Book description
The only SSCP study guide officially approved by (ISC)2
The (ISC)2 Systems Security Certified Practitioner (SSCP) certification is a well-known vendor-neutral global IT security certification. The SSCP is designed to show that holders have the technical skills to implement, monitor, and administer IT infrastructure using information security policies and procedures.
This comprehensive Official Study Guide—the only study guide officially approved by (ISC)2—covers all objectives of the seven SSCP domains.
- Security Operations and Administration
- Access Controls
- Risk Identification, Monitoring, and Analysis
- Incident Response and Recovery
- Cryptography
- Network and Communications Security
- Systems and Application Security
This updated Third Edition covers the SSCP exam objectives effective as of November 2021. Much of the new and more advanced knowledge expected of an SSCP is now covered in a new chapter "Cross-Domain Challenges." If you're an information security professional or student of cybersecurity looking to tackle one or more of the seven domains of the SSCP, this guide gets you prepared to pass the exam and enter the information security workforce with confidence.
Table of contents
- Cover
- Title Page
- Copyright
- Acknowledgments
- About the Author
- About the Technical Editor
- Introduction
- PART I: Getting Started as an SSCP
- PART II: Integrated Risk Management and Mitigation
-
PART III: The Technologies of Information Security
-
Chapter 5: Communications and Network Security
- Trusting Our Communications in a Converged World
- Internet Systems Concepts
- Two Protocol Stacks, One Internet
- Wireless Network Technologies
- IP Addresses, DHCP, and Subnets
- IPv4 vs. IPv6: Important Differences and Options
- CIANA Layer by Layer
- Securing Networks as Systems
- Summary
- Exam Essentials
- Review Questions
- Chapter 6: Identity and Access Control
-
Chapter 7: Cryptography
- Cryptography: What and Why
- Building Blocks of Digital Cryptographic Systems
- Keys and Key Management
- Modern Cryptography: Beyond the “Secret Decoder Ring”
- “Why Isn't All of This Stuff Secret?”
- Cryptography and CIANA+PS
- Public Key Infrastructures
- Applying Cryptography to Meet Different Needs
- Managing Cryptographic Assets and Systems
- Measures of Merit for Cryptographic Solutions
- Attacks and Countermeasures
- PKI and Trust: A Recap
- On the Near Horizon
- Summary
- Exam Essentials
- Review Questions
-
Chapter 8: Hardware and Systems Security
- Infrastructure Security Is Baseline Management
- Securing the Physical Context
- Infrastructures 101 and Threat Modeling
- Endpoint Security
- Malware: Exploiting the Infrastructure's Vulnerabilities
- Privacy and Secure Browsing
- “The Sin of Aggregation”
- Updating the Threat Model
- Managing Your Systems' Security
- Summary
- Exam Essentials
- Review Questions
-
Chapter 9: Applications, Data, and Cloud Security
- It's a Data-Driven World…At the Endpoint
- Software as Appliances
- Applications Lifecycles and Security
- CIANA+PS and Applications Software Requirements
- Application Vulnerabilities
- “Shadow IT:” The Dilemma of the User as Builder
- Information Quality and Information Assurance
- Protecting Data in Motion, in Use, and at Rest
- Into the Clouds: Endpoint App and Data Security Considerations
- Legal and Regulatory Issues
- Countermeasures: Keeping Your Apps and Data Safe and Secure
- Summary
- Exam Essentials
- Review Questions
-
Chapter 5: Communications and Network Security
-
PART IV: People Power: What Makes or Breaks Information Security
- Chapter 10: Incident Response and Recovery
-
Chapter 11: Business Continuity via Information Security and People Power
- What Is a Disaster?
- Surviving to Operate: Plan for It!
- Timelines for BC/DR Planning and Action
- Options for Recovery
- Cloud-Based “Do-Over” Buttons for Continuity, Security, and Resilience
- People Power for BC/DR
- Security Assessment: For BC/DR and Compliance
- Converged Communications: Keeping Them Secure During BC/DR Actions
- Summary
- Exam Essentials
- Review Questions
- Chapter 12: Cross-Domain Challenges
-
Appendix: Answers to Review Questions
- Chapter 1: The Business Case for Decision Assurance and Information Security
- Chapter 2: Information Security Fundamentals
- Chapter 3: Integrated Information Risk Management
- Chapter 4: Operationalizing Risk Mitigation
- Chapter 5: Communications and Network Security
- Chapter 6: Identity and Access Control
- Chapter 7: Cryptography
- Chapter 8: Hardware and Systems Security
- Chapter 9: Applications, Data, and Cloud Security
- Chapter 10: Incident Response and Recovery
- Chapter 11: Business Continuity via Information Security and People Power
- Chapter 12: Cross-Domain Challenges
- Index
- End User License Agreement
Product information
- Title: (ISC)2 SSCP Systems Security Certified Practitioner Official Study Guide, 3rd Edition
- Author(s):
- Release date: February 2022
- Publisher(s): Sybex
- ISBN: 9781119854982
You might also like
book
(ISC)2 SSCP Systems Security Certified Practitioner Official Study Guide, 2nd Edition
The only SSCP study guide officially approved by (ISC)2 The (ISC)2 Systems Security Certified Practitioner (SSCP) …
book
(ISC)2 SSCP Systems Security Certified Practitioner Official Practice Tests, 2nd Edition
Smarter, faster prep for the SSCP exam The (ISC)² SSCP Official Practice Tests, 2nd Edition is …
book
(ISC)2 CCSP Certified Cloud Security Professional Official Study Guide, 3rd Edition
The only official study guide for the new CCSP exam objectives effective from 2022-2025 (ISC)2 CCSP …
book
(ISC)2 CCSP Certified Cloud Security Professional Official Study Guide, 2nd Edition
The only official study guide for the new CCSP exam (ISC)2 CCSP Certified Cloud Security Professional …