CISSP Exam Cram: Models, Processes, and Frameworks

Поделиться
HTML-код
  • Опубликовано: 18 окт 2024

Комментарии • 94

  • @getdestroyed1958
    @getdestroyed1958 3 года назад +13

    This is exactly what I was talking about being a consolidated framework video! Very impressed with your material!

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +1

      Glad that one hit the spot! Did you see the video I released on "the cissp mindset"? Had a couple of testers this week tell me it was absolutely key to their clearing the exam.

  • @SingleSup540
    @SingleSup540 2 года назад +9

    Cleared CISSP last friday. Your videos were instrumental in my success. I watched this specific video multiple times and it 100% payed dividends during the exam. Keep up the great content

  • @karolchoi007
    @karolchoi007 3 года назад +7

    Glad that I was able to see this series of CISSP CRAM videos the week before my exam, which clarified some points I was not sure before. and i have passed :) Thanks

  • @vasudhakota972
    @vasudhakota972 2 года назад +5

    *Security & Risk Management - Domain 1*
    2:50 NIST 800-37
    4:35 Other RMF - OCTAVE, FAIR, TARA
    4:52 BCP
    5:20 Threat Modeling - 5:31 Approaches - Focused on Assets/Attackers/Software
    6:16 Threat Modeling Frameworks - STRIDE, PASTA, VAST, DREAD, TRIKE
    10:06 Security Control Framework - COBIT: Control OBjectives for Information & other related Tech
    *Asset Security - Domain 2*
    11:22 Data Classification for Govt Entities & Non-Govt Entities
    *Security Architecture & Engineering - Domain 3*
    13:20 Common Criteria (ISO-IEC 15048), TCSEC, ITSEC
    14:30 Common Criteria as a process- is of two kinds - Community Protection Profile(Black Box), Evaluation Assurance Level(White Box)
    16:09 Classes of TCSEC, ITSEC & Common Criteria
    17:20 Security Models
    18:22 Security Model Properties - Simple Security Property(read), * Security Property(write), Invocation
    18:50 Security Models - Integrity (BIBA, Clark-wilson, Goguen Meseguer, Sutherland Model), Confidentiality (Bell LaPadula, Brewer & Nash, Take Grant)
    26:43 State Machine Model
    27:35 Information Flow Model
    28:28 *Communication & Network Security Model - Domain 4*
    28:30 OSI Model
    *Identity & Access Management - Domain 5*
    30:19 Access Provisioning Life Cycle
    *Security Assessment & Testing - Domain 6*
    31:06 NIST SP 800-53A Rev. 5 (superseding existing SP in Jan, 2023)
    Assessing Security and Privacy Controls in Information Systems and Organizations
    calls out best practices for conducting security & privacy assessments
    31:35 NIST SP 800-53A Rev. 5 - components/specifications/documents
    *Security Operations - Domain 7*
    32:40 Change Management
    33:23 Information Lifecycle
    35:02 NIST SP 800-61 Rev. 2 : Computer Security Incident Handling Guide that enumerates 7 step process - primary incident response framework is referenced here
    37:34 BCP
    39:16 BCP vs DRP
    40:02 Patch Management Lifecycle
    41:23 *Software Development Security - Domain 8*
    42:11 SW-CMM
    43:25 CMMI
    45:44 IDEAL model
    46:43 SDLC
    48:25 AGILE model
    49:43 Waterfall model
    53:19 Spiral Model

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  2 года назад

      Just posted a new CISSP video you may appreciate. ruclips.net/video/qMScJnHaC9s/видео.html. Working on a very granular table-of-contents menu of topics I should have ready tomorrow.

  • @gebreabzgiaregawi291
    @gebreabzgiaregawi291 3 года назад +5

    I have provisionally passed the CISSP exam just on 100 questions yesterday. Thank you so much for your inspiring videos, slides and the 50 questions. It helped me a lot in summarizing the vast domains of the exam. So keep up the good work.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад

      Wonderful! Glad I could help! Congratulation! 🎉👍

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +1

      And BTW, only 100 questions?!? That means you CRUSHED IT! 👍🎉🏆🎖️

    • @gebreabzgiaregawi291
      @gebreabzgiaregawi291 3 года назад +1

      @@InsideCloudAndSecurity Yes just 100 questions, and still feel ecstasy and victorious about that. Thank you so much Sir.

    • @gebreabzgiaregawi291
      @gebreabzgiaregawi291 3 года назад

      @@InsideCloudAndSecurity Thank you so much. The steady and assuring flow of information you present through the videos and slides about the vast domains in short still resonates in mind even after passing the exam. It helped me a lot to build my confidence after exhaustive reading of the CBK and Study guide cover to cover. Your slides and videos are to the point and that helped a lot to solidify and focus.

    • @gebreabzgiaregawi291
      @gebreabzgiaregawi291 3 года назад

      @@InsideCloudAndSecurity Now I am left with the endorsement process and I looking for someone to do that.

  • @bobby7739
    @bobby7739 2 года назад +6

    This is a fantastic presentation. Been preparing for the CISSP for over two months and really needed this to help consolidate it all.

  • @gnollins
    @gnollins 2 года назад +3

    Thank you for these videos - I passed the CISSP exam today at the first attempt. Spent 2 months learning the study guide inside out.
    I watched all of the Exam Cram videos in the days leading up to the exam and they really helped!

  • @andrewarmanious2078
    @andrewarmanious2078 2 года назад +2

    I used your videos on the CISSP exam and the study guide and managed to pass the first try. Thank you for putting these videos out. Wouldn't have been able to do it without you.

  • @nathanbarber1499
    @nathanbarber1499 3 года назад +4

    Can’t thank you enough for putting out these videos. They were very helpful in helping me prepare for the test. Passed it yesterday first try!!! Thanks again

  • @piramnayag9340
    @piramnayag9340 3 года назад +4

    Thanks for these summary videos. Very helpful for my prep. I provisionally cleared cissp exam couple of hours ago. Gratitude!!

  • @kwakufordjour9568
    @kwakufordjour9568 8 месяцев назад +1

    After 175 questions, I am pleased to announce that I provisionally passed the CISSP today. May God continue to bless you and everything you do and if I can donate, help, or support your vision and generosity in any way, please let me know. I will be more than happy to help. Take care!

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  8 месяцев назад

      Well done! CONGRATULATIONS! 🏆🎉🌟Glad the series was helpful!

    • @justinlloyd-jones1658
      @justinlloyd-jones1658 6 месяцев назад

      That must have been nailbiting. My exam is very soon. At least it shows not to lose hope if you keep getting thrown more questions. Well done

  • @midem.1155
    @midem.1155 Год назад +2

    Thank you so much for this video. I took my exam this week (2nd attempt) and this time I had less time to prepare.
    This video helped me organized my preparation with limited time

  • @rockmdii
    @rockmdii 3 года назад +2

    Pete Zerger... Thank you so much for these videos. They helped me pass the CISSP on the first attempt! I am so grateful for the content you put out!

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +1

      That's great news! CONGRATULATIONS! 🏆🎉👍

    • @rockmdii
      @rockmdii 3 года назад

      @@InsideCloudAndSecurity Thanks so much!

  • @justinlloyd-jones1658
    @justinlloyd-jones1658 6 месяцев назад +1

    Top notch content. Delivered in a no nonsense and to the point, manner. Plus, great voice which makes it so much more easier to take in. Thank you

  • @tristanziemann1825
    @tristanziemann1825 Год назад +2

    Still super useful. You are a pillar of the CISSP community.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +2

      Thanks Tristan! If you're prepping for CISSP, make sure to take a look at the full exam cram video! ruclips.net/video/_nyZhYnCNLA/видео.html

    • @tristanziemann1825
      @tristanziemann1825 Год назад +1

      @InsideCloudAndSecurity been watched and watching all morning. I'm testing in 1 hour

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +1

      @@tristanziemann1825 Wow! Good luck! 🤞🍀👍

    • @tristanziemann1825
      @tristanziemann1825 Год назад

      @@InsideCloudAndSecurity I passed! Thank you!

  • @twinters8
    @twinters8 Год назад +1

    This is definitely the hardest part of the CISSP so far, remembering all these different multi-step processes and keeping them separate in your mind.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +1

      Definitely a challenge, because questions may drop you into the middle of a process and ask you what comes next.

  • @arashvermahmood7961
    @arashvermahmood7961 3 года назад +2

    Many thanks for this concise and informative video. It helps to remove a lot of confusion about frameworks and focus on what is important.

  • @jubairaladin5965
    @jubairaladin5965 3 года назад +2

    Thanks a lot for this wonderful videos just before my exam in few weeks.

  • @aumit7
    @aumit7 3 года назад +4

    Thank you for doing this, very much appreciated!

  • @Curious_Bob
    @Curious_Bob Год назад +1

    Small confusion
    CBK states following classification on basis of severity
    1. Confidential
    2. Sensitive
    3. Private
    4. Proprietary
    5. Public
    While other sources illustrate as following
    1. Confidential/ Proprietary
    2. Private
    3. Sensitive
    4. Public
    Which one is the correct classification

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад

      The first is mixing government and commercial. Use what I show at - ruclips.net/video/_nyZhYnCNLA/видео.html

  • @bipedalhominid6815
    @bipedalhominid6815 2 года назад +1

    " G 14 classified" hahah that's great. 19 years in USMC and that definitely made me laugh lol :)

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  2 года назад +1

      Borrowed a line from Chris Tucker from one of the Rush Hour movies. 😂

  • @TempleOfDoom930
    @TempleOfDoom930 2 года назад +1

    No reference book says that Clark Wilson is a Biba model which you showed here. The distinctive feature of CW is that it enforces SoD (a definitive clearance) and also Auditing. Integrity are ensured in CW in all sort and is done by Integrity Verification Procedures (IVP). These are missing in Biba.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  2 года назад

      Just to be sure, I'll go back and have a look after my team meeting, reconcile all the sources we've mentioned here and ping you back. 👍

  • @Speedster9550
    @Speedster9550 3 года назад +2

    Another awesome study guide... Thank You!!

  • @erico963
    @erico963 3 года назад +1

    Great video! Many thanks!
    Just in time for my exam. For domain 3, should it be ISO 15048 or 15408?

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +1

      Ah, it's actually iso-iec 15408, aka "Common Criteria" en.wikipedia.org/wiki/Common_Criteria. Good catch! Common Criteria is what you want to remember for the exam, and focus on Evaluation Assurance Levels (EAL)

  • @silkeholtmanns6514
    @silkeholtmanns6514 2 года назад

    Very useful summary. I still try to wrap my mind around Graham Denning, if it is orthogonal to the confidentiality and integrity properties or if it an integrity model. Similar for the Harrizon-Ruzzo-Ullmann Model.

    • @silkeholtmanns6514
      @silkeholtmanns6514 2 года назад

      Could you check with the latest CISSP guide (9th) on patch management steps and SDLC steps, I think they somehow changed them (or maybe I look at the wrong place)....

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  2 года назад +3

      You may also see the high-level patch mgmt process, which would be "Evaluate > Test > Approve > Deploy > Verify".

  • @joannapabelonia403
    @joannapabelonia403 2 года назад +1

    Pete, the free CISSP 50 practice questions seem to have been removed from the site. Can they still be accessed somewhere? Thanks.

  • @ilirrama6122
    @ilirrama6122 3 года назад +1

    Thank you sir, great stuff!

  • @Nunya24
    @Nunya24 3 года назад +1

    Question is not the patch management lifecycle; 1.) evaluate patches, 2.) Test Patches, 3.) Approve Patches, 4.) Deploy patches. 5.) Verify Patches are deployed...?? Please let me know

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +2

      Thanks for the question, Lee. While there's not one definitive patch management life cycle model, virtually any you will find will include a scanning element as detailed in this video. You need to scan systems to know where patches need to deployed based on vulnerabilities (remember to look at this process through the lens of security). What you see in domain 6 in this video is pretty consistent with what you will find in the public space. Certainly one could assume that testing has to happen somewhere in the 'download and deploy' phase. You'll even see variations titled the 'vulnerability management life cycle' or 'patch and vulnerability management life cycle'. I've not seen a patch management life cycle that includes an 'approve patches' phase, but one could assume that only patches that deployed in your test ring without negative impact or then deployed to production. Bottom line be familiar with the conceptual process and don't get bogged down in terminology for this one.

    • @Nunya24
      @Nunya24 3 года назад

      @@InsideCloudAndSecurity Thank you for that! the patch management system I described was in the CISSP sybex book.

  • @piotrstasinskij2929
    @piotrstasinskij2929 Год назад

    Thanks for Your job

  • @RamtinErKul
    @RamtinErKul Год назад

    Hi man thanks for the video, one thing got me confused. First you say that the "Biba" security model is a state machine model (in the overview) and then when you describe it in details you say that it is a lattice based. This got me a bit confused. Could you explain please? Thanks in advance.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +2

      You will find an updated explanation of that (and all models) in the full course I released earlier this year - CISSP Exam Cram Full Course (All 8 Domains) UPDATED - 2022 EDITION!
      ruclips.net/video/_nyZhYnCNLA/видео.html

  • @basantkumarsharma3824
    @basantkumarsharma3824 3 года назад +1

    Is this for current syllabus or 2021 ?please confirm....

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад +2

      Current syllabus AND still applicable for 2021. I'll be releasing updates to address what's been added for 2021, which are incremental changes in the big picture.

    • @kevinbarrett1545
      @kevinbarrett1545 3 года назад

      @@InsideCloudAndSecurity Has that new update been released yet?

  • @themiseducationoftheameric7407

    You said earlier that Biba (at 19:37) was a "state machine model", then at 27:48 you say Biba and Bell-Lapdula are both "information flow models", Which is it??

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +1

      Both. The Information Flow model is an extension of the state machine concept and serves as the basis of design for both the Biba and Bell-LaPadula models. www.pearsonitcertification.com/articles/article.aspx?p=1998558&seqNum=4

    • @themiseducationoftheameric7407
      @themiseducationoftheameric7407 Год назад +1

      @@InsideCloudAndSecurity Understood thank you.

  • @shermanhoman6666
    @shermanhoman6666 3 года назад

    I know that the OSI model is filled with complexity and sometimes confusion, but wouldn't SSL/TLS be part of Layer 6? I think that they have to at least be above Layer 4 because they run on TCP, Layer 5 is a total mystery to me, but Layer 6 deals with encryption which seems like the right layer for SSL/TLS.

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад

      Not exactly. Per Wikipedia, "Transport Layer Security (TLS) does not strictly fit inside the model either. It contains characteristics of the transport (layer 4) and presentation (layer 6) layers." (source: en.wikipedia.org/wiki/OSI_model). And since SSL has been replaced by TLS, I think you are safe in that a question on TLS in the OSI model is not going to be a question you see that determines your pass or fail.

  • @azeemrios4836
    @azeemrios4836 3 года назад +1

    sorry for the question but what cram stand's for?

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад

      cram = To study for a test in the last remaining hours. www.addthis.com/bookmark.php?lng=en-US&pub=ra-50dc926d011f6845&source=tbx-300&title=Urban+Dictionary%3A+cram&url=http%3A%2F%2Fcram.urbanup.com%2F145384&v=300&winname=addthis. And my videos are intended to provide a lot of information, in an easy to understand format, in a short amount of time

    • @azeemrios4836
      @azeemrios4836 3 года назад

      @@InsideCloudAndSecurity Thanks for the information. I have schedule my CISSP exam for the 28 of April. I'm a little bit worry about the kind of questions that will appear since all the practice test are more technical oriented and every one says "think like a manager" but none of the practice test are manager related questions. I have a overall basic knowledge of all the topics, will that be good for the test adding the manager mind set? honestly I don't have a clue of what type of questions to expect on the test!

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  3 года назад

      Here is a video to explain exactly what they mean by "think like a manager" ruclips.net/video/vfC9OLsCqgk/видео.html

  • @12yanschump
    @12yanschump Год назад

    @13:44 Common criteria is 15408 not 15048

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  Год назад +1

      That typo / errata was corrected for the full course - CISSP Exam Cram Full Course (All 8 Domains) UPDATED - 2022 EDITION!
      ruclips.net/video/_nyZhYnCNLA/видео.html

  • @TempleOfDoom930
    @TempleOfDoom930 2 года назад +1

    CC is ISO-15408 not ISO-15048

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  2 года назад

      Indeed, a typo capture in the errata in one of my comments. Will definitely address in the March update to the series. 🙏 Good luck on the exam! 🍀🤞

  • @Akashsingh-rq1vg
    @Akashsingh-rq1vg 7 месяцев назад

    I thought clark-wilson was a rule based model and not lattice model? 25:01

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  7 месяцев назад

      I corrected this bit of errata in the exam cram full course. Watch my full description of Clark-Wilson at this time-stamped link - ruclips.net/video/_nyZhYnCNLA/видео.htmlsi=r9cV9OaUZFqIDCOd&t=10483

    • @Akashsingh-rq1vg
      @Akashsingh-rq1vg 7 месяцев назад +1

      @InsideCloudAndSecurity thank you so much for the quick response!! You da best sir!! :)

    • @InsideCloudAndSecurity
      @InsideCloudAndSecurity  7 месяцев назад

      👍

  • @d3adv3nom
    @d3adv3nom 2 года назад

    30:08