| Security and Risk Management (~15%) |
Security governance (policies, standards, procedures, guidelines), risk management (identification, assessment, treatment: avoid/transfer/mitigate/accept), compliance and legal frameworks (GDPR, HIPAA, PCI-DSS, SOX, NIST), BCP and DRP (RTO, RPO, MTD, BIA), privacy principles (PII, PHI, data sovereignty), ISC2 Code of Ethics, security awareness training, supply chain risk management |
| Asset Security (~10%) |
Data classification (government and commercial models), data lifecycle (creation, storage, use, sharing, archival, destruction), data retention policies, data protection controls (encryption, masking, tokenization, DLP), asset inventory and management, data remanence and sanitization |
| Security Architecture and Engineering (~13%) |
Secure design principles (defense in depth, least privilege, zero trust, fail secure, separation of duties), security models (Bell-LaPadula, Biba, Clark-Wilson, Brewer-Nash), cryptography (symmetric, asymmetric, hashing, PKI, digital signatures, key management), cloud security (shared responsibility, IaaS/PaaS/SaaS), secure hardware (TPM, HSM, secure enclaves), site and facility security (physical controls, environmental controls) |
| Communication and Network Security (~13%) |
OSI and TCP/IP models (security at each layer), network devices (firewalls, IDS/IPS, WAF, proxies, load balancers), network attacks (DoS/DDoS, MITM, ARP spoofing, DNS poisoning), network segmentation (VLANs, microsegmentation, SDN), wireless security (WPA2, WPA3, 802.1X, EAP), VPN (IPsec transport/tunnel mode, SSL/TLS), SASE and zero trust network access |
| Identity and Access Management (~13%) |
Authentication (factors, biometrics, MFA, passwordless), identity federation (SAML 2.0, OAuth 2.0, OpenID Connect, RADIUS, LDAP), access control models (DAC, MAC, RBAC, ABAC, rule-based), identity lifecycle (provisioning, review, deprovisioning), privileged access management (PAM, just-in-time, just-enough-access), directory services and identity providers |
| Security Assessment and Testing (~12%) |
Vulnerability assessment (scanning, prioritization, reporting), penetration testing (black-box, white-box, gray-box, rules of engagement), security audits (internal, external, third-party, SOC reports), test types (synthetic transactions, misconfiguration review, code review), BC/DR testing (tabletop, walkthrough, simulation, full interruption), log reviews and data analytics |
| Security Operations (~13%) |
Incident response (preparation, detection, containment, eradication, recovery, lessons learned), digital forensics (evidence handling, chain of custody, acquisition methods, legal hold), SOC operations (monitoring, triage, threat hunting, SIEM), patch and vulnerability management, change and configuration management, physical security (CCTV, access badges, mantraps), personnel security (background checks, onboarding, offboarding) |
| Software Development Security (~11%) |
Secure SDLC (security requirements, threat modeling, secure design, secure coding, security testing, secure deployment), OWASP Top 10 (injection, broken auth, XSS, CSRF, SSRF), security testing (SAST, DAST, IAST, RASP, fuzzing), DevSecOps (CI/CD security gates, infrastructure as code scanning), software supply chain (SBOM, code signing, repository security), secure coding practices (input validation, output encoding, parameterized queries, error handling) |