Domain 7 · 13% of the exam
Security Operations
This domain focuses our attention on the day-to-day, moment-by-moment active use of the security controls and risk mitigation strategies that an organization is using. Security professionals reviewing CISSP Domain 7 must understand the principles of security operations and the different tools and techniques that can be used to manage security incidents, disaster recovery, and business continuity planning. This includes understanding the importance of ongoing monitoring and review of security controls and systems and of following regularly updated policies and procedures. Incident detection and response is at the heart of the information security operations' set of processes and principles. Everything done in the name of security operations should revolve around this center, supporting its purpose, enabling the security operations team to quickly and accurately detect potential intrusions or other incidents, and responding to them in a timely manner.
Learning objectives
- Describe the legal, organizational, and compliance requirements of investigation activities.
- Assess what makes logging practices effective and efficient.
- Describe the security implications, operations, and limitations of monitoring systems, including intrusion detection and prevention (IDS/IPS), security information and event management (SIEM), and user and entity behavior analytics (UEBA).
- Identify organizational enforcement approaches to support change management activities.
- Justify the use of increased automation of change activities in terms of systems and information security.
- Apply secure system design concepts, security models, and AC models to typical business and organizational processes.
- Understand the importance of media management and media protection techniques.
- Apply various incident response concepts and standards to incident response activities.
- Evaluate the impact of organizational culture and compliance expectations on incident response.
- Determine security implications for operational controls.
- Associate incident response activities with specific attack forms.
- Assess the security value of third-party services.
- Identify the necessity and challenges of patch management to address vulnerabilities.
- Relate organizational change management practices to information security.
- Identify change management standards.
- Describe established approaches to improving systems availability.
- Identify the key steps and resources necessary to support business continuity and recovery processes.
- Compare implementation and requirements of various types of testing for disaster recovery plans.
- Discuss participation in business continuity planning and various BC exercises.
- Identify information security implications of various physical controls.
- Assess information security implications of personnel safety practices.
Key topics
- Investigations
- Logging and Monitoring Activities
- Configuration Management
- Security Operations Concepts
- Resource Protection
- Incident Management
- Detective and Preventative Measures
- Patch and Vulnerability Management
- Change Management
- Recovery Strategies
- Disaster Recovery Processes and Plans
- Business Continuity Planning and Exercises
- Physical Security
- Safety and Security Concerns
Lessons
Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.
- 01Backup Storage StrategiesAccurate and comprehensive backups are instrumental to facilitating BCDR efforts; this is an essential aspect of the availability facet of the CIA triad.4 slides · 2 min read
- 02Implement Disaster Recovery Processes - AssessmentAs mentioned in earlier topics within this module, there is a fundamental need to calculate the entire, overall impact of the contingency; this includes both the damaging effects of the event itself, as well as the cost of the response efforts.4 slides · 1 min read
- 03Implement Disaster Recovery Processes - Training and AwarenessPersonnel assigned to BCDR tasks (responders and those who are part of the critical path, as well as alternates) should receive formal training for their roles; this should include involvement in all tests.3 slides · 1 min read
- 04Implement Disaster Recovery Processes - Personnelbpy.context.scene.objects.active = modifier_ob print("Selected" + str(modifier_ob)) = modifier ob is the active ob seirror_ob.select - •8 slides · 2 min read
- 05Implement Disaster Recovery Processes - RestorationThe ultimate goal of the response action is to resume full normal operations. The process to achieve this goal might include the following:4 slides · 2 min read
- 06Implement Disaster Recovery Processes - CommunicationsThe organization will need to have the capacity and resources for two types of essential contingency communications: internal and external.6 slides · 3 min read
- 07Major Change Management ActivitiesAll of the major change management practices address a common set of core activities that start with a request for change and move through various development and test stages until the change is released to the end users.6 slides · 2 min read
- 08Major Change Management Activities - Patch ManagementContinuing with the topic of change management activities, let's review how software routinely requires updating to address weaknesses, improve operating efficiency or added functionality.6 slides · 2 min read
- 09Major Change Management Activities - Patch Management StepsGoing further with patch management steps, review the following concepts and graphic that shows a typical patch management process:6 slides · 2 min read
- 10Configuration AutomationA baseline may exist for a single system or it may span thousands of systems.4 slides · 1 min read
- 11Case study - Bank of Bangladesh - Security Information and Event ManagementCase studyBank of Bangladesh: Security Information and Event Management5 slides · 4 min read
- 12Storage Media Protection and ManagementIt's tempting to think that the ubiquitous nature of cloud-hosted storage has eliminated the need for physical copies of important datasets or software to be created, stored, protected, managed, used, and then suitably destroyed at the end of their records…4 slides · 1 min read
- 13Security Controls for AvailabilityCIA Triad Availability: A system or software should be designed and implemented to recover from disruptions in a secure and quick manner to avoid negative impacts to productivity and business continuity.3 slides · 1 min read
- 14Personnel Management StrategiesIncluding Privileged Account Management, Job Rotation, Mandatory Vacation, and Other Personnel Management Strategies goNg 'A P JIME R322 R358 R37211 slides · 6 min read
- 15Internal Security ControlsWithin the facility, it is still necessary to maintain levels of security. LUL2 slides · 1 min read
- 16Intrusion Detection and PreventionIntrusion detection and prevention systems monitor network traffic to identify and block unauthorized or malicious activity in real time.7 slides · 3 min read
- 17DuressPersonnel should have a means to report to the organization if they are ever put under duress (threatened or hindered in movement).3 slides · 1 min read
- 18Change Management Standards and PracticesHow organizations affect change has been extensively studied within the context of many professional disciplines.4 slides · 1 min read
- 19Change Management Board (CMB)Change management boards evaluate, approve, and oversee IT changes to minimize risk and align with business objectives.4 slides · 2 min read
- 20Threat IntelligenceEffective threat intelligence enables organizations to anticipate, detect, and respond to evolving risks with informed, timely decisions.4 slides · 1 min read
- 21System Resilience, High Availability, Quality of Service, and Fault ToleranceOrganizations with extreme sensitivity to downtime - medical providers, military and/or intelligence agencies, high-volume online retailers, utilities - have a greater need to ensure BCDR capabilities are comprehensive and effective.7 slides · 2 min read
- 22Emergency ManagementEmergency management supports continuity by preparing for, responding to, and recovering from disruptions that threaten critical operations.3 slides · 1 min read
- 23Allowed vs. Blocked ListingControlling access to systems often involves listing items to explicitly allow or block specific files, applications, or connections.7 slides · 2 min read
- 24Continuous MonitoringInformation Security Continuous Monitoring (ISCM), coupled with automation, is now the norm for enterprise operations.6 slides · 1 min read
- 25Security Orchestration, Automation, and Response (SOAR)SOAR is a technology solution that streamlines threat detection and response by automating repetitive tasks and workflows.5 slides · 2 min read
- 26Honeypots and HoneynetsAnother method for protecting the environment involves the use of honeypots: machines that exist on the network but do not contain sensitive or valuable data (a number of machines of this kind, linked together as a network or subnet, are referred to as a…4 slides · 2 min read
- 27Ingress and Egress MonitoringDifferent tools become relevant depending on whether the risk from the attack is the result of traffic coming into or leaving the infrastructure.12 slides · 4 min read
- 28Log ManagementLog management collects, stores, and analyzes system activity to support security, troubleshooting, compliance, and operational awareness.8 slides · 3 min read
- 29Incident Response Activities - DetectionDetecting the first signs of a kill chain in action is the most critical step in responding to the attack.4 slides · 2 min read
- 30Security Training and AwarenessHealth and human safety are the paramount concern of all security efforts; ensuring personnel are properly trained and aware of safety and security threats and risks is essential.2 slides · 1 min read
- 31Separation of Duties (SoD) and ResponsibilitiesSeparation of duties reduces risk by ensuring no single individual controls all critical functions or access within a system.4 slides · 1 min read
- 32User and Entity Behavior Analytics (UEBA)User and Entity Behavior Analytics detects threats by analyzing unusual behavior patterns across users, devices, and systems.5 slides · 2 min read
- 33Firewalls, IDS, and IPSFirewalls, intrusion detection systems, and intrusion prevention systems are network defenses that control access, detect intrusions, and block malicious activity.3 slides · 1 min read
- 34Multiple Processing SitesSome organizations that seek to minimize downtime and enhance BCDR capabilities use multiple processing sites to obviate the effects of an impact to any single site.2 slides · 1 min read
- 35Implement Disaster Recovery Processes - ResponseA BCDR action can be triggered by a number of possible circumstances (natural disaster/severe weather, fire, physical damage to resources, external attack, etc.); to best manage the activation of the response, the organization must determine the following:3 slides · 1 min read
- 36Implement Disaster Recovery Processes - Lessons Learned From RecoveryAs you read through many business continuity and disaster recovery frameworks, standards, and guidance documents, you might get the impression that after the dust has settled and everything is back more or less to normal it is the right time to catch one's…4 slides · 1 min read
- 37TravelTravel raises security concerns for cybersecurity professionals, including data theft, unsecured networks, and exposure of sensitive devices or credentials.6 slides · 3 min read
- 38Recovery Site StrategiesRecovery site strategies provide alternate locations to restore operations after disruptions, ensuring business continuity and minimizing downtime.4 slides · 1 min read
- 39Third-Party Provided Security ServicesAs mentioned throughout the course, organizations can avail themselves of services offered by external entities to enhance security. This is especially true for organizations for which security is not a core competency.12 slides · 5 min read
- 40Maintaining the Integrity of an InvestigationPreserving the integrity of an investigation means protecting evidence from alteration, ensuring findings remain trustworthy and legally defensible.4 slides · 1 min read
- 41Business Continuity Planning and ExercisesPreparing for disruptions and disasters ensures organizations can maintain critical operations and recover quickly through tested continuity strategies.6 slides · 3 min read
- 42Digital Forensics Tools, Tactics, and ProceduresDigital forensics involves preserving, analyzing, and documenting electronic evidence to support investigations while maintaining its integrity and admissibility.9 slides · 3 min read
- 43Incident Response Activities - ResponseNIST 800-61 characterizes these activities as Containment, Eradication and Recovery, where the ISO 27035 framework calls them Responses.4 slides · 1 min read
- 44Investigative TechniquesThere are many ways to conduct an investigation and gather evidence.4 slides · 2 min read
- 45Case Study - Sony PicturesCase studyThe Sony Pictures hack of 2014 was a cyberattack that targeted Sony Pictures Entertainment, resulting in a massive data breach and widespread disruption.4 slides · 2 min read
- 46Possible Responses (Case Study - Sony Pictures)Case study answers1. What were the key challenges in conducting a thorough investigation into the Sony Pictures hack?1 slides · 1 min read
- 47Anti-Malware DefensesAnti-malware defenses detect and remove malicious software to protect systems and networks from compromise.7 slides · 4 min read
- 48Incident Response Activities, From Recovery to ReviewIncident response activities focus on identifying, containing, and resolving harmful events to minimize impact and restore normal operations.7 slides · 4 min read
- 49Incident Response Activities - MitigationMitigating an attack involves two logically separate tasks, containment and eradication, which are often done in combination.6 slides · 3 min read
- 50SandboxingSandboxing isolates code or files in a controlled environment to safely analyze behavior without risking the host system.3 slides · 1 min read
- 51Reporting and DocumentationAccurate reporting and documentation in cyber investigations ensure accountability, support legal action, and guide future prevention efforts.4 slides · 3 min read
- 52Evidence Collection and HandlingProper evidence collection and handling preserves the integrity, reliability, and admissibility of information during investigations and legal processes.5 slides · 4 min read
- 53Machine Learning and AI ToolsMachine learning and Al tools enhance security operations, track performance, metrics, and post emerging threats, that defenders must anticipate and counter.3 slides · 1 min read
