All domains

Domain 7 · 13% of the exam

Security Operations

This domain focuses our attention on the day-to-day, moment-by-moment active use of the security controls and risk mitigation strategies that an organization is using. Security professionals reviewing CISSP Domain 7 must understand the principles of security operations and the different tools and techniques that can be used to manage security incidents, disaster recovery, and business continuity planning. This includes understanding the importance of ongoing monitoring and review of security controls and systems and of following regularly updated policies and procedures. Incident detection and response is at the heart of the information security operations' set of processes and principles. Everything done in the name of security operations should revolve around this center, supporting its purpose, enabling the security operations team to quickly and accurately detect potential intrusions or other incidents, and responding to them in a timely manner.

Learning objectives

  • Describe the legal, organizational, and compliance requirements of investigation activities.
  • Assess what makes logging practices effective and efficient.
  • Describe the security implications, operations, and limitations of monitoring systems, including intrusion detection and prevention (IDS/IPS), security information and event management (SIEM), and user and entity behavior analytics (UEBA).
  • Identify organizational enforcement approaches to support change management activities.
  • Justify the use of increased automation of change activities in terms of systems and information security.
  • Apply secure system design concepts, security models, and AC models to typical business and organizational processes.
  • Understand the importance of media management and media protection techniques.
  • Apply various incident response concepts and standards to incident response activities.
  • Evaluate the impact of organizational culture and compliance expectations on incident response.
  • Determine security implications for operational controls.
  • Associate incident response activities with specific attack forms.
  • Assess the security value of third-party services.
  • Identify the necessity and challenges of patch management to address vulnerabilities.
  • Relate organizational change management practices to information security.
  • Identify change management standards.
  • Describe established approaches to improving systems availability.
  • Identify the key steps and resources necessary to support business continuity and recovery processes.
  • Compare implementation and requirements of various types of testing for disaster recovery plans.
  • Discuss participation in business continuity planning and various BC exercises.
  • Identify information security implications of various physical controls.
  • Assess information security implications of personnel safety practices.

Key topics

  • Investigations
  • Logging and Monitoring Activities
  • Configuration Management
  • Security Operations Concepts
  • Resource Protection
  • Incident Management
  • Detective and Preventative Measures
  • Patch and Vulnerability Management
  • Change Management
  • Recovery Strategies
  • Disaster Recovery Processes and Plans
  • Business Continuity Planning and Exercises
  • Physical Security
  • Safety and Security Concerns

Lessons

Ordered the way the course presents them. Work top to bottom, or jump to whatever you need.

  1. 01Backup Storage StrategiesAccurate and comprehensive backups are instrumental to facilitating BCDR efforts; this is an essential aspect of the availability facet of the CIA triad.4 slides · 2 min read
  2. 02Implement Disaster Recovery Processes - AssessmentAs mentioned in earlier topics within this module, there is a fundamental need to calculate the entire, overall impact of the contingency; this includes both the damaging effects of the event itself, as well as the cost of the response efforts.4 slides · 1 min read
  3. 03Implement Disaster Recovery Processes - Training and AwarenessPersonnel assigned to BCDR tasks (responders and those who are part of the critical path, as well as alternates) should receive formal training for their roles; this should include involvement in all tests.3 slides · 1 min read
  4. 04Implement Disaster Recovery Processes - Personnelbpy.context.scene.objects.active = modifier_ob print("Selected" + str(modifier_ob)) = modifier ob is the active ob seirror_ob.select - •8 slides · 2 min read
  5. 05Implement Disaster Recovery Processes - RestorationThe ultimate goal of the response action is to resume full normal operations. The process to achieve this goal might include the following:4 slides · 2 min read
  6. 06Implement Disaster Recovery Processes - CommunicationsThe organization will need to have the capacity and resources for two types of essential contingency communications: internal and external.6 slides · 3 min read
  7. 07Major Change Management ActivitiesAll of the major change management practices address a common set of core activities that start with a request for change and move through various development and test stages until the change is released to the end users.6 slides · 2 min read
  8. 08Major Change Management Activities - Patch ManagementContinuing with the topic of change management activities, let's review how software routinely requires updating to address weaknesses, improve operating efficiency or added functionality.6 slides · 2 min read
  9. 09Major Change Management Activities - Patch Management StepsGoing further with patch management steps, review the following concepts and graphic that shows a typical patch management process:6 slides · 2 min read
  10. 10Configuration AutomationA baseline may exist for a single system or it may span thousands of systems.4 slides · 1 min read
  11. 11Case study - Bank of Bangladesh - Security Information and Event ManagementCase studyBank of Bangladesh: Security Information and Event Management5 slides · 4 min read
  12. 12Storage Media Protection and ManagementIt's tempting to think that the ubiquitous nature of cloud-hosted storage has eliminated the need for physical copies of important datasets or software to be created, stored, protected, managed, used, and then suitably destroyed at the end of their records…4 slides · 1 min read
  13. 13Security Controls for AvailabilityCIA Triad Availability: A system or software should be designed and implemented to recover from disruptions in a secure and quick manner to avoid negative impacts to productivity and business continuity.3 slides · 1 min read
  14. 14Personnel Management StrategiesIncluding Privileged Account Management, Job Rotation, Mandatory Vacation, and Other Personnel Management Strategies goNg 'A P JIME R322 R358 R37211 slides · 6 min read
  15. 15Internal Security ControlsWithin the facility, it is still necessary to maintain levels of security. LUL2 slides · 1 min read
  16. 16Intrusion Detection and PreventionIntrusion detection and prevention systems monitor network traffic to identify and block unauthorized or malicious activity in real time.7 slides · 3 min read
  17. 17DuressPersonnel should have a means to report to the organization if they are ever put under duress (threatened or hindered in movement).3 slides · 1 min read
  18. 18Change Management Standards and PracticesHow organizations affect change has been extensively studied within the context of many professional disciplines.4 slides · 1 min read
  19. 19Change Management Board (CMB)Change management boards evaluate, approve, and oversee IT changes to minimize risk and align with business objectives.4 slides · 2 min read
  20. 20Threat IntelligenceEffective threat intelligence enables organizations to anticipate, detect, and respond to evolving risks with informed, timely decisions.4 slides · 1 min read
  21. 21System Resilience, High Availability, Quality of Service, and Fault ToleranceOrganizations with extreme sensitivity to downtime - medical providers, military and/or intelligence agencies, high-volume online retailers, utilities - have a greater need to ensure BCDR capabilities are comprehensive and effective.7 slides · 2 min read
  22. 22Emergency ManagementEmergency management supports continuity by preparing for, responding to, and recovering from disruptions that threaten critical operations.3 slides · 1 min read
  23. 23Allowed vs. Blocked ListingControlling access to systems often involves listing items to explicitly allow or block specific files, applications, or connections.7 slides · 2 min read
  24. 24Continuous MonitoringInformation Security Continuous Monitoring (ISCM), coupled with automation, is now the norm for enterprise operations.6 slides · 1 min read
  25. 25Security Orchestration, Automation, and Response (SOAR)SOAR is a technology solution that streamlines threat detection and response by automating repetitive tasks and workflows.5 slides · 2 min read
  26. 26Honeypots and HoneynetsAnother method for protecting the environment involves the use of honeypots: machines that exist on the network but do not contain sensitive or valuable data (a number of machines of this kind, linked together as a network or subnet, are referred to as a…4 slides · 2 min read
  27. 27Ingress and Egress MonitoringDifferent tools become relevant depending on whether the risk from the attack is the result of traffic coming into or leaving the infrastructure.12 slides · 4 min read
  28. 28Log ManagementLog management collects, stores, and analyzes system activity to support security, troubleshooting, compliance, and operational awareness.8 slides · 3 min read
  29. 29Incident Response Activities - DetectionDetecting the first signs of a kill chain in action is the most critical step in responding to the attack.4 slides · 2 min read
  30. 30Security Training and AwarenessHealth and human safety are the paramount concern of all security efforts; ensuring personnel are properly trained and aware of safety and security threats and risks is essential.2 slides · 1 min read
  31. 31Separation of Duties (SoD) and ResponsibilitiesSeparation of duties reduces risk by ensuring no single individual controls all critical functions or access within a system.4 slides · 1 min read
  32. 32User and Entity Behavior Analytics (UEBA)User and Entity Behavior Analytics detects threats by analyzing unusual behavior patterns across users, devices, and systems.5 slides · 2 min read
  33. 33Firewalls, IDS, and IPSFirewalls, intrusion detection systems, and intrusion prevention systems are network defenses that control access, detect intrusions, and block malicious activity.3 slides · 1 min read
  34. 34Multiple Processing SitesSome organizations that seek to minimize downtime and enhance BCDR capabilities use multiple processing sites to obviate the effects of an impact to any single site.2 slides · 1 min read
  35. 35Implement Disaster Recovery Processes - ResponseA BCDR action can be triggered by a number of possible circumstances (natural disaster/severe weather, fire, physical damage to resources, external attack, etc.); to best manage the activation of the response, the organization must determine the following:3 slides · 1 min read
  36. 36Implement Disaster Recovery Processes - Lessons Learned From RecoveryAs you read through many business continuity and disaster recovery frameworks, standards, and guidance documents, you might get the impression that after the dust has settled and everything is back more or less to normal it is the right time to catch one's…4 slides · 1 min read
  37. 37TravelTravel raises security concerns for cybersecurity professionals, including data theft, unsecured networks, and exposure of sensitive devices or credentials.6 slides · 3 min read
  38. 38Recovery Site StrategiesRecovery site strategies provide alternate locations to restore operations after disruptions, ensuring business continuity and minimizing downtime.4 slides · 1 min read
  39. 39Third-Party Provided Security ServicesAs mentioned throughout the course, organizations can avail themselves of services offered by external entities to enhance security. This is especially true for organizations for which security is not a core competency.12 slides · 5 min read
  40. 40Maintaining the Integrity of an InvestigationPreserving the integrity of an investigation means protecting evidence from alteration, ensuring findings remain trustworthy and legally defensible.4 slides · 1 min read
  41. 41Business Continuity Planning and ExercisesPreparing for disruptions and disasters ensures organizations can maintain critical operations and recover quickly through tested continuity strategies.6 slides · 3 min read
  42. 42Digital Forensics Tools, Tactics, and ProceduresDigital forensics involves preserving, analyzing, and documenting electronic evidence to support investigations while maintaining its integrity and admissibility.9 slides · 3 min read
  43. 43Incident Response Activities - ResponseNIST 800-61 characterizes these activities as Containment, Eradication and Recovery, where the ISO 27035 framework calls them Responses.4 slides · 1 min read
  44. 44Investigative TechniquesThere are many ways to conduct an investigation and gather evidence.4 slides · 2 min read
  45. 45Case Study - Sony PicturesCase studyThe Sony Pictures hack of 2014 was a cyberattack that targeted Sony Pictures Entertainment, resulting in a massive data breach and widespread disruption.4 slides · 2 min read
  46. 46Possible Responses (Case Study - Sony Pictures)Case study answers1. What were the key challenges in conducting a thorough investigation into the Sony Pictures hack?1 slides · 1 min read
  47. 47Anti-Malware DefensesAnti-malware defenses detect and remove malicious software to protect systems and networks from compromise.7 slides · 4 min read
  48. 48Incident Response Activities, From Recovery to ReviewIncident response activities focus on identifying, containing, and resolving harmful events to minimize impact and restore normal operations.7 slides · 4 min read
  49. 49Incident Response Activities - MitigationMitigating an attack involves two logically separate tasks, containment and eradication, which are often done in combination.6 slides · 3 min read
  50. 50SandboxingSandboxing isolates code or files in a controlled environment to safely analyze behavior without risking the host system.3 slides · 1 min read
  51. 51Reporting and DocumentationAccurate reporting and documentation in cyber investigations ensure accountability, support legal action, and guide future prevention efforts.4 slides · 3 min read
  52. 52Evidence Collection and HandlingProper evidence collection and handling preserves the integrity, reliability, and admissibility of information during investigations and legal processes.5 slides · 4 min read
  53. 53Machine Learning and AI ToolsMachine learning and Al tools enhance security operations, track performance, metrics, and post emerging threats, that defenders must anticipate and counter.3 slides · 1 min read