
CCSP Certified Cloud Security Professional All-in-One Exam Guide
Description
Alles über E-Books | Antworten auf Fragen rund um E-Books, Kopierschutz und Dateiformate finden Sie in unserem Info- & Hilfebereich.
More details
Content
- Cover
- Title Page
- Copyright Page
- Dedication
- Contents
- Acknowledgments
- Introduction
- Chapter 1 How to Obtain the CCSP and Introduction to Security
- Why Get Certified?
- How to Get Certified
- CCSP Domains
- Domain 1: Architectural Concepts and Design Requirements
- Domain 2: Cloud Data Security
- Domain 3: Cloud Platform and Infrastructure Security
- Domain 4: Cloud Application Security
- Domain 5: Operations
- Domain 6: Legal and Compliance
- Introduction to IT Security
- Basic Security Concepts
- Risk Management
- Business Continuity and Disaster Recovery
- Chapter Review
- Chapter 2 Architectural Concepts and Design Requirements
- Cloud Computing Concepts
- Cloud Computing Definitions
- Cloud Computing Roles
- Key Cloud Computing Characteristics
- Building-Block Technologies
- Cloud Reference Architecture
- Cloud Computing Activities
- Cloud Service Capabilities
- Cloud Service Categories
- Cloud Deployment Models
- Cloud Cross-Cutting Aspects
- Security Concepts Relevant to Cloud Computing
- Cryptography
- Access Control
- Data and Media Sanitation
- Network Security
- Virtualization Security
- Common Threats
- Security Considerations for the Different Cloud Categories
- Design Principles of Secure Cloud Computing
- Cloud Secure Data Lifecycle
- Cloud-Based Business Continuity/Disaster Recovery Planning
- Cost-Benefit Analysis
- Identify Trusted Cloud Services
- Certification Against Criteria
- System/Subsystem Product Certifications
- ISO/IEC 27001 and 27001:2013
- NIST SP 800-53
- Payment Card Industry Data Security Standard (PCI DSS)
- SOC 1, SOC 2, and SOC 3
- Common Criteria
- FIPS 140-2
- Cloud Architecture Models
- Sherwood Applied Business Security Architecture (SABSA)
- IT Infrastructure Library (ITIL)
- The Open Group Architecture Framework (TOGAF)
- NIST Cloud Technology Roadmap
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Chapter 3 Cloud Data Security
- Understanding the Cloud Data Lifecycle
- Phases
- Design and Implement Cloud Data Storage Architectures
- Storage Types
- Threats to Storage Types
- Technologies Available to Address Threats
- Design and Apply Data Security Strategies
- Encryption
- Key Management
- Masking/Obfuscation/Anonymization
- Tokenization
- Application of Technologies
- Emerging Technologies
- Data Discovery and Classification Techniques
- Data Discovery
- Classification
- Relevant Jurisdictional Data Protections for Personally Identifiable Information
- Data Privacy Acts
- Privacy Roles and Responsibilities
- Implementation of Data Discovery
- Classification of Discovered Sensitive Data
- Mapping and Definition of Controls
- Application of Defined Controls
- Data Rights Management
- Data Rights Objectives
- Tools
- Data Retention, Deletion, and Archiving Policies
- Data Retention
- Data Deletion
- Data Archiving
- Auditability, Traceability, and Accountability of Data Events
- Definition of Event Sources
- Identity Attribution Requirements
- Data Event Logging
- Storage and Analysis of Data Events
- Continuous Optimizations
- Chain of Custody and Nonrepudiation
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Chapter 4 Cloud Platform and Infrastructure Security
- Cloud Infrastructure Components
- Physical Environment
- Networking
- Computing
- Virtualization
- Storage
- Management Plane
- Risks Associated with Cloud Infrastructure
- Risk Assessment and Analysis
- Virtualization Risks
- Countermeasure Strategies
- Design and Plan Security Controls
- Physical and Environmental Protection
- System and Communication Protection
- Virtualization Systems Protection
- Management of Identification, Authentication, and Authorization
- Auditing
- Disaster Recovery and Business Continuity Management Planning
- Understanding the Cloud Environment
- Understanding Business Requirements
- Understanding Risks
- Disaster Recovery/Business Continuity Strategy
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Chapter 5 Cloud Application Security
- Training and Awareness in Application Security
- Cloud Development Basics
- Common Pitfalls
- Common Vulnerabilities
- Cloud Software Assurance and Validation
- Cloud-Based Functional Testing
- Cloud Secure Development Lifecycle
- Security Testing
- Verified Secure Software
- Approved API
- Supply-Chain Management
- Community Knowledge
- Understanding the Software Development Lifecycle (SDLC) Process
- Phases and Methodologies
- Business Requirements
- Software Configuration Management and Versioning
- Applying the Secure Software Development Lifecycle
- Cloud-Specific Risks
- Quality of Service
- Threat Modeling
- Cloud Application Architecture
- Supplemental Security Devices
- Cryptography
- Sandboxing
- Application Virtualization
- Identity and Access Management (IAM) Solutions
- Federated Identity
- Identity Providers
- Single Sign-On
- Multifactor Authentication
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Chapter 6 Operations
- Support the Planning Process for the Data Center Design
- Logical Design
- Physical Design
- Environmental Design
- Implement and Build the Physical Infrastructure for the Cloud Environment
- Secure Configuration of Hardware-Specific Requirements
- Installation and Configuration of Virtualization Management Tools
- Run the Physical Infrastructure for the Cloud Environment
- Configuration of Access Control for Local Access
- Securing Network Configuration
- OS Hardening via the Application of Baselines
- Availability of Standalone Hosts
- Availability of Clustered Hosts
- Manage the Physical Infrastructure for the Cloud Environment
- Configuring Access Controls for Remote Access
- OS Baseline Compliance Monitoring and Remediation
- Patch Management
- Performance Monitoring
- Hardware Monitoring
- Backup and Restore of Host Configuration
- Implementation of Network Security Controls
- Log Capture and Analysis
- Management Plan
- Build the Logical Infrastructure for the Cloud Environment
- Secure Configuration of Virtual Hardware-Specific Requirements
- Installation of Guest Operating System Virtualization Toolsets
- Run the Logical Infrastructure for the Cloud Environment
- Secure Network Configuration
- OS Hardening via Application of Baselines
- Availability of the Guest Operating System
- Manage the Logical Infrastructure for the Cloud Environment
- Access Control for Remote Access
- OS Baseline Compliance Monitoring and Remediation
- Patch Management
- Performance Monitoring
- Backup and Restore of Guest OS Configuration
- Implementation of Network Security Controls
- Log Capture and Analysis
- Management Plan
- Ensure Compliance with Regulations and Controls
- Change Management
- Continuity Management
- Information Security Management
- Continual Service Improvement Management
- Incident Management
- Problem Management
- Release and Deployment Management
- Configuration Management
- Service Level Management
- Availability Management
- Capacity Management
- Conduct Risk Assessment for the Logical and Physical Infrastructure
- Framing Risk
- Assessing Risk
- Responding to Risk
- Monitoring Risk
- Understand the Collection, Acquisition, and Preservation of Digital Evidence
- Proper Methodologies for the Forensic Collection of Data
- Evidence Management
- Manage Communication with Relevant Parties
- Vendors
- Customers
- Partners
- Regulators
- Other Stakeholders
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Chapter 7 Legal and Compliance Domain
- Legal Requirements and Unique Risks Within the Cloud Environment
- International Legislation Conflicts
- Appraisal of Legal Risks Specific to Cloud Computing
- Legal Controls
- eDiscovery
- Forensics Requirements
- Privacy Issues and Jurisdictional Variation
- Difference Between Contractual and Regulated PII
- Country-Specific Legislation Related to PII and Data Privacy
- Differences Among Confidentiality, Integrity, Availability, and Privacy
- Audit Processes, Methodologies, and Required Adaptions for a Cloud Environment
- Internal and External Audit Controls
- Impact of Requirements Programs by the Use of Cloud
- Assurance Challenges of Virtualization and Cloud
- Types of Audit Reports
- Restrictions of Audit Scope Statements
- Gap Analysis
- Audit Plan
- Standards Requirements
- Internal Information Security Management System (ISMS)
- Internal Information Security Controls System
- Policies
- Identification and Involvement of Relevant Stakeholders
- Specialized Compliance Requirements for Highly Regulated Industries
- Impact of Distributed IT Model
- Implications of Cloud to Enterprise Risk Management
- Assess Providers Risk Management
- Difference Between Data Owner/Controller vs. Data Custodian/Processor
- Risk Mitigation
- Different Risk Frameworks
- Metrics for Risk Management
- Assessment of the Risk Environment
- Outsourcing and Cloud Contract Design
- Business Requirements
- Vendor Management
- Contract Management
- Executive Vendor Management
- Supply-Chain Management
- Exercise
- Chapter Review
- Questions
- Questions and Answers
- Appendix A Exam Review Questions
- Questions
- Quick Answers
- Questions and Comprehensive Answer Explanations
- Appendix B About the Download
- System Requirements
- Installing and Running Total Tester
- Total Tester Premium Practice Exam Software
- Technical Support
- Glossary
- Index
System requirements
File format: ePUB
Copy protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (not Kindle).
The file format ePub works well for novels and non-fiction books – i.e., „flowing” text without complex layout. On an e-reader or smartphone, line and page breaks automatically adjust to fit the small displays.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our ebook Help page.
File format: PDF
Copy-Protection: Adobe-DRM (Digital Rights Management)
System requirements:
- Computer (Windows; MacOS X; Linux): Install the free reader Adobe Digital Editions prior to download (see eBook Help).
- Tablet/smartphone (Android; iOS): Install the free app Adobe Digital Editions or the app PocketBook before downloading (see eBook Help).
- E-reader: Bookeen, Kobo, Pocketbook, Sony, Tolino and many more (only limited: Kindle).
The file format PDF always displays a book page identically on any hardware. This makes PDF suitable for complex layouts such as those used in textbooks and reference books (images, tables, columns, footnotes). Unfortunately, on the small screens of e-readers or smartphones, PDFs are rather annoying, requiring too much scrolling.
This eBook uses Adobe-DRM, a „hard” copy protection. If the necessary requirements are not met, unfortunately you will not be able to open the eBook. You will therefore need to prepare your reading hardware before downloading.
Please note: We strongly recommend that you authorise using your personal Adobe ID after installation of any reading software.
For more information, see our eBook Help page.