Domain 1: Security Principles (24%)
1.1 Understand cybersecurity concepts
- Confidentiality
- Integrity
- Availability
- Authentication, Authorization, Accounting (AAA)
- Non-repudiation
- Privacy
1.2 Understand risk management concepts
- Risk management lifecycle
- Risk management processes
1.3 Understand governance concepts
- Regulations and laws
- Frameworks and guidelines
- Policies, standards (e.g., International Organization for Standardization (ISO), Center for Internet Security), procedures
1.4 Understand cybersecurity controls
- Technical controls
- Administrative controls
- Physical controls
1.5 Maintain professional and ethical conduct
- Professional code of conduct
- Due care and due diligence
- ISC2 Code of Ethics
Domain 2: Security Governance (17.3%)
2.1 Plan Governance, Risk, and Compliance (GRC)
- Purpose
- Importance
- Frameworks and tools
2.2 Understand redundancy
- Business Continuity (BC)
- Disaster Recovery (DR)
2.3 Understand security awareness
- Organizational culture (e.g., importance of security, security leadership)
- Concepts (e.g., social engineering, password protection, phishing)
2.4 Measure cybersecurity effectiveness
- Key metrics, Key Risk Indicators (KRI)
- Dashboards, score cards, reports
Domain 3: Identity and Access Management (IAM) Concepts (20%)
3.1 Understand identity life cycle management
- Roles definition
- Provision
- Review
- Deprovision
- Frameworks and tools
3.2 Understand logical access controls
- Principle of Least Privilege (PoLP)
- Separation of Duties (SoD)
- Access control models
Domain 4: Networking and Cloud Security Concepts (21.3%)
4.1 Understand network security
- Concepts (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), Virtual Private Network (VPN))
- Firewalls (e.g., ports, applications)
- Wireless (e.g., Wi-Fi, Bluetooth)
- Embedded systems (e.g., Industrial Control System (ICS)), Internet Of Things (IoT)
4.2 Understand network security architecture
- Comprehending network segmentation (e.g., Firewall zones, Virtual Local Area Network (VLAN), micro-segmentation)
- Defense in Depth
- Zero Trust (ZT)
4.3 Understand cloud security
- Characteristics (e.g., Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling)
- Service models
- Deployment models
- Shared security model (e.g., roles and responsibilities)
Domain 5: Security Operations and Incident Response (17.3%)
5.1 Understand data security
- Data handling (e.g., classification, labeling, masking, and sanitization)
- Encryption (e.g., symmetric, asymmetric, hashing, quantum resistant cryptography)
5.2 Understand security operations
- Logging and monitoring security events
- Security event triage (e.g., incident use cases, prioritization, correlation)
- Threat actors (e.g., types, motivations)
- Cyber threat intelligence
- Threat frameworks
5.3 Understand Incident Response (IR)
- Data handling policy implementing Incident Response Plan (IRP)
- Incident Response (IR) exercises (e.g., testing, tabletop)
5.4 Understand asset protection
- Asset lifecycle management (e.g., End Of Life (EOL) software and devices)
- Configuration and change management
5.5 Understand security testing
- Security readiness testing (e.g., blue teaming, purple teaming, red teaming)
- Application testing (e.g., vulnerability scanning, static analysis, dynamic analysis, threat modeling)
- Physical penetration testing (e.g., phishing, tailgating, impersonation)
The course content above may change at any time without notice in order to better reflect the content of the examination.