Course Contents
Introductions
- Course Overview
- Review and Revision Techniques
- The Exam, On the Day of the Exam, Exam Technique, After the Exam
Domain 1: Cloud Concepts, Architecture and Design
- Understand cloud computing concepts
- Describe cloud reference architecture
- Understand security concepts relevant to cloud computing
- Understand design principles of secure cloud computing
- Evaluate cloud service providers
Domain 2: Cloud Data Security
- Describe cloud data concepts
- Design and implement cloud data storage architectures
- Design and apply data security technologies and strategies
- Implement data discovery
- Implement data classification
- Design and implement Information Rights Management (IRM)
- Plan and implement data retention, deletion and archiving policies
- Design and implement auditability, traceability and accountability of data events
Domain 3: Cloud Platform and Infrastructure Security
- Comprehend cloud infrastructure and platform components
- Design a secure data centre
- Analyse risks associated with cloud infrastructure
- Design and plan security controls
- Plan Disaster Recovery (DR) and Business Continuity (BC)
Domain 4: Cloud Application Security
- Advocate training and awareness for application security
- Describe the Secure Software Development Life Cycle (SDLC) process
- Apply the Secure Software Development Life Cycle (SDLC)
- Apply cloud software assurance and validation
- Use verified secure software
- Comprehend the specifics of cloud application architecture
- Design appropriate Identity and Access Management (IAM) solutions
Domain 5: Cloud Security Operations
- Build and implement physical and logical infrastructure for cloud environment
- Operate and maintain physical and logical infrastructure for cloud environment
- Implement operational controls and standards (e.g., Information Technology Infrastructure Library (ITIL), International Organization for Standardization/International Electrotechnical Commission (ISO/IEC) 20000-1)
- Support digital forensics
- Manage communication with relevant parties
- Manage security operations
Domain 6: Legal and Compliance
- Articulate legal requirements and unique risks within the cloud environment
- Understand privacy issues
- Understand audit process, methodologies, and required adaptations for a cloud environment
- Understand implications of cloud to enterprise risk management
- Understand outsourcing and cloud contract design
Exam Preparation
- CCSP Official Practice Questions
- CCSP Workbook Review
Important note about the CCSP Exam
- The maximum time allowed for the exam is 3 hours, which includes all rest breaks.
- The exam has 125 questions, all of which must be answered.
- The pass mark is 700 / 1000.
Inclusions
Fees include:
- Comprehensive printed course workbook (digital copy)
- CCSP – Official (ISC)2 Study Guide (3e) (digital copy)&
- CCSP – Official (ISC)2 Practice Test (3e) (digital copy)
NOTE: The CCSP exam is NOT included in the course fees. The CCSP exam is administered by Pearson Vue on behalf of ISC2. If you wish to sit the exam you must register direct with Pearson Vue. See below.
Prerequisites
Candidates of the Cloud Security Certification must have at least five years of cumulative, paid full-time working experience in Information Technology. Three of these must be in information security, and one of which must be in one of the six CCSP domains.
Candidates who are already ISC2 members in good standing and who possess a Certified Information Systems Security Professional (CISSP) certificate may substitute all of the CCSP experience requirements on this basis
CCSP candidates who have passed the Cloud Security Alliance (CSA) Certificate of Cloud Security Knowledge (CCSK) may count this certification towards one year of experience in one of the six domains.
Exam format
- The maximum time allowed for the exam is 4 hours, which includes all rest breaks.
- The exam has 125 questions, all of which must be answered.
- The pass mark is 700 / 1000.
CCSP Exam – procedure | dates | locations
The CCSP exams are administered by Pearson Vue on behalf of ISC2. You must register for the exam direct with PearsonVue.
A list of PearsonVue Test Centres is shown below. For the most up-to-date listing please go to the PearsonVue ISC2 web page then click on Find a Test Centre in the upper right of the page.