HOW TO PREPARE FOR INFOSEC DOMAIN White Paper
HOW TO PREPARE FOR INFOSEC DOMAIN White Paper
Email : sales@infosectrain.com
Web : www.infosectrain.com
HOW TO PREPARE
FOR INFOSEC DOMAIN’S
BEST CERTIFICATIONS?
Introduction Why Choose Us
Information security and certifications go
hand in hand. Information security Learn from Industry Experts
domain’s certifications play a huge role in
career choices and successes today. Some
of the prominent Information security 24X7 Post Support
certifications are the CISSP, CCSP, CISM,
CISA, CEH, CRISC. This paper lays out the Certification Focused Programs
way in which we can prepare for industry’s
most coveted certifications.
1. How to prepare for CISSP?
Here are the details about how to prepare for the most coveted exam in the Information
security domain:
1. Book a date for the exam at least 3 months away and start studying immediately
2. It is good to study for at least 4 hours every day
3. It is necessary to draw a timetable and stick to it diligently
4. It is also necessary to take into account the different personal and official
responsibilities in the three-month time frame and adjust the timetable and work
hours accordingly
5. Since the exam has 100-150 questions which have to answered in 180 minutes the
candidate needs to be totally thorough with all the topics of the exam. Since there
is a chance that the questions will be wordy, you need to have an absolute grasp
over all the topics of the exam.
6. Patience, persistence, and consistency are some factors that will help you to crack
the exam
These exam tips are common for all exams.
1.c. Resources:
Official (ISC)2 Guide to the CISSP CBK ((ISC)2 Press) 4th Edition by Adam Gordon
www.infosectrain.com Page 1
This official (ISC)2 book contains enhancements to the CISSP syllabus and it was
published in 2015. This new book contains the modified and current CISSP eight
domains and questions pertaining to them.
The Official (ISC)2 Guide to the CISSP CBK Reference 5th Edition, Kindle Edition
by John Warsinske (Author), Mark Graff (Contributor), Kevin Henry (Contributor),
Christopher Hoover (Contributor), Ben Malisow (Contributor), Sean Murphy
(Contributor), Charles Oakes (Contributor), George Pajari (Contributor)
This CBK covers the new eight domains of CISSP with the nec essary depth to
apply them to the daily practice of information security. Written by a team of
subject matter experts, this comprehensive reference covers all of the more than
300 CISSP objectives and sub-objectives in a structured format with:
www.infosectrain.com Page 2
SP 800-86 - Guide to Integrating Forensic Techniques into Incident
Response
SP 800-88 - Guidelines for Media Sanitization
SP 800-137 - Information Security Continuous Monitoring
1. d. Endorsement process:
All candidates who pass the exam must complete the endorsement process within 9
months. The application must be endorsed and digitally signed by an (ISC) 2 professional.
The endorser must attest to the candidate’s work experience in the IT security industry.
Once the candidate receives his CISSP credential from (ISC) 2 , a candidate should
recertify every 3 years.
www.infosectrain.com Page 3
2. How to prepare for CCSP:
Here are the details on how to prepare for the CCSP exam:
1. Candidates for the CCSP exam must demonstrate at least 5 years of full-time work
experience out of which 3 years must be in the field of Information security and 1
year must be in one of 6 domains of the CCSP exam.
2. The candidate must score 700 out of a possible 1000 points to pass the exam
3. The duration of the exam is 4 hrs.
4. The candidate can check the pricing of the exam from this link
5. The exam has about 125 questions
2.b Resources:
The CCSP candidate should thoroughly know all the fundamentals related to encryption,
virtualization technologies and the difference between IaaS, PaaS, and SaaS.
The candidate is expected to study the following books thoroughly in order to pass the
exam with ease!
1. The Official (ISC) 2 Guide to the CCSP CBK 2nd Edition, Kindle Edition by Adam
Gordon
This is the first book that has to be studied and this is the (ISC) 2 endorsed study
guide for the CCSP exam from Sybex. As organizations increasingly move their
data to the cloud, cloud security assumes enormous significance in today’s world.
This second edition features clearer diagrams, real-life scenarios, illustrated
examples, tables, best practices, and more.
2. Next, we recommend you to read the following pdf file from Cloud security
Alliance which can be freely downloaded from this link:
The fourth version of the ‘Security guidance for critical areas of focus in cloud
www.infosectrain.com Page 4
computing’ incorporates advances in cloud, security, and supporting technologies;
reflects on real-world cloud security practices; integrates the latest Cloud Security
Alliance research projects; and offers guidance for related technologies.
3. CCSP candidates should also read the ‘The Treacherous 12’ which is a freely
downloadable file from CSA
‘Treacherous 12’ are the top security threats that organizations face and this can be
downloaded from the above link. Candidates are expected to read this before
appearing for the CCSP exam.
4. Next, the candidates are also expected to download and read the CSA - Cloud
Control Matrix
The Cloud Control Matrix is used to provide guidance to prospective vend ors and
cloud customers in assessing the overall security risk of a cloud provider.
5. CCSP candidates are also expected to read the Jericho - Cloud Cube Model
The Jericho cloud cube model differentiates the different cloud formations by the
following factors:
a. Internal/External
b. Proprietary/Open
c. Perimeterised/De-perimeterized Architectures
d. Insourced/Outsourced
7. The candidate is also expected to read and familiarize themselves with the
following NIST publications:
a. NIST SP 800-146 Cloud Computing Synopsis and Recommendations
b. NIST SP 800-144 Guidelines on Security and Privacy in Public Cloud
Computing
c. NIST SP 800-125 Guide to Security for Full Virtualization Technologies
8. Finally, the candidate can download the electronic CCSP flash cards from (ISC)2.
This is a study tool for those preparing to take the CCSP exam. It is a unique and
interactive way to test one’s knowledge of industry terms and the various CCSP
www.infosectrain.com Page 5
domains.
This study tool can also be accessed via the phone both for Android and iOS via
the Quizlet app.
9. Once you have studied from the various resources, the next step would be to test
your knowledge of the CCSP exam before the big day. You can test your
knowledge from these sources:
CCSP Official (ISC)2 Practice Tests 1st Edition
CCSP Certified Cloud Security Professional Practice Exams 1st Edition
‘Cloud computing’ being a rapidly changing field, it is also good to listen to various
podcasts to keep up with the current trends.
www.infosectrain.com Page 6
3. How to prepare for CISA:
‘CISA’ is ‘Certified Information Systems Auditor (CISA) refers to a designation issued by
the Information Systems Audit and Control Association (ISACA) The CISA designation is
a globally recognized certification for IS audit control, assurance and security
professionals.
Before we see how to prepare for CISA, here are few facts about CISA:
3.b. Resources:
www.infosectrain.com Page 7
actual exam items but provide the candidates with the type of questions that had
appeared previously in the exam.
CISA Review Questions, Answers & Explanations Database—
This is a comprehensive 1,000-question pool of items that contains the
questions from the CISA Review Questions, Answers & Explanations
Manual 11th Edition. It is available online as well.
CISA Online Review Course—
This course prepares learners to pass the CISA certification exam using
proven instructional design techniques and interactive activities. You can
either navigate the course through the recommended way or focus on more
job practice areas.
On-site CISA Exam Review Course
This course provides the learner the opportunity to study with an
experienced, accredited professional. This may also include instructor led
breakdowns of the five domains, mock exams and discussion forums.
3.c Maintaining the certification
1. Candidates who pass the CISA exam must maintain their certification by
continuously earning CPEs or ‘Continuous Professional education’ over an annual
and 3 year certification period. This enables the candidates keep up with the
changes and maintain and upgrade their skills.
2. Successful candidates must report 20 CPE hours annually and 120 hours for a
three year period.
3. Candidates can earn CPEs by attending webinars and virtual conferences, training
courses, serving as an ISACA volunteer, mentoring.
4. Candidates must also pay the annual maintenance fees to ISACA headquarters.
Refer this link for current rates.
www.infosectrain.com Page 8
4. How to prepare for CRISC:
CRISC(Certified in Risk and Information Systems Control ) certification is designed for
those experienced in the management of IT risk, and the design, implementation,
monitoring and maintenance of IS controls.
CRISC exam candidates should have a solid understanding of CRISC terminology and
concepts. The CRISC exam will primarily align with the terminology and concepts
described in The Risk IT Framework, The Risk IT Practitioner Guide, and COBIT 4.1.
Before we get started on how to prepare for CRISC exam, let us view the exam details.
4.2 Resources:
It is good to obtain the resources listed below to ace the exam in the first attempt.
www.infosectrain.com Page 9
The 6th edition manual is organized to assist candidates in understanding
essential concepts and studying the following job practice areas:
IT Risk Identification
IT Risk Assessment
Risk Response and Mitigation
Risk and Control Monitoring and Reporting
Prior to submitting the application you have to fulfill the following requirements:
www.infosectrain.com Page 10
5. How to prepare for CISM:
CISM (Certified Information Security Manager) is a management-focused certification. It
promotes international security practices and recognizes the individual who manages,
designs, and oversees and assesses an enterprise’s information security.
5.2 Resources:
The following is a list of resources that can be used to pass the exam.
www.infosectrain.com Page 11
of 1,000 multiple-choice study questions, answers and explanations, which are
organized according to the CISM job practice domains.
The complete set of resources that can be used to study for the CISM exam can be
found here
You should have passed the CISM Exam within the last 5 years.
You should have the relevant full-time work experience in the CISM Job Practice
Areas.
You should submit the CISM Certification Application including Application
Processing Fee of US $50
5.4. Maintaining the certification
In order to become and remain a CISM an individual must agree to comply with the CISM
continuing professional education policy. This policy requires an individual to earn a
minimum of twenty (20) continuing professional education hours annually and one
hundred and twenty (120) continuing professional education hours for every three year
cycle. In addition, an annual maintenance fee of US $45 ISACA member and US $80
nonmember is required.
www.infosectrain.com Page 12
www.infosectrain.com Page 13