Course ID: #CISSP

Certified Information Systems Security Professional (CISSP)

Duration: 5 days Dates: 19 October 2026 18 January 2027 19 April 2027 19 July 2027

CISSP is the ISC2 certification for experienced professionals who plan, implement and are responsible for information security. The course follows the exam outline that has been in effect since 15 April 2024, with eight domains that combine governance and risk management with architecture, networking, identities, testing, operations and software development. The course prepares you for the CISSP exam (certification «Certified Information Systems Security Professional»).

Domain 1: Security and Risk Management

  • Professional ethics and the ISC2 Code of Ethics; security concepts: confidentiality, integrity, availability, authenticity and non-repudiation
  • Governance principles, alignment with business objectives, frameworks such as ISO, NIST and COBIT
  • Legal and regulatory requirements, data protection, contracts; types of investigations
  • Security policies, standards and procedures; business continuity requirements with business impact analysis
  • Personnel security, risk management, threat modelling and supply chain risk management
  • Security awareness and training programmes

Domain 2: Asset Security

  • Identify and classify information and assets, establish handling requirements
  • Provision assets securely: ownership, inventory, management
  • Data lifecycle: data roles, collection, location, retention, destruction; end of life and end of support
  • Data security controls by data state (at rest, in transit, in use), DRM, DLP and CASB

Domain 3: Security Architecture and Engineering

  • Secure design principles: least privilege, defence in depth, zero trust, threat modelling
  • Security models such as Bell-LaPadula and Biba; select controls based on security requirements
  • Security capabilities of information systems, such as memory protection and Trusted Platform Module (TPM)
  • Assess and mitigate vulnerabilities in client-server systems, databases, cloud, IoT, containers and virtualisation
  • Cryptographic solutions: lifecycle, symmetric and asymmetric methods, PKI; cryptanalytic attacks
  • Site and facility security (server rooms, data centres, climate control, fire protection, power supply); information systems lifecycle

Domain 4: Communication and Network Security

  • Secure network architectures: OSI and TCP/IP models, IPv4 and IPv6, IPsec, SSH, TLS
  • Segmentation with VLANs, VPNs and microsegmentation; wireless networks, 5G, software-defined networking and virtual private cloud
  • Secure network components: infrastructure, transmission media, network access control, endpoint security
  • Secure communication channels for voice and video, remote access and data communications

Domain 5: Identity and Access Management (IAM)

  • Control physical and logical access to information, systems, devices, facilities and applications
  • Identification and authentication: MFA, passwordless methods, session management, single sign-on and federated identities (on-premises, cloud, hybrid)
  • Authorization models: RBAC, rule-based, MAC, DAC, ABAC and risk-based access control
  • Identity and access lifecycle: provisioning, account reviews, role changes, privilege escalation; implement authentication systems

Domain 6: Security Assessment and Testing

  • Strategies for assessments, tests and audits (internal, external, third-party)
  • Test security controls: vulnerability assessment, penetration testing, log reviews, code reviews, compliance checks
  • Collect process data: account management, metrics, backup verification, training, disaster recovery and business continuity planning
  • Analyse and report test results, handle exceptions, ethical disclosure; conduct or facilitate security audits

Domain 7: Security Operations

  • Support investigations: evidence handling, digital forensics; logging and monitoring with IDPS, SIEM, UEBA and threat intelligence
  • Configuration management, fundamental operating principles (least privilege, separation of duties, privileged accounts), resource protection
  • Incident management from detection to lessons learned; firewalls, IDS/IPS, sandboxing, honeypots and AI-powered tools
  • Patch, vulnerability and change management
  • Recovery strategies, disaster recovery processes and DR tests (tabletop, walkthrough, simulation, parallel and full interruption tests); business continuity planning
  • Physical security and personnel safety (travel, training, emergency management)

Domain 8: Software Development Security

  • Security in the development lifecycle: waterfall, agile, DevOps and DevSecOps, maturity models
  • Controls in development environments: programming languages, libraries, CI/CD, code repositories, SAST and DAST
  • Assess software security effectiveness; security implications of acquired software (COTS, open source, third-party, cloud services)
  • Secure coding guidelines, API security
Learning Solution

Blended Learning, Firmenseminar, Individualcoaching, Klassenraumtraining, Online Live Webinar

Language

Deutsch, Englisch, Französisch, Italienisch

Dates

2026/10/19, 2027/01/18, 2027/04/19, 2027/07/19, flexibel, auf Anfrage

Location

Brüttisellen, Lausanne, auf Anfrage, flexibel

Experienced information security professionals, such as security managers, security architects, security analysts, network and systems engineers, IT auditors and consultants.

You should have solid knowledge of IT security and networking. For certification, ISC2 requires at least five years of cumulative, full-time professional experience in at least two of the eight domains; a relevant bachelor’s or master’s degree, or an ISC2-approved certification, satisfies one year. Anyone who passes the exam without this experience can become an Associate of ISC2 and make up the experience later.

After the course you will be able to:

  • align security governance, compliance and risk management with business objectives
  • classify and protect information and assets throughout their entire lifecycle
  • assess and select secure architectures, networks and cryptographic solutions
  • manage identities and access using current models
  • plan security testing and audits and evaluate their results
  • organise security operations, incident response and disaster recovery
  • build security into software development and software acquisition

Price range: CHF4'410 through CHF15'000 excl. VAT

Clear

SIGN UP

Newsletter

Receive news about new courses, offers and promotions by email.

← Back

Thank you for your response. ✨

Email Subscription
Amazon
VMware and Virtualisation