
Explore security and risk management in CISSP domain 1, covering governance principles, risk management concepts, personnel security, business continuity, and compliance laws. Target career starters and professionals pursuing CISSP certification.
Explore lessons on security governance, policies, threat modeling, acquisition strategy, personnel security policies, risk management concepts, education and awareness, business continuity planning with BIA, and compliance with laws and contracts.
The course uses slides with a voice-over to present CISSP content, plus verbal explanations and examples, encouraging notes to build memos for the final sprint and feedback to improve iterations.
Master the CIA triad, protection mechanisms, and threat modeling within security governance. Apply data classification, due care and due diligence, and risk-aware acquisition.
Explore the CIA triad of confidentiality, integrity, and availability, and learn how these core security principles guide protection mechanisms and threat evaluation.
Apply confidentiality across storage, processing, and transit by enforcing access for authorized users. Use encryption, two-factor authentication, and data labeling to guard confidential data and maintain integrity.
Explore confidentiality as a security principle across storage, processing, and transit, including violations like network sniffing and shoulder surfing, and countermeasures such as encryption, two-factor authentication, and data classification.
Define and compare sensitivity, discretion, criticality, concealment, secrecy, privacy, seclusion, and isolation to understand how information confidentiality and risk are managed.
Maintain data integrity by restricting access, logging all actions, and validating data at each stage—storage, processing, and transit—using hash verification, intrusion detection, and ensuring only authorized modifications.
Ensure availability means granting timely, uninterrupted access to an object despite failures, environmental issues, or intentional disruptions, and use redundancy and access controls to maintain service continuity.
Explore auditing and accountability, and learn how audit trails, logs, and identity verification establish non-repudiation by linking actions to authorized users and reconstructing event sequences.
Explore four protection mechanisms—layering, abstraction, data hiding, and encryption—to maintain the CIA triad, using defense in depth and applying security controls to prevent single-point compromise.
Delve into security governance principles across topics: security planning, change management, data classification schemes (government and corporate), and roles from data owner to security professional, due care and due diligence.
Define security governance principles as practices guiding a company's security effort, aligned with corporate and IT governance and with laws, regulations, and industry requirements that support business activities.
Plan security across three levels—strategic, tactical, and operational—defining long-term, yearly, and project milestones, with senior management setting the tone and middle management translating governance through baseline guidelines and procedures.
Explore how mergers and acquisitions, divestitures, and governance committees shape cyber risk; assess integration, data sanitization, exit interviews, and non-disclosure agreements to protect the organization.
Learn to describe change management, assess risk, obtain cab approval, test changes, and plan rollbacks, with examples such as application updates, new servers, or network equipment replacements.
Learn a seven-step data classification concept to protect data with confidentiality, integrity, and availability, prioritize security by value and harm, and apply controls across storage, processing, and transit, including declassification.
Compare government and corporate data classification schemes from top secret to unclassified and confidential to public, and understand how disclosure affects security and the CISSP exam.
Explore the six to seven cybersecurity roles: data owner, data custodian, data users, senior managers, auditors, and security professionals—covering responsibilities, policy enforcement, testing, backups, and security measures.
Apply due care to protect the company's interests by establishing policy frameworks and procedures, and sustain due diligence across the IP infrastructure to reduce senior management culpability in security events.
Explore security policies, standards, procedures, and guidelines, covering policy concepts, types, sources, and maintenance, plus distinctions among standards, guidelines, and procedures for practical use in a company.
Define security policies as the living framework owned by senior management, covering assets, risk, and roles, with global and local scopes and regulatory, advisory, and informative types.
Explore standards, baselines, and guidelines that define minimum hardware, software, and security controls, document deviations, and apply compensating controls across the company.
Define security procedures and operational documents with a clear structure and step-by-step actions, maintained pragmatically by experienced staff to ensure consistent, up-to-date results.
Learn threat modeling by outlining four items, mapping potential attack scenarios in a diagram, and prioritizing risks with the dread method, considering data inputs, boundaries, and assumptions.
Learn threat modelling as an early, proactive and reactive risk management activity that identifies possible system threats, clarifies attacker motivations, and guides design decisions to reduce risk.
Identify threats from attacker and assets using the Stripe model's six categories—spoofing, tampering, reputation, information disclosure, denial of service, and elevation of privileges.
Explore potential attack scenarios and model how threats interact with users and objects. Visualize data flows, privileges, and trusted-zone boundaries to identify the most risky points.
Break down attack scenarios by analyzing each element’s role, data flow, inputs, trust boundaries, and assumptions to identify vulnerabilities and essential components.
Document every threat and rate it with the dread framework to prioritize responses. Assess probability, damage, reproducibility, exploitability, affected users, and discoverability to identify severe threats.
Identify the inherent security risks in acquiring new solutions, assess these solutions, evaluate ownership and maintenance costs, and define requirements to set a baseline.
Recap the CIA triad—confidentiality, integrity, availability—and information taxonomy with protection mechanisms, then review security governance, planning, organizational processes, change management, data classification, and threat modeling for acquisitions risk.
Explore risk management concepts and personnel security, focusing on the human element: hiring processes, the employer-employee environment, termination practices, and consultant contracts within security mechanisms.
Explore personnel security policies, including candidate screening, employment agreements, non-disclosure agreements, and job description reviews. Examine termination, access removal, contractor controls, service level agreements, privacy of information, related PII legislation.
Address the human aspect as the security's weakest link and stress clear job descriptions, least privilege, and separation of duties, job rotation, and cross training to maintain continuity.
Assess candidate suitability through traditional background checks, education verification, security clearance, and financial checks, and verify online presence to ensure trustworthiness and alignment with the job's sensitivity.
Outline the employment contract, policies, NDAs, and job description reviews to define rules, access, and compliance, including mandatory vacation in banking.
HR leads the termination process, focusing on human interaction, exit interviews, legal implications and confidentiality restrictions, equipment return, remote and building access removal, and payroll settlement on termination date.
Define contractor controls through a service level agreement that outlines performance criteria, uptime metrics, peak-load responses, penalties, and responsibilities to reduce risk.
Define privacy in the security and IT context, distinguish personally identifiable information from non-identifying data, and examine regulations like GDPR, HIPAA, SOX, and PCI-DSS.
Explore security governance for third parties, including laws, regulations, and industry standards, and compare do-it-yourself assessments, external audits, self-assessments, and document reviews to ensure data handling and defined investigation roles.
Define risk as probability times potential impact and score it to classify high, medium, or low, guiding threats and vulnerabilities assessment and mitigation strategies.
Explore the risk taxonomy by detailing assets and asset valuation, threats, vulnerabilities, exposure, safeguards, and defining risk as the likelihood of a threat exploiting a vulnerability.
Explore qualitative and quantitative risk assessment methods, including scenario-based focus groups, one-to-one expert interviews, cross-department brainstorming, the delfi technique, surveys, and checklists to identify risks.
Explore the three control categories—physical, technical, and administrative—and how they protect assets. Examine deterrent, preventive, detective, compensating, corrective, recovery, and directive controls.
Explore the differences between security awareness, training, and education, and learn how phishing exercises, on the job training, and formal education build cyber awareness for employees.
Define and manage the security function with cost-effective, measurable safeguards, backed by security assessments, and reassess protections as the environment changes.
Learn to craft a comprehensive business continuity plan through planning, team selection, impact assessment, strategy development, approval, implementation, training, and thorough documentation.
Learn how business continuity planning assesses risks, builds policies and procedures to minimize impacts, and guides disaster recovery across four steps to protect people.
Form a multi-department BCP team led by a business senior manager, include business, support functions, IT, security, legal, and management, and plan development, training, and disruption resources aligned with regulations.
Explore how to perform a business impact assessment (BIA) by identifying assets, asset value, and recovery metrics like recovery point objective and recovery time objective, then prioritize risks and resources.
Explore continuity planning and business continuity planning (BCP) to protect people, facilities, and infrastructure, map BIA outcomes, and link requirements to solutions. Mobilize resources and train employees for plan implementation.
Document the ten sections of the business continuity plan—goals, importance, priorities, responsibilities, timing, risk assessment, risk acceptance, vital records, emergency response, and maintenance—and keep it a living document with reviews.
Explore compliance, laws and regulations related to computer security, covering computer crimes, privacy, intellectual property and licensing, and outline criminal, civil and administrative categories and third-party contracts.
Explore the different laws and regulations governing computer issues, covering computer crimes, intellectual property, licensing, and privacy.
Examine computer crimes and laws, including the CFAA, Paperwork Reduction Act, GISRA, FISMA, and NIST guidelines, and how they drive risk assessments, policies, controls, training, testing, and continuity of services.
Explain the four main types of intellectual property—copyright, trademarks, patents, and trade secrets—and how they protect owners, with DMCA, USPTO, NDAs, and Coca-Cola's secret formula.
Explore four licensing types: contractual, shrink wrap, clickthrough, and cloud service, alongside federal export controls and embargoed countries governing transborder dataflow and intellectual property.
Navigate the U.S. and EU privacy landscape by examining key privacy laws, from the Fourth Amendment to HIPAA, COPPA, GLBA, and GDPR, and their data protection requirements.
Identify the three main categories of laws—criminal, civil, and administrative—and their roles in deterring crime, including computer crime, resolving disputes, and controlling public power.
Identify the aim of compliance and how regulations enforce security across frameworks. Apply controls when requirements overlap, with PCI DSS examples like firewall configuration, data encryption, access restrictions, and testing.
Evaluate cloud service providers through vendor governance reviews, verify security controls, and ensure your organization remains accountable for information exchanges with third parties.
Share your feedback and questions to improve my course on the first CISSP domain. Follow me to be notified about upcoming CISSP domains and other cyber security courses.
THIS is the RIGHT place for your CISSP Exam
Top reasons to take action NOW!
CISSP Exam Prep: Most detailed course, suitable for both the CISSP CAT and CISSP Linear exam.
Prepared by a CISSP Certified professional: Materials used by dozens of successful students.
Success Guaranteed: It will get you ready for the exam day!
If you correctly answer the practice questions, YOU WILL SUCCEED on the exam.
COURSE Overview
I. Security Governance Principles and Policies
Confidentiality, Integrity, and Availability
Security Governance Principles
Policies, Standards, Procedures, and Guidelines
Threat Modeling
Security Risk Considerations in Acquisition
II. Risk Management Concepts and Personnel Security
Personnel Security Policies
Security Governance
Risk Management Concepts
Security Education, Training, and Awareness
Security Function
III. Business Continuity
Planning
BCP Team Selection and Requirements
Business Impact Assessment
Continuity Planning
Documentation
IV. Compliance, Laws, and Regulations
The Different Laws and Regulations
Categories
Compliance
Contracts
V. Quiz
30 practice questions specifically tailored for the CISSP Domain 1
Related information on security certifications:
This CISSP course is perfectly designed for the preparation of IT Security certifications, ethical hacking, penetration testing, and the following cybersecurity certifications:
CISSP Certified Information Systems Security Professional from (ISC)²
CISM Certified Information Security Manager certification from ISACA
CRISC Certified in Risk and Information Systems Controls certification from ISACA
CISA Certified Information Systems Auditor from ISACA
CCSP Certified Cloud Security Professional certification from (ISC)²
CISSP concentrations: CISSP-ISSAP, CISSP-ISSEP, CISSP-ISSMP
CCSK Cloud Security certification, and CCAK Cloud Auditing Knowledge from CSA
ISO 27001:2022 Lead Auditor and ISO 27001:2022 Lead Implementer
CompTIA Security+ certification
Included in this BUNDLE:
3.5 hours of CISSP videos: Covering in detail the CISSP Domain 1
2 free downloadable resources: Made for your next career step
30 free CISSP Practice Questions: that will give you the confidence to sit for the CISSP exam
Course in English and auto-translated subtitles in German, Spanish, Portuguese, Polish, Italian, and Indonesian.
Access to 4 articles to develop your cybersecurity career
A curated list of the most useful CISSP links
High-quality Q&A, where I answer all your questions
Automatic certificate of completion, justifying your (CPE/CEUs)
30-day no question asked, money-back guarantee
Lifetime access to the course and all future updates
Offline video viewing on the Udemy mobile app
What's next?
Start your certification journey today, and let me help YOU get certified.
Hit the "Buy Now" or "Add to cart" button to start your CISSP journey today!
Enjoy learning!