| CISSP 是國際公認最具權威性的資訊安全專業人員證照,由國際資訊系統安全認證協會{ISC}2 所頒發。{ISC}2 成立於1989年,總部設立於北美,定位為獨立、非營利的組織,經營目標在於發展與管理一個資訊安全管理人員的認證架構。
該組織自1992年開始進行的 CISSP 認證,認證涵蓋的專業領域範圍十分廣泛,包括資訊安全管理實作、存取控制系統與方法、通訊與網路安全、密碼學、作業安全、應用程式與系統開發安全、資訊法律、電腦犯罪調查與電腦倫理、實體安全等。不僅如此,CISSP
認證還要求應試者資格,必須具備3~5年的資訊工作經驗。
CISSP 專業領域範圍:
- 資料存取控制系統及方法
- 應用系統發展安全
- 企業永續計劃(BCP)及災害復原計劃(DRP)
- 密碼學
- 法律犯罪調查及道德守則
- 作業安全
- 實體安全
- 資訊安全系統架構及模式
- 安全管理實務
- 資料通訊及網路安全
|
|
個人準備 CISSP 考試的參考資料 |
| Books |
- CISSP All-in-One Exam
Guide (All-in-One) by Shon Harris, Gareth Hancock
- The CISSP Prep Guide: Mastering the Ten Domains of Computer Security by Ronald L. Krutz, Russell Dean Vines, Edward M. Stroz
- Advanced CISSP Prep Guide: Exam Q&A by Ronald L. Krutz, Russell Dean Vines
- Sybex CISSP: Certified Information Systems Security Professional Study Guide
by Ed Tittel, Mike Chapple, James Michael Stewart
- CISSP Training Guide by Roberta Bragg
- Handbook
of Information Security Management by Micki Krause, Harold F. Tipton
- O'Reilly Practical
UNIX and Internet Security by Simson Garfinkel & Gene Spafford
(Sample
Chapters)
- O'Reilly Building
Internet Firewalls by D. Brent Chapman & Elizabeth D. Zwicky
(Sample
Chapters)
|
| Links for study |
- Official CISSP
Study Guide by ISC2
- Ben Rothke's CISSP preparation slides (download)
- www.cccure.org
- http://www.cissps.com/
- www.vlab.com.tw
- www.chinacissp.com (bbs.chinacissp.com)
- www.itpub.net
- CISSP
CBK Review Guides by Rob Slade
- 楊中皇老師「網路安全」參考資料
- Maximum
Security: A Hacker's Guide to Protecting Your Internet Site and Network
- www.securityfocus.com
- SANS InfoSec
Reading Room
- http://www.cissp.com/ new
|
| Sample Exams |
- CISSP and SSCP Open Study GROUP Online Quizzer
- Midwest's CISSP Test Preparation Software (download)
|
| Access Controls
|
- Kerberos:
IETF RFC
1510 and RFC
2712
|
| Applications Security
|
- IEEE Guide to the Software Engineering Body of Knowledge
(SWEBOK)
|
| Business Continuity Planning
|
- IT
contingency planning guidelines (NIST SP
800-34)
- CPM BCP
Handbook
|
| Cryptography
|
- Handbook of
Applied Cryptography

- eBCVG Network Security - Cryptography
Articles
- Introduction to Public Key Technology and the Federal PKI
Infrastructure (NIST
SP 800-32)
|
| Law, Investigations & Ethics
|
- IETF RFC 1087,
Ethics and the Internet
- ISC2 Code of Ethics
|
| Operations Security
|
- A Guide to Understanding Trusted Recovery in Trusted Systems,
NCSC Rainbow Series (Yellow Book)
|
| Physical Security
|
- DoD Trusted Computer System Evaluation Criteria,
NCSC Rainbow Series (Orange Book)
|
| Security Architecture
|
- A
Guide to Understanding Configuration Management in Trusted Systems,
NCSC Rainbow Series
- An
introduction to computer security: The NIST Handbook (NIST SP
800-12)
|
| Security Management
|
- Information Security Management Systems (Download)
- Generally Accepted Principles and Practices for Securing Information Technology Systems
(NIST SP
800-14)
- Risk Management Guide for Information Technology Systems (NIST SP
800-30)
- Security Self-Assessment Guide for Information Technology (NIST SP
800-26)
- IETF RFC
2196, Site Security Handbook New
- Security
testing (NIST SP
800-42)
- Guidelines
for developing security plans (NIST SP
800-18)
- Common Criteria for Information Technology Security Evaluation
- Conduct Security Awareness and Training
Building A Security Awareness Program - Addressing The Threat From Within
Building an Information Technology Security Awareness and Training Program
(NIST
SP 800-50)
|
| Telecommunications &
Network Security
|
- 台灣 交通大學 資訊科學研究所
資訊安全研究室 「網路安全」教材
- 大陸 北京大學 計算機系 訊息安全研究室 「網路與訊息安全」教材
及「電子商務安全」教材
- Keeping Your Site Comfortably Secure: An Introduction to Internet Firewalls
(NIST SP
800-10)
- Guidelines
on Firewalls and Firewall Policy (NIST SP
800-41)
- Intrusion
Detection Systems (NIST SP
800-31)
- Wireless Network Security: 802.11,
Bluetooth, and Handheld Devices (NIST SP
800-48)
|