The CISSP Prep Guide
Mastering the CISSP and ISSEP Exams
Chapter One
Security
Management
Practices
In our first chapter, we enter the domain of Security
Management. Throughout this book, you will see that many
Information Systems Security domains have several elements
and concepts that overlap. Although all other security
domains are clearly focused, this domain introduces concepts
that we extensively touch upon in both the Operations
Security (Chapter 6) and Physical Security (Chapter 10)
domains. A CISSP professional will be expected to know the
following:
* Basic security management concepts
* The difference between policies, standards, guidelines,
and procedures
* Security awareness concepts
* Risk management (RM) practices
* Data classification levels
We will examine the InfoSec domain of Security Management
by using the following elements:
* Concepts of Information Security Management
* The Information Classification process
* Security Policy implementation
* The roles and responsibilities of Security Administration
* Risk Management Assessment tools
* Secu ... read full excerpt from The CISSP Prep Guide: Mastering the CISSP and ISSEP (TM) Exams ebook