Hello everyone,
Ask yourself: Why do you want to become CISSP certified?
After you have the answer start your journey.
Dreams without goals are just dreams. To achieve goals you must
apply discipline and consistency.
It took me one year to accomplish this challenge.
My advice: Do it at your own pace. We all have different experience
and background .
To successfully pass the exam you must know the concept off all
domains.
Most valuable domains are 1,7. Focus on them (BIA, BCP/DRP,
RMF, Risk management ).
It took me 5.5 hours to complete the 250 questions and I was taking
a break every hour or 50 questions.
During my preparation, the main problem for me was the language.
English is my 3rd.
A special thanks to Madunix that helped me a lot with all his
unstoppable support, guidance and unique notes.
In this journey, I met wonderful people - Milhovitch Yaniv, Dawood ,
people in Luke Ahmed Telegram group. Thank you all.
Golden Rules
1. Remember that you are in a role of Risk Advisor for senior
management
2. People are often the weakest link in securing information.
How to mitigate ?
Awareness, Training, Education
3. The Goal of Knowledge Transfer is to modify employee behavior
4. Try to make handwritten notes. Write as much as you can.
5. Create your own mind maps.
6. Read Madunix process guide
7. Hard work works
8. ANYONE CAN DECLARE AN EMERGENCY, ONLY THE BCP
COORDINATOR CAN DECLARE A DISASTER (Anyone can pull the
fire alarm or trigger an emergency alarm. Only the BCP coordinator
or someone specified in the BCP can declare a disaster which will
then trigger failover to another facility)
Resources
1. Sybex official study guide (10/10)
2. AIO – Shon Harris (7/10) only for reference for domain BCP,SDLC
3. 11th Hour CISSP(10/10)
Video
1. Kali the one and only
https://www.cybrary.it/
2. Sari green
http://sarigreenegroup.com/cissp-training/
3. Skillset
https://www.youtube.com/results?search_query=skillset+cissp+doma
in
4. David miller
http://shop.oreilly.com/product/0636920040798.do
NIST SP 8XX
800-60 Guide for Mapping Types of Information and Information
Systems to Security Categories
800-34 Contingency Planning
800-37 Risk Management Framework
800.30 Risk Assessments
800-137 Information Security Continuous Monitoring (ISCM)
Practice test
1. Testbanks.wiley.com (10/10)
2. McGraw-Hill (10/10)
2. AIO total tester (9/10)
3. Exam cram (10/10)
4. Sybex – practice tests (7/10)