Author: Surya
CISSP Domain 8: Software Development Security Complete Guide
Software development security connects to application-level attack patterns — see Domain 8: Attacks and Domain 8: Malware. Database security and secure coding practices are explored in Domain 8: Database Security, Code Security, and Secure Coding Practices. The security assessment of software systems is covered in CISSP Domain 6: Security Assessment and Testing. Earlier CISSP notes… Read More →
CISSP Domain 7: Security Operations Complete Guide
Security operations relies on robust incident detection and response — the older CISSP notes on this topic are in 17 CISSP: Preventing and Responding to Incidents and 16 CISSP: Managing Security Operations. Microsoft Sentinel is a modern SIEM/SOAR platform for implementing security operations — common deployment mistakes are covered in Microsoft Sentinel Architecture Mistakes. Disaster… Read More →
CISSP Domain 6: Security Assessment and Testing Complete Guide
Security assessment and testing relies on a solid understanding of the security architecture being tested — see CISSP Domain 3: Security Architecture and Engineering. The IAM controls being assessed are covered in CISSP Domain 5: Identity and Access Management. Threat hunting and detection testing in Microsoft Sentinel is explored in Advanced Threat Hunting in Microsoft… Read More →
CISSP Domain 5: Identity and Access Management Complete Guide
The IAM Series on SunExplains provides step-by-step coverage of identity and access management concepts: start with IAM Part 1: The First Step in Controlling Access, followed by Identification and Authentication Strategy (Part 2), Authentication Factors Explained (Part 3), and Authorization Mechanisms (Part 4). The identity provisioning lifecycle — including joiner, mover, and leaver processes —… Read More →
CISSP Domain 4: Network Security Complete Study Guide
Network security builds on secure design principles from CISSP Domain 3: Security Architecture and Engineering. Access control to network resources is governed by identity and access management concepts covered in CISSP Domain 5: Identity and Access Management Complete Guide. Security assessment and testing of network controls are discussed in CISSP Domain 6: Security Assessment and… Read More →
CISSP Domain 3: Security Architecture and Engineering Complete Guide
The cryptographic foundations of this domain — including PKI and digital certificates — are covered in detail in Public Key Infrastructure (PKI) and Digital Certificates and 3.6 PKI and Cryptographic Applications. Secure design principles that anchor Domain 3 are explored in 3.1 Secure Design Principles. For the risk management context that drives security architecture decisions,… Read More →
Security Risk Management Explained: CISSP Domain 1 Study Guide
The foundational principles of the CIA Triad that underpin risk management are explained in CIA Triad and Security Concepts Explained: CISSP Domain 1 Foundation. For governance alignment, see Security Governance and Business Alignment Explained for CISSP. Risk treatment decision-making is covered in Risk Treatment Strategies Explained: Accept, Transfer, Mitigate, and Avoid. For continuous monitoring after… Read More →
Data Security Explained: Classification, Ownership, Retention, and Protection
Data classification is the first step — the decision framework is explained in Information and Asset Classification Explained: CISSP Domain 2 Asset Security Guide. Information handling procedures that follow classification are detailed in Information Handling Requirements: Why Data Classification Alone Is Not Enough. Ownership and accountability for data assets are covered in Information Ownership and… Read More →
Continuous Risk Monitoring for CISSP: Metrics, Maturity, and Improvement Explained
Continuous risk monitoring is part of a broader risk management lifecycle. For the foundational risk management framework, see Security Risk Management Explained: CISSP Domain 1 Study Guide. Risk treatment options that monitoring informs are covered in Risk Treatment Strategies: Accept, Transfer, Mitigate, and Avoid. The broader cybersecurity risk management context is in Cybersecurity Risk Management… Read More →
Microsoft Sentinel Analytics Rule Assessment Tool: How It Works
Sentinel Analytics Rule Audit Tool: Automate Your Rule Assessment This Sentinel analytics rule audit tool helps security engineers automatically assess, review, and validate Microsoft Sentinel analytics rules for quality, coverage, and accuracy. Auditing your Sentinel detection rules regularly is key to maintaining a strong SOC. This tool automates what used to take hours. For related… Read More →