CISSP Certified Information Systems Security Professional
Level: Expert
Course Overview
Course Overview
This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination.
You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk management, asset security, security architecture, network security, identity and access management, security testing, operations and software development security.
You’ll review important concepts, consider how they apply to real organisational situations and develop the broad understanding required for the CISSP examination.
Target Audience
This course is suitable for:
- Chief information security officers
- Security directors and managers
- IT directors and managers
- Security architects and consultants
- Security engineers and analysts
- Security auditors
- Network architects
- Experienced cybersecurity professionals preparing for the CISSP examination
By the End of This Course, You Will Be Able To
- Apply security governance and risk management principles.
- Protect information and organisational assets throughout their lifecycle.
- Evaluate security architecture and engineering controls.
- Explain secure network design and communication technologies.
- Apply identity and access management principles.
- Plan security assessments, testing and audits.
- Support secure operations, incident response and disaster recovery.
- Integrate security throughout the software development lifecycle.
- Approach CISSP examination questions with greater confidence.
This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination.
You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk management, asset security, security architecture, network security, identity and access management, security testing, operations and software development security.
You’ll review important concepts, consider how they apply to real organisational situations and develop the broad understanding required for the CISSP examination.
Target Audience
This course is suitable for:
- Chief information security officers
- Security directors and managers
- IT directors and managers
- Security architects and consultants
- Security engineers and analysts
- Security auditors
- Network architects
- Experienced cybersecurity professionals preparing for the CISSP examination
By the End of This Course, You Will Be Able To
- Apply security governance and risk management principles.
- Protect information and organisational assets throughout their lifecycle.
- Evaluate security architecture and engineering controls.
- Explain secure network design and communication technologies.
- Apply identity and access management principles.
- Plan security assessments, testing and audits.
- Support secure operations, incident response and disaster recovery.
- Integrate security throughout the software development lifecycle.
- Approach CISSP examination questions with greater confidence.
CISSP Certified Information Systems Security Professional
Module 1. Security and Risk Management
Aligning security and risk to organisational objectives
- Evaluate and apply security governance principles
- Implement policies, standards and procedures
- Applying compliance
Applying risk management concepts
- Assessing threats and vulnerabilities
- Performing risk analysis and control
- Defining qualitative and quantitative analysis
Preserving the business
- Adhering to Business Continuity Management Code of Practise and Specifications
- Performing a business impact analysis
Investigating legal measures and techniques
- Reviewing intellectual property, liability and law, and compliance
- Differentiating traditional computer crime
- Establishing information and asset handling requirements
Module 2. Asset Security
Examining security models and frameworks
- The Information Security Triad and multi-level models
- Investigating industry standards: ISO 27001/27002
- Evaluating security model fundamental concepts
Exploring system and component security concepts
- Certification and accreditation criteria and models
- Reviewing mobile system/cloud/IoT vulnerabilities
Protecting information by applying cryptography
- Detailing symmetric and asymmetric encryption systems
- Ensuring message integrity through hashing
- Uncovering threats to cryptographic systems
Safeguarding physical resources
- Designing environments to resist hostile acts and threats
- Designing environments to resist hostile acts and threats
Module 3. Communication & Network Security
Defining a secure network architecture
- TCP/IP and other protocol models
- Protecting from network attacks
- Reviewing secure network components and communication channels
Examining secure networks and components
- Identifying wired and wireless technologies
- Implementing firewalls, secure communications, proxies, and tunnels
Module 4. Identity & Access Management
Controlling access to protect assets
- Defining administrative, technical and physical controls
- Implementing centralised and decentralised approaches
- Investigating biometric and multi-factor authentication
- Identifying common threats
- Managing the identity and access provisioning lifecycle
Module 6. Security Assessment & Testing
Designing and conducting security assessment strategies
- Leveraging the role of testing and auditing to analyse the effectiveness of security controls
- Differentiating detection and protection systems
Conducting logging and monitoring activities
- Distinguishing between the roles of internal and external audits
- Conduct or facilitate security audits
Module 7. Security Operations
Maintaining operational resilience
- Managing security services effectively
- Leveraging and supporting investigations and incident response
- Differentiating detection and protection systems
- Securely provisioning resources
Developing a recovery strategy
- Designing a disaster recovery plan
- Implementing test and maintenance processes
- Provisioning of resources
Module 8. Software Security Development
Securing the software development life cycle
- Applying software development methods and security controls
- Addressing database security concepts and issues
- Define and apply secure coding guidelines and standards
- Reviewing software security effectiveness and security impact
CISSP Certified Information Systems Security Professional
Module 1. Security and Risk Management
Aligning security and risk to organisational objectives
- Evaluate and apply security governance principles
- Implement policies, standards and procedures
- Applying compliance
Applying risk management concepts
- Assessing threats and vulnerabilities
- Performing risk analysis and control
- Defining qualitative and quantitative analysis
Preserving the business
- Adhering to Business Continuity Management Code of Practise and Specifications
- Performing a business impact analysis
Investigating legal measures and techniques
- Reviewing intellectual property, liability and law, and compliance
- Differentiating traditional computer crime
- Establishing information and asset handling requirements
Module 2. Asset Security
Examining security models and frameworks
- The Information Security Triad and multi-level models
- Investigating industry standards: ISO 27001/27002
- Evaluating security model fundamental concepts
Exploring system and component security concepts
- Certification and accreditation criteria and models
- Reviewing mobile system/cloud/IoT vulnerabilities
Protecting information by applying cryptography
- Detailing symmetric and asymmetric encryption systems
- Ensuring message integrity through hashing
- Uncovering threats to cryptographic systems
Safeguarding physical resources
- Designing environments to resist hostile acts and threats
- Designing environments to resist hostile acts and threats
Module 3. Communication & Network Security
Defining a secure network architecture
- TCP/IP and other protocol models
- Protecting from network attacks
- Reviewing secure network components and communication channels
Examining secure networks and components
- Identifying wired and wireless technologies
- Implementing firewalls, secure communications, proxies, and tunnels
Module 4. Identity & Access Management
Controlling access to protect assets
- Defining administrative, technical and physical controls
- Implementing centralised and decentralised approaches
- Investigating biometric and multi-factor authentication
- Identifying common threats
- Managing the identity and access provisioning lifecycle
Module 6. Security Assessment & Testing
Designing and conducting security assessment strategies
- Leveraging the role of testing and auditing to analyse the effectiveness of security controls
- Differentiating detection and protection systems
Conducting logging and monitoring activities
- Distinguishing between the roles of internal and external audits
- Conduct or facilitate security audits
Module 7. Security Operations
Maintaining operational resilience
- Managing security services effectively
- Leveraging and supporting investigations and incident response
- Differentiating detection and protection systems
- Securely provisioning resources
Developing a recovery strategy
- Designing a disaster recovery plan
- Implementing test and maintenance processes
- Provisioning of resources
Module 8. Software Security Development
Securing the software development life cycle
- Applying software development methods and security controls
- Addressing database security concepts and issues
- Define and apply secure coding guidelines and standards
- Reviewing software security effectiveness and security impact
- Examination: Certified Information Systems Security Professional
- Awarding body: ISC2
- Delivery method: Computerised Adaptive Testing
- Duration: Three hours
- Number of questions: Between 100 and 150
- Question format: Multiple-choice and advanced item types
- Passing score: 700 out of 1,000
- Delivery: ISC2-authorised Pearson VUE testing centre
- Examination voucher: Not included
Certification Requirements
To become CISSP certified, you must have at least five years of cumulative professional experience in two or more of the eight CISSP domains.
A relevant degree or an additional credential from ISC2’s approved list may satisfy up to one year of the experience requirement. Only one year can be waived.
You must also:
- Pass the CISSP examination.
- Complete the ISC2 endorsement process.
- Agree to follow the ISC2 Code of Ethics.
- Pay the applicable annual maintenance fee.
- Meet ISC2’s continuing professional education requirements.
If you pass the examination without the required experience, you can become an Associate of ISC2 while working towards full certification. You will then have six years to obtain the required five years of experience.
- Examination: Certified Information Systems Security Professional
- Awarding body: ISC2
- Delivery method: Computerised Adaptive Testing
- Duration: Three hours
- Number of questions: Between 100 and 150
- Question format: Multiple-choice and advanced item types
- Passing score: 700 out of 1,000
- Delivery: ISC2-authorised Pearson VUE testing centre
- Examination voucher: Not included
Certification Requirements
To become CISSP certified, you must have at least five years of cumulative professional experience in two or more of the eight CISSP domains.
A relevant degree or an additional credential from ISC2’s approved list may satisfy up to one year of the experience requirement. Only one year can be waived.
You must also:
- Pass the CISSP examination.
- Complete the ISC2 endorsement process.
- Agree to follow the ISC2 Code of Ethics.
- Pay the applicable annual maintenance fee.
- Meet ISC2’s continuing professional education requirements.
If you pass the examination without the required experience, you can become an Associate of ISC2 while working towards full certification. You will then have six years to obtain the required five years of experience.
- Five days of instructor-led training and examination preparation delivered by an experienced CISSP trainer.
- Course notes and presentation slides.
- Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISC2.
Please note: The official CISSP examination voucher is not included in the course price. You must register and pay for the examination separately.
- Five days of instructor-led training and examination preparation delivered by an experienced CISSP trainer.
- Course notes and presentation slides.
- Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISC2.
Please note: The official CISSP examination voucher is not included in the course price. You must register and pay for the examination separately.
There are no formal prerequisites for attending this course or sitting the CISSP examination.
However, CISSP is intended for experienced cybersecurity practitioners, managers and executives. You should have a broad understanding of information security and practical experience in one or more cybersecurity disciplines.
Passing the examination does not automatically make you CISSP certified. You must also meet ISC2’s professional experience, endorsement and membership requirements.
There are no formal prerequisites for attending this course or sitting the CISSP examination.
However, CISSP is intended for experienced cybersecurity practitioners, managers and executives. You should have a broad understanding of information security and practical experience in one or more cybersecurity disciplines.
Passing the examination does not automatically make you CISSP certified. You must also meet ISC2’s professional experience, endorsement and membership requirements.
Does this course include an Exam Pass Guarantee?
Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.
Who is the CISSP course suitable for?
Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.
Do I need cybersecurity experience to attend?
This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.
To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.
Does this course include an Exam Pass Guarantee?
Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.
Who is the CISSP course suitable for?
Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.
Do I need cybersecurity experience to attend?
This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.
To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.
Dates & Prices
Live Instructor-Led Virtual
Live Instructor-Led Virtual
Live Instructor-Led Virtual
Can't find the course dates, location or delivery type you are looking for?
Fill out the request dates form above and we'll try our best to accommodate or contact us directly.
"*" indicates required fields
How we deliver our courses
Virtual
Our virtual courses allow you to access live instructor-led training from the same expert instructors that deliver our classroom courses, without leaving the comfort of your home or office. All virtual courses are fully interactive, and learners can communicate with their trainer and peers at any time.
Many of our virtual courses are also recorded, so you can recap over the content you learnt as many time as you wish.
Classroom
Our classroom courses allow you to learn and interact face-to-face with our expert instructors in a comfortable and modern training environment. All of our classroom based courses take place at NILC centers, or high quality training facilities, and include all required IT and physical equipment.
We also limit our class sizes to help promote better discussions and to ensure your learning experience is comfortable as possible.
Onsite
Save time and hassle by arranging for one of our expert instructors to come to you. Our onsite courses allow you to learn in a location of your choosing, and you can train as many or as few people as you want – from a single person or team to whole departments. We can also fully customize the course content to the specific requirements of your business or project.
We offer onsite courses throughout the UK and it can be a great team building opportunity for colleagues to come together, bond and discuss.
Online
Our Online Self Paced courses allow you to learn new skills from our expert instructors, in your own time and at your own pace. Our flexible online learning platform allows you to access content on your computer, tablet or mobile device, whether you’re on the move or at home. All our online courses come with immediate access and you can start learning straight away, from any internet enabled compatible device.
We also offer online email support from our expert instructors, so they’re always on hand and happy to help you with any questions which may arise.
Why choose NILC for your training?
Award-Winning Training with Industry-Leading Customer Satisfaction
Trusted Training Partner by Colleges, Government Organisations and Businesses
UK-Based Trainers with Real-World Industry Experience
Family-Run Business with Customer Service at Its Core
Rated Excellent on Trustpilot with 950+ Customer Reviews
Our learners rate us 'Excellent' on Trustpilot
Frequently Asked Questions
Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.
Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.
This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.
To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.
We prepare you for all eight CISSP domains:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management
- Security Assessment and Testing
- Security Operations
- Software Development Security
CISSP covers both technical and managerial security responsibilities. It examines how security programmes are designed, implemented, and managed, covering areas such as architecture, networks, identity, testing, operations, and secure software development.
Yes. CISSP covers a broad body of knowledge, and our five-day course is intensive. We recommend reviewing your course materials, practising exam-style questions and addressing weaker domains before attempting the examination.
No. Passing the exam is only part of the certification process. You must also satisfy ISC2’s professional experience requirements and complete its endorsement process.
If you pass without having enough experience, you can become an Associate of ISC2 while working towards the experience required for full certification.
Frequently Asked Questions
Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.
Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.
This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.
To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.
We prepare you for all eight CISSP domains:
- Security and Risk Management
- Asset Security
- Security Architecture and Engineering
- Communication and Network Security
- Identity and Access Management
- Security Assessment and Testing
- Security Operations
- Software Development Security
CISSP covers both technical and managerial security responsibilities. It examines how security programmes are designed, implemented, and managed, covering areas such as architecture, networks, identity, testing, operations, and secure software development.
Yes. CISSP covers a broad body of knowledge, and our five-day course is intensive. We recommend reviewing your course materials, practising exam-style questions and addressing weaker domains before attempting the examination.
No. Passing the exam is only part of the certification process. You must also satisfy ISC2’s professional experience requirements and complete its endorsement process.
If you pass without having enough experience, you can become an Associate of ISC2 while working towards the experience required for full certification.
Trusted By