Assess Security Controls

Preview unavailable

You must log in or sign up to view this lesson.

LoginSign up

Cybersecurity Career Mentorship Program

Buy nowLearn more

STEP 1: The Skills

  • Introduction 4-29-22
  • STEP ONE
  • Letter of Commitment.pdf

Module 1: Introduction

  • Promo Video (REGISTER TO WATCH PREVIEW)
  • Intro
  • ISSO SCA and GRC Cybersecurity Roles2
  • Which Role is Right For me.mp4
  • Who is an ISSO?
  • Job Environment
  • Qualifications
  • Things you should know
  • Responsibilities and daily tasks prt1
  • Responsibilities and daily tasks prt2
  • Responsibilities and daily tasks prt3
  • RMF Rev. 2
  • RMF Continued: Prepare
  • Prepare
  • Categorize
  • Select
  • Implement
  • Assess
  • Authorize
  • Monitor
  • Summary
  • RMF (Driver's License Analogy)
  • Module One Quiz
  • Weekly Coaching

Module 2: Cybersecurity Basics

  • What is Cybersecurity?
  • The CIA Triad: The 3 Pillars of Security
  • Integrity
  • Availability
  • Separation of Duties
  • Job Rotation and Mandatory Leave
  • Risk Management Framework (RMF)
  • Common Roles and Responsibilities
  • Top Down Approach
  • Control Frameworks1
  • Due Care and Due Diligence
  • Compliance1
  • Privacy
  • Privacy Continued
  • European Union Privacy Laws
  • GDPR
  • Computer Crime
  • MOM
  • How Data Breaches Occur
  • Threats: Virus, Trojan, Logic bomb, Worm, Bot, Rootkit, Spyware, Spam
  • BIA
  • Business Continuity Plan (BCP)
  • Disaster Recovery Sites
  • Threat Modeling
  • OWASP
  • DoS and DDoS Attacks
  • Man-in-the Middle Attacks
  • Social Engineering
  • Types of Social Engineering
  • Types of security controls1
  • RAT and Backdoor
  • Adware
  • Keylogger
  • Data Protection
  • Wireless Security
  • Ports1
  • OS Hardening
  • Multifactor Authentication
  • Identifying Authentication Factors
  • Mobile Security
  • Social Media
  • What is Networking?
  • Networking
  • Quiz
  • Weekly Coaching

Module 3: Duties

  • Attending Meetings
  • Types of Meetings
  • Conducting PTAs and PIA
  • Lab: Completing a PTA
  • Incident Response
  • Scenario_Incident Response
  • Questions to ask
  • Responding Back
  • Data Calls
  • Change Management
  • Developing ISAs
  • ISA Walk-through
  • Developing MOU/MOA (MEMORANDUM OF UNDERSTANDING or AGREEMENT)
  • Reviewing and Developing Contingency Plan Documentation
  • Contingency Plan (ISCP) Intro1
  • SIA (Security Impact Analysis)
  • SIA Walkthrough
  • Security Controls
  • NIST 800-53 Rev 5
  • Site for viewing Security Controls
  • AC Controls
  • AC-3
  • NIST Control Families
  • Developing an SSP part 1
  • Developing an SSP part 2

Module 4: Risk Management Framework (RMF)

  • RMF
  • RMF Rev2 Part1
  • Prepare (New Phase)
  • RMF Analogy (Building a House)
  • Prepare Analogy
  • Categorize Analogy
  • Select Analogy
  • Implement Analogy
  • Assess Analogy
  • Authorize Analogy
  • Monitor Analogy
  • RMF House Analogy House Summary
  • Driver's License Analogy
  • Main Roles and their Objectives
  • RMF Phases and Roles in Real World
  • Prepare Phase
  • Categorize Phase
  • How to categorize an information system
  • Kickoff
  • Case Study Kickoff Meeting
  • Kickoff Walkthrough
  • SDLC
  • Class Project Categorize LCM
  • Class Project Categorize LCM Walkthrough
  • Entering System Categorization in SSP
  • SAP (Security Assessment Plan)
  • Selecting Controls Class Project LCM
  • Selecting Common Controls
  • Selecting Common controls continued (Hybrid Controls)
  • Implementing Security Controls
  • Upload Artifacts and Contact Assessor
  • Assess Security Controls
  • Evidence Review Tips
  • Reviewing Security Controls Artifacts
  • 2 Main Roles and thier Objectives.
  • System Information XYZ system
  • ISSO and SCA Duties in a Nutshell
  • A to Z break down Prepare to Implementation
  • A to Z break down Assessment to Monitor
  • Quiz (Categorize Information System)
  • Select Phase Tasks
  • Selecting security Controls: What is a Security Control?
  • Select Phase Types of Controls Management Technical and Operational
  • Select Phase Common control System Specific Control and Hybrid Control
  • Select Phase: NIST 800-53 and FIPS 200
  • Select Phase NIST Website and SSP Templates
  • Select Phase: NIST Control Families
  • Select Phase: Low, Moderate, High and Enhancements
  • Select Phase Tailoring
  • Baseline and Benchmark
  • Implement 1
  • Implement Documenting Implementation Statements1
  • Assess Tasks
  • Assess SAP 2
  • Assess Evidence Review Tips
  • Conducting the assessment
  • Assessment Using the SAP worksheet
  • Assess Phase: Entering Assessment Observations
  • Assess SAP 1
  • Assess Phase: SAR
  • Assess Phase: Documenting the Findings in the SAR2
  • Assess Phase: Remediation Actions
  • Assess Phase: POA&M Report
  • Assess Phase: Documenting Plan of Action and Milestones POA&Ms
  • Authorize Phase
  • Monitor Phase
  • Monitor Phase Part 2
  • NIST 800-37 Rev 2 (Free)
  • Hands On Activity.pptx
  • System Categorization FIPS 199 - Template.docx
  • nistspecialpublication800-60v2r1.pdf
  • Weekly Coaching
  • Project Selecting Security Controls.pdf
  • SSP_for LCM System_v4.docx
  • SAP Worksheet.xlsx
  • POAM_LCM System_9-23-21.xls

Assessment Artifacts

  • AT-Security Awareness training Screenshot.png
  • AT- Security Awareness certificate.pdf
  • IR- Incident Response Plan_FEA.docx
  • AC-4__Interconnection Security Agreement v2.docx

STEP 2: Get Certified

  • The 2 Certifications to Get.mp4
  • Security Plus Intro.mp4
  • Security plus Course Objectives.mp4
  • Security plus Course Objectives 2.mp4
  • Security plus Course Objectives 3.mp4
  • comptia-security-sy0-601-exam-objectives-(2-0).pdf
  • The CAP Exam intro.mp4
  • Exam requirements
  • CAP Exam Prep
  • CAP Exam Outline-Post Oct 15
  • Exam Prep Questions
  • Weekly Coaching

STEP 3: Get The Job

  • Developing Your Resume.
  • Developing Your Resume part 2
  • Resume Template_for Security Control Assessor
  • Resume_John Doe_ISSO_.docx
  • Resume Roles and Responsibilities list.pdf
  • Using the Roles and Responsibilities List to Update your Resume

Module 5: Finding a Job

  • Tips on finding a Job
  • Finding a Job
  • Finding a Job with no Experience
  • Job Search Sites
  • Job Search Sites Indeed
  • Job Search Sites Glassdoor
  • Job Market
  • Background Investigation

Module 6: The interview Process

  • The Interview
  • Things to do before you go for an Interview
  • Interview process
  • Interview Tips 1st Call
  • Interview Questions PDF
  • Interview Questions
  • ISSO Salary Indeed
  • Interview Tips 2nd Call
  • Interview Tips: In-person interview
  • Interview Tips: Skype interview
  • Negotiating your Salary.
  • Researching your Salary
  • Company Reviews, Salaries on Glassdoor.
  • 7 Step Playbook to Get Hired in Cybersecurity
  • 7 Step Playbook to Get Hired in Cybersecurity
  • Weekly Coaching
  • Interview Session.mp4

Module 7: Developing Your Career

  • Things You Should do in Your First Week
  • ISSO Tips
  • Daily Scrum
  • ISSO Decision Making Matrix.pdf

Module 8: Resources: Templates, Forms, Guides, Cheat Sheets

  • NIST.SP.800-53r5
  • NIST.SP.800-18r1
  • Templates
  • NIST.FIPS.199
  • nistspecialpublication800-137
  • nistspecialpublication800-64r2
  • nist.sp.800-53ar4
  • POA&M Template
  • Resume Template
  • Security Controls Assessor Resume Template
  • nist.sp.800-37r1
  • ATO Letter Template
  • Cybersecurity Links to free online Resources
  • FAQ Monitor Phase
  • FAQ Categorize Phase
  • FAQ Select Phase
  • Career Advice Pocket Guide
  • Denial of ATO-Letter-Template.docx
  • NIST.SP.800-37r2.pdf
  • NIST.SP.800-53r4.pdf
  • NIST.SP.800-53r5.pdf
  • nistspecialpublication800-60v2r1.pdf
  • ATO Process Cheat Sheet.pdf
  • Controls that directly deal with encryption.docx
  • Controls you should be familiar with.docx
  • Resume_John Doe_ISSO_.docx

Security Controls

  • AC-18.mp4
  • AC-18 part2.mp4
  • AC-17.mp4
  • AC-19.mp4
  • AC-20.mp4
  • AC-21.mp4
  • AC-23 part 2.mp4
  • AC-23 part 1.mp4
  • PT-1.mp4
  • AC-22.mp4
  • NIST.SP.800-53Ar5.pdf
  • NIST.SP.800-53Ar5.pdf
  • SR-3.mp4
  • PT-2.mp4
  • SR-2.mp4
  • PT-2 part2.mp4
  • PT-4.mp4
  • SR-4 plus en hancements.mp4
  • PE Controls part1.mp4

ASK a QUESTION

  • Ask a Question
  • Asking a question Guidelines Part 1
  • Asking a question Guidelines Part 2
  • FAQ (Frequently Asked Questions)
  • Zoom Q&A Session
  • Outro
  • Coaching Session1
  • Coaching Session 3-18-22.mp4
  • Coaching Session 5-27-22.mp4
  • Coaching Session 5-27-22.mp4
  • Coaching call 6-10-22.mp4
  • Implementation descriptions.docx
  • Coaching Call 6-17-2022.mp4
  • Coaching Call 6-24-22.mp4
  • Coaching call 7-15-22.mp4
  • Coaching Call 7-22-22_.mp4
  • Coaching Call 11-16-22.mp4
  • Coaching Call 12-1-22.mp4
  • Coaching Call 12-14-22
  • Coaching Call 12-21-22.mp4
  • Coaching Call 2-15-23.mp43
  • Coaching Call 2-22-23_Select.mp4
  • Coaching Call 3-1-23_implement.mp4
  • Coaching Call 3-8-23_Assess_SAP.mp4
  • Coaching Call 3-22-23-Assess (Test, Interview, Examine)
  • Coaching call 6-14-23.mp4
  • Coaching Call 6-28-23.mp4
  • Coaching call 4-3-24.mp4

Hands-On Exercises

  • Categorize Hands on Activity 2 (Student Copy).pptx
  • System Categorization FIPS 199 - Template.docx
  • nist.fips.199.pdf
  • Hands On Activity.pptx
  • Select Hands On Activity.pdf
  • Security Controls In Scope for LCM System.pptx
  • Screenshots.docx
  • Assess Hands on Activity.pdf
  • FEA Security Assessment Report (SAR)_final.docx
  • Security Assessment Plan (SAP) Template_Student version.docx
  • SSP_for LCM System_v3-.docx
  • System Administration Manual_SOP_LCM.doc
  • SAP Worksheet.xlsx

On The Job Simulation (Virtual Internship Simulation)

  • Simulation Intro
  • DAY 1 Instructions
  • DAY 1: Daily Status Meeting
  • DAY 1: Email
  • DAY 1: Tip of the Day