Skip to content
Artwork for CISSP Central

CISSP Central

Krishnakumar Mahadevan

Welcome to CISSP Central, the ultimate podcast for aspiring and certified CISSP professionals! Whether you’re studying for the CISSP 2024 syllabus exam or looking to sharpen your cybersecurity skills, this podcast is your go-to resource. Each episode dives deep into the critical domains of cybersecurity, offering insights, tips, and real-world experiences from industry experts.

Join us as we explore the latest trends, challenges, and solutions in information security, helping you stay ahead in a rapidly evolving digital world. From encryption to risk management, compliance to cloud security, CISSP Central covers it all!

Perfect for CISSP candidates, InfoSec pros, and anyone passionate about safeguarding information in the modern age. Tune in, learn, and become the cybersecurity expert you were meant to be!

Note: This entire podcast has been prepared based on a published book on Amazon named C(R)ISSP: The Most Concise Handbook for CISSP 2024, written by myself, which can be purchased directly from Amazon by clicking this link.

Play
  • 20 episodes
  • Avg 11 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

  • S1 · E50
    Oct 16, 2024 · 12 min

    CISSP Domain8 Section 5

    8.5 Define and apply secure coding guidelines and standards 8.5.1 Security weaknesses and vulnerabilities at the source-code level 8.5.2 Security of application programming interfaces (API) 8.5.3 Secure Coding Practices 8.5.4 Software-defined security

    • Transcript
  • S1 · E49
    Oct 16, 2024 · 13 min

    CISSP Domain8 Section 3 and 4

    8.3 Assess the effectiveness of software security 8.3.1 Auditing and logging of changes 8.3.2 Risk analysis and mitigation 8.4 Assess security impact of acquired software 8.4.1 Commercial-off-the-shelf (COTS) 8.4.2 Open Source 8.4.3 Third-Party 8.4.4 Managed Services (e.g.., enterprise applications) 8.4.5 Cloud Services (e.g.., SaaS, IaaS, PaaS)

    • Transcript
  • S1 · E48
    Oct 16, 2024 · 11 min

    CISSP Domain8 Section2

    8.2 Identify & apply security controls in development environments 8.2.1 Programming languages 8.2.2 Libraries 8.2.3 Tool sets 8.2.4 Integrated Development Environment (IDE) 8.2.5 Runtime 8.2.6 Continuous Integration and Continuous Delivery (CI / CD) 8.2.7 Software Configuration Management (SCM) 8.2.8 Code Repositories 8.2.9 Application security testing (e.g., SAST, DAST, IAST & SCA)

    • Transcript
  • S1 · E47
    Oct 16, 2024 · 13 min

    CISSP Domain8 Intro and Section 1

    8.1 Understand and integrate security in the software development lifecycle 8.1.1 Development Methodologies 8.1.2 Maturity Models (e.g., Capability Maturity Model (CMM), Software Assurance Maturity Model (SAMM)) 8.1.3 Operations & Maintenance 8.1.4 Change Management 8.1.5 Integrated Product Team (IPT)

    • Transcript
  • S1 · E46
    Oct 16, 2024 · 3 min

    CISSP Domain7 Section 13, 14 and 15

    7.13 Participate in Business Continuity (BC) planning and exercises 7.14 Implement and manage physical security 7.15 Address personnel safety and security concerns 7.15.1 Travel 7.15.2 Security Training & Awareness 7.15.3 Emergency Management 7.15.4 Duress

    • Transcript
  • S1 · E45
    Oct 16, 2024 · 10 min

    CISSP Domain7 Section 12

    7.12 Test Disaster Recovery Plans 7.12.1 Read-through/Checklist 7.12.2 Walk-through/Tabletop 7.12.3 Simulation 7.12.4 Parallel 7.12.5 Full Interruption 7.12.6 Communications (e.g., stakeholders, test status, regulators)

    • Transcript
  • S1 · E44
    Oct 16, 2024 · 13 min

    CISSP Domain7 Section 11

    7.11 Implement Disaster Recovery Process 7.11.1 Response 7.11.2 Personnel 7.11.3 Communications 7.11.4 Assessment 7.11.5 Restoration 7.11.6 Training & Awareness 7.11.7 Lessons Learned

    • Transcript
  • S1 · E43
    Oct 16, 2024 · 11 min

    CISSP Domain7 Section 8, 9 and 10

    7.8 Implement and support patch and vulnerability management 7.9 Understand and participate in change management processes 7.10 Implement recovery strategies 7.10.1 Backup storage strategies 7.10.2 Recovery site strategies 7.10.3 Multiple processing sites 7.10.4 System resilience, high availability (HA), Quality of Service (QoS), and fault tolerance (FT)

    • Transcript
  • S1 · E42
    Oct 16, 2024 · 7 min

    CISSP Domain7 Section 7

    7.7 Operate and maintain detection and preventative measures 7.7.1 Firewall 7.7.2 Intrusion detection and prevention systems 7.7.3 Whitelisting/Blacklisting 7.7.4 Third-party provided security services 7.7.5 Sandboxing 7.7.6 Honeypots / Honeynets 7.7.7 Anti-malware 7.7.8 Machine learning and artificial intelligence (AI) based tools

    • Transcript
  • S1 · E41
    Oct 16, 2024 · 10 min

    CISSP Domain7 Section 6

    7.6 Conduct incident management 7.6.1 Detection 7.6.2 Response 7.6.3 Mitigation 7.6.4 Reporting 7.6.5 Recovery 7.6.6 Remediation 7.6.7 Lessons Learned

    • Transcript
  • S1 · E40
    Oct 16, 2024 · 11 min

    CISSP Domain7 Section 5

    7.5 Apply resource protection techniques 7.5.1 Media Management 7.5.2 Hardware and software asset management 7.5.3 Data at rest/Data in transit

    • Transcript
  • S1 · E39
    Oct 16, 2024 · 8 min

    CISSP Domain7 Section 3 and Section 4

    7.3 Perform Configuration Management (e.g., provisioning, baselining, automation) 7.4 Apply foundational security operations concepts 7.4.1 Need to know/Least privileges 7.4.2 Separation of Duties (SoD) and responsibilities 7.4.3 Privileged account management 7.4.4 Job rotation 7.4.5 Service Level Agreement (SLA)

    • Transcript
  • S1 · E38
    Oct 16, 2024 · 15 min

    CISSP Domain7 Section 2

    7.2 Conduct logging and monitoring activities 7.2.1 Intrusion detection and prevention systems (IDPS) 7.2.2 Security information and Event Management (SIEM) 7.2.3 Security orchestration, automation, and response (SOAR) 7.2.4 Continuous Monitoring 7.2.5 Egress Monitoring 7.2.6 Log Management 7.2.7 Threat Intelligence (e.g. Threat feeds, threat hunting) 7.2.8 User and Entity Behavior Analytics (UEBA)

    • Transcript
  • S1 · E37
    Oct 16, 2024 · 17 min

    CISSP Domain7 Intro and Section 1

    7.0 DOMAIN 7: SECURITY OPERATIONS 7.1 Understand and support investigations 7.1.1 Evidence Collection and Handling 7.1.2 Reporting and Documentation 7.1.3 Investigation Techniques 7.1.4 Digital forensics tools, tactics, and procedures 7.1.5 Artifacts (e.g., data, computers, networks, mobile devices)

    • Transcript
  • S1 · E36
    Oct 16, 2024 · 13 min

    CISSP Domain6 Intro and Section 4

    6.4 Analyze test output and generate report 6.4.1 Remediation 6.4.2 Exception Handling 6.4.3 Ethical disclosure 6.5 Conduct or facilitate security audits 6.5.1 Internal 6.5.2 External 6.5.3 Third Party 6.5.4 Location

    • Transcript
  • S1 · E35
    Oct 16, 2024 · 10 min

    CISSP Domain6 Intro and Section 3

    6.3 Collect Security Process data 6.3.1 Account Management 6.3.2 Management review and approval 6.3.3 Key Performance and Risk Indicator 6.3.4 Backup Verification data 6.3.5 Training and Awareness 6.3.6 Disaster Recovery (DR) and Business Continuity (BC)

    • Transcript
  • S1 · E34
    Oct 16, 2024 · 11 min

    CISSP Domain6 Section 2

    6.2 Conduct Security Control Testing 6.2.1 Vulnerability Assessment 6.2.2 Penetration Testing 6.2.3 Log Reviews 6.2.4 Synthetic Transaction 6.2.5 Code review and testing 6.2.6 Misuse case testing 6.2.7 Coverage analysis 6.2.8 Interface Testing 6.2.9 Breach attack simulations (BAS) 6.2.10 Compliance checks

    • Transcript
  • S1 · E33
    Oct 16, 2024 · 11 min

    CISSP Domain6 Intro and Section 1

    6.0 DOMAIN 6: SECURITY ASSESSMENT AND TESTING 6.1 Design and Validate assessment, test, and audit strategies 6.1.1 Internal 6.1.2 External 6.1.3 Third-party 6.1.4 Location (e.g. on-premises, cloud, hybrid)

    • Transcript
  • S1 · E32
    Oct 16, 2024 · 14 min

    CISSP Domain5 Intro and Section 5

    5.5 Manage the identity and access provisioning lifecycle 5.5.1 Account access review (e.g., user, system, service) 5.5.2 Provisioning and deprovisioning (e.g., on/off boarding & transfers) 5.5.3 Role definition & transition (e.g. people assigned to new roles) 5.5.4 Privilege escalation (e.g. use of sudo, auditing its use) 5.5.5 Service Accounts Management 5.5.6 Implement Authentication Systems

    • Transcript
Showing 1–20 of 20 episodes