本书以CISSP认证考试为目标,内容涵盖了CISSP的所有考试要点,详细地介绍了应试者所应该掌握的所有技能。\r\n\r\n 本书在介绍考试要点时针对每个考试目标,使用了大量的插图、表格、试验、测试等,使读者在牢固掌握知识点的同时,轻松地获得丰富的实践经验。\r\n\r\n 本书由具有丰富CISSP认证培训经验的专家编写,是参加CISSP认证考试人员的必备辅导材料。\r\n
\r\n
1 Security Management Practices \r\n\r\n Objective 1.01 Management Responsibilities \r\n\r\n Objective 1.02 Risk Management \r\n\r\n Objective 1.03 Possible Threats \r\n\r\n Objective 1.04 Security Control Types \r\n\r\n Objective 1.05 Calculating Risk \r\n\r\n Objective 1.06 Security Policies and their Supporting \r\n\r\n Objective 1.07 Roles and Responsibilities \r\n\r\n Objective 1.08 Information Classification \r\n\r\n Objective 1.09 Employee Management \r\n\r\n 2 Access Control \r\n\r\n Objective 2.01 Identification and Authentication \r\n\r\n Objective 2.02 Single Sign-On Technologies \r\n\r\n Objective 2.03 Access Control Models and Techniques \r\n\r\n Objective 2.04 Access Control Administration \r\n\r\n Objective 2.05 Intrusion Detection System \r\n\r\n Objective 2.06 Unauthorized Access Control and Attacks \r\n\r\n 3 Security Models and Architecture \r\n\r\n Objective 3.01 System Components \r\n\r\n Objective 3.02 Operation System Security Mechanisms \r\n\r\n Objective 3.03 Security Models \r\n\r\n Objective 3.04 Security Evaluation Criteria \r\n\r\n 4 Physical Security \r\n\r\n Objective 4.01 Controls Pertaining to Physical Security \r\n\r\n Objective 4.02 Electrical Power and Environmental Issues \r\n\r\n Objective 4.03 Fire Detection and Suppression \r\n\r\n Objective 4.04 Perimeter Security \r\n\r\n 5 Telecommunication and Networking Securty \r\n\r\n Objective 5.01 TCP/IP Suite \r\n\r\n Objective 5.02 Cabling and Data Transmission Types \r\n\r\n Objective 5.03 LAN Technologies \r\n\r\n Objective 5.04 Networking Devices and Services \r\n\r\n Objective 5.05 Telecommunications Protocols and Devices \r\n\r\n Objective 5.06 Remote Access Methods and Technologies \r\n\r\n Objective 5.07 Fault Tolerance Mechanisms \r\n\r\n 6 Cryptography \r\n\r\n Objective 6.01 Cryptography Definitions \r\n\r\n Objective 6.02 Cipher Types \r\n\r\n Objective 6.03 Hybrid Approach \r\n\r\n Objective 6.04 Message Integrity and Digital Signatures \r\n\r\n Objective 6.05 Cryptography Applications \r\n\r\n Objective 6.06 Cryptographic Protocols \r\n\r\n Objective 6.07 Attacks \r\n\r\n 7 Disaster Recovery and Business Continuity \r\n\r\n Objective 7.01 Disaster Recovery versus Business Continuity \r\n\r\n Objective 7.02 Project Initiation Phase \r\n\r\n Objective 7.03 Business Impact Analysis \r\n\r\n Objective 7.04 Possible Threats \r\n\r\n Objective 7.05 Backups and Off-Site Facilities \r\n\r\n Objective 7.06 DRP and BCP Planning Objectives \r\n\r\n 8 Law, Investigation, and Ethics \r\n\r\n Objective 8.01 Ethics \r\n\r\n Objective 8.02 Hacking Methods \r\n\r\n Objective 8.03 Organiztion Liabilities and Ramifications \r\n\r\n Objective 8.04 Types of Law \r\n\r\n Objective 8.05 Computer Crime Investigation \r\n\r\n 9 Applications and Systems Development \r\n\r\n Objective 9.01 Project Development \r\n\r\n Objective 9.02 Object-Oriented Programming \r\n\r\n Objective 9.03 Distributed Computing \r\n\r\n Objective 9.04 Databases \r\n\r\n Objective 9.05 Artificial Intelligence \r\n\r\n Objective 9.06 Malware \r\n\r\n 10 Operations Security \r\n\r\n Objective 10.01 Operations Controls \r\n\r\n Objective 10.02 Configuration Management and Media Control \r\n\r\n Objective 10.03 Reacting to Failures and Recovering \r\n\r\n Objective 10.04 Software Backups \r\n\r\n A About the Free Online Practice Exam \r\n\r\n B Career Flight Path \r\n\r\n Index \r\n
\r\n
Shon Harris, CISSP MCSE, is a security consultant and a member of the Information Warfare unit in the U.S. Air Force. She is a contributing writer to Information Security Magazine and Windows 2000 magazine, a contributing author to the best-selling Hacker's Challenge and the author of CISSP All-in-One Exam Guide. Shon is also currently an instructor for the information technology training center Intense School (www intenseschool. com ).