the OSI. Seven liter layer burrito. Layer three of the OSI model is the. network layer. All right…All right That's all we've got for reduced cyber risk podcast today And we are going to be moving on to Hey I'll see the next podcast coming out next week. But the links today with ISC squared training study guide Quizzlet InfoSec Institute and Wikipedia. All right Hope you enjoyed this podcast Also remember that there's training available for you@reducecyberrisk.com. slash C I S S P training or you can check out my videos on YouTube amy.com which you will get a great deal by going to youtube.com and you'll get updates. from what's happening within the CIS SP on a weekly basis. All right Have a great and wonderful week We'll catch you on the flip side See. Thanks so much for joining me today on my podcast. If you like what you heard please leave a review on iTunes is I would greatly appreciate your feedback. Also check out my CA S P videos that are on YouTube. Lastly head over to reduce cyber risk and look at the cornucopia of free CISSP S P materials. Available do all my email subscribers. Thanks again for listening…
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – CISSP Exam Changes (2018)
· CISSP Training – Cybercrime and Data Breaches
· CISSP Exam Question – SDLC Development Models
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Global Knowledge
https://www.globalknowledge.com/us-en/resources/resource-library/articles/everything-you-need-to-know-about-the-cissp-exam-changes/
NCSL
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Security Architecture and Engineering) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Trusted Computing Base (TCB)
· CISSP Training – Manage Engineering Processes Using Secure Design
· CISSP Exam Question – CIA / TPM
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Tech Target
https://searchsecurity.techtarget.com/definition/trusted-computing-base
Wikipedia
https://en.wikipedia.org/wiki/Trusted_computing_base
Wiley
Transcript:
Hey all is Sean Gerber again with reduced cyber risk And I hope you're all having a beautiful day today. It's a gorgeous day here in Wichita Kansas. It's it's just couldn't ask for anything better So it's an awesome day And in Wichita Kansas. Well today we have some great things that we're going to be happening in the CIS S S P training field And we're going to be talking today on our C I S S P is security integration is going to be around trusted computing base, otherwise known as the TCB. Our overall training can be on domain two and we're going to be talking around managing engineering processes, using secure design. And then finally the CISP exam question is going to be focusing on the CIA triad goal and TPM. Trusted platform module I think is what it was Yeah. I think that's what it is There's too many acronyms Can't keep track of them all, but we'll get into that here in just a little bit. But before we do I want to get quick, put a quick shout out about my CIS S P training courses that are available for your purchase. At umami.com and you can catch those up at. you tummy You also can go to reduce cyber risk.com/c I S S P dash training. And you can get access to the UME courses that I have available I have put out there all of the CIS S P courses. Domains one through eight are all available for you to go get at you tummy. And as you well know your enemies bargain basement prices are actually pretty incredible. I mean it's just it's amazing what they offer from a pricing standpoint. But the cool part about all that is I will put updates to those on a routine basis Each of those domains will be updated on a weekly basis based on the content that's put out So it is a great place for you to go get your CIS as P training to help you augment your studying for the CISP. P exam. So go check it out@ume.com or@reducecyberrisk.com slash C I S S P dash training. All right let's get going. Okay And the CISP cybersecurity integration We're going to be talking about three dot two fundamental concepts of secure. models. Now how does this work Well basically what I ended up doing is I take the ISC squared training manual that they put out. That goes over What you need to understand for the CIS is As P from ISC squared. And I break it down into the different chapters and sub domains that they have. And so what I've done is I have three dot two which basically focuses on the fundamental concepts of security models. These are the key aspects and data that you're going to need to understand for the CISP exam and the key concepts the key understandings And we will go over all of that with you here on reduced cyber risk. Now one of the key points to consider is that this is the foundation of creating secure code. And when you're dealing with when you're trying to come up with, and I have a development team that worked for me so. I deal with this on a routine basis as we're relating to development development of code for my my team and for, to protect our company. And this includes operating systems and associated security mechanisms So it doesn't necessarily mean just the code that would go into potential CMS. It also means the operating system code which would be in let's just say XP, which is really really old but people still do it or windows 2008 server or whatever it might be. It SQL server whatever the bottom line is is that the operating system itself needs to have the The level of security put into the actual development of the code. But this also means a B BS That's a really good word. It also becomes around the hardware the physical locations the network hardware software, and the prescribed procedures You need to really include a cure coding in all that you do. Now there's some key provisions you need to follow. Access authorization resources. User authentication and the backup of the data. So those are some key concepts And when it comes into the provisions it's, who has access how do they have access? W who has the correct authorizations for those specific resources whether it's even an individual account or is it potentially a service account Something that's accessing it to just run the system. User author. And then also how do you back up the data and how is that data secured? All of those key pieces are fundamental in when you're dealing with the. Concepts around security models…Now TCB, the history around this is this came from a gentleman by the name of John Rush. B by B depends how you sign it and how you say it Say it. They call me Shawn or Shawn. Yeah. But see, my first name is on C. It's just I love it. It's just great My parents did that to me Hey, by the way if you're a parent don't do that to your children Just just don't do it Just say no. Just don't call them Moonbeam or something like that Just say like call them bill. Or Fred. Those are always good names Yeah. Those are good names. All right so I'm sorry A little bit better. Prince My friends call me Enrique So if you don't if you don't know you can call me and recap, but basically John Rush be defined TCB is a combination of a kernel and trusted processes. Now what does this actually mean This isn't kernel like a kernel of corn that you would get and you'd grow out in your field or in your plot of land. But this is a kernel that's tied to the hardware. And then the software these are trusted processes that run. Uh level of software that runs as a trusted process within with on the kernel. Now these are designed to be very very small in size and and so therefore, as they're small inside they can't be very big right hand small insights, but they also have to be lightweight and be able to run very quickly and efficiently. And these are a set of controls that are designed to work together to form a trusted base a base code. To enforce a security policy on that Colonel. Now we talked about the orange the different books that are available I think we talked about that last week, but the rainbow series and it's the NSA version of that and what what they have the different green the blue orange books and so forth. Well the orange book is a part of the rainbow series and it defines the TCB as this it's a total the totality of protection mechanisms within it include hardware firmware and software. The combination of which is responsible for enforcing a. security policy. Again the policies are they're not like a, a policy that you would make to go create a law. I mean they kind of are, but they're not It's basically the rules set up to to govern how security is in place Put in place. On a specific system. So those are the policy and you'll deal with policies in security policies that are within your company as a CIS. Or as a cybersecurity professional, you may end up putting some level of policies in place. And these are a written document that specify how things need to be taken care of. So there's those kinds of policies as well. Now the orange book defines that the boundaries of the TCB depends significantly on the definition. Of the security policy hands. That's what defines where they can get access and where they can get access…So as an example, we'll use a web server. Now this is a multi-user application right Web servers lots of people log into them Lots of people use them from admins that log into them to the fact that there's just people gobs of people hitting them from all over the world. The it is not part of the O S S T C B Okay So the web server itself is not part of that. Now it provides access controls to preventative individuals from usurping other people's rights So you can't be a squatter go in there and kick somebody out. If there are various access controls in place to prevent that from occurring. Now a breach of the application so of the web server application, whatever that might be whatever you're using. Would be would not constitute the breach of the OSS TCB. So it's the layer above the TCB above, above the overall OS itself. So if you beat if you blow up the application you get access to it and you are gone on the application. You do not necessarily have access to the OSS TCB…So as a TCB software protection, the orange boot book speaks of the TCB needing to be protected against tampering Dole Right? You don't want somebody to get access to that because if they get access to your trusted computing base, they game over they own. it all. Okay Cause that's kind of a problem right If you own the foundation then you own everything That's tied to the foundation. And the TCB must prevent its own software from being written to now they have a memory management unit you might've been hearing about this is in some of the trainings you've learned and some of the. The readings you've done is an M M you okay Now? In a previous life and MMU was used for as a mass measurement unit I used it when I used to fly a seven I didn't fly those I actually worked on them. Uh a seven course error that just shows how old I am I'm like dirt old, but these MMUS. That's to digress They used to work in the navigation but the memory management unit it's on a computer as protections to protect your TCB. Now it's programmable by the operating system So it allows denies and laws are. Denied access to specific ranges of systems memory. Requiring to be run so that it actually provides it will provide a capability or it'll remove the capability depending upon what's going to occur. And then of course there's got to be God mode. Well this is supervisor mode which allows for and restricts this access. So the supervisor mode allows you to do that with the operating system. So again the TCB software has a lot of protections in place just to protect it from knuckleheads like myself that would go poke around and get into areas I probably should not be getting into. Okay That is the TCB software protection. And we are a TCB I should say. And so we are going to move on to the CIS S P training…Okay So as we're dealing with CISP domain three security architecture and engineering. The topic does your is going to be implement and manage engineering processes using secure design…All right So we talked about the TCB in, from a Wikipedia concept Now we're going to talk about what some more things that would be detailed out in the CIS SP. So we talked about as far as the TCB and how it's considered at all stages of system development It's how important it is. that you need to consider its use. Programmers should also strive for secure development And this is when you come down to developing from a firmware. To the OSTP model the OSTP all the way up to the application you should strive for a secure development And this would be, you'll see terms out there I've heard them I've seen them just as. S DLC which has just basically software development life cycle and security is kind of weaved in there. I've also seen SDLC which is your secure software development life cycle So. It kind of goes hand-in-hand I would say that the security when you're calling that out specifically obviously that defines security more than being just a software. However if you're going to be doing SDLC, one of the questions I ask any potential new. Uh developer is how do they. We've security within the SDLC Cause I'll throw out there is a big buzzword going software development life cycle You need to do it. Or I do it right now and I'm pretty awesome. And then when I ask is I ask okay so how do you do that for a security standpoint? I mean do you do you incorporate some level of security within your SDLC? So something there to consider. And and so therefore, when you talk about this stuff it's important that there are some key concern security items for security design that you need to consider. Now we're going to get into objects and subjects. So an object is a resource used by a subject which would also be a computer system So your object could be a computer system a divine system that you are going to be working on. Subject's our user our processes requesting access such as an individual or an RPA which would be a robot process algorithm Okay Those are our PA's. And so that those are different things that are put in place there Object in your subject. Now there's a trust These trusts are set up between objects and subjects. So as an example you'd have service accounts. That would be a user Okay And then you have an R and D computer which would be an object and the service accounts have access to this object and therefore. can manipulate and go back and forth. However the bad guys the hackers the attackers they will then manipulate this trust between the objects and the subjects. So therefore it's important that you have proper protections in place to minimize the attackers from getting them now living in a previous life. Uh service count I've talked about this before on reduced cyber risk is that it is the granddaddy dog that you want to they want to go after. Typically service accounts are set up that they're 24 by seven. They have very little limited protections. Passwords probably don't change a whole lot. And so therefore they are the ones that are used to manipulate other objects and to just take advantage of them. So…again if you're a CISP and you're studying for this this is the key and this is what separates re-do cyber risk from a lot of other people that are teaching CISP, we've got gobs of experience on this stuff and we've seen it a little bit of it I believe me I know I got a lot more to learn tons more to learn. But that those things are definitely liver leveraged And so just understanding the test and pass. the test is with the first piece of this. But ongoing and understanding how these accounts are leveraged. Yeah That's that's the ongoing aspect that you gotta be aware of…Now there's closed and open systems a closed system is designed to work with a very narrow range Okay So it's just designed in a certain area. Again I've dealt with this in the past from a military technology standpoint those were closed systems and they are defined typically by the manufacturer So let's say you have a stealth fighter. And you have a specific system that needs to be working on that cell stealth fighter. They will have that as a closed system It's not updates all that stuff It doesn't reach out to the internet. Hey I'm going to go to update you know it doesn't do any of that You you have very close parameters on how the updates occur. They are sent specifically to individuals to update themselves. They're they're trying to avoid as many inputs from outside that would be random And that could potentially add to a vector into the the system itself. Again so these are defined by the manufacturer. They can be more secure They really can't say of, and then what I mean by that is the fact that because they are a closed system they are segregated away. And the downside of that is and you see this even when the manufacturing space. When you have a manufacturing system that is. such as using the Purdue model what'll happen is is in many cases, these systems that are maybe blocked off by firewalls do not get updated as routinely as they potentially should. So therefore they are Uh, a bit more susceptible to vulnerabilities. And so that's why it's important that I say sort of, uh you you need to make sure that you if you do have a closed system within your environment you do make sure that you do update it as much as you possibly can. Now open systems these are agreed upon an industry standard and these are much easier to integrate with other systems I E because they are have a standard and they're updated on a routine basis. We used to call this cots which is. What I used to they think they still do. Let's cut common off the shelf software and systems. I think that's what the acronym stood for Basically it's stuff you could go by off the shelf and shove it in a plane. Cots. It is an important aspect Now the problem with cots was it was not as tested. As these are the systems that are defined specifically for a. An aircraft or for the military but they are getting more and more integrated within the. Military system as well. There are more options to these networks as far as one of the being an open system but they are less secure. And as they are less secure you have to be aware of that. So again, an example of that would be a computer current computer system that you can get You can go buy a new laptop desktop. Um desktops are really kind of hard to get ready to anymore but when you can buy them obviously but they're not nearly as prolific as they used to be. But you go get this new current computer systems and they are built to a standard. They integrate well with others They play well with others and, but they don't really have the they They run the risk of being a little less secure because they have so many bells and whistles that have to be in place…Now techniques to maintain confidentiality integrity and availability We're going to get into confinement. Okay So this is various techniques that are created by software developers. And any of the following can be used outside of software development And it doesn't have to be specifically in the software development world. But. It's where we're talking about right now. But bottom line is confinement for what does that mean It restricts user Yes That makes sense The word says confined restrict strict for users and process asset access or actions to a program. It also allows a process to read right from specific locations So it re it confines it to what it can do where it can read it defines who can access it, what programs can access it So again it confines the restriction it puts restrictions on it. Uh sandbox is a place to restrict where you can operate again. Now this is also a place where cats go Pooh, but we're not talking about that sandbox We're talking about a different sandbox. This is one where they you place at restrictions on where you can operate You can play in it's a it's a place you can play and beefs protected from the bad guys out there outside of the sandbox. That's that's the purpose of it, but you must meet and operate with higher level of security in the sandbox. Now I've seen it with other companies I've firearm many others will do this They will have a sandbox in place where piece of malware will come in It'll go dumped in the sandbox and it'll be run to see if it implodes. If it doesn't implode, then it will be moved on. Now the bad guys have figured out how to get around that Obviously they just put timers on things and so forth so that when it blows it up in the sandbox Hey it works no big deal. And then it moves it on and then it blows up and does bad things But the sandbox is a place where you can, things can go nasty and you don't care except for when their cats go in there and use it as a litter box. That's usually not so good. Anyway, the moving on example is only a specified systems can operate against a specific database. Any system outside the scope are not allowed So again, You're a very specific system It can operate on that database It can operate in the sandbox, but nobody else has out. Is allowed out inside the sandbox that is not supposed to be there No chilled. from other places…Now bounds and process isolation What does this mean Well bounds are defined processes that are given authority to operate. They can be many or few So again the processes that are in place you define these bounds right? Now obviously more is not necessarily better. Especially as you're dealing with the Colonel and other things but one of the aspects around this is the unit user, the Colonel and the administrator These are specific processes that are given access. And authority to operate but you have to create these bounds to, to define what they can and cannot do. The operating system memory and hardware These are process that would be defined. Bounds defined right. You operating system this system can use or this. User can use this memory This one can this one can do it And hardware typically the Colonel can do it almost all those places I should be able to do it in all those places so that those are aspects that you're going to have to, that will be defined for you in most in most situations. Now an example. My malware will utilize errors in these bounce settings, and then it will go and start mucking with stuff And an example would be kernel manipulation So if your bounds are not set correctly, to get to deal with the Colonel and you have users that can get access to the kernel, then it will go and flag it will. There'll be able to mess with it and if they mess with it and then for the Colonel, as we talked about and TCB, they will own everything. Now the key around all that though is is that if you have a product such as EDR which would be endpoint detection and response or recovery of response, That would note a lot It wouldn't notarize That's not really a good word It would utilize the or understand if someone was to manipulate the kernel and then trigger on that. So again that's why these these end point detection products are really really valuable. Now process isolation this ensures that only affected specific memory locations or only specific memory locations are affected And it's a central part of a stable system. If you don't get into process isolation, What'll happen is then all these processes are running all kinds of goofy stuff and then it'll crash and cause you all kinds of issues. Now it also prepare. applications from accessing memory from other locations. Cut paste Copy. All of these will be allowed to transition And so therefore it's important that as you're dealing with process isolation that you, you do make this. Peace Very limited. As an example you got cut paste and copy. Those are processes that would be isolated. If you don't do that then you can use these functions in many other ways and, and hackers can utilize them outside of their parameters And then that will be bad. And they will try that They try everything. And then another way would be macros easy to kind of run outside of defined parameters And then you get all kinds of manipulation occurring of these macros with biohackers or attackers that are causing effects to your environment. Okay That's all I have for CIS is P training Let's get into those exam questions. All right. exam questions domain three. All right So this question is going to be talking a little bit about confidentiality integrity and availability. All right So Fred recently received an email from bill So bill got an email from Fred saying Hey you're awesome I like you you're you're like me Yeah we're good Let's go out and have do some fishing and go have barbecue. No that's not what he said but that's what I just ad-libbed no Fred recently received an email from bill in his inbox. What goal would need to be achieved to ensure Fred that the email is legitimate and it has not been spoofed. We got confidentiality. Non-repudiation. Integrity. Availability. Or one of those 3, 4, 5, 1 of the four. Okay. A B C or D So a is confidentiality B is non-repudiation. C is integrity. D is availability. The answer is B non-repudiation does not allow the sender to transmit a message. And then to deny that it was sent by them So that's B. And so yeah, I kind of fed to you guys It wasn't about CIA It was actually about non-repudiation so gotcha. Bottom line though is not a pre repudiation is the goal So you want to be able to be able to repudiate So someone says I wasn't me I didn't do it as repudiation. So non-repudiation would be the negative that, that does not allow the center to transmit the message and then deny it was them And so that's what you also want to do from maintaining your systems is you want to have the availability for. Non-repudiation from a hacker and you have logs that are taught lockdown that people can't get access to You want to have the ability to, to basically be able to restrict people from getting access to systems that they can't get act They don't need to get access to…Now quite next question What is the falling as it relates to the trusted platform module which of these as it relates to them is true. A the TPM installed within hardware is much slower than the software variant. Be the TPM does not store the crypto keys for the system. See. The TPM is responsible for storing…and processing the crypto keys for the system and can be in software and hardware systems. Date. All of the above. all of the above. Okay. And the answer is…C the TPM sole purpose is considered the trusted source within the computing system and will store and process cryptographic security keys. Full disk encryption will store the encryption keys in this location. Now I didn't go over this in the TPM but it does do that The trusted platform module we'll go over and deal with the encryption and crypto keys and it will store them for you. So that is we'll talk about that in another. Uh domain or another podcast but it's basically that is the domain of domain three You'd be dealing with the TPM. So again the TPM is responsible for storing and processing that crypto keys up for a system and can be in software and hardware systems, hardware like firewalls and. Switches and stuff like that. Okay software like your software.
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Remanence - Rainbow Series
· CISSP Training – Protecting Privacy
· CISSP Exam Question – Sensitive Data / Destroying Hard Drive
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Misc.:
https://thorteaches.com/cissp-certification-rules-laws-and-regulations-oecd/
OECD
http://www.oecd.org/sti/ieconomy/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm
Rainbow Books
https://fas.org/irp/nsa/rainbow/tg025-2.htm
GXA
Transcript:
…Hey all is Shon Gerber again with reduced cyber risk And I hope you're all having a wonderful morning. I'm having a great morning My kids are heading off to, to camp this today So I am extremely excited about that They have, I have five children still at home and they are all going to camp. and it is an exciting exciting time. I don't know if any of you all have children might be living out there, but anytime that you can get away from the kids or the kids can get away from you. It's a wonderful blessing And you think those your lucky stars for having those little blessings Because, yeah it's going to be a super quiet in the house and I'm pretty excited about that because it'll just be my wife and me and the dogs It'll be pretty awesome. so yeah, that's just had to give that a little bit of a tidbit out there about that. So one of the things that we're going to be talking about today a lot of great cybersecurity aspects that are going to be dealing with training. And we're going to have a talk about cybersecurity Integration is going to be the data remnants and rainbow series. We're going to be talking about data remnants as the CIS S P training and what you need to understand. for the CISSP exam. And then we're gonna talk about some CIS S P exam questions that are around sensitive data and destroying of hard drives. But before we do one of the things I want to mention is the C I S S P training courses that are available. to you just for individuals who listen to this podcast. You will find out that there are some great training courses that I have available on youtube.com. that are around the CISSP. And they actually focus on all eight domains of the CISSP. So the training you see here you're going to get that in on the steroids They're going to be tons of it. and we'll go through each and every domain as it relates to the CIS SP from domain one to domain eight And you can get all of those as you well know. To me they're bargain basement prices That are pretty amazing. the the cool part about that is that by going to the link of reduced cyber risk.com. dash training. You can get those that link all in one spot from basically domain one to domain eight. And that will take you to. you to me.com. Where you can then purchase those, those courses But again you get lifetime access. It's an incredible opportunity If you just want to go to you to me or to go to reduce Avaris. Dot com CISSP training. those are some great opportunities for you there. All right. Well lets us roll on into the training today. Okay So let's CIS S P cybersecurity integration training We are going to talk about the NSA slash N C S C S Brainbow series And you've heard me talk about this especially as you're dealing with the CISSP. There's different rainbow series books that you will deal with. and one of the main questions they talk about in there is what what is it a specific book and why does it do what it does? what what is the aspect of it? And we're going to kind of go into a couple of that right today But the interesting part was I had gone through and been teaching the CIS as P for awhile and, and understood the rainbow series And I remember being in cybersecurity now for as many years as I have basically since 2001. you you realized that the, the rainbow series are an important aspect. Of the overall picture that you know especially at the beginning how this whole thing worked, but I never really understood where they were and and you can get these all online in the past They were in actual books that you would get because that's how old I am You would actually have a book not online. But now they're all online that you can go check them out on at, at at the NSA. and that's basically F fast.org, IRP NSA rainbow and so on and so forth And they will walk you through You'd see where all the books are at. But there's some key terms we're going to focus on today And this is around, dealing with. Data remnants And that's the whole aspect of it I kind of wanted to keep all of these domains as we talk about cybersecurity and the integration and the different, websites that are out there for cyber security. I want to focus on the specific domain that we're in and we're dealing with it Cause it, I was kind of jumping around a little bit I thought well let's just keep it focused on what individual domain we're dealing with so that it makes it a bit easier as your say. this information. So the key terms we need to be aware of is one first one is clearing and this is what they call it removing the sensitive data from an information system So if you have some sort of data that's out there and you want to remove it this is how you clear the data from that device. and there's some different terms that you will get to know quite frequently. another one is purging and this is actually removal of the sensitive data from a period of processing So what they talk about there is it actually removes it from the processing. period that's occurring on that device that hard drive that disc, that the information is being stored on a declassification is removal of security classifications of a subject media. Now in the previous life where I dealt with the military we had unclassified. You have your classified networks you're on classified networks You, when you had classifications your secret top secret and so forth, you had to remove that security classification. If you want to be able to use that data in spaces that are outside of what they were designed for. A good example of that is like in the case of the Mueller report in the United States they had, those are classified documents in some respects. Because maybe they give out information about, individuals in this report So what happens is is it has to go through a process of declassification before they can do that. And and so. Like for example if I get a document. And you know I'm, I'm the author of even can come down from a declassification standpoint. If I'm the author of a document I can classify that document So I can say it's classified secret. then what ends up happening though is I cannot be the one that says I'm going to declassify and I'm just going to remove this the security clearance off of that. Cause it was a reason I made it. At classification of secrets So therefore it has to go to an individual who then has to review and say, okay yeah if you remove this information it is would be unclassified or parts of it would be redacted. And so therefore that's what the declassification process is It's a it's a whole process a whole way of removing that information. coercive…okay See I can't even say that course activity My third grade educations coming out. yeah, that that word. It's measured in This is another word that I can't handle. Oh or stats or steads and it's basically don't oh E and this is a property of magnetic material used as a measure of the magnetic field. Okay So if you're geeking out that's what that is It's a V they call that oh eight Now I'm I'm geeking on you a little bit here. just because one as I'm teaching this I also have learned it. I did not really know and understand how that was all set out So it's like oh okay Well then now that makes more sense versus just going. Yeah you need to purge it You need to remove it. So this is a little level deep detail that you may be going, why are we getting into this Well it's just to kind of show you a little bit more around It's not just, Hey I'm going to clear it I'm going to purge it and I'm going to declassify it because those are key terms You'll need to know for your CISSP. But when it comes right down to it there is a little bit more backstory behind it…Now I knew I do know that that we talk about in the CIC. the different types of tapes and there's a type one type two type three tape, and these are magnetic tapes And these have a coercive the civic duty of the mat type one is three 50 O E. The type two is 3 51 0 8 to 7 51. And the type three is above 75 or 750. I said 3 51 Yeah 750. So basically it was 3 50, 3 50, 1 to seven 50 and seven 50 and above. And those are the different types of tapes that are available magnetic tapes And again this is like way old. If you're talking people like me but, in many cases he data centers still have magnetic tapes that. I information is backed up too. So you need to keep that in mind especially as it deals with destruction how do you deal with that And it also comes down to the the tape that. the magnet magnet Tivity of a hard disc drive. Now what does it…well that is a device that generates a magnetic field for deep browsing magnetic storage. My media, what does that mean? It basically puts this quote-unquote force field and it you put your magnetic tape in there and it's got these humongous monsters magnets. That then just basically rearrange all the bits and they no longer are in a logical path that, that allows the device to be able to point to them. Cause they all have pointers And if you have a certain file it points to a certain place on the hard disk drive If you're dealing with just drive. And the D Geyser. We'll nuke that it will totally mess up those hard disc drives Now, as we have SSDs come into play the D Gaza really has no factor in any of that So then you'll have to get into physical destruction. but bottom line is that's where you're still a lot of magnetic tapes that are out there. That you need to be concerned with and worried about. And so therefore that's just something to consider. permanent magnetic decomposer. this is a handheld permanent magnet that can be used to dig cows floppies Yes they are floppies and they still exist. And be you'd be surprised There's still people using floppies. I don't know how you can use them that much but there are probably plenty of out there that still use a floppy drive. And if you're not familiar with that is it's like a little square. Plat piece of plastic it used to be plastic It was just kind of the magnet. Magnet. It was the. The spinning magnetic drive per se on. Pacey flimsy piece of…plastic that would hold the data and it would just go…That's kind of how that worked and it made those specific noises too Pretty scary. but that that was the old way they used to deal with floppy drives and they also can deal with it on Desplat. Which is basically your hard drives and magnetic drums et cetera So it was basically a handheld decals or that you could go by and walk by and you nuke a hard drive. now there wasn't used obviously to do gals tape the best thing to do with tape. Honestly it's shredded Just destroy it. it makes it a whole lot easier that way. But the permanent decals or wood is just a high powered magnet You can be Magneto from the X-Men and just nuke. Your stuff. Bottom line though is on. Don't get close to anything You don't want a new cause if you do it's done You're not going to use it again. So that is a permanent magnet decomposer. So now if you're looking at different mid risk considerations for storage and media reuse these are some key aspects for you to keep in mind. the you need to understand the destination of the released media. And where you plan on keeping it So if you plan on storing it. What are you going to do once you release it Where's it going to be stored And it's going to be stored in a salt Mine is going to be stored in a warehouse. where where's it going to be stored Because all of those things will affect how well the data is kept. for an example if you're dealing with. heat and age you know, those all of that will age the device if you keep it for a long period of time that will cause issues with the data. So all of those things will cause you some level of grief if, as it relates to your maintaining your information. mechanical storage of device equipment failure If you have, as you keep these things online. What'll happen is the mechanical devices will be we'll have issues. they will have problems and they won't be able to last a long period of time So your storage and where you keep it. We'll also cause issues with mechanical failure and bottom line is if you have these old devices, they also don't, they you can't get replace them So you may have the hard drive but if you don't have the chassis and. All of the operating systems that go along with to run these old systems. That also is a factor you need to be aware of. there's also a comment that your storage device segments not receptive to overwrite And we'll talk about that here a little bit further about not receptive to overwrite What does that mean? but they basically won't You do you can't it won't override it at all It says Nope, I'm done You can't mess with me anymore And you can't make changes to it. overwrite the software and clearing and purging So again you got to have find a specific overwrite software that will do this clearing and purging for you. those are some things to keep in mind As you, as these things get older, you got to have the older software to do it New software will not work with, these old systems So you'll have to keep that So there's a lot of legacy stuff You've got to keep in mind by keeping these older data. the asshole as time goes on you may not understand the data sensitivity of it It sits in this big box for years. Is it sensitive Is it pictures of my fuzzy kitty? Or is it pictures of top secret nuclear science projects which you hopefully wouldn't keep in a box somewhere but you never know people do those things. so again not understanding that to hold dense data sensitivities especially if you're keeping it for a long period of time. And then improper use of degaussing equipment. I struggled with this one but knowing myself when I was a teenager I'm trying to think what would be one thing that I would be using improper housing equipment and probably I guess, Hey let's run through the magnetic field and see what it does. I mean, I guess that's what, but basically going and playing with your friends going Hey I'm Magneto watch out for me You know, those things. I just struggle with why you would use it improperly because you're playing with big monster magnets and they're kind of in the past they've been pretty good size. And but now they're in a box more or less that you just stick the device in a box and it nukes it. But yeah I laughed at that one improper use of decals of equipment So do not know horseplay with the housing equipment. That just goes bad. It goes bad for everybody…Now when you're dealing with not receptive to overwrite some the storage devices segments are not receptive to this And what happens is is that they're unusable tracks on a disc drive. And I come back to disc drives again because you know we all know that they're going to SSDs are more prevalent within our environment, but there's still a lot of disk drives that are out there that are being used in servers. When you can't overwrite the segments it becomes very difficult to wipe. and so therefore if it becomes difficult to wipe, how are you going to deal with that? so you need to check these devices for unusable or damaged areas before uploading the data and making sure like one good thing we've talked about on reduced cyber risk. Was the Amazon glacier and how you could potentially put all of this data in the cloud. But if you run into these issues of overwrite challenge. one you go okay well I'm going to do that I'm going to upload it to the cloud Well I find out I have these unusable or damaged areas. How you going to deal with that And I will put a little plug out there for spin right by Steve Gibson It's a really good product to help damaged areas within your device drives. I highly recommend that if you're going to be used if you need to get the data off of there. but also keep in mind from a cybersecurity standpoint if you can't get the data off of this, and if it's sensitive you need to really make sure the best thing to do is. I mean the housing is important I think it's it's good. And personally I think it's probably step one of a two-step process especially if you're dealing with sensitive data, is that you dig out the Dickens out of it and then you shred it. or you know what just shred it and be done with it And you don't have to worry about the housing It. But the bottom line is is that if you have any areas that are. Damaged. and they do not give that DCD aware that disc drive away because what'll happen is if you do that you are now running the risk that someone could get access to that data. you never know if the technology's out there They may be able to get access to this damaged or unused spot. if it is unreceptive again, Tried to gouging re-imaging the device or re-imaging it? if you did gals that you, you knew it you can't really use it anymore but those are things you need to consider. If you the segments do not have the ability to overwrite. Okay That's all I have for the cybersecurity integration Let's roll on to the CISSP SSP training. Okay This is domain two asset security and more topic is going to be about protecting privacy Two dot three. Okay As well the objective is two dot three a protecting your privacy and the topic on this is data processor. so we're going to get into a lot of these different aspects and a lot of this falls into what GDPR talks about, and if you're not sure what GDPR is the general data privacy regulation that's put out by the European union. As it relates to data privacy and maintaining it And that is, it's a pretty large. Regulation that focuses on, managing. the data privacy of individuals in the European union. the big thing that made this thing happen to come into play there was safe Harbor in place before this. but what moved it in this direction was the fact that they wanted to have better access and better control of data privacy. Now it's interesting because you look at data privacy from the EU is one direction which is more or less focused around the individual. And how do we protect the rights of the individual that European union citizen? And then you go to the opposite extreme where you have the Chinese government where it is the privacy of the state. Now the privacy of the people is important to the Chinese government obviously, but it's more important to the privacy or the understanding of the state and the collective. And then you have United States was really kind of in the middle It's kind of all over the place. So you get different states in the United States that are more private than others And so that adds com. Convoluted T convolute com. Yeah it makes it all messed up. Get you that third grade education. but you. it ends up messing things up because you have different states that have different requirements. So bottom line is is where this part is going to be around GDPR. Now context is everything as it relates to processing data, a system to process data or is it looking at the GD PR data processor? Processor is defined as this, a legal or a natural or legal person, public authority agency or other body, which processes personal data. Solely only behalf of another data controller. So what it really basically comes down to is you have an individual who's a data controller that controls the information that from within an organization. You can outsource this the to a third party which would be a data processor. one thing that you can see as this as an. always works is so you have a. A third party. Processes that does payroll that would have personal information about the individual, from pay name address all those things that you considered as. personal information, you actually that you consider just an IP address of the computer you're using as personal information. So they would have all of this data. So this, this data processor can be defined as an individual person. that within your organization who has the authority to do this or it can be outsourced to a third party. And so therefore you need to be aware of how does that affect your company How does that affect. what you're doing and then how do you want to make sure that you document that correctly, but a data processor. Happens quite frequently. you just have to decide is it somebody internally Is it externally or is it a combination of both…Now we talked about GDPR One of the big aspects of them making this thing have some teeth is the fact that it is a fight You could face fines up to 4% of global revenue. Now 4% is a lot of money especially with you're dealing with a corporation. who has a global presence? you know and even if you're small company so. it to this way So if you're making. A hundred thousand dollars a year right? So a hundred while hopefully you're making more than that but let's say it's a million dollars a year. So if you have a million dollars a year, 4% of a million dollars is a what is that I don't really, I say I had to do math in public I have to think about that for I did it So maybe what $4,000 No it'd be. 1%. 1% of a million dollars. Okay 10% is a hundred thousand dollars. of a million, so yeah 10% was a 4% would be a $40,000 right Yeah $40,000. So it's $40,000 hit. And that's if you're doing a million dollars in business now that, that a million dollars of business. You get a $40,000 hit your margins Aren't very high. That could be DECA. So let's put it this way So many businesses are only making if I say. Many. The average comes into. If you're a good business making big money. and you're you're blessed. You're probably making about 8% margins on your product. So you know anywhere from six 8% is what the typically what I've seen again I'm not a finance guy I'm a cyber guy So what the heck do I know? But I do know that typical margins from a business, some businesses have way higher margins than that but let's just say it's a standard businesses making between six and 8% of their margin. Well if you take an 8% of your margin if you're lucky to get that, then you could face fines a 4% So you could also take a 4% hit of your overall profit. That is huge hat 50% could be put in paying out these fines. so it seems like not very much but when your margins are pretty tight it's a lot of money. so an example I have is if you got a billion dollars USD globally, that's a $40 million fine. That is huge. That is a monstrous fine That would cost you gobs and gobs of money. Now as you're dealing with the EU and us privacy shield this will again was previously safe Harbor. there's organizations can self-certify saying that they meet or comply with the privacy shield requirements and principles. so therefore yeah. can in the past you could do that You'd say Hey I'm doing it I'm saying I'm doing it. If you want to audit me audit me and then you can find out if I'm actually saying doing what I'm saying. and but that's that was the U S us privacy shield our EU us privacy shield. There were 16 principles in total that you need to vow to uphold at least seven of them. And so therefore you could actually get away with not upholding them all. but those are the aspects that you had to say that I will comply with that And then therefore they had the right to audit you And if they audited you and you weren't doing at least the seven. Well then you would have to pay some significant fines for doing so could lose that status, all of those pieces And then if you lose status what that ends up happening is is now you can no longer share data between you and the EU. so if you're in the United States and you're a multinational, you've got business in the Europe and in the United States, you can no longer share data between you and Europe. that's just not good. And so therefore you want to make sure you comply with the requirements as much as you possibly can. At least seven hours at 16…Now there's other key GDPR terms and one is pseudonym Meninism see. Third grade. the sooner, yeah. I'm not even gonna bother saying that but it's basically using pseudonyms. And what it comes down to is as you have, like for an example bill Smith is patient 1, 2, 3, 4, 5. and it works to op use obfuscate data So you know that in the records. Bill is patient one through five And but you have to have a key or a cipher to be able to determine yep Patient 1, 2, 3, 4, 5 is bill Smith. but that's a really good way to suit a man randomized individuals and their. their names. And so then you can hide the actual patient data itself. Another one is anonymization and this is basically removing all relevant data about the person or their identity. a good example of this would be data masking And so you'd be using in SQL table. So for an example you would say, input would be bill Smith 1 2, 3, 4 5 6, 7, 8, 9. for like in the case of United States it'd be a social security number And let's just say that would be a really bad way of identifying somebody by the way Don't don't do that. even if you're going to randomize somebody just just don't do that. the output would be then Jennifer Smith, 9 8 7 6 5 4 3 2 months. Okay. That is is good but it really causes lots of challenges with that so you have to have a cipher to understand how to reconnect the dots. And that's that's where you really kind of gets confusing, but it's a way to totally randomize or anonymized that individual you would not know who they are unless you have the cipher unless you have a way to understand and how to reconnect everything together…Now as we deal with data reminisce some things to understand around this This is how the data that's remaining after media has been erased. And we kind of talked about that briefly and the cybersecurity integration piece of this. it's residual data after a full eraser of disk. So if you go and you do a full ratio of it, and you wipe it there's still data potentially remanent on. that device. You have to have a way to how do you deal with that and how do you remove that? so that's the residual data after your full disc exposure. Now there are serious problems especially with today's tools that you can do Cause you can find out if you say well I'm just going to do the standard format. Start out star. the the size of these disks it will take you forever in some cases also, if it doesn't always erase the data you just erase the pointers of the data. So if you can go back and find tools that can go out and actually pull this data out of the disc. that can be very valuable So, this is why it's important that you honestly if you have any sort of sensitive data just Newcomb or shred them, that as a better and then run a hammer through them. I can't run the hammer through them putting a nail through them something like that. But it comes into data leakage and data loss You will get that by having data remnants. there's also ghost images on computers and CRT monitors If you're CRT. these are really old which is a cathode Ray too when they're the green kind of things. those CRT monitors. If they've had a burn in for a long time say the data hasn't it's just always like a display screen. It will leave on the photo. I can't remember how they call it but it's basically it's a phosphorus type. Front end and it excites it And when it does that it leaves an image, a ghost image on the monitor. if you're really old like me you've probably seen that. And so therefore what ends up happening is is you can actually have a data sensitivity that is exposed. Now I don't know how many more CRTs are out there and available to people They are an extremely inefficient way and they're very. The power hungry They suck a lot of power. So, but they are they do still exist I'm sure of it. Could you see him I walk into Goodwill in the United States and I see those in our the Goodwill's and area that they give away things to people donate devices and things and clothes, and then people can come in and buy this stuff And that money goes to, the underprivileged people. so Goodwill has a lot of time to see our team monitors in there that people have given away. but those things are like way old and they're they don't work that well but…people still use them So you understand that ghost images on computers…Now there's a process to remove it We talked about this a little bit earlier about degaussing again these are powerful binds to destroy the typical magnetic drives and they are important There's also the handheld to Gaza right That's you do not have horseplay, no horseplay with the browser Just don't do it. physical destruction These are the jaws of deaths and death and you basically run your magnetic drive through this and it chews it up into shredded pulverized pieces of metal. so that's a really good way to make sure no one gets it. and it's also highly recommended for yourself State drives run everything that you don't want through there that you don't want to exist. Run it through that the jaws of death, and it will destroy that stuff So it will it will destroy almost any media product out there. worst comes to worst get a hammer and beat the living Dickens out of it If you can't put it in the jaws of death like a sledgehammer and just smash it to pieces. Ah that's a good way to destroy it as well. when you're erasing it delete the operation This is basically a delete operation on the file or media type And what I said like I mentioned before, It really only removes the pointer or the file locations not the data itself It's just guessed How is the data how do you find the data through that pointer? So, racing is just not a bad not a good idea at all. recommend that you actually do some level of software to do a complete overwrite which will overwrite the ones and zeros to all ones. but when the size of the SSD or the size of the drives today these like mega terabyte drives, it will take for AVOR. To do that So. it's almost just as easy just to destroy the drive itself unless you really really really want to reuse it again…we talked about clearing This is an override process and there's ways that you can get a there's some great websites out there on how to clear it. and you can buy that software specifically for clearing those devices. Again I gotta be careful on again a one to two terabyte device. it will take a long time. to overwrite this process for the media to be reused. so you have to just decide is it really worth it or not? you can write it basically writes a single character over the entire disc and there are very various tools to do this purging more intense form of Clara media to be reused. what it does is it then writes ones and zeros like in like seven different passes. So clearing at one time is one thing and then purging it and basically writing over it multiple times. that's if typically in the government if we were going to reuse something what we would do. Is we would you do the DOD standard which would then in turn override it like seven times before you could actually reuse it? But realistically these things are so cheap today that Dennis drives that it's almost better off just, just shredding it and going out and buying a new one. just because you'll spend more time from an opportunity cost standpoint clearing these things then to just go ahead and shred it and start all over…Transporter data flows this is a previous domains around trans border and you're going to have more and more personal data is moving from nation to nation And, and so therefore this, you have to be able to manage it and to be able to understand how this all works. Well there was an organization that through that they came to a con consensus and is called the organization for economic cooperation and development O E C D. And there's the key provisions that are in there of these 30 member states that said to how we do transporter data flows How do you do that And then how do you manage that…this was issued in 1980 and I know back then 1980, the internet was pretty small it did exist Al gore invented it, but it did exist. And so therefore what ended up happening was, the the data flows were pretty, pretty tight, pretty small today's world man They are flowing everywhere Data does not stay in one location It goes everywhere. And so therefore the. These a lot of these laws are a lot of these thoughts are a little bit dated and antiquated, but bottom line. is is there are data. trans transferred border data flows around how to you maintain and manage the personal data…Now there's eight driving principles of the O E C D. And one is a collection limitations It's a collection of personal data should be limited and not be, get gathered and garner too much. It should be obtained by Lee legal and fair methods There's no. basically siphoning data back on people without a legal or without That a proper way of doing that. the data quality It means that it should be kept complete You shouldn't take snippets of the data It should be maintained in the wholeness of it. One thing around that is if people cherry pick specific like you can say just even saying news news media all all the news media do it in some form. Is a conversation may occur and they'll take a piece of that a snippet of that conversation, and it will be taken out of context and therefore it gives a married different perspective And you can do that with data, whether it's video audio or just actually written forms. So it needs to be kept complete and it needs to be consistent with the purpose how it's being used. purpose selection notification to the person, purpose or person around collecting their information You need to let them know that Hey, I'm siphoning off your data I hope you're okay with that. they need to be able to know that Yeah I'm taking it I'm copying it It's okay Right You don't mind. and again this is at the time of collected and for the specific purpose of why you're doing it…Use limitations they need to have consent of the person or the law of 40 authority to disclose data. how are you disclosing it Do you have approval to do that? Do you notice notify the data's used for purposes stated in a different manner than what you disclosed So I'm going to use them for my research project Oh wait Then I send them to the sun or the national Inquirer on something that you said Yeah that's not right That's going to go badly for everybody Just don't do that. security standards basically do you have reasonable safeguards in place to protect the data? And do you have openness? When you develop your practices and policies were ground the data. be communicated What are you going to do with it How are you going to manage it? what do you how are you going to share it And do you have policies to protect it? the individuals should be. Be having individual participation as it relates to what do they want to do? and especially as it relates to personal data how. Are they okay with their data going across transporter…And then accountability organizations are accountable to ensure they comply with other principles as well. When they're dealing with the cross border data transfers. Okay So that's all I have for the CIS is P training Let us roll into the exam questions. Alright CISSP exam questions domain two…Okay Here's a question for domain two. What is the most correct term When an administrator is removing sensitive data from a system before putting it back into a less secure environment? Letter a. Erasing, let her be purging. Letter C clearing. Letter D. overriding and the answer is. See clearing clearing is an overriding process for immediate so that it can not be recovered once it is quote unquote cleared. Now we talked about before, clearing is a very important part Now if you are going to be working on the DOD standard and you want to have to make sure the data's completely erased, then you could purge the data with doing multiple overwrites. But clearing will be sufficient. in many cases especially if it's kept within the organization. you can just clear the device Now if you're going to be moving the device. to a different location than you'd want to look at purging the system…Next question. What is the following is the most secure method of destroying data on a hard disk drive in HDD, we have formatting. We have degaussing. You have destruction. And we have deleting what is the most secure way of destroying the data? And the answer is…C. destruction. All of them We'll delete the data in some form or another They will they'll all delete it and take care of it. But to ensure it's fully nuked and fully destroyed, you should are basically it's…de. Dead Yeah it's shredded. you should destroy it And that's really only physical destruction of the system itself will be the best method when making sure that the device there's the data is not available to individuals. So again that's a good one to think about destruction. All right. Let's move on…All right These are the links ISC squared study guide Quizlet. Also so there's some training from Thor teaches O E. D rainbow books and G X a. All right I hope you enjoyed this training from reduce cyber.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – HITECH
· CISSP Training – Compliance Requirements
· CISSP Exam Question – Preventive Controls / CIA Triangle
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Tech Target
https://searchsecurity.techtarget.com/quiz/Cybersecurity-risk-management-CISSP-practice-exam
Compliancy Group
https://compliancy-group.com/what-is-the-hitech-act/
Wikipedia
https://en.wikipedia.org/wiki/Arms_Export_Control_Act
Wiley
Transcript:
Hey Alice younger from reduced cyber risk and I hope you're all having a wonderful day in this beautiful state of Kansas I'm having a great day It's 75 degrees is going to be gorgeous today. It can be a little warm which is awesome It's also going to be just a little bit on the cool side in the evening which is even better. And the mosquitoes haven't come out yet That are the size of birds. I saw some small spiders running around which are quite large actually but yeah that's not bad My dog just eats those. But other than that life is good here in Kansas And we are going to be taught about some awesome things as it relates to cybersecurity today on today's podcast. But before we do I wanted to kind of go talk to you a little bit about Ru cyber risk and some great training that I've got out there for you specifically. And this is CIS S P train that you can get through you to me right now It's awesome You can just go to the site You to me and you can search for my name Sean dot Gerber or you can click on the show notes and I've got a great link to it on CISP training at reduced cyber risk. And it will take you specifically straight straight to you to me and get some incredible CISP training that I have available. you, and this is great stuff And as you know with you to me, They give you some really good prices on this You really can't beat it at all. I mean, honestly the bargain basement prices are pretty amazing just by going to YouTube and getting those. So again you can check those out@youtube.com or you can go click on my link at reduce cyber risk and get that C I S S P training specifically for you. All right So we're going to be talking about today The CISP cyber security integration. We're gonna be getting into a product called high-tech. Okay That's a health insurance. Uh in for our health information piece of this And we'll kind of go into that in just a little bit. CIS has P training's going to be aware on compliance requirements. And then the CISP exam questions are going to be on preventative controls and the CIA triangle. All right let's get going…Okay let's roll into this. So this is for Wikipedia and it talks about high-tech and high-tech is the health information technology for economic and clinical health act. Have to. Okay Yeah Say that 10 times and your brain will freeze and you're probably going what the Dickens is that. Well this final falls under the compliance aspects that we're going to get into and Wikipedia had a really good product about this and put it out there. Someone had obviously typed it into Wikipedia. And went through the different aspects of high-tech. And in high-tech is one of those things If you're dealing with the health insurance aspects and if you are studying for your CISP which I assume you probably are if you're listening to this podcast and or you're a cybersecurity professional wanting to understand a little bit more about these aspects. Because honestly when being a CISP myself, you get very niched and do a certain area. And so therefore you kind of forget or you don't really deal with these other aspects. And this is just a really good way of for you to kind of understand a broaden your capabilities. And this was per the anticipated the expansion of III protected health information, which is the electronic Phi And I don't know if you all are in the United States and you probably run this around the globe as well. I just got back from China and I notice that everything they have is online I mean you use we-chat for everything. They use Ali pay for other aspects. So I mean they are totally connected in China. And I think there's just it's It was when I was in India is the same thing Everybody's on their phone They're walking around the streets. So it's only going to be more and more of this Well in the United States we are all as to are are moving along in this base. And an electronic…health records are actually all out there. Uh right now if I can go online I can look at all my kids and what they have online. What what are some of the different cases are I have to go to the doctor all of my authorizations all that stuff is done online. And so this, this was designed to help with that electronic capability that just kept coming up as they kept dealing with this And this was passed by the Obama administration back in 29, 20 2009. And the goal of it. Was to reduce the cost of healthcare sharing as they're putting stuff out. And and so therefore it that's kind of why it came out was just to help reduce those physical costs…Now this is the design is that it would be if you're having data between hospitals and other entities that store your EPHI or your E patient health information, and that's the whole purpose of it So there's lots of information that is passed back and forth between an entity that let's just say you have a company that is a third party to a hospital, and these people work on MRIs. Well they have the ability to have some data of individuals that is passing back and forth. Well they wanted some level of privacy added to these and it expanded the scope of privacy and security protections for this data that is moving around. Tween these entities. And it also increased the light legal liability If you don't protect it Now one thing I've learned in corporate world is that you have lots of third-party vendors and these vendors will, are basically the little fish that sit around the big whale. And so therefore they are all servicing this big, the big whale Well what ends up happening is is sometimes these guys security isn't as, as intense as it possibly should be. And so therefore they induce a lot of issues to companies because of the simple fact is that they're tied in, well now you add the complexity So you know corporate America you have a vendor that takes care of you You have those requirements to make sure they protect your data, but now you add that additional component of having. Uh, per PII or Phi which is your patient health information. Potentially being stored by these third parties Well then what ends up happening is now you've just incurred greater risk by having these third parties involved within your hospitals. So therefore this was to increase the legal liability of individuals who do not protect this information. Now they had put out some monetary incentives back in 2011 to 2015 to get people to migrate to this direction. I know in China they moved people to we-chat and I honestly I can't even use a corporate credit card in China anymore just because everything is on Weechat. Well in the United States they've they've tried to move them in that direction They didn't really say this is the way it's going to be. And so therefore, And those incentives were set up until 2015. And there were penalties out for not acting after 2015 So for some reason you said, you know what I'm not going to do it after 2015. Then there were some penalties that you would have been incurred for not doing that…Well so it's 2019. And now what. Well, the thing is that's interesting is, and again this comes from Wikipedia So I don't know if this is truly the case It'd be interesting to see if anybody would provide some feedback around this but when it comes to 2019, There is an industry perception that it really isn't inforced that they're not enforcing any of this capability at all. And so therefore it's interesting how they're going to do this And what is the longterm play in this space Not really sure It it'll be interesting to see if there's going to be more enforcement. Now I am. You are seeing some things out there that there's more of this ratcheting up. However one of the things is just the perception is that it isn't really being enforced. Audits are occurring but many fields that they're just not very effective in what they're doing. And the one thing that high-tech had talked about the high-tech act was that if you have willful neglect and they have prosecuted some of these where you will be penalized and it but it is set up on a case by case basis. The fines will range anywhere from 250,000 to 1.5 million. At depending upon how willfully neglectful you are. So that's a lot of cash and you really not really focused on this And if you're a CISP going to work or a health insurer or a health company, and you're dealing with high tech, you better understand how you're protecting these people's information because it. Again I come back to this. If if you're not being audited and penalized now, it's, it will be It's just a matter of time. It's just a matter of time before there's a big breach or something large that happens. And then there will be a knee jerk reaction to then enforce these audits If they're not already being done. So the best thing to do is to work to strive to get towards compliance on these as best as you can, just because of sin. fact of it is is that you're going to have to deal with it at some point. And it's only going to get worse as we get more and more cyber breaches that occur. With in every career whether it's in the health industry or whether it's in manufacturing whatever it might be…Now high-tech also had a brief note breach notification and this breach notification is similar to others that you deal with PII disclosure. Now high-tech requires patients to be notified at any unsecured breach You see this a lot in pretty much anything out there deals with these unsecured breaches. But if it's got 500 plus patients, Then health and human services must be notified of the situation. Also in to include that your state privacy officer would need to be notified as well. So now you're not just involving the individuals that are involved the 500 plus people are at H S H H H S your own notifying the private state privacy officers that the state that they resided in. Now if you are a large hospital there's really good chance that you could have multiple states involved. So then you gotta deal with multiple lawsuits. So the fine is just one aspect of it So 250 grand of 1.5 million is the fine from HHS from health and human services. But now you Gail into lawsuits for loss of their privacy information Are there. There are data that that can go up and be millions as well So it's it really behooves you to pay attention to this stuff and to strive to deal with trying to protect the data. And I've also mentioned this before you. When it comes to these compliance aspects And again I am not a lawyer so do not take this as legal advice. But one thing that I would say is if you do everything in your power to protect information and we all know that people's data will still get breached from time to time, it still will happen. But if you've done everything you can to protect your data and put it in. In respect to what the is defined within the high-tech act. Then you are in a much better more defensible position in the event of a breach still doesn't mean you're not going to eat fine And it still doesn't mean you're not going to get sued by customers. However you're in a much. more defensible position than if you just say eh I'm not going to worry about it It's not being audited Nobody's caring about it Matt We'll just keep moving on. That is not a good place to be. So just just keep that in your back pocket Again not a lawyer, not the one that can tell you what to do. But it's just from what I've seen in this space in this world that doing those things and that due diligence goes a long way especially with the courts. They also talked about breach Patients need a first-class mailing and then they must basically Reese resolution to the issue And it must specify specifically what did you do to fix it? Are you putting them on some sort of, oh what do they call that I can't think of the name of it. Well you're dealing with the…identity theft protection those kinds of things Are you dealing with that Are you putting on people in there protecting their data through a Experian or one of those? And then if you have possible credit monitoring services that you may offer to them, all of those things they're going to ask what did you do to resolve the challenge that was occurred because of the breach? Okay. That's all I've got for this cybersecurity integration Let's move on to the training…Okay this is under the CISP domain one security and risk management. We're going to be a topic on this one is determining compliance requirements. All right As we all know compliance is a huge aspect as relates to cybersecurity and the CIS has P so one dot three of the CIS is P training manual that you'll get through ISC squared kind of talks a little bit about some compliance requirements and some of the things you need to be considering about that. And one of the topics is determining compliance requirements. So let's kind of roll into a little bit about this and see what you will we can kind of dig into but. Basically it's an overview There's an act of conforming or adhering to rules, policies regulations standards or requirements. And it's basically you must comply with these things And I kind of talk about there's a couple different areas There's, there's a big C compliance and little C compliance Well, when you're dealing with these big C compliance this means you must follow rules policies regulations standards or requirements And I deal with this on a daily basis. If you're a cybersecurity professional this is summer. that is near and dear to your heart and you must deal with it all the time. And our employees need to be trained on their responsibility around complying with applicable laws and the regulations And you need to make sure that you teach people this. And as it relates to cybersecurity in the past it's always been compliance Does one thing cybersecurity does another because we're under it. That is not the case at all I deal with our compliance folks all the time. I mean on it almost on a daily basis. And it's because not especially now with cybersecurity rolling into every space of. The world and from privacy to data protection you name it It's it's all over that Yet GDPR you've got Chinese cyber laws You got privacy laws that are in Singapore. Yeah all over the place. So you're going to have to deal with these Now you've got states that hell have different laws that are involved in So you have you get called in on a routine basis to kind of go over. What do you think about that I mean just to be honest I've got emails in my inbox right now to talk about those specific issues. So those are things you need to consider and it's very important to overall in your overall. governance to understand these pieces. Now as an example you got PCI DSS Now there's extensive training available and required that you have to do when you're dealing with PCI DSS. And I've also got on reduced cyber risk of get some more training that's available for you on the PCI aspects that are kind of go over that specifically and some specific training around it. But there's 12 main requirements are as a firewall configurations. There's a unique voice. A vendor supplied default passwords That's a big one, encrypt transmissions between locations And we'll talk about in future podcasts around some different kind of transmission protocols and with encryption. Uh restrict access on car data to only the people that need to know, not the guy you hired for the summer That's going to be surfing the web on the computer that holds all that information. Not not a good idea Just don't do that. And then there's many many others obviously but bottom line is there's some key things that you must maintain with your when you're trying to get PCI DSS certified. And so as a vendor who or as an individual. has a credit card at their location. You're going to have to make sure that these things are set in place. Now there's different PCI criteria that that are available for you. That you, you need depending upon what your company does where you'll have to follow. But bottom line is is that you need to maintain these And so therefore as a cybersecurity professional, you need to make sure you're in compliance with that specific regulation than that rule…Now when we're dealing with contractual legal and industrial standards this is kind of an objective that's on the CIS. And a privacy has been, been and continues to grow as a hot topic within the United States And we see this all over the United States. Especially in the California and I'm seeing in Massachusetts but you're also seeing it states that don't typically fall the California Massachusetts type of timeline where you know those are the key drivers the key. Ones that many people use to guide their direction around cybersecurity are actually around privacy And there's many other states now that are adopting this piece countries were addressing this as a digital age continues to grow And yet China us EU, and this will vary from country to country. And I've also noticed like even within China the country may say one thing, but even the provinces have different perspective of what the country is saying So you've got that dynamic to deal with as well. You have us privacy laws and there's a fourth amendment of the us constitution And this kind of talks about this And this was again obviously the constitution was dude done in 1919. Uh 1770, I think it was 78 is when the actual constitution was done up. I get I I think I screwed that up Probably they'll probably be somebody that'll let me know No, the constitution was donut in 1786 and 20 two-toned high. It's I think it was two years after it was actually ratified. Are they actually the signers sign The, the, yeah What did they sign? I'm blown away. It's all right It's quite early here in Kansas And so I'm half asleep as we're doing this but, but it's a right for the people to secure their persons or houses or papers and effects against unreasonable searches seizures and shall not be violated And this was designed in the United States around the king. The the the United Kingdom and England coming in and they're they're soldiers undoing unlawful search and seizures. And just basically just ransacking the place trying to find what they want and what they could about you. And there should be no warrants shall issue, but upon probable cause support by oath or affirmation, and particularly describing the place to be searched and the persons and things to be seized. Bottom line is you can't go in and just grab people's stuff And you got to have a warrant to say that you're going to do it as the United States I don't know how that is in the country of where you're listening to this but it hopefully you have something similar to that. Bottom line is though is us constitution spells it out So you can pull that out when someone tries to do it. Changes to the amendment have included what we call wiretapping to include with, with now it moved into the. I was the it wasn't the digital age. 'cause wiretapping has been around right after obviously in the early 19 hundreds is when the a that started all coming to be. And these these. Laws are woefully inadequate In some cases they're actually getting better over time. But I think in many cases this just they've had. key try to keep up with the digital transformation which is extremely hard and challenging…The privacy act of 1974 the federal government this is where they deal with private information about individual citizens. And it's get puts limits Thank goodness on what the government can do. Now It doesn't mean that they're actually following it You would love to say they are but there's lots of wiggle room in legal language. And so therefore they do these things And this is kind of also where the Patriot act came into play. And we'll talk about that later on but it allowed them to use SERP Some of these privacy laws that are in place and they had to go back and get resole or re get it reaffirmed every year. But that's one of the thing that's that it's a whole different animal. There's only applies to government agencies in this case here So when you're dealing with privacy is it comes down to is that only government agencies will be able to limit that about individual citizens and what they can actually do. Now the exceptions are health and safety census law enforcement court orders and national archives. And again those those could be. Tweaked a bit to help you help the government get what they want. But bottom line is those are the main exceptions to the privacy act of 1974…Now the electronic privacy act This is basically came out in 1986 which is kind of more my generation. And yeah that just dated me I'm like really really old it's basically it was to evade. It was. Designed to invade the privacy electronic privacy of an individual It's a crime to do that And so therefore they wanted to put this in place. And it helped broaden the federal wiretap act that had been put in place in the early I think it was in the fifties that they put that fifties or sixties They put that in place. I'm probably wrong on that as well. But it it prohibited the interception of the electronic communication So they just couldn't go out and start sucking down information about you as it related to our proper warrants Right. And it's illegal to for mobile to tapping to mobile phone conversations. Now that has changed a lot in this from 1986 from when I had the big old bag phone that I put in my car. With an antenna and it was just it was tied to a wire. That's come a long way since then or now everybody has mobile phones and you. I still say I walk it through India and you know they got 1.4 billion people and everybody is on a phone Everybody's got their head down walking on a phone. It's just it blows my mind And that's what that's kind of what cellular technology has done is it's helped expand these networks. Two places where typically phone coverage wasn't covered. You didn't have phone coverage and now everybody does It's connected the world even more. Communications assistance for law enforcement This act as a 1994, and it allows for communication carriers to, to allow for wiretaps Now that's where this came into play where you could actually get into mobile phone conversations. Of the 1994 and hence that's why because now they went from bag phones to everybody has a cell phone…Now the electronic economic espionage act of 1996 this diff extends the definition of personal property into the electronic property. So now you're getting you're getting out of this whole physical. Data or I have a check now for a bank I now have an electronic apple pay account. So it's going from personal property into elect. property. The health insurance portability hiphop that was set up in 1996 This is privacy and security regulations incorporate into the law. These are specifically set up as they were set up in that law. And then then we get into high-tech which you talked about earlier, and this is the health information technology for economic clinical health act of 2009. And this was also to help update the HIPAA and privacy and security requirements as it relates to what. What's in place and it deal with the, the technology The EPHI is we had talked about before. And the bottom line is it comes down to breach notification again over 500 individuals You have to notify HHS. And then also the state privacy officers as well…Some other notable mentions around this would be Copa And this is a big one As it relates to taking care of kids online. This is the children's online privacy protection act of 1998. And this is basically online privacy for children. And there's the Gramm-Leach-Bliley act of 1999 This this is a the financial restrictions between institutions and allow more communication between them. The one thing I wanted to come back with Copa. That's actually a really good thing that they finally put in place for that And it helps add put a little bit of restrictions around what you can show children what you can't. I would say in some cases that are kind of pushing the envelope on some of that a little bit. And again that comes down to what some people believe but. It's as as data becomes more and more open and available, you really got to watch what's out there for these kids because some of this stuff is pretty, that's not so good It's That's so good. You just Patriot act to talk about that of 2001 that was a result or a resolution of nine 11 that it hit New York trade centers and took those out. And it basically allows for blanket authority to monitor a person. Now it's set to expire in 2019. It's reviewed by Congress and it has been reviewed over the past Yeah I mean I guess every year they have to reaffirm it or every two years. And they have to reinstate this Uh, again I think at this point in time it's interesting to see it's one of those things It's like taxes Once you give once you've set up a certain amount of taxes and you pay taxes. It's really hard to revoke those taxes In many cases they don't Virgo away They always just stay there and you end up making more money to offset the cost of those taxes. Same thing comes into place around this with the Patriot act. They got Congress doesn't want to lose their control And so it'll be interesting to see what happens with it I think people are finally getting fed up from a privacy standpoint. That you know you're protecting us from the bad guy whoever the quote unquote bad guy is of the day, but at the end of the end of it what do you lose from a privacy standpoint which is very different than some other countries don't necessarily care so much. But I would say here in the United States it's becoming a more and more a problem. This with me. I don't, I'm not a big fan of it I'm. I'm former military And I I'm all for having the government have control in some cases to help protect the citizens, but it needs to be a restructured and limited cause at some point then it becomes ultimate power and that's just not a good thing So. You got to, got to kind of watch that and put checks and balances on that. On the family education rights and privacy act FERPA. This is for parents students with parents of students with the rights with educational institutions So. this is how you set this up with educational institutions that they ma manage the rights of your students. And then identity theft and assumption deterrence axial That's all these lots of bills lots of laws, severe criminal penalties for identity theft So this kind of falls in line with when you deal with identity theft if someone steals your stuff, They get nailed with multiple things They'll get nailed with wiretap They'll get Neal nail with money fraud with money laundering They'll get nailed with in this case here identity theft and this could be a $250,000 Fine Up to 15 years in prison term. So there's a lot of things you can get added for doing this identity theft stuff. That's why, again that the upside might be good You might think it is you get some short-term cash and you can be living large for awhile. But the downside is you got to break big rocks into little rocks and that's not just a good thing So there's the issues as it deals with identity theft and assumption deterrence act…Okay So that's all I have for the CIS. SP training Let's roll right into the exam questions…All right these damn questions are over domain one…All right Here's a question. Preventative controls. Okay That's an authorize the president to designate those items that shall be considered as defense articles and defense services and control their import and export. All right So what does that mean What basically means is that there are is true because there are controls in place that the government can put in place that gives the president the ability to put in restrictions around what can and cannot be imported and export. Now the arms control act of 1976 does this this gives the president the United States the authority to control import export of defense articles and defense services. Typically this gets called into play is the cryptography. And so therefore various cryptography and or cryptographic technology can be limited based on import export laws. This has been in the past This has been seen where we used to have the Cray supercomputer which in today's world is probably old school, but it you could only export certain technologies and that even and when it gets to the UK I know they, they didn't have all the technology They they could be potentially sent to the United Kingdom. And so those are the president of United States can authorize that Now that goes both ways right The government other countries do the same thing to the United States for import export. I know Israel Israel has a lot of stuff that they make specifically internally to them that they do export and sell. But I know they keep back some of the things that are specifically to their country. So those are aspects around it that you've, that you'll understand from a CISP question. It's the arms export control act of 1976. For anything that might be used from a defense standpoint for military purposes can be limited. All right Another question is vulnerabilities and risks that are evaluated based on their own threats against which of the following Okay So we have a one or more of the CIA triad triangle. Principles. B data usefulness…See. Do care. And D extent of liability. All right The answer is dun dun da. One or more of the CIA triad Brian's principles All right So when you're focusing on vulnerabilities and risks that are evaluated what do you do against them You focus them on the CIA which is confidentiality integrity and availability. How do they affect each of those three? That will then determine how do you want to deal with that specific threat? So therefore when you're evaluating it you focus on the CIA triangle and it really is that it comes back to that If you can focus on those three things, how does it affect confidentiality? How does it affect integrity of the data? And how does it affect availability of the data? Those are all very important pieces that you need to keep in.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will discuss the salaries associated with the CISSP and other cybersecurity roles. Also, he will discuss about setting the expectations as it relates to taking the CISSP exam.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
Hey all is Shon Gerber with a C I S S P cyber training and reduce cyber risk podcast I hope you all are doing well This beautiful day. And just say it's great here in Wichita Kansas So I love it It's awesome. So quick question for you We are just today we're…episode five This is the ongoing series around how basically. The CIS S P cyber training got started. And we're just now rolling into this next podcast We're going to be talking a little bit about CISP expectations around salaries and so forth. But before we do we'll kind of talk back about what we did And we, we discussed in the last episode and it was around understanding the CIS S P certification and preparing for the future. One of the points brought up is that it you are certified you do run the the ability to potentially make at least 22% more than being non-certified. Now I've seen that article out there and I I've quoting that but at the end of the day it really comes down to experience So having the cert is extremely valuable. However having the experience is as much if not more So, so just kind of coupling to just consider as you're looking at this. We talked about the CISP and the requirements around it as well as having the experience needed to become a CISP. There's a all the three areas the three concentrations would be your architecture engineering and management. And then we also discussed a little bit around the associate CISP and the additional certifications as it relates to security plus and network plus. So that was just kind of the last podcast and servers are a four And. The ultimate point was just to kind of walk through these different areas and to give you an idea of where we're at. So now as we're dealing with expectations around the CISP and taking the exam, one of the big things that you see I see online quite for. is around the salary as it comes to being in the cyber security. Now there's a lot of things that will break down the salary and I've got training at over at CISP cyber training I've got a an actual training specifically and you might even see it on YouTube Cause I'll put it out there. Where around what can you expect based on the role that you're looking to do? And a lot of things When you start off as a an individual that's trying to get into security into the cyberspace. Your pay can change quite substantially depending upon the role that you actually take. Now I pulled off via C squared They they have uh, an article there on their website and they're the ones that put forward The CIS is P along with a lot of other certifications but one of the things they bring up is kind of the breakdown in actual income based on where you're at. So a in the Asia Pacific region they're basically saying is around 57,000 us dollars is what you would make. Europe is around 81,000. I think north America they're saying around 120. is what you can anticipate. By getting the CIS as P. Now I will tell you that that will range And also the other thing is it really depends on the role. You can get the CISP and be a security analyst and you'll be making 70 to 80 maybe $90,000 a year, which is…amazing Right I mean that's really really good income, but you also could be a CISP. Being a chief information security officer and make substantially more than that. So it really depends upon the role just getting the certification does not automatically include that you're going to get paid that amount of money. It's a great cert but it's not that great of a cert. So kind of keep that in mind Now also keep in mind that the pay will range a lot from location to location. As I'm out interviewing people for different roles from security engineers to analysts. You name it you know you you've ended up architects you end up interviewing them. And as you interview these individuals, you also have to keep in mind where they are at. in there Where they want to live. If you have somebody that's in New York and they are going to stay in New York, what ends up happening is is their pay is probably going to be substantially higher. However if they were in Wichita Kansas their pay might not be as high as it would be in. And in New York city. Now you go to Asia you go to India. Now the pay compared to us standards would be lower. However in India it would be substantially higher So again it really depends on the geographic location of where you're at. It's all relative It really truly is. So you need to keep that in consideration as you're looking at getting a job some location. The other thing that comes into is if you're looking at working in New York, the odds of finding, having more competition is higher. So therefore the role that you may wish that makes the income that you want. May not be available to you unless you have the experience to back it up. So it isn't just again it's not a meal ticket You don't just punch it and you win That's not this isn't a lottery. However, if you do accomplish these different goals, you set yourself up for extreme success, both short-term And long-term because this again, this isn't a short-term game This is a long-term future that you want to do for you and your family and your career. So therefore it's extremely important that you think that way. Don't just look for the fat the fast money. Another option as it deals with making money is the fact that as you can end up commanding a very significant amount of income based on what you're willing to do. Now let's talking to other…The sows that are in my position. And one of the aspects came up as he said, we were talking about compensation And how do you look at compensation for other security officers What what would the be the norm. And it will again it will vary from position to position. However one thing he did bring up is he said if you're willing to do some things that other people aren't willing to do. You obviously could make a lot more money. Now again one thing you got to think about with ISC squared and being coming to CISP, it's gotta be ethical It's gotta be moral It's gotta be something that you would do that you have to be able to hang your name on. Now you can go out and be in criminal and you can make a lot of money but that is not where you want to go Okay Short term, short term the money may sound great but let's be realistic. There's a lot of a lot of downsides with that besides being ethically wrong. First off is if you get caught. That the downside is you break big rocks into little rocks You are is not a good option. But that being said if you are an expert in what you do, you can then be an individual that would go to a company who may have been hacked for example. And we call it the dumpster fire situation, where they have a total dumpster fire going on right This company just got hacked Their security person is out. They maybe they don't have a security person. You now would be parachuted in and you can help them with their situation. And by doing so you could command a. significant income from that. Now that being said there's a lot of risk with that as well. If there's risk there's reward right You got to decide as a reward is high Is the risk high baby Maybe not. But that being said you could come in, you could make commander. A large salary, you can help them protect them and then maybe move on and do your own thing. And that's more of a consulting type gig. The other option is that you can go potentially hang your shingle. You're basically I'm open for business on Upwork or other contracting type websites. And you can say I'm willing to do X Y and Z. A good friend of mine That is in when I was an aggressor at the 1 77 information aggressor squadron. He was my counterpart with the active duty air force. He I've talked to him just the other day and he's got a consulting company and he does that right now out of his own consulting business. And he's done very very well. Now the downsides of that obviously are the fact that you've got to have a good plan You've got to have money set aside because when jobs come they don't all come in at this at a very program time. It's either feast or famine. So you've got to have a good plan for that, but there are options right So when I throw out these numbers at you keep in mind, this is based on a workforce You can make a lot more than this. If you're willing to do different things. That are both legally and ethical Okay Just set that expectation. So as we go into jobs what are some different ways that you can understand how that works? Okay So I'm going to throw some titles and I'm going to put out some sample jobs that are out there pulling off numbers from glass door, Upwork and other areas. So let's just go a cloud security engineer Now cloud security engineer can range anywhere from 70,000 to 120,000 us dollars I'm going to put all this in us. If you're listening to this in India obviously you look at rupees and figure out how you want to convert that But again and that would also be different in India. Uh the pricing obviously is about 30% less if you're in India, but the overall buying power is about the same. So your cloud security engineer is around 70 to 120,000 us dollars. Again depending upon your experience will get you more income. The cert will help but the experience is what makes you the more money. Security architects and various. All variations of this will range between 90 and 180,000. I know there's people that have talked on YouTube that they make 200,000 pluses in architect. You can I mean there's bonuses that are included in there You can definitely make over $200,000 doing it. But again on the flip side is is there's pros and cons for that Not everybody does that Let's be real Not everyone makes $200,000 as a security architect. Now there's many that making the a hundred and fifties a hundred and sixties. And coming from a guy that was broke right I mean I have seven children and I have no money. One of the aspects that came up if I was making a hundred thousand dollars a year, I counted my blessings and I was very happy. and that was even making a hundred thousand was extreme life changing for me and my family. So that that's huge Right. Security analysts will make anywhere from 60 to a hundred thousand and then a chief information security officer can make 110 ish. To two 50 or more depending upon again bonus structures, other types of activities and what you're willing to do. Talked about contract work with Upwork And as one example is I'll just give you an example that I saw on Upwork and they go I need a CIS SP to implement TSA which is a transportation security or safety expert security act I don't know. Requirements. You could also have someone comes in and says, I am part of Fat's in the United States which is the chemical facility anti-terrorism standards I need somebody to help me implement that. I have a government contract to help me do that. There's CMMC which is the cybersecurity maturity model certification. I need people to help me get my business up to the CMC standards. There's lots of ways you can use that your CIS SP to help you Moonlight on the side Even if you have a right a job right now doing something else. Again doing that is a great way to build your resume It's also a great way to for you to get a new opportunity. So there's lots of ways to do this. The hardest part is getting started, making a decision and get started. In most cases these are set up as hourly right You'll get paid a certain percentage or a certain amount for your time that you work. You're also going to have to get you'll learn during this process especially if you're doing like an Upwork type event. You'll figure out what is your time worth and what are you willing to commit? You may be willing to commit, say 20 hours at a much lower rate to get the job. Because you need the experience and you need it to put it on your resume. Then maybe someone who comes in who has all that experience already and really doesn't need it and is willing to take wants to take more money because their time is valuable to them. So there's lots of different things you can think about in that regard…Now as it relates to CIS S P certification costs. One thing to keep in mind is around. What is it going to cost to do this To get certified? Now there I mentioned before in past episodes the free option. But like everything there is nothing free. What you're going to have to do is you will have to buy a book. Okay I guess you can rent it or you can go ahead and look at it from the library. But in reality I marked my book up I made copies I made notes I stuck sticky tabs You just just break down by the book I mean realistically. You're talking a hundred dollars that you're going to have to invest to buy the book. Now you're also going to want to get some practice questions. Now there's practice questions on CISP cyber training I have some available for you. You can go out and find other practice questions online that are free. But you also can go out and buy some that are better curated, and that will give you a much better experience. And so those are options you need to consider. So your study guide your study questions are a hundred dollars Your practice questions will go from a hundred to 300 So right now you're all in at around four to $500 before, honestly before you take your test but this is now you're going to spend your equity We call it sweat equity. In learning to do do you get the your CISP and that's what you're going to need to invest in is you spend the extra four to 500 which it can be very challenging to find that money I know been there done that Got the t-shirt. But you may have to do that to be able to then put your sweat equity into your business, to be able to make the money you want to make so that you can have the life that you really truly want. This is attainable. The only thing that will stop you from making your dreams and a reality in cybersecurity is you. You are the person that has to make that decision And you're the one that has to do the work. Now the free training is out there Again I come back to this it's you get what you pay for now There's some really really good free training There truly is. And I will tell you some of the networks plus and security plus an A-plus training I saw it on YouTube is amazing. And. I recommend it And actually it's some of the curated stuff that I've I've got in my site is to recommend that training for you. But what really will help you is the fact that you're having somebody keeping you accountable and helping you walk you through this process is a really important factor. Again we talked about the paid specialized training. You can get that in various locations either If you want to drop the money on a bootcamp. You know five six $7,000 or more. Or if you want to do it a little bit more cost-effective by going through CISP cyber training or other type websites out there, bottom line is you need to consider one of those options. The boot camps they will run anywhere from five to seven days And bootcamps will cost anyone the upwards of five to seven potentially even $10,000. Depending upon if you're going to be in-person or online. If you're going to be in person you got to pay for hotels food transportation so on and so forth So that can add up quite substantially over a period of a week. The exam fees are usually included in them And many times they do guarantee success. They they have their instructors have been teaching the test law enough and know well enough what are the exact questions that are going to be asked of you? So they will give you a pretty good understanding of what you need to be paying attention to. However that being said, Just because like I mentioned before you because you get the test does not mean that you're going to just automatically. Get everything you need to be successful in cybersecurity. So I'm just telling you it's it's. The boot camps are great I'm not knocking them I think they're a great tool for the right people. Just the fact is though is just because you get the cert. Doesn't mean you're going to get the job. I think I've beat that horse to death enough I hope I haven't. I probably have a anyway trade schools trade schools universities again another way that you can make the money or get the training you need, but they do cost more money and there's it finding good instructors can be a challenge. Okay so some questions around the CISP. The CIS is P there was a question that came up that I looked online is the CIS. P a hard exam. Yes it's a hard exam. It. not easy Consider it like taking a master's program in security Some people may get it faster than others but it doesn't matter It's a tough exam. It's computerated testing which means it learns. If you do poorly on a couple of questions, it will ask you more questions like that That are just as hard If not harder. And the purpose is is to weed you out early. You get six hours to complete this. And it may not take you that long but you're allowed that specific amount of time. There's 250 questions. And again the exam is pretty expensive. It's at least two times the other exams you're going to see out there like I talked about, so it's about 700 to $800 us dollars to take it. I don't know what it's costs in other countries but just assume it's going to be. Pretty high there as well. One thing I think is important for you to know as you're listening to this podcast the pie the pass rate for the CISP. Is for the first time the pass rate the first time is only 20%. So only 20% of the people who sit down and take that test. We'll pass it the first time. And I'll raise my hand because guess what? I was one of those that did not pass it the first time. So and then I'll tell you that that's a brutal it hurts your your F your mentally. It hurts you financially, and it's a it's a kick It really hurts So again you want to set yourself up for success and do the best you possibly can so that you pass it the first time. Now is the CIS is P for beginners was a question. No it's really not It's not a good test for the beginners. But it would because of the work requirements because of the endorsements, because of the fact that you really need to have a good understanding of networking and understanding that aspect of it. It is probably one of the most hard certifications out there It's not the hardest but it's it's a very challenging cert. So it is not for beginners. You need to focus on getting the skills you needed to go and you can get those@cybercispcybertraining.com I gotta put the plugs in just gotta, but that will help you with getting your path to success. So again CISP is not for beginners. Now how long does it take to become a CISP We talked about that before through the podcast about five years experience. Full-time employment at least two of the domains which we mentioned of those eight domains that asset security identity and access management and so forth There's there's many different domains. Eight total. But the point is you got to have full-time employment in those college courses or certifications We'll give you an extra year towards that five-year work requirement which basically means if you take go to school and or you do the cert, you will be able to you'll have four years to get the knowledge you need to be able to get your CISP…Now as far as preparing for the test, you need to self study is about three to six months I'll just be honest with you all there's guys out there They'll say I'll help you get it in 30 days I'll hope you get it in 60 days…Again you have to listen to it and see if it's worth it to you If you know I'll tell you from a guy who's got 21 years experience, can you potentially pass this thing in 30 to 60 days? Yeah you can, if you do. everything you can in the next 30 to 60 days to just study for that test you probably can do it I feel confident you can do it. However it would not be a phonics. Uh invent you would not be happy And I personally feel that all you would do is you just regurgitate the information. Pass a test and you dump it. Not to say that that's a bad thing I'm just telling you that to really truly understand the CISP and to understand some of the concepts it's going to take you three to six months. With having a life outside of studying. If you have a family if you have a job, it will take you a good three to six months. Everybody I've talked to that has done it. It's in my world. They will all say the same thing. Okay again. CSSP cyber training I got resources that can help you with that too Again, if you're going to spend the time let's help you walk through it. Bootcamps are available And again they do help compress that timeline So you can get this thing done in a week right. Uh but you've just got to spend $10,000 They're great for the short term, but the other thing that comes out of that is is if you don't have a long-term plan to keep that knowledge going, you'll remember it And then you'll forget it…So one of the other questions that came up was what does a CISP S P do. Okay So this is a question that you'll see online is what is a CIS S P do? Well the certification will help expose you to various concepts that you may or may not have in your current role. And that's the ultimate goal so that you look at something with a different perspective. As an example I was talking to my intern and we were talking about how security is set up and some of the concepts that I gave to him around. Information rights management and protecting data through encryption I was a total changer to him And he looked at now from a different perspective. That's the ultimate goal of it is to provide you that knowledge. Another one is around secure development life cycle I was talking to my security my developers a few years back and mentioned secure development life cycle. They had absolutely no idea what I was talking about. But as I brought it up to him and explained to him that, oh that makes sense to them. The other part is around like security and risk management. One aspect of this as the TSA sea fats China's cyber regulations that falls under governance and regulatory requirements. If you are insecurity at all. If you feel that you won't ever deal with regulations I'm sorry to tell you but you're wrong now You may not deal with them right away when you get first get started as much as you will as you get more time in with the security space, but you're going to deal with them. So you're going to have to understand them. And I don't like them I really don't. But it's one of those things that if you don't like you better do more of so that you end up do liking it. And I will tell you that I've gotten really good at it Not because that I'm a genius by any stretch of imagination I'm Michael Small guy from Iowa I mean, I live in. I was a pig farmer. I mean that's where I came from. That doesn't mean anything about intellect It just means that's what I was exposed to. And I'm pretty good at regulations. And it's because of the fact that I have focused very strongly on it because I know that all. cyber stuff is great but the governments whatever government is can come down and totally crush you. If you don't have these things in place and if you're not paying attention to it, So better pay attention to it. Now that's really all I have today for this part of this podcast. Now this podcast again was over CISP salaries testings and also setting expectations around the CISP. I'll say going forward you're going to have more podcasts out there We're going to be focused primarily on the CISP the different domains I'll pull out a domain as it just to give you an example. The one coming up next is dealing with compliance requirements and how you have to worry about that for the CISP. And those compliance requirements will be going over What are some things you need to be concerned about? And what are the things that you have to be worried about from a security professionals perspective? I'm going to deal with data remnants, identity and access management logging and monitoring cyber crime. All of these aspects I'll be taking out of each domain and I'll be talking about specific pieces of this both from my training That's at CIS. SP cyber training. As well as my knowledge in what I know. So all of that stuff you're going to be seeing from now on you'll also be getting it'll be coming out in these podcasts exercises Right So your your exam questions. So I'll grab an exam question and I'll read through that exam question and then we'll dissect it and we'll talk about it. Now the ultimate goal is I'm doing this through a podcast I do put this out on YouTube and you'll see some videos. They may not all have video in them They may just be audio. But at the end of the day my goal is to provide this much information as I can so that you can become successful in your cyber career or on the other side, you realize I don't want nothing to do with this. And this is not for me. I'd rather have you figure that out now before you spend a bunch of money and time getting into the cybersecurity space, it's not for everyone. Just because the money may or the may or may not be there or because it sounds sexy or NCI S or whatever's out there. It's not for everyone. So it's better to find it out now before you invest a bunch of time energy and money into it. Okay That's all I've got for today Thank you so much for joining me on this podcast Again the CIS. Cyber training.com Go check it out. There's a lot of really great stuff there You will You'll totally enjoy it It's building So as you get there you'll see. Hey there's there's lots of information here but there maybe there's a little bit more coming every single week There'll be more information coming to you. So definitely check it out get on my email list because then I can send you information such as met with a gentleman just yesterday talking about his resume. I'll be having some tips and tricks about that as well. And so go check it out also. Go on to iTunes and these other places and give me a thumbs up or like me or whatever that is. Or leave a leave a comment as well. I really want to help you all And I know you'll be successful Just let me help you either through the podcast or through my website, give you what you need. All right Have a wonderful wonderful day and we'll catch you on the flip side. See ya…
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
…Hey y'all Shon Gerber with. CISSP cyber training.com and reduce cyber risk podcast. So how are you all today It's a beautiful day here in Wichita Kansas and it is an amazing amazing place to live in a beautiful country that we live in the United States It's awesome. No…Hey all this Shon Gerber with the CISSP cyber risk. No…Hey y'all is Shon Gerber with the CISSP is P cyber training and they reduce cyber risk podcast. Hope you all are having a wonderful wonderful day to day. So I'm having an awesome day here in Wichita Kansas It just it's amazing It's very nice It's actually the weather it's beautiful to bike 45 degrees So it is a great day. Well I hope you all have had a chance to listen to my other podcasts as it relates to the CISSP. Cyber training And the day this is episode four we're going to understand that the title of this is understanding the CISSP S P certification. And preparing for the future. Now, the last podcast we kind of talked a little bit about what how do you get into cybersecurity What is the training path and so forth? And this is kind of a follow onto that to kind of talk about the CISSP as P and why it's important. Now again a little bit about myself. Shon Gerber I've been in cybersecurity for 20 some years and I've got my CISSP and I've been doing this from a level of going from actually having no experience in cyber all the way up to being a chief information security officer So I understand this path and I've taught hundreds of people how to deal with cybersecurity from both from learning how to be a hacker up to the point of. Getting their CISSP. So I'm here to help you in your path Well, one of the things that comes out of this. is understanding how do you do this? Well, as we talk about how do you get your CISSP a couple things have come up from the conundrum around, how do I get my training How do I get into cyber And we answered that in the last podcast. Around some of the questions they have you know most of my students that I teach in college and I've taught in the past, they really come back and say they have really no idea what are the next steps. And so we went over that in the last podcast What are the next steps in How, what can you do to get past that space that space. The other thing is we had questions from business leaders around how do I find people in find open roles Well again, how do we get there with a train that's tied to that? And what can you do to become successful? And so we walked about that in the last episode but today we're actually now going to talk a little bit about how is what is the CISSP and how does that specifically work? So, as you all know the CISSP is P is one of the premier certification. that you need to get If you're going to become a long-term professional in the cybersecurity space. Now it's not required, but in reality it's it's held at such a high bar that most hiring companies really do want you to have the CISSP. And we'll kind of go into reasons why they think that and what's the purpose behind it. But one thing to think about if you get an it certification one of the things that come out of that as you say, you've got about a 22% better chance of being, of getting more income than being non-certified. And the reasons behind that in many cases is because the HR folks the individuals that are looking to hire you don't really know what they're looking for So they use a certification as a bar as a litmus test for you to basically get the role. Now if you have lots of experience and you don't have the certification, well that's fine too in many cases but there are some situations where the HR or the hiring manager may require the CISSP. Not necessarily realizing what they're actually requiring. So that's why it's kind of important to get your CISSP SP. As you're getting your CISSP There are some things you need to keep in mind. Why don't you got to have at least five years of experience learning and understanding security before you can even become a CISSP. And of that five years you have to have full-time employment in at least two of these eight domains that are tied to the CISSP exam. First one is I don't I've gone through the domains and you all have probably heard these or dealt with these especially if you're trying to get your CISSP SP. But for folks that have not really understand what are those domains What are those learning areas? Here are the eight. You have security and risk management. Assets security, security architecture and engineering. Communications and network security. Identity and access management. Security assessment and testing. Security operations. And software development security. Those are the eight domains that are tied to the CISSP exam. So what they're saying is is for you to get your CISSP. You can sit for the test pretty much at any time, but you cannot be a C I S S P until you actually have those five years experience. And you have to have again full-time employment that deals with at least two of the eight domains. But you got to understand that doesn't mean you have to be doing security necessarily in those eight domains. You have to be able to understand what are the domains Let's just say asset security for an example. And let's say you are in. It management and you're dealing with various servers. And you are responsible for those servers your work at a an it shop of some kind right. And you were responsible for those servers? Well that's the asset That's an asset security You could understand How do I best protect those assets? The other part comes into it is you could also have them tied into maybe you have development team that you work very closely with and they use those servers and you have are able to work with maybe the leader of that development team to help provide them guidance around software development. And what can you do in that area? That would also be a way that those would be two of the domains. And again there's a lot of there's a lot of openness in that. And it's not the fact that you pad your resume or you pad your knowledge which basically means you don't. Musically say you have more knowledge than you actually do, but you look for opportunities in your current role to help touch in all eight of those domains is many of those as you possibly can. And then you just have to be able to describe that and demonstrate that on your resume to the person who's going to be signing off as the CISSP is going to be signing off saying yes, Shon is qualified to become a CISSP. And that's something that I ended up doing is if someone comes to me, I look at the resume I do an interview Alfa the eight domains and I determine whether or not they actually have the knowledge they say they do. So those are parts that you're going to have to go into but that's okay because there's so many ways you can learn and get knowledge in these eight domains…Now the next step is your your concentrations. Now they do have a CISSP SP concentration is basically an add on now You don't necessarily have to do this You can just get your S your CISSP exam, but if you feel confident that you want to have the ability to get an add on after you get your CISSP you can go and sit for a architecture. Engineering or management add on to the CISSP S P a certificate. What it basically says is that you the CSSP understands the large, you you have a good grasp of that. But let's say you are really good at architecture and you enjoy that and you want to have an additional certification tied to that. You can go sit for the architectures, add on and then you can become a CISSP slash architecture. Now there'll be additional. and additional CPEs and that's continuing education professional education training that you'll have to do. But at the end of it it it just it's a personal preference. Is it needed, not necessarily unless the job that you always want is requiring it, but short of that it's not a necessity that you have that completed. Now the associate's CISSP is P you may have seen some information around that. Now the associate was designed to allow people to get into and start understanding the CISSP as P ahead of time, and maybe get the test out of the way while they're building up their experience. Now you have to be a practicing security professional. How are you, how are you actually working in the security space within and studying for the CISSP? You now and as you do that they they talk about having at least five years of full-time paid work experience which we talked about to actually get the CISSP. But you can get a various other additional training that will help you with getting that requirement that five years. So at the associate you can go in you can take the test you got that out of the way. And then if you go to college let's say for example you go to a four year school. Yeah that will count for one year of the five years that you have going towards being a CISSP…Now the other part is is…you can also take another certification So as an example if you go get your security plus certification, and there's a whole laundry list of various certifications that you get. If you can get one of those that will also knock off a year from your five-year requirement. The other thing about the associate program that is kind of important is that it allows you to get take six years to complete the five-year requirement. So it's designed for people that are maybe going to college and you end up you don't have time to get your you're spending a lot of time in school and you don't have that time to get your five years. You can then go out and take the test, be part of the associates program. And then it gives you basically an X. year. Now one thing you can't do is you can't use both the certificate or the certification process like security plus, and then the college degree you can't use them both to count for once for one year ones for another year. And that would be two years You can't do that. The most you can shave off of the required time that you have to have before you can actually become a certified CISSP is four years. Okay That's the actually say most you can shave off is one year. And so yeah it does require you to have four years experience at a minimum, if you have an additional certification or if you have gone to a school and therefore I bypass that product. Now, so that's an important thing to think about now the associates CISSP. I I'll tell you point blank I'm not a big supporter of it I don't think it's really useful other than allows you to take your test early. And but it adds a lot of complications to the to things So you just gotta decide if there's a situation where it may benefit you then maybe you should do it But. That's really a personal deCISSPion at that point. Now the CISSP has P endorsement. There's a key thing you need to keep in mind as it relates to once you get your CISSP or once you start studying for this process. Is you have to be endorsed by a currently. In good standing. CISSP S P person right. I myself or somebody else. They will have to then fill out the paperwork and help you fill out the paperwork and they will also have to do an interview of you. And they'll do an interview. They'll look at your CV and then they'll say yes. Bill Smith or Jenna Thompson or whoever is, has done all the requirements to be a CISSP they've taken the exam. They have the credentials, they have the resume, they have the work experience so on and so forth. Okay. So that's an important fact that you have to do. And it's so it must be in written form. And the ISC does acknowledge though that conversely. are the best method to ensure you're qualified So one thing to think about with that I have that little note. To make sure I bring up. They understand that you could do this via email However they do recommend that you have a. A formal conversation with the person. Personally. Unless I know the person very closely, I would want a personal conversation with them just to kind of talk about what do they know and where are they at? Because getting a, getting the CISSP exam and passing it that's just one step. And I and I think I've mentioned before in the previous podcast. Somebody may come in and just take the test or I've even seen it where people have taken the test for another individual. And that doesn't prove that you actually know anything All you know how to do is take a test. And so if I'm going to sign for somebody, I want to make sure that I know that they have the information they need to be successful, and I'm not going to cheapen the whole experience. You'll need your last name your member ID And again you'll then you'll wait for approval. But bottom line is there is a process by which you have to go. a sign off. Now one thing we talk about is the CISSP how important it is And it's it's a very important certification. And as you're relating to the overall training path with the CISSP SP I consider it. To be like a master's level program. And it really is because of the the concepts that I teach. at the CISSP level, in many cases…are beyond what is taught at most four year colleges. So it the overall concept now bits and pieces of the CISSP are taught at the four year schools. However many of the things that are in the master's programs are tied into the CISSP. So if you do get it I do firmly believe it is like having a master's program. But there are some additional certifications that would be extremely valuable for you. Prior to getting the CISSP. Because you don't have to do this but I feel that. It will help you not just getting the the certification, but also helping you with your long-term career. A plus that's dealing with hardware. Now many people just kind of scoff at that but it's really important because hardware has changed dramatically from when I did it many many years ago to where it is today. So having a firm grasp of hardware And how does hardware talk to each other? Is an important piece, then it rolls into the comp Tia network plus kind of training So you have comps T as A-plus and the networks plus. Very good networking capability. It teaches you how to do networking and the basic understanding of networking. It also teaches a little bit around security but mostly around how do networks communicate How do they talk? What is the differences between all of them? It's a really important factor because when you're trying to secure your network, if you don't understand networking protocols and how they work together, Then it makes it you're a bit of a disadvantage. Then there's the comp Tia security plus program. I do recommend that as well That gives you the basics of security. With layered on with the network capability. So you got eight plus networks plus and security plus all three of those will really put you in a great position for a good future. I mean I did all three of those and that was a while ago And the point comes back to is. Even talking to some of my students, they don't understand networking because they don't really know And this is students that are coming out of high school. This is also students that are coming out of college. If you're just trying to get into the cybersecurity field, it also is a really good way for you to understand if you really want to do this, because if you enjoy those three things, Then odds are high You'll be very successful if you don't enjoy them. Then you will not be happy doing any of this. So I feel it's really a good point that you need to kind of look as a prerequisite before even thinking about taking the CISSP. Or even getting into the cyber space career field. Now the cool part about all of that is is most of that stuff is online and it's free and you can gain access to it Just go to YouTube. Now I'm going to kind of break down a little bit around networks plus and what it can give you. So networks plus there's various domains similar to the CISSP. And it breaks into network concepts infrastructure network operations network security and network troubleshooting tools. Those are the bane domains that are tied to networks Plus. And dealing with wired and wireless networks IPV four V6 network availability cloud connectivity which is a big deal even more. And so it is a really important factor It gives you those foundational aspects too, because I deal with all of those topics on a daily basis, all of them every one of them. And so it's important for you to really understand and get the foundations of how they all work. Especially if you're coming into this really new and green to the entire event. The exam will cost you about three 50 to $400 And then you're passing scores about a seven 20. is the minimum passing score and this is from 100 to 900 Is the is the overall range? Again so you need to understand is that. do you need to take the test You don't necessarily have to take the test right There's no requirement to do it. Now they ask for required experience There really isn't any requirement They do recommend that you have between nine and 12 months of networking experience. So if you started off in a small business and you were doing networking for them, much of this would actually help you You'd be able to understand it a bit better but you don't have to have any sort of networking requirements to sit for the test. again, you decide whether it's a certification you want to do or don't want to do. Security plus the purpose of it it's meant for people with red or relatively new to the field of security and they want to pursue it. It talks about attacks threats and vulnerabilities. Architecture design implementation. Operations and incident response and then governance. we call it GRC which is your governance risk and compliance. Which is a huge factor right So you've got all of those aspects. That are in the security plus area. Well guess what? I deal with those on a daily basis. So it is. They would be very very helpful in a plus network plus security plus extremely good and foundational and to be blunt. That's what I taught our folks that were working as maintenance people with the B one. That was the same path that I taught them is A-plus networks plus and security plus, because it did it helped them understand whether or not they really truly wanted to get into the security world. Now some topics obviously is your incident response processes your governance and risk and compliance are key factors. Those are some of the topics you'll deal with. The cost is or between four and $450 us dollars. 90 multiple choice And your score is a seven 50 is what you have to have her passing and that's 100 to 900 Is the range itself. Multiple choice questions So again, You just need to pass the test if you really want to do it but there is no specific requirement for…security plus environment. Now as you look online there's some various aspects people will say well what should I get the CISSP versus security plus what should I do? Now as we've just kind of talked about here security plus is a good foundational thing to begin with. It gives you the core skills you need for any cybersecurity role. And it is a foundational aspect of it to understand cybersecurity language. I like to use the analogy is is if you have a shark and you have a dolphin, they don't talk the same language. Well you need to have a way to be able to get that shark to understand dolphin. Now it's probably a bad analogy Maybe it's a whale and a dolphin because they're both mammals but at the end of the day you need to have a way to communicate. The nice thing was security plus is it does give you that initial language to understand security conversations. Again no requirement for sitting for the test It's also a great way to help you determine if you like cyber, right. There's lots of self study products out there to help you pass the test with very little help again. You can do this or you really can't. The CISSP has P on the other hand it's like getting like I mentioned before master's degree in cybersecurity. It's more complex and challenging. The test is very challenging. There are specific requirements for passing the test and maintaining the certification These are CPEs your. I just lost it, but basically you're continuing professional education Right? So you those things are there that you're going to have to continue. That the certification is required by many hiring managers Whereas the security plus certification really isn't a requirement by anybody. You have traditional self study can be a long and problematic especially for the CISSP because it is realistically a four month process to pass the CISSP. If you do not have the security background and you do not have a lot of the experience and you're just trying to take the test, I'm just going to be blunt taking the CISSP. Without having much experience at all is a be a bit of a challenge You could do it but it would be very challenging. And having a security plus background and having a little bit of experience would go a long way in helping pass that test. Okay So at CISSP S P cyber training I have three options to help you with your CISSP is P you have yourself pace training. That's that's basically all the domains that are there One through eight for the CISSP. It's going to give you all the questions is going to help you with questions I've got multiple questions there I've got curated content and so forth in a step-by-step study guide. It's there over 20 some hours of video content. It's all available for you through the self-paced training. The tailored training piece of this is the membership and it's a monthly membership but it's designed to give you all the content that you would have with the self-paced aspect. But you do get additional content as it relates to the CISSP piece supplemental exam questions, as well as the podcast that I have curated and available to you. You also have the ability to ask me questions and have them answer each week. Then the last one is the personal coaching and membership or mentorship I have that in place It's a full membership It's available for you for a year. It gives you 12 schedule meetings to meet with me for at a period of time. and we will actually talk back and forth. It's a really good way to get your endorsement and also to help you with resume and interview prep. And I will tell you it's a great deal what it is because the fact is is that right now, if I meet with an outside company to talk about cybersecurity, like to do an evaluation of a product for them, I charge anywhere from three 50 on the low end to up to $500 an hour to visit with them. So this is a really good deal If you want if you're that place in your life where you want to actually be able to talk to them So to talk to somebody and help with mentorship. So again that's that's those are the three options that I can help you with at the CISSP cyber training. Now bottom line is you have to decide what is best for you and how you want to do it. But when it comes to the CISSP SP the certification and preparing for a future is not hard And I would recommend. That but it takes time and it takes effort. I shouldn't say it's not hard It is challenging but it's not insurmountable. What do you want do is decide do I want to do this If you want to do it then I'd highly recommend at a minimum If you don't want to do a plus and networks plus just to really understand if you like cyber. Then maybe just look at security plus and go through and sit through a course That's on YouTube and try to understand it. If that really interests you and you like that then I would recommend looking through the a plus network plus, and security plus videos that you might see. On YouTube Udemy wherever you're wherever their ELLs. And try to get up to speed on that. At the minimum then at that point if you really truly want to go study take for your CISSP reach out to me at CISSP cyber training or even before then, if I can help you with some questions that you may have around. Studying for the A-plus us networks plus or security Plus just come out to my site@CISSPcybertraining.com. And, and log in and just basically send me an email and I'm happy to help you with giving you some guidance and direction around that Again at the end of the day, I want you to be successful. I've helped a lot of people become. I've been doing this for a few years and I know what it takes to be successful in cyber. So let me help you do that. All right That is all I have for today We're going to be next a podcast actually I shouldn't before I leave I want to next podcast. We're going to be talking about the CISSP salary and as it relates to the the expectations for what you should be dealing with. On a roll And what does that look like? So again that's we'll get into salary the overall cost or the experience you can receive from from income all the way down to bonuses and so forth. That'll all be available to you in our next podcast And that will be number five. So short of that that is all I have for today I hope you have a wonderful day wherever you are at in the globe And we will catch you on the flip side. See.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
…Hey y'all This is Shawn Gerber with a C I S S P cyber training.com and reduce cyber risks.com. Or I should say reduce cyber risk okay…Hey all this is Shon Gerber with CISSP cyber training and the reduced cyber risk podcast. Hope everybody is doing wonderful today It's been a beautiful gorgeous day here in Wichita Kansas which is in the heart of the United States So it's awesome I can't complain at all And because you know what it doesn't do any good if you do. so we'll we'll make a quick tie thing we're going to talk about This is episode 0 0 3 number three right of our CIS. Cyber training and do it This is going to be talking about reduce cyber risk And my CIS is P cyber training.com. Where you can go to get CIS Speece cyber information and training that you need. To pass it the first time. Right. Well to kind of walk through a little bit around what did we talk about last episode? So I really talked about six steps for success One is you need to decide what goals you want to accomplish. So as it relates to what you're trying to deal when you're going to look for your new career in cybersecurity you want to decide what are your overall goals? Now you may have goals around, being making becoming a bazillionaire You may have goals around having more time with your family. You need to decide whatever ultimate goals in cybersecurity and how should you handle them. You also need to really decide what how much time you're willing to spend to dedicate towards those goals. Now that means is that in the case of myself So I studied in the evenings basically from around, about nine 30 to 10 o'clock every night until about two to one to two o'clock in the morning. I did that for about four months. So that's the time. had now I'll tell you that when I record many of my podcasts that you see here on reduce cyber risk and CISSP cyber training. I record those at a probably around four 30 in the morning. Now the reason is because guess what? yeah I just that's the only time I have my wife has got a business I help her I've got I work as a chief information security officer. I don't have a lot of time. So I dedicate the time that I have, and I do with what I have. That's basically it's you have to decide for you What do you have How much time are you willing to dedicate? To meet your dreams and to get what you want as it relates to security. Now you also needed to decide on a course of study. Are you a beginner Are you experienced Are you advanced in what would that be now if you're just getting started off then obviously the beginner path is a one where you need to look at and there's some different training options for you in. As it relates to the beginner path. And as well as the experienced and advanced right So you those. Each of those tiers have a level of training for you to kind of understand. Now you also need to decide on the training ops. Like we mentioned before you have your self paced you have your, specialized paid specialized training and then you have your universities or two year schools So you need to decide which option is best for you. Then you need to develop a plan which I have at CISSP cyber training There's actually a plan for you that you can use You can download and help you guide you through pasture CISSP. And then you need to work your plan. I mean that's bottom line and that's anything that we deal with is if you really truly want to be successful in security. You can have it I guarantee you I did it You can definitely do it. However, you're going to have to give up something and you're going to have to work pretty hard, but if you work hard at it, you will pay you will reap the rewards as time goes on. Now there's two bonus steps Again for longterm success, you need to become part of a local chapter Like I talked about last time in ISC squared I Saka one of them That's really important. And then you need to find a mentor someone to help you either that's free or paid. you need to find somebody to give you some guidance and direction. Again if it's free probably a friend if it's paid you may have to pay some money for that. But you need to also check and make sure that whoever you use as a mentor, they are the person that can that has in life what you want. And therefore you can do what they've done. So that's just one piece of advice on that. Now so why did I start reduced cyber risk and the CISSP cyber training websites. So like I mentioned before people ask me all the time how do I get into cyber security? And like I mentioned last episode there really is no training path You have the different options you have for your students, but at the end of the day there just really isn't anything that is defined as well as becoming an airline pilot That's predefined. There really isn't anything for the cyberspace So that's why I came up with the reduced cyber risk and the C I S S P cyber training programs. And originally I started off with reduce cyber risk podcast. And the reduce cyber risk.com. To help business to businesses or to help businesses basically deal with. That's kind of where I went I see a huge gap there. But and that's where I started But at the end of the day I really realized that. A majority of the problem out there is a training of new people coming up. And as I was looking at an evaluation of a company called Drago's and they deal with industrial control security. Their founder young guy Now he's a multi gazillionaire. made a comment He said he just wants to protect the world from the evil hacker horde. She wants he wants to help the world as it is so that it doesn't fall into chaos. And that's the whole point is that I want to feel the same way I'd realize that young people as they're getting started whether they're whatever young is cause I didn't start in this journey. Until I was in my thirties. that I actually became a hacker So you mean you think about it I was in my thirties when I learned this information. And so you can start at any age but I realized that until we start teaching more people around security, it's not going to get any better. And there was an. that just came out today that from Davos Switzerland and it was a relation to the world economic forum. Where it's basically where all the really rich people that have lots of bank bank accounts and lots of money are trying to figure out what the globe looks like around as relates to money. Well one of the key factors that came out of that conversation that they had was the fact that this the cyber criminal organizations on the globe right now constitute 10.5. Trillion dollars. So to put that in perspective. If you had the U S and China with their economies. If you had a state. Or a country whatever you want to call it that had the same kind of income at 10.5 was their GDP $10.5 trillion. They would be the third largest. GDP on the planet. This is all crime. $10.5 trillion is being taken from people and wealth is being transferred. It's it's a shame It's terrible. And so therefore it's important that we have security professionals to help mitigate this Well that's one of the other things they mentioned at Davos. Was that most companies are concerned substantially about their long-term longevity as a business. And a lot of it comes down They can't find the right people. So hence that's why we have CISSP cyber training to help you in that journey. And this is one phase of a multi-phase approach that I plan on doing to help people gain their the knowledge that they need to be successful. Now the CISSP cyber training program that they're dot com that's that's my site. The goal is to provide a location where cybersecurity students can go to get the skills and knowledge and mentorship They need to grow their careers. And I have I emphasized the mentorship because. I've seen a lot of people take tests and you can take the cert and pass the cert. But if you don't have someone to help you it's just a piece of paper It doesn't help you a whole lot. And if you come into me and you interview with me, I look at that and I see you passed your CISSP, but if you don't have any other. on your resume or you can't articulate it during the technical screen, you're not going to get the job. So just because you pass the test does not mean you're going to get the job that you want. That's why I've got CISSP. SP cyber training built. That's why is to help you get through that initial issue? Now there's three key tenants to meet that mission One is to provide training products and services for students who want to pass the CISSP. Now or in the future. Because there is a there's an issue with the CISSP. Not really an issue but it's a requirement that you have to have five years experience before you can even be called at CIS. SP you can take it before then, but you can't actually be a certified. CISSP until you actually meet those requirements around five years. Also to provide a location where students can collaborate and share knowledge and pass the industry exams while expanding their networks. You see Facebook groups you see all these different groups out there. That's great But at the end of the day, I wanted one spot where people could go and collaborate, but it's not just about passing the test Like I mentioned before, is there something that you learned that you could pass on to other students? I was talking to my intern just today and he made it I made a comment to him around security and it's so much more. Than a security operation center or being a pen tester. Now the industry will you'll see a lot of, of, drama or a lot of exposure around being in a security operation center or being in a pen test or they're trying to break into facilities. And I've done those. And those are great, but there's so much more than just those two aspects. But unless you can collaborate with people you don't know that you may not know that there are these other job opportunities out there beyond what you see on TV. And that's one of the reasons why we started up CISSP cyber training. Now also does the provide mentorship and career advice for students. I my goal is to have some way to teach you. train you what you need to be successful. And looking from a resume standpoint, looking from job interviews, interview questions how can you better prepare? How could you get into a job with me as the person that's interviewing you? Again I've interviewed a lot of people I've been doing this a long time I can help you get the job that you want. By giving you experience and talking to you in ways that you can help articulate what you know. To the hiring manager, who's hiring you. So what do you get with the CIS S P cyber training.com. What you're going to get as I break it down right now into three different products. And these three different products are around self paced training that you can do on your own. Now there's a one-time fee that will go into that And the purpose of it is to provide you the CISSP P video series that I have on domains One through eight, the training will provide you all the necessary tools you need to pass the CIS. Along with study materials that you need to help you get there. Okay It'll help you prepare it for as it relates to the ISC squared study guide. It will use years of experience that I haven't security as I pass that on both through the training. And through other trainings that I add in as time goes on because I'll be adding other content to it as time goes on. You're also going to be able to get the ability for as the updates come with that CISSP I'll make update changes to it. So there's a lot of opportunities that you'll get just through getting by domains one through eight. And you can get this CIS as P type training in multiple places And like I said, you can even get it free if you go to YouTube No question And I don't doubt you I don't. hold that back from you at all If you decide to do that. But I'll just tell you that from my experience what I can give you, and I feel confident that you'll get exactly what you need from the content in there to help you pass the CISSP the first time I really truly do. You're also going to get curated lists of information of that I've dug out on the web that I feel is important. And as part of that you'll be on my email list that I'll be able to send you content that updates. Both one you see in the news and how it may relate to the CISSP exam. Also you may get from my email list as well You'll be getting any sort of content that I may send around interview questions and how to get jobs. So again just being part of that ecosystem at CISSP cyber training is going to be a valuable tool for you. And I'm all there to help you with that And again it's it's a one-time fee You'll be able to get that what you need to pass the CISSP the first time. So my second product is a tailored training of the CIS S P video series. And that's again domains one through eight and it's a monthly membership. Now it's designed to provide you all the videos audio and additional CISSP content that I provide for the CISSP. So that you can pass it the first time. Now this is all the extra stuff that I'm going to provide and this would be from my podcast It would be from I have CISSP supplemental. I have all kinds of different things that will be added in there over the years And as I get more content it too will go in there. So you're going to get all the benefits of the self paced training program, but you will get that additional content from supplementals exam questions and really so much more. You'll get access to all my podcasts both from the CISSP. Cyber training and the reduced cyber risk podcast, curated and based on the respective domains So domain one two and so forth. That's where you'll get that content. You'll also get the ability to ask questions and have them answered each week. So through the membership you can ask me direct questions and I'll come back and give you answers to them. Now some of those questions may be exam questions. Some of them might be career questions, but you can chime in in the portal and in the membership site And it'll also be a way for you to help other people as well. And my third product is a personal coaching and mentorship. The person of this was the purpose of this is a diff. Provide a tailored and personalized coaching program, supplying you all the tools to pass the CISSP exam while providing you the necessary capabilities to acquire your first or next cybersecurity role. The purpose of this is just to kind of help you right That's. What you need you need someone to help you guide you and direct you during this process. I'll look at your resume I will look at interview questions I can help you get ready so that you meet that your needs for your next role. I can tell you what they're going to be looking for from a question standpoint. I can really help you during this process. Also in addition to that I'll deal with your CISSP S P endorsement I can take care of that because part of the CISSP I have to know who you are I have to look at your resume. And I have to pretty much interview you So knowing that I feel confident I can do a CISSP. Endorsement and help you get onto that next path. Again this is a really good product And I honestly being down sitting down with me it can I charge about $500 an hour just to sit down and. Evaluate products. So for one hour I charge close to $500 an hour just to visit with companies on what kind of products they have And if those products are cybersecurity evaluated or not. So it's it's it'd be a really good opportunity for you if you decided if you had the funds to be able to do that depending upon what your plan is for your career. Now the benefits I'm going to provide again from my This is P cyber training is you're going to get all the audio formats that are there from the podcast You're going to get exam questions. You're going to get my personal exam questions as well as recommended locations on getting additional questions. You're going to get CRE curated resource content where you can find everything you need It'll be in that location in the CIS is P cyber training, but there'll also be places where you can find it online as well. I'm going to help walk you through this process so that you pass and that you feel confident that you'll pass. When you go sit for the test. There's nothing worse than actually sitting for a test and not really feeling confident that you're going to pass it. You're going to have access to me again a cybersecurity leader with over 21 years of experience, I've been in red teams I've been a security architect, assist So I'm a professor. And I've done a little bit of everything. And I definitely can help you with that. Now there's a lot of questions that I get. Can you do can you do this journey alone? Are you free other free options available? How do I get started in cybersecurity What are employers looking Those are what I see a lot. I can help you with this Okay I really truly cam. Now we've got to throw out the disclaimer again like everything else. There's no guarantee that you'll pass you You have to be able to do the work yourself. They're all the content that we have that I have on my site will fall within the CISSP. Everything that includes at 1000 page study manual will be there. Plus you're going to get my knowledge to help you with that. But bottom line is you have to invest You have to invest money. You have to invest time. You have to do that If you truly want to pass the CISSP. But you know what You can do it I fully believe that you can do this No problem. You just have to dedicate what you need to get there Get it done. All right So that's all I have for today Our next episode we're going to kind of talk about understanding the CISSP certification and preparing for your future. And that's kind of the plan for this next episode I hope you have a wonderful day and we'll catch you on the flip side. See ya.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
Hey all Shon Gerber again we're CIS S P cyber training and I hope you all are having a beautiful day today. It is a gorgeous day here in Wichita Kansas could not complain at all So you know life is good Shouldn't complain because you just, it could be a whole lot worse right? Well just on that This is a number two This is our second episode in our CIS. Cyber training. course that we've got out there And the purpose of this is to kind of talk a little bit about, why we're doing the CIS S P training and really to try to solve the cybersecurity training problem. And to just as a recap from last podcast. Kind of introduced myself as obviously Shon Gerber and I have this CIS S P cyber training website basically that I'm looking to teach people how to understand the CISSP. But in addition to that I'm looking to also provide guidance and direction for folks that are really just wanting to get into cyber security. I see a lot of different things out online around cybersecurity AI. what you sh what it takes to become successful and to get the job that you always want. Well I can help you with that because I've done It been basically went from zero to where I'm at today and it's. I'm very very blessed. Well as a background I used to fly I was former military and I used to fly B one bombers for the military air force at that It is and did that for plenty of years for about eight years. And then I became a hacker for the us government. And I did that as a, as a red team and I was a member of the red team and I ended up being the squadron commander for an air force red team and just totally loved it It was amazing but so I went from being a commercial pilot. To being a military pilot and navigator. To becoming a hacker So it's a very different skillset from when I first started. But I also went to school to learn to be an airline pilot and I didn't go to school for anything as it relates to being an MIS or any sort of like that So my background was not in computers. So what ended up happening though is as I became a hacker I wanted to teach people how to basically do that And also how to protect, individuals from hackers. And so I taught a squadron full of people how to become hackers from being mechanics from someone that really didn't have any experience in cyber to becoming one of the best cyber organizations in the country. I then moved on to corporate America where I am now the chief information security officer for a very large multi-national. But in the process I was the manager of a security operation center which helped stand that up. And I was also a security architect for this large multinationals So like I say I've been through much of what you all are trying to accomplish and I can definitely help you with that. Hence that's why we're doing this podcast. So the purpose of this podcast So again is to solve the training problem. And how do we do that? Now as I was talking to a an intern that works for me just today it's really quite obvious and quite evident that it is a humongous problem It's a very big problem. for individuals all over the country and all over the globe. So what I'm going to cover is basically what are the things that I struggled with as well as how I overcame it. And then what you can do immediately to help your future I mean that's really what a bottom line What you're trying to accomplish is you want more for your life and you want ways to do it but you don't know how to actually do that. And that's where this comes into play That's where I kind of come into play So I'm going to help you get the role that you've always wanted Now the big difference here though. For that to happen is you're going to have to do your part. I'm going to be able to walk you through it. CIS is P in this podcast also in the CISSP cyber training that I have, what you need to do to become successful in cyber, but you're going to have to do a part to it as well. It isn't magical It isn't it isn't something that is like super easy that you can just kind of wake up and be there. But if you're dedicated and you're designed to what you want to do you can have it There's no question in my mind about that. So you just have to decide what you want to do. Okay. But the purpose of doing this also is to also help protect the word. from the evil hacker horde. And I say that because as of the recording of this podcast, The, world economic forum that was in Davos Switzerland just made a comment that they said cybercriminals are were are basically taken $10.5 trillion from the global economy. And that most people that are in business. That are actually having to try to protect things from cyber people or from the evil hacker horde say that only 27% of these businesses feel that they're actually resilient from a cyber attack. That means 70% of the business out there don't feel that way. Or they just don't even know. So it's important that you do pass your seat your CISSP and as well as any other credentials you're trying to get, because we need to protect the globe from this nemesis We just really truly do. So let's start with the problem. And people ask me all the time how do you get into cybersecurity They don't know They have no idea They have no clue. They just hear about it They think. really cool But at the end of the day they don't really know And there's a lot of confusion. So there's numerous training programs out there and ways for you to do it Now I've seen various videos out there going get your CISSP in 30 days do this in 14 days do this in. Whatever right. I'll tell you right now that might be great to get the cert if you if you're fortunate enough to do that, but that's one piece of this entire journey. And certifications are only as good as the experience you have to back them up. You may get the cert but that doesn't mean you're going to get the role. It just doesn't I've hired people I hired a lot of people and you know what if I see your resume and you're a CIS SP or you have other other search, but you have no experience to back it up. I'm sorry it's not going to be as good for you as it would be for someone who does, but you can do that There's definitely can get the experience you need and we're going to walk through how that can happen. So there's a their training paths are set up this way. So you have you have conventional and you have a non-conventional path. The conventional is your tea standard two to four year higher education with potential master's program right That's a conventional path. A non-conventional path would be of a certification approach where you go and you spend the time you get your certification. He passed the test. And great Now you've been minted as a brand new CISSP or security plus or whatever certification does your you want to be. But at the end of the day those are really the two different paths. Not at the end of that. Neither one can guarantee you a job, neither one can, but what's going to add that additional benefit is what you know and what some of the experiences you've had. Okay. So one of the questions I get from students both college students and from individuals that are just trying to learn this as they have no idea what the next steps are. They have no idea how to begin or move up the ladder as they would say you know the ladder of success. How do I get experience If I don't have experience who in cyber can mentor me because again that's an important part. Getting the cert is one thing, but having someone mentor you in security, security is huge It's a monstrous and talking with the individual that works for me now my new intern, he just couldn't even imagine how big cyber is. Which is awesome. 'cause you know what it's more than just being a pen tester. It's more than just being a security operations analyst. It's way more than that There's so much more than just those things. But if you don't know and you don't talk to people that are in this space, You may not understand that And therefore you may be heading down a path that may not be the correct one for you. Now you'll have soulful talk to questions from business leaders They just basically go, I don't have enough talent to fill my open roles. Now the talent And I mean by that is just because someone says they're in cyber. Doesn't mean that the right person for that role and they're going to they're going to pay a high compensation for an individual. They have to be prepared to be able to basically put up or shut up They have to be able to do that work. So…that's a problem that business owners have is they don't know who to even select. Now colleges students entering in through colleges really don't understand the networking basics And I've seen that firsthand. They come through school so that you in the United States and it may be different in the, where you're at I'm a globe. But in the United States, what ends up happening is is they go to school in high school. They may be get a little bit of computer programming of some kind, and then they go into high school into college. The challenge is when they do that, they still don't truly understand networking. They don't understand how to actually how do, how does TCP IP work? How does UDP work? those are some basics What is the OSI model? And the and I talked to. And I'm really honestly I'm using this my new intern as an a good example, after hearing from my students and now seeing firsthand what he knows. It's amazing He knows a lot but at the same time is is he still very new in this whole space? So what he doesn't understand is the networking concepts and you have to know networking before you can even dream of trying to become a high level security engineer or a. professional. Now. There is no real path that takes you from zero to hero. That's why you need mentorship to help you and guide you in that direction. And that's where I'm here to help you in that space. Now it's got an examples I talked to a friend or an individual from Bangalore India and I've got business in India I've been to India. I work a lot of folks in India and they are very smart very talented individuals that have a lot of drive. Well he went to the unite the United Kingdom to UK to Britain. To get his master's in security. That's where he went He wanted to be in security Now he was a developer beforehand. But he felt I have to go to get my security knowledge So I'm going to go to a master's program in the UK. Now that worked out for him, but is that the right path? Maybe maybe not. I may not hire this individual but I may I don't know. The bottom line though is is there's multiple ways you can do this There is no perfect answer. Now students in college again we talked about they don't know what courses to take in college to be successful. They're there. trying to they're just throwing darts at stuff And unfortunately a lot of the colleges. They don't have. Professors that really truly understand this workforce And so therefore they're doing the best they can to give them the skills they need, but they still are coming out, ending up short. Now. Also when there's young adults who want to get into cybersecurity and they too don't understand what to do. They they live with their parents Maybe their parents are trying to find roles for them and they don't know how to even get started What should I do? So they're here's a path that we're just going to kind of go through and walk through What are some different aspects that you can consider, especially if you're looking at this from getting your cybersecurity. career started off whether it's in. specifically in. Ethical hacking penetration testing whatever that might be. Again there is no dedicated path but you do need experience And I'm going to tell you how do you get that It's really an important factor. How do you get that experience that you need? So before we get into that I'm just going to walk through why. are some of the key roles that we have there that you can see out there. And then what are some of the potential salaries that you might encounter with those roles? So some of the variations you have a certified ethical hacker, you have auditors you have malware analysis, penetration testers forensics, you have all those pieces Those are different titles that you may have heard of roles that aren't in the cybersecurity space. There's gobs of them Right. security architect. Security engineer You name it. Now the CIS is P I'm going to go back to the CIS piece sent. scenario because that's what we're talking about here in this, in this podcast is the CISSP. Now the salaries in many cases and then this doesn't include necessarily some of the other incentives that may go with that. But there the jobs are out there If you look@cyberseek.org that's cyber seek.org. There are multiple roles that are available to you. Okay That to anybody. And the United States was approximately 800,000 rolls that are open. Worldwide There's about three and a half million They're saying by 2025 and 1.5 million in India alone. So then the question comes into is what is the compensation for some of these roles? And that will vary Again it varies upon the market that you're in a if you are in a large city that may change it If you are in a high demand. Specific role that you're looking to get that may change it. But at the end of the day we'll just kind of throw out some numbers And these again these are pulled off of Glassdoor or PayScale. But a specialist basically a cybersecurity specialist or analyst can start off And these are all in us dollars around $75,000. Your engineers about a hundred architects 130, and then your security officers are $180,000. And up now that being said there's also there's bonuses that are included in there that aren't included in these numbers So that's the, we call it total compensation. You're you're compensation that you get for your salary is these numbers a hundred hundred and 31 80 80 You know those are the your compensation numbers. However what you'll want is is when you get bonuses or profit sharing or any of those other incentives that may be there. Those are not included in these numbers because they will vary dramatically from company to company. But at the end of the day, I mean let's be realistic. cybersecurity engineer making a hundred thousand dollars in the United States is not too shabby especially since you don't necessarily have to go to a four year college to get this. You don't. I can tell you how to do it now and how you can get that in place. It the thing you have to do is put in the work to get there. So again, Salaries are large. They can be very they can even grow from there even beyond that amount. So what are some of your training options Now I break this down Other people have different ideas but I break it down into basically three options. You have a free service. You have a paid specialty service and then you have your standard trade schools or universities. Those are the kind of the three main buckets that you have. Now your free services come down to YouTube podcasts. The UK has free governmental sources on the job training you name it There's all kinds of information And a gentleman that I know that I respect highly has a website called flipped lifestyle.com. And he helps people start businesses. Well one of the things he makes a comment about is that if you're looking for resources online, There's gobs of resources that are free online. They're free everywhere You can find them. They're all over the place. And you can get your CIS as P training free right now If you go to YouTube I'm guaranteed You can get it. Now if you go to CISSP cyber training my website, you can get a free self study guide to help you through that process If you want to use all of those free resources that study guide will help you It'll walk you through how you should be prepared to study. Okay. Now when you're just dealing with the CISSP there is really no such thing as free because you're still. have to buy the book. You still should pay for some questions to help you through this process But at the end of the day is relatively inexpensive. Now…we move on to the next one which is a paid specialized training. Now the paste specialized training is online trading programs that do have a cost or a fee. Obviously there's you to me there's CIS is P cyber training Ha me, there's also a training boot camps There's various other cyber training. Venues out there to help teach and train you on what you need to become successful. They do come at a cost. Some are costs more than others. Bootcamps can cost in the upwards of five to six to 7,000 us dollars to do. And again they will help you through the CISSP in passing that certification. There's also bootcamps for security plus and you name it There's other ones as well. But bottom line is there's all kinds of different training camps that are available. From free and paid specialized. Now the third option is your trade schools and your universities. So your trade schools and your universities, they. up a two year certified programs or a four year college program. And they will start in many cases basics around cybersecurity beginnings and then they move up from there. Now they both can be really good They can provide a very solid foundational training and they can be very curated contact. Now I talk about curated. The free services Isn't curated You can search all over the globe trying to find the stuff but you'll have to go to multiple places. The paid specialized training is a curated content Okay So it's it can be very comprehensive It can be curated to the point where all of the information is there and available for you. You just have to go study it. The same with trade schools and universities. They have a lot of cases that is already to go for you. You just have to go through the steps to get there. Now the downside of the trade schools and universities are is they're limited. Okay They're they're not they're not like online everywhere and I should say that they're going online but at the end of the day there's you still have a university that you have to go to. But. they're also much more expensive. So if you rank the pricing wise you've got free service obviously relatively free. You're paid specialized services can be relatively inexpensive or could be. Pretty expensive Just depends on what you want to do. Your trade schools and universities can be much more expensive. So that's kind of the ranking. So you have to decide what can you do One how much time can you spend? You know and also how much money are you willing to spend? Now I'm gonna throw out two more bonus steps for you around ensuring you have longterm success. You need to become part of a local cybersecurity chapter. ISC squared. I SACA C risk…I can't remember one of those but bottom line is you need to look at a cybersecurity chapter that is going to provide you some guidance Now the good thing about these chapters is is they also help bring people together and they help you with maybe networking. So if some company is looking for a cybersecurity resource and you go to this. this meeting. Well guess what There's possible You could connect with an individual, so there's options there right? So they're important to get and plus you get to meet a lot of the people that are in the cybersecurity space within your local area. You also need to look at finding a mentor Now there's various places out online that you can find mentors around cybersecurity. And I highly recommend that you do find one. Some of them can be free I E your friend. Or some of them could be paid depending upon what you need Now, again I need to look at the fruit on the tree This is kind of what I like to throw out is if you need a mentor to help guide you look for somebody that is in life where you want to be. And has done what you want to do. That's where it'd be a good mentor to help guide and train you And they think the way you think. So again I there's tons of people out there I and I'm not bagging on any of them I think they're all there are many of them have opportunities to can provide you what you need. However just make sure that you validate that they actually are. And they have done what you want to do. That's really the key without that. You're just got a bunch of people talking and they may not provide you the level of knowledge you may need. Now I'm coming back to why reduce cyber risk And the CIS is P cyber training.com was established. Now I'll kind of that that's kind of the next podcast but I'll give you just a little insight. I had started reduced cyber risk a while ago. And kind of pivoted right I'm a sisal I am super busy And so I therefore pivoted a little bit and didn't see the gaps that were there for these students. Then time went by and I started teaching in college and I realized you know what I need to put together this CIS S P cyber training program. And I really need to have that available because I see the gaps. I got college students that are coming out of four-year college with debt that don't understand how to move on to the next level. And that's really realistically what I want to help you do. And I've got friends that are in India. I talked to them all the time and they're going how do I get into cyber What can I do? And so the point is is that that's why I've created this study plan but I'm also in the process of creating a way to help individuals. Walk through the process they need to become successful and get the role that they want and then help mentor them into that next. That next level because I've done it. I've gone from being nobody from not having any capability at all from being a pilot to working my way up. To take in the CIS is P by self study by then going out and actually becoming commander of a of a red team. Okay I didn't know what I was doing. Commander of a red team then from there went into corporate America didn't understand any of that became an architect, then developed a security operation center and now became a cyst So, and I teach college courses in risk and an IOT. Now I tell you that not to be bragging upon myself but to tell you that I've done what you want to do. I've done it. And for you to be able to get it I want you to get this and help you in. family because realistically it can change your life. So again go out check me out@CISSPcybertraining.com. And you'll like what you see I got some free stuff there Again the sites being built up it's growing it's changing but and be patient with it But at the end of the day, I can help you get your needs. Next next episode is going to be around how. Reduce cyber has started And also the CIS SB training.com was established. We'll get into that and we'll talk to you a little bit more on how I can help you meet your needs. All right. Have a wonderful day and we'll catch you on the flip side.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript
Hey everyone This is Shawn Gerber with CIS. Cyber training.com and reduce cyber risk podcast. I hope you all are having a beautiful day today And I will tell you that it is amazing here in the great state of Kansas in the United States. it is an awesome awesome day Actually It's about 42 degrees and I can't complain 40 degrees Fahrenheit That is so for my friends that are in India, that's a little bit different than what you guys have from a temperature standpoint. but as it relates to the CIS. And studying for the CISSP. I am just bringing forward this podcast I've been in business for a while but I want to talk a little bit about that but I'm bringing forward this podcast to help give you some understanding and training around taking the CISSP exam. So before we get started this is podcast 0 0 1 obviously the first, but you can also check out some of my other podcasts on reduced cyber risk podcast And I'll kind of get into the reason behind both of those but at the end of the day is this is just kind of an intro for those that are starting to listen to my podcast, why I'm doing it and who I am. So a little bit about myself So I am I grew up in a very small town in Iowa So just to state north of where I'm at in Kansas. And I was basically I've been there was there my entire life growing up. So the town was from the folks that I've met around the globe is about 250 people which is extremely small as it relates to a place to be from. Now as I got family that I've got kids that are from China You know obviously the smallest town in China in many cases is like a million people. So out of two hundred fifty, two hundred and fifty people. It's pretty tiny It's about the size of a block. but again I've been based out of the United States and I've lived now in Kansas in Wichita Kansas which is in the middle of the United States. And I'm married to a beautiful wife of 30 years And I am just completely amazed at what that she still sticks with me, but I. have been married for about 30 years to Trish Gerber and she's amazing lady. I have seven children and I am basically a son-in-law and a potential son-in-law that might be happening here in the near future. I have my children as you may Abby asking going. Y seven Yeah Well, I only have three biological that my wife and I produced but we have four adopted kids that are from Uganda. China and. Yeah those those two places So we have three kids from China We have one from Uganda. Now the reason I was had a pause is my potential future Son-in-law. again I say potential he's from Sri Lanka So we have a very diverse family. I also have a granddaughter and she is about two years old and she lives in Kentucky. So my family is pretty large and it's growing quite rapidly. So that's just a little bit about me and where I came from As far as my family life. No. why am I even doing this And you probably most of the folks that listen to these podcasts and especially reduce cyber risk and pod and people I introduced introduce with and I talked to. They all have a very strong background in some level of cybersecurity or in some level of it. Well, I don't but I started off with looking as a kid the Texas instruments T 80 and the apple two E's and I was part of the video game craze that hit Okay And I'll just tell you I'm an old guy compared to most of you that are probably listening to this podcast. I'm pretty old now I'm in my fifties So yeah that's that's like dirt old in many cases However, I've been doing a lot of stuff in those 50 years of my life and of which has been cybersecurity and the CISSP. But I got part of my growing up time was around computers and when they just started hitting the market and the T I 80 the apple two E's all of those were part of it I also started a beginning of programming within just basic. So I always had an affinity to really enjoy that type of activity I liked using my brain I like thinking of things outside the box and it was it was really an awesome awesome time. But when I grew up one of the things I always want to do is I wanted to be a pilot. I wanted to fly airplanes. And so as a child growing up learning to fly I started off with really small planes. Some of these that are two seat planes you have basically only the pilot and the copilot. Some of them were a little bit larger six eight passenger type planes but as time went on I learned to fly airplanes with the goal. Of becoming an airline pilot. That was my ultimate purpose is I wanted to be an airline pilot now. Fast forward to my current position I am not an airline pilot. So if you're trying to listen to this podcast and you want to know how to be an airline pilot, I can tell you how to get there but I don't have the experience to say that I lasted very long in that space. So after flight greeting, my. pilot's license So I grew up small airplanes Got my commercial pilot's license. Got my certified flight instructor license and I was teaching people how to fly small airplanes. Well an opportunity came up where I could fly the B one bomber. Now if you are connected with any of us military. there is a plane called the…and it's a four person. bomber very large Intercontinental bomber and it goes really fast and it's super sexy and is really cool. And I was had the opportunity to fly in that plane. Now growing up as a pilot that's what I wanted to do However because of my age at the time and what I was trying to find as far as military options, they were what they call banking pilots which means there weren't enough pilot seats available for the number of people wanting to fly. So I got banked and because of that I want but I wanted to fly and I didn't want to wait. I wanted to take any role I could in flying airplanes. So an opportunity came up for me to become the weapon systems officer on a B one with the goal that once I got in I could then hopefully upgrade to becoming the pilot. Did that for a flu until 2002. It was amazing opportunity I just loved it went really really fast really low really high, did all kinds of fun crazy stuff And I did that I flew with the Navy flew with the air force. And so I've had a really awesome career in aviation And so many people would think that and it's like amazing And it was. But life changed a different path. So as a transition. There'd be ones had decided there was leadership and Washington that made a decision that the were going to leave my organization. So after the B ones Ones went away. Then what ended up happening is is that there a we had to go out and try to find a new mission. So we went on a road show looking around the country trying to find a new mission to help employ people within the. To some extent we didn't know. that was going to be. However what ended up happening was is that we stumbled across an air force red team. The cool part about the air force red team was, was that it was in cybersecurity which was a relatively new space. But at the end of the day we knew we could teach people that had been on. been doing maintenance on airplanes and we could teach them potentially to become hackers for the government. Now the cool part about it was there was no training path in place nothing existed. So we had to build this from scratch on how to go from basically teaching. Wrench Turners. Okay Maintenance people to being a hacker on a global standpoint. And it was amazing I learned a lot out of it, learned some good things to how what worked We also learned some things that didn't work. Now the cool part about all this though is is that after that we pitched our idea to our leadership and they bought into it. We then took these folks and we taught them up in a series of timeframes. And the cool part is is it happened within a very short period of time, but we had a methodical standard approach on how you could actually get that done. Now again we took these group of people ended up being about 82 people Totally. Total. Of that there was about 40 of them became hackers for the government. Now we had full-time and I had part-time folks And of those they I would say the mix was probably around 60 40 now probably more like 80 20. 80% Full-time 20% Part-time. But we did global operations everywhere Okay All over the globe we operated, I actually was one of the initial cadre to help teach the NSA their red team Cause they were just standing one up at that time as well. So it was a really dynamic time especially in the cybersecurity space. The interesting part was though is it was really before we sat the vision to see where it was going but we just didn't know how big it was actually going to get I mean I had a sneaky suspicion It was going to be this big if not bigger, but we didn't really know…the other part of the barn being with a red team is our ultimate goal is to teach. the DOD department of defense and us air force employees on the threat. So I had to teach people who didn't understand cyber at all, what to do to be successful to protect themselves from external entities trying to steal their information. So again it was awesome It was extremely successful Military squadron it's been around it's still around. It's. It was an amazing experience. Now fast-forward to my CIS. P journey. What is that Well it was a result of the DOD requirement for CIS SPS and managers That's really what it came of. So I'd been leading the company. Leah my squadron I became I was a squatter commander so I was leading them in their organization their vision of where we were going. But the DOD requirement came out that you had to have a CISSP. I didn't necessarily have to have it but it was highly recommended and encouraged. Well that was really it personally the first exposure I had to the CIS. So I wa went out. and I started studying for it. Now I was the first person within our squadron to actually get the CISSP. And I there was no resources available The only resource that was out there was a book by Shawn Harris and the ISC squared study guide That was a pretty much it. So I took those books and I started going through them line by line by line. Now understand I came from a military background first a pilot, then military it, and then trying to understand in some respects corporate it, which they were very different. So it was a very challenging process when I was doing this. So the first time out there I studied for about four months reading the books reading Sean Harris's book reading the IC square book, and I took gobs and gobs of notes. Practice test after practice test after practice test. again it was a lot of work and I felt confident sort of in taking the test So what did I do I went and took the test. I guess what I failed. So just like. 80% of the people that take the CISSP exam they fail the first time. Now the problem is is that it was a lot of work to go in there the first time and then fail the test. So I had a little bit of just depression Not no prize pay is a strong word but I was just really bummed out. So I took about a month off of some self-pity going this socks I don't want to do this This is no fun. Right Just why am I doing this to myself? Well then I finally said okay enough of that let's go. So. Again started back up into studying Again, I redoubled my efforts on studying and I took a different approach now of which is the CIS. Study guide that I have on CISSP cyber training.com You can get the study guide out there. And that's the same study guide I used to pass it the second time. And so what I ended up doing was I went through it over and over and over and again after much time much thinking about it, but a really thing I came out of that second time was I understood now how to take the test What kind of questions are asking? So I traveled six hours to go take this test. As I traveled to this place in Arkansas to take it there they were having a bootcamp a CISSP bootcamp going on at that same time. But I didn't have the funds to pay for the bootcamp. So I just was going to take the take the test drop the $800 whatever it was at the time and just take the test. So I went in there I told myself if I fail it again, I'm done. I don't want to deal with this anymore. I'm done. Well guess what Second time around I passed So it was good right Life is good I pass the test, but I to pass the CISSP. In a squadron that really didn't require it. But I learned a lot during that process. Now fast forward a little bit further That was 2009 When I passed the CISSP I'm now in 2011 I leave. the military retire as Lieutenant Colonel. Leave the military and I go work for a large corporate entity Okay Large multinational. I get hired as a security architect and I'm learning the basics of corporate security. Now I have the background of it. I got flying background I've got. Military it, and now I'm learning corporate it so that I can understand all of the different gamuts that are there. Now this was a relatively new capability with the corporate organization And I assisted I also assisted in standing up a security operation center that is 24 by seven at that time. And it was basically on new technology They had never done it before. And so this is a whole new environment for this large multinational. Now after that time I ended up being the security operations manager for that. security operations center. Okay So I was the manager I have a sock, did that for about two and a half years And then an opportunity came up for me to become the CSO Okay The chief information security officer for another multinational that is under the the whole family of umbrella the umbrella of. There's one main company. So the point of it is though is that as the Cisco now for this other multinational we have a global presence We're in the cloud I mean IOT I'm in manufacturing I IP intellectual property. I mean the gamut is huge You've got about 6,000 employees So it's I mean it's a good size company It's not a monster like Georgia Pacific or Microsoft or anybody else. But it's a good size company right? So my ultimate goals is educating employees is my top priority I want to employ it educate them as well as protecting our companies intellectual property. So that is my corporate stint now. Been off a little bit is I also am an adjunct professor at a small college in Wichita Kansas. Now it's not small for Wichita but for most of you all that are listening on this podcast is probably not that big. Now it's about 10,000 12,000 students but as a professor adjunct professor there I teach cyber risk. And I also teach cyber-physical systems So IOT type activities. These are 400 level courses So again and not they're not lower level They're a higher level course. and because of that though I took that job with the re indication or with the idea. Of understanding the student's pain points What is a big struggle? Why are they what are some of the things they're having with as it relates to cyber how do they get their new jobs How do they get into the career? So the goal was was to understand all of those things so that I could be better at helping out people with cybersecurity. So as it relates now to sire certifications, I have various certifications Some of them are pretty old. Some of them are built They're kind of old right? Because when it comes to search I think certs are very important. So as a person who's gone through this entire process from from knowing nothing to growing up to be a a Cisco So for a large company. I've done search and there's value in those but there's also more of the value of the knowledge you gain out of getting the cert in my mind is much more important than actually check box I got the cert. Now. I've got a plus network plus security plus you know obviously the CISSP and then some various other ones out there as it relates to legal which I think is really important Illegal courses Super important for you. and there's some various pieces that are in there but you can you can go to my site at CIS S P S cyber training.com and you'll be able to see those as well. So again, take learn from me Okay This is I'm gonna give you my profile So I didn't start till I was in my late thirties with no clue in what I was doing. But yet I was getting into this cybersecurity field. I had no experience in it or security to speak of. I saw an opportunity and I jumped in with nothing to guide or direct me Now I had the military which was a big benefit and a lot of people say, well it's the military is reason you got what you did And that's probably a lot of truth in some of the knowledge that I've gained is because of the military. However, when I started there was nobody insecurity So now there's so many more opportunities for people to get into and get knowledge and experience way beyond whatever I had. Now I've made a lot of mistakes And so the key around that is let me help you navigate those mistakes and those issues for your career. My goal is to help you with that. I really do have a passion about helping people get jobs I just helped a couple of my students. what the, as a professor I was just helping them get jobs with local companies. And also with some other companies, I've helped them with resumes I've helped them with interview skills. All of that piece is is out there and available And I really want to help you do that. So like the point is is I've done it. I've went from being absolutely having no capability whatsoever I do not have a cybersecurity pedigree. I do not have a master's in cybersecurity I don't have any of that I barely have a bachelor's degree in aviation. But that doesn't mean anything All it means is that I have a passion for this and I want to succeed and I want to help other people succeed. So again that's my goal Help you get to the goals you want and you desire. that we all can get ahead That's the bottom line. So this podcast here was basically an introduction Now then the next podcast I'm going to talk about the CIS. Cyber training.com. A little bit more what you can find out there but I'm also going to talk about solving the training problem. Now again, going from zero to, I wouldn't say hero but zero to. A little bit more successful. has been an interesting event and I've learned a lot about the training problem that everybody's struggling with. I'll explain how I overcame it what I did to do what you can do immediately to help your future That's the goal How can you help yourselves and your family's future right now? And then eventually maybe get the role that you've always wanted And I will tell you that the role that you want. May change It will change as time goes on but the role that may be your future role may not even be existed yet It may not have been created. And then also want to help you begin a career that is satisfying and fulfillment fulfilling. and lastly I want you to help. the world. From the evil hacker hoard because they're out there everywhere trying to take advantage of this and we need more people that can actually step up. And fill the gap and be this. The security resources to help protect companies to help businesses, nonprofits you name it We need more resources in this space. So I would like to ask last plug is the go to…Training. cyber CISSP cyber training.com You can go check us out there There's a lot of really good stuff that's in there There's stuff That's free There's stuff that's paid. But bottom line is there's a lot of great information out there Now the site is relatively new, but the cool part about it is ever growing and ever building So you're just going to as every time you visit it you'll get to see more and more information. Get put there. So again this is the end of this podcast I'm extremely excited to work with you again as the introduction we will talk about the next one about. cyber training and solving the training problem So please definitely go there and listen to that one, but I hope you have a wonderful day and we will catch you on the flip side. See ya.