Danh sách chương — Chapter list
ISSAP — Information Systems Security Architecture Professional
Kiến trúc bảo mật doanh nghiệp: SABSA/TOGAF/Zachman, Zero Trust Architecture (NIST SP 800-207), cloud landing zone design, IAM/PAM architecture, SOC/SIEM/SOAR integration, resilience architecture với RTO/RPO engineering.
ISSEP — Information Systems Security Engineering Professional
Kỹ thuật bảo mật hệ thống: SSE-CMM, NIST SP 800-160 Vol.1 & Vol.2, FAIR quantitative risk, NIST RMF 7-step, FedRAMP, FISMA, STIG/OpenSCAP, Common Criteria EAL levels, CMMC Level 2 compliance.
ISSMP — Information Systems Security Management Professional
Quản lý chương trình bảo mật: CISO leadership & board reporting, ERM (ISO 31000/COSO), threat intelligence lifecycle, ISAC/STIX/TAXII, ISO 22301 BCP, DR testing types, DORA cyber resilience, compliance program management.
Yêu cầu tiên quyết / Prerequisites
- Đã có chứng chỉ CISSP (hoặc đang ôn thi CISSP — Phase 3 của lộ trình này).
- Ít nhất 2 năm kinh nghiệm thực tế trong domain liên quan (architecture / engineering / management).
- Các CISSP Concentration được (ISC)² cấp riêng biệt — mỗi chứng chỉ có kỳ thi CBK riêng.
- Khuyến nghị: hoàn thành Phase 4 (CCSP/CSSLP/CGRC) trước khi học Phase 6.