CISSP考兩大區塊:管理類(Dodmain#1, 2, 5, 6, 7)、技術(Dodmain#3, 4, 8)
#專業倫理、#道德規範(ISC² code of Professional ethics + 組織的)
#五大支柱、#CIA 三要素
#治理、#安全治理原則
#法律、#合規、#合約與法規遵循(如: GDPR)
#資安原則、#安全概念
#安全政策、標準、程序和指南
#風險管理、#風險評鑑、#營運持續(BC)
#人員安全政策和程序、安全意識、教育和培訓計畫
#調查類型、#威脅建模 概念和方法
#供應鏈風險管理(SCRM)
1.1- Understand, adhere to, and promote professional ethics
理解、遵守並促進職業道德
ISC2 Code of Professional Ethics — 職業道德規範
Organizational code of ethics — 組織道德規範
1.2- Understand and apply security concepts
理解並應用安全概念
資訊安全的五大支柱: Confidentiality, integrity, availability, authenticity, and nonrepudiation (5 Pillars of Information Security) — 機密性、完整性、可用性、真實性與不可否認性
1.3- Evaluate and apply security governance principles
評估並應用 安全治理原則
• Alignment of the security function to business strategy, goals, mission, and objectives — 確保 資安管理工作 與業務策略、目標、使命和宗旨一致
•Organizational processes (e.g., acquisitions, divestitures, governance committees) — 組織流程(如:併購、資產剝離/分割/撤出/事業單位分拆、治理委員會)
•Organizational roles and responsibilities — 組織角色與職責
• Security control frameworks (e.g., ISO, NIST, COBIT, SABSA, PCI, FedRAMP) — 資安控制框架
• Due care/due diligence — 應盡注意/應盡義務
全面理解與資訊安全相關的法律、法規與合規議題
•Cybercrimes and data breaches — 網路犯罪 與 資料外洩
•Licensing and Intellectual Property requirements — 授權與智慧財產權要求
• Import/export controls — 匯入/匯出控制[技術或資料流通(如加密產品、技術轉移)]
• Transborder data flow — 跨境資料流通
• Issues related to privacy (e.g., GDPR, CCPA, PIPL, POPIA) — 與隱私相關的議題
•Contractual, legal, industry standards, and regulatory requirements — 合約、法律、產業標準與法規要求
1.5- Understand requirements for investigation types (i.e., administrative, criminal, civil, regulatory, industry standards)
理解各類調查的要求(如:行政、刑事、民事、監管、產業標準)
1.6- Develop, document, and implement security policy, standards, procedures, and guidelines
制定、記錄並實施安全政策、標準、程序與指引
1.7- Identify, analyze, assess, prioritize, and implement Business Continuity (BC) requirements
識別、分析、評估、優先排序並實施 業務持續需求
Business impact analysis (BIA) — 業務影響分析
External dependencies — 外部依賴因素
1.8- Contribute to and enforce personnel security policies and procedures
協助建立並強化 人員安全政策與程序
Candidate screening and hiring — 候選人篩選與雇用
Employment agreements and policy driven requirements — 雇傭契約與來自內部政策所驅動的要求[公司內部的政策(如資安政策、遠端工作政策、BYOD政策等)所制定的行為與安全標準要求,雖未列入契約但必須遵守。]
Onboarding, transfers, and termination processes — 入職、調職與離職流程
Vendor, consultant, and contractor agreements and controls — 廠商、顧問與承包商協議與控管
1.9- Understand and apply risk management concepts
理解並應用風險管理概念
Threat and vulnerability identification — 威脅與弱點識別
Risk analysis, assessment, and scope — 風險分析、評估與範圍界定
Risk response and treatment (e.g., cybersecurity insurance) — 風險回應與處理(如:網路安全保險)
Applicable types of controls (e.g., preventive, detection, corrective) — 控制類型(如:預防性、偵測性、修正性)
Control assessments (e.g., security and privacy) — 控制評估(如:安全與隱私)
Continuous monitoring and measurement — 持續監控與衡量
Reporting (e.g., internal, external) — 報告(如:內部、外部)
Continuous improvement (e.g., risk maturity modeling) — 持續改進(如:風險成熟度建模)
Risk frameworks (e.g., ISO, NIST, COBIT, SABSA, PCI) — 風險框架
1.10- Understand and apply threat modeling concepts and methodologies
理解並應用威脅建模的概念與方法
1.11 - Apply Supply Chain Risk Management (SCRM) concepts
套用供應鏈風險管理(SCRM)概念
•Risks associated with the acquisition of products and services (e.g., product tampering, counterfeits, implants) — 與取得產品與服務相關的風險(如:產品竄改、偽造、植入)
•Risk mitigations (e.g., third-party assessment and monitoring, SLAs, silicon root of trust, PUF, SBOM) — 風險緩解措施(如:第三方評估與監控、最低安全要求、服務等級協議、硬體信任根)
1.12 - Establish and maintain a security awareness, education, and training program
建立並維護資安意識、教育與訓練計畫
Methods and techniques to increase awareness (e.g., social engineering, phishing, gamification) — 提升資安意識的方法與技巧(如:社交工程、網路釣魚、遊戲化)
Periodic content reviews (e.g., cryptocurrency, AI, blockchain) — 定期內容更新,納入新興科技與趨勢(如:加密貨幣、人工智慧、區塊鏈)
Program effectiveness evaluation — 計畫成效評估
Reference:CISSP Certification Exam Outline Summary[Effective Date: April 15, 2024]