10 CBK of CISSP
10 CBK (Common Body of Knowledge) included in CISSP:
Access control: administrators and operators need ways to control access mechanisms to access content, authorization, authentication, audit and monitoring
Communications and network security: internal, external, public and private communication systems, Internet, devices, protocols, and remote access management.
Information security governance and risk assessment: the right way to determine the level of security protection of the target, a budget to reduce risks and financial losses.
Software development security: software development methods, application security and software defects.
Cryptography: techniques, methods, and techniques in cryptography.
Security architecture and design: methods used by security audit software applications, international security metrics, and specific implications for different platforms.
Operating system security: people, hardware, systems, and audit and monitoring technologies, mainly aimed at the security architecture of the operating system.
BCP and DRP: business continuity technology and disaster recovery plan.
Laws, compliance, investigation and compliance: computer crimes, laws and regulations, evidence collection and disposal procedures and procedures
Physical (environmental) security: for protection implementation, hardware, data, media and personnel measures.