Study Guide
ISC2 CISSP Study Guide
Use the companion study guide to organize the material, compare important concepts, annotate key ideas, and build a written reference for review.
ISC2 · Free, ad-free audio course
A structured audio course for professionals building broad security knowledge across risk, architecture, operations, software, identity, and governance.
Companion Books
The study guide helps you organize and revisit the material. The flashcards book adds active recall and rapid review across the course objectives.
Study Guide
Use the companion study guide to organize the material, compare important concepts, annotate key ideas, and build a written reference for review.
Flashcards Book
Use the flashcards book for active recall, terminology checks, rapid review, and repeated practice across the course objectives.
Complete Lesson Directory
Search by topic or narrow the directory by exam domain. Courses with multiple editions are organized below so every season remains easy to find. Each lesson includes its own audio player, full description, transcript when available, and previous-or-next navigation.
140 lessons available
Getting Started
In this foundational episode, we introduce the Certified Information Systems Security Professional—better known as the CISSP.…
Getting Started
Choosing the right cybersecurity certification can shape your career for years to come. In this episode, we compare the CISSP to other well-known certifications including CompTIA Security+, CISM, CRISC, and CEH.…
Getting Started
The CISSP isn’t just a certification—it’s a powerful career accelerator. This episode breaks down how earning your CISSP can open doors to high-level roles, raise your earning potential, and give you access to new leadership opportunities in the cybersecurity field.…
Getting Started
Success on the CISSP exam requires more than memorizing facts—it takes a strategy, the right materials, and a focused mindset.…
Domain 1 · Security and Risk Management
Every cybersecurity professional must understand the CIA triad—confidentiality, integrity, and availability. These three pillars form the core of nearly every security strategy, policy, and control.…
Domain 1 · Security and Risk Management
Governance gives structure and direction to an organization’s cybersecurity efforts. In this episode, we explore what it means to build a security strategy aligned with business goals, risk appetite, and compliance obligations.…
Domain 1 · Security and Risk Management
Cybersecurity professionals must navigate a complex landscape of compliance obligations. This episode explains the differences between legal, regulatory, and contractual requirements, and how they impact your organization’s security posture.…
Domain 1 · Security and Risk Management
Security is not the job of a single person or department—it’s a shared responsibility across the organization. In this episode, we examine the roles of executives, managers, security teams, end users, and third-party stakeholders in protecting assets and managing risk.…
Domain 1 · Security and Risk Management
Ethics are the backbone of trust in the cybersecurity profession. This episode explores the professional responsibilities outlined in the ISC² Code of Ethics, including the duty to protect society, act honorably, provide competent service, and advance the profession.…
Domain 1 · Security and Risk Management
Risk management is a cornerstone of cybersecurity, and this episode introduces the essential vocabulary and concepts you need to know.…
Domain 1 · Security and Risk Management
Once a risk is identified and assessed, the next critical step is determining how to respond. In this episode, we examine the four primary risk response strategies: risk avoidance, risk mitigation, risk transference, and risk acceptance.…
Domain 1 · Security and Risk Management
Business Continuity Planning, or BCP, is essential for maintaining operations during unexpected disruptions. This episode explores the key elements of a successful BCP strategy, including risk identification, business impact analysis, and recovery planning.…
Domain 1 · Security and Risk Management
Disaster Recovery Planning is a focused component of business continuity that addresses the rapid restoration of IT infrastructure and systems.…
Domain 1 · Security and Risk Management
A strong cybersecurity program is built on clear and well-documented policies. In this episode, we break down the four foundational types of documentation: policies, standards, procedures, and guidelines.…
Domain 1 · Security and Risk Management
People are often the weakest link in cybersecurity, and managing personnel risk is a critical responsibility. In this episode, we discuss best practices for pre-employment screening, including background checks and reference validation.…
Domain 1 · Security and Risk Management
Even the best technical defenses can fail if employees don’t understand their security responsibilities. This episode focuses on the development and delivery of effective security awareness and training programs.…
Domain 1 · Security and Risk Management
Today’s organizations rely heavily on vendors, contractors, and service providers—but each relationship introduces potential risks. In this episode, we cover the principles of third-party risk management, including due diligence, contractual controls, and ongoing monitoring.…
Domain 1 · Security and Risk Management
Supply chains extend far beyond traditional logistics—they now include digital components, cloud providers, software dependencies, and more. This episode explores how cyber threats enter through the supply chain and what due diligence processes are needed to prevent compromise.…
Domain 1 · Security and Risk Management
Protecting personal data is not just a compliance requirement—it’s a trust imperative. In this episode, we dive into key privacy principles such as data minimization, purpose limitation, and transparency.…
Domain 1 · Security and Risk Management
Cybersecurity professionals must understand how to protect not only data but also intellectual property. This episode unpacks the key types of intellectual property—copyrights, trademarks, patents, and trade secrets—and how they apply in the digital world.…
Domain 1 · Security and Risk Management
Cybersecurity professionals operate in a legal landscape that spans continents, jurisdictions, and regulatory systems.…
Domain 1 · Security and Risk Management
Effective security governance depends on clear documentation and measurable performance. This episode explains the structure and function of security documentation—including policies, standards, guidelines, and procedures—as well as how to manage these documents over time.…
Domain 2 · Asset Security
Understanding how data flows through its lifecycle is essential for protecting it appropriately. This episode walks through the phases of the information lifecycle: creation, storage, usage, transmission, archival, and disposal.…
Domain 2 · Asset Security
Labeling data according to its sensitivity is one of the most overlooked but powerful techniques in cybersecurity.…
Domain 2 · Asset Security
Every piece of information in an organization should have an assigned owner and one or more stewards. In this episode, we define what it means to be a data owner—someone accountable for the data’s use, classification, and protection.…
Domain 2 · Asset Security
Keeping data longer than necessary can increase your risk exposure, but disposing of it too early can create legal and operational gaps. This episode addresses how to build effective data retention and archival strategies that meet legal, regulatory, and business needs.…
Domain 2 · Asset Security
Personally Identifiable Information (PII) is one of the most regulated and targeted types of data in cybersecurity. This episode focuses on how organizations identify, handle, and protect PII throughout its lifecycle.…
Domain 2 · Asset Security
Even when you delete a file, remnants can linger—posing serious security risks. This episode delves into the concept of data remanence and the techniques used to ensure secure data disposal.…
Domain 2 · Asset Security
Data is constantly on the move—or waiting to be accessed—and must be protected in both states. In this episode, we examine the best practices for securing data at rest (stored on disk or cloud) and data in transit (moving across networks).…
Domain 2 · Asset Security
Digital media—whether it’s a hard drive, USB stick, or backup tape—requires special handling to ensure data remains protected throughout its lifecycle. This episode explores how to securely store, track, and sanitize various types of storage media.…
Domain 2 · Asset Security
You can’t protect what you don’t know you have. In this episode, we focus on the importance of maintaining a comprehensive and accurate inventory of all information assets—hardware, software, data, and even personnel.…
Domain 2 · Asset Security
In a global digital economy, where your data resides can determine which laws apply to it. This episode explains data sovereignty—the principle that data is subject to the laws of the country in which it’s stored—and how jurisdictional control affects compliance, privacy, and access.…
Domain 2 · Asset Security
Cloud services offer scalability and convenience, but they also introduce unique security risks—especially when sharing infrastructure with other tenants.…
Domain 2 · Asset Security
Backup and recovery plans are your insurance against data loss. In this episode, we explore the critical controls necessary to ensure backups are available, secure, and usable when needed.…
Domain 2 · Asset Security
Some systems and data are too critical to treat like everything else. This episode focuses on how organizations identify, secure, and manage sensitive systems and high-value assets (HVAs), such as financial databases, intellectual property repositories, and industrial control systems.…
Domain 2 · Asset Security
Without visibility, security is just guesswork. In this episode, we explore how logging and monitoring give security teams the information they need to detect, investigate, and respond to incidents.…
Domain 3 · Security Architecture and Engineering
Designing secure systems isn’t just about applying tools—it’s about embedding principles. This episode introduces two foundational security design concepts: defense in depth and least privilege.…
Domain 3 · Security Architecture and Engineering
Security models are theoretical frameworks that help define how systems enforce access control, integrity, and confidentiality.…
Domain 3 · Security Architecture and Engineering
Security must be applied across all layers of a system, from the physical infrastructure to the application interface.…
Domain 3 · Security Architecture and Engineering
Security isn’t only about software—hardware matters too. This episode introduces key elements of secure hardware architecture, including trusted computing bases, secure boot processes, and hardware root of trust.…
Domain 3 · Security Architecture and Engineering
Virtualization and cloud computing are cornerstones of modern IT, but they also introduce unique security challenges. In this episode, we examine the architecture and risks associated with virtual machines, hypervisors, containers, and cloud platforms.…
Domain 3 · Security Architecture and Engineering
Systems don’t stay secure by accident—they stay secure through consistent configuration and control. In this episode, we cover the concepts of secure baselining and configuration management.…
Domain 3 · Security Architecture and Engineering
Flawed architecture is one of the most serious vulnerabilities in any system. In this episode, we explore common architectural security weaknesses, including insecure defaults, lack of isolation, poor trust boundaries, and insufficient input validation.…
Domain 3 · Security Architecture and Engineering
Cryptography is the backbone of digital security, and understanding its core principles is essential. In this episode, we explain the difference between symmetric and asymmetric encryption, along with their real-world applications.…
Domain 3 · Security Architecture and Engineering
Cryptographic tools aren’t set-and-forget solutions—they require lifecycle management. This episode explores how organizations select, deploy, and eventually retire cryptographic algorithms.…
Domain 3 · Security Architecture and Engineering
Hashing ensures that data remains unchanged during storage or transmission—a core requirement for integrity. In this episode, we explore how cryptographic hash functions like SHA-256 and SHA-3 are used to detect tampering, generate digital signatures, and verify file authenticity.…
Domain 3 · Security Architecture and Engineering
Cryptographic systems are only as secure as the keys they use—and how those keys are managed. In this episode, we delve into key management principles, including generation, storage, distribution, rotation, and destruction.…
Domain 3 · Security Architecture and Engineering
Public Key Infrastructure (PKI) is essential for enabling secure communication and verifying digital identities. This episode breaks down how PKI works, including the roles of certificate authorities (CAs), registration authorities (RAs), and digital certificates.…
Domain 3 · Security Architecture and Engineering
No cryptographic system is immune to attack, and CISSPs must understand the methods used to break or weaken them. In this episode, we explore cryptanalysis techniques including brute-force, dictionary attacks, chosen plaintext attacks, and side-channel analysis.…
Domain 3 · Security Architecture and Engineering
Security evaluations provide assurance that systems meet defined security requirements. In this episode, we examine key evaluation frameworks including Common Criteria (CC), the NIST Risk Management Framework (RMF), and the ISO/IEC 27000 series.…
Domain 3 · Security Architecture and Engineering
Security boundaries are essential for creating logical separations between systems, users, and data flows. In this episode, we explore how boundaries are defined and enforced, using both physical and logical mechanisms.…
Domain 3 · Security Architecture and Engineering
Technological innovation continues to transform the security landscape. In this episode, we examine how emerging technologies such as the Internet of Things (IoT), Artificial Intelligence (AI), and machine learning are impacting security architecture.…
Domain 3 · Security Architecture and Engineering
Supervisory Control and Data Acquisition (SCADA) systems and embedded devices operate some of the most critical infrastructure in the world—from energy grids to transportation systems.…
Domain 3 · Security Architecture and Engineering
Downtime is not an option for mission-critical systems. In this episode, we dive into fault tolerance, redundancy, and high availability—design strategies that ensure continuity despite component failures or unexpected disruptions.…
Domain 4 · Communication and Network Security
Understanding how networks are built and connected is foundational for any security professional. In this episode, we review core network architecture concepts, including the structure and purpose of Local Area Networks (LANs), Wide Area Networks (WANs), and the global Internet.…
Domain 4 · Communication and Network Security
The OSI and TCP/IP models provide a layered approach to understanding how data is transmitted, received, and managed across networks. In this episode, we refresh your understanding of these models and their significance in network security.…
Domain 4 · Communication and Network Security
Secure communication protocols form the backbone of protected digital environments. In this episode, we explore widely used secure protocols like HTTPS, SSH, SFTP, and SNMPv3.…
Domain 4 · Communication and Network Security
Segmentation limits the spread of attacks and improves control over traffic flows within a network. In this episode, we examine both traditional network segmentation and microsegmentation techniques.…
Domain 4 · Communication and Network Security
Layered security—known as defense in depth—is a core concept in cybersecurity architecture. This episode focuses on how firewalls and demilitarized zones (DMZs) serve as essential layers in protecting internal networks.…
Domain 4 · Communication and Network Security
Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) are crucial for identifying and stopping threats in real time. This episode explores how these tools work, their deployment strategies, and how they integrate with broader security operations.…
Domain 4 · Communication and Network Security
Secure routing and switching are foundational elements of network security. In this episode, we explore how routers and switches operate, and how attackers exploit their misconfigurations or weaknesses to gain access or disrupt communication.…
Domain 4 · Communication and Network Security
Listen to VPNs, Remote Access, and Tunneling Protocols in the ISC2 CISSP audio course.
Domain 4 · Communication and Network Security
Wireless networks present a unique set of vulnerabilities due to their reliance on open air transmission. In this episode, we examine wireless security protocols and controls, including WEP, WPA2, WPA3, and 802.1X.…
Domain 4 · Communication and Network Security
Voice over IP (VOIP) technologies have replaced traditional telephony in many organizations, but they come with their own set of security concerns.…
Domain 4 · Communication and Network Security
NAT and proxy servers play important roles in hiding internal IP addresses, enforcing access policies, and controlling traffic flow. In this episode, we explore how Network Address Translation (NAT) works to conserve IP space and obscure internal architectures.…
Domain 4 · Communication and Network Security
Continuous monitoring and traffic analysis are essential for detecting threats, performance issues, and policy violations. In this episode, we explore tools and techniques used to observe network behavior in real time.…
Domain 4 · Communication and Network Security
Zero Trust has emerged as a powerful model for modern cybersecurity, shifting the focus from perimeter defenses to granular, identity-centric control.…
Domain 4 · Communication and Network Security
Content Delivery Networks (CDNs) accelerate access to web content by distributing it across global edge nodes, but they also introduce new attack surfaces.…
Domain 4 · Communication and Network Security
As more organizations move to the cloud, network security must evolve. This episode focuses on cloud-native controls including Cloud Access Security Brokers (CASB), Secure Access Service Edge (SASE), and virtual firewalls.…
Domain 4 · Communication and Network Security
Distributed Denial of Service (DDoS) attacks are designed to overwhelm systems and take down critical services. In this episode, we explain how these attacks work—volumetric, protocol, and application-layer—and the techniques used to defend against them.…
Domain 5 · Identity and Access Management
Authentication is the process of verifying identity, and it forms the first line of defense in access control.…
Domain 5 · Identity and Access Management
Before you can authenticate someone, you must first establish their identity through a process called identity proofing. In this episode, we cover how identity proofing works—from in-person validation and biometric capture to document verification and knowledge-based authentication.…
Domain 5 · Identity and Access Management
Once a user’s identity is authenticated, the system must decide what they are allowed to do.…
Domain 5 · Identity and Access Management
Identity and Access Management (IAM) is not just about technology—it’s a continuous lifecycle that requires strong governance. This episode walks through each stage of the IAM lifecycle: provisioning, access management, auditing, revalidation, and deprovisioning.…
Domain 5 · Identity and Access Management
Passwords remain one of the most widely used—but frequently abused—authentication methods. In this episode, we explore how to design and manage effective password policies that balance usability with security.…
Domain 5 · Identity and Access Management
Biometric authentication uses unique physical or behavioral traits—like fingerprints, facial features, or voice—to verify identity.…
Domain 5 · Identity and Access Management
Federated identity systems allow users to authenticate across multiple platforms using a single identity, often enabling Single Sign-On (SSO). In this episode, we explain how standards like SAML, OAuth 2.0, and OpenID Connect enable cross-domain authentication.…
Domain 5 · Identity and Access Management
Privileged accounts have elevated access and are among the most targeted assets in any organization. In this episode, we examine Privileged Access Management (PAM) solutions, including vaulting, session recording, just-in-time provisioning, and approval workflows.…
Domain 5 · Identity and Access Management
Directory services are centralized databases that store and manage user credentials, permissions, and group memberships.…
Domain 5 · Identity and Access Management
Multi-Factor Authentication (MFA) significantly strengthens identity verification by requiring more than one authentication factor.…
Domain 5 · Identity and Access Management
Identity-as-a-Service (IDaaS) provides centralized identity and access management capabilities from the cloud.…
Domain 5 · Identity and Access Management
Managing credentials securely is critical to preventing unauthorized access and ensuring business continuity. This episode explores techniques for secure credential issuance, storage, expiration, and revocation.…
Domain 5 · Identity and Access Management
Access control mechanisms determine who can access what—and how. In this episode, we compare two classic models: Access Control Lists (ACLs) and capability tables. ACLs associate permissions with objects, while capability tables associate them with subjects.…
Domain 5 · Identity and Access Management
Access permissions tend to accumulate over time, creating a significant security risk if not reviewed regularly. This episode focuses on access recertification—the process of periodically validating that users still need the permissions they’ve been granted.…
Domain 5 · Identity and Access Management
Controlling user sessions is a critical part of maintaining secure access. In this episode, we examine how session tokens are issued, maintained, and terminated—along with techniques to prevent hijacking and session fixation attacks.…
Domain 5 · Identity and Access Management
Identity systems are high-value targets, and attackers use increasingly sophisticated techniques to exploit them. This episode examines key IAM-related attack vectors, including replay attacks, pass-the-hash, credential stuffing, brute-force, and phishing-based compromise.…
Domain 6 · Security Assessment and Testing
Security assessments come in many forms—each with a specific purpose. In this episode, we compare and contrast vulnerability scanning, penetration testing, and formal security audits.…
Domain 6 · Security Assessment and Testing
Security assessments must be planned thoroughly to be effective, safe, and actionable. This episode walks through the planning phase of an assessment project, including goal setting, scope definition, timeline management, and stakeholder communication.…
Domain 6 · Security Assessment and Testing
Security controls are only effective if they’re working as designed. In this episode, we explore how to test those controls using both manual and automated methods.…
Domain 6 · Security Assessment and Testing
Code is a frequent source of vulnerabilities, and reviewing it is essential for secure software development. In this episode, we discuss secure code review techniques—both manual and tool-assisted.…
Domain 6 · Security Assessment and Testing
Security testing requires careful control over both the test environment and the data used within it. In this episode, we explore how to create and manage dedicated testing environments that accurately simulate production systems without risking real assets.…
Domain 6 · Security Assessment and Testing
How do you know your security testing is thorough? In this episode, we examine test coverage metrics and how they help evaluate the effectiveness and completeness of assessments.…
Domain 6 · Security Assessment and Testing
Risk assessments help prioritize security controls by identifying vulnerabilities, evaluating threats, and estimating potential impacts.…
Domain 6 · Security Assessment and Testing
Audits provide assurance that an organization is following its security policies and regulatory obligations. In this episode, we explore how compliance audits are structured, conducted, and evaluated.…
Domain 6 · Security Assessment and Testing
Logs are a goldmine of insight—but only if you know how to analyze them effectively. This episode dives into log collection, normalization, and correlation to support both forensic investigations and compliance reporting.…
Domain 6 · Security Assessment and Testing
Proactive threat hunting involves searching for signs of compromise that automated tools may miss. In this episode, we explain how threat hunters use hypothesis-driven analysis, threat intelligence, and behavioral indicators to uncover hidden risks.…
Domain 6 · Security Assessment and Testing
The value of a security assessment is only realized when the results are communicated clearly. In this episode, we discuss how to structure, write, and deliver effective reports for vulnerability scans, penetration tests, audits, and more.…
Domain 6 · Security Assessment and Testing
What gets measured gets managed—and security is no exception. This episode focuses on security metrics and key performance indicators (KPIs) that help organizations evaluate the effectiveness of their controls and programs.…
Domain 6 · Security Assessment and Testing
Security is not a one-time event—it’s a continuous process. In this episode, we explore how continuous monitoring helps organizations detect changes, uncover risks, and maintain compliance in dynamic environments.…
Domain 6 · Security Assessment and Testing
Vendors and service providers often have privileged access to your data and systems—making them a potential weak link. This episode focuses on third-party risk management, including how to evaluate a vendor's security posture before and after engagement.…
Domain 7 · Security Operations
Security operations are built on consistency, structure, and clear documentation. In this episode, we explore the daily tasks that keep cybersecurity programs running—such as log reviews, system checks, user access reviews, and patch verification.…
Domain 7 · Security Operations
Capturing events is only the beginning—making sense of them is where the real value lies. This episode covers how organizations collect, normalize, and correlate logs from various systems and devices using Security Information and Event Management (SIEM) platforms.…
Domain 7 · Security Operations
Incidents are inevitable, and how you respond can determine the scale of impact. In this episode, we walk through the phases of incident management—preparation, identification, containment, eradication, recovery, and lessons learned.…
Domain 7 · Security Operations
Preserving and analyzing digital evidence requires precision, consistency, and legal awareness. This episode explores the fundamentals of digital forensics—from identifying and collecting evidence to maintaining a documented chain of custody.…
Domain 7 · Security Operations
The reliability of evidence hinges on how it’s handled. In this episode, we dive deeper into the principles and techniques for acquiring and preserving digital evidence.…
Domain 7 · Security Operations
When disaster strikes, organizations must restore operations quickly—and with minimal data loss. This episode focuses on Disaster Recovery Planning (DRP), particularly the metrics used to guide recovery strategies: Recovery Time Objective (RTO) and Recovery Point Objective (RPO).…
Domain 7 · Security Operations
Plans are only useful if they’re tested. In this episode, we explore the various methods for testing business continuity and disaster recovery plans—including walkthroughs, simulations, functional tests, and tabletop exercises.…
Domain 7 · Security Operations
Unpatched systems are one of the leading causes of successful cyberattacks. In this episode, we explore the role of patch management and configuration control in maintaining secure and reliable systems.…
Domain 7 · Security Operations
Security isn’t just about stopping bad changes—it’s about managing all changes effectively.…
Domain 7 · Security Operations
Data doesn’t disappear just because you delete it. In this episode, we focus on how to securely dispose of media and sanitize storage devices to prevent data recovery.…
Domain 7 · Security Operations
Endpoints remain a primary target for cyberattacks, and protecting them requires more than traditional antivirus solutions. This episode explores Endpoint Detection and Response (EDR), a modern approach to securing laptops, desktops, servers, and mobile devices.…
Domain 7 · Security Operations
Not all threats come from the outside. Insider threats—whether malicious or accidental—pose a significant risk to organizational security. In this episode, we examine how to identify, monitor, and respond to threats from employees, contractors, or partners with legitimate access.…
Domain 7 · Security Operations
Understanding malware is essential for effective defense. This episode explores how security teams analyze and contain malicious software, including viruses, worms, ransomware, and trojans.…
Domain 7 · Security Operations
Cybersecurity extends into the physical world, where threats like unauthorized access, theft, and sabotage can bypass digital defenses.…
Domain 7 · Security Operations
People are at the heart of every security program—and also one of its greatest vulnerabilities. In this episode, we examine personnel security controls that mitigate human-based risks.…
Domain 7 · Security Operations
The Security Operations Center (SOC) is the nerve center of cybersecurity monitoring and incident response. In this episode, we explore SOC roles, responsibilities, staffing models, tools, and key performance indicators.…
Domain 8 · Software Development Security
Secure software doesn’t happen by accident—it’s the result of disciplined development practices.…
Domain 8 · Software Development Security
Development methodologies have a direct impact on how security is integrated into software projects. This episode compares three major approaches—Waterfall, Agile, and DevOps—and how each handles risk, testing, and control.…
Domain 8 · Software Development Security
Secure applications start with secure design. In this episode, we explore how to incorporate security into architecture and code from the very beginning. Topics include threat modeling, input validation, secure defaults, and fail-safe mechanisms.…
Domain 8 · Software Development Security
User input is one of the most common vectors for exploitation in modern applications. In this episode, we focus on two critical programming techniques: input validation and output encoding.…
Domain 8 · Software Development Security
The OWASP Top 10 is a widely recognized list of the most critical security risks to web applications. In this episode, we walk through each entry—from injection and broken authentication to cross-site scripting, insecure deserialization, and insufficient logging.…
Domain 8 · Software Development Security
Many devastating cyberattacks originate from well-known coding flaws. This episode examines classic vulnerabilities including buffer overflows, SQL injection, and other input-related attacks.…
Domain 8 · Software Development Security
Security testing helps ensure software behaves as intended under hostile conditions.…
Domain 8 · Software Development Security
Source code repositories are central to modern software development—and to software security. This episode covers the security considerations for using platforms like GitHub, GitLab, Bitbucket, and internal repositories.…
Domain 8 · Software Development Security
Secure development doesn't stop at writing code—it includes how that code is built, tested, and deployed. In this episode, we explore configuration management and continuous integration/continuous delivery (CI/CD) pipelines.…
Domain 8 · Software Development Security
Version control systems track changes to code—but they also need to be protected themselves. This episode explores how tools like Git help enforce code integrity, collaboration, and traceability across development teams.…
Domain 8 · Software Development Security
Not all applications should be allowed to run in your environment. This episode explores application control mechanisms like whitelisting and sandboxing.…
Domain 8 · Software Development Security
Mobile apps introduce unique risks due to their widespread use, diverse platforms, and limited control over user devices. In this episode, we explore mobile app security concerns, including insecure storage, weak authentication, exposed APIs, and code tampering.…
Domain 8 · Software Development Security
APIs enable system integration but can expose your infrastructure to serious vulnerabilities if not secured properly. This episode focuses on how to design and manage secure APIs.…
Domain 8 · Software Development Security
DevSecOps is not just a toolset—it’s a culture that integrates security into every phase of the software development lifecycle. In this episode, we explore how DevSecOps breaks down silos between development, operations, and security teams.…
Exam Strategy and Review
Some CISSP topics consistently challenge even experienced professionals. In this episode, we break down ten of the most difficult concepts on the exam—ranging from cryptographic key lifecycle and security models to risk calculations and legal frameworks.…
Exam Strategy and Review
With so much material to retain, memory tools are a CISSP candidate’s secret weapon.…
Exam Strategy and Review
CISSP exam questions are known for being complex, layered, and sometimes intentionally confusing. In this episode, we teach you how to break questions apart to find the real point being tested.…
Exam Strategy and Review
CISSP exam questions often hinge on a single word that changes everything.…
Exam Strategy and Review
With so much material to retain, memory tools are a CISSP candidate’s secret weapon.…
Exam Strategy and Review
CISSP exam questions are known for being complex, layered, and sometimes intentionally confusing. In this episode, we teach you how to break questions apart to find the real point being tested.…
Exam Strategy and Review
CISSP exam questions often hinge on a single word that changes everything.…
Exam Strategy and Review
The CISSP exam uses Computerized Adaptive Testing (CAT), which means question difficulty and test length vary based on your performance. In this episode, we demystify the CAT format, explain how scoring works, and share strategies to manage your time across the exam.…
Exam Strategy and Review
Earning your CISSP opens new doors—but where you go next depends on your goals. In this episode, we explore the post-CISSP landscape, including leadership roles like CISO, and technical specializations like cloud security and digital forensics.…
Exam Strategy and Review
Not everyone passes on the first try—but failure doesn’t define your journey. In this episode, we guide you through a structured plan for recovery if you don’t pass the CISSP exam.…
Try another term or clear one of the filters.
A Practical Study Routine
Use the free audio course during a commute, walk, workout, or focused study session.
Use the study guide to organize the material, annotate key ideas, and build a reference you can return to.
Use the flashcards book to practice active recall and quickly revisit weak areas.
Related Magazine Features
Related Cyber Wiki
A defensive guide to the Enterprise ATT&CK campaign record C0028, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2015 campaign that disrupted Ukrainian electric-power substations using BlackEnergy and KillDisk.
ATT&CK Campaign AnalysisA defensive guide to the Enterprise ATT&CK campaign record C0025, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2016 campaign that disrupted Ukrainian electric-power distribution using Industroyer.
ATT&CK Campaign AnalysisA defensive guide to the Enterprise ATT&CK campaign record C0034, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a 2022 campaign against a Ukrainian electric utility that combined malware and living-off-the-land behavior to issue unauthorized SCADA commands.
ATT&CK Campaign AnalysisA defensive guide to the Enterprise ATT&CK campaign record C0063, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing destructive December 2025 attacks against Polish energy infrastructure involving Windows and PowerShell wipers.
ATT&CK Campaign AnalysisA defensive guide to the Enterprise ATT&CK campaign record C0057, including chronology, evidence, behavior mapping, and resilience lessons. The official record summarizes public reporting describing a cascading supply-chain compromise that moved from a trojanized trading application into 3CX build environments.
AI auditAI audit overreliance safeguards keep auditors responsible for scoping, evidence evaluation, judgment, challenge, and conclusions even when AI performs analysis or drafting.