Certified Information Security Manager (CISM) Cert Prep (2022): 3 Information Security Program

Certified Information Security Manager (CISM) Cert Prep (2022): 3 Information Security Program

5h 26mAdvanced2022-09-07

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Prepare to pass the Certified Information Security Manager (CISM) exam. In this course, Mike Chapple details how to best set up, define, and manage an information security program in an organization—concepts that can help you ace the questions in the Information Security Program exam domain. Mike helps you grasp the role of a manager in an information security program and goes over a wide variety of technical, physical, and administrative controls used to safeguard information and systems. Learn how to build your security team and maintain security in the hiring process; approach cloud storage security; secure mobile devices; work with firewalls, VPNs, and VPN concentrators; maintain employee safety; and much more.

Skills covered

Governance, Risk, and ComplianceCert PrepCybersecurity

Concepts

Introduction

  • Information security program
  • What you need to know
  • Study resources

Information Security Program Development

  • Scope and charter
  • Alignment of security and business objectives
  • Building a security team
  • Conducting a gap analysis

Personnel Security

  • Improving personnel security
  • Security in the hiring process
  • Employee termination process
  • Employee privacy
  • Social networking

Cloud Computing and Virtualization

  • What is the cloud
  • Cloud computing roles
  • Drivers for cloud computing
  • Virtualization
  • Cloud activities and the Cloud Reference Architecture
  • Cloud deployment models
  • Cloud service categories
  • Security and privacy concerns in the cloud

Host Security

  • Operating system security
  • Malware prevention
  • Application management
  • Host-based network security controls
  • File integrity monitoring
  • Data loss prevention
  • Data encryption
  • Hardware and firmware security

Mobile Security

  • Mobile device security
  • Mobile device management
  • Mobile device tracking
  • Mobile application security
  • Mobile security enforcement
  • Bring your own device (BYOD)
  • Mobile deployment models

Cryptography

  • Understanding encryption
  • Symmetric and asymmetric cryptography
  • Goals of cryptography
  • Choosing encryption algorithms
  • The cryptographic lifecycle
  • Key exchange
  • Diffie-Hellman
  • Key escrow
  • Key stretching
  • Trust models
  • PKI and digital certificates
  • Hash functions
  • Digital signatures
  • TLS and SSL
  • IPsec
  • Securing common protocols

Physical Security

  • Site and facility design
  • Data center environmental controls
  • Physical access control
  • Visitor management
  • Physical security personnel

Network Security

  • Routers, switches, and bridges
  • Firewalls
  • VPNs and VPN concentrators
  • Network intrusion detection and prevention
  • Unified threat management
  • VLANs and network segmentation
  • Network access control
  • Remote network access

Identity and Access Management

  • Identification, authentication, and authorization
  • Usernames and access cards
  • Authentication factors
  • Biometrics
  • Multi-factor authentication
  • Something you have
  • Understanding account and privilege management
  • Account types
  • Account policies
  • Account monitoring
  • Privileged access management
  • Provisioning and deprovisioning

Asset Management

  • Change management
  • Configuration management
  • Physical asset management

Personnel Safety

  • Personnel safety
  • Emergency management

Software Security

  • Software platforms
  • Development methodologies
  • Maturity models
  • Operation, maintenance, and change management
  • Code review
  • Software testing
  • Code security tests
  • Third-party code

Conclusion

  • Continuing your studies
100,000 Toman