Produktbild: The Official (ISC)2 SSCP CBK Reference
- 12%

The Official (ISC)2 SSCP CBK Reference

12% sparen

69,99 € UVP 79,90 €

inkl. gesetzl. MwSt., Versandkostenfrei


Beschreibung

Produktdetails

Einband

Gebundene Ausgabe

Erscheinungsdatum

13.06.2022

Verlag

John Wiley & Sons Inc

Seitenzahl

832

Maße (L/B/H)

23,9/19,2/4,5 cm

Gewicht

1536 g

Auflage

6. Auflage

Sprache

Englisch

ISBN

978-1-119-87486-7

Beschreibung

Produktdetails

Einband

Gebundene Ausgabe

Erscheinungsdatum

13.06.2022

Verlag

John Wiley & Sons Inc

Seitenzahl

832

Maße (L/B/H)

23,9/19,2/4,5 cm

Gewicht

1536 g

Auflage

6. Auflage

Sprache

Englisch

ISBN

978-1-119-87486-7

Herstelleradresse

Libri GmbH
Europaallee 1
36244 Bad Hersfeld
DE

Email: gpsr@libri.de

Ein neues Kapitel für Ihre Bücher

Ein neues Kapitel für Ihre Bücher

Schenken Sie Ihren alten Schätzen ein zweites Leben und erhalten dafür eine Thalia Geschenkkarte.

Jetzt verkaufen
Jetzt verkaufen

Noch keine Bewertungen vorhanden

Verfassen Sie die erste Bewertung zu diesem Artikel

Helfen Sie anderen Kundinnen und Kunden durch Ihre Meinung.

Kundinnen und Kunden meinen

Bewertungen (0)

Die Leseprobe wird geladen.
  • Produktbild: The Official (ISC)2 SSCP CBK Reference
  • Foreword xxiii

    Introduction xxv

    Chapter 1: Security Operations and Administration 1

    Comply with Codes of Ethics 2

    Understand, Adhere to, and Promote Professional Ethics 3

    (ISC)2 Code of Ethics 4

    Organizational Code of Ethics 5

    Understand Security Concepts 6

    Conceptual Models for Information Security 7

    Confidentiality 8

    Integrity 15

    Availability 17

    Accountability 18

    Privacy 18

    Nonrepudiation 26

    Authentication 27

    Safety 28

    Fundamental Security Control Principles 29

    Access Control and Need-to-Know 34

    Job Rotation and Privilege Creep 35

    Document, Implement, and Maintain Functional Security Controls 37

    Deterrent Controls 37

    Preventative Controls 39

    Detective Controls 39

    Corrective Controls 40

    Compensating Controls 41

    The Lifecycle of a Control 42

    Participate in Asset Management 43

    Asset Inventory 44

    Lifecycle (Hardware, Software, and Data) 47

    Hardware Inventory 48

    Software Inventory and Licensing 49

    Data Storage 50

    Implement Security Controls and Assess Compliance 56

    Technical Controls 57

    Physical Controls 58

    Administrative Controls 61

    Periodic Audit and Review 64

    Participate in Change Management 66

    Execute Change Management Process 68

    Identify Security Impact 70

    Testing/Implementing Patches, Fixes, and Updates 70

    Participate in Security Awareness and Training 71

    Security Awareness Overview 72

    Competency as the Criterion 73

    Build a Security Culture, One Awareness Step at a Time 73

    Participate in Physical Security Operations 74

    Physical Access Control 74

    The Data Center 78

    Service Level Agreements 79

    Summary 82

    Chapter 2: Access Controls 83

    Access Control Concepts 85

    Subjects and Objects 86

    Privileges: What Subjects Can Do with Objects 88

    Data Classification, Categorization, and Access Control 89

    Access Control via Formal Security Models 91

    Implement and Maintain Authentication Methods 94

    Single-Factor/Multifactor Authentication 95

    Accountability 114

    Single Sign-On 116

    Device Authentication 117

    Federated Access 118

    Support Internetwork Trust Architectures 120

    Trust Relationships (One-Way, Two-Way, Transitive) 121

    Extranet 122

    Third-Party Connections 123

    Zero Trust Architectures 124

    Participate in the Identity Management Lifecycle 125

    Authorization 126

    Proofing 127

    Provisioning/Deprovisioning 128

    Identity and Access Maintenance 130

    Entitlement 134

    Identity and Access Management Systems 137

    Implement Access Controls 140

    Mandatory vs. Discretionary Access Control 141

    Role-Based 142

    Attribute-Based 143

    Subject-Based 144

    Object-Based 144

    Summary 145

    Chapter 3: Risk Identification, Monitoring, And Analysis 147

    Defeating the Kill Chain One Skirmish at a Time 148

    Kill Chains: Reviewing the Basics 151

    Events vs. Incidents 155

    Understand the Risk Management Process 156

    Risk Visibility and Reporting 159

    Risk Management Concepts 165

    Risk Management Frameworks 185

    Risk Treatment 195

    Perform Security Assessment Activities 203

    Security Assessment Workflow Management 204

    Participate in Security Testing 206

    Interpretation and Reporting of Scanning and Testing Results 215

    Remediation Validation 216

    Audit Finding Remediation 217

    Manage the Architectures: Asset Management and Configuration Control 218

    Operate and Maintain Monitoring Systems 220

    Events of Interest 222

    Logging 229

    Source Systems 230

    Legal and Regulatory Concerns