Led by an (ISC)² authorised instructor, this training course provides a comprehensive review of information security concepts and industry best practices, covering the 8 domains of the CISSP CBK:
- Security and Risk Management
- Asset Security
- Security Engineering
- Communications and Network Security
- Identity and Access Management
- Security Assessment and Testing
- Security Operations
- Software Development Security
This training course will help candidates review and refresh their information security knowledge and help identify areas they need to study for the CISSP exam and features:
- Official (ISC)² courseware
- Taught by an authorised (ISC)² instructor
- Student handbook
- Collaboration with classmates
- Real-world learning activities and scenarios
*Early-Bird discounts are available to registrations made more the 45 days before course commencement. Not available for ADF, as your rate is already discounted.
What is the CISSP Certification?
The vendor-neutral CISSP certification is the ideal credential for those with proven deep technical and managerial competence, skills, experience, and credibility to design, engineer, implement, and manage their overall information security program to protect organisations from growing sophisticated attacks.
Backed by (ISC)², the globally recognised, not-for-profit organisation dedicated to advancing the information security field, the CISSP was the first credential in the field of information security to meet the stringent requirements of ISO/IEC Standard 17024. Not only is the CISSP an objective measure of excellence, but also a globally recognised standard of achievement.
On completion of this course, participants should be able to:
- Understand and apply the concepts of risk assessment, risk analysis, data classification, and security awareness.
- Understand the structures, transmission methods, transport formats, and security measures used to provide confidentiality, integrity, and availability for transmissions over private and public communications networks.
- Offer greater visibility into determining who or what may have altered data or system information.
- Plan for technology development, including risk, and evaluate the system design against mission requirements.
- Protect and control information processing assets in centralised and distributed environments.
Several types of activities are used throughout the course to reinforce topics and increase knowledge retention. These activities include open ended questions from the instructor to the students, matching and poll questions, group activities, open/closed questions, and group discussions. This interactive learning technique is based on sound adult learning theories.
- Understand and apply the concepts of risk assessment, risk analysis, data classification, and security awareness and implement risk management and the principles used to support it (Risk avoidance, Risk acceptance, Risk mitigation, Risk transference).
- Apply a comprehensive and rigorous method for describing a current and/or future structure and behaviour for an organisation's security processes, information security systems, personnel, and organisational sub-units so that these practices and processes align with the organisation's core goals and strategic direction and address the frameworks and policies, concepts, principles, structures, and standards used to establish criteria for the protection of information assets, as well as to assess the effectiveness of that protection and establish the foundation of a comprehensive and proactive security program to ensure the protection of an organisation’s information assets.
- Apply a comprehensive and rigorous method for describing a current and/or future structure and behaviour for an organisation's security processes, information security systems, personnel, and organisational sub-units so that these practices and processes align with the organisation's core goals and strategic direction and examine the principles, means, and methods of applying mathematical algorithms and data transformations to information to ensure its integrity, confidentiality, and authenticity.
- Understand the structures, transmission methods, transport formats, and security measures used to provide confidentiality, integrity, and availability for transmissions over private and public communications networks and media and identify risks that can be quantitatively and qualitatively measured to support the building of business cases to drive proactive security in the enterprise.
- Offer greater visibility into determining who or what may have altered data or system information, potentially affecting the integrity of those asset and match an entity, such as a person or a computer system, with the actions that entity takes against valuable assets, allowing organisations to have a better understanding of the state of their security posture.
- Plan for technology development, including risk, and evaluate the system design against mission requirements, and identify where competitive prototyping and other evaluation techniques fit in the process.
- Protect and control information processing assets in centralised and distributed environments and execute the daily tasks required to keep security services operating reliably and efficiently.
- Understand the Software Development Life Cycle (SDLC) and how to apply security to it, and identify which security control(s) are appropriate for the development environment, and assess the effectiveness of software security.
Who Should Attend
The CISSP is ideal for those working in positions such as, but not limited to:
- Security Consultant
- Security Manager
- IT Director/Manager
- Security Auditor
- Security Architect
- Security Analyst
- Security Systems Engineer
- Chief Information Security Officer
- Director of Security
- Network Architect
What You Will Receive
- Continued access to course content for 6 months including virtual recordings of prior sessions
- 1-year access to courseware materials
- Live online support from an (ISC)² Authorised Instructor
- Official (ISC)² Student Training Guide (electronic)
- Interactive CISSP Flash Cards
- Certificate from (ISC)²
Face to face delivery:
- Official (ISC)² Student Training Guide
- CISSP Flash Cards
- Certificate from (ISC)²
NICE Framework Mapping
This course maps to the following NICE Framework KSAs (Knowledge, Skills & Abilities):
K0002: Knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
K0179: Knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
K0612: Knowledge of what constitutes a “threat” to a network.
S0034: Skill in discerning the protection needs (i.e., security controls) of information systems and networks.
A0077: Ability to coordinate cyber operations with other organisation functions or support activities.
A0123: Ability to apply cybersecurity and privacy principles to organisational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
What is the NICE Framework?
The National Initiative for Cybersecurity Education (NICE) Cyber Security Workforce Framework developed by the National Institute of Standards and Technology (NIST) establishes a taxonomy and common lexicon that describes cyber security work and job roles.
To find out more about the NICE Framework, go to: niccs.us-cert.gov/workforce-development/cyber-security-workforce-framework
UNSW Canberra Cyber
UNSW Canberra Cyber is a unique, cutting-edge, interdisciplinary research and teaching centre, working to develop the next generation of cyber security experts and leaders.
The centre is based in Canberra at the Australian Defence Force Academy and provides professional, undergraduate and post graduate education in cyber security. Our air-gapped, state of the art cyber range offers a secure environment where we deliver a number of technical and highly specialised learning opportunities.
Our courses are designed to give the next generation of cyber security professionals the skill sets needed to thrive in the industry. We can also create bespoke professional education programs tailored to your organisation's needs.
Contact us at firstname.lastname@example.org to discuss how.
Further Informationcyber@adfa.edu.au W: www.unsw.edu.au/cyber No dates? Or unable to attend dates shown? Submit an Expression of Interest below to be notified of upcoming courses.