ISC2 CISSP: Identity and Access Design Without Blind Trust
Identity is central to security architecture because almost every system must decide who or what may act, against which resource, in which…
Read articleSECURITY & GOVERNANCE
Learn practical security operations, identity, threat defense, assurance, incident response and governance.
Security involves different kinds of evidence at different levels. An analyst investigating an intrusion needs timelines, indicators and defensive telemetry; an architect needs a coherent approach to trust boundaries and identity; a governance specialist must judge whether controls are effective and risk decisions can be defended.
CompTIA Security+ (SY0-701) covers broad security foundations, while CISSP addresses a wider security-management and architecture perspective. ISACA CISA approaches many of the same organizational systems from an audit and assurance standpoint. These distinctions are more useful than treating every cybersecurity certification as interchangeable.
CURATED FROM THE EDITORIAL LIBRARY
Carefully selected articles on the technologies, roles and concepts that shape this subject.
Identity is central to security architecture because almost every system must decide who or what may act, against which resource, in which…
Read articleSecurity architecture is not a contest to select the most controls. It is the discipline of choosing boundaries, failure modes and protections…
Read articleA confidential pricing workbook has the correct sensitivity label, but an old SharePoint sharing link makes it visible to a much larger…
Read articleA departing executive deletes a folder of sensitive emails while an investigation is underway. What happens to those messages depends on more…
Read articleAn employee downloads a large set of design documents two weeks before leaving the company. The action might represent theft, a routine…
Read articleA data loss prevention alert reports that someone copied a sensitive file to removable storage. Did the file leave the organization, was…
Read articleA finance director marks a spreadsheet Confidential, sends it to a vendor and assumes that the organization is protected. That assumption may…
Read articleAn analyst sees an endpoint alert for suspicious PowerShell activity and an identity alert for the same employee account. The easy response…
Read articleA security operations center has no active high-priority alarms, but a recent investigation revealed that an attacker remained in a peer organization…
Read articleA vulnerability scanner reports two thousand findings. Some are old certificates on isolated lab systems, others concern exposed services that process customer…
Read articleAn analyst reads a report about credential theft targeting organizations in the same industry. The report lists domains, file hashes and a…
Read articleA security analyst receives an alert that an employee account authenticated from an unusual address. The dashboard marks it high severity, but…
Read articleFURTHER EXPLORATION
Explore related disciplines across the editorial library.