Shon Gerber from the Reduce Cyber Risk and CISSP Cyber Training podcasts provides valuable insight, guidance, and training to you each week that only a senior cybersecurity expert can perform. Shon has over 21+ years of experience in cybersecurity from large corporations, government, and even as a college professor. Shon provides you the information and knowledge you need pass the CISSP exam the first time along with practical steps needed to enhance and grow your cybersecurity career. Shon is a CISSP since 2009 and has over 21 years of experience in corporate, government, and collegiate environments. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity. In addition, you will receive extremely valuable security tips and techniques that you can put into practice immediately setting you apart from other individuals within the world of cybersecurity. Lets get going….GIDDY UP!
The digital landscape for financial institutions has forever changed with the rapid advancement of artificial intelligence and machine learning technologies. What started as simple robotic process automation has evolved into sophisticated AI systems capable of transforming everything from fraud detection to customer service - but at what security cost?
Sean Gerber draws on his 20+ years of cybersecurity experience across military, corporate, and consulting roles to deliver a crucial message: AI implementation must follow a "secure by design" approach from day one. Organizations that rush to deploy AI solutions without proper security frameworks find themselves facing exponentially more difficult remediation challenges just 2-3 years later.
Through clear, accessible explanations, Gerber demystifies the differences between artificial intelligence, machine learning, and large language models while highlighting their practical applications in financial services. From JP Morgan's AI-powered legal contract reviews to Bank of America's advanced security measures, real-world examples demonstrate both the transformative potential and inherent risks of these technologies.
The episode provides a pragmatic roadmap for financial institutions navigating AI implementation, covering essential frameworks like the NIST AI Risk Management Framework and critical security considerations including data anonymization, network segmentation, and intellectual property protection. Gerber emphasizes that while robust security requires investment, the alternative - retrofitting security after problems emerge - proves far more costly in both financial and reputational terms.
Whether your organization is just beginning to explore AI capabilities or already deploying advanced solutions, this episode delivers actionable guidance for building multidisciplinary teams, developing AI-specific security policies, and creating governance structures that balance innovation with protection. As Gerber notes, "AI in banking is here to stay. It's transformational, but not without risk" - and the time to implement proper safeguards is now.
Ready to strengthen your organization's AI security posture? Connect with Sean through Reduce Cyber Risk, CISSP Cyber Training, or Next Peak for personalized guidance on your AI security journey.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
The boundary between physical and cybersecurity is rapidly disappearing, creating both challenges and opportunities for security professionals across domains. This eye-opening conversation with Casey Rash from Secure Passage explores how modern physical security devices have evolved into sophisticated IoT endpoints generating valuable security data that traditional teams often lack the expertise to fully leverage.
Drawing from his diverse background spanning military intelligence, fintech, logistics, and cybersecurity, Casey offers unique insights into the convergence of physical and cyber domains. He introduces Secure Passage's innovative solutions: Haystacks for critical infrastructure monitoring and Truman for Physical Detection and Response (PDR), which applies familiar cybersecurity principles to physical security data streams.
Through practical examples ranging from employee termination scenarios to school safety monitoring, we explore how the integration of physical and cyber domains addresses critical security gaps. Modern smoke detectors can now detect THC, gunshots, and calls for help, while surveillance systems incorporate advanced AI capabilities like object detection and crowd analysis – all generating data streams that most organizations aren't effectively monitoring.
For CISSP candidates and security professionals, the conversation maps these solutions to relevant domains including Security Operations, Asset Security, and Identity and Access Management, providing valuable context on how theoretical security principles translate to real-world challenges. Casey offers a provocative perspective: "Most of the responsibility for unifying security systems lies on the cyber side, because we understand the data."
Whether you're studying for certification or leading security strategy, this discussion will expand your understanding of converged security and the growing importance of holistic approaches that span both physical and digital realms. Connect with Casey at SecurePassage.com to learn more about bridging these traditionally siloed domains.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Unlock the secrets to safeguarding your business in today's volatile supply chain landscape. On this episode of the Reduce Cyber Risk Podcast, hosted by Shon Gerber, we take you on a journey through the intricacies of cybersecurity in supply chains. With rapid technological advancements and the rise of AI models like DeepSeek, businesses must navigate data security challenges like never before. You'll discover why countries such as Italy are limiting these AI tools and learn how to balance innovation with caution to protect sensitive data from potential threats.
Embark on a comprehensive guide to establishing a robust Cyber Supply Chain Risk Management (CSERM) program. Together, we'll explore strategies to secure stakeholder buy-in and cultivate organizational awareness through tailored training initiatives. By aligning your CSERM goals with your mission and compliance requirements, especially if you’re handling government contracts or operating within the financial sector, you can proactively guard against cyber threats. Prioritize critical assets and integrate CSERM into vendor selection to mitigate vulnerabilities across third-party relationships.
For businesses lacking internal cybersecurity resources, resourceful strategies are at your fingertips. From harnessing the power of online tools like Google and ChatGPT to leveraging expert consulting services, we offer insights into fortifying your defenses. Dive into the wealth of resources available at ReduceCyberRisk.com, including free materials and training opportunities for IT teams. Whether you're taking your first steps or refining your existing measures, this episode equips you with the knowledge to strengthen your cybersecurity posture and safeguard your organization against evolving threats.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Is your business ready to tackle the hidden vulnerabilities lurking within your software supply chains? Discover the profound impact of President Biden's recent cybersecurity executive orders and learn why third-party software is a crucial focal point for safeguarding your organization. From real-world examples to actionable insights, I navigate the complex realm of cybersecurity, especially for small and medium-sized companies operating under the CMMC framework, while addressing the looming cyber threats posed by nation-states.
Explore the intricate web of emerging threats challenging today's digital landscape. As software dependencies and hardware compromises become commonplace, I illuminate the critical need for a future-proof security strategy that addresses the burgeoning power of quantum computing. From the risks of data poisoning and the sophistications of deepfakes to the potent social engineering tactics manipulating political and market environments, this episode uncovers the multifaceted vulnerabilities businesses must contend with to ensure their cybersecurity.
Unlock advanced strategies to build a cyber-resilient organization. By implementing a cybersecurity mesh and embracing identity-first security approaches, your company can stay ahead of sophisticated threats. As I discuss the transformative role of generative AI in both defensive measures and cyber threats, the importance of automated detection and response becomes evident. Cultivating a security-aware culture and ensuring robust supply chain security are essential, as these elements play a pivotal role in maintaining business continuity amidst a rapidly evolving cyber landscape. Join me for a deep dive into continuous improvement and proactive planning, equipping your business with the skills needed to fend off future attacks.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Uncover the secrets to mastering cybersecurity amidst a booming demand for IT professionals. Join me, Shon Gerber, as we tackle the thrilling landscape of tech opportunities, where U.S. tech unemployment has reached a two-year low. Discover how certifications like CompTIA can launch your career in this high-stakes field, and learn why experience is becoming more critical than formal degrees in certain roles. We also spotlight hiring trends at industry giants like Amazon and Deloitte, showing why now is the perfect time to step into the world of IT and cybersecurity.
Dive into the mind of a cyber attacker as we dissect their motivations, from government-backed nation-state operatives to curious script kiddies. Understanding these varied personas and their goals is vital for businesses safeguarding valuable intellectual property. We explore the financial, social, and disruptive motives driving cyber threats, shedding light on the broader implications for global financial stability as highlighted by the International Monetary Fund. This knowledge is crucial for businesses to develop strategies that fortify their defenses against potential cyber threats.
Prepare yourself for potential cyber threats with strategies inspired by elite air-to-air combat training. Specialized training, operational exercises, and robust cybersecurity frameworks like NIST CSF and ISO 27001 are essential to bolstering your organization's security posture. We emphasize the critical need for comprehensive business resiliency plans and well-developed incident response strategies. Equip yourself and your team with the necessary tools and know-how to withstand cybercriminals, ensuring your digital defenses are more formidable than ever before.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
From the cockpit of a B-1 bomber to the nerve centers of global cybersecurity, I, Shon Gerber, invite you to explore the thrilling transition that shaped my career and mission. Discover the unexpected parallels between flying high-stakes missions and safeguarding billion-dollar enterprises from cyber threats. This episode offers a personal narrative of my journey, highlighting my experiences on the US Air Force Red Team and the critical role these played in forging a path into the world of cybersecurity. You'll hear about the moments that defined my career, my insights on balancing family life, and my commitment to making cybersecurity accessible and effective for businesses everywhere.
Join me as we navigate the complex challenges of managing security for a Koch Industries company, where I held the reins as Chief Information Security Officer. Learn how I tackled the intricacies of protecting intellectual property and global operations, and why I believe that preparedness is the strongest defense against cyber threats. We'll discuss my transition to consulting, my teaching experiences at Wichita State University, and the pressing need for businesses to fortify their defenses against hackers. Through this episode, I aim to empower you with the knowledge and tools to reduce cyber risks, ensuring your organization's resilience in the face of potential attacks.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever get tangled up in the complexities of identity and access management? Tired of letting confusion rob you of effective cybersecurity strategies? Well, it's time to tune in and simplify it all! As your resident cybersecurity expert, Sean Gerber, I'll be taking the reins in this exciting journey into the heart of identity and access management. We'll tackle the big three – identity management, federated identity management, and credential management systems. Believe me when I say, by the end, you'll be navigating these concepts like a pro!
Are you ready to discover the true value of identity and access management? We all know security is paramount, but have you considered the benefits to productivity, user experience, and cost savings? Let's uncover these hidden perks together! The aim isn't just to understand but to utilize this knowledge effectively. We'll discuss the crucial importance of timely user removal and how to tackle challenges head-on when the system breaks. The big bonus? We'll also dig into how IAM aids in meeting those pesky compliance requirements and how automating processes can really save you a penny or two.
No cybersecurity journey would be complete without a deep dive into SAML, OAuth2, and OpenID Connect. Sounds complicated? Not for long! I'll be your guide as we examine these protocols and their roles in transferring authentication and authorization data. By the end, you'll understand SAML assertions, OAuth2's tokens, and how OpenID Connect is built on top of OAuth2. And, because we believe in value beyond theory, we'll explore real-world examples too. But that's not all! Stick around as I share how you can access free CISSP questions online and why joining the CISSP cyber training community is a game-changer. So, are you ready to revolutionize your understanding of identity and access management? Let's rock and roll!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever wondered how to ace the CISSP Cyber exam's domain four? Or, perhaps, you're merely intrigued by the intricate world of Voiceover IP (VOIP)? Either way, this episode is packed with the insights you've been seeking! Join me, Sean Gerber, as we dissect the key protocols that VOIP uses for multimedia transmissions. Together, we'll unravel the complex intricacies of Session Initiation Protocol (SIP) messages and how sessions kick off in a VOIP implementation. You'll also gain an understanding of the differences between Real-Time Transport Protocol (RTP) and Real-Time Transport Control Protocol (RTCP) and how they're applied.
As we journey deeper into this episode, we'll explore the fascinating world of Internet Small Computer Systems Interface (iSCSI), focusing on its functions and default ports. Fear not, the mystery of SCSI command encapsulation will no longer be a mystery to you! We'll then shift our attention to the security aspects of SIP-based VOIP traffic, scrutinizing SIP-aware firewalls and the implementation of Transport Layer Security (TLS). Finally, we'll round off our discussion by examining RTCP's role in providing quality of service feedback in a VOIP implementation and wrapping up with an understanding of block-level transport in iSCSI. Prepare to expand your cybersecurity knowledge in a way you never thought possible!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ever wish you could decrypt the mysteries of cybersecurity and ace your CISSP exam? This episode is your treasure map to success, guiding you through the labyrinthine layers of the OSI model, starting with the physical transmission of data and the crucial role of physical access controls. We also enlighten you about MAC address filtering and how it fortifies network security.
As we move deeper, we unlock the secrets of encryption, digital signatures, and secure coding practices. We delve into the heart of the session and presentation layers, spotlighting the importance of input validation and secure API design. Get to appreciate the role of protocols like Session Initiation Protocol and Real-Time Transport Protocol in VoIP. We also bring to light the security risks associated with VoIP and iSCSI, introducing you to the sinister world of call hijacking, eavesdropping, and toll fraud.
Finally, we don our armor and arm you with the best security controls for VoIP, such as encryption, authentication, and access control. And just when you thought it couldn't get better, we guide you on how to hit the bullseye in your CISSP exam. Exploring the benefits of a CISSP Cyber Training membership and how it sets you up for a triumphant win in the exam. So, gear up for a thrilling voyage into the captivating realm of cybersecurity.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to conquer the CISSP exam? Join me, Sean Gerber, as I break down complex concepts and guide you through an in-depth exploration of threat models, including their components and the crucial role they play in identifying and mitigating potential threats. You'll not only get an understanding of the TRITE methodology and when to use STRIDE or DREAD, but also learn to pinpoint which threats in STRIDE refer to an act that modifies data or system configurations.
We'll unravel the secrets of successful threat modeling and the key steps involved - leaving no stone unturned. Unearth how to interpret multiple choice questions, and understand the nitty-gritty of the TRITE methodology. In addition, we'll shed light on the importance of updating and maintaining threat models as an ongoing process. This episode is guaranteed to leave you feeling prepared and confident for the CISSP exam. Don't just take the exam, ace it! Tune in to this episode and get set to become a pro at threat modeling.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you prepared to defend your organization from cybersecurity threats? I'm Sean Gerber, and this week I'm unraveling the intimidating world of threat modeling. Get ready to supercharge your cybersecurity knowledge as we dissect threat identification, risk assessment, and mitigation strategies. This isn't just for acing your CISSP exam, it's for becoming an indispensable security professional who can effectively safeguard your organization.
We'll embark on a journey through the labyrinth of regulatory compliance, and work towards mastering the art of threat modeling. We’ll highlight the importance of robust communication, continuous education, and the strategic role of stakeholders in countering threats, vulnerabilities, and concealed secrets buried in code repositories. Expect to gain a comprehensive understanding of Stride and Trike threat modeling, underlining the significance of tackling repudiation, information disclosure, denial of service, and elevation of privilege to safeguard sensitive information.
As we delve deeper, we'll expose the vulnerabilities and considerations of Trike security, emphasizing the criticality of well-defined security requirements, cost implications, and essential automated tools. I'll also divulge my blueprint for the CISSP exam available on CISSP cyber training. This is more than just a tutorial - it's your stepping stone to becoming a proficient cybersecurity professional. So, brace yourself for an episode teeming with insights and tactical strategies that you can't afford to miss.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you ready to unlock the secrets of data classification and pass your CISSP exam in one go? That's right! Your host, Sean Gerber, is here to guide you through an insightful exploration into the world of data classification. From the intricacies of content-based and context-based data classification to the various stages of the information life cycle, this episode promises to be a goldmine of information. We'll dissect the appropriate levels of data classification suitable for different types of data and unravel the efficiency of various asset classification methods.
Ever wondered when user-based classifications would come in handy or how assets are effectively grouped into categories like finance, HR, and IT departments? We've got you covered! This episode dives deep into the asset life cycle stage and the sophisticated tools that analyze unstructured data. On top of that, we also demystify the commonly utilized levels of data classification like public, internal use, highly confidential, and restricted. As we delve into these layers, we'll differentiate between them and shed light on why the secret level is rarely used in commercial entities. Join us and boost your CISSP exam preparation while developing a broader understanding of data classification.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you ready to make your digital assets and information impenetrable? Well, we're here to navigate you through the maze of understanding and protecting your most valued digital treasures. This episode is packed with a wealth of knowledge, as we discuss the intricacies of information and asset protection. We highlight the vitality of data classification, and the importance of effectively training your team to attach the right labels.
Your senior team needs to be on the same page with you when it comes to data security. We uncover the crucial link between information and assets and how they are dependent on each other. Mobile devices often carry valuable data, making them susceptible to threats. To avoid a compromise, it's important to understand the potential risks and impacts of placing sensitive data on such assets. And, should a compromise occur, we discuss the possible repercussions, including reputational damage and lost future earnings.
The journey doesn't stop there. We move on to the defining stages of the information lifecycle, emphasizing the need for secure data collection and sharing processes. Misclassifying data can have dire consequences, hence we delve into various classification types and the importance of having protective policies. Lastly, we give a sneak peek into asset tracking and management tools, and how to choose the right one for your use case. Remember, understanding, protecting, and handling digital assets and information securely is a crucial part of the CISSP domain 2 exam. So, fasten your seatbelt as we take you on this enlightening journey.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you charged with navigating the precarious terrain of supply chain risk management? Then, prepare to sharpen your skills in this action-packed episode! I'm Sean Gerber, and I'll be guiding you through the labyrinth of supplier audits and evaluations, discussing the delicate balance between the two. We'll also delve into strategies for mitigating risk, including the benefits of outsourcing to multiple vendors and having redundant suppliers for those all-important components.
But that's not all! We also take a journey through the CISSPcybertraining.com site, a haven for those gunning for the CISSP certification. I'll unpack the site's blueprint, highlighting how the questions available can be a treasure trove for exam prep. On top of that, you'll hear about the growing popularity of the CISSP exam and how YouTube is buzzing with resources to support candidates. So, whether you’re studying for the CISSP exam, or you’re just hungry to broaden your cybersecurity and risk management knowledge, this episode is your ticket to enlightenment. Tune in!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Prepare to unravel the complexities of supply chain risk management (SCRM) and gain invaluable insights that could safeguard your business from massive disruptions. We're diving into the nerve-wracking challenges of SCRM, emphasizing just how crucial it is for every business in our hyper-connected age. Learn about the nuances of this formidable task as we explore real-life scenarios that underline the dire need for security professionals to lend their expertise to those who find themselves in the deep end of SCRM vulnerabilities.
We're laying out the intricate tapestry of SCRM domains, from hardware and software to third-party services, casting light on the risks associated with outsourcing. We'll guide you through the maze of supply chain elements, helping you identify potential risks and understand the threats looming over your daily operations. It's not all gloom and doom though; we'll also equip you with proven strategies like engaging third-party services such as Showdan and Security Scorecard for supply chain reviews, and the critical role legal and compliance teams play in this intricate dance.
As we wrap up, we'll tackle the ominous reality of ransomware attacks on businesses. Using the chilling example of the 2017 NotPetya attack, we journey into the shadowy underworld of cybercrime, where profit margins are hefty, and the risk to the perpetrators is minimal. With the projected cost of ransomware attacks set to hit a staggering $25 billion by 2025, we explore the dire implications of this trend. As somber as these realities might be, our intent is to arm you with the knowledge and resources to fortify your supply chain and protect your business. Join us, and let's navigate these choppy waters together.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to conquer the CISSP exam with confidence? Join me, Shon Gerber, in this week's CISSP Cyber Training Podcast as we tackle questions from all eight domains to give you the insights and knowledge you need for success. From understanding the purpose of a risk register to exploring the primary security concerns in a microservices architecture, this episode covers a wide range of topics to sharpen your cybersecurity prowess.
We'll dive into essential concepts like data classification, stateless firewalls, and incident response phases. Plus, I'll share valuable tips and strategies to help you handle each question with ease. Don't miss out on this opportunity to deepen your understanding of key CISSP concepts and prepare for the exam like a pro. And don't forget to check out CISSP cyber training for more free questions and resources to support you on your journey.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Do you know the differences between security events and security incidents? Are you confident in your ability to protect log files from unauthorized access? Join me, your host Sean Gerber, in this week's episode of the CISSP Cyber Training Podcast as we explore domain 7 of the CISSP exam and tackle these important questions. Remember, it's all about understanding the concepts, not just memorizing the questions.
I'm also excited to introduce my CISSP blueprint, a product designed to guide you step-by-step through the process of studying for the CISSP exam. This blueprint not only offers a comprehensive study guide but also breaks down each step with links to resources, readings, and tasks to complete. Check out my CISSP blueprint at CISSPcybertraining.com and be sure to tune in next week as we continue our journey through the CISSP exam questions and topics.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Are you ready to level up your understanding of logging and monitoring in the world of cybersecurity? Join us, your host Sean Gerber, as we take a deep dive into CISSP domain seven, exploring the ins and outs of logging, monitoring, and how they play a crucial part in keeping your system protected. Listen closely as we unravel the challenges of managing vast amounts of data, deploying and disposing of resources, and utilizing cryptographic resources for physical security.
Discover the different types of logs - system, application, and security logs - and how they can be used to detect incidents, operational problems, and policy violations. We discuss the importance of accurate date and time stamps and the role logs play in forensics analysis, compliance, and troubleshooting. Moreover, we tackle the challenges of data overload, false positives, and evading detection.
In this episode, we also discuss the exciting role of Artificial Intelligence (AI) and Machine Learning (ML) in the security world, and how they can be used to enhance protection. Learn best practices when dealing with logging and monitoring, such as encryption, regular monitoring, and backups. By the end of this episode, you'll be well-equipped with knowledge on logging and monitoring that will not only help you pass the CISSP exam but also vastly improve your cybersecurity strategy.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to ace the CISSP exam? Join me in this episode as we explore domain six, focusing on security controls and assessments. You'll not only learn the primary objective of security control testing but also gain insights into various types of tests and the limitations of vulnerability scanners. Together, we'll dive into the nitty-gritty of security control testing, ensuring you're well-equipped to tackle the CISSP exam with confidence.
We'll go beyond just understanding the concepts - I'll provide examples and explanations for each question, so you truly grasp the material. From compliance-based security control tests to manual security control tests, we'll break down the benefits and limitations of each. We'll also discuss the crucial difference between black box security control tests and other types. By the end of this episode, you'll understand why security control testing should be an ongoing process and not just a one-time event in the system development lifecycle. So, let's get started and take that step closer to passing the CISSP exam!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
Ready to ace the CISSP exam and level up your cybersecurity knowledge? Together with my background as a former red teamer, we guide you through domain six - security assessments and testing, covering both military and corporate America perspectives. We'll discuss essential concepts such as vulnerability assessments, risk tolerance of companies, and the tools required to identify vulnerabilities.
Join us as we explore the different types of testing, including manual and automated testing, and explain the importance of following security methodologies during a security assessment. You'll learn about penetration testing as a form of surgical strike and its role in gaining long-term access to an organization. Additionally, we'll reveal the importance of securing AWS accounts and API connections to prevent data breaches, and how pen tests can help validate security controls and incident response processes.
Finally, discover the role of automated tools in meeting compliance requirements, like the American Disabilities Act. We'll also examine manual testing, code reviews, and the use of machine learning models and social engineering to manipulate individuals. With our valuable insights and practical examples, you'll be prepared to tackle the CISSP exam and enhance your cybersecurity skills. Don't miss out on this action-packed episode!
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Ready to conquer the CISSP exam and advance your cybersecurity career? Join me, Sean Gerber, as we break down identity and access management, exploring the primary benefits of single sign-on systems, session management, and multi-factor authentication. Plus, get insights on the differences between role-based access controls and other access controls, giving you the knowledge and tools to pass the CISSP exam the first time.
Not only will we discuss the importance of passing the CISSP for a successful career in cybersecurity, but we'll also share vital resources to support your exam preparation. Whether you're an experienced professional or just starting in the field, this episode is packed with valuable information to help you achieve CISSP certification and take your career to the next level. Don't miss out on this chance to gain expert guidance and confidence for your exam!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Are you ready to up your cybersecurity game? Look no further, as I, Sean Gerber, take you on a deep-dive into the world of identity and access management. Together, we'll explore various authentication methods, such as passwords, tokens, biometrics, and multi-factor authentication, and analyze their strengths and vulnerabilities. We'll also tackle the all-important concept of credential creeping and discuss how to prevent unauthorized access to sensitive data.
But wait, there's more! Identity and access management isn't just about security; it's also about compliance. Join me as we examine the role of IDM in regulatory requirements like GDPR, HIPAA, CMMC, and Chinese Cyber Laws. I'll share expert tips on streamlining user management by creating and removing accounts to ensure the safety and security of your organization. Plus, we'll delve into the challenges of granting and denying access to resources based on privileges, helping you combat credential creeping effectively.
To wrap it all up, I'll reveal the best practices for identity and access management, including crafting clear and comprehensive policies, robust authentication and authorization frameworks, and privileged access management solutions. We won't stop there – I'll also discuss the significance of session and federated identity management, touching on aspects like user authentication, session tracking, session timeout, and session termination. So, don't miss this information-packed episode guaranteed to strengthen both your cybersecurity knowledge and CISSP exam preparation!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
Gain access to 30 FREE CISSP Exam Questions each and every month by going to FreeCISSPQuestions.com and sign-up to join the team for Free.
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Join Shon Gerber on the "CISSP Cyber Training Podcast" as he delves into Domain 4 of the CISSP exam, which focuses on Communications and Network Security. In this episode, Shon will cover some of the most challenging CISSP exam questions related to the OSI model, various TCP/IP layers, and protocols such as SYN, SYN/ACK, etc. He will explain the intricacies of each layer and how they work together to provide secure communication channels. Whether you are just starting to study for the CISSP exam or are a seasoned security professional, this episode is a must-listen. Shon will break down complex concepts into easy-to-understand terms and provide tips and tricks for passing the exam. Don't miss this informative and engaging episode of the "CISSP Cyber Training Podcast"!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
In this episode of the CISSP Cyber Training Podcast, we explore Domain 4 of the CISSP exam - Implementing a Secure Channel. We delve into the intricacies of the OSI model and TCP/IP, as well as the four layers of the TCP/IP model, to provide a comprehensive understanding of how to establish and maintain secure communication channels in your network. We discuss the importance of encryption, authentication, and authorization in maintaining network security. Our expert guests share their insights and experiences on best practices for implementing secure channels, including practical examples and real-world scenarios. Whether you're a cybersecurity novice or a seasoned professional, this episode will provide you with valuable knowledge and skills to enhance your cybersecurity expertise. Join us on the CISSP Cyber Training Podcast and stay ahead of the curve in today's constantly evolving cybersecurity landscape.
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Join cybersecurity expert Shon Gerber on the CISSP Cyber Training Podcast as we explore Domain 3 of the CISSP exam, focused on security models. In this episode, we delve into the various security models, including the Bell-LaPadula, Biba, Clark-Wilson, and other models. Our expert guests share their experiences and insights on these models, their applications, strengths, and weaknesses, and how they are used in real-world scenarios. We also provide an in-depth review of the associated CISSP exam questions related to security models, giving you the knowledge and skills you need to succeed on test day. Whether you're a cybersecurity professional looking to enhance your knowledge or a student studying for the CISSP exam, this episode is a valuable resource. Don't miss out on this opportunity to gain a competitive edge in your cybersecurity career. Tune in to the CISSP Cyber Training Podcast with Shon Gerber now!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Description: In this episode, we delve into the fundamental concepts of security models, a critical topic in the CISSP exam. Aspiring CISSP professionals and cybersecurity enthusiasts will gain valuable insights on Domain 3.2, covering key concepts, principles, and best practices related to security models. Join us as we explore various security models, including the Bell-LaPadula model, the Biba model, the Clark-Wilson model, and the Brewer-Nash model, among others. We'll discuss their unique features, strengths, limitations, and practical applications in securing information systems. Whether you're a CISSP candidate preparing for the exam or seeking to enhance your cybersecurity knowledge, this podcast provides comprehensive coverage of security models, supported by practical examples and exam tips. Don't miss this opportunity to expand your understanding of security models and ace the CISSP exam!
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Do you struggle with understanding CISSP exam questions related to data ownership in Domain 2?
Tune in to our latest episode of the CISSP Cyber Training Podcast, where we discuss the most challenging CISSP exam questions outlined by Shon Gerber in relation to data ownership.
We cover the legal and regulatory requirements, establishing data ownership policies, and data ownership in the cloud.
Our experts provide insights and tips to help you understand the nuances of these questions, so you can confidently approach them on the exam.
Don't miss out on this opportunity to improve your chances of passing the CISSP exam. Listen now to the CISSP Cyber Training Podcast for valuable insights on Domain 2 of the CISSP Exam.
Podcast Link:
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Welcome to the CISSP Cyber Training Podcast, where we're diving deep into Domain 2 and exploring the importance of data ownership. Join us as we discuss how understanding data ownership plays a crucial role in protecting sensitive information and ensuring compliance with legal and regulatory requirements. Our expert instructors will walk you through real-world scenarios to help you establish proper data ownership policies within your organization. Don't miss out on this valuable opportunity to enhance your knowledge and gain the confidence you need to pass your CISSP exam with flying colors. Tune in now to the CISSP Cyber Training Podcast! #CISSP #CyberTraining #DataOwnership #ExamPrep
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔒 Master the Data Lifecycle with CISSP Cyber Training! 🎧🔍
🎙️ Attention CISSP Exam Takers! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for mastering Domain 2: Managing Data Lifecycle! 📚💡
🔐 Deep dive into the intricacies of data management and gain expert insights on the lifecycle process through our engaging podcast episodes. From data creation and storage to its secure disposal, we cover it all! 🎧✨
📌 Enhance your understanding of data classification, retention, and encryption techniques. Stay updated with industry best practices and regulatory requirements to ensure the utmost data security throughout its lifecycle. 💼🔒
🌟 Equip yourself with the knowledge and skills to excel on the CISSP exam! Follow us on LinkedIn and Facebook to access valuable resources, tips, and expert advice on mastering Domain 2. Let's conquer the Data Lifecycle together! 👉📊
Podcast Link:
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔒 Master the Data Lifecycle with CISSP Cyber Training! 🎧🔍
🎙️ Attention CISSP Exam Takers! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for mastering Domain 2: Managing Data Lifecycle! 📚💡
🔐 Deep dive into the intricacies of data management and gain expert insights on the lifecycle process through our engaging podcast episodes. From data creation and storage to its secure disposal, we cover it all! 🎧✨
📌 Enhance your understanding of data classification, retention, and encryption techniques. Stay updated with industry best practices and regulatory requirements to ensure the utmost data security throughout its lifecycle. 💼🔒
🌟 Equip yourself with the knowledge and skills to excel on the CISSP exam! Follow us on LinkedIn and Facebook to access valuable resources, tips, and expert advice on mastering Domain 2. Let's conquer the Data Lifecycle together! 👉📊
Podcast Link:
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔐 Ace the CISSP Exam with Confidence! 🎧🔍
🎙️ Exciting News for Aspiring CISSP Professionals! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for mastering Domain 1: CISSP Exam Questions! 📚💡
🔐 Enhance your knowledge and test-taking skills with our expert-led podcast episodes. Get ready to tackle the most challenging concepts, from security governance principles to risk management frameworks and beyond! 🎧✨
📌 Gain valuable insights into the intricacies of Domain 1 and equip yourself with the tools needed to excel on the CISSP exam. Dive deep into real-world scenarios, sharpen your problem-solving abilities, and become a CISSP champion! 💼🏆
🌟 Don't miss out on this incredible opportunity! Follow us on LinkedIn and Facebook, and embark on your journey towards CISSP certification.
Let's conquer Domain 1 together! 👉🔒
Podcast Link: https://www.buzzsprout.com/2167626/12706900
👉 LinkedIn: www.linkedin.com/in/shongerber
👉 Facebook: https://www.facebook.com/CyberRiskReduced/
👉 CISSPCyberTraining: https://www.cisspcybertraining.com/
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
🔒 Boost Your Cybersecurity Knowledge! 🎧🔍
🎙️ Exciting News for Aspiring CISSP Professionals! Introducing the "CISSP Cyber Training Podcast," your ultimate resource for acing Domain 1: Understanding the Legal and Regulatory Issues in Information Security! 📚💡
🔐 Dive deep into the crucial aspects of information security law and regulations with our expert-led podcast episodes. Uncover the foundations of compliance, privacy, intellectual property, and more in just a few minutes each day! 🎧✨
📌 Stay up-to-date with the latest industry developments, including global data protection laws and cyber regulations. Gain valuable insights from seasoned professionals and enhance your understanding of legal requirements within the CISSP realm. 💼🌐
🌟 Prepare yourself for success! Follow us on LinkedIn and Facebook, and embark on your journey towards CISSP certification. 🏆🔒
👉 Episode Link: https://www.buzzsprout.com/2167626/12706883
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!
Again, head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
In the world of cybersecurity, maintaining professional ethics is paramount. Aspiring CISSP professionals need to understand the importance of ethical behavior and its impact on information security. Join us in this podcast episode as we explore Domain 1 of the CISSP exam, focusing on the fundamental concepts of understanding and adhering to professional ethics.
We'll delve into the ethical principles that guide the cybersecurity industry, including integrity, confidentiality, and professional competence. We'll discuss the significance of ethical decision-making, the implications of unethical behavior, and the consequences of non-compliance with industry standards. With insights from seasoned cybersecurity experts, we'll provide real-world examples and scenarios to help you grasp the relevance of professional ethics in the cybersecurity field.
Whether you're a cybersecurity professional preparing for the CISSP exam or someone interested in the field of cybersecurity, this episode will provide valuable insights into the ethical foundations of the CISSP certification. Don't miss this opportunity to gain a deeper understanding of professional ethics in the context of CISSP certification. Join us for this thought-provoking discussion on cybersecurity ethics and best practices.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!
Again, head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Welcome to CISSP Cyber Training, the podcast that delves deep into the world of cybersecurity and provides you with expert insights and strategies for mastering CISSP Domain 8. If you're seeking CISSP training and looking to excel in the field of information security, this is the podcast for you!
Join our experienced hosts as they explore the critical concepts, best practices, and challenges related to software development security, one of the most crucial domains of CISSP certification. From secure coding practices to threat modeling, from secure software testing to secure software deployment, our experts will share their wealth of knowledge and practical tips to help you stay ahead of the game in this rapidly evolving field.
Whether you're a seasoned information security professional or just starting your CISSP journey, this podcast will equip you with the skills and knowledge to excel in software development security. So, tune in, and let's dive deep into the world of CISSP and software development security together!
Keywords: cybersecurity, CISSP training, CISSP.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!
Again, head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
"Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!"
Head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will be covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Don't risk failing the CISSP exam. Head over to CISSPQuestions.com right now and check out my free collection of CISSP exam questions and increase your chances of passing the first time!
Again, head on over to CISSPquestions.com and get your FREE Collection of Top-Quality Exam Questions today to help you master the CISSP exam with Confidence!
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will be covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam:
· CISSP Articles – Supporting Investigations
· CISSP Training – Understanding and Supporting Investigations
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:
· CISSP Articles – Access Control Types
· CISSP Training – Access Control Types
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will be covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
hon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam:
· CISSP Articles – Supporting Investigations
· CISSP Training – Understanding and Supporting Investigations
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:
· CISSP Articles – Access Control Types
· CISSP Training – Access Control Types
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/identity-and-access-management/access-control-categories/#gref
TechTarget
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP Articles – Secure Network Design
· CISSP Training – Cybercrime and Data Breaches
· CISSP Exam Questions
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Peerlyst
https://www.secureops.com/networking/effective-network-security-design/
TechTarget
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will cover questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Transcript:
…Hey y'all this is Shon Gerber Thanks for listening today But before we get started I wanted to update you on the launch of my CISSP cyber training membership for my listening audience. On March 5th, 2023 I began offering a monthly CISSP membership at 60% off my already low price. This is an introductory offer of $19 a month for the first year. With that insanely inexpensive price you will get all of my CISSP content practice exam questions, all my current and upcoming curated content. And finally me. As I'm growing my products and services for my site you will be on the ground floor to take advantage of an offer that will never ever come back again. So if you're planning on taking the exam in 2023 or if you want to learn more about cybersecurity, this will be the time to make a life and career altering decision for you and your family. There's amazing offer is only available for the next two weeks So I highly recommend that you don't delay and sign up today. All right let's get started. Welcome to the reduce cyber risk and CISSP training podcast, where we provide you the training and tools you need to pass the CISSP exam The first time. Hi my name is Sean Gerbert I'm your host for this action packed informative podcast. Join me each week as I provide the information you need to pass the CISSP exam and grow your cybersecurity knowledge. All right let's get started…Okay Question number seven. What is the security mechanism that is typically put in place to ensure that data is not compromised? Okay answer a honeypots answer B intrusion detection systems, answer C encryption. Answer D host based intrusion detection system or Hibbs That's what I kind of like enough has found like you have a mouth full of marbles who literally. Okay So again the security mechanism that typically is put in place to ensure that data is not compromised. And if you look at all these questions, Which one would keep the data from being compromised. The answer is C encryption. Encrypting is commonly use. to ensure that data is not compromised, both intransigent. And while it's sitting at rest in databases or other locations, Again that is encrypted. Answer C honeypots what do they do They kind of act as something the way that kind of allows people to bite off on something that's there They they become and they look like a. A free. Target intrusion detection systems are looking for intrusions right? Host based intrusion detection systems or something that's based on the host itself. So they're really just looking for other intrusions, but when it comes to ensuring that the data key word data is not compromised, the answer is C encryption…Okay. number eight. When a device ORC slash capability is considered highly available, it means that the system must remain available. A most of the time. Be a large part of the time C only when necessary or D all the time. Okay again question is when a device or capability is considered high availability. It means the system must remain available. A most of the time be a large part of the time. See, only when it's necessary and D all of the time. If high availability is called out and required it must be available all the time. So again by setting this requirement you. can add additional resources or terms in contracts to ensure that this occurs What does that mean? It means if you are requiring this as a company that you must have high availability for those systems. Then at that point you wanted to find that within your statements of work or within your contracts, because that will drive in some respects how much work they have to do, but also how much money it's going to cost. So you have to determine is high availability a necessity for your business…Okay Question number nine. Availability is compromised when a denial of service occurs and is. A mitigated. Be not mitigated I…see adequate protections are implemented. or D a system has non-repudiation enabled. Okay So again…Availabilities compromise when a denial of service occurs and is a mitigated. Be not mitigated I see adequate protections are implemented or D a system is non-repudiation enabled. So if you look at those three questions, really what it comes right down to what is denial of service You need to know that denial of service is something that is denying you access to it So the availability to gain access to the data it's denying it So if it's denying that service to you, Then it hasn't been mitigated. Right So that you're causing issues So adequate protections are implemented that's out because it's not working. C R D a system is non-repudiation. enabled. That's really not. That's talking and not about anything about denial of service So you get rid of that It's an easy one to throw out. And then D mitigate it So C and D are pretty much the same pretty close right? B is not mitigated So if you have denial of service it is not mitigated. And therefore it is causing you disruption. And the answer is B. Thanks so much for joining me today on my podcast. If you like what you heard please leave a review on iTunes as I would greatly appreciate your feedback. Also don't forget the 60% off buy membership at CIS S. Cyber training.com. We'll be ending on the 19th of March. So sign up today for this once in a lifetime sales event. Thanks again for listening.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Engineering Secure Design) of the CISSP Exam:
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Peerlyst
https://www.peerlyst.com/posts/how-to-start-looking-for-an-infosec-job-my-list-of-tips-evgeny-belenky-1?utm_source=linkedin&utm_medium=Application_Share&utm_content=peerlyst_post&utm_campaign=peerlyst_shared_post
TechTarget
Transcript:
Hey y'all welcome to the reduce cyber risk podcast This is Shawn Gerber Again calling out to you and hope everybody's doing well This beautiful week. We have a wonderful. Thanksgiving holiday coming up here in the United States And so everything is getting prepared for that. It's a great time to be If you like food it's an awesome time And United States. Is one of the things that we actually trust truly crave It's great Yet turkeys you got a ham you've got everything you could possibly think of. On this Thanksgiving holiday season. And for us it's just a great time. The everybody has been doing well this past couple of weeks. And things have been really busy here at Gerber central here in Wichita Kansas. It's been pretty crazy as I've been working with my wife and her business. We've now bedded that down for the season So that's been a good thing And I'm able to spend a little bit more time on reduced cyber risk podcast and creating some great content around the CIS SP. And so as we know the one thing that we're trying to get into more is. As you view. there self studying for the CIS. it can be a bit of a challenge to do that And I've I've just been paying attention to some people that were in the Wichita area that have been studying for that exam. And it's been kind of interesting talking to them. They they've been having some study groups They've been trying to get that. That going for quite some time now. And they've had some good success but at the end of it it really comes down to is trying to self study for this thing can be a challenge So that's kind of the purpose behind reduced cyber risk podcast and why we've put all this together. So today's podcast we're going to be getting to a couple of key things And as you if you have already known we kind of pull out some CISP articles that are on the web, as well as providing some CISP training that I provide through the courseware that you can go ahead and Google that you'll find it real quickly, but there's also the training that I provide there as well. And then finally some CISP exams will be available to you Quite exam questions are there as well So that stuff that you can do to study for for the exam and that's the one thing I was also reading a recent article on about the CISP is that 50% is knowledge and 50% is based on how you take these exam questions. And I will also say though that the interesting part around that is if you taking. I remember when I studied for this thing it was how many questions can I cram in? How fast can I do it And can I regurgitate it as quickly as I possibly can. And then that's changed a lot over time but at the end of it the questions that they provide in the test banks. We'll not, I mean there probably are some that will go word for word but at the end of it, ISC square puts out questions that you can use. The books have questions you can use. And…you just got to ask yourself though. The ISC is not going to make these questions the same. Now they may make them similar, but they're not going to make them the same So understanding the content is really a great way for you to actually be able to to get do well on this test And at the end of it, when you pass the test, You want the CISP certification You want the ability to get a job? And so you're going to have to know this information You can't just go in and take a test and dump it and go, my kids do that quite frequently They would they would take a test and then they would just dump it And then you'd ask them that same question, not too long later And they would go what are you talking about So it's kind of interesting because. They they don't think about the long-term consequences for just cramming for these tests So it's kind of interesting. All right So let's get into our first question Our first. Comment we're going to have today on this podcast and what it is we're looking for the basically around who's how to start looking for an InfoSec which is information security job. That's going to be the article that we're going to go into today. And and what I'll tell you also as we go into this, you can get some, the free videos that I have available out there. Basically domain one through fours but the CIS is P videos The full length videos that I use for teaching. Yeah you can get a plethora of those through domains One through four, I've got to select a select number of those videos out there available. But if you go and you set up for my email list you'll be able to get 11 videos free just for signing up. So I highly recommend you go out there and you do that as it was also on building other various free content that will be available out there. Podcasts the links to those podcasts are all there as well. And so there's a lot of different aspects you can do by just going to the website. If you want you also can buy my, the full domains one through eight video train that's available@shaundra.com You can get all of that there. There's a really good black pro black Friday pricing here in the United States We have black Friday and that's coming up in June Uh on. I think it's in Yeah it's on Friday. This coming Friday. And so you can pick up all of that content right there and available for you And it's awesome So we're going to have a really reduced price going to be basically 50% off of buy more normal pricing. Okay so let's roll right into the CISP articles. This comes from peer list.com and they have some articles out there about what should you do when you're looking for an InfoSec job? How how should you handle it? And. so here's some key nuggets from this article that they had put out there and you can click you'll have the link will be on my show notes So you can be able to click on that link and go to them directly. And one of the key these are some big bullets but I'll I'll add some context to this as well. They talk about don't be afraid to ask questions Now the one thing I've I've done numerous interviews with people because I'm pretty old. I've been around for quite a while And and so when I first did interviews I one thing I was concerned about as the interview E is what should I ask questions? Being on the opposite end of the table Ask asking the questions of people that want a job. I will tell you flat out right now If you have the ability to ask questions please do it It shows that you actually are interested It shows that you have done some thought into this So asking questions is very important. No I add a little bit of a caveat to that. You need to be very careful about not asking too many questions. So it's, it's kind of one of those things where if you get asked. I'm just using this as an arbitrary number you get asked. Three questions are. questions, then you ask maybe one question. I'd say more like if you ask, if they ask four or five questions then you ask one So about 20%. And so you need to ask some question but they also need to be. Ones that have been thought out not like where's the bathroom…You need it and understanding if the job is going to be. If you're looking for benefits or maybe a benefits question would be good One question around benefits. But the questions need to be focused on around the security piece of this And how would you utilize security within their environment And I would ask them key questions based on the role. What is the role of if it's a security architect role? You know what is can you to explain a little bit more about your enterprise and the role of a security architect within your enterprise? And then that have them say some stuff around that But again you need to make sure you ask the right pertinent questions to the right pertinent people. You also need uh you need to specify the list of positions you're looking to move into and which ones do you want to go So if you are. you have your resume and you already applied for a role and say a security analyst role within a security operation center, you need to be. Understanding Those are the positions that are available. You also need to provide technical details about yourself and what you're trying to achieve. And that this comes under your goals What are you trying to be with your goals your, your bio how are you wanting to get there What did you start How did you end there again There? The employer's trying to pick out a, an aspect about you that they can decide Hey you know what I want to hire this person. Now try not to be too pushy And that's what. When it talks about when asking people for help So that means when you're talking to people that are helping you get in the role don't, don't try to push on them going Hey where am I at What am I what's going on How would I how'd I do. Those kinds of things you don't need to be. Pushing onto people. However you need to be able to to ask questions. So it's that fine balance of people skills. There's a really good book that I recommend and it's super thin It doesn't cost much It's like on Amazon for it's like two to three us dollars. It's called skill with people and it's I think less Gibson and it's a really good book on how to deal with people. If you're in it you probably struggle with this And sometimes a lot of it people do. It's a really good book and I'd highly recommend you go out and buy it. If you're looking for an internship. You but you must really first look at what are the companies out there that are looking for interns. It not all companies are looking for interns in the security space so that's kind of an important area to be there. Also you need to connect with various groups on social networks and engage there. Now key a key piece around that is. If you are a social networking person. Be very careful what you post online. Because again people are watching what you do and if you post some buffoonery out there of online, the interesting part is that never goes away. And as a security professional you should know this that when you put post something out there, it will always be there for avert. It will never go away ever. You can contact recruiters Italo agencies. I've done this as well and been in contact with various recruiters. It's it's a way that you can be…basically having guidance around that Now I also would recommend that one way to help when with recruiters. Is to provide value for them If you can look at ways that you can help them. And and help them find new people. That's always positive too So then the recruiters are helping you to find a role. Now as there are over 2 million jobs. That it's always good to have a recruiter on your side because they will help you kind of fish through or our funnel through some of the stuff that may be a good fit for your role That you're. With your background and or others that may not be a good fit…If it's relevant again look at what your what the opportunities are You need to Polish up your English skills It's always a plus and I would highly recommend that you do this Now I've got a daughter who is speaks English as a second language. And the one thing that I have talked to her on over and over is her Spengler English her Spanglish Now that's not a good word. Her English speaking skills and in the United States or in doesn't really matter what role you're working with. The common language typically used is English So if you have solid English skills and you can make those better that is wonderful. It to also also put it in perspective I said also twice. Geez That's crazy. To put it in perspective as well. One thing to consider is that. Do you need to in this role security roles, they are influencing roles They are roles that will you talk to two different companies You talked to leadership. And so therefore you need to be able to. To provide influence on leadership around what needs to occur Well if your English skills are not very good. It's pretty hard to go. And. Provide influence. So that's why we recommend that you get some level of, of increased knowledge around the English skills. Is it totally required No not at all. Like if you're from China and you're only going to work in the Chinese market. And you. don't want to go anywhere else. Well then your English skills may not be as important. But I will say you work with contractors and you work with vendors. And so having a good English skills would be helpful in that space as well. So just just something to consider. The other thing is one of the bolts they had also down there. Was that you should utilize Grammarly. It's a basically it's when you're dealing with. Writing. Uh content and you want to have the ability for it to to tell it's the grim grammatically correct. Use Grammarly to do that. Now I will say Grammarly is pretty close It does a pretty good job however it's not perfect. So don't rely totally on Grammarly. Also as you are understanding how Grammarly is doing things. You you need to understand as well. What is the sentence structure look like So my daughter, she she's really good at leaving off prepositions. Now she's Chinese So that. That that makes sense Right So I I've, it was all funny when I was. up with a kid I could never understand why. The Chinese would leave off prepositions Well in their language they don't have that. And and so I didn't get it when I was younger and I really actually didn't get it until I adopted a child from China. And now has she speaks I see her leave out those key. Uh prepositions and adjectives that. She just doesn't do it She has doesn't do a very good job with it So it's important that as you were studying Grammarly and that you if it's helping you with your. Uh sentence structure that you understand why you're doing that and pay attention to it because if you do it it will go very well for you It really well. You also need to tweak your message when contacting people based on that what's worked best so far for you. And it's always good to have someone that's personally within a company to help you, because again they are. If they can help walk your resume in it's way easier for you to get a job or at least get an interview. Then if you just start blasting people with emails that just doesn't work out. it may work but you may not get what you may not want what you get And that's really what it, what could happen to you So make sure that you build personal relationships And if you haven't figured it out yet in the world of security, Personal relationships are everything. And that is how everything is built here And so if you build those good relationships the good roles will come to you. And then not so good roles will move on or at least you'll have a heads up on what role is good and what one is not good. You mean to use job boards There's various ones that Peerless talks about once they've had indeed Gaudet not go daddy, monster.com. That dice.com is another one that is for more of technical people. And again that's those are important places to go freelance fiver as well. You need to treat your job search. Basically as your current jobs it's like, again I use my kids as an analogy cause I got so many of them I mean I have I have seven children so it. I see things on a daily basis that most people deal with and you just like really. I mean I had a daughter come in a day. She's 18. She made the comment to my wife. She was going downstairs and they were having a bit of a challenge and basically did this. And these are the scales from Uganda. And you know it didn't, didn't didn't have anything and which, which and the United States it's interesting because you don't necessarily need all the stuff that you get in the United States And so this girl who came from Uganda, Walks down the stairs and she goes, After having a little bit of a TIFF with my wife and says you started this. And you're just like are you kidding me? So that a interesting world So if you have children out there you know what. Yeah they're they're great Or they they're fun when they're little and they're fun when they're middle And then then when they get older they're not so much fun anymore So. It's interesting time. And if those of you who don't have children great uses as an opportunity possibly to think of but think twice about doing that. Wait a little while before you do it That's for sure. So again those are those are important things to consider when you're. at a job. Now I'm going to give you my takeaway So Gerbes is takeaway again Gerbes is my call sign I have on my flu B ones, but I give you my takeaway on all of this. You need to work on your certifications. Uh security plus network plus, and then also the CIS. P associate I think it's very important that you get those certifications done. If you can get the certified ethical hacker I think that helps put a different perspective on how you look at things. So those are those are some key certifications that if you can get those I would highly recommend it. Also if you are in the United States you can join the military or even in your organism in your country They may have this cyber forces that are within your military. If you can join their military I would recommend that. One if you use patriotism towards your country but two, they teach you also the skills you will never ever get anywhere else It's very hard to get those skills. And then basically three is join various local security organizations to help you with introductions to people, with getting some technical knowledge around these different aspects that are going on. So those are great ways to get started And then if you go to college or local university in your area that could also help you with depending upon what kind of security program they have in place. But again you get it's not just the technical pieces that you have to focus on. It's the soft skills as well. So those are very important that you get the right books You study the right. Uh techniques and you get the soft skills you need to be successful in security. All right So let's move on next to our C I S. P training. So overview the security is considered basically at all stages of system development So when you're looking at engineering processes and you're trying to divine. Design a secure environment. You need to have security considered at all stages of the system development. And I say this because I do this on a personal basis daily in my job, I am always dealing with security in the various stages from the beginning of the applications creation all the way to the completion and it could be the application built itself. for a specific process or it could be. A already pre-built application that a vendor's providing a for you. And one of the questions that I asked these vendors that bring us products is your your pro your security people do they are they understanding the secure development life cycle and as our secure software development life cycle which is typically called SDLC. Sometimes you'll see it acronym as just SDLC for software development life cycle, and security is considered one aspect underneath that, but that's it should be considered a basically an all does areas of system development. And following the following one I'll throw out there are really some key items that you'd need to be aware of as you're dealing with secure design. Now you have objects and subjects. An object is a resource that used by a subject. So as an example an object would be a computer system that would be an object subject would be basically the process requesting access. could be We call them an RPA robot process algorithm. Or it could possibly be an individual. It could be a service account It could be anything that is reaching in and using that object or that computer system, that wireless router that whatever that might be. Okay So those are objects and subjects. Now the other key point around this is that as we all know security is based around trust and there has to be trust set up between the objects and the subjects. And so as a user let's say a service account as a user. And then you in this in this scenario You know R and D computer system is the object. Well these two must have a trust between the two. The service account and the R and D computer system. Well the manipulate this could be manipulated by attackers in the fact that attackers would come out and they would go after that R and D computer hoping to get access to it And an example of this would be. It was occurred a while back where the Iranians had a centrifuges that were hacked. Using I think Stuxnet. And and so that's those accounts that acted the. Are activated and worked on those centrifuges. They had they were user access. Well there was a service account or individual user's credentials were compromised. Those are user accounts. So that R and D computer system would be hacked by these attackers So these trusts though, are in place Now if the trust didn't exist well then the attackers wouldn't get anything. So that's why it's important that a trust is set up between these objects and the subjects. Some other key terms is closed and open systems. You hear terms about this but a closed system is designed to work with a, in a very narrow range. So we would have typically in the military we'd have a closed environment network. And what you would do is that they would, it would not be connected to anything else You couldn't do anything other than what's inside that system. So if that system is able to hook to the F 20. To fighter, then what would happen is is that system would be connected to it but it would not be connected to any nit internet, any other network shares nothing. It would be a closed system. And it's really defined by the manufacturer So many of the defense contractors will develop closed systems so that they don't get hacked. The problem with this just to keep in mind is that they take a lot more overhead to ensure that they are protected. These closed systems the manufacturers put things in place but they don't always put the level of security in there as well. And and. Again it can be a little bit more. They are not little. They can be. Significantly more secure. However it's just you need to plan for this You need to make sure that you have people that can manage these systems. Now open systems these are agreed upon on an industry standard So if there's an industry standard set up around these particular environments, These are open systems and they're much easier to integrate with other systems as well. There's more options into the network they're less secure, and this would be a computer current computer system that you would run into would fall into these open systems. And in typical networking and typical computer systems are open So…Now there's close and open source code and a closed source code is proprietary code that is set up specifically for your environment. You may have a a. I don't know a lab. I usually keep kind of gonna go back to the lab environment or you built up just a basic application that maybe working as and I've seen this in like visual basic six right So it was really old, but that application works specifically for whatever you want it to do That would be proprietary code. These can be designed for both open and closed systems but what ends up happening is is. They're not always updated because they rely on the manufacturer for those. If they're a home grown system like I just mentioned with the VB six. You do run into risks where they will get exploited by people. And so these people exploit them. And they're never really updated because one person just made this out of convenience made this application and it works and it doesn't get provides what they want. But it's never updated So therefore over time creates a vulnerability. There's good companies around. this space will be Microsoft Boeing I mean you name it There's software development people everywhere. Here in Wichita Kansas we got to an individual We have Flint Hills group which is another company that does software development for all kinds of contractors You name it They're there all over the place. You also need to have techniques to maintain your confidentiality integrity and availability Now if you're studying for your CIS as P CIA is extremely important and there's various techniques by software developers to do this. And basically you can any of the following that we're going to talk about here. Can be used outside of software development as well. But software development is the primary place where this kind of begins. Now confinement. Is a restricted user you process access and actions to a program So what happens as you restrict the user to, or the process to a specific program or a specific action within a program? Now it does allow the process to read right For specific locations. And that would be just you're confining the capability of what it can cannot do. Now the sandbox also can provide some level of confinement You want that? Applications to run in the sandbox And this is where you place these restrictions. On where they can operate and they must meet or operate areas with a higher sense of security. Now, when it comes right down to is this is like an example I could have for you is only a specified systems can operate against a specified database You get very narrowed on what they can and cannot do. They also have any systems outside of the scope will not be allowed So those are kind of the examples that are in place I use this all the time especially when dealing with higher proprietary systems. You want to make sure that they'll only these ones can talk to certain other ones that didn't really make sense All these ones that's not that's starting to sound like my daughter. No, all of this systems that can to only a certain subset so only a can talk to be It can't talk to see but it can only talk to B. Those are kind of important areas to put in place…Now as we get into bounds bounds are defined process is a given specific authority to operate and there can be many or there can be few. I recommend less is more. Don't do a lot Keep it little. Okay. That doesn't make keep it little. That's really strange by English language His skills are not so good today. When it comes into as you get your user you get your kernel you got administrator. They needed to find these processes for a specific capability So if you need this Colonel the Colonel process to run a certain way, then you define that If you have your administrator to run a certain way, you define that. And these bounds will keep them from doing this from doing more than they should. They operate You also have to put these bounds in place for operating systems memory and hardware. Do you want the kernel to be running in a certain format? Do you want it to have full capability within the entire system up and down the stack? Or do you want the user to have that capability? Those are key things you need to put in place to restrict that kind of use. As an example you'd have a malware utilizes errors wince in setting bounds and basically deals with the Colonel manipulates the curve. you see this fruit routinely in the security space that the. Because what's happening as a user accounts are getting locked out pretty well. So now what are they doing They're going after the system or the use or the Colonel accounts to try to manipulate the overall system themselves…Now process isolation ensure that it only affects specific memory locations. These you mean to make sure you you isolate the processes so that only areas within memory are affected. It's a, it's really a part of a stable system And what'll happen with hackers If they're trying to do a denial of service attack. They will go and mess with these processes and if they can cause them to be unstable while then it causes the system. Not work and and realistically, you don't have to nuke the system to make it not a functional You just have to create unstability in it And it will that will do a huge factor in as well. As an example you could have cut paste Copy You would allow those to transition between the two. You can have macros to run outside to find parameters All of those pieces can be available. So it's just something to kinda keep in mind…As you deal with controls. There's also you need to put in place different controls to limit the access to authorized objects. These rules are in place to limit your access For example, file access You may have only. You may have a lot of people have read only, but you may only want a few that can modify. So again those are the type of controls you would put in place to restrict access to an environment. There's mandatory discretionary access controls, Mack and Dak, and these are designed to limit. Access to objects by subjects So the object are limited in And so there are only certain subjects can talk to these objects which we talked If you start at the beginning of this section on the podcast around, and those what these max and Dax are for a Mac is a subject cannot define the object that can be accessed by the user. So. Basically the saying is that the subject can't define what it was going to go after You have to define that for them So that's a Mac mandatory access controls. And so those are already set. for that user. DAC is flexibility with access. Objects can be accessed by the user So the user has the capability to move things around to decide what he wants He or she wants to have access to. So again mandatory it's defined. Discretionary. It's more, it's more loosey goosey It's more available for you to do be able to do what you need to do. And so an identity of a user may be granted greater access That would be an example of Adak and and that in that space would be. It depends on the situation You may want the user to be able to do that. So those are kind of different access controls Mac and Dak and you'll see these kinds of all these questions are all these terms in various formats within the CIS SP exam…All right so let's move on to the CIS. P exam questions. And we've got three questions for you today. And we're going to go through and find out which ones do you think fit? The mole. All right So this comes from tech target tech target had some different options out there and I like what tech target brings from some different CISP exam questions They pull some of these specifically from ISC squared. So the first one. What are the various SDLC development models covered in the CIS is P exam. Now I didn't talk about these today but they are covered in the exam And if you are dealing with development you will have to deal with these in some form or shape or another. So the first one is waterfall. Second or I should say Hey waterfall, V-shaped iterative, agile spiral and big bang. Now these are the different methodologies on how you do development work So…if you've dealt with development, these are all relatively you know these but if you have never dealt with development which when I first took my CISP As P I'd never dealt with that at all. It was very interesting And uh now I deal with development a lot so. I have a development team that works specifically for me. So those are key pieces right So waterfall V-shaped iterative agile spiral and big bang. Waterfall. Yeah it was a boy. waterfall X shaped So V-shaped X shape. Repetitive agile spiral and big bang. C waterfall Y shaped repetitive agile spiral and big bang. Or D none of the above. Okay So the big difference on all that again if you're taking the CISP exam pick out the ones that kind of stand out which ones you have if you don't know then guests…So in this case here I is a waterfall V it's waterfall V-shaped iterative agile spiral and big bang. All right So that is the first question. Second question attempt to take advantage of how the system handles multiple requests. So if there's an attempt to take advantage of how a system handles multiple requests, what kind of attack is this? So you have aggregation is a. B is a state attack. C is a state machine model. D is a method author, author. The key on. I can't even say it Authorization authentication. code Mack. I can't even say it It's really sad. So aggregation state attacks state machine model and message authentication code. Okay So if you're taking the CISP look for some things that may be similar. So in the case of state of tax and state machine models do you know the difference between the two if you don't know what those two seem to stand out as. They're trying to say the same question twice. Maybe it's one of those. And it is it's state attacks…All right So this involves removal of characteristic from an identity in order to easily. Represent in essential properties. All right So this comes down to is a algorithm. B abstraction. C diffusion. D substitution. So it involves removal of characteristics from an entity in order to easily represent its essential properties. All right So it's taking characteristics away. To basically represent what does it look like? So. It's algorithm. abstraction diffusion, substitution. And it is obstruction So you're removing the characteristics from an entity to try to pull pieces out abstracting pieces out to understand the essential properties of that. Okay so that's obstruction. The core of N O S…and one of its main functions is to provide. Access to system resources which includes the systems hardware and processes. So the core of an oh S and one of its main functions is to provide access to system resources which includes the systems hardware and processes. A system kernel. B state attack C abstraction. D firmware. Okay So if you looked at it listen to the last couple of questions, none of those two of those don't make any sense right Distraction and stare attacks that that doesn't make any sense. So you could narrow it down to two system. Kernel is the answer a.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Marking of Sensitive Data
· CISSP Training – Protection of Sensitive Data / Labels
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
…Hey all is Sean Gerber again with reduced cyber risk How are you all doing this Beautiful beautiful morning I hope things are going well in your part of the globe in this big shiny blue marble, things are going awesome in Wichita Kansas Yes The small little town of Wichita Kansas. it's going well I can not complain at all It's a beautiful summer day School's getting ready to get started and my kids are getting ready to go back to school which is an awesome thing Very very cool. It a one of those situations in your life when you have 50 if and when you have ever have children out there, kids are great most days other days, not so much And so when it comes to going back to school, most parents will just glee with be or be super happy with glee. Yeah that doesn't really good word there but anyway they're really super happy because of the fact that the kids are no longer at home And they're now focused on school. So yeah it's a it's a good thing. Well today we're going to be talking about software development And how old is this? around that? And you'll see many things that have occurred recently It was just a recent breach that hit with that. capital one here in the United States. And they said there was probably I don't know how many millions of people were affected by that And so therefore what ended up happening is is, there there was an insider threat issue Well the today we're not gonna talk about the insider We're going to talk more about the software development, but in the case of when you're creating apps or crew from a Your websites whether you're creating apps for the app store that go into the Google play or iTunes. All of that needs to have some level of software development security built into it. And so there are some key aspects we're going to go into, as it relates to doing that. Along with that is going to be the main things that you're going to have to know for the CISSP exam as you know reduce cyber risk My ultimate. Plan is is to be able to give you that CISSP training You need to pass the CIS S. The first time again we want go into that If you want to pass this I know this test is a bugger din They're done that We're going to have some next upcoming episodes We're gonna talk a little more about the exam. But bottom line is is this test is a bugger and I failed it The first time I studied my butt off for that test I studied basically three months just self study just to go put, pass the test because at the time there there were bootcamps but I didn't have the funds to be able to go pay for a bootcamp. And so I've studied it. And it was actually good that I studied just because of the fact that, it it helped me get a good knowledge of what I deal with on a daily basis. But the cool part about knowing the CISSP and passing the exam the first time is the fact that you will utilize those skills on a daily basis as a CSO, for a large multinational So those are things that consider is that the good thing is just. Just by taking the test is the first step And the examiner is the first step in the whole road to make becoming a cyber security professional. And so therefore it's it's imperative that you get these foundations and you know, fundamentals. And studying too much. Of test questions is very important you know just to understand what are they going to ask for and how they're going to ask. But those test questions are designed mainly to help you as you go through them. Understand the questions and how would they answer How would they. Question you or how would they provide the information for you so that the answers you provide are the right ones. But again Canada has already addressed but the cool part about studying for the CISSP is the fact that you used to learn a lot of good stuff. Well today we're going to learn about software development and the security that goes into that. So when I talk to my SSP cybersecurity integration This is the area that I grabbed some information from the internet, like an article or so forth. And this one is software development life cycle and we'll get into that And that's an interesting piece that you should understand your software development life cycle from beginning to end So from the beginning when it was conceived, Junior beautiful mind to when it dies and is rotting in the ground. So that's the, in some cases some of these apps. I mean I've got apps that were in our environment that are. the 1970s So they never die They just get a little aged. A CISSP. Training We're gonna talk about integrate security in the software development life cycle high burn integrate that and domain eight. And then the CISSP exam questions are obviously around development security and S D L C. All right Let's get get into it…Yeah So this is CIS S P cybersecurity integration This is the InfoSec Institute reference and I that's the who we're going to be calling up today from their website. And they're going to talk we talk about eight.one software development life cycle This is if you are, have the CISSP. The ISC squared, document that focuses on the different sub chapters around the ISC This is eight.one that's called out in that document. this is software development life cycle. Okay As I talked about in the intro applications are becoming more and more complex and therefore we're seeing these eggs that are tied together Now in the past you would have, you had just an app that let's just I say the past that's so distant past. Where it was. a year just your app store was set up with iTunes or with Google play And you had that was your app, or you had you'd build some sort of application that had a offering a ser saw a software as a service where you'd log into a web portal and you would have access to it that way. Now what ends up happening is as these applications are becoming more complex because you have edge computing that's dealing with Amazon AWS. You have your apps that you put on your phone and your phone. These things are extremely powerful So therefore that is able to come do massive computations So as technology continues to grow and get faster and faster these applications are growing in size and complexity. as well And so security needs to be a key factor in when you're successful implementation. of your application now whether this is an intentional or unintentional, it really doesn't matter The fact of it is you got to do it and you really need to look at how you keep software embedded within your environment. Now software and hardware control are extremely important And so if you're to put any sort of app out there at all, you need to have these controls in place. Now as you're dealing with Sophos. Some development control system development controls that are needed for the CISSP exam. There's some key things you need to keep in mind. Now system development steps need for creating modifying our maximizing information system So you need to have steps in place. That are going to be used to help when you're dealing with creating modifying or maximizing your information system That's a key term that you're going to run into. On the CISSP. And you need to have a formal activities set up for development so that you're heavy Like in case of myself I have a development team. They worked for me. They work out of India. And they do a great job and they do an awesome job and they have a ability to do development. And they're in the process of building out an entire suite of things that they need to do from their initial development products to CIC D to automated testing So on and so forth all that needs to be put in place. Well when you're dealing with that you also need to have some level of security built into it as well. and you need to create development standards around this coding and we've run into this with third parties. So if I have a third party that helps me and they provide some sort of coding than what is the standard by which they're developing their coats. so that's an important piece of this is that what are the aspects from the development standards? How can they do this? Now it could be as simple as a checklist They could be. My naming convention is this, we have we do have, we do fuzz testing on the application when it's done. we have you know all these little steps can be built into their process and they just go through it step by step. now I have noticed the challenges that go into this because the developers are they get paid They're incentivized to develop quickly and to develop, with good code but develop quickly And so therefore, Sometimes we don't want to take the time to do the initial steps to run it through a scanning engine, to make sure that it does that it works So those are those are conditions that you need to help in talk to your people about and ensure that they're connected with it. And then oh wasps Sam core model Now OSP is an organization that's on a that provides development for web applications. And it's basically a web applications And what are the aspects around securing those web applications? So you can go to old wasp and check it out online They have a whole laundry list of things you can use specifically for ensuring that your product is properly secured your application. I mean they have all kits from scanners to best practices I mean it's a really good place If you are a application developer and you're looking to incorporate security within your environment. they have a software assurance model That's the Sam the software assurance maturity model. And it's basically an open framework and we like to talk about frameworks but…realistically it's a guide or a checklist little checklist is a little bit too tight but it's more of a guide to formulate a strategy around applications and events evaluates the organization's existing security practices while puts in well-defined iterations for their software. they did demonstrates concrete improvements and it measures the security. activity So did the bottom line is it breaks it down for you? To be able to put security into your right now your current process. So it's just a good framework and a good checklist to go by. the highly recommend checking out Oh Wass but they have a great product out there and you will be. It will be called upon it on the CISSP. Now they may not call it the old hospice. Specifically, but they're 20 best practices that they have are we'll be we'll be called out specifically within the CIS. Those prac those best practices coding practices You you may see that…Now their top 10 project proactive controls of this is of 2016 first one is verify the security early on often obviously right But you need to stay on top of it. but rather than having something go into production and then have to do scans for it. parametize queries and co data validate all inputs That's a huge one there where you have inputs that are going in for a form field. And you validate that that yeah this I want a date of birth to go in here and I don't want Java code to be put into your I want just date of birth. That needs to be a. Input validation step that needs to be. implement identity and authentication controls huge, implement appropriate access controls protect the data again Now if you're dealing with applications that are just basic wonky data. That may not be such an important step However if you're dealing with any sort of personal data or data for your company that's considered confidential. and if you're building an app that is for somebody else you need to consider that, would that data be, be possibly considered confidential, then you need to look at protecting the data. you need to implement logging and intrusion detection. this is when we had last week from talking about logging. Lever security frameworks and libraries and then air and exception handling. So those top 10 if you did those that would do is dramatically reduce the risk to your sites. and what would end up happening is is you'd put you in a much better position as it relates to your site being affected. Bye. And it hackers are the like, Now as you're dealing with the SDLC there are some key aspects to keep in mind. one is planet our planning and requirement gathering You need to understand when you're dealing with your device. what are the requirements around it? Also architecture and design How do you designing your application and your software out there What is the purpose behind it? And then how do you make sure that it's maintained be updated? How do you update it How is that Is that built into the overall development strategy? test planning How do you test strategy over development code So how do you build that out till you're going to test to ensure that it does not like your input validations What will you put in there to ensure that the wrong input validations don't get put in and they could run potentially run code on your server? Coding and implementation ensuring code is complete by dividing into various modules. Testing and deployment, and that would be product development based on requirements. And then your release and maintenance your final product release and its maintenance and then maintaining that product. but again you have to begin this from the beginning of when they have the light of the application or the software is born to when it dies or it guess what It may not die unless you kill it. Especially we're dealing with software as a service you can kill these things but if you go out individual programs that are going out. That kind of stuff. it stays around forever So just consider that whatever you make. What is the way you're going to be able to update it And do you want to deal with that headache for a long period of time? Now One thing also about the CIS CIS. they talk about SDLC models that are covered in the CISSP. Now the most common are there there's various comments that are old or various models that are open and I'm going to go over some of these right now But, the main one that I deal with is a. scrum and you'll see that model here in just a little bit. I should say agile and that's crumbs a method of doing it It's actually, because scrum is like with a rugby, but no it's agile the agile method And we'll get into that just here in a second. A waterfall model This is the most common model And it's typically been used by many in the past And this basically basically comes down to as you finish one phase and then you go on to the next, but there's not much room for making changes to the waterfall model You have to wait until the whole process is done. Before you can go Meg, go back and make changes So if you notice that there's changes. While you're in the middle of the of the sprint with the waterfall model There's very little leeway to go back and make changes to it And you have to basically come back around after the whole thing is done. the V-shaped model was just very key verification and validation model and it's very similar to the waterfall but each phase has a testing phase. So the good piece of that is you don't wait till the end to find that you have issues. You each phase we'll give you some sort of testing and then you can make you put that in the backlog and then make iterations to that. But it is still though the overall project If you have like five sprints for this one project. you may get all the way through the project and then realize okay now I get you to go back and fix those changes. the iterative model which has repletion and improvement And basically that comes back in it replete rev repeats it. And then it improves it and it takes care of those things It's set of requirements that are tested and implemented. And you basically are You're iterating you're going back and forth back and forth And the new various versions are based on new and inner. versions of the software. So as draft software gets updated. A new iteration as a crooner occurred, then they come back and make changes and it just keeps going on that process. it's a very it gets you a very viable product early So if you're dealing with the VIP which is your VA viable product, that's a very good point It gets you there in a very quick period of time but it may take a lots of resources to do that because there's a lot of things that are going on especially if you're having to iterate it over and over again. And again these models are designed not to be One is the only one you do. the they're designed to depending upon your situation which model would you use The waterfall waterfall model. Oh waterfall the V-shape model, or the inner of model. Now we have the spiral model Now this works in an iterative model basically starts by continually repeating it over and over and over again, but it kind of goes out It allows for improvements on each round So it just you repeat phases, the four phases over and over and over And so you just keep going in a circle. the big bang model typically Good for small prod. a little work being done on planning, and most of the roads sources are for development And with that comes into as you bang you're done you just hit it hard Everybody jumps in all hands on deck and that's the big bang model. but if you're dealing with a small project that is very tiny in nature and that you can do quickly. that would be a really good model to use. The agile model Again this is one of the I use customer interaction and feedback So you're basically reaching out to the product owners getting feedback from them on how the process is going You have a backlog, sprints are usually in two week cycles. And what ends up happening is you'll, you'll go through the backlog you prioritize what you're going to do You do that product. And then at the end of it you the next sprint. anything that is considered a bug that doesn't critical gets thrown back in the backlog and then it gets reprioritized prioritize in the next sprint. it's basically you test it at each iteration. And so there is testing it's put into a testing your production, our staging and production. And so that process is done through the agile model Can it depends on which one works best for you and your organization. So in the past you would test after completion strategy for security And they would typically do this at the end of everything. If and I say that even if the case has many times, they wouldn't even test. but it does leave you vulnerable especially if you're waiting to the end that things have been in production. incorporating security at the beginning does help. Create more secure applications and it reduces your overall risk. Ah, From someone getting access to you And especially during the time when you maybe if you find a mistake, But you know what you fixed. Eight of the 10 but you found two of them that are vulnerable. Well that's good That's I mean at least there's only two versus if you don't add security from the beginning, you now have 10 plus and that causes a lot of issues. you incorporate code review and pen testing and your architecture analysis and there's different SDLC models available Microsoft has a development model. M S S D L and then NIST also talks about it with 800 dash 64 which is a national national national Institute of tech. And this 800 dash 64 does provide security considerations into system development lifecycle. Now there's also another model it's called class which is a comprehensive lightweight application security process class. and this says a set of processes mapped to job roles and allows for early security in stages. So again there's different SDLC models that you have to look at And when it comes to the CISSP they're going to focus on what are some models that are available. And I say when I say that it's going to, it's one of the questions that you could run into doesn't mean that this specific question is on the task No, not saying that at all, but it is a Microsoft development life cycle One question you could potentially see is when considering SDLC models that are available to you. What's one of the following is a model, the model T by Ford, the model. Vega from the car, the model XYZ or the Microsoft security development life cycle model. Or which which a government organization. you with this and that's the NIST 800 dash 64. So those are the questions that you could see on the CISSP exam…Okay That's all I had for the CISSP integration. And now we're going to roll into the CIS is P training eight.one Understand and integrate security in software development life cycle That's the plan We're gonna talk about it in this next objective, As part of the site reduce ever his podcast And there's going to be your CISSP training's going to be available to you. all of the videos that I've created over the time around CISSP are going to be there. The CIS P training manual that's are videos that are focused on the ISA. squared. Exam that are there There's about 129 different, videos that you can watch They'll take you through zero all the way to hero. And the cool part about it is at the end of the day when it's all said and done, it will set you up substantially for to pass the CISSP exam. because it it just really will, you have the knowledge that you get from those videos what you've done on your own. And if you want to go self study for the test you are going to have a subset substantial chance of passing the test. I mean it you'll pass it the first time And that's the ultimate goal is that we want you to help you pass it. The first time. All right so let's roll right into the training. Okay So when we're looking at security again for software environments now this is to all this information I'm providing you is considered out of the ISC square training manuals that have been provided. So what you saw with the original CISSP integration is from InfoSec Institute This is actually out of. My knowledge and working with the also the ISS ISC squared tra official training manual for 2018. Now when you're talking with key aspects you need to avoid developer. even to prevent developers in a work environment from creating an environment that is bad for software. you also need to have the ability to tap apply technical controls where appropriate in your software environment. And it's also important to understand that what could happen if your software development area is compromised. What would somebody get if they got into your code repository? what if they got into your your code and development environment? So what are some key aspects to keep in mind in there? Especially if you're developing apps for your company what kind of credentials could they potentially steal? Did utilize and leverage against you development security considerations You need to have a separate business development functions And this would come into the place where you have email slash document management in a firm should be separate from development. They need to be in separate environments. Not necessarily need to be in separate, completely separate environments but they needed not be work. Your your daily work stuff and your development stuff should be separate. you need to utilize active directory groups and or virtual must. As you're looking at creating, your security environment So those are important things again that separates from the business environment the business network. considered development environment has been compromised So if you look at it from a standpoint of a business are should say most, develop our most networks. You need to consider as you're building out security And as you're looking at what's available to you. The fact that your development environment might be compromised. And that means you just separate your admin and user accounts They can not have the same ability to work on the same things. And you didn't incorporate multifactor as it relates to dealing with security for your environment. it is with your the pin you have like say you go on and you log in you have to enter any multi-factor code. That's on your phone The second token that allows you in, there also would request like multiperson review a good thing is to have someone within your organization review your code before it gets shipped to production. That allows to look for any sort of bugs that may be there. Or something else that may have affected it. also look at trust but verify you need to trust your individuals, but not necessarily their accounts. and that's another thing to consider is that as you are. Dealing with these accounts. Are people, your people are working for you at you need to trust them but their individual network accounts could be compromised and they wouldn't even know it. So it's important that you do trust your people but not there. Your individual accounts. You need to incorporate logging and monitoring which we talked about last week and the importance of doing that. security actions You need to reduce your attack surface And by doing that is that if you have something in production don't have a lot of spurious pages that are sitting out there available for people to go and attack, keep it clean keep it crisp, and you need to protect your assets that your credentials to get into your property It's imperative that you do that secret keys are important as well. And then you also need to understand from an incident response standpoint what is the impact of a compromise and ensure that those controls are in place to limit slash manage the Compromise If it does occur. keep production development environment separate and then ensure again when logging and monitoring isn't is enabled and being monitored. The problem is is turning on logging and monitoring is great but if you don't do anything with it, So much. So it's imperative that you do things like that…Now you're dealing with configuration management as an aspect of secure coding you need to impact the analysis of your change. and you need to request change It needs to be done through the sprint cycle It doesn't mean you go in and just make changes. You should have a sprint cycle set up, whether you're using one of those different waterfall methods and you need to go ahead and put that change in. You also need to have a formal approval process to make that change and put that in the place highly recommended that people are involved in conversations on the phone. And if you have an automated change request process, there needs to be some way to verify that So that if somebody got in a hacker and said Hey add this level of code into your environment please. That would be a bad thing. also approve and reject changes You need to have a formal approach process on how to deal with that. And then ways to test the change, that is in your environment basically a non-production location that you could do through like, you could have it set up on AWS or someplace like that that it has a pipeline where we actually go through and run automated testing. You have that place to check for change. Schedule a time to change the production again come back to when would you do this Have a plan organize orchestrated event, and then document the change Make annotations in the document control. Now you're dealing with versioning. You need to have some level of nomenclature around this You need to have a naming convention and this could come down to some level of late labeling you get your one dot oh your one.one your one dot two so on and so forth And you need to have documentation around your versioning and why you did it. the software configuration management is imperative as it deals with version controls. And the one thing I've learned is that documentation around versioning is definitely a it's an art and and how people do it And then the commenting that goes along with the versioning and labeling. that will cause issues as if you have ineffective version controls, it will cause outages and issues And because what it comes down to is people don't understand. Y you're going from one.one to one.one one one dollar.one one.one one. Yeah I just confused myself. See how easy it is that can happen to anybody. So the point of that is is versioning is important but you needed to have that defined in a written format somewhere. Now your code repositories these are impose very important that you take care of your code repositories. because the fact they keep everything there they act as a central location for developers, your GitHub or Bitbucket your source forge all of those act as a code repository. And so you need to understand the security around that Because again if a hacker gets into those, what's that going to get they're going to get all of your code Well if your code has proprietary information in it, that would be bad. That'll take you out of business Your competitor could get it. And now you're done. you also need to look at a single sign on or multifactor piece to this as well. Avoid the use of API keys in the code repository So the API key basically is set up so that. It will connect to something else and you. API key may have credit is acting as a credential. Well if you have these API keys that are sitting in your code repository, somebody could utilize the API connect into your environment and you wouldn't even know it. unless you have proper logging and monitoring enabled And so odds are high If you have API keys in your codes. You might not have logging and monitoring enabled And then therefore now they're in your environment just like in they're able to pass data in and out without anybody really even seeing it. you need to have security best practices Do avoid remove any sensitive data within the repository and control access by adding removing the, and adding removing process. You also need to have a security.md file which would have your disclosure policies security update policy configurations and gaps and possible enhancements Again that's a message file That's available to talk about security and what could be W what needs to be changed What has been changed? Well how can people disclose it and so forth? You need to rotate your SSH keys and your personal tokens. again those are good best practices Don't keep them the same It's important to move that stuff around. However we do know this people are human and people will if they default to the fact of it's hard to do it they will not do it So something to consider is that many software development companies are many people will not rotate the keys They just won't. And and so therefore you need to look at how do you implement that into your environment? Always consider security when you are developing anything…All right So that's all I have for the CISSP around the ISC square training manual 2018. Let's roll into the CIS. P exam questions. Okay this one's on usernames and passwords. Now considering a development security there are some key considerations you need to be aware of. And I said considering twice considering and considerations those considering. All right So there's some key things that you consider. W a separate business and development functions. Be considered development environment compromised. See trust but verify. D all the above. E none of the above. So when considering development security there are some key considerations you need to be aware of. Separate business development functions. Consider the development environment a compromised. Trust but verify or all the above or none of the above. Answer is B all the above They are all a crucial to thinking around development security. Again separate business environment. You consider your environment compromise you trust but verify you control your. You trust your people but at the same time as you you don't trust their credentials. Those are key things As it relates to username and password in the software development life cycle. Okay this one's on preventative access controls What are the various SDLC development models covered in the CISSP exam? Waterfall. V-shape. Iterative. Agile…spiral and big bang. That was a B. Is waterfall X shaped. Repetitive. Agile. spiral and big bang…See waterfall why shape? He has a lot of letters They're repetitive. Agile. Spiral and big bang. Or D none of the above. So which ones are involved in that are gonna be covered by the CISSP exam. And then now. Number is or the letter is a waterfall V-shaped iterative, agile spiral and the big kahuna bang. All right That's that question right there Again those are important things You need to know the models on the and what are some of the pros and the cons around each of those development models.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will covering questions from his CISSP Exam Questions at CISSPCyberTraining.com.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – CISSP Exam Changes (2018)
· CISSP Training – Cybercrime and Data Breaches
· CISSP Exam Question – SDLC Development Models
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Global Knowledge
https://www.globalknowledge.com/us-en/resources/resource-library/articles/everything-you-need-to-know-about-the-cissp-exam-changes/
NCSL
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
In this episode, Shon will talk about the following items that are included within Domain 8 - Software Development Security of the CISSP Exam:
CISSP / Cybersecurity Integration – Software Development Life Cycle
CISSP Training – Integrate Security in the Software Development Life Cycle (Domain 8)
CISSP Exam Question – Development Security / SDLC
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Infosec Industry
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/software-development-security/#gref
OWASP
file:///C:/Users/gerbersa/Downloads/SAMM_Core_V1-1-Final-1page.pdf
SYNK.IO
https://snyk.io/blog/ten-git-hub-security-best-practices
National Cyber Security Centre
Transcript:
…Hey all is Sean Gerber again with reduced cyber risk How are you all doing this Beautiful beautiful morning I hope things are going well in your part of the globe in this big shiny blue marble, things are going awesome in Wichita Kansas Yes The small little town of Wichita Kansas. it's going well I can not complain at all It's a beautiful summer day School's getting ready to get started and my kids are getting ready to go back to school which is an awesome thing Very very cool. It a one of those situations in your life when you have 50 if and when you have ever have children out there, kids are great most days other days, not so much And so when it comes to going back to school, most parents will just glee with be or be super happy with glee. Yeah that doesn't really good word there but anyway they're really super happy because of the fact that the kids are no longer at home And they're now focused on school. So yeah it's a it's a good thing. Well today we're going to be talking about software development And how old is this? around that? And you'll see many things that have occurred recently It was just a recent breach that hit with that. capital one here in the United States. And they said there was probably I don't know how many millions of people were affected by that And so therefore what ended up happening is is, there there was an insider threat issue Well the today we're not gonna talk about the insider We're going to talk more about the software development, but in the case of when you're creating apps or crew from a Your websites whether you're creating apps for the app store that go into the Google play or iTunes. All of that needs to have some level of software development security built into it. And so there are some key aspects we're going to go into, as it relates to doing that. Along with that is going to be the main things that you're going to have to know for the CISSP exam as you know reduce cyber risk My ultimate. Plan is is to be able to give you that CISSP training You need to pass the CIS S. The first time again we want go into that If you want to pass this I know this test is a bugger din They're done that We're going to have some next upcoming episodes We're gonna talk a little more about the exam. But bottom line is is this test is a bugger and I failed it The first time I studied my butt off for that test I studied basically three months just self study just to go put, pass the test because at the time there there were bootcamps but I didn't have the funds to be able to go pay for a bootcamp. And so I've studied it. And it was actually good that I studied just because of the fact that, it it helped me get a good knowledge of what I deal with on a daily basis. But the cool part about knowing the CISSP and passing the exam the first time is the fact that you will utilize those skills on a daily basis as a CSO, for a large multinational So those are things that consider is that the good thing is just. Just by taking the test is the first step And the examiner is the first step in the whole road to make becoming a cyber security professional. And so therefore it's it's imperative that you get these foundations and you know, fundamentals. And studying too much. Of test questions is very important you know just to understand what are they going to ask for and how they're going to ask. But those test questions are designed mainly to help you as you go through them. Understand the questions and how would they answer How would they. Question you or how would they provide the information for you so that the answers you provide are the right ones. But again Canada has already addressed but the cool part about studying for the CISSP is the fact that you used to learn a lot of good stuff. Well today we're going to learn about software development and the security that goes into that. So when I talk to my SSP cybersecurity integration This is the area that I grabbed some information from the internet, like an article or so forth. And this one is software development life cycle and we'll get into that And that's an interesting piece that you should understand your software development life cycle from beginning to end So from the beginning when it was conceived, Junior beautiful mind to when it dies and is rotting in the ground. So that's the, in some cases some of these apps. I mean I've got apps that were in our environment that are. the 1970s So they never die They just get a little aged. A CISSP. Training We're gonna talk about integrate security in the software development life cycle high burn integrate that and domain eight. And then the CISSP exam questions are obviously around development security and S D L C. All right Let's get get into it…Yeah So this is CIS S P cybersecurity integration This is the InfoSec Institute reference and I that's the who we're going to be calling up today from their website. And they're going to talk we talk about eight.one software development life cycle This is if you are, have the CISSP. The ISC squared, document that focuses on the different sub chapters around the ISC This is eight.one that's called out in that document. this is software development life cycle. Okay As I talked about in the intro applications are becoming more and more complex and therefore we're seeing these eggs that are tied together Now in the past you would have, you had just an app that let's just I say the past that's so distant past. Where it was. a year just your app store was set up with iTunes or with Google play And you had that was your app, or you had you'd build some sort of application that had a offering a ser saw a software as a service where you'd log into a web portal and you would have access to it that way. Now what ends up happening is as these applications are becoming more complex because you have edge computing that's dealing with Amazon AWS. You have your apps that you put on your phone and your phone. These things are extremely powerful So therefore that is able to come do massive computations So as technology continues to grow and get faster and faster these applications are growing in size and complexity. as well And so security needs to be a key factor in when you're successful implementation. of your application now whether this is an intentional or unintentional, it really doesn't matter The fact of it is you got to do it and you really need to look at how you keep software embedded within your environment. Now software and hardware control are extremely important And so if you're to put any sort of app out there at all, you need to have these controls in place. Now as you're dealing with Sophos. Some development control system development controls that are needed for the CISSP exam. There's some key things you need to keep in mind. Now system development steps need for creating modifying our maximizing information system So you need to have steps in place. That are going to be used to help when you're dealing with creating modifying or maximizing your information system That's a key term that you're going to run into. On the CISSP. And you need to have a formal activities set up for development so that you're heavy Like in case of myself I have a development team. They worked for me. They work out of India. And they do a great job and they do an awesome job and they have a ability to do development. And they're in the process of building out an entire suite of things that they need to do from their initial development products to CIC D to automated testing So on and so forth all that needs to be put in place. Well when you're dealing with that you also need to have some level of security built into it as well. and you need to create development standards around this coding and we've run into this with third parties. So if I have a third party that helps me and they provide some sort of coding than what is the standard by which they're developing their coats. so that's an important piece of this is that what are the aspects from the development standards? How can they do this? Now it could be as simple as a checklist They could be. My naming convention is this, we have we do have, we do fuzz testing on the application when it's done. we have you know all these little steps can be built into their process and they just go through it step by step. now I have noticed the challenges that go into this because the developers are they get paid They're incentivized to develop quickly and to develop, with good code but develop quickly And so therefore, Sometimes we don't want to take the time to do the initial steps to run it through a scanning engine, to make sure that it does that it works So those are those are conditions that you need to help in talk to your people about and ensure that they're connected with it. And then oh wasps Sam core model Now OSP is an organization that's on a that provides development for web applications. And it's basically a web applications And what are the aspects around securing those web applications? So you can go to old wasp and check it out online They have a whole laundry list of things you can use specifically for ensuring that your product is properly secured your application. I mean they have all kits from scanners to best practices I mean it's a really good place If you are a application developer and you're looking to incorporate security within your environment. they have a software assurance model That's the Sam the software assurance maturity model. And it's basically an open framework and we like to talk about frameworks but…realistically it's a guide or a checklist little checklist is a little bit too tight but it's more of a guide to formulate a strategy around applications and events evaluates the organization's existing security practices while puts in well-defined iterations for their software. they did demonstrates concrete improvements and it measures the security. activity So did the bottom line is it breaks it down for you? To be able to put security into your right now your current process. So it's just a good framework and a good checklist to go by. the highly recommend checking out Oh Wass but they have a great product out there and you will be. It will be called upon it on the CISSP. Now they may not call it the old hospice. Specifically, but they're 20 best practices that they have are we'll be we'll be called out specifically within the CIS. Those prac those best practices coding practices You you may see that…Now their top 10 project proactive controls of this is of 2016 first one is verify the security early on often obviously right But you need to stay on top of it. but rather than having something go into production and then have to do scans for it. parametize queries and co data validate all inputs That's a huge one there where you have inputs that are going in for a form field. And you validate that that yeah this I want a date of birth to go in here and I don't want Java code to be put into your I want just date of birth. That needs to be a. Input validation step that needs to be. implement identity and authentication controls huge, implement appropriate access controls protect the data again Now if you're dealing with applications that are just basic wonky data. That may not be such an important step However if you're dealing with any sort of personal data or data for your company that's considered confidential. and if you're building an app that is for somebody else you need to consider that, would that data be, be possibly considered confidential, then you need to look at protecting the data. you need to implement logging and intrusion detection. this is when we had last week from talking about logging. Lever security frameworks and libraries and then air and exception handling. So those top 10 if you did those that would do is dramatically reduce the risk to your sites. and what would end up happening is is you'd put you in a much better position as it relates to your site being affected. Bye. And it hackers are the like, Now as you're dealing with the SDLC there are some key aspects to keep in mind. one is planet our planning and requirement gathering You need to understand when you're dealing with your device. what are the requirements around it? Also architecture and design How do you designing your application and your software out there What is the purpose behind it? And then how do you make sure that it's maintained be updated? How do you update it How is that Is that built into the overall development strategy? test planning How do you test strategy over development code So how do you build that out till you're going to test to ensure that it does not like your input validations What will you put in there to ensure that the wrong input validations don't get put in and they could run potentially run code on your server? Coding and implementation ensuring code is complete by dividing into various modules. Testing and deployment, and that would be product development based on requirements. And then your release and maintenance your final product release and its maintenance and then maintaining that product. but again you have to begin this from the beginning of when they have the light of the application or the software is born to when it dies or it guess what It may not die unless you kill it. Especially we're dealing with software as a service you can kill these things but if you go out individual programs that are going out. That kind of stuff. it stays around forever So just consider that whatever you make. What is the way you're going to be able to update it And do you want to deal with that headache for a long period of time? Now One thing also about the CIS CIS. they talk about SDLC models that are covered in the CISSP. Now the most common are there there's various comments that are old or various models that are open and I'm going to go over some of these right now But, the main one that I deal with is a. scrum and you'll see that model here in just a little bit. I should say agile and that's crumbs a method of doing it It's actually, because scrum is like with a rugby, but no it's agile the agile method And we'll get into that just here in a second. A waterfall model This is the most common model And it's typically been used by many in the past And this basically basically comes down to as you finish one phase and then you go on to the next, but there's not much room for making changes to the waterfall model You have to wait until the whole process is done. Before you can go Meg, go back and make changes So if you notice that there's changes. While you're in the middle of the of the sprint with the waterfall model There's very little leeway to go back and make changes to it And you have to basically come back around after the whole thing is done. the V-shaped model was just very key verification and validation model and it's very similar to the waterfall but each phase has a testing phase. So the good piece of that is you don't wait till the end to find that you have issues. You each phase we'll give you some sort of testing and then you can make you put that in the backlog and then make iterations to that. But it is still though the overall project If you have like five sprints for this one project. you may get all the way through the project and then realize okay now I get you to go back and fix those changes. the iterative model which has repletion and improvement And basically that comes back in it replete rev repeats it. And then it improves it and it takes care of those things It's set of requirements that are tested and implemented. And you basically are You're iterating you're going back and forth back and forth And the new various versions are based on new and inner. versions of the software. So as draft software gets updated. A new iteration as a crooner occurred, then they come back and make changes and it just keeps going on that process. it's a very it gets you a very viable product early So if you're dealing with the VIP which is your VA viable product, that's a very good point It gets you there in a very quick period of time but it may take a lots of resources to do that because there's a lot of things that are going on especially if you're having to iterate it over and over again. And again these models are designed not to be One is the only one you do. the they're designed to depending upon your situation which model would you use The waterfall waterfall model. Oh waterfall the V-shape model, or the inner of model. Now we have the spiral model Now this works in an iterative model basically starts by continually repeating it over and over and over again, but it kind of goes out It allows for improvements on each round So it just you repeat phases, the four phases over and over and over And so you just keep going in a circle. the big bang model typically Good for small prod. a little work being done on planning, and most of the roads sources are for development And with that comes into as you bang you're done you just hit it hard Everybody jumps in all hands on deck and that's the big bang model. but if you're dealing with a small project that is very tiny in nature and that you can do quickly. that would be a really good model to use. The agile model Again this is one of the I use customer interaction and feedback So you're basically reaching out to the product owners getting feedback from them on how the process is going You have a backlog, sprints are usually in two week cycles. And what ends up happening is you'll, you'll go through the backlog you prioritize what you're going to do You do that product. And then at the end of it you the next sprint. anything that is considered a bug that doesn't critical gets thrown back in the backlog and then it gets reprioritized prioritize in the next sprint. it's basically you test it at each iteration. And so there is testing it's put into a testing your production, our staging and production. And so that process is done through the agile model Can it depends on which one works best for you and your organization. So in the past you would test after completion strategy for security And they would typically do this at the end of everything. If and I say that even if the case has many times, they wouldn't even test. but it does leave you vulnerable especially if you're waiting to the end that things have been in production. incorporating security at the beginning does help. Create more secure applications and it reduces your overall risk. Ah, From someone getting access to you And especially during the time when you maybe if you find a mistake, But you know what you fixed. Eight of the 10 but you found two of them that are vulnerable. Well that's good That's I mean at least there's only two versus if you don't add security from the beginning, you now have 10 plus and that causes a lot of issues. you incorporate code review and pen testing and your architecture analysis and there's different SDLC models available Microsoft has a development model. M S S D L and then NIST also talks about it with 800 dash 64 which is a national national national Institute of tech. And this 800 dash 64 does provide security considerations into system development lifecycle. Now there's also another model it's called class which is a comprehensive lightweight application security process class. and this says a set of processes mapped to job roles and allows for early security in stages. So again there's different SDLC models that you have to look at And when it comes to the CISSP they're going to focus on what are some models that are available. And I say when I say that it's going to, it's one of the questions that you could run into doesn't mean that this specific question is on the task No, not saying that at all, but it is a Microsoft development life cycle One question you could potentially see is when considering SDLC models that are available to you. What's one of the following is a model, the model T by Ford, the model. Vega from the car, the model XYZ or the Microsoft security development life cycle model. Or which which a government organization. you with this and that's the NIST 800 dash 64. So those are the questions that you could see on the CISSP exam…Okay That's all I had for the CISSP integration. And now we're going to roll into the CIS is P training eight.one Understand and integrate security in software development life cycle That's the plan We're gonna talk about it in this next objective, As part of the site reduce ever his podcast And there's going to be your CISSP training's going to be available to you. all of the videos that I've created over the time around CISSP are going to be there. The CIS P training manual that's are videos that are focused on the ISA. squared. Exam that are there There's about 129 different, videos that you can watch They'll take you through zero all the way to hero. And the cool part about it is at the end of the day when it's all said and done, it will set you up substantially for to pass the CISSP exam. because it it just really will, you have the knowledge that you get from those videos what you've done on your own. And if you want to go self study for the test you are going to have a subset substantial chance of passing the test. I mean it you'll pass it the first time And that's the ultimate goal is that we want you to help you pass it. The first time. All right so let's roll right into the training. Okay So when we're looking at security again for software environments now this is to all this information I'm providing you is considered out of the ISC square training manuals that have been provided. So what you saw with the original CISSP integration is from InfoSec Institute This is actually out of. My knowledge and working with the also the ISS ISC squared tra official training manual for 2018. Now when you're talking with key aspects you need to avoid developer. even to prevent developers in a work environment from creating an environment that is bad for software. you also need to have the ability to tap apply technical controls where appropriate in your software environment. And it's also important to understand that what could happen if your software development area is compromised. What would somebody get if they got into your code repository? what if they got into your your code and development environment? So what are some key aspects to keep in mind in there? Especially if you're developing apps for your company what kind of credentials could they potentially steal? Did utilize and leverage against you development security considerations You need to have a separate business development functions And this would come into the place where you have email slash document management in a firm should be separate from development. They need to be in separate environments. Not necessarily need to be in separate, completely separate environments but they needed not be work. Your your daily work stuff and your development stuff should be separate. you need to utilize active directory groups and or virtual must. As you're looking at creating, your security environment So those are important things again that separates from the business environment the business network. considered development environment has been compromised So if you look at it from a standpoint of a business are should say most, develop our most networks. You need to consider as you're building out security And as you're looking at what's available to you. The fact that your development environment might be compromised. And that means you just separate your admin and user accounts They can not have the same ability to work on the same things. And you didn't incorporate multifactor as it relates to dealing with security for your environment. it is with your the pin you have like say you go on and you log in you have to enter any multi-factor code. That's on your phone The second token that allows you in, there also would request like multiperson review a good thing is to have someone within your organization review your code before it gets shipped to production. That allows to look for any sort of bugs that may be there. Or something else that may have affected it. also look at trust but verify you need to trust your individuals, but not necessarily their accounts. and that's another thing to consider is that as you are. Dealing with these accounts. Are people, your people are working for you at you need to trust them but their individual network accounts could be compromised and they wouldn't even know it. So it's important that you do trust your people but not there. Your individual accounts. You need to incorporate logging and monitoring which we talked about last week and the importance of doing that. security actions You need to reduce your attack surface And by doing that is that if you have something in production don't have a lot of spurious pages that are sitting out there available for people to go and attack, keep it clean keep it crisp, and you need to protect your assets that your credentials to get into your property It's imperative that you do that secret keys are important as well. And then you also need to understand from an incident response standpoint what is the impact of a compromise and ensure that those controls are in place to limit slash manage the Compromise If it does occur. keep production development environment separate and then ensure again when logging and monitoring isn't is enabled and being monitored. The problem is is turning on logging and monitoring is great but if you don't do anything with it, So much. So it's imperative that you do things like that…Now you're dealing with configuration management as an aspect of secure coding you need to impact the analysis of your change. and you need to request change It needs to be done through the sprint cycle It doesn't mean you go in and just make changes. You should have a sprint cycle set up, whether you're using one of those different waterfall methods and you need to go ahead and put that change in. You also need to have a formal approval process to make that change and put that in the place highly recommended that people are involved in conversations on the phone. And if you have an automated change request process, there needs to be some way to verify that So that if somebody got in a hacker and said Hey add this level of code into your environment please. That would be a bad thing. also approve and reject changes You need to have a formal approach process on how to deal with that. And then ways to test the change, that is in your environment basically a non-production location that you could do through like, you could have it set up on AWS or someplace like that that it has a pipeline where we actually go through and run automated testing. You have that place to check for change. Schedule a time to change the production again come back to when would you do this Have a plan organize orchestrated event, and then document the change Make annotations in the document control. Now you're dealing with versioning. You need to have some level of nomenclature around this You need to have a naming convention and this could come down to some level of late labeling you get your one dot oh your one.one your one dot two so on and so forth And you need to have documentation around your versioning and why you did it. the software configuration management is imperative as it deals with version controls. And the one thing I've learned is that documentation around versioning is definitely a it's an art and and how people do it And then the commenting that goes along with the versioning and labeling. that will cause issues as if you have ineffective version controls, it will cause outages and issues And because what it comes down to is people don't understand. Y you're going from one.one to one.one one one dollar.one one.one one. Yeah I just confused myself. See how easy it is that can happen to anybody. So the point of that is is versioning is important but you needed to have that defined in a written format somewhere. Now your code repositories these are impose very important that you take care of your code repositories. because the fact they keep everything there they act as a central location for developers, your GitHub or Bitbucket your source forge all of those act as a code repository. And so you need to understand the security around that Because again if a hacker gets into those, what's that going to get they're going to get all of your code Well if your code has proprietary information in it, that would be bad. That'll take you out of business Your competitor could get it. And now you're done. you also need to look at a single sign on or multifactor piece to this as well. Avoid the use of API keys in the code repository So the API key basically is set up so that. It will connect to something else and you. API key may have credit is acting as a credential. Well if you have these API keys that are sitting in your code repository, somebody could utilize the API connect into your environment and you wouldn't even know it. unless you have proper logging and monitoring enabled And so odds are high If you have API keys in your codes. You might not have logging and monitoring enabled And then therefore now they're in your environment just like in they're able to pass data in and out without anybody really even seeing it. you need to have security best practices Do avoid remove any sensitive data within the repository and control access by adding removing the, and adding removing process. You also need to have a security.md file which would have your disclosure policies security update policy configurations and gaps and possible enhancements Again that's a message file That's available to talk about security and what could be W what needs to be changed What has been changed? Well how can people disclose it and so forth? You need to rotate your SSH keys and your personal tokens. again those are good best practices Don't keep them the same It's important to move that stuff around. However we do know this people are human and people will if they default to the fact of it's hard to do it they will not do it So something to consider is that many software development companies are many people will not rotate the keys They just won't. And and so therefore you need to look at how do you implement that into your environment? Always consider security when you are developing anything…All right So that's all I have for the CISSP around the ISC square training manual 2018. Let's roll into the CIS. P exam questions. Okay this one's on usernames and passwords. Now considering a development security there are some key considerations you need to be aware of. And I said considering twice considering and considerations those considering. All right So there's some key things that you consider. W a separate business and development functions. Be considered development environment compromised. See trust but verify. D all the above. E none of the above. So when considering development security there are some key considerations you need to be aware of. Separate business development functions. Consider the development environment a compromised. Trust but verify or all the above or none of the above. Answer is B all the above They are all a crucial to thinking around development security. Again separate business environment. You consider your environment compromise you trust but verify you control your. You trust your people but at the same time as you you don't trust their credentials. Those are key things As it relates to username and password in the software development life cycle. Okay this one's on preventative access controls What are the various SDLC development models covered in the CISSP exam? Waterfall. V-shape. Iterative. Agile…spiral and big bang. That was a B. Is waterfall X shaped. Repetitive. Agile. spiral and big bang…See waterfall why shape? He has a lot of letters They're repetitive. Agile. Spiral and big bang. Or D none of the above. So which ones are involved in that are gonna be covered by the CISSP exam. And then now. Number is or the letter is a waterfall V-shaped iterative, agile spiral and the big kahuna bang. All right That's that question right there Again those are important things You need to know the models on the and what are some of the pros and the cons around each of those development models.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Communications
· CISSP Training – Implement Secure Communication Channels
· CISSP Exam Question – Point to Point / OSI Layers
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
https://www.isc2.org/Training/Self-Study-Resources
Infosec Industry
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/security-operations/logging-and-monitoring/#gref
Transcript:
…Hey Alice Shon Gerber with reduced cyber risk How are you all doing this wonderful day It's been a beautiful day here in Kansas It's been like scorching hot though. About 100 degrees It was last week So yeah it's pretty pretty toasty outside but other than that it's a wonderful summer's day and I cannot complain at all. And just wanted to call and talk to you today about some great things we've got going on with reduced cyber risk. But in this episode we're going to be talking about domain seven security operations and this is going to be all part of the CISSP exam. And these are some key areas that we cover And this is domain seven. And I try to focus on a specific podcast to go over a specific domain and areas that you need to be concerned about as you're dealing with logging and monitor as you're dealing with the CISSP exam. So in the first part of the CIS piece, Cybersecurity integration. We're going to be talking about logging and monitoring overview. And as far as the CIS is P training specifically about logging and monitoring activities this is domain seven. And if you study the I I S C squared CISSP training manuals, you will know that that's where that falls into. And then the CISSP exam questions are going to be around logging and monitoring and data life cycle domain seven. All right As it relates to the CIS S P cybersecurity integration, we're going to be talking from a article I saw online from the InfoSec Institute, and this is objective seven dot three conduct logging and monitoring activities. The topic is logging and monitoring overview and really what it comes down to is we're going to get into what exactly our logs is The first thing we're going to kind of focus on. And typically people wonder what our log files. Well you know this is riveting stuff I hate to tell you It's just riveting What is the log file? A log files got dated. Oh my gosh Just, just turn the pages It's cannot compel. You cannot hold back the enthusiasm about a log file No it really they're quite boring and quite painful. so therefore we will talk about how you can ingest those log files but bottom line is there an event log something that occurs within an environment? And they are typically called with a computer name. They have creation deletion and records They have all of those pieces that are tied to an event log that may occur. Now most systems Now I will say most because in many older type systems or applications, They may not generate much for log files at all. In newer systems they do They. They generate a plethora of log files which at times can be a bit overwhelming. But log files are an integral part especially as in you're dealing with the CISSP exam and understanding this as a cybersecurity professional. Now there's different types of logs And this comes again from InfoSec Institute and you'll see this in your CISSP exam, but there's types of logs and these are authentication logs or. logs and system logs These are different types of logs that you will see. And they each have a different thing And authentication obviously is when you're logging into something and authenticate you audit log is basically looking at the system itself and finding out if there's an audit trail around those logs. And then your system fought logs are logs that are dealing with specifically with the system that's operating on it. Now there's some different use cases that you need to keep logs for And these these use cases would be regulations that negation or even application debugging. I mean there's many different as situations where you would want log files, but in the today's world especially as a litigious as it is see that's a big $10 word Yeah Litigious. I should I don't even know what that means Cause my third grade education won't let me go any further than that but it's a bad thing I assume being a litigation Litigious Yes. so these use cases around litigation regulations, you have to maintain logs for a period of time. And depending upon the company depending upon the regulations, you may have to keep some of these logs potentially indefinitely were you would then in turn be using products like AWS glacier or someplace like that to store them. That's a different podcast. But bottom line is is that you would have to keep these logs for a period of time and regulations litigations or debugging may, may want you to have some form of logs and be able to keep them for a period…Nausea some key considerations around the log files that you need to be aware of. They start off small and they're really EDBD they're not very big at first. But then you add one device and then another device and another device And next thing you know you got log files coming out of your ears They replicate like a rabbits. And so you go what am I going to do with all these Well, so in realistic realistically here it comes down to log files are only as good as if you even look at them If you don't look at them what's the point You don't need them. And they just take up space and they basically take up processing speed. However, if you were to get sued due to some thing that would be unfortunate such as a breach. and if you don't have log files and you, you. Purpose. did not collect log files. Yeah That's a bad thing for you So I would not recommend doing that. So therefore you need to start off and start off small, but the logs need to be it could be in a situation where they need to be forwarded and moved on. That's a possibility. they also the storage can become a serious challenge as it relates to keeping your log files. You don't know, these things build up and as they build up they store for a long period of time Now if you have to keep them for a long period, You now go from being oh gigabytes to terabytes to whatever it'd be on a terabyte a lot. but multiple terabytes. T to keep these logs Now these logs typically aren't they call a flat file So they're not very big. But as you get lots of systems reporting in they will grow substantially…Now deal life cycle of keeping These should also be considered. How long do you want to keep your logs for you want to keep them for 90 days six months one month one week two days. I don't know He had to decide. Now regulations may dictate what you should and shouldn't do around that. Place but at the end of the day you need to come. how long do you keep that data in your environment? Now as you're dealing with log management you must develop a solid monitoring strategy And this is where it comes into play where you have a, some sort of auto robot type thing a, a Splunk or a some sort of SIM which would be your. A security incident event management system that would, all these things would get dumped into and they would help monitor this. I also need to consider a human machine automation What do you want to give to the computer What do you want to have humans Look at. And you define that from a strategy standpoint what works best for you? You also need to determine what to log. Everything doesn't need to be logged You got to ask yourself do you really need to log it? Well in some cases a banking situation you may need a log almost everything, but another plate may. In other cases you probably don't need to And it's just additional waste is really what it comes down to. Now you need to start off small We talked about that but bill value within your organization there's some devices that you can monitor which would be your intrusion prevention your intrusion detection switches. All the things we're routing goes through some level of traffic Now again comes down to your environment. Comes down to your occupation. Whether how much you should record or should not record with logs. But again you want to look for anomalies That is the key behind all of this. Now when you do on a log review you needed to find criticality of the systems to be monitored I E intellectual property systems they would be the ones the first ones to look at. They have financial data personal data Those systems you'd want to keep logs up. Now do you want to keep logs of the raspberry PI That is just checking? I don't know The people entering and exiting a building. Probably not. it's just one piece of information you probably don't need, but you needed to find the criticality of these systems that you want to be monitored. In to determine a process to handle issues incident response process Do you have one. Is there an automated situations or events that you can click off and have this thing just go for you in the lieu that there is an issue. And you may need a tiered approach when you're handling these events you know how do you want to handle the. A situation where. You've been breached Well that would be a tear. Oh my gosh Kind of tier versus a yeah this guy's computer It doesn't work real well And it's got ransomware on it and it's really not worth anything Well that's like oh yawn not a big deal. So you have to determine which one works best for you and your organization…Now you also need to consider frequency We talked about this as well Do you want 90 days 60 days A hundred days. A hundred? Yeah It could be exactly one. One day. I was at one That's a good one. Now you gotta decide what frequency how often do you want to collect these You want to collect them daily hourly monthly. Minute by minute minutely That's not a real word but it works for me. so you can determine how frequently how frequently you want to collect them. Where do you want to store these Do you have a forward or that fours on your logs Do you have a. CIS log server that basically aggregates collects all your logs. what is the bandwidth of the connection for your logs You may have a situation where that you have bandwidth constrained and therefore these logs just take up extra space that you do not want them to do. Are these systems critical Non-critical. are they scripted or a manual collection What do you how did you work That is it set up that they automatically post at a certain period of time to a certain location? depending upon how you have things set up you can have API APIs set up so that it would have one application would talk to another application and just pitch the logs to a certain location. I said location three times That's pretty cool. You get actually 10 points extra for saying the same word three times in one sentence. Yeah No that's not really a good English so yeah Don't don't listen to what I just said. you need to understand your environment as well Operating systems applications tools external access, third party connections All of those things need to be considered what are going to Keep logs on now as a personal example I've got…where I've got third parties coming into our environment. I want to watch those logs now do I want to watch the ticket meter that allows people in and out of an environment You know like the gate No I really don't care about those but now third party guys and gals coming in Yeah I kinda want to watch those You never know what's gonna be coming in through a third party connection. So you just got to make sure that you keep all of that. Now as you're dealing with log analysis, you need to consider again And we talked about the data life of it and there's various phases of your data life cycle. Here's your collection, your examination your storage your archiving and your deletion. Those are basically five aspects The five phases of cycle of generation. yeah basically those are the things you need to consider yourself as you're dealing with data life cycle collection examination storage, archiving, and deletion. Now there's various quiet requirements that you need to consider in each of these phases Are you dealing with GDPR which is your general data privacy regulation Are you dealing with HIPAA, which is your health insurance portability accountability act I got to say that 10 times socks like the red Sox Yeah That that. Well I'm going to now I can't Sarbanes Oxley That's basically what that comes down to But do you have requirements that focus you in this space that requires you to have a certain amount of collection How much do you examine it Where do you store it Is it encrypted? do you archive it And then what is the process for deleting all these things you may have to define depending upon the environment. or the industry that you are in…now policy decisions will also need to be made to address each of these So it's important that you have it set up, that you have a policy for collection examination storage archiving and deletion. Say that a lot. So. What I'm saying is I'm trying to hint at the fact that she probably didn't know those that that's probably good to know. Probably just good to know. but bottom line is is that you need to have policies that focus on those So because it will help you make your environment much more secure…All right So that's all I have for the CISSP integration was rolled into the training. Now as we're dealing with seven dot three conduct logging and monitoring activities All right moving on All right Sorry to digress. All right so we're getting into seven dot. Three conduct logging and monitoring activities There are some key aspects around logging and monitoring You need to keep them. So we talked about logs right? Well there's security logs there System logs There's application. all these have a log. Now I kind of hint back to the fact that if you have older applications, They sometimes don't have much for logs. and some of them may not have any logs So that's something to consider as you're looking to dump all of this stuff into your security operations center or the tool that tool does. That they may be using. Almost everything though does have some form of log. Again some can be useful. Some not so useful. But the key around this though is you do need to consider protecting the log data that you collect one for a couple of reasons Well if you've got a situation coming up where someone gets hacked, first thing they do is they go to the logs. Well if the logs have been manipulated then people will not trust the logs So then therefore they ended up throwing out that as evidence within, or they will then turn around and use it as a very. More circumstantial evidence that isn't really worth a whole lot. Because they maybe they feel it they're tainted. so the point of it is is you need to protect these logs from attacker so that they don't get access to them So they don't manipulate them. that's a key point around that. You also need to look at where do you want store these things and what kind of repository which we alluded to earlier is that do you have a security incident event management system a SIM. could be CyberArk, not CyberArk dossiers. Now it could be Splunk It could be ArcSight could be other situations You could have a home grown system that you use, but anything that basically manages and collates events that occur within your environment. You also probably need a forwarder and this forwarder will then collect logs from certain locations and forward them on to another location or basically four of them out of the SIM. at this will depend a lot on the size and complexity of your organization. keeping logs We talked about that 30, 60, 90 days is the typical amount that people usually do I've seen it as high as six months. I have seen and heard of people that keep it indefinitely especially as it relates to legal hold. And we've talked about that in a different part of the CISSP but bottom line is is if yours litigation going on in your company and you may have court communications that involve that company that's under litigation you may be required to hold onto this information under a. hold status. Which basically means you can't get rid of stuff you can't delete it. And if you did delete it that would be really really really bad So don't delete it. but bottom line is you may have to keep your logs for an indefinite period of time. Now I do note this destroy them when not being used Okay. Bottom line Don't be a hoarder Just don't do it It's not fun. It's expensive. And you lose a lot of friends over it So just just don't do it. Yeah Yeah You also kind of stink if you're a hoarder. So, I mean I don't know I don't know a lot of hoarders, but I would think so because maybe you hoard so much stuff that you don't take a shower cause you can't take a shower because it's in your shower. Yeah. Okay Moving on, but destroy it when it's not used. Okay Various risks for keeping logs too long There are various risks If you keep it too long, you now open yourself up to litigation say in the event through our legal hold and you kept all the records that go back 18 zillion years. And they are now set up and say Hey by the way do you have those logs Oh yes we do. We have five of them go back 18 gazillion years Oh, great Well we can I could probably figure out something you did wrong So therefore you will go to jail Have a nice day. Don't pass Go just go to straight to jail. it's hell no don't keep those for a long period of time Just, just a bad idea. As a deal with security information and event management to you need to consider the automated or configurable product SIM they are basically have them set up as rule sets they're established to alert or flag on suspicious activity. So if you got lots of suspicious activity going on then you probably don't be probably want to SIM. To to verify and correlate it. Colet court correlated Yeah Okay Third grade education kicking in a range in price depending on bells and whistles you put they can be very very expensive or they can be very very. Not quite as expensive They're still expensive Don't don't anybody fool you. There are a lot of money, but you can get by with some that are small especially if you're a small business that there you can get by with something a little bit less expensive. A typical bullet deployment around these is it there's usually an agent or their agent lists Okay It gives you both ends of the spectrum. The age. ones will take logs directly from the system and they'll ingest those or send those directly to the SIM. And agent one we'll use a software to collect and send the logs to the SIM They may collect them into a certain point and then they'll ship them off to the SIM. agents are deployed to systems being monitored and that's where they get they get shipped off to and they can provide additional functionality with the device So if you basically have a an agent on this system it's allowing you to have insight into that device Well it can give you additional functionality. around that again example would be CrowdStrike CrowdStrike has a great agent works on the systems and it can provide multiple levels of protection as well as log sources as needed. Now Sims are usually quite configurable depending upon the one that you use they are they can be very easy to use pull out of the box and mash a big button and they work, or they may take a lot of configurations to make them really just hum. Now they all will need some level of that If you really want them to hit on all eight cylinders, you're going to need someone to help config. them However, some are better than others that just roll them out of the box and just stick them in your environment and let them run…Now again it may require a very special skillset to do this I warn you They are not cheap. These special skillset people ArcSight Splunk et cetera are very expensive. So if you're going to put that in your environment and you're saying for your CISSP it's one of the questions you will run into, but I'll tell you right now that if you're gonna put that in your environment you better come with a lot of zeros and be prepared to find the right people in the talent Now I will say with India there's a lot of great opportunities that you can outsource that capability, but they're they're not cheap Just. Just just telling you the ain't cheap, expensive. correlation engines and machine learning was also be incorporated into the Sims and a lot of the aspects of of learning that's coming down that path. And you can also incorporate these into other device management systems such as S S C C M It's a Microsoft product I used to manage devices. Now as you deal with continuous monitoring monitoring. You need to con The purpose around continuous monitoring. to provide an audit trail. it's also what we call investigation fodder and I didn't really know what fodder was and I probably just totally butchering this But fodder is the old peasants from the old days that would be marched along to go in front of the. The British red coats And you would basically just go walking to your death. I think that's what they called Fodder cannon fodder You just kind of in the way and you get blown up. That's it So investigation fodder stuff. That's probably totally wrong but Hey it sounds good. without the logs you basically basically have nothing other than the incident So you got to have a logs I mean, You can get some glean some information if you've had an incident but in many cases it's just days old and the logs will give you that trail that paper trail. Virtual paper trail to be able to help you with in the event There's an issue. as a key piece though you need to have a network time protocol capability and TP. And these are synchronized and this basically tells you what's the time that it occurred. If you don't have an NTP server, there's telling you it's sinking your time within your environment Typically you can do this just through the internet but. if you have to a large enterprise you may need that in your enterprise to make everything sync. You got to have that for timestamps If you don't have that that makes it extremely challenging to prove your case. they basically the bottom line is is all this stuff leaves breadcrumbs that you can go out and chase to bring, to help bring justice if somebody does breach your environment. And also it does promote continuous monitoring does promote accountability It lets people know Hey, I'm watching, I'm watching you. Yep Just go ahead. Just do it cross the line Oh you did Okay Now I'm going to beat you know, that that's a promotes some level of accountability. Monitoring techniques as continuous monitoring provides all the data for adequate investigations and log amounts will again we talked about before be quite substantial and large. you do need to invest in some level of automated tools to search these volumes of logs because otherwise you're your puny little brain as much as it's wonderful as it is. we'll have a hard time scouring through gobs and gobs of log files, eagerness monitoring some key aspects of. this is monitoring traffic leaving your network Hence egress ingress is coming in Egress is going out. so there's some key aspects around us You know you monitor the traffic that's leaving your network. It's important because a lot of times you might not know what's actually coming in your environment, but man it all has to go out through the internet in most cases So it's better to watch. Obviously what's coming in but more importantly Hey what's leaving Cause usually when it's leaving that's bad. you need to assume that your internal network has been compromised by some form shape or manner. And this happens all the time. A network will get compromised You won't know the bad guys in the environment for many many months if not years. And so you have to make the assumption that it is compromised. The attacker wants data to leave It wants to get rid of it It wants to be able to send it to wherever it wants to go. It does not want to leave it in your environment So it's got to ship it out some way. USB sticks. Eh that doesn't work so well I mean it can happen but man it takes a lot of sticks to be able to move your data and you gotta have physical access. Well if you're in country X, halfway around the globe. It's kind of hard to get physical access to the server So therefore, yeah they got to ship it out through the internet. tools to assist in stopping this loss You've got web proxies and these are basically rules configured to stop traffic to Noon destinations. there's data loss prevention which is basically network based or endpoint based. And it can be set up so that you can not use USBs. You can't type in specific keywords, you know restrict you from doing certain aspects. Mainly comes down to as you want to go and watch the hairless cats that are on the internet, it will stop you from looking at the hairless cats on the internet. No not really but it could I guess. stenography is basically embedding messages within a message file And it's extremely hard to discover but it is possible Yes, it is quite possible but you gotta know what you're looking for because yeah it's hidden set of picture. And if you don't know that then yeah you ain't gonna find it. file-based DLP as a software that affects all the different vial types Doc dot.dot J. et cetera et cetera. And there's different companies that provide it But Azure has one's called Azure IP. That is a file-based DLP solution. That will help you from getting rid of it. All right That's all I have for the CIS is P aspect. Let us roll in to the CISSP P exam questions. Question number one, as it relates to logging and monitoring what are some of the key purposes behind capturing logs? Provides a provides an adult. Adult. And audit trail allows for illegal actions and promotes accountability. B provides an audit trail keeps employees concern promotes dependability. See allows for compliance to track employees which is what we always want to do. Keep employees concerned which is even better and promotes accountability. Or D none of the above. Which one is it? It is a promotes audit trail Yes. Allows for legal actions Yes. And promote accountability Yes Yes Yes it is a, so again you have to what you want to do is you want to make sure you have an audit trail Danny Danny be able to find to be able to go back and do those breadcrumbs. You gotta have some level of legal action in the event that you could use those logs. And you got to make sure that people are aware of what you're doing so that there's accountability involved…All right the next question. When considering the data life cycle what are the phases slash cycles Not of the moon that be that the data is generated. A collection inspection storage archiving deletion. You remember I mentioned this you mean to pay attention? B Co gathering examination storage archiving deletion. C collection examination backups archiving deletion. I'm seeing a trend here. Collection examination storage archiving deletion. What is it? A B C or D. It is D collection examination storage archiving and deletion. Those are the key considerations when looking at data life.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 6 (Security Assessment and Testing) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Disaster Recovery and Business Continuity
· CISSP Training – Conduct security control testing (Domain 6)
· CISSP Exam Question – CVSS / Scanning Tools
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Disaster Recovery Journal
https://www.drj.com/drj-world-archives/dr-plan-testing/practical-ideas-for-auditing-and-testing-the-disaster-recovery-plan.html
Person IT Certification
http://www.pearsonitcertification.com/articles/article.aspx?p=2931575&seqNum=3
OWASP
Transcript:
Hey all Shon Gerber Again it reduced cyber risk.com and a wonderful day in Kansas I have today and life is good Can't complain at all And it wouldn't do any good anyway because nobody lets listening about your complaints They just want to hear it all the good things in your life. Actually they're not even paying any attention. In most cases people are saying how you doing? I'm doing good How about you I'm good But in reality their lives just really stink. So no. but I'm doing good nonetheless. So I hope everybody thinks going well for everybody else out there in the world and things are great here. from a cybersecurity standpoint. Couldn't get any better There's actually it's interesting how the world keeps changing and getting more and more. connected And as a result, there are lots of threats that are affecting cybersecurity And if you're studying for your CIS SP you as you well know it's actually a great opportunity to get your CISSP There's so many jobs that are coming open. it's it's just blows my mind And but in many cases you have to have a CIS S. To even be able to play in this space. So therefore it's it's a good thing that you're you're working on your. SP. And the fact that you are trying to enhance your cybersecurity career. So what's it's good Life is good All right So let's get into some what our plans are for today. Today we're going to be talking about disaster recovery and business continuity and our CISSP integration. the CISSP training's going to be conducting security control testing It's all part of domain six and the CISSP exam questions are going to be around CV S S. Common vulnerabilities and then the scanning tools that are associated So again those are the CISSP questions. Also listen to the as you continue to listen to the podcast you'll be hearing, I go over domain or exam questions as well on a weekly basis that are just kind of more to brief into the point And the whole point of it is though is they're just kind of a snippet of what I offer on my YouTube courses that you can get yourself. if you want the CISSP training that you can go and study and also use it to augment your CIS. Studying. you go to U two me.com. You can check those out there at And look for Shawn S H O S S H O N Yeah I know My parents are unique so I couldn't spell So they made a phonetic on Yeah I love it It's great. Shon gerber@udemydotcomoryoucangotomysiteatreducecyberrisk.com C I S S P dash training. And you can actually have access to the training. you can go but it's it's it'll take you to you to me where you can purchase that, that training as well So it's awesome stuff. I guarantee you It is a great training I've done There's like probably close to. well I think it was around 19 hours of training that you can get specifically to help you with the CIS SP each of the different domains that are there And honestly it's it is it's bargain basement pricing that you will get at you to me. and it's I mean obviously they get they get a little bit out of it I get a little bit out of it but at the end of the day, you get a lot out of it And that's the ultimate purpose behind doing reduce cyber risk and the CIS. Training. So all right As enough about the plug but anyway check it out. All right Let's move on to the training…Okay The CISSP integration we are going to be talking from a reference of InfoSec Institute and this is off six dot three collect security processes data. And it's focused around disaster and recovery. So as you will know working on your CISSP and studying this space especially if you're a cybersecurity professional disaster recovery is a key part of how you protect your data and ensuring that it is properly protected and available for people And again this comes down to the CIA triangle, as it relates to availability. Having a disaster and recovery plan is a great first step to having a, availability of the data. So testing on a disaster recovery and business continuity plans they should occur You should have these and you should do these and have these in place. and this comes down to you should have a security assessments and testing that are set up to determine which disaster recovery. Or what systems need a disaster recovery plan and which ones need. continuity plans And so to tell it a little bit of background from a disaster recovery point of view, in the event of a disaster, you have to have the ability to bring critical systems backup at a certain period of time. within a, within a few minutes from a week. And we typically call this an RPO, which is your recovery point objective to your recovery time objective, which is part of the disaster piece. And and so therefore you need to have that in place Well you'll have to do an assessment and understand what does that look like? From a standpoint of data recovery. And so you should you can should consider that also So country. Consider security control testing as well in your disaster recovery plans. Now from a business continuity standpoint you need to understand what are certain aspects or certain systems that need business continuity completed I do. So like I say you have a one complete system that needs to be, it needs to operate no matter what in the business it has to be operational has to be ready to go. And so that would fall under the business continuity and that is a individual point system disaster recovery is kind of the more larger broad brush systems that you would deal with. you also need to understand what are the security processes for data collection as it relates to your disaster recur, recovery and business continuity plans. Now there's there's factors that reduce your Dr Plan's effectiveness and these come into new equipment that you have in place like new acquisitions. So if you don't have if you haven't done a really good job of assessing whether these are critical systems or not or whether they should have a good disaster recovery plan. That can limit your effectiveness of your Dr Plan. So in effect, basically comes into this you have a system and you said you have a Dr Plan for this system and its system a…well system B rolls into town and you get rid of system a. But system a had a Dr Plan in place. You now have system B. Okay. ACE gone bees here. Well what ends up happening Well you disaster occurs and you go, oh Pooh. We didn't have a Dr Plan set up for system B. and so therefore it's imperative that it so then the effectiveness is like ah I don't know what to do Do you know what to do No I don't know You know, what are we going to do? those are bad things to have run into especially when things go south. So therefore it's important that any new equipment you bring in you reevaluate the requirements and the criticality. Of that equipment. Also staff changes. When key positions that change how does this affect your organization? So you have your main Dr Person within your company And that person has the keeper of all the knowledge They are the big brain that operates the, the situation And if you've seen wizard of Oz they are the puppet master They're the man behind the curtain or woman behind the curtain. And so therefore, you need to understand well, is that the right at that person's gone now What what do we do I don't know. So again it comes back to that I don't know Do you know I don't know Yeah. It's kind of not good. So the point of it is is that if you have staff changes you need to prepare for that as well and have a plan in place to deal with the issues of individuals leaving your organization especially if they deal with VR…Now Dr Plan effectiveness Another thing that fact a factor that reduces your Dr Plan effectiveness is shifting processing priorities. data center versus cloud processing. And when I say data center obviously and the cloud there they're one of the same there's anonymous It's just, is your data center on prem on prem in your environment that you control or is it in the cloud and somebody else controls it. Or is it your cloud Again these are all different things that you need to consider. when you're dealing with Dr Plan effectiveness And so often people will migrate things to the cloud. Not thinking that well by doing that do I incur some issues with my Dr Plan? And then that kind of comes sometimes can cause a situation, actual application complexity automation and SAS solutions which is software as a service solutions. Do they add complexity Oh yeah they do They do add a lot of complexity and you need to understand if you're adding this new system that's in place that automatically pushes stuff to the cloud. Does that need to be Dr I don't know Does it should it have a good solution place to Dell deal with it Maybe don't know. So those are different aspects you need to consider as you're dealing with application complexity and then legislation channel challenges or changes that happens routinely And if that happens how do you deal with it? Recently there's just been some with the Chinese cyber law They had some requests for Out for comment And that was supposed to be done by the end of June So that has been completed. And now we're waiting on. What is the final ruling on some of these things from the Chinese government. Again legislation changes even though they are slow to operate in some of these changes but they have dramatic impact effects when they do make these changes So. changes in laws in all countries could have a dramatic effect on how you do business especially if you're on a global basis. Or if you are in country and you're trying to come to United States because our data laws may change too As time goes on…Audit preparation you need to prepare the team to meet any regulatory requirements that you may have And this includes, you're ensuring your inspect. Your expectations are set that the team will not enforce the procedures. so you'd need to make sure that they understand what does it take if you do not enforce these procedures how does that affect you? What how does it deal with. What are you going to do about it And do you have a way to document in the event that someone did not follow these procedures? you need to make sure that people are prepared for it And this comes down to the team of the your cybersecurity team It could be just anybody within it could be anybody within the business. I've recently been dealing with all of those things and the cyber legislation. I'm working all the way up to our board of our company because of these changes and they affect not just it they affect the entire company. So those are important pieces to consider. team members need fluency around internal audit data security and data processing. There they need to understand what are the different aspects around that and how do they manage those things So they need to understand the vernacular. And again I've talked about in recent podcasts that main point is understand how to talk to people to level they understand they are They can understand what you're saying. so they need to fluency on the cyber stuff and then be able to transmit that and translate that into words that people can use. outside resources can provide a little or a lot of technical assistance depending upon you If you want that or not from an audit preparation standpoint, that would be your ENY your Deloitte and so forth They can help you with this from a preparation point of view. or they cannot just kind of comes down to what you want them to accomplish for you…Okay That is what the training I had from the InfoSec Institute from cybersecurity integration. And that was over disaster recovery. Section six step three. All right So now we're going to roll into the CIS S P training. And that is objective six dot two conduct security control testing, domain six…Now we're going to talk about vulnerability assessments There's a physical aspect of. Asman that doesn't really work That's not a really good word. What does that word mean? I was a physical aspect…Does aspects of an assessment and these are scanning tools Penetration tests are big key physical aspects around an assessment. And if if you just heard a groaning it's from my dog Sorry my dog's in here and he's not happy that he's actually having to listen to cyber security stuff. there's assessment findings mitigations So these are all the different things you need to be aware of as you're doing an assessment for a vulnerability assessment from those tools to the penetration tests and so forth. Now there's a common set of standards for vulnerabilities and these can be all over the map. as far as the standards for these vulnerabilities and you just need to be aware of those. Now some examples around this are your CVEs and the CVE In this case the example I have is a CVE 20 18 1 2 3 4 5 What that is is that's a nomenclature they have for the common vulnerabilities exposures. And these are what. the governments have come up with that These are some of the vulnerabilities that are out there and this is the exposure to that. Now it talks about a descriptor. of the vulnerability It talks about references and how it got to that exposure A CVE number. these will typically go by the year. 20 18 1, 2, 3, 4, 5 I want to see for 5, 6, 7 and 8, 9, 10, 11 and so on and so forth. and they will then talk about the vulnerability and what are the issues And you can you reference these CVE numbers when you've scanned for vulnerabilities? And a lot of times a scanner will actually reach out and they utilize the database the CVE database. To say well Hey. XYZ vulnerability is tied to…CVE 20 18 1 or 2, 3, 4, 5. and then it'll cut tonic Talk about talk about that a little bit…There's also a common vulnerability scoring system And that's another one So you get CVS yet CVS S this is the principal character of the vulnerability What is it And it also ranks it on a scoring of a CVSs is from zero to 10 being the most secure or most secure. But most severe that was when you really got problems It's the apocalypse. things are coming down asteroids from heaven and plagues locus and all those things is when you hit two range 10. when it's range zero. It's like why bother even wasting my time? So those are the different CVS numbers that they have but they that's how they rank them. There's also many others. As well that kind of talk about this but your CVE and your CVSs are typically the two that are most used…now from a vulnerability scan There's automatic evaluation of systems applications and networks. these automatic evaluations of these systems you will automatically go out there It look at them. Now sometimes it needs to have an authenticated scan. And what that means is it may need credentials to actually do a full scan of what it needs to. So it may as an example of vulnerability scanner may just do a fingerprint of it It may only get the operating system name and may get a version of it It also may not get the most accurate information if it doesn't have an authenticated scan. So that's something to consider If you're doing these. scans within your environment. He has does it have to be authenticated to ensure that it's done properly? And typically set for a routine basis You need to set these up so that they're done on a monthly basis. and in many case cases the the scan is only good as the operator I've seen it where there were a person will match the easy button and they'll smash the button and a scanner will work and they go okay here's your report? Well, that's really useless because sometimes the reports that kick out of these things are like eight Zillion pages long and it's just, it's not useful. So it's important that you have a good operator who understands the scanning piece of this. And there will be need to be some level of interpretation as a release to the scanning and and how what does what's actually occurring within the environment and how does that affect you? So vulnerability scans again they're typically done on a routine basis but you you need to make sure that whoever does it is. And I like to say we I mean I like to focus My company focuses on a thought process around entrepreneurship and that people need to own their product. and you need to, so if you have someone who's doing vulnerability scans for you. if it's an internal resource they need to own their product and be able to provide you good results. If it's a third party that's doing the scans for you due to regulatory requirements, they need to give you a good product and they need to be able to talk to it Not just say here here's your report and have a nice day check box complete. they they need to be able to do a, a good product and give you or give you a good product and do a good job…Now from a network scan standpoint there are four main types You have network discovery. Network vulnerability. Web application and database vulnerability scans…The network discovery scan Now this is basically a different range of techniques around this and it's looking for open systems that are vaguely. Open and potentially vulnerable and ports that go to them So you could have tons of systems that are out there but if the ports are all closed and you can't get access to it that's a good thing. but in many cases that's not the case In many cases when you'll scan a system you'll find out that there's gobs of ports open, which would allow potential attackers to get into your environment. little mini companies typically do not have good knowledge around what other assets on their environment. And so network discovery scans are important Now, something to keep in mind with network discovery scans is that if you have older legacy systems, The news legacy the new network discovery scans that we have today are very they can be a bit. What do you call it? Oh, strong They can cause issues with a, with environments is that they're too much and they can make things tip over because they're just so strong. So there's various scanning options that you need to consider as you're doing it When you're putting these out there, just know that if you have old legacy systems and you're running a scanner you could run into issues So it's better to start small and work your way out. Now there's TCP syn scanning, TCP connect scanning, act scanning and then Christmas scanning. And obviously the TCP San you're looking for a sin. And that will tell you that basically it's alive If you're trying to do a connection it'll actually connect to the device. And then an actual we'll go in and acknowledge that it's even listening on a specific port. your Christmas scanning basically means you'd you you send the scan and it lights up like a Christmas tree and that's usually not good. but those are the different kinds of scanning options that are available for you with a network discovery scan…Network vulnerability scan This is a much deeper than the discovery piece and it was looking for known vulnerabilities. So you based on your CVE C V S S…a S. Aye. Items. it will be looking for those vulnerabilities and it compares a discovery of the data to what's within the database. So if it finds out that there's issues with it it will go and say that there's a problem with it And it'll tell you. these these basic compares a discovery to the data within the database itself specifically. and author unauthorized scans typically are are not as good So therefore an authorized scan gives you a lot more detail when you're dealing with a network vulnerability scan. You just gotta determine if you can put their credentials in place to do that. Now if you have to have certain level of credentials for that. that are elevated Now you need to protect those in a way that it doesn't incur more risk within your. There's various scanners that will help you do this There's Nessus Metasploit rapid seven Nexpose These are all scanners that you can we'll provide you that level of detail. you just have to decide whether you want to use free or you want to use paid versions. the paid versions obviously can get very expensive but they give you a lot more detailed They're more granular Obviously the free versions will give you something, but you got to ask. What do you need now if you just trying to do some basic maintenance and trying to understand your risk. Free scanners will work out well, if you're dealing from a standpoint of you got exposure on the web and you have regulatory requirements compliance requirements. You may want to invest in something different just because. They typically are updated better with the database They also will give you a better support, those kinds of things. So you gotta decide what works best for you As you're dealing with network vulnerability scans for your organization…When vulnerability scanning this scans for vulnerable web applications that are on the internet. it's usually the first line that is attacked because the rest of them they are. to get within your network The webs are out there and forced the webs. The…web the web vulnerabilities are your internet facing websites are typically the first line of attack because it's out there and available for people to go against. and in many cases these provide valuable data on even how you do your nomenclature within your network. So if they can get even if they can't. leverage an attack against that that server. it can give them valuable information of how your network has configured. And so therefore if that's the case if they do get inside your network through a phishing attack of some other kind it can cause issues Right They got more intelligence about your network. The other thing is is that if you get your web server and it gets attacked and they can get access to it. It can cause reputational impact. So you need to develop a process on scanning sites to understand how vulnerable they are. You also need to have a process in place to scan your lab and your production environments from a development standpoint. It's important that you know what your lab environment in your purse. environment looked like from a web point of view. Now if you have a third party that's doing this for you So you have a marketing company that's doing your your web applications and do our doing your front end for your websites. You need to make sure they have a good security program in place And I would have do an assessment of them to make sure they're managing it Appropriately. false positives can and do occur You will get false positives was your scanning engine So just keep that in mind. It's going to happen So you might chase a rabbit that doesn't exist It's very possible And yes it will happen. so therefore it's good to have multiple TA ideas and using good scanners will help you with this But I have seen really good pilot paid scanners are highly expensive Scanners do give me all kinds of false positives. So Thai again having a good operator that knows what they're doing will help you dramatically in this space. Oh wasp has a list of scanning tools that are available for you as well. That you can utilize for your vulnerability scanning…Database vulnerability scanning this typically. some of the most sensitive data within your organization is in a database. and so usually their internal M and a that. That's typically what's kind of buried in the bowels of the beast And also because of that it's internal. What also ends up happening is sometimes you don't even know they exist. So very cloud providers are changing this thought process because now we are getting more databases in the cloud, but you need to consider where do these databases reside And in many cases they are tied to various web applications…All right That's all I have for the CIS S P training today, as we relates to vulnerability scanning. so we're going to now roll right into the CIS. P exam questions. This is for domain six…Okay And this question we are going to be talking about CVSs So when looking at common vulnerability scoring system CVSs, When a vulnerability is ranked 10, what does that mean…It's most open for patching a. It's most severe mumbo-jumbo B. It's least severe not a big deal See. Or it's easily managed. Which one is it? It is B most severe right That's the end of the apocalypse, locusts plagues, big asteroids coming from heaven not hemorrhoids but asteroids coming from heaven. Yes that is the most severe ranked 10 that's bad Okay So CVS score of 10 is most severe which is bad…Vulnerabilities. So what tool is commonly used as a scan engine to find vulnerabilities within an environment? A Nessus…B and map…C. Not the golf club, but pink. D DNS. And the answer is don't dun duh A Nessus is commonly used to look for vulnerabilities within a net. to determine if an exploit can be used against the system Nessus Yes I've used Nessus It's a big monster tool It works like a champ. it gives you all kinds of gobs of information but if you don't know what you're looking at it's just like looking at Greek. And honestly there's people way smarter than me that understand that super well. But Nessus is commonly used to look for vulnerabilities and ping is not a set of golf clubs while that is a set of golf clubs but not for cybersecurity. Now if you like to play golf good on ya. Alright. So moving on. All right This is the links we have and I ISC square training study guide Quizzlet disaster recovery journal. Person it certification and O wasp.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Identity Governance
· CISSP Training – Manage the identity and access provisioning lifecycle (Domain 5)
· CISSP Exam Question – Username-Password / Preventative Controls
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Infosec Institute
https://resources.infosecinstitute.com/category/certifications-training/cissp/domains/identity-and-access-management/#gref
Wikipedia
Transcript:
Hey y'all this is Shon Gerber again from reduce cyber risk And we are in this wonderful state of Kansas and the United States and things are great We just got done with our July 4th weekend here in the United States It's actually been a little while but but Kind of want to talk about that a little bit and had a great time over the July 4th weekend. I had some time with the family and my kids just, I love them but they yeah they drive you crazy So if any of you guys if any of you all have children, you will understand that Yes teenagers are a lot of fun and in my case, They keep me popping Like there is no tomorrow. I've got two that just graduated high school and in the United States that's a big event So one's going off to college So we'd be prepping for college here before long, and then I've got another one who's going to be joining us Probably we're going to be starting up a business My wife is. And so therefore with that with between her business and the kids coming into Scala college and between, I have three others and still in school one more senior. it is a busy busy day. and we've. since we have we we basically have four. Or five, seven children total and of that five of them. our four of them have been adopted And so we are, we're very fortunate It also is add a lot of challenges that are a lot of fun to kind of work through. And I say fun in air quotes so yeah but other than that life is good I cannot complain at all. All right we're gonna get into our training and we get taught today We're going to talk about CISSP cybersecurity integration was going to be identity governance Again this is over domain five. CIS is P training is going to be managing the identity and access provisioning lifecycle. This is. The main five obviously. CIS is P exam question will be usernames and passwords and preventative controls. All right before we get started just want to put out a plug out there for the CIS S P training courses You can get these Yes you can. You can get these in your hands or actually yeah Clicking in your hands or in your eyeballs. Yeah. It's kind of gross actually but in your eyeballs you can get these by going to you to me Dot com that's U D E M y.com. And depends on who you talk to Some people call it. some people call it you to me. It depends how you want to say it but it calls different ways but you can go to your tummy.com or you can go to reduce cyber risk.com C I S S P dash training And that will point you in the right direction. four of the different domains Again we have there's eight different domains You can get those at your leisure and you can get access to all of the CIS S P training that I put out. Along with exam questions you can get those as well. and I also put out exam questions during the week and you can get access to that just by going to reduce cyber risk and becoming part of my email team. And you can get all that as well So you get exam questions you get the CISSP. It's a plethora A cornucopia of information available to you at your fingertips. All right let's get going on into our training. Okay CIS S P in cybersecurity integration. The InfoSec this came from InfoSec. This is the reference. Again the links will all be in the back and, and the final part of the presentation or the podcast I should say. And also in the show notes as well So I'll be there and available for you. jeopardy objective five dot three of your CIS SP managing identity and access provisioning life cycle. And then the topic today will be identity governance. Again this is an article from InfoSec Institute…Now managing the identity and access provisioning life cycle This is crucial to have a effective control over your logical environment And when we talk about different environments, You know you have your your basic physical environment and you have your logical environment which is the the aspects around the technical pieces right That all falls within the logical aspect of your specific environment. And these include operational documentation maintenance. Monitoring reporting, access rules roles and titlements maintenance And we'll get into those Those are big $10 words and obviously InfoSec Institute, his a lot of smart really smart people because they I use these big $10 words and I struggle with $10 words but we'll try to make them simple because that's the whole purpose. The C I S S P training made simple. the operational documentation maintenance this helps develop structure provides oversight and how implement the local access controls. So basically what it comes down to is you want to put in access controls and these are logical right? These are all logical controls but you have to have these documentation around your operational things that you put in place. So you have your your basically your it functions but then you have your operational functions that work within your organization that makes the operations the daily day things go. and so you need to have this documentation in place and then this but it does though is this maintenance aspect is kind of like an assessment piece of this where you go back in and you'll provide oversight on how to do this. and these can be fallen or policies that can fall under different areas as well. But it's it's a basically how it flows into the operational…It also establishes a governance model that helps to ensure compliance And we talk about this quite a bit. In the fact that you need to have some governance model in this. And when we talk about compliance we don't talk about the big C compliance We talk about the little C compliance. this would be your, when you're talking to the big C compliance that means you have regulatory requirements that force you to to do these different aspects with your company, to ensure that you meet their compliance of the government regulations. that may be out there and there's those be state and local regulations It could be other aspects to the little C is that you follow the process that you've provided You've put in place to comply with the aspects that you're wanting to. To accomplish. And it also. So that's the whole purpose of it right Is to have some governance around how to help you get that done. Monitoring reporting. This is a monitoring the compliance with policies and standards Now you're just making sure that you meet and you follow through with what you say you're going to do with the policies and standards you have in place. this provides guidance through executive dashboards and reports. So if you can hit get an executive dashboard and it could be as simple as you have a spreadsheet that's got little green and little red and little orange. That's not really. Green yellow Red Yeah. Green yellow red Yeah stoplight thing. there's not much of an orange there. That's kind of a blend between yellow and red orange, but no So you brought up provide the guidance through executive dashboards and reports That's the whole part sorry. Some weight. measuring how are you doing What are you doing How are you doing it? And are you moving forward or are you falling backwards? We don't want to fall backwards We always want a full fall forward. access rules roles and entitlement maintenance. this B. Basically deals with. And you have exception management and you have definition of the rules and how you're going to follow these different rules for the roles. So do you have how do you bring things on how do you take things off? How do you provide provision and de-provision individuals their devices all of that all falls under the access rules and roles. And it basically is the life cycle from beginning to end How do you start it How do you end it How do you decommission it? and if you have that in place I mean honestly, that's a big deal If you can get your access. That whole life cycle piece going and put it in place and start off simple. That does a lot for your company to ensure that it is secure. It is it really does a great job on that…Another key component is operational readiness advisory Now this begins with various stages around your requirements So once those are defined and you have your design your test and you're doing all the operational onboarding that you need to do this is where this begins Right So it's how do you begin to get ready to go And that's the whole purpose of. I'm getting ready for my operational side I need some assistance. I need to know what I'm going to do All right Let's go. And this provides advisory or consultation to the development of these various systems So it's, it's basically the SMEEs the subject matter expert to help you with. Are you ready to go and give you some guidance around that? Some change management also around the aspects of of change management And this is a process of managing the change around your identities and how do your people, how do they get provisioned deep provision That's the life cycle. but then what is the process process for managing the change with those identities So bill who has access to all these file shares. How do you manage his change So bill has access to these files shares but you know what Now Bill's moved on to a new role. it's still in the same area but we need to reduce the level that he has access to. So how do we manage that? They're also it's how do you deal with the communication piece of this at this built into it Can it be automated and ideally in today's world you can automate so much of this and it can be done if you utilize SharePoint or something along those lines. They it can be. automated within like not Infopass not the right word but flow flows It the product they use now with SharePoint online, you can provide this change management advisory piece to people. and that can be really simple It can be set up in a simple format. That will give you what you need. so again that that's changed management advisory communications…Now as you're dealing with identity operations this includes the access review and reporting and this is access request fulfillment and there's. many other aspects that around this. And this function is focused specifically on your day-to-day access control requests. This is your provisioning your administration all that maintaining maintaining of the life cycle that's associated with it. enforcement of logical access controls is another key component of your identity operations. and again this is the day-to-day stuff This operations is your day to day. Get dirty, get in the weeds kind of thing. and then so that's the whole purpose of that. And in rules are related to ID access requests approvals and so forth. So you have these rules in place to basically deal with your identification. And also anybody who may request access to your specific systems. again this is the it's all responsible for the day-to-day ops and it basically it allows you to provide the capability of bringing people on taking people off. And that's your identity operations function That's kind of what they took called about out there is that you basically need to have governance. Day-to-day operations and you need to have some way to. Deal. the life cycle. That's that's how it all works Those three pieces will go take you a long way. Okay So that is the discussion around from InfoSec Institute. Okay And we're going to move on into the C I S S P training. Okay So in this CISSP training part we're going to again talk about five dot three managing identity and access provisioning, lifecycle domain five So this is going to be a supplemental or. That part that we We saw before a little bit of a supplemental of what we're going to be talking about today and the rest of this podcast. And the basically this refers to change management of accounts So again we talk about creation deletion and management of these accounts. one of the key points is identity is the most commonly used user account So you are you. Basically we're trying to get identity of individuals. And so that's the main part of all this it's the most common part of a user account is how do you identify the individual who they are? are they the right person That's supposed to be accessing it? do they have the right credential? and the ability to do their job. All of those things are part it's the most common part of a user account specifically. Now when you're dealing with access control administration. There are three main pieces that you need to be aware of. One is provisioning. The second is account review. And then count revocation which is basically. The deep provisioning or the turning it off of the account. and and again I will I will tell you I apologize Sometimes these a these big $10 words. I try to make them simple. and so therefore they they use big words but then I'll go to some easy one Like yeah you just had to turn it off and And so it there's a, I will struggle And if you're working on your CIS. With the cybersecurity, career. Here's one thing to keep in mind as you're moving forward. And this don't mean this to offend anybody at all That is not the intent, but it's a lot of times cybersecurity individuals will put these big $10 words out there and they will say big monstrous words, in the thought and hope that it. them look way smarter and then they potentially maybe are. And I'm saying that they're not I'm just saying that a lot of times I've seen this in meetings a lot. Where people will use big $10 words and I am totally confused going what the Dickens are you saying? just just use third grade language I can understand that because it's all I have from a knowledge standpoint. And and so therefore, sometimes I'll use a big word and I'll say it out there and then I'll try to. Bring it down just a little bit because honestly I, I get confused then. Then if I'm confused I only assume that maybe only about 10% of you all are confused, just because you all are probably way smarter than me. so just kind of keep that in mind as we move forward in the C I S P training I challenge you to look for the big $10 words, and then try to make those simple, because here's the point. If you're going to be a Cisco or if you're going to be someone that's going to provide influence for your board or whomever that in your cybersecurity field, you need to know how to do this. You need to know how to break down the $10 word. And put it in terms that the, for a third grade level. Not because you're dealing with third graders because that's not the case So that's one thing The other thing to think about as a cyber I'm on a little bit of a tangent here but. That's one of the things to think about as a cybersecurity professional is do not treat people like they're third graders do not Okay Because I'll tell you right now, most people in, in the world are there's people that are way smarter than all of us Right. and then but if you can talk to people at a level that is easily understood when that's why I say the third grade level because if you can talk at a third grade level to people that's easily understood by most And so therefore if you're talking to your CFO your CEO, any other C levels? You know the board whoever that might be. They're going to want you to talk at that lower level Not because they're stupid or they don't know what the heck they're talking about. It's because it's a language that everybody can understand when you get these big $10 words that are out there. It your $10 word in cybersecurity is very different than the CFO's $10 word and financial. Terms. And so therefore it's important that you bring it to a level where everybody can under. All right. Yeah right We've had a little bit of digress there but the point of it is is just keep it simple, silly. All right. So again provisioning. Account review and account revocation or deep provisioning or turning it off…Provisioning So there's key points about this is creating the new accounts were privileges It's important that you keep it as simple as possible. Do not over-complicate this And I am guilty of all of those of making it way more complicated than it needs to be, thinking And this kind of comes down to the development space where you create this complicated thing Thinking you're going to add features in later on You never really do in all these features ever do from a development standpoint is cause risk. so you need to keep it simple as possible follow specifically defined processes and procedures. If you don't have the processes and procedures defined then define them and then follow them. But keep them simple and then you can move on You can grow onto these simple procedures as time goes on. Oh you need to have a way to confirm the identity of the individual It would be photo ID HR security clearances whatever it might be You need to have that confirmation of their identity in place. this concludes all users contractors employees and so forth. Now sometimes it may be as simple fact that. Who confirms that identity you may rely on the HR person to confirm the identity of it. but you need to keep the process as simple as possible. if it's you that's doing HR and doing a provisioning and everything because you are the person that's, that's going to be doing that. Then obviously you've got a lot to do, but again keep it simple as possible. And keep it the same process. If you have compliance issues to consider as you have PII or personal identifiable information, then you need to con you need to adequately protect that. that also could be, personally identifiable health information as you're dealing with those. Questions as well. So you need as a cybersecurity professional especially studying for your CIS SP you need to understand those key points about this. the China the birth name that's another good issue Is that in China privacy aspects what is the birth name of the individual? like in my daughter's name was you know, okay I mean I can't think of her name. That's not good or Chinese name? Well I'll go with my son So his was a Molly Jo. So that was a Chinese name but we call him Jax. Jax J a X Gerber right That's his that's his name And therefore, his middle name We call him…But in China he was. my wife. As what he was. Actually his middle name's…Somewhere around there Yeah. Anyway, that's the whole purpose around him. and so those are different aspects that you got to be aware of as you're dealing with compliance issues. employees contractors that you need to have way to for them to sign documents as well. how do you confirm that So if they haven't used DocuSign or some other doc document signing technology, that would be extremely valuable…Now your ongoing maintenance around this piece is your. You to audit the accounts you need to provide and, and the access to these accounts you need to have the ability to do that. the process for promotion departures. Based I imply in Berta employee…I can't even say it. Employee transfers you need to keep all of those the same. the the whole new process of anything that you deal with somebody that enters the role or leaves a role you need to keep that actually the same as well. so again these are employee transfers and an ongoing maintenance…Now you're dealing with account review Some other key points to keep in mind is these need to be reviewed periodically. Do not rely on the fact that these are just going to set them and forget them kind of thing. That's where credentials get added in where they'd never go away. I've…seen it in previous lives many many times where I would actually go into a when I was doing the…hacking world, I would go into an account R into a environment I would see if there was accounts that had been there for seven eight years and asked the question was this person still here And the person hadn't it kinda hadn't been used in seven eight years. As I know that person's left but the account was still there act and active. It wasn't even the point where it was turned off it was still active. So you need to have that set up and you also need to ensure that the policies are in place to address audits. now we talk about audits that could be audit or they could be an assessment. Audit typically a formal type of thing is done usually by a third party or at a minimum and outside. Resource either within your company that is specifically designed to do audits or it's actually a third party that, that maybe you have it's a sister company, or it could be a company like E and Y Ernst and young or Deloitte or one of them to do an audit on you…you need to have script you can have scripts to run audit reports on your accounts. so hence no activity logged in for 30 plus days et cetera et cetera. You could have those in place And so those are ways you can look at your different accounts and how to review those. privileges There's excessive privileges You need to know as far as that goes to do someone have more privileges than they need to have. And how do you manage that? do they have the necessary privileges to do their role Do they not have the necessary privileges And do you have a process in place how to add them privileges in easy format? I'll be honest If you can do this, then you're really setting yourself up Well I will say that many of us struggle in this space just because it's there's so many things to do And these are one of the things that gets left behind and it really needs to be one that really needs to be the top priority. privileged creep in the case of individuals of how much. Our Creek how much creeper do they have No, it's not a much They're creeping. It's how many privileges do they have So if you have privileged a and then you move into a new role now you have privileged B, but you now because you move to the new role you have privilege a and B. And then when you moved to a new role you got privileged a B and C that's privileged creep That's a little bit of this a little bit of that And next thing you know you've got a lot. and then audits will help address this as well. Now you need to consider the principle of leaf least privilege What do you need to have to get the job done Do you need it all Well no Okay So in the case of myself I have. Typically, if you're a cybersecurity person you should not have admin rights. You just shouldn't…especially if you're dealing with if you do, because you are the only person left, then that's one thing but then you also need to make sure that you do not use your admin rights obviously for surfing the web and doing those things. I in my role I they they've asked me said what do you want Admin rights I do not see any need for me to have admin rights. the simple fact of it is one. I'll just mess things up to, from a targeting standpoint I'm probably targeted a little bit more than some people, so therefore I don't want to be increase the exposure so I don't have that stuff And I just rely on other people to do that So again the principle of least privilege…Account revocation So someone would pull an employee departs or leaves. This is I E leaves terminated resigns. they depart the fix Okay That's flying term. Depart the fixed and they leave to a different location. that is when you want to have account revocation and you need to have a process in place to address these departures. if you don't not have a process in place to address these departures. Yeah that will be bad because what happens is these people never go away. And then then they're on your books for ever. Okay And if you can tell me the movie there's a bonus question in there for that. For vert. All right And then that's what they're here forever So that's you need to have a process to address the departures I had a lot of coffee this morning Holy cow I'm ready to go. HR is usually the ones that are most connected with account revocation They know who is coming and who's going. And so HR needs to have the ability to to. Basically clean this up. there's an account removal process and there's the account are removed immediately after leaving. so once a person leaves the area then the accounts are shut down and they move away. you remove access is disabled for a period of 30 days and then you delete the counts After those 30 days are over. so those are kind of the process and you need to have that automated where once a person leaves account is removed immediately after leaving So or it's put into a standby mode per. at a minimum. And then you remove access that should be disabled for a period of 30 days So access is denied and you hold onto that. And a lot of times. will hold onto these accounts specifically for a reason that there may be. Documents that they need to get access to. and so therefore it's important that you look at those documents You have your supervisor. Visors look at the documents with those credentials for a period of 30 days. You then go ahead and you can pull out that information Now, once that's done and you have that set up and the credentials are revoked, then at that point in time you can delete them after another 30 days So basically it's a 90 day process. As what kind of well in this case it's 60 days of what I've got called out But as soon as they leave there the counselor the access is removed is disabled I do that for 30 days Once that is done then you go ahead and delete the counts After 30 days, sometimes you may set it up. We may leave access for this thing for a period of a week maybe. but the problem is is when you leave access accounts still active. I've already seen situations where an individual has made backdoor for themselves. They've logged in, from a remote capability And what ended up happening is their accounts are still active and they went in and they caused all kinds of mayhem and destruction. Now granted that was a really stupid idea. 'cause he ends up going to jail for something like that But at the end of the day don't do that. but you should that's why you should remove those accounts access immediately after leaving…Some other additional precautions you're gonna have is audit it personnel with elevated. Permissions that is a big deal So it guess what they touch almost everything and having them with elevated permissions, God permissions. is usually not a good idea and you need to audit those people to make sure they're doing the right thing because they all do have gone prevent for her permissions And so therefore I should say all many of them do. And especially when you start dealing with domain admins and so forth you got to audit them to make sure that they're doing what they say They're not surfing the web with their domain admin credentials. high risk employees your R and D and your senior leaders Those are also ones you need to audit. just because they are typically targeted from a cybersecurity standpoint. hackers will go after these senior leaders, sometimes. they do after him because they have a little bit more information that they wouldn't normal people like myself wouldn't have. So they go after them R and D is because they have intellectual property knowledge that they may go after them as well. So those are some consider. And then the cybersecurity leaders they will go after them as well Because many times they have the list of vulnerabilities that are out there So as working on your CISSP and your cybersecurity space, you need to make sure that you are connected with that. All right So that was all about the CISSP training We had set up for this podcast We're now going to roll into the C I S S P exam questions. We are not talking domain five of the CISSP exams. All right And this question, we're going to get into usernames and passwords. When looking at user logs, the purpose of the username and password provides the following. Which one is it? A identification. B authentication. C accountability. D. authorization. And the answer is. A username It ensures that the correct identification is used when accessing the account. So you want to understand that it's important that you have these you correct username when they're accessing this. And as you're dealing with logs it's also important to ensure that the username is connected because what ends up happening is is if you don't have a username, it's pretty hard to get. And we talk at non-repudiation good $10 word basically. The, and that's a good word It's a really good word too to make something a sentence a little bit more simple but you want to be able to prove that their hacker actually did what they said they were did. And if you don't have usernames or. You don't know who actually what was the account that actually worked at So it's important that you have the username available. And these logs to ensure that you can track it all back to the right. Username or the right device…Alright this question preventative access controls. Which one of the following is a preventative access control type. A CCTV. Me. Matt. checks. See. Mantra. And track. I like that My trip. the none of the above. Which one of those is it preventative preventative access control. See Oh man traps are considered a preventative access control that will limit individuals from a specific facility. CCTV is there and available so that if you want to. And usually the CCTV honestly, there's nobody really, in most many cases, 24 by seven viewing of CCTV does not exist. So therefore it's important that you understand. That's usually a control it's after the fact a background check again is done beforehand and usually it's before the person even enters the area. And then the mantrap is really designed as a preventative for a facility So you. If you're not familiar with a man trap is you walk doors open up you walk in doors closed behind you, and then if it validates your identity it allows you in If it does not it says you are not leave Stand here until security forces come and get you. so yeah there's and then they they're also watching for if you carry your buddy in, carrying your buddy into into a facility. And your back. They have pressure plates going okay this guy weighs 450 pounds. He's really either really big or there's two people. So that's something else that they keep in mind. So th those are again those are preventative access control type is the mantrap. All right So that's all we have for today's podcast These are the links ISC squared training study guide Quizlet, InfoSec Institute and Wikipedia.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Security Architecture and Engineering) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Trusted Computing Base (TCB)
· CISSP Training – Manage Engineering Processes Using Secure Design
· CISSP Exam Question – CIA / TPM
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Tech Target
https://searchsecurity.techtarget.com/definition/trusted-computing-base
Wikipedia
https://en.wikipedia.org/wiki/Trusted_computing_base
Wiley
Transcript:
Hey all is Sean Gerber again with reduced cyber risk And I hope you're all having a beautiful day today. It's a gorgeous day here in Wichita Kansas. It's it's just couldn't ask for anything better So it's an awesome day And in Wichita Kansas. Well today we have some great things that we're going to be happening in the CIS S S P training field And we're going to be talking today on our C I S S P is security integration is going to be around trusted computing base, otherwise known as the TCB. Our overall training can be on domain two and we're going to be talking around managing engineering processes, using secure design. And then finally the CISP exam question is going to be focusing on the CIA triad goal and TPM. Trusted platform module I think is what it was Yeah. I think that's what it is There's too many acronyms Can't keep track of them all, but we'll get into that here in just a little bit. But before we do I want to get quick, put a quick shout out about my CIS S P training courses that are available for your purchase. At umami.com and you can catch those up at. you tummy You also can go to reduce cyber risk.com/c I S S P dash training. And you can get access to the UME courses that I have available I have put out there all of the CIS S P courses. Domains one through eight are all available for you to go get at you tummy. And as you well know your enemies bargain basement prices are actually pretty incredible. I mean it's just it's amazing what they offer from a pricing standpoint. But the cool part about all that is I will put updates to those on a routine basis Each of those domains will be updated on a weekly basis based on the content that's put out So it is a great place for you to go get your CIS as P training to help you augment your studying for the CISP. P exam. So go check it out@ume.com or@reducecyberrisk.com slash C I S S P dash training. All right let's get going. Okay And the CISP cybersecurity integration We're going to be talking about three dot two fundamental concepts of secure. models. Now how does this work Well basically what I ended up doing is I take the ISC squared training manual that they put out. That goes over What you need to understand for the CIS is As P from ISC squared. And I break it down into the different chapters and sub domains that they have. And so what I've done is I have three dot two which basically focuses on the fundamental concepts of security models. These are the key aspects and data that you're going to need to understand for the CISP exam and the key concepts the key understandings And we will go over all of that with you here on reduced cyber risk. Now one of the key points to consider is that this is the foundation of creating secure code. And when you're dealing with when you're trying to come up with, and I have a development team that worked for me so. I deal with this on a routine basis as we're relating to development development of code for my my team and for, to protect our company. And this includes operating systems and associated security mechanisms So it doesn't necessarily mean just the code that would go into potential CMS. It also means the operating system code which would be in let's just say XP, which is really really old but people still do it or windows 2008 server or whatever it might be. It SQL server whatever the bottom line is is that the operating system itself needs to have the The level of security put into the actual development of the code. But this also means a B BS That's a really good word. It also becomes around the hardware the physical locations the network hardware software, and the prescribed procedures You need to really include a cure coding in all that you do. Now there's some key provisions you need to follow. Access authorization resources. User authentication and the backup of the data. So those are some key concepts And when it comes into the provisions it's, who has access how do they have access? W who has the correct authorizations for those specific resources whether it's even an individual account or is it potentially a service account Something that's accessing it to just run the system. User author. And then also how do you back up the data and how is that data secured? All of those key pieces are fundamental in when you're dealing with the. Concepts around security models…Now TCB, the history around this is this came from a gentleman by the name of John Rush. B by B depends how you sign it and how you say it Say it. They call me Shawn or Shawn. Yeah. But see, my first name is on C. It's just I love it. It's just great My parents did that to me Hey, by the way if you're a parent don't do that to your children Just just don't do it Just say no. Just don't call them Moonbeam or something like that Just say like call them bill. Or Fred. Those are always good names Yeah. Those are good names. All right so I'm sorry A little bit better. Prince My friends call me Enrique So if you don't if you don't know you can call me and recap, but basically John Rush be defined TCB is a combination of a kernel and trusted processes. Now what does this actually mean This isn't kernel like a kernel of corn that you would get and you'd grow out in your field or in your plot of land. But this is a kernel that's tied to the hardware. And then the software these are trusted processes that run. Uh level of software that runs as a trusted process within with on the kernel. Now these are designed to be very very small in size and and so therefore, as they're small inside they can't be very big right hand small insights, but they also have to be lightweight and be able to run very quickly and efficiently. And these are a set of controls that are designed to work together to form a trusted base a base code. To enforce a security policy on that Colonel. Now we talked about the orange the different books that are available I think we talked about that last week, but the rainbow series and it's the NSA version of that and what what they have the different green the blue orange books and so forth. Well the orange book is a part of the rainbow series and it defines the TCB as this it's a total the totality of protection mechanisms within it include hardware firmware and software. The combination of which is responsible for enforcing a. security policy. Again the policies are they're not like a, a policy that you would make to go create a law. I mean they kind of are, but they're not It's basically the rules set up to to govern how security is in place Put in place. On a specific system. So those are the policy and you'll deal with policies in security policies that are within your company as a CIS. Or as a cybersecurity professional, you may end up putting some level of policies in place. And these are a written document that specify how things need to be taken care of. So there's those kinds of policies as well. Now the orange book defines that the boundaries of the TCB depends significantly on the definition. Of the security policy hands. That's what defines where they can get access and where they can get access…So as an example, we'll use a web server. Now this is a multi-user application right Web servers lots of people log into them Lots of people use them from admins that log into them to the fact that there's just people gobs of people hitting them from all over the world. The it is not part of the O S S T C B Okay So the web server itself is not part of that. Now it provides access controls to preventative individuals from usurping other people's rights So you can't be a squatter go in there and kick somebody out. If there are various access controls in place to prevent that from occurring. Now a breach of the application so of the web server application, whatever that might be whatever you're using. Would be would not constitute the breach of the OSS TCB. So it's the layer above the TCB above, above the overall OS itself. So if you beat if you blow up the application you get access to it and you are gone on the application. You do not necessarily have access to the OSS TCB…So as a TCB software protection, the orange boot book speaks of the TCB needing to be protected against tampering Dole Right? You don't want somebody to get access to that because if they get access to your trusted computing base, they game over they own. it all. Okay Cause that's kind of a problem right If you own the foundation then you own everything That's tied to the foundation. And the TCB must prevent its own software from being written to now they have a memory management unit you might've been hearing about this is in some of the trainings you've learned and some of the. The readings you've done is an M M you okay Now? In a previous life and MMU was used for as a mass measurement unit I used it when I used to fly a seven I didn't fly those I actually worked on them. Uh a seven course error that just shows how old I am I'm like dirt old, but these MMUS. That's to digress They used to work in the navigation but the memory management unit it's on a computer as protections to protect your TCB. Now it's programmable by the operating system So it allows denies and laws are. Denied access to specific ranges of systems memory. Requiring to be run so that it actually provides it will provide a capability or it'll remove the capability depending upon what's going to occur. And then of course there's got to be God mode. Well this is supervisor mode which allows for and restricts this access. So the supervisor mode allows you to do that with the operating system. So again the TCB software has a lot of protections in place just to protect it from knuckleheads like myself that would go poke around and get into areas I probably should not be getting into. Okay That is the TCB software protection. And we are a TCB I should say. And so we are going to move on to the CIS S P training…Okay So as we're dealing with CISP domain three security architecture and engineering. The topic does your is going to be implement and manage engineering processes using secure design…All right So we talked about the TCB in, from a Wikipedia concept Now we're going to talk about what some more things that would be detailed out in the CIS SP. So we talked about as far as the TCB and how it's considered at all stages of system development It's how important it is. that you need to consider its use. Programmers should also strive for secure development And this is when you come down to developing from a firmware. To the OSTP model the OSTP all the way up to the application you should strive for a secure development And this would be, you'll see terms out there I've heard them I've seen them just as. S DLC which has just basically software development life cycle and security is kind of weaved in there. I've also seen SDLC which is your secure software development life cycle So. It kind of goes hand-in-hand I would say that the security when you're calling that out specifically obviously that defines security more than being just a software. However if you're going to be doing SDLC, one of the questions I ask any potential new. Uh developer is how do they. We've security within the SDLC Cause I'll throw out there is a big buzzword going software development life cycle You need to do it. Or I do it right now and I'm pretty awesome. And then when I ask is I ask okay so how do you do that for a security standpoint? I mean do you do you incorporate some level of security within your SDLC? So something there to consider. And and so therefore, when you talk about this stuff it's important that there are some key concern security items for security design that you need to consider. Now we're going to get into objects and subjects. So an object is a resource used by a subject which would also be a computer system So your object could be a computer system a divine system that you are going to be working on. Subject's our user our processes requesting access such as an individual or an RPA which would be a robot process algorithm Okay Those are our PA's. And so that those are different things that are put in place there Object in your subject. Now there's a trust These trusts are set up between objects and subjects. So as an example you'd have service accounts. That would be a user Okay And then you have an R and D computer which would be an object and the service accounts have access to this object and therefore. can manipulate and go back and forth. However the bad guys the hackers the attackers they will then manipulate this trust between the objects and the subjects. So therefore it's important that you have proper protections in place to minimize the attackers from getting them now living in a previous life. Uh service count I've talked about this before on reduced cyber risk is that it is the granddaddy dog that you want to they want to go after. Typically service accounts are set up that they're 24 by seven. They have very little limited protections. Passwords probably don't change a whole lot. And so therefore they are the ones that are used to manipulate other objects and to just take advantage of them. So…again if you're a CISP and you're studying for this this is the key and this is what separates re-do cyber risk from a lot of other people that are teaching CISP, we've got gobs of experience on this stuff and we've seen it a little bit of it I believe me I know I got a lot more to learn tons more to learn. But that those things are definitely liver leveraged And so just understanding the test and pass. the test is with the first piece of this. But ongoing and understanding how these accounts are leveraged. Yeah That's that's the ongoing aspect that you gotta be aware of…Now there's closed and open systems a closed system is designed to work with a very narrow range Okay So it's just designed in a certain area. Again I've dealt with this in the past from a military technology standpoint those were closed systems and they are defined typically by the manufacturer So let's say you have a stealth fighter. And you have a specific system that needs to be working on that cell stealth fighter. They will have that as a closed system It's not updates all that stuff It doesn't reach out to the internet. Hey I'm going to go to update you know it doesn't do any of that You you have very close parameters on how the updates occur. They are sent specifically to individuals to update themselves. They're they're trying to avoid as many inputs from outside that would be random And that could potentially add to a vector into the the system itself. Again so these are defined by the manufacturer. They can be more secure They really can't say of, and then what I mean by that is the fact that because they are a closed system they are segregated away. And the downside of that is and you see this even when the manufacturing space. When you have a manufacturing system that is. such as using the Purdue model what'll happen is is in many cases, these systems that are maybe blocked off by firewalls do not get updated as routinely as they potentially should. So therefore they are Uh, a bit more susceptible to vulnerabilities. And so that's why it's important that I say sort of, uh you you need to make sure that you if you do have a closed system within your environment you do make sure that you do update it as much as you possibly can. Now open systems these are agreed upon an industry standard and these are much easier to integrate with other systems I E because they are have a standard and they're updated on a routine basis. We used to call this cots which is. What I used to they think they still do. Let's cut common off the shelf software and systems. I think that's what the acronym stood for Basically it's stuff you could go by off the shelf and shove it in a plane. Cots. It is an important aspect Now the problem with cots was it was not as tested. As these are the systems that are defined specifically for a. An aircraft or for the military but they are getting more and more integrated within the. Military system as well. There are more options to these networks as far as one of the being an open system but they are less secure. And as they are less secure you have to be aware of that. So again, an example of that would be a computer current computer system that you can get You can go buy a new laptop desktop. Um desktops are really kind of hard to get ready to anymore but when you can buy them obviously but they're not nearly as prolific as they used to be. But you go get this new current computer systems and they are built to a standard. They integrate well with others They play well with others and, but they don't really have the they They run the risk of being a little less secure because they have so many bells and whistles that have to be in place…Now techniques to maintain confidentiality integrity and availability We're going to get into confinement. Okay So this is various techniques that are created by software developers. And any of the following can be used outside of software development And it doesn't have to be specifically in the software development world. But. It's where we're talking about right now. But bottom line is confinement for what does that mean It restricts user Yes That makes sense The word says confined restrict strict for users and process asset access or actions to a program. It also allows a process to read right from specific locations So it re it confines it to what it can do where it can read it defines who can access it, what programs can access it So again it confines the restriction it puts restrictions on it. Uh sandbox is a place to restrict where you can operate again. Now this is also a place where cats go Pooh, but we're not talking about that sandbox We're talking about a different sandbox. This is one where they you place at restrictions on where you can operate You can play in it's a it's a place you can play and beefs protected from the bad guys out there outside of the sandbox. That's that's the purpose of it, but you must meet and operate with higher level of security in the sandbox. Now I've seen it with other companies I've firearm many others will do this They will have a sandbox in place where piece of malware will come in It'll go dumped in the sandbox and it'll be run to see if it implodes. If it doesn't implode, then it will be moved on. Now the bad guys have figured out how to get around that Obviously they just put timers on things and so forth so that when it blows it up in the sandbox Hey it works no big deal. And then it moves it on and then it blows up and does bad things But the sandbox is a place where you can, things can go nasty and you don't care except for when their cats go in there and use it as a litter box. That's usually not so good. Anyway, the moving on example is only a specified systems can operate against a specific database. Any system outside the scope are not allowed So again, You're a very specific system It can operate on that database It can operate in the sandbox, but nobody else has out. Is allowed out inside the sandbox that is not supposed to be there No chilled. from other places…Now bounds and process isolation What does this mean Well bounds are defined processes that are given authority to operate. They can be many or few So again the processes that are in place you define these bounds right? Now obviously more is not necessarily better. Especially as you're dealing with the Colonel and other things but one of the aspects around this is the unit user, the Colonel and the administrator These are specific processes that are given access. And authority to operate but you have to create these bounds to, to define what they can and cannot do. The operating system memory and hardware These are process that would be defined. Bounds defined right. You operating system this system can use or this. User can use this memory This one can this one can do it And hardware typically the Colonel can do it almost all those places I should be able to do it in all those places so that those are aspects that you're going to have to, that will be defined for you in most in most situations. Now an example. My malware will utilize errors in these bounce settings, and then it will go and start mucking with stuff And an example would be kernel manipulation So if your bounds are not set correctly, to get to deal with the Colonel and you have users that can get access to the kernel, then it will go and flag it will. There'll be able to mess with it and if they mess with it and then for the Colonel, as we talked about and TCB, they will own everything. Now the key around all that though is is that if you have a product such as EDR which would be endpoint detection and response or recovery of response, That would note a lot It wouldn't notarize That's not really a good word It would utilize the or understand if someone was to manipulate the kernel and then trigger on that. So again that's why these these end point detection products are really really valuable. Now process isolation this ensures that only affected specific memory locations or only specific memory locations are affected And it's a central part of a stable system. If you don't get into process isolation, What'll happen is then all these processes are running all kinds of goofy stuff and then it'll crash and cause you all kinds of issues. Now it also prepare. applications from accessing memory from other locations. Cut paste Copy. All of these will be allowed to transition And so therefore it's important that as you're dealing with process isolation that you, you do make this. Peace Very limited. As an example you got cut paste and copy. Those are processes that would be isolated. If you don't do that then you can use these functions in many other ways and, and hackers can utilize them outside of their parameters And then that will be bad. And they will try that They try everything. And then another way would be macros easy to kind of run outside of defined parameters And then you get all kinds of manipulation occurring of these macros with biohackers or attackers that are causing effects to your environment. Okay That's all I have for CIS is P training Let's get into those exam questions. All right. exam questions domain three. All right So this question is going to be talking a little bit about confidentiality integrity and availability. All right So Fred recently received an email from bill So bill got an email from Fred saying Hey you're awesome I like you you're you're like me Yeah we're good Let's go out and have do some fishing and go have barbecue. No that's not what he said but that's what I just ad-libbed no Fred recently received an email from bill in his inbox. What goal would need to be achieved to ensure Fred that the email is legitimate and it has not been spoofed. We got confidentiality. Non-repudiation. Integrity. Availability. Or one of those 3, 4, 5, 1 of the four. Okay. A B C or D So a is confidentiality B is non-repudiation. C is integrity. D is availability. The answer is B non-repudiation does not allow the sender to transmit a message. And then to deny that it was sent by them So that's B. And so yeah, I kind of fed to you guys It wasn't about CIA It was actually about non-repudiation so gotcha. Bottom line though is not a pre repudiation is the goal So you want to be able to be able to repudiate So someone says I wasn't me I didn't do it as repudiation. So non-repudiation would be the negative that, that does not allow the center to transmit the message and then deny it was them And so that's what you also want to do from maintaining your systems is you want to have the availability for. Non-repudiation from a hacker and you have logs that are taught lockdown that people can't get access to You want to have the ability to, to basically be able to restrict people from getting access to systems that they can't get act They don't need to get access to…Now quite next question What is the falling as it relates to the trusted platform module which of these as it relates to them is true. A the TPM installed within hardware is much slower than the software variant. Be the TPM does not store the crypto keys for the system. See. The TPM is responsible for storing…and processing the crypto keys for the system and can be in software and hardware systems. Date. All of the above. all of the above. Okay. And the answer is…C the TPM sole purpose is considered the trusted source within the computing system and will store and process cryptographic security keys. Full disk encryption will store the encryption keys in this location. Now I didn't go over this in the TPM but it does do that The trusted platform module we'll go over and deal with the encryption and crypto keys and it will store them for you. So that is we'll talk about that in another. Uh domain or another podcast but it's basically that is the domain of domain three You'd be dealing with the TPM. So again the TPM is responsible for storing and processing that crypto keys up for a system and can be in software and hardware systems, hardware like firewalls and. Switches and stuff like that. Okay software like your software.
hon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Security Architecture and Engineering) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Trusted Computing Base (TCB)
· CISSP Training – Manage Engineering Processes Using Secure Design
· CISSP Exam Question – CIA / TPM
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Tech Target
https://searchsecurity.techtarget.com/definition/trusted-computing-base
Wikipedia
https://en.wikipedia.org/wiki/Trusted_computing_base
Wiley
Transcript:
Hey y'all is Shon Garrigan was her new cyber risk I hope you're all having a wonderful day today It's a great day in Wichita Kansas A Heartland of America. Basically smack dab in the middle of the United States So yeah there's pretty flat here it's pretty hot here but it's July 8th. Hey just wanted to go over We're going to be talking about in our site. OSI CISSP cybersecurity integration. Data communications. And then on our CISSP training where to get into implement secure communication channels. And then in our exam question where to get to point to point, it's not from like point a to point B it's a different kind of point to point. And then the OSI layers. All right before we get started I want to just throw out a plug there for my C I S S P training that you can find on youtube.com. You can check it out there at a Shawn S H O N Gerber. And I have CIS. training CISSP certification training You can find specifically on YouTube or you can go to reduce cyber risk.com at CIS slash C I S S P dash training at. you'll take you to the UME links as well So you check it out It's a lot of great information you're going to have there, all the domain stuff that you're going to have for as it relates to the CIS. P exam. To properly prepare you for that exam It's a great way to augment your training. And as you well know, you to me has some great deals as it relates to training. especially as for what I got So. Some really good things. Also all my CAS is P training. the various domains will be updated on a weekly basis Now some domains may be. Updated one week and then another domain the next week But they all all of my training is updated on a weekly basis So. some great things that are coming out there as far as the CISSP to help you be successful and pass the exam…Okay So the CIS is P integration This is from the InfoSec Institute and we're going to focus on objective four dot three which is implementing secure communication channels. According to design. and the topic will be specifically data communications…Now as you're dealing with different communication protocols we're going to you're going to hear some different terms and it's important to understand what these terms mean. you'll hear these terms thrown out like SSL and TLS and all of that, not TLC which is tender loving care It's different It's transport layer security Yes Security. Now the SSL is secure socket layer and what this is it's a standard security technology to create an encrypted link. it what it does it ensures that data is pat that's data's past remains private. It means specifically for private to individuals. And it does not go out to anybody else And that's the whole purpose of it right Is to have the SSL to protect your data and to ensure that it is private from other people looking over and stealing your information. It is also considered an industry standard to protect online transactions Now. SSL has been moved on It was it's still considered a industry standard. However the new version of SSL is what we call T L S I which is transport layer security. And they have TLS version two as well as one of the key points that are out there. But it's, it is the newest version of encryption of TLS is, and it utilizes symmetric crypto cryptography. basically there's two layers as a TLS record and a TLS handshake. and those are the aspects around the security but so you'll hear a lot of the synonymous…where you see third grade education. the SSL secure socket layer is being used synonymously with TLS, but everybody has moved on In most cases if you are dealing with the next level of security is around TLS and it's the next area. I said that twice. I know it's kind of not really cool but anyway did I did just did. All right then there's another product out there called swipe which is your swipe IP security protocol. and this little S little w capital IP and then he you got to love how they'd make these fun little things Swipe. it provides confidentiality integrity and authentication of network traffic. it does not however handle policy and key management. it that has can handle outside of the specific swipe protocol. so that is those just specifically swipe encapsulates each IP data gram Okay To be secured with inside the swipe packet. So basically the IP datagram which we talk about in the different levels of the OSI model and so forth the IP data gram will be secured inside the overall swipe packet And that's where it encapsulates it and wraps it up in a pretty little boat. But that is the swipe IP security protocol…Set is a secure electronic transaction and what this is at communicates. It's a communication protocol standard for securing credit card transactions…Set is a secure electronic transaction. and it's a communication protocol standard for securing credit card transactions. and so that's what you'll see typically within when you're using credit cards now, as in the United States. Many other countries have just got back from China They don't really use credit cards They use their product called we-chat and or Ali pay And it's the same concept but they it has to be tied to a bank account specifically within China. And but it's what they utilize at least in the United States for secure electronic transactions. it has a set of security protocols and it's set user provides electronic wallet or digital cert that basically puts you who you are. and if that's kind of how the whole. Basically ties you to the individuals through that digital SERP. the digital certificates and signatures are amongst the purchasers the merchant and the purchasers bank. It's just kind of how they the. The digital signature works between them all. But that is utilizing the term. Are the protocols security protocol of set secure electronic transaction…Then there's pap which is the password authentication protocol. Now this is a password based authentication protocol used by point to point protocol or PPP through triple P. you deserve Pippa PPP. it's considered a weak authentication scheme and it's not one that typically is used as much, but it still is used It's just not. you wouldn't want to use it for your main authentication or your main type of authentication scheme that you're working with in your organization. It does transmit un-encrypted passwords over the network So hence that's kind of why it's not utilized as much. there are some others which is the extensible authentication protocol which is EAP. You have your secure remote procedure call which is S dash RPC and then chat which is your challenge handshake authentication protocol. Now as far as the CISSP is concerned I remember seeing all of these you will you will come to some level of understanding around all three of these pieces are all these various levels authentication protocols And so. protocols. They are on the CISSP exam. Garrone T now. Some may not be on it Some will be on it but you do they do cover these in different aspects on the CISSP exam. So it'd be prepared for that…And understand how they are used. the key point around this again in the exam is that you will see they utilize these in ways that are kind of designed to trick you up a little bit and they'll utilize the pap aspect and they'll say password authentication. Protocol is used with set and you go oh yeah yeah PPP or no eight pap Wait. I said oh no And you'll make a mistake So, the goal is is to understand all these protocols and how they all work together. Okay So that is what I have for the CISSP integration And that again was from InfoSec Institute. Let's roll down to this CIS JSP training. Okay And the CISSP training we are gonna focus on objective four dot three implement secure communication channels According to design. Okay Voice. voiceover digital is quickly becoming the standard from teams to Skype to you Name it. Voice is becoming the standard over the digital platform, but this the old business of private branch exchanges or PBX's is going away And that's your typical phone routing switch switches that are out there. Those are all going away to a product called VoIP. Which is by far more flexible and secure. in most cases, Yeah I mean flexible in the fact that sometimes Skype doesn't work so well. But VoIP is a TCP IP network connection And it's configured to be simple, to the more complex depending upon what level of encryption and where that is protected at now standard phone conversations does have encryption built into it. these these do occur. However it depending upon if you want to have secure voice, like in the case of the military there's different levels of, infrastructure that needs to be put in place to ensure that the communication channel can be clear from. somebody over eavesdropping and con and collecting the information. Now there are some problems associated with VoIP A caller ID can be spoofed That is a possibility, and they are susceptible to denial of service attacks Hence the reason is they're on an IP network So if they're on an IP network they can be. denial of service They can basically be that they can flood gates with the network connections with nothing but garbage and therefore your voice connection will go down. Man in the middle. Issues can occur with VoIP and the traffic is not that is not encrypted can be deciphered. so you can listen to these information these conversations. If it's not encrypted. Now in many cases this stuff is encrypted but there are situations there are protocols where it may not be. So therefore you need to be aware that voice is like anything else Now if you do standard PBX where it's right over the wire, those can be listened to as well but they are not susceptible to denial of service tax. Unless you take out a switching environment then yeah Then your voice. You're basically you're. One heart. The line the phone line goes down. That's it? He goes bye. Bye. Goodbye. The next is PBX fraud What does that mean Well basically in the past it used to be where they would do it would take advantage of long distance phone calls and they would call this. Freakers And now I say that because it's still. We usually may have in the CSPs cause it's still a valid attack. And you deal there's there still are lines out there that you can utilize from a freaking standpoint. But it basically was designed to gain unauthorized access to phone systems and they would rack up toll charges for other peoples, that would try to be utilizing Unless your international phone calls or whatever they would then rock up phone call charges for them. This is becoming less and less of a problem because of cell phones and those that capability but it still does exist. that to limit this you'd have logical or technical controls on the network specifically to keep this and this would roll into administrative. that you need to have in place. you want to also avoid securing These are you don't want to avoid securing these older systems. You want to look at what are some of the ways you can secure them and protect them from these type of attacks from a PBX fraud attack. So don't just say well they're all So nobody's going to mess with them I'm not going to worry about it. That's really a bad idea in today's world where everything's interconnected more and more than ever You can be vulnerable to any type of attack that may be out there So again PBX fraud is still existed It still does exist and people still do it, but it is come down quite substantially from the previous days of like, Mitnick and all of them…Multimedia collaboration what this is is working on projects from a distance So now if you are anybody in the cybersecurity space or in it, you realize you know what, there's all kinds of collaboration that occurs through multimedia uses. from you incorporate email video voice you name it It's all there from a multimedia stay. and everybody does it. so therefore you must consider all of these voices security, all of these channels to secure, which becomes a very daunting task as a cybersecurity professional. you will see that this is a problem and it's something we struggle with on a daily basis. these remote meeting concepts and capabilities These are all something that you'll have to go through. And as you'll see they understand that from a multimedia standpoint it is everywhere. Now remote meetings this allows for interacting with remote parties which kind of comes into the collaboration space And it's important that you be able to do this in today's world because guess what? It's everybody's shares it and everybody's working remotely and they're working from dis I can't think of that big $10 word but from remotely geographic remotely separated locations Yeah There was a probably a really cool $10 word that would work well there, but yeah I couldn't think of it. now there's some key concern security considerations As you're dealing with this strong authentication activities are logged and monitored and open and encrypted. So those are key aspects you need to be aware of as you're dealing with remote meetings. And also understanding who's listening in And if there's somebody that logs into your remote meeting, that you don't know who it is, you might want to boot them out and tell you can figure out who they are because guess what? A lot of people drop in I used to do that We would drop in on phone calls. conference calls but see us before Skype where they'd have a phone number pop up. And so therefore they wouldn't know who we are We would just log in and listen. Instant messaging What this does is this allows for real time chatting right So this is the ability for you to have real time chatting through a digital media platform And everybody, everybody does. Instant messaging at some form or another it could be from your, when you're on Facebook it could be in various aspects but allows you to have instant communication back and forth through a texting environment. Now it is possible to do file transfer through instant messaging. And so from a security professional you need to be aware of that And if can you send voices can you send pictures Can you do all of those aspects can be put and they're all done. in potentials. On this security environments. sending social security numbers or PII personally identifiable information over texting is a bad idea Typically. there's some key security considerations that you need to keep in mind That's careful communications on what you put in a text Cause guess what? If you put in a text it's got to come out They always do They never ever not come out They always do. you also need to have records management Cause these records they go everywhere and you will run into them They will they they get legs and they move. So understand the records aspect around this. Also you need to limit your encryption as it relates to. or it has limited encryption I should say. The the aspect of text messaging, some, some text messaging depending upon the application you use does have a little bit of encryption involved with it or does have encryption. But in most cases these do not They the only encryption they have is the encryption through the telephone network the CDMA network. In most cases there are no. encryption from a texting standpoint. many are public services such as slacks Hangouts et cetera. And so when you send this out your text it's going to the cloud which everybody it goes to a server which everybody potentially could have access to. At least at a minimum the administrators have access to it. So there is no privacy There's very limited to new privacy when it comes to texting Snapchat all of those those things do get legs and move. So as a cybersecurity professional it's important for you to make sure that you teach people that this is a situation and working on your CIS. Especially you need to understand how that all plays into the overall game…Security and the email. Do you need to address this with your security policy There are some acceptable policies for email that you need to put in place. And as you're looking to secure your email, there are ways to do this through PKI which is your public key infrastructure You can get digital signatures on your email which will help protect it. but you also can have access controls Do you allow all old w a like is your, outlook web access you and your basically your online capability to your email? Do you have multi-factor in place on your email That's available online. and so those are key considerations And also as you're dealing with privacy around email it's important to consider. How do you protect your company's email as it relates to GDPR? So it's important that you have that in place as well. So you as a cybersecurity professional working on your CIS S. P you need to understand V. Cognizant of these different aspects around privacy. And and what you should do as far as dealing with the email, also understand the security person You should not have access to email You should have or people's emails You should have that all run through your legal and compliance teams If you have them. if not and you are the person then you definitely need to run that through legal before you do anything along those lines. as your backup and records management keeping emails until the apocalypse just a bad idea. so you need to consider getting purging those emails when it's appropriate, do not keep that stuff you're getting from legal considerations It's important to understand that you don't need all that forever. now if your company had puts it on legal hold where you have to maintain it well then obviously you have to keep those emails for whatever reason. But for the most part you you need to make sure that you don't keep any more data than you absolutely have to because, because storage is so cheap everybody keeps everything. It opens you up for a lot of different issues especially legal and litigation issues. so just kind of keep that in the back of your cranium…As we're looking at other email security solutions you need to understand the secure multipurpose internet mail extensions S mime. And privacy enhanced mail which is another term which is PEM. And then you're pretty good privacy which is PGP which you'll see with from an encryption standpoint for your email works typically for most of those providers that provide you some level of. email protection The PGP is typically used for the third party types. and S S. Mine is used for the more like your outlooks and so forth. And then you have your sender policy framework which is the F S. F those are again other email security solutions that you need to be aware of for the C I S S P…Okay C I S S P exam questions domain four…All right So in this question we're going to be talking about point to point. What layer formats packets from network layer for transmission and is commonly used point to point protocol and the integrated services digital network ISD N. Session layer. That's a…data link layer. That's B. Application layer. At sea. Network layer. That's D. And the, and the winner is B the data link layer is responsible for formatting packets from the network layer to be used in the transmission of data. So yes as the data link layer that is one that puts them all together And when you're dealing with the OSI model the seven layer burrito and puts it all together to get it shipped out the door. All right So now this question is about the OSI model. What layer which will you almost last minute about those I model too. Well what is the layer three? Of the OSI model…A transport layer. B data link layer. See physical layer. Or D the network layer. And the answer is D the network layer is the layer three of the OSI model situated between the data link which is layer two Okay So you guys see the video. Got layer two or I'm actually a layer two is down here And our toe, and then you have layer three which is the data link layer And then you have transport layer which is above that. Okay. That is the different models of the OSI. Seven liter layer burrito. Layer three of the OSI model is the. network layer. All right…All right That's all we've got for reduced cyber risk podcast today And we are going to be moving on to Hey I'll see the next podcast coming out next week. But the links today with ISC squared training study guide Quizzlet InfoSec Institute and Wikipedia. All right Hope you enjoyed this podcast Also remember that there's training available for you@reducecyberrisk.com. slash C I S S P training or you can check out my videos on YouTube amy.com which you will get a great deal by going to youtube.com and you'll get updates. from what's happening within the CIS SP on a weekly basis. All right Have a great and wonderful week We'll catch you on the flip side See. Thanks so much for joining me today on my podcast. If you like what you heard please leave a review on iTunes is I would greatly appreciate your feedback. Also check out my CA S P videos that are on YouTube. Lastly head over to reduce cyber risk and look at the cornucopia of free CISSP S P materials. Available do all my email subscribers. Thanks again for listening…
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:
· CISSP / Cybersecurity Integration – Data Remanence - Rainbow Series
· CISSP Training – Protecting Privacy
· CISSP Exam Question – Sensitive Data / Destroying Hard Drive
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/\
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Misc.:
https://thorteaches.com/cissp-certification-rules-laws-and-regulations-oecd/
OECD
http://www.oecd.org/sti/ieconomy/oecdguidelinesontheprotectionofprivacyandtransborderflowsofpersonaldata.htm
Rainbow Books
https://fas.org/irp/nsa/rainbow/tg025-2.htm
GXA
Transcript:
…Hey all is Shon Gerber again with reduced cyber risk And I hope you're all having a wonderful morning. I'm having a great morning My kids are heading off to, to camp this today So I am extremely excited about that They have, I have five children still at home and they are all going to camp. and it is an exciting exciting time. I don't know if any of you all have children might be living out there, but anytime that you can get away from the kids or the kids can get away from you. It's a wonderful blessing And you think those your lucky stars for having those little blessings Because, yeah it's going to be a super quiet in the house and I'm pretty excited about that because it'll just be my wife and me and the dogs It'll be pretty awesome. so yeah, that's just had to give that a little bit of a tidbit out there about that. So one of the things that we're going to be talking about today a lot of great cybersecurity aspects that are going to be dealing with training. And we're going to have a talk about cybersecurity Integration is going to be the data remnants and rainbow series. We're going to be talking about data remnants as the CIS S P training and what you need to understand. for the CISSP exam. And then we're gonna talk about some CIS S P exam questions that are around sensitive data and destroying of hard drives. But before we do one of the things I want to mention is the C I S S P training courses that are available. to you just for individuals who listen to this podcast. You will find out that there are some great training courses that I have available on youtube.com. that are around the CISSP. And they actually focus on all eight domains of the CISSP. So the training you see here you're going to get that in on the steroids They're going to be tons of it. and we'll go through each and every domain as it relates to the CIS SP from domain one to domain eight And you can get all of those as you well know. To me they're bargain basement prices That are pretty amazing. the the cool part about that is that by going to the link of reduced cyber risk.com. dash training. You can get those that link all in one spot from basically domain one to domain eight. And that will take you to. you to me.com. Where you can then purchase those, those courses But again you get lifetime access. It's an incredible opportunity If you just want to go to you to me or to go to reduce Avaris. Dot com CISSP training. those are some great opportunities for you there. All right. Well lets us roll on into the training today. Okay So let's CIS S P cybersecurity integration training We are going to talk about the NSA slash N C S C S Brainbow series And you've heard me talk about this especially as you're dealing with the CISSP. There's different rainbow series books that you will deal with. and one of the main questions they talk about in there is what what is it a specific book and why does it do what it does? what what is the aspect of it? And we're going to kind of go into a couple of that right today But the interesting part was I had gone through and been teaching the CIS as P for awhile and, and understood the rainbow series And I remember being in cybersecurity now for as many years as I have basically since 2001. you you realized that the, the rainbow series are an important aspect. Of the overall picture that you know especially at the beginning how this whole thing worked, but I never really understood where they were and and you can get these all online in the past They were in actual books that you would get because that's how old I am You would actually have a book not online. But now they're all online that you can go check them out on at, at at the NSA. and that's basically F fast.org, IRP NSA rainbow and so on and so forth And they will walk you through You'd see where all the books are at. But there's some key terms we're going to focus on today And this is around, dealing with. Data remnants And that's the whole aspect of it I kind of wanted to keep all of these domains as we talk about cybersecurity and the integration and the different, websites that are out there for cyber security. I want to focus on the specific domain that we're in and we're dealing with it Cause it, I was kind of jumping around a little bit I thought well let's just keep it focused on what individual domain we're dealing with so that it makes it a bit easier as your say. this information. So the key terms we need to be aware of is one first one is clearing and this is what they call it removing the sensitive data from an information system So if you have some sort of data that's out there and you want to remove it this is how you clear the data from that device. and there's some different terms that you will get to know quite frequently. another one is purging and this is actually removal of the sensitive data from a period of processing So what they talk about there is it actually removes it from the processing. period that's occurring on that device that hard drive that disc, that the information is being stored on a declassification is removal of security classifications of a subject media. Now in the previous life where I dealt with the military we had unclassified. You have your classified networks you're on classified networks You, when you had classifications your secret top secret and so forth, you had to remove that security classification. If you want to be able to use that data in spaces that are outside of what they were designed for. A good example of that is like in the case of the Mueller report in the United States they had, those are classified documents in some respects. Because maybe they give out information about, individuals in this report So what happens is is it has to go through a process of declassification before they can do that. And and so. Like for example if I get a document. And you know I'm, I'm the author of even can come down from a declassification standpoint. If I'm the author of a document I can classify that document So I can say it's classified secret. then what ends up happening though is I cannot be the one that says I'm going to declassify and I'm just going to remove this the security clearance off of that. Cause it was a reason I made it. At classification of secrets So therefore it has to go to an individual who then has to review and say, okay yeah if you remove this information it is would be unclassified or parts of it would be redacted. And so therefore that's what the declassification process is It's a it's a whole process a whole way of removing that information. coercive…okay See I can't even say that course activity My third grade educations coming out. yeah, that that word. It's measured in This is another word that I can't handle. Oh or stats or steads and it's basically don't oh E and this is a property of magnetic material used as a measure of the magnetic field. Okay So if you're geeking out that's what that is It's a V they call that oh eight Now I'm I'm geeking on you a little bit here. just because one as I'm teaching this I also have learned it. I did not really know and understand how that was all set out So it's like oh okay Well then now that makes more sense versus just going. Yeah you need to purge it You need to remove it. So this is a little level deep detail that you may be going, why are we getting into this Well it's just to kind of show you a little bit more around It's not just, Hey I'm going to clear it I'm going to purge it and I'm going to declassify it because those are key terms You'll need to know for your CISSP. But when it comes right down to it there is a little bit more backstory behind it…Now I knew I do know that that we talk about in the CIC. the different types of tapes and there's a type one type two type three tape, and these are magnetic tapes And these have a coercive the civic duty of the mat type one is three 50 O E. The type two is 3 51 0 8 to 7 51. And the type three is above 75 or 750. I said 3 51 Yeah 750. So basically it was 3 50, 3 50, 1 to seven 50 and seven 50 and above. And those are the different types of tapes that are available magnetic tapes And again this is like way old. If you're talking people like me but, in many cases he data centers still have magnetic tapes that. I information is backed up too. So you need to keep that in mind especially as it deals with destruction how do you deal with that And it also comes down to the the tape that. the magnet magnet Tivity of a hard disc drive. Now what does it…well that is a device that generates a magnetic field for deep browsing magnetic storage. My media, what does that mean? It basically puts this quote-unquote force field and it you put your magnetic tape in there and it's got these humongous monsters magnets. That then just basically rearrange all the bits and they no longer are in a logical path that, that allows the device to be able to point to them. Cause they all have pointers And if you have a certain file it points to a certain place on the hard disk drive If you're dealing with just drive. And the D Geyser. We'll nuke that it will totally mess up those hard disc drives Now, as we have SSDs come into play the D Gaza really has no factor in any of that So then you'll have to get into physical destruction. but bottom line is that's where you're still a lot of magnetic tapes that are out there. That you need to be concerned with and worried about. And so therefore that's just something to consider. permanent magnetic decomposer. this is a handheld permanent magnet that can be used to dig cows floppies Yes they are floppies and they still exist. And be you'd be surprised There's still people using floppies. I don't know how you can use them that much but there are probably plenty of out there that still use a floppy drive. And if you're not familiar with that is it's like a little square. Plat piece of plastic it used to be plastic It was just kind of the magnet. Magnet. It was the. The spinning magnetic drive per se on. Pacey flimsy piece of…plastic that would hold the data and it would just go…That's kind of how that worked and it made those specific noises too Pretty scary. but that that was the old way they used to deal with floppy drives and they also can deal with it on Desplat. Which is basically your hard drives and magnetic drums et cetera So it was basically a handheld decals or that you could go by and walk by and you nuke a hard drive. now there wasn't used obviously to do gals tape the best thing to do with tape. Honestly it's shredded Just destroy it. it makes it a whole lot easier that way. But the permanent decals or wood is just a high powered magnet You can be Magneto from the X-Men and just nuke. Your stuff. Bottom line though is on. Don't get close to anything You don't want a new cause if you do it's done You're not going to use it again. So that is a permanent magnet decomposer. So now if you're looking at different mid risk considerations for storage and media reuse these are some key aspects for you to keep in mind. the you need to understand the destination of the released media. And where you plan on keeping it So if you plan on storing it. What are you going to do once you release it Where's it going to be stored And it's going to be stored in a salt Mine is going to be stored in a warehouse. where where's it going to be stored Because all of those things will affect how well the data is kept. for an example if you're dealing with. heat and age you know, those all of that will age the device if you keep it for a long period of time that will cause issues with the data. So all of those things will cause you some level of grief if, as it relates to your maintaining your information. mechanical storage of device equipment failure If you have, as you keep these things online. What'll happen is the mechanical devices will be we'll have issues. they will have problems and they won't be able to last a long period of time So your storage and where you keep it. We'll also cause issues with mechanical failure and bottom line is if you have these old devices, they also don't, they you can't get replace them So you may have the hard drive but if you don't have the chassis and. All of the operating systems that go along with to run these old systems. That also is a factor you need to be aware of. there's also a comment that your storage device segments not receptive to overwrite And we'll talk about that here a little bit further about not receptive to overwrite What does that mean? but they basically won't You do you can't it won't override it at all It says Nope, I'm done You can't mess with me anymore And you can't make changes to it. overwrite the software and clearing and purging So again you got to have find a specific overwrite software that will do this clearing and purging for you. those are some things to keep in mind As you, as these things get older, you got to have the older software to do it New software will not work with, these old systems So you'll have to keep that So there's a lot of legacy stuff You've got to keep in mind by keeping these older data. the asshole as time goes on you may not understand the data sensitivity of it It sits in this big box for years. Is it sensitive Is it pictures of my fuzzy kitty? Or is it pictures of top secret nuclear science projects which you hopefully wouldn't keep in a box somewhere but you never know people do those things. so again not understanding that to hold dense data sensitivities especially if you're keeping it for a long period of time. And then improper use of degaussing equipment. I struggled with this one but knowing myself when I was a teenager I'm trying to think what would be one thing that I would be using improper housing equipment and probably I guess, Hey let's run through the magnetic field and see what it does. I mean, I guess that's what, but basically going and playing with your friends going Hey I'm Magneto watch out for me You know, those things. I just struggle with why you would use it improperly because you're playing with big monster magnets and they're kind of in the past they've been pretty good size. And but now they're in a box more or less that you just stick the device in a box and it nukes it. But yeah I laughed at that one improper use of decals of equipment So do not know horseplay with the housing equipment. That just goes bad. It goes bad for everybody…Now when you're dealing with not receptive to overwrite some the storage devices segments are not receptive to this And what happens is is that they're unusable tracks on a disc drive. And I come back to disc drives again because you know we all know that they're going to SSDs are more prevalent within our environment, but there's still a lot of disk drives that are out there that are being used in servers. When you can't overwrite the segments it becomes very difficult to wipe. and so therefore if it becomes difficult to wipe, how are you going to deal with that? so you need to check these devices for unusable or damaged areas before uploading the data and making sure like one good thing we've talked about on reduced cyber risk. Was the Amazon glacier and how you could potentially put all of this data in the cloud. But if you run into these issues of overwrite challenge. one you go okay well I'm going to do that I'm going to upload it to the cloud Well I find out I have these unusable or damaged areas. How you going to deal with that And I will put a little plug out there for spin right by Steve Gibson It's a really good product to help damaged areas within your device drives. I highly recommend that if you're going to be used if you need to get the data off of there. but also keep in mind from a cybersecurity standpoint if you can't get the data off of this, and if it's sensitive you need to really make sure the best thing to do is. I mean the housing is important I think it's it's good. And personally I think it's probably step one of a two-step process especially if you're dealing with sensitive data, is that you dig out the Dickens out of it and then you shred it. or you know what just shred it and be done with it And you don't have to worry about the housing It. But the bottom line is is that if you have any areas that are. Damaged. and they do not give that DCD aware that disc drive away because what'll happen is if you do that you are now running the risk that someone could get access to that data. you never know if the technology's out there They may be able to get access to this damaged or unused spot. if it is unreceptive again, Tried to gouging re-imaging the device or re-imaging it? if you did gals that you, you knew it you can't really use it anymore but those are things you need to consider. If you the segments do not have the ability to overwrite. Okay That's all I have for the cybersecurity integration Let's roll on to the CISSP SSP training. Okay This is domain two asset security and more topic is going to be about protecting privacy Two dot three. Okay As well the objective is two dot three a protecting your privacy and the topic on this is data processor. so we're going to get into a lot of these different aspects and a lot of this falls into what GDPR talks about, and if you're not sure what GDPR is the general data privacy regulation that's put out by the European union. As it relates to data privacy and maintaining it And that is, it's a pretty large. Regulation that focuses on, managing. the data privacy of individuals in the European union. the big thing that made this thing happen to come into play there was safe Harbor in place before this. but what moved it in this direction was the fact that they wanted to have better access and better control of data privacy. Now it's interesting because you look at data privacy from the EU is one direction which is more or less focused around the individual. And how do we protect the rights of the individual that European union citizen? And then you go to the opposite extreme where you have the Chinese government where it is the privacy of the state. Now the privacy of the people is important to the Chinese government obviously, but it's more important to the privacy or the understanding of the state and the collective. And then you have United States was really kind of in the middle It's kind of all over the place. So you get different states in the United States that are more private than others And so that adds com. Convoluted T convolute com. Yeah it makes it all messed up. Get you that third grade education. but you. it ends up messing things up because you have different states that have different requirements. So bottom line is is where this part is going to be around GDPR. Now context is everything as it relates to processing data, a system to process data or is it looking at the GD PR data processor? Processor is defined as this, a legal or a natural or legal person, public authority agency or other body, which processes personal data. Solely only behalf of another data controller. So what it really basically comes down to is you have an individual who's a data controller that controls the information that from within an organization. You can outsource this the to a third party which would be a data processor. one thing that you can see as this as an. always works is so you have a. A third party. Processes that does payroll that would have personal information about the individual, from pay name address all those things that you considered as. personal information, you actually that you consider just an IP address of the computer you're using as personal information. So they would have all of this data. So this, this data processor can be defined as an individual person. that within your organization who has the authority to do this or it can be outsourced to a third party. And so therefore you need to be aware of how does that affect your company How does that affect. what you're doing and then how do you want to make sure that you document that correctly, but a data processor. Happens quite frequently. you just have to decide is it somebody internally Is it externally or is it a combination of both…Now we talked about GDPR One of the big aspects of them making this thing have some teeth is the fact that it is a fight You could face fines up to 4% of global revenue. Now 4% is a lot of money especially with you're dealing with a corporation. who has a global presence? you know and even if you're small company so. it to this way So if you're making. A hundred thousand dollars a year right? So a hundred while hopefully you're making more than that but let's say it's a million dollars a year. So if you have a million dollars a year, 4% of a million dollars is a what is that I don't really, I say I had to do math in public I have to think about that for I did it So maybe what $4,000 No it'd be. 1%. 1% of a million dollars. Okay 10% is a hundred thousand dollars. of a million, so yeah 10% was a 4% would be a $40,000 right Yeah $40,000. So it's $40,000 hit. And that's if you're doing a million dollars in business now that, that a million dollars of business. You get a $40,000 hit your margins Aren't very high. That could be DECA. So let's put it this way So many businesses are only making if I say. Many. The average comes into. If you're a good business making big money. and you're you're blessed. You're probably making about 8% margins on your product. So you know anywhere from six 8% is what the typically what I've seen again I'm not a finance guy I'm a cyber guy So what the heck do I know? But I do know that typical margins from a business, some businesses have way higher margins than that but let's just say it's a standard businesses making between six and 8% of their margin. Well if you take an 8% of your margin if you're lucky to get that, then you could face fines a 4% So you could also take a 4% hit of your overall profit. That is huge hat 50% could be put in paying out these fines. so it seems like not very much but when your margins are pretty tight it's a lot of money. so an example I have is if you got a billion dollars USD globally, that's a $40 million fine. That is huge. That is a monstrous fine That would cost you gobs and gobs of money. Now as you're dealing with the EU and us privacy shield this will again was previously safe Harbor. there's organizations can self-certify saying that they meet or comply with the privacy shield requirements and principles. so therefore yeah. can in the past you could do that You'd say Hey I'm doing it I'm saying I'm doing it. If you want to audit me audit me and then you can find out if I'm actually saying doing what I'm saying. and but that's that was the U S us privacy shield our EU us privacy shield. There were 16 principles in total that you need to vow to uphold at least seven of them. And so therefore you could actually get away with not upholding them all. but those are the aspects that you had to say that I will comply with that And then therefore they had the right to audit you And if they audited you and you weren't doing at least the seven. Well then you would have to pay some significant fines for doing so could lose that status, all of those pieces And then if you lose status what that ends up happening is is now you can no longer share data between you and the EU. so if you're in the United States and you're a multinational, you've got business in the Europe and in the United States, you can no longer share data between you and Europe. that's just not good. And so therefore you want to make sure you comply with the requirements as much as you possibly can. At least seven hours at 16…Now there's other key GDPR terms and one is pseudonym Meninism see. Third grade. the sooner, yeah. I'm not even gonna bother saying that but it's basically using pseudonyms. And what it comes down to is as you have, like for an example bill Smith is patient 1, 2, 3, 4, 5. and it works to op use obfuscate data So you know that in the records. Bill is patient one through five And but you have to have a key or a cipher to be able to determine yep Patient 1, 2, 3, 4, 5 is bill Smith. but that's a really good way to suit a man randomized individuals and their. their names. And so then you can hide the actual patient data itself. Another one is anonymization and this is basically removing all relevant data about the person or their identity. a good example of this would be data masking And so you'd be using in SQL table. So for an example you would say, input would be bill Smith 1 2, 3, 4 5 6, 7, 8, 9. for like in the case of United States it'd be a social security number And let's just say that would be a really bad way of identifying somebody by the way Don't don't do that. even if you're going to randomize somebody just just don't do that. the output would be then Jennifer Smith, 9 8 7 6 5 4 3 2 months. Okay. That is is good but it really causes lots of challenges with that so you have to have a cipher to understand how to reconnect the dots. And that's that's where you really kind of gets confusing, but it's a way to totally randomize or anonymized that individual you would not know who they are unless you have the cipher unless you have a way to understand and how to reconnect everything together…Now as we deal with data reminisce some things to understand around this This is how the data that's remaining after media has been erased. And we kind of talked about that briefly and the cybersecurity integration piece of this. it's residual data after a full eraser of disk. So if you go and you do a full ratio of it, and you wipe it there's still data potentially remanent on. that device. You have to have a way to how do you deal with that and how do you remove that? so that's the residual data after your full disc exposure. Now there are serious problems especially with today's tools that you can do Cause you can find out if you say well I'm just going to do the standard format. Start out star. the the size of these disks it will take you forever in some cases also, if it doesn't always erase the data you just erase the pointers of the data. So if you can go back and find tools that can go out and actually pull this data out of the disc. that can be very valuable So, this is why it's important that you honestly if you have any sort of sensitive data just Newcomb or shred them, that as a better and then run a hammer through them. I can't run the hammer through them putting a nail through them something like that. But it comes into data leakage and data loss You will get that by having data remnants. there's also ghost images on computers and CRT monitors If you're CRT. these are really old which is a cathode Ray too when they're the green kind of things. those CRT monitors. If they've had a burn in for a long time say the data hasn't it's just always like a display screen. It will leave on the photo. I can't remember how they call it but it's basically it's a phosphorus type. Front end and it excites it And when it does that it leaves an image, a ghost image on the monitor. if you're really old like me you've probably seen that. And so therefore what ends up happening is is you can actually have a data sensitivity that is exposed. Now I don't know how many more CRTs are out there and available to people They are an extremely inefficient way and they're very. The power hungry They suck a lot of power. So, but they are they do still exist I'm sure of it. Could you see him I walk into Goodwill in the United States and I see those in our the Goodwill's and area that they give away things to people donate devices and things and clothes, and then people can come in and buy this stuff And that money goes to, the underprivileged people. so Goodwill has a lot of time to see our team monitors in there that people have given away. but those things are like way old and they're they don't work that well but…people still use them So you understand that ghost images on computers…Now there's a process to remove it We talked about this a little bit earlier about degaussing again these are powerful binds to destroy the typical magnetic drives and they are important There's also the handheld to Gaza right That's you do not have horseplay, no horseplay with the browser Just don't do it. physical destruction These are the jaws of deaths and death and you basically run your magnetic drive through this and it chews it up into shredded pulverized pieces of metal. so that's a really good way to make sure no one gets it. and it's also highly recommended for yourself State drives run everything that you don't want through there that you don't want to exist. Run it through that the jaws of death, and it will destroy that stuff So it will it will destroy almost any media product out there. worst comes to worst get a hammer and beat the living Dickens out of it If you can't put it in the jaws of death like a sledgehammer and just smash it to pieces. Ah that's a good way to destroy it as well. when you're erasing it delete the operation This is basically a delete operation on the file or media type And what I said like I mentioned before, It really only removes the pointer or the file locations not the data itself It's just guessed How is the data how do you find the data through that pointer? So, racing is just not a bad not a good idea at all. recommend that you actually do some level of software to do a complete overwrite which will overwrite the ones and zeros to all ones. but when the size of the SSD or the size of the drives today these like mega terabyte drives, it will take for AVOR. To do that So. it's almost just as easy just to destroy the drive itself unless you really really really want to reuse it again…we talked about clearing This is an override process and there's ways that you can get a there's some great websites out there on how to clear it. and you can buy that software specifically for clearing those devices. Again I gotta be careful on again a one to two terabyte device. it will take a long time. to overwrite this process for the media to be reused. so you have to just decide is it really worth it or not? you can write it basically writes a single character over the entire disc and there are very various tools to do this purging more intense form of Clara media to be reused. what it does is it then writes ones and zeros like in like seven different passes. So clearing at one time is one thing and then purging it and basically writing over it multiple times. that's if typically in the government if we were going to reuse something what we would do. Is we would you do the DOD standard which would then in turn override it like seven times before you could actually reuse it? But realistically these things are so cheap today that Dennis drives that it's almost better off just, just shredding it and going out and buying a new one. just because you'll spend more time from an opportunity cost standpoint clearing these things then to just go ahead and shred it and start all over…Transporter data flows this is a previous domains around trans border and you're going to have more and more personal data is moving from nation to nation And, and so therefore this, you have to be able to manage it and to be able to understand how this all works. Well there was an organization that through that they came to a con consensus and is called the organization for economic cooperation and development O E C D. And there's the key provisions that are in there of these 30 member states that said to how we do transporter data flows How do you do that And then how do you manage that…this was issued in 1980 and I know back then 1980, the internet was pretty small it did exist Al gore invented it, but it did exist. And so therefore what ended up happening was, the the data flows were pretty, pretty tight, pretty small today's world man They are flowing everywhere Data does not stay in one location It goes everywhere. And so therefore the. These a lot of these laws are a lot of these thoughts are a little bit dated and antiquated, but bottom line. is is there are data. trans transferred border data flows around how to you maintain and manage the personal data…Now there's eight driving principles of the O E C D. And one is a collection limitations It's a collection of personal data should be limited and not be, get gathered and garner too much. It should be obtained by Lee legal and fair methods There's no. basically siphoning data back on people without a legal or without That a proper way of doing that. the data quality It means that it should be kept complete You shouldn't take snippets of the data It should be maintained in the wholeness of it. One thing around that is if people cherry pick specific like you can say just even saying news news media all all the news media do it in some form. Is a conversation may occur and they'll take a piece of that a snippet of that conversation, and it will be taken out of context and therefore it gives a married different perspective And you can do that with data, whether it's video audio or just actually written forms. So it needs to be kept complete and it needs to be consistent with the purpose how it's being used. purpose selection notification to the person, purpose or person around collecting their information You need to let them know that Hey, I'm siphoning off your data I hope you're okay with that. they need to be able to know that Yeah I'm taking it I'm copying it It's okay Right You don't mind. and again this is at the time of collected and for the specific purpose of why you're doing it…Use limitations they need to have consent of the person or the law of 40 authority to disclose data. how are you disclosing it Do you have approval to do that? Do you notice notify the data's used for purposes stated in a different manner than what you disclosed So I'm going to use them for my research project Oh wait Then I send them to the sun or the national Inquirer on something that you said Yeah that's not right That's going to go badly for everybody Just don't do that. security standards basically do you have reasonable safeguards in place to protect the data? And do you have openness? When you develop your practices and policies were ground the data. be communicated What are you going to do with it How are you going to manage it? what do you how are you going to share it And do you have policies to protect it? the individuals should be. Be having individual participation as it relates to what do they want to do? and especially as it relates to personal data how. Are they okay with their data going across transporter…And then accountability organizations are accountable to ensure they comply with other principles as well. When they're dealing with the cross border data transfers. Okay So that's all I have for the CIS is P training Let us roll into the exam questions. Alright CISSP exam questions domain two…Okay Here's a question for domain two. What is the most correct term When an administrator is removing sensitive data from a system before putting it back into a less secure environment? Letter a. Erasing, let her be purging. Letter C clearing. Letter D. overriding and the answer is. See clearing clearing is an overriding process for immediate so that it can not be recovered once it is quote unquote cleared. Now we talked about before, clearing is a very important part Now if you are going to be working on the DOD standard and you want to have to make sure the data's completely erased, then you could purge the data with doing multiple overwrites. But clearing will be sufficient. in many cases especially if it's kept within the organization. you can just clear the device Now if you're going to be moving the device. to a different location than you'd want to look at purging the system…Next question. What is the following is the most secure method of destroying data on a hard disk drive in HDD, we have formatting. We have degaussing. You have destruction. And we have deleting what is the most secure way of destroying the data? And the answer is…C. destruction. All of them We'll delete the data in some form or another They will they'll all delete it and take care of it. But to ensure it's fully nuked and fully destroyed, you should are basically it's…de. Dead Yeah it's shredded. you should destroy it And that's really only physical destruction of the system itself will be the best method when making sure that the device there's the data is not available to individuals. So again that's a good one to think about destruction. All right. Let's move on…All right These are the links ISC squared study guide Quizlet. Also so there's some training from Thor teaches O E. D rainbow books and G X a. All right I hope you enjoyed this training from reduce cyber.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
· CISSP / Cybersecurity Integration – HITECH
· CISSP Training – Compliance Requirements
· CISSP Exam Question – Preventive Controls / CIA Triangle
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
https://www.isc2.org/Training/Self-Study-Resources
Quizlet
https://quizlet.com/87472460/official-isc-cissp-domain-1-security-and-risk-management-flash-cards/
Tech Target
https://searchsecurity.techtarget.com/quiz/Cybersecurity-risk-management-CISSP-practice-exam
Compliancy Group
https://compliancy-group.com/what-is-the-hitech-act/
Wikipedia
https://en.wikipedia.org/wiki/Arms_Export_Control_Act
Wiley
Transcript:
Hey Alice younger from reduced cyber risk and I hope you're all having a wonderful day in this beautiful state of Kansas I'm having a great day It's 75 degrees is going to be gorgeous today. It can be a little warm which is awesome It's also going to be just a little bit on the cool side in the evening which is even better. And the mosquitoes haven't come out yet That are the size of birds. I saw some small spiders running around which are quite large actually but yeah that's not bad My dog just eats those. But other than that life is good here in Kansas And we are going to be taught about some awesome things as it relates to cybersecurity today on today's podcast. But before we do I wanted to kind of go talk to you a little bit about Ru cyber risk and some great training that I've got out there for you specifically. And this is CIS S P train that you can get through you to me right now It's awesome You can just go to the site You to me and you can search for my name Sean dot Gerber or you can click on the show notes and I've got a great link to it on CISP training at reduced cyber risk. And it will take you specifically straight straight to you to me and get some incredible CISP training that I have available. you, and this is great stuff And as you know with you to me, They give you some really good prices on this You really can't beat it at all. I mean, honestly the bargain basement prices are pretty amazing just by going to YouTube and getting those. So again you can check those out@youtube.com or you can go click on my link at reduce cyber risk and get that C I S S P training specifically for you. All right So we're going to be talking about today The CISP cyber security integration. We're gonna be getting into a product called high-tech. Okay That's a health insurance. Uh in for our health information piece of this And we'll kind of go into that in just a little bit. CIS has P training's going to be aware on compliance requirements. And then the CISP exam questions are going to be on preventative controls and the CIA triangle. All right let's get going…Okay let's roll into this. So this is for Wikipedia and it talks about high-tech and high-tech is the health information technology for economic and clinical health act. Have to. Okay Yeah Say that 10 times and your brain will freeze and you're probably going what the Dickens is that. Well this final falls under the compliance aspects that we're going to get into and Wikipedia had a really good product about this and put it out there. Someone had obviously typed it into Wikipedia. And went through the different aspects of high-tech. And in high-tech is one of those things If you're dealing with the health insurance aspects and if you are studying for your CISP which I assume you probably are if you're listening to this podcast and or you're a cybersecurity professional wanting to understand a little bit more about these aspects. Because honestly when being a CISP myself, you get very niched and do a certain area. And so therefore you kind of forget or you don't really deal with these other aspects. And this is just a really good way of for you to kind of understand a broaden your capabilities. And this was per the anticipated the expansion of III protected health information, which is the electronic Phi And I don't know if you all are in the United States and you probably run this around the globe as well. I just got back from China and I notice that everything they have is online I mean you use we-chat for everything. They use Ali pay for other aspects. So I mean they are totally connected in China. And I think there's just it's It was when I was in India is the same thing Everybody's on their phone They're walking around the streets. So it's only going to be more and more of this Well in the United States we are all as to are are moving along in this base. And an electronic…health records are actually all out there. Uh right now if I can go online I can look at all my kids and what they have online. What what are some of the different cases are I have to go to the doctor all of my authorizations all that stuff is done online. And so this, this was designed to help with that electronic capability that just kept coming up as they kept dealing with this And this was passed by the Obama administration back in 29, 20 2009. And the goal of it. Was to reduce the cost of healthcare sharing as they're putting stuff out. And and so therefore it that's kind of why it came out was just to help reduce those physical costs…Now this is the design is that it would be if you're having data between hospitals and other entities that store your EPHI or your E patient health information, and that's the whole purpose of it So there's lots of information that is passed back and forth between an entity that let's just say you have a company that is a third party to a hospital, and these people work on MRIs. Well they have the ability to have some data of individuals that is passing back and forth. Well they wanted some level of privacy added to these and it expanded the scope of privacy and security protections for this data that is moving around. Tween these entities. And it also increased the light legal liability If you don't protect it Now one thing I've learned in corporate world is that you have lots of third-party vendors and these vendors will, are basically the little fish that sit around the big whale. And so therefore they are all servicing this big, the big whale Well what ends up happening is is sometimes these guys security isn't as, as intense as it possibly should be. And so therefore they induce a lot of issues to companies because of the simple fact is that they're tied in, well now you add the complexity So you know corporate America you have a vendor that takes care of you You have those requirements to make sure they protect your data, but now you add that additional component of having. Uh, per PII or Phi which is your patient health information. Potentially being stored by these third parties Well then what ends up happening is now you've just incurred greater risk by having these third parties involved within your hospitals. So therefore this was to increase the legal liability of individuals who do not protect this information. Now they had put out some monetary incentives back in 2011 to 2015 to get people to migrate to this direction. I know in China they moved people to we-chat and I honestly I can't even use a corporate credit card in China anymore just because everything is on Weechat. Well in the United States they've they've tried to move them in that direction They didn't really say this is the way it's going to be. And so therefore, And those incentives were set up until 2015. And there were penalties out for not acting after 2015 So for some reason you said, you know what I'm not going to do it after 2015. Then there were some penalties that you would have been incurred for not doing that…Well so it's 2019. And now what. Well, the thing is that's interesting is, and again this comes from Wikipedia So I don't know if this is truly the case It'd be interesting to see if anybody would provide some feedback around this but when it comes to 2019, There is an industry perception that it really isn't inforced that they're not enforcing any of this capability at all. And so therefore it's interesting how they're going to do this And what is the longterm play in this space Not really sure It it'll be interesting to see if there's going to be more enforcement. Now I am. You are seeing some things out there that there's more of this ratcheting up. However one of the things is just the perception is that it isn't really being enforced. Audits are occurring but many fields that they're just not very effective in what they're doing. And the one thing that high-tech had talked about the high-tech act was that if you have willful neglect and they have prosecuted some of these where you will be penalized and it but it is set up on a case by case basis. The fines will range anywhere from 250,000 to 1.5 million. At depending upon how willfully neglectful you are. So that's a lot of cash and you really not really focused on this And if you're a CISP going to work or a health insurer or a health company, and you're dealing with high tech, you better understand how you're protecting these people's information because it. Again I come back to this. If if you're not being audited and penalized now, it's, it will be It's just a matter of time. It's just a matter of time before there's a big breach or something large that happens. And then there will be a knee jerk reaction to then enforce these audits If they're not already being done. So the best thing to do is to work to strive to get towards compliance on these as best as you can, just because of sin. fact of it is is that you're going to have to deal with it at some point. And it's only going to get worse as we get more and more cyber breaches that occur. With in every career whether it's in the health industry or whether it's in manufacturing whatever it might be…Now high-tech also had a brief note breach notification and this breach notification is similar to others that you deal with PII disclosure. Now high-tech requires patients to be notified at any unsecured breach You see this a lot in pretty much anything out there deals with these unsecured breaches. But if it's got 500 plus patients, Then health and human services must be notified of the situation. Also in to include that your state privacy officer would need to be notified as well. So now you're not just involving the individuals that are involved the 500 plus people are at H S H H H S your own notifying the private state privacy officers that the state that they resided in. Now if you are a large hospital there's really good chance that you could have multiple states involved. So then you gotta deal with multiple lawsuits. So the fine is just one aspect of it So 250 grand of 1.5 million is the fine from HHS from health and human services. But now you Gail into lawsuits for loss of their privacy information Are there. There are data that that can go up and be millions as well So it's it really behooves you to pay attention to this stuff and to strive to deal with trying to protect the data. And I've also mentioned this before you. When it comes to these compliance aspects And again I am not a lawyer so do not take this as legal advice. But one thing that I would say is if you do everything in your power to protect information and we all know that people's data will still get breached from time to time, it still will happen. But if you've done everything you can to protect your data and put it in. In respect to what the is defined within the high-tech act. Then you are in a much better more defensible position in the event of a breach still doesn't mean you're not going to eat fine And it still doesn't mean you're not going to get sued by customers. However you're in a much. more defensible position than if you just say eh I'm not going to worry about it It's not being audited Nobody's caring about it Matt We'll just keep moving on. That is not a good place to be. So just just keep that in your back pocket Again not a lawyer, not the one that can tell you what to do. But it's just from what I've seen in this space in this world that doing those things and that due diligence goes a long way especially with the courts. They also talked about breach Patients need a first-class mailing and then they must basically Reese resolution to the issue And it must specify specifically what did you do to fix it? Are you putting them on some sort of, oh what do they call that I can't think of the name of it. Well you're dealing with the…identity theft protection those kinds of things Are you dealing with that Are you putting on people in there protecting their data through a Experian or one of those? And then if you have possible credit monitoring services that you may offer to them, all of those things they're going to ask what did you do to resolve the challenge that was occurred because of the breach? Okay. That's all I've got for this cybersecurity integration Let's move on to the training…Okay this is under the CISP domain one security and risk management. We're going to be a topic on this one is determining compliance requirements. All right As we all know compliance is a huge aspect as relates to cybersecurity and the CIS has P so one dot three of the CIS is P training manual that you'll get through ISC squared kind of talks a little bit about some compliance requirements and some of the things you need to be considering about that. And one of the topics is determining compliance requirements. So let's kind of roll into a little bit about this and see what you will we can kind of dig into but. Basically it's an overview There's an act of conforming or adhering to rules, policies regulations standards or requirements. And it's basically you must comply with these things And I kind of talk about there's a couple different areas There's, there's a big C compliance and little C compliance Well, when you're dealing with these big C compliance this means you must follow rules policies regulations standards or requirements And I deal with this on a daily basis. If you're a cybersecurity professional this is summer. that is near and dear to your heart and you must deal with it all the time. And our employees need to be trained on their responsibility around complying with applicable laws and the regulations And you need to make sure that you teach people this. And as it relates to cybersecurity in the past it's always been compliance Does one thing cybersecurity does another because we're under it. That is not the case at all I deal with our compliance folks all the time. I mean on it almost on a daily basis. And it's because not especially now with cybersecurity rolling into every space of. The world and from privacy to data protection you name it It's it's all over that Yet GDPR you've got Chinese cyber laws You got privacy laws that are in Singapore. Yeah all over the place. So you're going to have to deal with these Now you've got states that hell have different laws that are involved in So you have you get called in on a routine basis to kind of go over. What do you think about that I mean just to be honest I've got emails in my inbox right now to talk about those specific issues. So those are things you need to consider and it's very important to overall in your overall. governance to understand these pieces. Now as an example you got PCI DSS Now there's extensive training available and required that you have to do when you're dealing with PCI DSS. And I've also got on reduced cyber risk of get some more training that's available for you on the PCI aspects that are kind of go over that specifically and some specific training around it. But there's 12 main requirements are as a firewall configurations. There's a unique voice. A vendor supplied default passwords That's a big one, encrypt transmissions between locations And we'll talk about in future podcasts around some different kind of transmission protocols and with encryption. Uh restrict access on car data to only the people that need to know, not the guy you hired for the summer That's going to be surfing the web on the computer that holds all that information. Not not a good idea Just don't do that. And then there's many many others obviously but bottom line is there's some key things that you must maintain with your when you're trying to get PCI DSS certified. And so as a vendor who or as an individual. has a credit card at their location. You're going to have to make sure that these things are set in place. Now there's different PCI criteria that that are available for you. That you, you need depending upon what your company does where you'll have to follow. But bottom line is is that you need to maintain these And so therefore as a cybersecurity professional, you need to make sure you're in compliance with that specific regulation than that rule…Now when we're dealing with contractual legal and industrial standards this is kind of an objective that's on the CIS. And a privacy has been, been and continues to grow as a hot topic within the United States And we see this all over the United States. Especially in the California and I'm seeing in Massachusetts but you're also seeing it states that don't typically fall the California Massachusetts type of timeline where you know those are the key drivers the key. Ones that many people use to guide their direction around cybersecurity are actually around privacy And there's many other states now that are adopting this piece countries were addressing this as a digital age continues to grow And yet China us EU, and this will vary from country to country. And I've also noticed like even within China the country may say one thing, but even the provinces have different perspective of what the country is saying So you've got that dynamic to deal with as well. You have us privacy laws and there's a fourth amendment of the us constitution And this kind of talks about this And this was again obviously the constitution was dude done in 1919. Uh 1770, I think it was 78 is when the actual constitution was done up. I get I I think I screwed that up Probably they'll probably be somebody that'll let me know No, the constitution was donut in 1786 and 20 two-toned high. It's I think it was two years after it was actually ratified. Are they actually the signers sign The, the, yeah What did they sign? I'm blown away. It's all right It's quite early here in Kansas And so I'm half asleep as we're doing this but, but it's a right for the people to secure their persons or houses or papers and effects against unreasonable searches seizures and shall not be violated And this was designed in the United States around the king. The the the United Kingdom and England coming in and they're they're soldiers undoing unlawful search and seizures. And just basically just ransacking the place trying to find what they want and what they could about you. And there should be no warrants shall issue, but upon probable cause support by oath or affirmation, and particularly describing the place to be searched and the persons and things to be seized. Bottom line is you can't go in and just grab people's stuff And you got to have a warrant to say that you're going to do it as the United States I don't know how that is in the country of where you're listening to this but it hopefully you have something similar to that. Bottom line is though is us constitution spells it out So you can pull that out when someone tries to do it. Changes to the amendment have included what we call wiretapping to include with, with now it moved into the. I was the it wasn't the digital age. 'cause wiretapping has been around right after obviously in the early 19 hundreds is when the a that started all coming to be. And these these. Laws are woefully inadequate In some cases they're actually getting better over time. But I think in many cases this just they've had. key try to keep up with the digital transformation which is extremely hard and challenging…The privacy act of 1974 the federal government this is where they deal with private information about individual citizens. And it's get puts limits Thank goodness on what the government can do. Now It doesn't mean that they're actually following it You would love to say they are but there's lots of wiggle room in legal language. And so therefore they do these things And this is kind of also where the Patriot act came into play. And we'll talk about that later on but it allowed them to use SERP Some of these privacy laws that are in place and they had to go back and get resole or re get it reaffirmed every year. But that's one of the thing that's that it's a whole different animal. There's only applies to government agencies in this case here So when you're dealing with privacy is it comes down to is that only government agencies will be able to limit that about individual citizens and what they can actually do. Now the exceptions are health and safety census law enforcement court orders and national archives. And again those those could be. Tweaked a bit to help you help the government get what they want. But bottom line is those are the main exceptions to the privacy act of 1974…Now the electronic privacy act This is basically came out in 1986 which is kind of more my generation. And yeah that just dated me I'm like really really old it's basically it was to evade. It was. Designed to invade the privacy electronic privacy of an individual It's a crime to do that And so therefore they wanted to put this in place. And it helped broaden the federal wiretap act that had been put in place in the early I think it was in the fifties that they put that fifties or sixties They put that in place. I'm probably wrong on that as well. But it it prohibited the interception of the electronic communication So they just couldn't go out and start sucking down information about you as it related to our proper warrants Right. And it's illegal to for mobile to tapping to mobile phone conversations. Now that has changed a lot in this from 1986 from when I had the big old bag phone that I put in my car. With an antenna and it was just it was tied to a wire. That's come a long way since then or now everybody has mobile phones and you. I still say I walk it through India and you know they got 1.4 billion people and everybody is on a phone Everybody's got their head down walking on a phone. It's just it blows my mind And that's what that's kind of what cellular technology has done is it's helped expand these networks. Two places where typically phone coverage wasn't covered. You didn't have phone coverage and now everybody does It's connected the world even more. Communications assistance for law enforcement This act as a 1994, and it allows for communication carriers to, to allow for wiretaps Now that's where this came into play where you could actually get into mobile phone conversations. Of the 1994 and hence that's why because now they went from bag phones to everybody has a cell phone…Now the electronic economic espionage act of 1996 this diff extends the definition of personal property into the electronic property. So now you're getting you're getting out of this whole physical. Data or I have a check now for a bank I now have an electronic apple pay account. So it's going from personal property into elect. property. The health insurance portability hiphop that was set up in 1996 This is privacy and security regulations incorporate into the law. These are specifically set up as they were set up in that law. And then then we get into high-tech which you talked about earlier, and this is the health information technology for economic clinical health act of 2009. And this was also to help update the HIPAA and privacy and security requirements as it relates to what. What's in place and it deal with the, the technology The EPHI is we had talked about before. And the bottom line is it comes down to breach notification again over 500 individuals You have to notify HHS. And then also the state privacy officers as well…Some other notable mentions around this would be Copa And this is a big one As it relates to taking care of kids online. This is the children's online privacy protection act of 1998. And this is basically online privacy for children. And there's the Gramm-Leach-Bliley act of 1999 This this is a the financial restrictions between institutions and allow more communication between them. The one thing I wanted to come back with Copa. That's actually a really good thing that they finally put in place for that And it helps add put a little bit of restrictions around what you can show children what you can't. I would say in some cases that are kind of pushing the envelope on some of that a little bit. And again that comes down to what some people believe but. It's as as data becomes more and more open and available, you really got to watch what's out there for these kids because some of this stuff is pretty, that's not so good It's That's so good. You just Patriot act to talk about that of 2001 that was a result or a resolution of nine 11 that it hit New York trade centers and took those out. And it basically allows for blanket authority to monitor a person. Now it's set to expire in 2019. It's reviewed by Congress and it has been reviewed over the past Yeah I mean I guess every year they have to reaffirm it or every two years. And they have to reinstate this Uh, again I think at this point in time it's interesting to see it's one of those things It's like taxes Once you give once you've set up a certain amount of taxes and you pay taxes. It's really hard to revoke those taxes In many cases they don't Virgo away They always just stay there and you end up making more money to offset the cost of those taxes. Same thing comes into place around this with the Patriot act. They got Congress doesn't want to lose their control And so it'll be interesting to see what happens with it I think people are finally getting fed up from a privacy standpoint. That you know you're protecting us from the bad guy whoever the quote unquote bad guy is of the day, but at the end of the end of it what do you lose from a privacy standpoint which is very different than some other countries don't necessarily care so much. But I would say here in the United States it's becoming a more and more a problem. This with me. I don't, I'm not a big fan of it I'm. I'm former military And I I'm all for having the government have control in some cases to help protect the citizens, but it needs to be a restructured and limited cause at some point then it becomes ultimate power and that's just not a good thing So. You got to, got to kind of watch that and put checks and balances on that. On the family education rights and privacy act FERPA. This is for parents students with parents of students with the rights with educational institutions So. this is how you set this up with educational institutions that they ma manage the rights of your students. And then identity theft and assumption deterrence axial That's all these lots of bills lots of laws, severe criminal penalties for identity theft So this kind of falls in line with when you deal with identity theft if someone steals your stuff, They get nailed with multiple things They'll get nailed with wiretap They'll get Neal nail with money fraud with money laundering They'll get nailed with in this case here identity theft and this could be a $250,000 Fine Up to 15 years in prison term. So there's a lot of things you can get added for doing this identity theft stuff. That's why, again that the upside might be good You might think it is you get some short-term cash and you can be living large for awhile. But the downside is you got to break big rocks into little rocks and that's not just a good thing So there's the issues as it deals with identity theft and assumption deterrence act…Okay So that's all I have for the CIS. SP training Let's roll right into the exam questions…All right these damn questions are over domain one…All right Here's a question. Preventative controls. Okay That's an authorize the president to designate those items that shall be considered as defense articles and defense services and control their import and export. All right So what does that mean What basically means is that there are is true because there are controls in place that the government can put in place that gives the president the ability to put in restrictions around what can and cannot be imported and export. Now the arms control act of 1976 does this this gives the president the United States the authority to control import export of defense articles and defense services. Typically this gets called into play is the cryptography. And so therefore various cryptography and or cryptographic technology can be limited based on import export laws. This has been in the past This has been seen where we used to have the Cray supercomputer which in today's world is probably old school, but it you could only export certain technologies and that even and when it gets to the UK I know they, they didn't have all the technology They they could be potentially sent to the United Kingdom. And so those are the president of United States can authorize that Now that goes both ways right The government other countries do the same thing to the United States for import export. I know Israel Israel has a lot of stuff that they make specifically internally to them that they do export and sell. But I know they keep back some of the things that are specifically to their country. So those are aspects around it that you've, that you'll understand from a CISP question. It's the arms export control act of 1976. For anything that might be used from a defense standpoint for military purposes can be limited. All right Another question is vulnerabilities and risks that are evaluated based on their own threats against which of the following Okay So we have a one or more of the CIA triad triangle. Principles. B data usefulness…See. Do care. And D extent of liability. All right The answer is dun dun da. One or more of the CIA triad Brian's principles All right So when you're focusing on vulnerabilities and risks that are evaluated what do you do against them You focus them on the CIA which is confidentiality integrity and availability. How do they affect each of those three? That will then determine how do you want to deal with that specific threat? So therefore when you're evaluating it you focus on the CIA triangle and it really is that it comes back to that If you can focus on those three things, how does it affect confidentiality? How does it affect integrity of the data? And how does it affect availability of the data? Those are all very important pieces that you need to keep in.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
In this episode, Shon will discuss the salaries associated with the CISSP and other cybersecurity roles. Also, he will discuss about setting the expectations as it relates to taking the CISSP exam.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
Hey all is Shon Gerber with a C I S S P cyber training and reduce cyber risk podcast I hope you all are doing well This beautiful day. And just say it's great here in Wichita Kansas So I love it It's awesome. So quick question for you We are just today we're…episode five This is the ongoing series around how basically. The CIS S P cyber training got started. And we're just now rolling into this next podcast We're going to be talking a little bit about CISP expectations around salaries and so forth. But before we do we'll kind of talk back about what we did And we, we discussed in the last episode and it was around understanding the CIS S P certification and preparing for the future. One of the points brought up is that it you are certified you do run the the ability to potentially make at least 22% more than being non-certified. Now I've seen that article out there and I I've quoting that but at the end of the day it really comes down to experience So having the cert is extremely valuable. However having the experience is as much if not more So, so just kind of coupling to just consider as you're looking at this. We talked about the CISP and the requirements around it as well as having the experience needed to become a CISP. There's a all the three areas the three concentrations would be your architecture engineering and management. And then we also discussed a little bit around the associate CISP and the additional certifications as it relates to security plus and network plus. So that was just kind of the last podcast and servers are a four And. The ultimate point was just to kind of walk through these different areas and to give you an idea of where we're at. So now as we're dealing with expectations around the CISP and taking the exam, one of the big things that you see I see online quite for. is around the salary as it comes to being in the cyber security. Now there's a lot of things that will break down the salary and I've got training at over at CISP cyber training I've got a an actual training specifically and you might even see it on YouTube Cause I'll put it out there. Where around what can you expect based on the role that you're looking to do? And a lot of things When you start off as a an individual that's trying to get into security into the cyberspace. Your pay can change quite substantially depending upon the role that you actually take. Now I pulled off via C squared They they have uh, an article there on their website and they're the ones that put forward The CIS is P along with a lot of other certifications but one of the things they bring up is kind of the breakdown in actual income based on where you're at. So a in the Asia Pacific region they're basically saying is around 57,000 us dollars is what you would make. Europe is around 81,000. I think north America they're saying around 120. is what you can anticipate. By getting the CIS as P. Now I will tell you that that will range And also the other thing is it really depends on the role. You can get the CISP and be a security analyst and you'll be making 70 to 80 maybe $90,000 a year, which is…amazing Right I mean that's really really good income, but you also could be a CISP. Being a chief information security officer and make substantially more than that. So it really depends upon the role just getting the certification does not automatically include that you're going to get paid that amount of money. It's a great cert but it's not that great of a cert. So kind of keep that in mind Now also keep in mind that the pay will range a lot from location to location. As I'm out interviewing people for different roles from security engineers to analysts. You name it you know you you've ended up architects you end up interviewing them. And as you interview these individuals, you also have to keep in mind where they are at. in there Where they want to live. If you have somebody that's in New York and they are going to stay in New York, what ends up happening is is their pay is probably going to be substantially higher. However if they were in Wichita Kansas their pay might not be as high as it would be in. And in New York city. Now you go to Asia you go to India. Now the pay compared to us standards would be lower. However in India it would be substantially higher So again it really depends on the geographic location of where you're at. It's all relative It really truly is. So you need to keep that in consideration as you're looking at getting a job some location. The other thing that comes into is if you're looking at working in New York, the odds of finding, having more competition is higher. So therefore the role that you may wish that makes the income that you want. May not be available to you unless you have the experience to back it up. So it isn't just again it's not a meal ticket You don't just punch it and you win That's not this isn't a lottery. However, if you do accomplish these different goals, you set yourself up for extreme success, both short-term And long-term because this again, this isn't a short-term game This is a long-term future that you want to do for you and your family and your career. So therefore it's extremely important that you think that way. Don't just look for the fat the fast money. Another option as it deals with making money is the fact that as you can end up commanding a very significant amount of income based on what you're willing to do. Now let's talking to other…The sows that are in my position. And one of the aspects came up as he said, we were talking about compensation And how do you look at compensation for other security officers What what would the be the norm. And it will again it will vary from position to position. However one thing he did bring up is he said if you're willing to do some things that other people aren't willing to do. You obviously could make a lot more money. Now again one thing you got to think about with ISC squared and being coming to CISP, it's gotta be ethical It's gotta be moral It's gotta be something that you would do that you have to be able to hang your name on. Now you can go out and be in criminal and you can make a lot of money but that is not where you want to go Okay Short term, short term the money may sound great but let's be realistic. There's a lot of a lot of downsides with that besides being ethically wrong. First off is if you get caught. That the downside is you break big rocks into little rocks You are is not a good option. But that being said if you are an expert in what you do, you can then be an individual that would go to a company who may have been hacked for example. And we call it the dumpster fire situation, where they have a total dumpster fire going on right This company just got hacked Their security person is out. They maybe they don't have a security person. You now would be parachuted in and you can help them with their situation. And by doing so you could command a. significant income from that. Now that being said there's a lot of risk with that as well. If there's risk there's reward right You got to decide as a reward is high Is the risk high baby Maybe not. But that being said you could come in, you could make commander. A large salary, you can help them protect them and then maybe move on and do your own thing. And that's more of a consulting type gig. The other option is that you can go potentially hang your shingle. You're basically I'm open for business on Upwork or other contracting type websites. And you can say I'm willing to do X Y and Z. A good friend of mine That is in when I was an aggressor at the 1 77 information aggressor squadron. He was my counterpart with the active duty air force. He I've talked to him just the other day and he's got a consulting company and he does that right now out of his own consulting business. And he's done very very well. Now the downsides of that obviously are the fact that you've got to have a good plan You've got to have money set aside because when jobs come they don't all come in at this at a very program time. It's either feast or famine. So you've got to have a good plan for that, but there are options right So when I throw out these numbers at you keep in mind, this is based on a workforce You can make a lot more than this. If you're willing to do different things. That are both legally and ethical Okay Just set that expectation. So as we go into jobs what are some different ways that you can understand how that works? Okay So I'm going to throw some titles and I'm going to put out some sample jobs that are out there pulling off numbers from glass door, Upwork and other areas. So let's just go a cloud security engineer Now cloud security engineer can range anywhere from 70,000 to 120,000 us dollars I'm going to put all this in us. If you're listening to this in India obviously you look at rupees and figure out how you want to convert that But again and that would also be different in India. Uh the pricing obviously is about 30% less if you're in India, but the overall buying power is about the same. So your cloud security engineer is around 70 to 120,000 us dollars. Again depending upon your experience will get you more income. The cert will help but the experience is what makes you the more money. Security architects and various. All variations of this will range between 90 and 180,000. I know there's people that have talked on YouTube that they make 200,000 pluses in architect. You can I mean there's bonuses that are included in there You can definitely make over $200,000 doing it. But again on the flip side is is there's pros and cons for that Not everybody does that Let's be real Not everyone makes $200,000 as a security architect. Now there's many that making the a hundred and fifties a hundred and sixties. And coming from a guy that was broke right I mean I have seven children and I have no money. One of the aspects that came up if I was making a hundred thousand dollars a year, I counted my blessings and I was very happy. and that was even making a hundred thousand was extreme life changing for me and my family. So that that's huge Right. Security analysts will make anywhere from 60 to a hundred thousand and then a chief information security officer can make 110 ish. To two 50 or more depending upon again bonus structures, other types of activities and what you're willing to do. Talked about contract work with Upwork And as one example is I'll just give you an example that I saw on Upwork and they go I need a CIS SP to implement TSA which is a transportation security or safety expert security act I don't know. Requirements. You could also have someone comes in and says, I am part of Fat's in the United States which is the chemical facility anti-terrorism standards I need somebody to help me implement that. I have a government contract to help me do that. There's CMMC which is the cybersecurity maturity model certification. I need people to help me get my business up to the CMC standards. There's lots of ways you can use that your CIS SP to help you Moonlight on the side Even if you have a right a job right now doing something else. Again doing that is a great way to build your resume It's also a great way to for you to get a new opportunity. So there's lots of ways to do this. The hardest part is getting started, making a decision and get started. In most cases these are set up as hourly right You'll get paid a certain percentage or a certain amount for your time that you work. You're also going to have to get you'll learn during this process especially if you're doing like an Upwork type event. You'll figure out what is your time worth and what are you willing to commit? You may be willing to commit, say 20 hours at a much lower rate to get the job. Because you need the experience and you need it to put it on your resume. Then maybe someone who comes in who has all that experience already and really doesn't need it and is willing to take wants to take more money because their time is valuable to them. So there's lots of different things you can think about in that regard…Now as it relates to CIS S P certification costs. One thing to keep in mind is around. What is it going to cost to do this To get certified? Now there I mentioned before in past episodes the free option. But like everything there is nothing free. What you're going to have to do is you will have to buy a book. Okay I guess you can rent it or you can go ahead and look at it from the library. But in reality I marked my book up I made copies I made notes I stuck sticky tabs You just just break down by the book I mean realistically. You're talking a hundred dollars that you're going to have to invest to buy the book. Now you're also going to want to get some practice questions. Now there's practice questions on CISP cyber training I have some available for you. You can go out and find other practice questions online that are free. But you also can go out and buy some that are better curated, and that will give you a much better experience. And so those are options you need to consider. So your study guide your study questions are a hundred dollars Your practice questions will go from a hundred to 300 So right now you're all in at around four to $500 before, honestly before you take your test but this is now you're going to spend your equity We call it sweat equity. In learning to do do you get the your CISP and that's what you're going to need to invest in is you spend the extra four to 500 which it can be very challenging to find that money I know been there done that Got the t-shirt. But you may have to do that to be able to then put your sweat equity into your business, to be able to make the money you want to make so that you can have the life that you really truly want. This is attainable. The only thing that will stop you from making your dreams and a reality in cybersecurity is you. You are the person that has to make that decision And you're the one that has to do the work. Now the free training is out there Again I come back to this it's you get what you pay for now There's some really really good free training There truly is. And I will tell you some of the networks plus and security plus an A-plus training I saw it on YouTube is amazing. And. I recommend it And actually it's some of the curated stuff that I've I've got in my site is to recommend that training for you. But what really will help you is the fact that you're having somebody keeping you accountable and helping you walk you through this process is a really important factor. Again we talked about the paid specialized training. You can get that in various locations either If you want to drop the money on a bootcamp. You know five six $7,000 or more. Or if you want to do it a little bit more cost-effective by going through CISP cyber training or other type websites out there, bottom line is you need to consider one of those options. The boot camps they will run anywhere from five to seven days And bootcamps will cost anyone the upwards of five to seven potentially even $10,000. Depending upon if you're going to be in-person or online. If you're going to be in person you got to pay for hotels food transportation so on and so forth So that can add up quite substantially over a period of a week. The exam fees are usually included in them And many times they do guarantee success. They they have their instructors have been teaching the test law enough and know well enough what are the exact questions that are going to be asked of you? So they will give you a pretty good understanding of what you need to be paying attention to. However that being said, Just because like I mentioned before you because you get the test does not mean that you're going to just automatically. Get everything you need to be successful in cybersecurity. So I'm just telling you it's it's. The boot camps are great I'm not knocking them I think they're a great tool for the right people. Just the fact is though is just because you get the cert. Doesn't mean you're going to get the job. I think I've beat that horse to death enough I hope I haven't. I probably have a anyway trade schools trade schools universities again another way that you can make the money or get the training you need, but they do cost more money and there's it finding good instructors can be a challenge. Okay so some questions around the CISP. The CIS is P there was a question that came up that I looked online is the CIS. P a hard exam. Yes it's a hard exam. It. not easy Consider it like taking a master's program in security Some people may get it faster than others but it doesn't matter It's a tough exam. It's computerated testing which means it learns. If you do poorly on a couple of questions, it will ask you more questions like that That are just as hard If not harder. And the purpose is is to weed you out early. You get six hours to complete this. And it may not take you that long but you're allowed that specific amount of time. There's 250 questions. And again the exam is pretty expensive. It's at least two times the other exams you're going to see out there like I talked about, so it's about 700 to $800 us dollars to take it. I don't know what it's costs in other countries but just assume it's going to be. Pretty high there as well. One thing I think is important for you to know as you're listening to this podcast the pie the pass rate for the CISP. Is for the first time the pass rate the first time is only 20%. So only 20% of the people who sit down and take that test. We'll pass it the first time. And I'll raise my hand because guess what? I was one of those that did not pass it the first time. So and then I'll tell you that that's a brutal it hurts your your F your mentally. It hurts you financially, and it's a it's a kick It really hurts So again you want to set yourself up for success and do the best you possibly can so that you pass it the first time. Now is the CIS is P for beginners was a question. No it's really not It's not a good test for the beginners. But it would because of the work requirements because of the endorsements, because of the fact that you really need to have a good understanding of networking and understanding that aspect of it. It is probably one of the most hard certifications out there It's not the hardest but it's it's a very challenging cert. So it is not for beginners. You need to focus on getting the skills you needed to go and you can get those@cybercispcybertraining.com I gotta put the plugs in just gotta, but that will help you with getting your path to success. So again CISP is not for beginners. Now how long does it take to become a CISP We talked about that before through the podcast about five years experience. Full-time employment at least two of the domains which we mentioned of those eight domains that asset security identity and access management and so forth There's there's many different domains. Eight total. But the point is you got to have full-time employment in those college courses or certifications We'll give you an extra year towards that five-year work requirement which basically means if you take go to school and or you do the cert, you will be able to you'll have four years to get the knowledge you need to be able to get your CISP…Now as far as preparing for the test, you need to self study is about three to six months I'll just be honest with you all there's guys out there They'll say I'll help you get it in 30 days I'll hope you get it in 60 days…Again you have to listen to it and see if it's worth it to you If you know I'll tell you from a guy who's got 21 years experience, can you potentially pass this thing in 30 to 60 days? Yeah you can, if you do. everything you can in the next 30 to 60 days to just study for that test you probably can do it I feel confident you can do it. However it would not be a phonics. Uh invent you would not be happy And I personally feel that all you would do is you just regurgitate the information. Pass a test and you dump it. Not to say that that's a bad thing I'm just telling you that to really truly understand the CISP and to understand some of the concepts it's going to take you three to six months. With having a life outside of studying. If you have a family if you have a job, it will take you a good three to six months. Everybody I've talked to that has done it. It's in my world. They will all say the same thing. Okay again. CSSP cyber training I got resources that can help you with that too Again, if you're going to spend the time let's help you walk through it. Bootcamps are available And again they do help compress that timeline So you can get this thing done in a week right. Uh but you've just got to spend $10,000 They're great for the short term, but the other thing that comes out of that is is if you don't have a long-term plan to keep that knowledge going, you'll remember it And then you'll forget it…So one of the other questions that came up was what does a CISP S P do. Okay So this is a question that you'll see online is what is a CIS S P do? Well the certification will help expose you to various concepts that you may or may not have in your current role. And that's the ultimate goal so that you look at something with a different perspective. As an example I was talking to my intern and we were talking about how security is set up and some of the concepts that I gave to him around. Information rights management and protecting data through encryption I was a total changer to him And he looked at now from a different perspective. That's the ultimate goal of it is to provide you that knowledge. Another one is around secure development life cycle I was talking to my security my developers a few years back and mentioned secure development life cycle. They had absolutely no idea what I was talking about. But as I brought it up to him and explained to him that, oh that makes sense to them. The other part is around like security and risk management. One aspect of this as the TSA sea fats China's cyber regulations that falls under governance and regulatory requirements. If you are insecurity at all. If you feel that you won't ever deal with regulations I'm sorry to tell you but you're wrong now You may not deal with them right away when you get first get started as much as you will as you get more time in with the security space, but you're going to deal with them. So you're going to have to understand them. And I don't like them I really don't. But it's one of those things that if you don't like you better do more of so that you end up do liking it. And I will tell you that I've gotten really good at it Not because that I'm a genius by any stretch of imagination I'm Michael Small guy from Iowa I mean, I live in. I was a pig farmer. I mean that's where I came from. That doesn't mean anything about intellect It just means that's what I was exposed to. And I'm pretty good at regulations. And it's because of the fact that I have focused very strongly on it because I know that all. cyber stuff is great but the governments whatever government is can come down and totally crush you. If you don't have these things in place and if you're not paying attention to it, So better pay attention to it. Now that's really all I have today for this part of this podcast. Now this podcast again was over CISP salaries testings and also setting expectations around the CISP. I'll say going forward you're going to have more podcasts out there We're going to be focused primarily on the CISP the different domains I'll pull out a domain as it just to give you an example. The one coming up next is dealing with compliance requirements and how you have to worry about that for the CISP. And those compliance requirements will be going over What are some things you need to be concerned about? And what are the things that you have to be worried about from a security professionals perspective? I'm going to deal with data remnants, identity and access management logging and monitoring cyber crime. All of these aspects I'll be taking out of each domain and I'll be talking about specific pieces of this both from my training That's at CIS. SP cyber training. As well as my knowledge in what I know. So all of that stuff you're going to be seeing from now on you'll also be getting it'll be coming out in these podcasts exercises Right So your your exam questions. So I'll grab an exam question and I'll read through that exam question and then we'll dissect it and we'll talk about it. Now the ultimate goal is I'm doing this through a podcast I do put this out on YouTube and you'll see some videos. They may not all have video in them They may just be audio. But at the end of the day my goal is to provide this much information as I can so that you can become successful in your cyber career or on the other side, you realize I don't want nothing to do with this. And this is not for me. I'd rather have you figure that out now before you spend a bunch of money and time getting into the cybersecurity space, it's not for everyone. Just because the money may or the may or may not be there or because it sounds sexy or NCI S or whatever's out there. It's not for everyone. So it's better to find it out now before you invest a bunch of time energy and money into it. Okay That's all I've got for today Thank you so much for joining me on this podcast Again the CIS. Cyber training.com Go check it out. There's a lot of really great stuff there You will You'll totally enjoy it It's building So as you get there you'll see. Hey there's there's lots of information here but there maybe there's a little bit more coming every single week There'll be more information coming to you. So definitely check it out get on my email list because then I can send you information such as met with a gentleman just yesterday talking about his resume. I'll be having some tips and tricks about that as well. And so go check it out also. Go on to iTunes and these other places and give me a thumbs up or like me or whatever that is. Or leave a leave a comment as well. I really want to help you all And I know you'll be successful Just let me help you either through the podcast or through my website, give you what you need. All right Have a wonderful wonderful day and we'll catch you on the flip side. See ya…
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
…Hey y'all Shon Gerber with. CISSP cyber training.com and reduce cyber risk podcast. So how are you all today It's a beautiful day here in Wichita Kansas and it is an amazing amazing place to live in a beautiful country that we live in the United States It's awesome. No…Hey all this Shon Gerber with the CISSP cyber risk. No…Hey y'all is Shon Gerber with the CISSP is P cyber training and they reduce cyber risk podcast. Hope you all are having a wonderful wonderful day to day. So I'm having an awesome day here in Wichita Kansas It just it's amazing It's very nice It's actually the weather it's beautiful to bike 45 degrees So it is a great day. Well I hope you all have had a chance to listen to my other podcasts as it relates to the CISSP. Cyber training And the day this is episode four we're going to understand that the title of this is understanding the CISSP S P certification. And preparing for the future. Now, the last podcast we kind of talked a little bit about what how do you get into cybersecurity What is the training path and so forth? And this is kind of a follow onto that to kind of talk about the CISSP as P and why it's important. Now again a little bit about myself. Shon Gerber I've been in cybersecurity for 20 some years and I've got my CISSP and I've been doing this from a level of going from actually having no experience in cyber all the way up to being a chief information security officer So I understand this path and I've taught hundreds of people how to deal with cybersecurity from both from learning how to be a hacker up to the point of. Getting their CISSP. So I'm here to help you in your path Well, one of the things that comes out of this. is understanding how do you do this? Well, as we talk about how do you get your CISSP a couple things have come up from the conundrum around, how do I get my training How do I get into cyber And we answered that in the last podcast. Around some of the questions they have you know most of my students that I teach in college and I've taught in the past, they really come back and say they have really no idea what are the next steps. And so we went over that in the last podcast What are the next steps in How, what can you do to get past that space that space. The other thing is we had questions from business leaders around how do I find people in find open roles Well again, how do we get there with a train that's tied to that? And what can you do to become successful? And so we walked about that in the last episode but today we're actually now going to talk a little bit about how is what is the CISSP and how does that specifically work? So, as you all know the CISSP is P is one of the premier certification. that you need to get If you're going to become a long-term professional in the cybersecurity space. Now it's not required, but in reality it's it's held at such a high bar that most hiring companies really do want you to have the CISSP. And we'll kind of go into reasons why they think that and what's the purpose behind it. But one thing to think about if you get an it certification one of the things that come out of that as you say, you've got about a 22% better chance of being, of getting more income than being non-certified. And the reasons behind that in many cases is because the HR folks the individuals that are looking to hire you don't really know what they're looking for So they use a certification as a bar as a litmus test for you to basically get the role. Now if you have lots of experience and you don't have the certification, well that's fine too in many cases but there are some situations where the HR or the hiring manager may require the CISSP. Not necessarily realizing what they're actually requiring. So that's why it's kind of important to get your CISSP SP. As you're getting your CISSP There are some things you need to keep in mind. Why don't you got to have at least five years of experience learning and understanding security before you can even become a CISSP. And of that five years you have to have full-time employment in at least two of these eight domains that are tied to the CISSP exam. First one is I don't I've gone through the domains and you all have probably heard these or dealt with these especially if you're trying to get your CISSP SP. But for folks that have not really understand what are those domains What are those learning areas? Here are the eight. You have security and risk management. Assets security, security architecture and engineering. Communications and network security. Identity and access management. Security assessment and testing. Security operations. And software development security. Those are the eight domains that are tied to the CISSP exam. So what they're saying is is for you to get your CISSP. You can sit for the test pretty much at any time, but you cannot be a C I S S P until you actually have those five years experience. And you have to have again full-time employment that deals with at least two of the eight domains. But you got to understand that doesn't mean you have to be doing security necessarily in those eight domains. You have to be able to understand what are the domains Let's just say asset security for an example. And let's say you are in. It management and you're dealing with various servers. And you are responsible for those servers your work at a an it shop of some kind right. And you were responsible for those servers? Well that's the asset That's an asset security You could understand How do I best protect those assets? The other part comes into it is you could also have them tied into maybe you have development team that you work very closely with and they use those servers and you have are able to work with maybe the leader of that development team to help provide them guidance around software development. And what can you do in that area? That would also be a way that those would be two of the domains. And again there's a lot of there's a lot of openness in that. And it's not the fact that you pad your resume or you pad your knowledge which basically means you don't. Musically say you have more knowledge than you actually do, but you look for opportunities in your current role to help touch in all eight of those domains is many of those as you possibly can. And then you just have to be able to describe that and demonstrate that on your resume to the person who's going to be signing off as the CISSP is going to be signing off saying yes, Shon is qualified to become a CISSP. And that's something that I ended up doing is if someone comes to me, I look at the resume I do an interview Alfa the eight domains and I determine whether or not they actually have the knowledge they say they do. So those are parts that you're going to have to go into but that's okay because there's so many ways you can learn and get knowledge in these eight domains…Now the next step is your your concentrations. Now they do have a CISSP SP concentration is basically an add on now You don't necessarily have to do this You can just get your S your CISSP exam, but if you feel confident that you want to have the ability to get an add on after you get your CISSP you can go and sit for a architecture. Engineering or management add on to the CISSP S P a certificate. What it basically says is that you the CSSP understands the large, you you have a good grasp of that. But let's say you are really good at architecture and you enjoy that and you want to have an additional certification tied to that. You can go sit for the architectures, add on and then you can become a CISSP slash architecture. Now there'll be additional. and additional CPEs and that's continuing education professional education training that you'll have to do. But at the end of it it it just it's a personal preference. Is it needed, not necessarily unless the job that you always want is requiring it, but short of that it's not a necessity that you have that completed. Now the associate's CISSP is P you may have seen some information around that. Now the associate was designed to allow people to get into and start understanding the CISSP as P ahead of time, and maybe get the test out of the way while they're building up their experience. Now you have to be a practicing security professional. How are you, how are you actually working in the security space within and studying for the CISSP? You now and as you do that they they talk about having at least five years of full-time paid work experience which we talked about to actually get the CISSP. But you can get a various other additional training that will help you with getting that requirement that five years. So at the associate you can go in you can take the test you got that out of the way. And then if you go to college let's say for example you go to a four year school. Yeah that will count for one year of the five years that you have going towards being a CISSP…Now the other part is is…you can also take another certification So as an example if you go get your security plus certification, and there's a whole laundry list of various certifications that you get. If you can get one of those that will also knock off a year from your five-year requirement. The other thing about the associate program that is kind of important is that it allows you to get take six years to complete the five-year requirement. So it's designed for people that are maybe going to college and you end up you don't have time to get your you're spending a lot of time in school and you don't have that time to get your five years. You can then go out and take the test, be part of the associates program. And then it gives you basically an X. year. Now one thing you can't do is you can't use both the certificate or the certification process like security plus, and then the college degree you can't use them both to count for once for one year ones for another year. And that would be two years You can't do that. The most you can shave off of the required time that you have to have before you can actually become a certified CISSP is four years. Okay That's the actually say most you can shave off is one year. And so yeah it does require you to have four years experience at a minimum, if you have an additional certification or if you have gone to a school and therefore I bypass that product. Now, so that's an important thing to think about now the associates CISSP. I I'll tell you point blank I'm not a big supporter of it I don't think it's really useful other than allows you to take your test early. And but it adds a lot of complications to the to things So you just gotta decide if there's a situation where it may benefit you then maybe you should do it But. That's really a personal deCISSPion at that point. Now the CISSP has P endorsement. There's a key thing you need to keep in mind as it relates to once you get your CISSP or once you start studying for this process. Is you have to be endorsed by a currently. In good standing. CISSP S P person right. I myself or somebody else. They will have to then fill out the paperwork and help you fill out the paperwork and they will also have to do an interview of you. And they'll do an interview. They'll look at your CV and then they'll say yes. Bill Smith or Jenna Thompson or whoever is, has done all the requirements to be a CISSP they've taken the exam. They have the credentials, they have the resume, they have the work experience so on and so forth. Okay. So that's an important fact that you have to do. And it's so it must be in written form. And the ISC does acknowledge though that conversely. are the best method to ensure you're qualified So one thing to think about with that I have that little note. To make sure I bring up. They understand that you could do this via email However they do recommend that you have a. A formal conversation with the person. Personally. Unless I know the person very closely, I would want a personal conversation with them just to kind of talk about what do they know and where are they at? Because getting a, getting the CISSP exam and passing it that's just one step. And I and I think I've mentioned before in the previous podcast. Somebody may come in and just take the test or I've even seen it where people have taken the test for another individual. And that doesn't prove that you actually know anything All you know how to do is take a test. And so if I'm going to sign for somebody, I want to make sure that I know that they have the information they need to be successful, and I'm not going to cheapen the whole experience. You'll need your last name your member ID And again you'll then you'll wait for approval. But bottom line is there is a process by which you have to go. a sign off. Now one thing we talk about is the CISSP how important it is And it's it's a very important certification. And as you're relating to the overall training path with the CISSP SP I consider it. To be like a master's level program. And it really is because of the the concepts that I teach. at the CISSP level, in many cases…are beyond what is taught at most four year colleges. So it the overall concept now bits and pieces of the CISSP are taught at the four year schools. However many of the things that are in the master's programs are tied into the CISSP. So if you do get it I do firmly believe it is like having a master's program. But there are some additional certifications that would be extremely valuable for you. Prior to getting the CISSP. Because you don't have to do this but I feel that. It will help you not just getting the the certification, but also helping you with your long-term career. A plus that's dealing with hardware. Now many people just kind of scoff at that but it's really important because hardware has changed dramatically from when I did it many many years ago to where it is today. So having a firm grasp of hardware And how does hardware talk to each other? Is an important piece, then it rolls into the comp Tia network plus kind of training So you have comps T as A-plus and the networks plus. Very good networking capability. It teaches you how to do networking and the basic understanding of networking. It also teaches a little bit around security but mostly around how do networks communicate How do they talk? What is the differences between all of them? It's a really important factor because when you're trying to secure your network, if you don't understand networking protocols and how they work together, Then it makes it you're a bit of a disadvantage. Then there's the comp Tia security plus program. I do recommend that as well That gives you the basics of security. With layered on with the network capability. So you got eight plus networks plus and security plus all three of those will really put you in a great position for a good future. I mean I did all three of those and that was a while ago And the point comes back to is. Even talking to some of my students, they don't understand networking because they don't really know And this is students that are coming out of high school. This is also students that are coming out of college. If you're just trying to get into the cybersecurity field, it also is a really good way for you to understand if you really want to do this, because if you enjoy those three things, Then odds are high You'll be very successful if you don't enjoy them. Then you will not be happy doing any of this. So I feel it's really a good point that you need to kind of look as a prerequisite before even thinking about taking the CISSP. Or even getting into the cyber space career field. Now the cool part about all of that is is most of that stuff is online and it's free and you can gain access to it Just go to YouTube. Now I'm going to kind of break down a little bit around networks plus and what it can give you. So networks plus there's various domains similar to the CISSP. And it breaks into network concepts infrastructure network operations network security and network troubleshooting tools. Those are the bane domains that are tied to networks Plus. And dealing with wired and wireless networks IPV four V6 network availability cloud connectivity which is a big deal even more. And so it is a really important factor It gives you those foundational aspects too, because I deal with all of those topics on a daily basis, all of them every one of them. And so it's important for you to really understand and get the foundations of how they all work. Especially if you're coming into this really new and green to the entire event. The exam will cost you about three 50 to $400 And then you're passing scores about a seven 20. is the minimum passing score and this is from 100 to 900 Is the is the overall range? Again so you need to understand is that. do you need to take the test You don't necessarily have to take the test right There's no requirement to do it. Now they ask for required experience There really isn't any requirement They do recommend that you have between nine and 12 months of networking experience. So if you started off in a small business and you were doing networking for them, much of this would actually help you You'd be able to understand it a bit better but you don't have to have any sort of networking requirements to sit for the test. again, you decide whether it's a certification you want to do or don't want to do. Security plus the purpose of it it's meant for people with red or relatively new to the field of security and they want to pursue it. It talks about attacks threats and vulnerabilities. Architecture design implementation. Operations and incident response and then governance. we call it GRC which is your governance risk and compliance. Which is a huge factor right So you've got all of those aspects. That are in the security plus area. Well guess what? I deal with those on a daily basis. So it is. They would be very very helpful in a plus network plus security plus extremely good and foundational and to be blunt. That's what I taught our folks that were working as maintenance people with the B one. That was the same path that I taught them is A-plus networks plus and security plus, because it did it helped them understand whether or not they really truly wanted to get into the security world. Now some topics obviously is your incident response processes your governance and risk and compliance are key factors. Those are some of the topics you'll deal with. The cost is or between four and $450 us dollars. 90 multiple choice And your score is a seven 50 is what you have to have her passing and that's 100 to 900 Is the range itself. Multiple choice questions So again, You just need to pass the test if you really want to do it but there is no specific requirement for…security plus environment. Now as you look online there's some various aspects people will say well what should I get the CISSP versus security plus what should I do? Now as we've just kind of talked about here security plus is a good foundational thing to begin with. It gives you the core skills you need for any cybersecurity role. And it is a foundational aspect of it to understand cybersecurity language. I like to use the analogy is is if you have a shark and you have a dolphin, they don't talk the same language. Well you need to have a way to be able to get that shark to understand dolphin. Now it's probably a bad analogy Maybe it's a whale and a dolphin because they're both mammals but at the end of the day you need to have a way to communicate. The nice thing was security plus is it does give you that initial language to understand security conversations. Again no requirement for sitting for the test It's also a great way to help you determine if you like cyber, right. There's lots of self study products out there to help you pass the test with very little help again. You can do this or you really can't. The CISSP has P on the other hand it's like getting like I mentioned before master's degree in cybersecurity. It's more complex and challenging. The test is very challenging. There are specific requirements for passing the test and maintaining the certification These are CPEs your. I just lost it, but basically you're continuing professional education Right? So you those things are there that you're going to have to continue. That the certification is required by many hiring managers Whereas the security plus certification really isn't a requirement by anybody. You have traditional self study can be a long and problematic especially for the CISSP because it is realistically a four month process to pass the CISSP. If you do not have the security background and you do not have a lot of the experience and you're just trying to take the test, I'm just going to be blunt taking the CISSP. Without having much experience at all is a be a bit of a challenge You could do it but it would be very challenging. And having a security plus background and having a little bit of experience would go a long way in helping pass that test. Okay So at CISSP S P cyber training I have three options to help you with your CISSP is P you have yourself pace training. That's that's basically all the domains that are there One through eight for the CISSP. It's going to give you all the questions is going to help you with questions I've got multiple questions there I've got curated content and so forth in a step-by-step study guide. It's there over 20 some hours of video content. It's all available for you through the self-paced training. The tailored training piece of this is the membership and it's a monthly membership but it's designed to give you all the content that you would have with the self-paced aspect. But you do get additional content as it relates to the CISSP piece supplemental exam questions, as well as the podcast that I have curated and available to you. You also have the ability to ask me questions and have them answer each week. Then the last one is the personal coaching and membership or mentorship I have that in place It's a full membership It's available for you for a year. It gives you 12 schedule meetings to meet with me for at a period of time. and we will actually talk back and forth. It's a really good way to get your endorsement and also to help you with resume and interview prep. And I will tell you it's a great deal what it is because the fact is is that right now, if I meet with an outside company to talk about cybersecurity, like to do an evaluation of a product for them, I charge anywhere from three 50 on the low end to up to $500 an hour to visit with them. So this is a really good deal If you want if you're that place in your life where you want to actually be able to talk to them So to talk to somebody and help with mentorship. So again that's that's those are the three options that I can help you with at the CISSP cyber training. Now bottom line is you have to decide what is best for you and how you want to do it. But when it comes to the CISSP SP the certification and preparing for a future is not hard And I would recommend. That but it takes time and it takes effort. I shouldn't say it's not hard It is challenging but it's not insurmountable. What do you want do is decide do I want to do this If you want to do it then I'd highly recommend at a minimum If you don't want to do a plus and networks plus just to really understand if you like cyber. Then maybe just look at security plus and go through and sit through a course That's on YouTube and try to understand it. If that really interests you and you like that then I would recommend looking through the a plus network plus, and security plus videos that you might see. On YouTube Udemy wherever you're wherever their ELLs. And try to get up to speed on that. At the minimum then at that point if you really truly want to go study take for your CISSP reach out to me at CISSP cyber training or even before then, if I can help you with some questions that you may have around. Studying for the A-plus us networks plus or security Plus just come out to my site@CISSPcybertraining.com. And, and log in and just basically send me an email and I'm happy to help you with giving you some guidance and direction around that Again at the end of the day, I want you to be successful. I've helped a lot of people become. I've been doing this for a few years and I know what it takes to be successful in cyber. So let me help you do that. All right That is all I have for today We're going to be next a podcast actually I shouldn't before I leave I want to next podcast. We're going to be talking about the CISSP salary and as it relates to the the expectations for what you should be dealing with. On a roll And what does that look like? So again that's we'll get into salary the overall cost or the experience you can receive from from income all the way down to bonuses and so forth. That'll all be available to you in our next podcast And that will be number five. So short of that that is all I have for today I hope you have a wonderful day wherever you are at in the globe And we will catch you on the flip side. See.
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge in cybersecurity from being a Red Team Squadron Commander; Chief Information Security Officer (CISO); and Adjunct Professor providing superior training from his years of experience in educating people in cybersecurity.
This is the first episode of CISSP Cyber Training.com. In this episode, Shon will talk about his background and how he has been successful in cybersecurity.
BTW - Get access to all my Training Courses here at: https://www.cisspcybertraining.com
Want to find Shon Gerber / CISSP Cyber Training elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
CISSPCyberTraining.com - https://www.cisspcybertraining.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Transcript:
Hey everyone This is Shawn Gerber with CIS. Cyber training.com and reduce cyber risk podcast. I hope you all are having a beautiful day today And I will tell you that it is amazing here in the great state of Kansas in the United States. it is an awesome awesome day Actually It's about 42 degrees and I can't complain 40 degrees Fahrenheit That is so for my friends that are in India, that's a little bit different than what you guys have from a temperature standpoint. but as it relates to the CIS. And studying for the CISSP. I am just bringing forward this podcast I've been in business for a while but I want to talk a little bit about that but I'm bringing forward this podcast to help give you some understanding and training around taking the CISSP exam. So before we get started this is podcast 0 0 1 obviously the first, but you can also check out some of my other podcasts on reduced cyber risk podcast And I'll kind of get into the reason behind both of those but at the end of the day is this is just kind of an intro for those that are starting to listen to my podcast, why I'm doing it and who I am. So a little bit about myself So I am I grew up in a very small town in Iowa So just to state north of where I'm at in Kansas. And I was basically I've been there was there my entire life growing up. So the town was from the folks that I've met around the globe is about 250 people which is extremely small as it relates to a place to be from. Now as I got family that I've got kids that are from China You know obviously the smallest town in China in many cases is like a million people. So out of two hundred fifty, two hundred and fifty people. It's pretty tiny It's about the size of a block. but again I've been based out of the United States and I've lived now in Kansas in Wichita Kansas which is in the middle of the United States. And I'm married to a beautiful wife of 30 years And I am just completely amazed at what that she still sticks with me, but I. have been married for about 30 years to Trish Gerber and she's amazing lady. I have seven children and I am basically a son-in-law and a potential son-in-law that might be happening here in the near future. I have my children as you may Abby asking going. Y seven Yeah Well, I only have three biological that my wife and I produced but we have four adopted kids that are from Uganda. China and. Yeah those those two places So we have three kids from China We have one from Uganda. Now the reason I was had a pause is my potential future Son-in-law. again I say potential he's from Sri Lanka So we have a very diverse family. I also have a granddaughter and she is about two years old and she lives in Kentucky. So my family is pretty large and it's growing quite rapidly. So that's just a little bit about me and where I came from As far as my family life. No. why am I even doing this And you probably most of the folks that listen to these podcasts and especially reduce cyber risk and pod and people I introduced introduce with and I talked to. They all have a very strong background in some level of cybersecurity or in some level of it. Well, I don't but I started off with looking as a kid the Texas instruments T 80 and the apple two E's and I was part of the video game craze that hit Okay And I'll just tell you I'm an old guy compared to most of you that are probably listening to this podcast. I'm pretty old now I'm in my fifties So yeah that's that's like dirt old in many cases However, I've been doing a lot of stuff in those 50 years of my life and of which has been cybersecurity and the CISSP. But I got part of my growing up time was around computers and when they just started hitting the market and the T I 80 the apple two E's all of those were part of it I also started a beginning of programming within just basic. So I always had an affinity to really enjoy that type of activity I liked using my brain I like thinking of things outside the box and it was it was really an awesome awesome time. But when I grew up one of the things I always want to do is I wanted to be a pilot. I wanted to fly airplanes. And so as a child growing up learning to fly I started off with really small planes. Some of these that are two seat planes you have basically only the pilot and the copilot. Some of them were a little bit larger six eight passenger type planes but as time went on I learned to fly airplanes with the goal. Of becoming an airline pilot. That was my ultimate purpose is I wanted to be an airline pilot now. Fast forward to my current position I am not an airline pilot. So if you're trying to listen to this podcast and you want to know how to be an airline pilot, I can tell you how to get there but I don't have the experience to say that I lasted very long in that space. So after flight greeting, my. pilot's license So I grew up small airplanes Got my commercial pilot's license. Got my certified flight instructor license and I was teaching people how to fly small airplanes. Well an opportunity came up where I could fly the B one bomber. Now if you are connected with any of us military. there is a plane called the…and it's a four person. bomber very large Intercontinental bomber and it goes really fast and it's super sexy and is really cool. And I was had the opportunity to fly in that plane. Now growing up as a pilot that's what I wanted to do However because of my age at the time and what I was trying to find as far as military options, they were what they call banking pilots which means there weren't enough pilot seats available for the number of people wanting to fly. So I got banked and because of that I want but I wanted to fly and I didn't want to wait. I wanted to take any role I could in flying airplanes. So an opportunity came up for me to become the weapon systems officer on a B one with the goal that once I got in I could then hopefully upgrade to becoming the pilot. Did that for a flu until 2002. It was amazing opportunity I just loved it went really really fast really low really high, did all kinds of fun crazy stuff And I did that I flew with the Navy flew with the air force. And so I've had a really awesome career in aviation And so many people would think that and it's like amazing And it was. But life changed a different path. So as a transition. There'd be ones had decided there was leadership and Washington that made a decision that the were going to leave my organization. So after the B ones Ones went away. Then what ended up happening is is that there a we had to go out and try to find a new mission. So we went on a road show looking around the country trying to find a new mission to help employ people within the. To some extent we didn't know. that was going to be. However what ended up happening was is that we stumbled across an air force red team. The cool part about the air force red team was, was that it was in cybersecurity which was a relatively new space. But at the end of the day we knew we could teach people that had been on. been doing maintenance on airplanes and we could teach them potentially to become hackers for the government. Now the cool part about it was there was no training path in place nothing existed. So we had to build this from scratch on how to go from basically teaching. Wrench Turners. Okay Maintenance people to being a hacker on a global standpoint. And it was amazing I learned a lot out of it, learned some good things to how what worked We also learned some things that didn't work. Now the cool part about all this though is is that after that we pitched our idea to our leadership and they bought into it. We then took these folks and we taught them up in a series of timeframes. And the cool part is is it happened within a very short period of time, but we had a methodical standard approach on how you could actually get that done. Now again we took these group of people ended up being about 82 people Totally. Total. Of that there was about 40 of them became hackers for the government. Now we had full-time and I had part-time folks And of those they I would say the mix was probably around 60 40 now probably more like 80 20. 80% Full-time 20% Part-time. But we did global operations everywhere Okay All over the globe we operated, I actually was one of the initial cadre to help teach the NSA their red team Cause they were just standing one up at that time as well. So it was a really dynamic time especially in the cybersecurity space. The interesting part was though is it was really before we sat the vision to see where it was going but we just didn't know how big it was actually going to get I mean I had a sneaky suspicion It was going to be this big if not bigger, but we didn't really know…the other part of the barn being with a red team is our ultimate goal is to teach. the DOD department of defense and us air force employees on the threat. So I had to teach people who didn't understand cyber at all, what to do to be successful to protect themselves from external entities trying to steal their information. So again it was awesome It was extremely successful Military squadron it's been around it's still around. It's. It was an amazing experience. Now fast-forward to my CIS. P journey. What is that Well it was a result of the DOD requirement for CIS SPS and managers That's really what it came of. So I'd been leading the company. Leah my squadron I became I was a squatter commander so I was leading them in their organization their vision of where we were going. But the DOD requirement came out that you had to have a CISSP. I didn't necessarily have to have it but it was highly recommended and encouraged. Well that was really it personally the first exposure I had to the CIS. So I wa went out. and I started studying for it. Now I was the first person within our squadron to actually get the CISSP. And I there was no resources available The only resource that was out there was a book by Shawn Harris and the ISC squared study guide That was a pretty much it. So I took those books and I started going through them line by line by line. Now understand I came from a military background first a pilot, then military it, and then trying to understand in some respects corporate it, which they were very different. So it was a very challenging process when I was doing this. So the first time out there I studied for about four months reading the books reading Sean Harris's book reading the IC square book, and I took gobs and gobs of notes. Practice test after practice test after practice test. again it was a lot of work and I felt confident sort of in taking the test So what did I do I went and took the test. I guess what I failed. So just like. 80% of the people that take the CISSP exam they fail the first time. Now the problem is is that it was a lot of work to go in there the first time and then fail the test. So I had a little bit of just depression Not no prize pay is a strong word but I was just really bummed out. So I took about a month off of some self-pity going this socks I don't want to do this This is no fun. Right Just why am I doing this to myself? Well then I finally said okay enough of that let's go. So. Again started back up into studying Again, I redoubled my efforts on studying and I took a different approach now of which is the CIS. Study guide that I have on CISSP cyber training.com You can get the study guide out there. And that's the same study guide I used to pass it the second time. And so what I ended up doing was I went through it over and over and over and again after much time much thinking about it, but a really thing I came out of that second time was I understood now how to take the test What kind of questions are asking? So I traveled six hours to go take this test. As I traveled to this place in Arkansas to take it there they were having a bootcamp a CISSP bootcamp going on at that same time. But I didn't have the funds to pay for the bootcamp. So I just was going to take the take the test drop the $800 whatever it was at the time and just take the test. So I went in there I told myself if I fail it again, I'm done. I don't want to deal with this anymore. I'm done. Well guess what Second time around I passed So it was good right Life is good I pass the test, but I to pass the CISSP. In a squadron that really didn't require it. But I learned a lot during that process. Now fast forward a little bit further That was 2009 When I passed the CISSP I'm now in 2011 I leave. the military retire as Lieutenant Colonel. Leave the military and I go work for a large corporate entity Okay Large multinational. I get hired as a security architect and I'm learning the basics of corporate security. Now I have the background of it. I got flying background I've got. Military it, and now I'm learning corporate it so that I can understand all of the different gamuts that are there. Now this was a relatively new capability with the corporate organization And I assisted I also assisted in standing up a security operation center that is 24 by seven at that time. And it was basically on new technology They had never done it before. And so this is a whole new environment for this large multinational. Now after that time I ended up being the security operations manager for that. security operations center. Okay So I was the manager I have a sock, did that for about two and a half years And then an opportunity came up for me to become the CSO Okay The chief information security officer for another multinational that is under the the whole family of umbrella the umbrella of. There's one main company. So the point of it is though is that as the Cisco now for this other multinational we have a global presence We're in the cloud I mean IOT I'm in manufacturing I IP intellectual property. I mean the gamut is huge You've got about 6,000 employees So it's I mean it's a good size company It's not a monster like Georgia Pacific or Microsoft or anybody else. But it's a good size company right? So my ultimate goals is educating employees is my top priority I want to employ it educate them as well as protecting our companies intellectual property. So that is my corporate stint now. Been off a little bit is I also am an adjunct professor at a small college in Wichita Kansas. Now it's not small for Wichita but for most of you all that are listening on this podcast is probably not that big. Now it's about 10,000 12,000 students but as a professor adjunct professor there I teach cyber risk. And I also teach cyber-physical systems So IOT type activities. These are 400 level courses So again and not they're not lower level They're a higher level course. and because of that though I took that job with the re indication or with the idea. Of understanding the student's pain points What is a big struggle? Why are they what are some of the things they're having with as it relates to cyber how do they get their new jobs How do they get into the career? So the goal was was to understand all of those things so that I could be better at helping out people with cybersecurity. So as it relates now to sire certifications, I have various certifications Some of them are pretty old. Some of them are built They're kind of old right? Because when it comes to search I think certs are very important. So as a person who's gone through this entire process from from knowing nothing to growing up to be a a Cisco So for a large company. I've done search and there's value in those but there's also more of the value of the knowledge you gain out of getting the cert in my mind is much more important than actually check box I got the cert. Now. I've got a plus network plus security plus you know obviously the CISSP and then some various other ones out there as it relates to legal which I think is really important Illegal courses Super important for you. and there's some various pieces that are in there but you can you can go to my site at CIS S P S cyber training.com and you'll be able to see those as well. So again, take learn from me Okay This is I'm gonna give you my profile So I didn't start till I was in my late thirties with no clue in what I was doing. But yet I was getting into this cybersecurity field. I had no experience in it or security to speak of. I saw an opportunity and I jumped in with nothing to guide or direct me Now I had the military which was a big benefit and a lot of people say, well it's the military is reason you got what you did And that's probably a lot of truth in some of the knowledge that I've gained is because of the military. However, when I started there was nobody insecurity So now there's so many more opportunities for people to get into and get knowledge and experience way beyond whatever I had. Now I've made a lot of mistakes And so the key around that is let me help you navigate those mistakes and those issues for your career. My goal is to help you with that. I really do have a passion about helping people get jobs I just helped a couple of my students. what the, as a professor I was just helping them get jobs with local companies. And also with some other companies, I've helped them with resumes I've helped them with interview skills. All of that piece is is out there and available And I really want to help you do that. So like the point is is I've done it. I've went from being absolutely having no capability whatsoever I do not have a cybersecurity pedigree. I do not have a master's in cybersecurity I don't have any of that I barely have a bachelor's degree in aviation. But that doesn't mean anything All it means is that I have a passion for this and I want to succeed and I want to help other people succeed. So again that's my goal Help you get to the goals you want and you desire. that we all can get ahead That's the bottom line. So this podcast here was basically an introduction Now then the next podcast I'm going to talk about the CIS. Cyber training.com. A little bit more what you can find out there but I'm also going to talk about solving the training problem. Now again, going from zero to, I wouldn't say hero but zero to. A little bit more successful. has been an interesting event and I've learned a lot about the training problem that everybody's struggling with. I'll explain how I overcame it what I did to do what you can do immediately to help your future That's the goal How can you help yourselves and your family's future right now? And then eventually maybe get the role that you've always wanted And I will tell you that the role that you want. May change It will change as time goes on but the role that may be your future role may not even be existed yet It may not have been created. And then also want to help you begin a career that is satisfying and fulfillment fulfilling. and lastly I want you to help. the world. From the evil hacker hoard because they're out there everywhere trying to take advantage of this and we need more people that can actually step up. And fill the gap and be this. The security resources to help protect companies to help businesses, nonprofits you name it We need more resources in this space. So I would like to ask last plug is the go to…Training. cyber CISSP cyber training.com You can go check us out there There's a lot of really good stuff that's in there There's stuff That's free There's stuff that's paid. But bottom line is there's a lot of great information out there Now the site is relatively new, but the cool part about it is ever growing and ever building So you're just going to as every time you visit it you'll get to see more and more information. Get put there. So again this is the end of this podcast I'm extremely excited to work with you again as the introduction we will talk about the next one about. cyber training and solving the training problem So please definitely go there and listen to that one, but I hope you have a wonderful day and we will catch you on the flip side. See ya.
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://www.cisspcybertraining.com/
CISSP Exam Questions
Question: 165
Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection. Which of the following best describes an item the software development team needs to address to ensure that drivers cannot be loaded in an unauthorized manner? A. Improved security kernel processes B. Improved security perimeter processes C. Improved application programming interface processes D. Improved garbage collection processes
https://www.brainscape.com/subjects/cissp-domains
Question: 166
Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection. Which of the following best describes Steve’s confusion? A. Certification must happen first before the evaluation process can begin. B. Accreditation is the acceptance from management, which must take place before the evaluation process. C. Evaluation, certification, and accreditation are carried out by different groups with different purposes. D. Evaluation requirements include certification and accreditation components.
https://www.brainscape.com/subjects/cissp-domains
Question: 167
Sarah’s team must build a new operating system for her company’s internal functionality requirements. The system must be able to process data at different classifications levels and allow users of different clearances to be able to interact with only the data that maps to their profile. She is told that the system must provide data hiding, and her boss suggests that her team implement a hybrid microkernel design. Sarah knows that the resulting system must be able to achieve a rating of EAL 6 once it goes through the Common Criteria evaluation process. Which of the following best describes one of the system requirements outlined in this scenario and how it should be implemented? A. Data hiding should be implemented through memory deallocation. B. Data hiding should be implemented through properly developed interfaces. C. Data hiding should be implemented through a monolithic architecture. D. Data hiding should be implemented through multiprogramming.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://www.cisspcybertraining.com/
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from CISSPCyberTraining.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://www.cisspcybertraining.com/
CISSP Exam Questions
Question: 168
Sarah’s team must build a new operating system for her company’s internal functionality requirements. The system must be able to process data at different classifications levels and allow users of different clearances to be able to interact with only the data that maps to their profile. She is told that the system must provide data hiding, and her boss suggests that her team implement a hybrid microkernel design. Sarah knows that the resulting system must be able to achieve a rating of EAL 6 once it goes through the Common Criteria evaluation process. Which of the following is a characteristic that this new system will need to implement? A. Multiprogramming B. Simple integrity axiom C. Mandatory access control D. Formal verification
https://www.brainscape.com/subjects/cissp-domains
Question: 169
Sarah’s team must build a new operating system for her company’s internal functionality requirements. The system must be able to process data at different classifications levels and allow users of different clearances to be able to interact with only the data that maps to their profile. She is told that the system must provide data hiding, and her boss suggests that her team implement a hybrid microkernel design. Sarah knows that the resulting system must be able to achieve a rating of EAL 6 once it goes through the Common Criteria evaluation process. Which of the following reasons best describes her boss’s suggestion on the kernel design of the new system? A. Hardware layer abstraction for portability capability B. Layered functionality structure C. Reduced mode transition requirements D. Central location of all critical operating system processes
https://www.brainscape.com/subjects/cissp-domains
Question: 170
Sarah’s team must build a new operating system for her company’s internal functionality requirements. The system must be able to process data at different classifications levels and allow users of different clearances to be able to interact with only the data that maps to their profile. She is told that the system must provide data hiding, and her boss suggests that her team implement a hybrid microkernel design. Sarah knows that the resulting system must be able to achieve a rating of EAL 6 once it goes through the Common Criteria evaluation process. Which of the following is a required characteristic of the system Sarah’s team must build? A. Multilevel security B. Dedicated mode capability C. Simple security rule D. Clark-Wilson constructs
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 165
Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection. Which of the following best describes an item the software development team needs to address to ensure that drivers cannot be loaded in an unauthorized manner? A. Improved security kernel processes B. Improved security perimeter processes C. Improved application programming interface processes D. Improved garbage collection processes
https://www.brainscape.com/subjects/cissp-domains
Question: 166
Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection. Which of the following best describes Steve’s confusion? A. Certification must happen first before the evaluation process can begin. B. Accreditation is the acceptance from management, which must take place before the evaluation process. C. Evaluation, certification, and accreditation are carried out by different groups with different purposes. D. Evaluation requirements include certification and accreditation components.
https://www.brainscape.com/subjects/cissp-domains
Question: 167
Sarah’s team must build a new operating system for her company’s internal functionality requirements. The system must be able to process data at different classifications levels and allow users of different clearances to be able to interact with only the data that maps to their profile. She is told that the system must provide data hiding, and her boss suggests that her team implement a hybrid microkernel design. Sarah knows that the resulting system must be able to achieve a rating of EAL 6 once it goes through the Common Criteria evaluation process. Which of the following best describes one of the system requirements outlined in this scenario and how it should be implemented? A. Data hiding should be implemented through memory deallocation. B. Data hiding should be implemented through properly developed interfaces. C. Data hiding should be implemented through a monolithic architecture. D. Data hiding should be implemented through multiprogramming.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 162
John has been told that one of the applications installed on a web server within the DMZ accepts any length of information that a customer using a web browser inputs into the form the web server provides to collect new customer data. Which of the following describes an issue that John should be aware of pertaining to this type of issue? A. Application is written in the C programming language. B. Application is not carrying out enforcement of the trusted computing base. C. Application is running in ring 3 of a ring-based architecture. D. Application is not interacting with the memory manager properly.
https://www.brainscape.com/subjects/cissp-domains
Question: 163
Steve has found out that the software product that his team submitted for evaluation did not achieve the actual rating they were hoping for. He was confused about this issue since the software passed the necessary certification and accreditation processes before being deployed. Steve was told that the system allows for unauthorized device drivers to be loaded and that there was a key sequence that could be used to bypass the software access control protection mechanisms. Some feedback Steve received from the product testers is that it should implement address space layout randomization and data execution protection. A. Non-protected ROM sections B. Vulnerabilities that allowed malicious code to execute in protected memory sections C. Lack of a predefined and implemented trusted computing base D. Lack of a predefined and implemented security kernel
https://www.brainscape.com/subjects/cissp-domains
Question: 156
If a security mechanism offers availability, then it offers a high level of assurance that authorized subjects can _________ the data, objects, and resources.
A) Control
B) Audit
C) Access
D) Repudiate
Access
Accessibility of data, objects, and resources is the goal of availability. If a security mechanism offers availability, then it is highly likely that the data, objects, and resources are accessible to authorized subjects.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP study and training for Domain 4 (Communication and Network Security) of the CISSP Exam. His knowledge will provide the skills needed to pass the CISSP.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 159
Vulnerabilities and risks are evaluated based on their threats against which of the following?
A) One or more of the CIA Triad principles
B) Data usefulness
C) Due care
D) Extent of liability
One or more of the CIA Triad principles
Vulnerabilities and risks are evaluated based on their threats against one or more of the CIA Triad principles.
https://www.brainscape.com/subjects/cissp-domains
Question: 160
While performing a risk analysis, you identify a threat of fire and a vulnerability because there are no fire extinguishers. Based on this information, which of the following is a possible risk?
A) Virus infection
B) Damage to equipment
C) System malfunction
D) Unauthorized access to confidential information
Damage to equipment
The threat of a fire and the vulnerability of a lack of fire extinguishers lead to the risk of damage to equipment.
https://www.brainscape.com/subjects/cissp-domains
Question: 161
What process or event is typically hosted by an organization and is targeted to groups of employees with similar job functions?
A) Education
B) Awareness
C) Training
D) Termination
Training
Training is teaching employees to perform their work tasks and to comply with the security policy. Training is typically hosted by an organization and is targeted to groups of employees with similar job functions.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP training and study around the tools you need to better understand what you need to know to be better prepared for the CISSP Exam Questions. His knowledge will provide the skills needed to pass the CISSP Exam.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 156
If a security mechanism offers availability, then it offers a high level of assurance that authorized subjects can _________ the data, objects, and resources.
A) Control
B) Audit
C) Access
D) Repudiate
Access
Accessibility of data, objects, and resources is the goal of availability. If a security mechanism offers availability, then it is highly likely that the data, objects, and resources are accessible to authorized subjects.
https://www.brainscape.com/subjects/cissp-domains
Question: 157
All but which of the following items require awareness for all individuals affected?
A) Restricting personal email
B) Recording phone conversations
C) Gathering information about surfing habits
D) The backup mechanism used to retain email messages
The backup mechanism used to retain email messages
Users should be aware that email messages are retained, but the backup mechanism used to perform this operation does not need to be disclosed to them.
https://www.brainscape.com/subjects/cissp-domains
Question: 158
Which of the following statements is not true?
A) IT security can provide protection only against logical or technical attacks.
B) The process by which the goals of risk management are achieved is known as risk analysis.
C) Risks to an IT infrastructure are all computer based.
D) An asset is anything used in a business process or task.
Risks to an IT infrastructure are all computer based.
Risks to an IT infrastructure are not all computer based. In fact, many risks come from noncomputer sources. It is important to consider all possible risks when performing risk evaluation for an organization. Failing to properly evaluate and respond to all forms of risk, a company remains vulnerable.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 153
Which commercial business/private sector data classification is used to control information about individuals within an organization?
A) Confidential
B) Private
C) Sensitive
D) Proprietary
Private
The commercial business/private sector data classification of private is used to protect information about individuals.
https://www.brainscape.com/subjects/cissp-domains
Question: 154
Which of the following is not an element of the risk analysis process?
A) Analyzing an environment for risks
B) Creating a cost/benefit report for safeguards to present to upper management
C) Selecting appropriate safeguards and implementing them
D) Evaluating each threat event as to its likelihood of occurring and cost of the resulting damage
Selecting appropriate safeguards and implementing them
Risk analysis includes analyzing an environment for risks, evaluating each threat event as to its likelihood of occurring and the cost of the damage it would cause, assessing the cost of various countermeasures for each risk, and creating a cost/benefit report for safeguards to present to upper management. Selecting safeguards is a task of upper management based on the results of risk analysis. It is a task that falls under risk management, but it is not part of the risk analysis process.
https://www.brainscape.com/subjects/cissp-domains
Question: 155
Which of the following is not a defense against collusion?
A) Separation of duties
B) Restricted job responsibilities
C) Group user accounts
D) Job rotation
Group user accounts
Group user accounts allow for multiple people to log in under a single user account. This allows collusion because it prevents individual accountability.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
Shon will provide CISSP study and training for Domain 3 (Engineering Secure Design) of the CISSP Exam. His knowledge will provide the skills needed to pass the CISSP.
BTW - Get access to all my Free Content and CISSP Training Courses here at: https://shongerber.com/
Available Courses:
CISSP Exam Questions
Question: 150
How is the value of a safeguard to a company calculated?
A) ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard
B) ALE before safeguard * ARO of safeguard
C) ALE after implementing safeguard - annual cost of safeguard - controls gap
D) Total risk - controls gap
[A] ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard
The value of a safeguard to an organization is calculated by ALE before safeguard - ALE after implementing the safeguard - annual cost of safeguard [(ALE1 -- ALE2) - ACS].
https://www.brainscape.com/subjects/cissp-domains
Question: 151
What is the primary objective of data classification schemes?
A) To control access to objects for authorized subjects
B) To formalize and stratify the process of securing data based on assigned labels of importance and sensitivity
C) To establish a transaction trail for auditing accountability
D) To manipulate access controls to provide for the most efficient means to grant or restrict functionality
[B] To formalize and stratify the process of securing data based on assigned labels of importance and sensitivity
The primary objective of data classification schemes is to formalize and stratify the process of securing data based on assigned labels of importance and sensitivity.
https://www.brainscape.com/subjects/cissp-domains
Question: 152
What is the primary goal of change management?
A) Maintaining documentation
B) Keeping users informed of changes
C) Allowing rollback of failed changes
D) Preventing security compromises
Preventing security compromises
The prevention of security compromises is the primary goal of change management.
https://www.brainscape.com/subjects/cissp-domains
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 144
To get proper management support and approval of the plan, a business case must be made. Which of the following is least important to this business case? A. Regulatory and legal requirements B. Company vulnerabilities to disasters and disruptions C. How other companies are dealing with these issues D. The impact the company can endure if a disaster hits
C. The other three answers are key components when building a business case. Although it is a good idea to investigate and learn about how other companies are dealing with similar issues, it is the least important of the four items listed.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 145
Which of the following describes a parallel test? A. It is performed to ensure that operations performed at the alternate site also give the same results as at the primary site. B. All departments receive a copy of the disaster recovery plan and walk through it. C. Representatives from each department come together and go through the test collectively. D. Normal operations are shut down.
A. In a parallel test, some systems are run at the alternate site, and the results are compared with how processing takes place at the primary site. This is to ensure that the systems work in that area and productivity is not affected. This also extends the previous test and allows the team to walk through the steps of setting up and configuring systems at the offsite facility.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 146
Which of the following describes a structured walk-through test? A. It is performed to ensure that critical systems will run at the alternate site. B. All departments receive a copy of the disaster recovery plan and walk through it. C. Representatives from each department come together and review the steps of the test collectively without actually performing those steps. D. Normal operations are shut down.
C. During a structured walk-through test, functional representatives review the plan to ensure its accuracy and that it correctly and accurately reflects the company’s recovery strategy.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 147
When is the emergency actually over for a company? A. When all people are safe and accounted for B. When all operations and people are moved back into the primary site C. When operations are safely moved to the offsite facility D. When a civil official declares that all is safe
B. The emergency is not actually over until the company moves back into its primary site. The company is still vulnerable and at risk while it is operating in an altered or crippled state. This state of vulnerability is not over until the company is operating in the way it was prior to the disaster. Of course, this may mean that the primary site has to be totally rebuilt if it was destroyed
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 141
Who has the final approval of the business continuity plan? A. The planning committee B. Each representative of each department C. Management D. External authority
C. Management really has the final approval over everything within a company, including these plans.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 142
What is the most crucial requirement in developing a business continuity plan? A. Business impact analysis B. Implementation, testing, and following through C. Participation from each and every department D. Management support
D. Management’s support is the first thing to obtain before putting any real effort into developing these plans. Without management’s support, the effort will not receive the necessary attention, resources, funds, or enforcement.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 143
During development, testing, and maintenance of the continuity plan, a high degree of interaction and communications is crucial to the process. Why? A. This is a regulatory requirement of the process. B. The more people who talk about it and are involved, the more awareness will increase. C. This is not crucial to the plan and should not be interactive because it will most likely affect operations. D. Management will more likely support it.
B. Communication not only spreads awareness of these plans and their contents, but also allows more people to discuss the possible threats and solutions, which may lead to ideas that the original team did not consider.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 138
Which of the following is something that should be required of an offsite backup facility that stores backed-up media for companies? A. The facility should be within 10 to 15 minutes of the original facility to ensure easy access. B. The facility should contain all necessary PCs and servers and should have raised flooring. C. The facility should be protected by an armed guard. D. The facility should protect against unauthorized access and entry.
D. This question addresses a facility that is used to store backed-up data; it is not talking about an offsite facility used for disaster recovery purposes. The facility should not be only 10 to 15 minutes away, because some types of disasters could destroy both the company’s main facility and this facility if they are that close together, in which case the company would lose all of its information. The facility should have the same security standards as the company’s security, including protection against unauthorized access.
https://www.brainscape.com/flashcards/cissp-chapter-8-business-continuity-and-d-1538409/packs/2943708
Question: 139
Which item will a business impact analysis not identify? A. Whether the company is best suited for a parallel or full-interrupt test B. What areas would suffer the greatest operational and financial loss in the event of a particular disaster or disruption C. What systems are critical for the company and must be highly protected D. What amount of outage time a company can endure before it is permanently crippled
A. All the other answers address the main components of a business impact analysis. Determining the best type of exercise or drill to carry out is not covered under this type of analysis
https://www.brainscape.com/flashcards/cissp-chapter-8-business-continuity-and-d-1538409/packs/2943708
Question: 140
Which areas of a company are recovery plans recommended for? A. The most important operational and financial areas B. The areas that house the critical systems C. All areas D. The areas that the company cannot survive without
C. It is best if every department within the company has its own contingency plan and procedures in place. These individual plans would “roll up” into the overall enterprise BCP.
https://www.brainscape.com/flashcards/cissp-chapter-8-business-continuity-and-d-1538409/packs/2943708
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 135
Which of the following contains references to expected business continuity planning (BCP) practices that organizations must implement
A. ISO 17799:2008, Section 1 B. ISO 27005:2008, Section 8 C. ISO 27002:2005, Section 10 D. ISO 27001:2005, Annex A
Answer: D
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 136
What process identifies the business continuity requirements for the organization's assets? A. risk analysis B. business impact analysis C. threat analysis D. asset classification
Answer: B
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 137
A contingency plans should be written to A. address all possible risk scenarios B. address all likely risk scenarios C. remediate all vulnerabilities D. recover all operations
Answer: B
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 132
Which of the following is less likely to accompany a contingency plan, either within the plan itself or in the form of an appendix?
A. Contact information for all personnel
B. Vendor contract information, including offsite storage and alternate site
C. Equipment ad system requirements lists of hardware, software, firmware, and other resources required to support system operations
D. The Business Impact Analysis
Answer: D Explanation: You use the BIA as a guideline to create the contingency plan.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 133
The first step in contingency planning is to perform:
A. A hardware backup B. A data backup C. An operating system software backup D. An application software backup
Answer: B
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Question: 134
Which of the following teams should not be included in an organization’s contingency plan?
A. Damage assessment team B. Hardware salvage team C. Tiger team D. Legal affairs team
Answer: C Explanation: Tiger is an algorithm Excerpt is from CISSP / Shon Harris / 5th edition.
https://www.brainscape.com/flashcards/business-continuity-planning-4303634/packs/6456925
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 129
Which of the following could lead to the conclusion that a disaster recovery plan may not be operational within the timeframe the business needs to recover? A. )The alternate site is a warm site B. Critical recovery priority levels are not defined C. Offsite backups are located away from the alternate site D. The alternate site is located 70 miles away from the primary site
Answer: B Explanation:
From
Question: 130
What are the four domains of communication in the disaster planning and recovery process? A. Plan manual, plan communication, primer for survival, warning and alarms B. Plan communication, primer for survival, escalation, declaration C. Plan manual, warning and alarm, declaration, primer for survival D. Primer for survival, escalation, plan communication, warning and alarm
Answer: C Explanation:
From
Question: 131
The underlying reason for creating a disaster planning and recover strategy is to A. Mitigate risks associated with disaster. B. Enable a business to continue functioning without impact. C. Protect the organization’s people, place and processes. D. Minimize financial profile.
Answer: A Explanation: “Disaster recovery has the goal of minimizing the effects of a disaster and taking the necessary steps to ensure that the resources, personnel, and business processes are able to resume operation in a timely manner.” Pg 550 Shon Harris: All-in-One CISSP Certification
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 128
In what type of software testing does the tester have access to the underlying source code?
Static testing
In order to conduct a static test, the tester must have access to the underlying source code.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 129
What portion of the change management process allows developers to prioritize tasks?
Request control
The request control provides users with a framework to request changes and developers with the opportunity to prioritize those requests.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 130
Which one of the following key types is used to enforce referential integrity between database tables?
Foreign key
Foreign keys are used to enforce referential integrity constraints between tables that participate in a relationship.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 125
What type of virus utilizes more than one propagation technique to maximize the number of penetrated systems?
Multipartite virus
Multipartite viruses use two or more propagation techniques (for example, file infection and boot sector infection) to maximize their reach.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 126
What programming language(s) can be used to develop ActiveX controls for use on an Internet site?
All of these are correct
Microsoft's ActiveX technology supports a number of programming languages, including Visual Basic, C, C++, and Java. On the other hand, only the Java language can be used to write Java applets.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 127
What transaction management principle ensures that two transactions do not interfere with each other as they operate on the same data?
Isolation
The isolation principle states that two transactions operating on the same data must be temporarily separated from each other such that one does not interfere with the other.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 8 (Software Development Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 122
What type of reconnaissance attack provides attackers with useful information about the services running on a system?
Port scan
Port scans reveal the ports associated with services running on a machine and available to the public.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 123
What technology does the Java language use to minimize the threat posed by applets?
Sandbox
The Java sandbox isolates applets and allows them to run within a protected environment, limiting the effect they may have on the rest of the system.
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Question: 124
What is the most effective defense against cross-site scripting attacks?
Input validation
Input validation prevents cross-site scripting attacks by limiting user input to a predefined range. This prevents the attacker from including the HTML
From https://www.brainscape.com/flashcards/software-development-security-976024/packs/1774328
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 119
Explanation: [d] A violation of a company's acceptable use policy is considered a Computer Security Incident. The other options fit within the broad concept of an incident.
Question: 120
Explanation: [b] The primary goal of a Change Management Process is to avoid outages within your network environment. All of the above are important, but the primary goal is to avoid outages.
Question: 121
Explanation: [d] All of the above are considered a strategic solution for you backups within a business environment.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 116
Explanation: [a] All of the above are reasons not to keep log files too long on your environment, but the highest risk to your organization is the opportunity for legal discovery.
Question: 117
Explanation: [c] Each person should only have the access needed for their role/position. Typically, employees’ access will increase over time as access is granted, but rarely removed.
Question: 118
Explanation: [b] CDs / DVDs will degrade over time and should not be considered good storage media for data for long periods of time.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 7 (Security Operations) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 113
Explanation: [d] All of the above should be considered when conducting an investigation of an incident within your organization.
Question: 114
Explanation: [a] When gathering evidence there are three legal options available to gain access to evidence: Voluntary Surrender, Subpoena, and a Search Warrant.
Question: 115
Explanation: [a] There are situations where emergency changes need to occur, but it should be an emergency and not the desire of an individual to just make the change.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
o https://www.isc2.org/Training/Self-Study-Resources
o https://www.dflabs.com/blog/9-key-components-of-incident-and-forensics-management/
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 6 (Security Assessment and Testing) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 110
Tom would like to test system that lie within his network for vulnerabilities that could be exploited by the most recent set of ransomware variants. Which one of the following tools would be best suited to accomplish this task?
Explanation [b] A network vulnerability scanner would be the best tool for discovering what vulnerabilities reside within your network.
Question: 111
Explanation: [b] An authenticated scan allows you to use credentials which will provide you the most detailed information. An unauthenticated scan will only provide you a view that is available from the outside and may not be an adequate or fair assessment of the system.
Question: 112
What is the most common port used to communicated encrypted traffic on a web server?
Explanation: [d] 443 is the common standard where encrypted communications use for transmitting data. However, any port can be used for encrypted data, but 443 is considered the common standard.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 6 (Security Assessment and Testing) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 108
What are the various phases associated with completing a Penetration Test for an organization.
Explanation: [c] Planning, Reporting, Vulnerability Scanning, Exploiting, and Information Gathering (not in order) are the phases of completing a penetration test for an organization.
Question: 109
When creating metrics for your leadership, what are first items you should focus first on and what should be your level of complexity for the report?
Explanation: [b] Starting off with simple metrics focused on critical systems with the following metrics: Open vulnerabilities, Time to resolve, Outdated systems, Uploaded data, Legal/Compliance Issues is the best method to get started. Obviously, you organization may be different and you will have to modify to meet your needs, but it is good place to get started….keep it simple.
Question: 110
When completing a Penetration Test of your organization who needs to be involved in the discussion and decision?
Explanation: [c] It is important the right people are involved in the decision making process as a Pen Test can have significant impact on an organization and cause a disruption within a company.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 6 (Security Assessment and Testing) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 105
What tool is commonly used as scan engine to find vulnerabilities within an environment
Explanation: [a] Nessus is commonly used to look for vulnerabilities within an network to determine if an exploit can be used against the system.
Question: 106
What are the typical components that security assessments are typically used within an organization?
Explanation: [a] Tests, Assessments, and Audits are the main components of a security assessment for an organization.
Question: 107
Which one items below is not normally added as part of a security assessment?
Explanation: [c] Vulnerability mitigation strategies are not typically added as a part of the overall security assessment as the mitigation and/or acceptance of risk is highly dependent on the organization.
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 5 (Identity and Access Management) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 102
If you want to restrict access into or out of a facility, which would you choose?
Turnstile
A turnstile is a form of gate that prevents more than one person from gaining entry at a time and often restricts movement to one direction. It is used to gain entry but not exit, or vice versa.
From
Question: 103
Which of the following is not a disadvantage of using security guards?
Security guards are usually unaware of the scope of the operations within a facility.
Security guards are usually unaware of the scope of the operations within a facility, which supports confidentiality of those operations and thus helps reduce the possibility that a security guard will be involved in the disclosure of confidential information.
From
Question: 104
What type of motion detector senses changes in the electrical or magnetic field surrounding a monitored object?
Capacitance
A capacitance motion detector senses changes in the electrical or magnetic field surrounding a monitored object.
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 5 (Identity and Access Management) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 099
What is the ideal humidity range for a computer room?
40-60 percent
The humidity in a computer room should ideally be from 40 to 60 percent.
From
Question: 100
A Type B fire extinguisher may use all except which of the following suppression mediums?
Water
Water is never the suppression medium in Type B fire extinguishers because they are used on liquid fires.
From
Question: 101
Which of the following is not a disadvantage of using security guards?
Security guards are usually unaware of the scope of the operations within a facility.
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 5 (Identity and Access Management) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 096
At what voltage level can static electricity cause destruction of data stored on hard drives?
1,500
Destruction of data stored on hard drives can be caused by 1,500 volts of static electricity.
From https://www.brainscape.com/flashcards/physical-environmental-security-1004067/packs/1774328
Question: 097
What type of physical security controls focus on facility construction and selection, site management, personnel controls, awareness training, and emergency response and procedures?
Administrative
Administrative physical security controls include facility construction and selection, site management, personnel controls, awareness training, and emergency response and procedures.
From https://www.brainscape.com/flashcards/physical-environmental-security-1004067/packs/1774328
Question: 098
Which of the following is typically not a culprit in causing damage to computer equipment in the event of a fire and a triggered suppression?
Light
Light is usually not damaging to most computer equipment, but fire, smoke, and the suppression medium (typically water) are very destructive.
From https://www.brainscape.com/flashcards/physical-environmental-security-1004067/packs/1774328
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 4 (Communication and Network Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 093
________ is a standards-based mechanism for providing encryption for point-to-point TCP/IP traffic.
IPSec
IPSec, or IP Security, is a standards-based mechanism for providing encryption for point-to-point TCP/IP traffic.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Question: 094
What is both a benefit and a potentially harmful implication of multilayer protocols?
Encapsulation
Encapsulation is both a benefit and a potentially harmful implication of multilayer protocols.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Question: 095
Which of the following is not true regarding firewalls?
They are able to block viruses.
Most firewalls offer extensive logging, auditing, and monitoring capabilities as well as alarms and even basic IDS functions. Firewalls are unable to block viruses or malicious code transmitted through otherwise authorized communication channels, prevent unauthorized but accidental or intended disclosure of information by users, prevent attacks by malicious users already behind the firewall, or protect data after it passed out of or into the private network.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Subscribe: iTunes | Goggle Play | Stitcher Radio | RSS
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 4 (Communication and Network Security) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 090
Which type of firewall automatically adjusts its filtering rules based on the content of the traffic of existing sessions?
Dynamic packet filtering
Dynamic packet-filtering firewalls enable the real-time modification of the filtering rules based on traffic content.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Question: 091
By examining the source and destination addresses, the application usage, the source of origin, and the relationship between current packets with the previous packets of the same session, firewalls are able to grant a broader range of access for authorized users and activities and actively watch for and block unauthorized users and activities.
Stateful inspection
Stateful inspection firewalls are able to grant a broader range of access for authorized users and activities and actively watch for and block unauthorized users and activities.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Question: 092
Which of the following can be used to bypass even the best physical and logical security mechanisms to gain access to a system?
Social engineering
Social engineering can often be used to bypass even the most effective physical and logical controls. Whatever activity the attacker convinces the victim to perform, it is usually directed toward opening a back door that the attacker can use to gain access to the network.
From https://www.brainscape.com/flashcards/telecommunications-and-network-security-971259/packs/1774328
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 3 (Engineering Secure Design) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 084
What is the most commonly used technique to protect against virus attacks?
Signature detection
Signature detection mechanisms use known descriptions of viruses to identify malicious code resident on a system.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 085
In which of the following security modes can you be assured that all users have access permissions for all information processed by the system but will not necessarily need to know of all that information?
System high
In system high mode, all users have appropriate clearances and access permissions for all information processed by the system but need to know only some of the information processed by that system.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 086
What is a trusted computing base (TCB)?
The combination of hardware, software, and controls that work together to enforce a security policy
The TCB is the combination of hardware, software, and controls that work together to enforce a security policy.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 3 (Engineering Secure Design) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 081
Which one of the following storage devices is most likely to require encryption technology in order to maintain data security in a networked environment?
Removable drives
Removable drives are easily taken out of their authorized physical location, and it is often not possible to apply operating system access controls to them. Therefore, encryption is often the only security measure short of physical security that can be afforded to them. Backup tapes are most often well controlled through physical security measures. Hard disks and RAM chips are often secured through operating system access controls.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 082
What advanced virus technique modifies the malicious code of a virus on each system it infects?
Polymorphism
In an attempt to avoid detection by signature-based antivirus software packages, polymorphic viruses modify their own code each time they infect a system.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 083
Which one of the following types of memory might retain information after being removed from a computer and, therefore, represent a security risk?
Secondary memory
Secondary memory is a term used to describe magnetic and optical media. These devices will retain their contents after being removed from the computer and may later be read by another user.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will provide CISSP training for Domain 3 (Engineering Secure Design) of the CISSP Exam. His extensive training will cover all of the CISSP domains.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 078
Which database security risk occurs when data from a higher classification level is mixed with data from a lower classification level?
Contamination
Contamination is the mixing of data from a higher classification level and/or need-to-know requirement with data from a lower classification level and/or need-to-know requirement.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 079
How many major categories do the TCSEC criteria define?
Four
TCSEC defines four major categories: category A is verified protection, category B is mandatory protection, category C is discretionary protection, and category D is minimal protection.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Question: 080
Which Bell-LaPadula property keeps lower-level subjects from accessing objects with a higher security level?
No read up property
The no read up the property, also called the Simple Security Policy, prohibits subjects from reading a higher security level object.
Source: https://www.brainscape.com/flashcards/security-architecture-and-design-983876/packs/1774328>
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 075
As head of sales, Jim is the data owner for the sales department. Which of the following is not Jim’s responsibility as data owner?
Answer: C. The responsibility of verifying the availability of data is the only responsibility listed that does not belong to the data (information) owner. Rather, it is the responsibility of the data (information) custodian. The data custodian is also responsible for maintaining and protecting data as dictated by the data owner. This includes performing regular backups of data, restoring data from backup media, retaining records of activity, and fulfilling information security and data protection requirements in the company’s policies, guidelines, and standards. Data owners work at a higher level than the data custodians. The data owners basically state, “This is the level of integrity, availability, and confidentiality that needs to be provided—now go do it.” The data custodian must then carry out these mandates and follow up with the installed controls to make sure they are working properly.
From
Question: 076
Assigning data classification levels can help with all of the following except:
Answer: C. Data classification does not involve the extraction of data from a database. However, data classification can be used to dictate who has access to read and write data that is stored in a database. Each classification should have separate handling requirements and procedures pertaining to how that data is accessed, used, and destroyed. For example, in a corporation, confidential information may only be accessed by senior management. Auditing could be very detailed and its results monitored daily, and degaussing or overwriting procedures may be required to erase the data. On the other hand, information classified as public may be accessed by all employees, with no special auditing or destruction methods required.
From
Question: 077
Susan, an attorney, has been hired to fill a new position at Widgets, Inc.: chief privacy officer (CPO). What is the primary function of her new role?
Answer: [Ensuring the protection of customer, company, and employee data] The chief privacy officer (CPO) position is being created by companies in response to the increasing demands on organizations to protect myriad types of data. The CPO is responsible for ensuring the security of customer, company, and employee data, which keeps the company free from legal prosecution and—hopefully—out of the headlines. Thus, the CPO is directly involved with setting policies on how data is collected, protected, and distributed to third parties. The CPO is usually an attorney and reports to the chief security officer (CSO).
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 072
Jared plays a role in his company’s data classification system. In this role, he must practice due care when accessing data and ensure that the data is used only in accordance with allowed policy while abiding by the rules set for the classification of the data. He does not determine, maintain, or evaluate controls, so what is Jared’s role?
Answer: C. Any individual who uses data for work-related tasks is a data user. Users must have the necessary level of access to the data to perform the duties within their position and are responsible for following operational security procedures to ensure the data’s confidentiality, integrity, and availability to others. This means that users must practice due care and act in accordance with both security policy and data classification rules.
From
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 069
You work as an IT professional for a defense contractor that handles classified military information. Which one of the following data classifications applies to information that could be expected to cause serious damage to national security if disclosed in an unauthorized fashion?
Top Secret classification is \"applied to information, the unauthorized disclosure of which reasonably could be expected to cause exceptionally grave damage to the national security.\" Confidential classification is \"applied to information, the unauthorized disclosure of which reasonably could be expected to cause damage to the national security.\" Sensitive But Unclassified (SBU) information is protected information that does not reach the threshold for classified information
From
Question: 070
You are using symmetric encryption to protect data stored on a hard drive that will be shipped across the country. What key(s) are involved in the protection of this information?
Public keys are used to encrypt information intended for a specific recipient in asymmetric cryptography. They are not used in symmetric cryptography. Private keys are used to decrypt information in asymmetric cryptography. They are not used in symmetric cryptography. Public and private keypairs are used in asymmetric cryptography. They are not used in symmetric cryptography.
From
Question: 071
Which one of the following is NOT a European Union data handling principle required for participation in the Safe Harbor program?
The Notice principle states that organizations must inform individuals about the purpose and scope of data collection efforts. The Choice principle states that organizations must offer individuals the ability to opt out of information collection and storage programs. The Onward Transfer principle states that organizations must only share information with other organizations that comply with the data privacy directive
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 066
Which of the following would generally not be considered an asset in a risk analysis?
Answer: [D] Users' personal files - The personal files of users are not usually considered assets of the organization and thus are not considered in a risk analysis.
From
Question: 067
You've performed a basic quantitative risk analysis on a specific threat/vulnerability/risk relation. You select a possible countermeasure. When performing the calculations again, which of the following factors will change?
Answer: [d] Annualized rate of occurrence - A countermeasure directly affects the annualized rate of occurrence, primarily because the countermeasure is designed to prevent the occurrence of the risk, thus reducing its frequency per year.
From
Question: 068
What ensures that the subject of an activity or event cannot deny that the event occurred?
Answer: [c] Nonrepudiation - Nonrepudiation ensures that the subject of an activity or event cannot deny that the event occurred.
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 063
When seeking to hire new employees, what is the first step?
Answer: A. Create a job description.
The first step in hiring new employees is to create a job description. Without a job description, there is no consensus on what type of individual needs to be found and hired.
Source: From
Question: 064
Which of the following describes the freedom from being observed, monitored, or examined without consent or knowledge?
Answer: [b] Privacy - One definition of privacy is freedom from being observed, monitored, or examined without consent or knowledge.
Source: From
Question: 065
Which of the following is typically not a characteristic considered when classifying data?
Answer: [b] Size of object - Size is not a criterion for establishing data classification. When classifying an object, you should take value, lifetime, and security implications into consideration.
From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
CISSP Exam Questions
Question: 060
You are a security consultant. A large enterprise customer hires you to ensure that their security operations are following industry standard control frameworks. For this project, the customer wants you to focus on technology solutions that will discourage malicious activities. Which type of control framework should you focus on?
Answer: [B] Explanation: Deterrent frameworks are technology-related and used to discourage malicious activities. For example, an intrusion prevention system or a firewall would be appropriate in this framework.
There are three other primary control frameworks. A preventative framework helps establish security policies and
security awareness training. A detective framework is focused on finding unauthorized activity in your environment
after a security incident. A corrective framework focuses on activities to get your environment back after a security
incident. There isn’t an assessment framework.
Source: From
Question: 061
You are performing a risk analysis for an internet service provider (ISP) that has thousands of customers on its broadband network. Over the past 5 years, some customers have been compromised or experienced data breaches. The ISP has a large amount of monitoring and log data for all customers. You need to figure out the chances of additional customers experiencing a security incident based on that data. Which type of approach should you use for the risk analysis?
Answer: [B] Explanation: You have three risk analysis methods to choose from: qualitative (which uses a risk analysis matrix), quantitative (which uses money or metrics to compute), or hybrid (a combination of qualitative and quantitative but not an answer choice in this scenario). Because the ISP has monitoring and log data, you should use a quantitative approach; it will help quantify the chances of additional customers experiencing a security risk.
STRIDE is used for threat modeling. A market approach is used for asset valuation. A reduction analysis attempts to eliminate duplicate analysis and is tied to threat modeling.
Source: From
Question: 062
You are working on a business continuity project for a company that generates a large amount of content each day for use in social networks. Your team establishes 4 hours as the maximum tolerable data loss in a disaster recovery or business continuity event. In which part of the business continuity plan should you document this?
Answer: [B] Explanation: The RTO establishes the maximum amount of time the organization will be down (or how long it takes to recover), the RPO establishes the maximum data loss that is tolerable, the MTD covers the maximum tolerable downtime, and MDT is just a made-up phrase used as a distraction. In this scenario, with the focus on the data loss, the correct answer is RPO.
Source: From
Want to find Shon elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 8 (Software Development Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 8 (Software Development Security) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 6 (Security Assessment and Testing) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 6 (Security Assessment and Testing) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 6 (Security Assessment and Testing) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 6 (Security Assessment and Testing) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 6 (Security Assessment and Testing) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 5 (Identity and Access Management) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 5 (Identity and Access Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 4 (Communication and Network Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 4 (Communication and Network Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 3 (Engineering Secure Design) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about questions for Domain 3 (Engineering Secure Design) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ShonGerber.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Engineering Secure Design) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: https://shongerber.com/
Want to find Shon Gerber elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the items that are included within Domain 2 (Asset Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://shongerber.com/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://shongerber.com/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
ISC2 Training Study Guide
Global Knowledge
NCSL
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at:
http://www.shongerber.com/
http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at:
http://www.shongerber.com/
http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 8 - Software Development Security of the CISSP Exam:
CISSP / Cybersecurity Integration – Software Development Life Cycle
CISSP Training – Integrate Security in the Software Development Life Cycle (Domain 8)
CISSP Exam Question – Development Security / SDLC
BTW - Get access to all my CISSP Training Courses here at: http://www.shongerber.com/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at:
http://www.shongerber.com/
http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 4 (Communication and Network Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at:
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 7 (Security Operations) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://www.shongerber.com/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 6 (Security Assessment and Testing) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 3 (Security Architecture and Engineering) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 5 (Identity and Access Management) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 2 (Asset Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 2 (Asset Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 4 (Communication and Network Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Wikipedia
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 1 (Security and Risk Management) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 3 (Security Architecture and Engineering) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 1 (Security and Risk Management) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 1 (Security and Risk Management) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 1 (Security and Risk Management) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
ription:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 2 (Asset Security) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Misc.:
OECD
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will be covering CISSP Exam questions that are associated with Domain 2 (Asset Security) of the ISC2 CISSP Exam.
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following items that are included within Domain 1 (Security and Risk Management) of the CISSP Exam:
BTW - Get access to all my CISSP Training Courses here at: http://reducecyberrisk.com/cissp-training/
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Wikipedia
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following:
· CISSP / Cybersecurity Integration – CISSP Recognized
· CISSP Training – Evidence Collection
· CISSP Exam Question – Maintaining Files for Extended Periods / Degradation of Digital Media
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
Description:
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following:
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
Tech Target - PII
HIPAAJournal.com
BusinessDictionary.com
ISC2 - Information Security Certifications
Shon Gerber from ReduceCyberRisk.com provides you the information and knowledge you need to prepare and pass the CISSP Exam while providing the tools you need to enhance your cybersecurity career. Shon utilizes his expansive knowledge while providing superior training from his years of training people in cybersecurity.
In this episode, Shon will talk about the following:
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Description:
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent Security News:
Our Cybersecurity Training for the Week is: Recorded Future
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
o ]https://en.wikipedia.org/wiki/Recorded_Future
o https://www.recordedfuture.com/
o https://www.recordedfuture.com/intelligence-goals-library-overview/
o https://www.csoonline.com/article/3393440/public-sap-exploits-could-enable-attacks-against-thousands-of-companies.html#tk.rss_all
o https://www.pcmag.com/news/368151/police-shut-down-the-wall-street-market-a-top-dark-web-site
o https://www.darkreading.com/risk/new-executive-order-aims-to-grow-federal-cybersecurity-staff/d/d-id/1334609?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple
o https://www.nist.gov/itl/applied-cybersecurity/nice/resources/nice-cybersecurity-workforce-framework
o https://www.isc2.org/Training/Self-Study-Resources
Description:
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent Security News:
Our Cybersecurity Training for the Week is: Amazon Glacier - Deep Archive
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
LINKS:
o https://threatpost.com/fbi-bec-scam-losses-double/144038/
o https://thehackernews.com/2019/04/wordpress-plugin-hacking.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+TheHackersNews+%28The+Hackers+News+-+Cyber+Security+Blog%29&m=1
o https://www.darkreading.com/endpoint/city-of-stuart-still-recovering-from-ryuk-ransomware-attack-/d/d-id/1334510?_mc=rss_x_drr_edt_aud_dr_x_x-rss-simple
o https://www.csoonline.com/article/3390976/why-your-business-continuity-and-disaster-recovery-plans-should-account-for-emp-attacks-and-gmd-eve.html?upd=1556125631099
o https://www.isc2.org/Training/Self-Study-Resources
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience. In this episode, Shon will talk about recent Security News: * Cyber Fast Track * OPM Final Rule – Direct Hire for Cyber * Motel 6 – Leaving the Light On For ICE * GAO – Identity Theft Protection Not Enough
Our Cybersecurity Training for the Week is: Personal Safety And Security Concerns - Domain 7 - CISSP Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet? * LinkedIn – www.linkedin.com/in/shongerber * ReduceCyberRisk.com - https://reducecyberrisk.com/ * Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience. In this episode, Shon will talk about recent security news: -- 540 Million Facebook Users Exposed -- Ransomware Response – Norsk Hydro -- Verizon Phishing Scam – Mobile First Our Cybersecurity Training for the Week is: Global Cybersecurity Alliance Small Business Cybersecurity Toolkit As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification. Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet -- LinkedIn – www.linkedin.com/in/shongerber -- ReduceCyberRisk.com - https://reducecyberrisk.com/ -- Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Insurance Companies-Cybersecurity Ratings; Microsoft finds "NSA-Style Backdoor" in Huawei Laptops; NDSU - Nations First Ph.D. in Cybersecurity.
Our Cybersecurity Training for the Week is: PCI-DSS Training - Part II
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: US Chemical Firms Cyber Attack; New Jersey Privacy Bill - PII Breach Notification; Vulnerability Assessments vs. Penetration Testing
Our Cybersecurity Training for the Week is: PCI-DSS Training - Part I
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: $20 Million Dollar Mexican Bank Heist; Global Cybersecurity Alliance and Mastercard Partnership - FREE Cybersecurity Toolkit; China Won't Ask Chinese Companies to Spy.
Our Cybersecurity Training for the Week is: Data Classification - Part II
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Alarm System Vulnerabilities - 3 Million Affected; Equifax revisited by Congressional Investigators; 3 Steps for Cybersecurity Program
Our Cybersecurity Training for the Week is: Data Classification - Part I
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: PoS Clients Targeted with Colbalt Stirke; Azure Sentinel / Threat Experts; Securing the Cloud – Dark Reading.
Our Cybersecurity Training for the Week is: Business Impact Analysis – Part II
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Sensor panic - Why you should be concerned about Privacy; Malware targeting job seekers - LinkedIn phishing scams targeting job seekers; UK's worries about Huawei; Business Impact Analysis - Part I providing cybersecurity guidance for your Business Continuity program.
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Big Trouble Down Under - Password Resets; Four signs you need a CISO; US Lawmakers looking at foreign VPN usage; PWC corporate director survey. In addition, Shon will be providing Part I of his training Cyber Awareness Training and what you can do to implement within your organization. Some of the content will include: Methods to present training, content reviews, metrics, program evaluations, and the differences between security education, awareness and training...much, much more.
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook -
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Big Trouble Down Under - Password Resets; Four signs you need a CISO; US Lawmakers looking at foreign VPN usage; PWC corporate director survey. In addition, Shon will be providing Part I of his training Cyber Awareness Training and what you can do to implement within your organization. Some of the content will include: Methods to present training, content reviews, metrics, program evaluations, and the differences between security education, awareness and training...much, much more.
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: NERC (CIP); Execs in Cybersecurity; Webstresers going to Jail. In addition, Shon will be providing Part II of his training on the understanding of Cybersecurity Frameworks and their importance in protecting your business or for your CISSP certification. Some of the content will include PCI-DSS, ISO 27001, Cybersecurity Framework, and so much more.
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskReduced/
Shon Gerber from ReduceCyberRisk.com reveals to you the steps and the cybersecurity training you need to grow your Information Security career while protecting your business and reduce your company’s cyber risk. Shon utilizes his expansive knowledge while providing superior training from his years of cybersecurity experience.
In this episode, Shon will talk about recent security news: Colorado Communication Encryption; DHS DNS Hijacking; 5 Stages of a CISO. In addition, Shon will be providing training on the understanding of Cybersecurity Frameworks and their importance in protecting your business or for your CISSP certification. Some of the content will include PCI-DSS, ISO 27001, Cybersecurity Framework, and so much more.
As always, utilize Shon’s cybersecurity training to help fulfill your Continuing Education credits for your CISSP or other security certification.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber ReduceCyberRisk.com - https://reducecyberrisk.com/ Facebook - https://www.facebook.com/CyberRiskReduced/
In this episode, Shon will be going over cybersecurity news items concerning a large email/password discovery. Payment Card Industry Application Development Standards and Part II around building out an Information Security Governance program for your business.
In this episode, Shon will be going over recent items in the cybersecurity news along with Part One of the Information Security Governance.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk.
Shon provides cybersecurity training for individuals working on their CISSP as well as ways to better secure your business's daily activities.
In this show, Shon will go over recent Security News, Security Vendors, and the CISSP training around Confidentiality, Integrity, and Availability. These videos will go over what the hiring professionals should be looking for and what potential candidates should strive to achieve to meet the growing cybersecurity job demand.
Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
LinkedIn – www.linkedin.com/in/shongerber
ReduceCyberRisk.com - https://reducecyberrisk.com/
Facebook - https://www.facebook.com/CyberRiskRed...
In this episode, Shon will be going over the Marriott Breach, AWS Security Groups and the introduction to the CISSP.
In this show, Shon will go over the key aspects of the cybersecurity jobs responsibilities, skills, and the duties associated. This is part 5 of 5 in the ongoing series designed to help HR/Hiring managers as well as those looking for cybersecurity jobs.
In this show, Shon will go over the key aspects of looking for candidates externally to your organization or if you should consider one of your current employees. This is part 4 of 5 in the designed to help HR/Hiring managers and individuals
In this show, Shon will go over the key aspects for individuals looking for cybersecurity jobs. This is part 3 of 5 in the ongoing series designed to help HR/Hiring managers as well as those looking for cybersecurity jobs.
In this show, Shon will go over the key aspects of HR/Hiring professionals. This is part 2 of 5 in the ongoing series designed to help HR/Hiring managers as well as those looking for cybersecurity jobs.
In this episode, Shon will be go over some of the key aspects of hiring cybersecurity professionals. This will be part 1 of an ongoing series designed to help HR/hiring managers as well as provide insight to individuals wanting to enter the cyber field
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 9), Shon will address, the minimum security practices you should consider when looking at a cybersecurity insurance policy. Implementing these Minimum Security Practices can help reduce your premiums as well better protect your business.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 8), Shon will address, the key aspects around cybersecurity insurance such as: exclusions, security best practices, and so much more. This training is important for all companies, but more especially suited for Small and Medium sized businesses.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 8), Shon will go over the basics around cybersecurity insurance and what you should consider for your business. This training is important for all companies, but more especially suited for Small and Medium-sized businesses.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 6), Shon will talk about what you need to to do mitigate the risk for your business and some options that you can put in place immediately.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 6), Shon will talk about what you need to to do mitigate the risk for your business and some options that you can put in place immediately.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 4), Shon will address, Cyber Risk Management. He will cover the fundamentals and what you need to consider when evaluating the cyber risk for your business.
In this episode (Part 3), Shon will address, "The Why" and why you should be concerned about cybersecurity for businesses, especially as a Small and Medium sized companies.
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 5), Shon will go over the differences between Information Security and Cybersecurity; why businesses struggle with Cybersecurity and what you as a business can do to mitigate the issue
Shon Gerber from Reduce Cyber Risk.com reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk. Shon provides cybersecurity for business training and how you can begin to address the cyber risk for your daily business.
In this episode (Part 2), Shon will address, the Small and Medium Business Statistics that you need to consider in an attempt to help quantify the risk to your company. This training is important for all companies, but more especially suited for Small and Medium-sized businesses. Want to find Shon Gerber / Reduce Cyber Risk elsewhere on the internet?
Overview: This is the beginning of the states taking proactive approach to transfer the risk to businesses and through regulations. Common Occurrence – China, EU, Spain, Various States, etc…. GDPR for the US is coming….but that is for Data Privacy EU Cyberlaw that will be hitting the end of the year….Focused on Data Transfers, along with other items It is all coming, so you better be prepared to REDUCE YOUR CYBER RISK! Details: Quote: Justin Orcutt - The South Carolina Insurance Data Security Act was signed into law on May 14th, 2018 by South Carolina Governor Henry McMaster. It’s the first piece of cybersecurity legislation ever to be passed in the United States aimed at covering the insurance industry. Insurance Data Security Model – Drafted by the National Association of Insurance Commissioners in 2017 Similar to the Alabama Breach Law, NYDFS Law, etc Official January 1, 2019 but all the requirements don’t hit until 2020 Interesting tidbit: -All Licensees of the South Carolina Department of Insurance must have a “comprehensive, written, cybersecurity program” in place -Insurers, agents, other licensed entities, plus real-estate lawyers who are also real-estate agents -Cybersecurity Program -Breach Response plan – 72 hours (YEA BABY) -BIGGIE: Designate Individual, Third Party, or Affiliate who is responsible for your program -Can there be more!!!! --250 vs. HIPAA’s 500people -Investigate Promptly and records must be retained for 5 years It goes on….. Recommendation / Outcome: -Read the law and determine if it affects you and your business -Look for resources to help you build out a program, designate a person, etc. -Legal counsel on the best course of action to ensure you meet the law -Cybersecurity advice who can work with legal counsel and your business -Utilize my training that I am building for this very situation!
Shon Gerber from Reduce Cyber Risk reveals to the recent changes in the Chinese Cyber Law and how that could affect your business.
Shon Gerber from Reduce Cyber Risk reveals to you the steps each week the information you need to best protect your business and reduce your company’s cyber risk.