• No results found

Information Systems Security Engineering Professional (ISSEP)

N/A
N/A
Protected

Academic year: 2021

Share "Information Systems Security Engineering Professional (ISSEP)"

Copied!
24
0
0

Loading.... (view fulltext now)

Full text

(1)

Information Systems

Security Engineering

Professional

(ISSEP)

Information Systems

Information Systems

Security Engineering

Security Engineering

Professional

Professional

(ISSEP)

(ISSEP)

(2)

2 UNCLASSIFIED

Presentation Outline

Presentation Outline

What is ISSE

Why ISSEP

Development of the ISSEP

Concentration Content

(3)

Systems Security Engineering

Systems Security Engineering

Definition

Definition

The

art and science

art and science

of

discovering users security needs and

discovering users security needs and

designing and making

designing and making

,

with

economy and elegance

economy and elegance

,

(information) systems

so that they can

safely resist the

safely resist the

forces to which they may be subjected

(4)

23-Dec-03 UNCLASSIFIED 4 DISCOVER NEEDS DEFINE SYSTEM REQUIREMENTS ASSESS EFFECTIVENESS USERS/USERS’ REPRESENTATIVES IMPLEMENT SYSTEM DEVELOP DETAILED DESIGN DESIGN SYSTEM ARCHITECTURE

Systems Security Engineering Process

Systems Security Engineering Process

PLAN TECHNICAL EFFORT

MANAGE TECHNICAL

(5)

Presentation Outline

Presentation Outline

What is ISSE

Why ISSEP

Development of the ISSEP

Concentration Content

(6)

23-Dec-03 UNCLASSIFIED 6

Why was the ISSEP created

Why was the ISSEP created

Enhance the field of information

systems security engineering

Promote a common process

NSA/IAD has committed itself to

promoting this certification to its

employees and vendors

(7)

Why was the ISSEP created

Why was the ISSEP created

(continued)

(continued)

Fill a need that NSA has identified to

recommend and use approved

contractors to support our customers

While a specific policy statement has not

been issued at this time, it is not known if

the NSA/IAD will require, or simply

prefer, individuals with the ISSEP in

connection with certain information

assurance projects

(8)

8 UNCLASSIFIED

Presentation Outline

Presentation Outline

What is ISSE

Why ISSEP

Development of the ISSEP

Concentration Content

(9)

Development of the ISSEP

Development of the ISSEP

Joint effort with NSA/IAD and

International Information Systems

Security Certification Consortium, Inc.

(ISC)

2

Initiated in April 2002

Test development started in October

2002

(10)

23-Dec-03 UNCLASSIFIED 10

NSA’s

NSA’s

Role

Role

NSA/IAD provides the Subject

Matter Experts

Motivation and justification

Motivation and justification

for this project is found in

for this project is found in

NSD 42 and the Federal

NSD 42 and the Federal

Technology Transfer Act of

Technology Transfer Act of

1986

1986

(15 U.S.C. Section 3710A)

(11)

(ISC)

(ISC)

22

’s Role

’s Role

(ISC)

2

will own and manage the

certification

The development of

The development of

concentration examinations

concentration examinations

is a direct response to

is a direct response to

(ISC)² research indicating

(ISC)² research indicating

that these needs of

that these needs of

information security

information security

professionals were not being

professionals were not being

met.

(12)

23-Dec-03 UNCLASSIFIED 12

Candidates for the ISSEP

Candidates for the ISSEP

Candidates for the ISSEP will have to

successfully complete the Certified

Information Systems Security

Professional (CISSP) exam and be in

good standing

The Common Body of Knowledge

(CBK) covered by the 10 domains is

considered foundational to the role of

the ISSE

(13)

CISSP Domains

CISSP Domains

Security Management Practices

Security Architecture and Models

Access Control Systems & Methodology

Application Development Security

Operations Security

Physical Security

Cryptography

Telecommunications, Network, &

Internet Security

Business Continuity Planning

(14)

14 UNCLASSIFIED

Presentation Outline

Presentation Outline

What is ISSE

Why ISSEP

Development of the ISSEP

Concentration Content

(15)

What the ISSEP Covers

What the ISSEP Covers

The ISSEP exam will include the

additional domains of:

Systems Security Engineering

Systems Security Engineering

Certification and Accreditation

Certification and Accreditation

Technical Management

Technical Management

U.S. Government Information

U.S. Government Information

Assurance Regulations

(16)

23-Dec-03 UNCLASSIFIED 16

Systems Security Engineering Process

Systems Security Engineering Process

1. Describe the Information Systems Security

Engineering (ISSE) process as documented in the Information Assurance Technical Framework

(IATF). (Knowledge)

2. Describe systems engineering processes in general and infer how security engineering

integrates with these processes. (Comprehension) 3. Construct network architectures according to the

principle of Defense-in-Depth. (Application)

4. Construct proper documentation for each phase of the ISSE process. (Application)

(17)

Certification and Accreditation

Certification and Accreditation

Sub-Domains 1. Definitions

2. Applicability to U.S. Government agencies

3. NIACAP, DITSCAP, Risk Management/Assessment 1. Describe the National Information Assurance C&A

Process (NIACAP) and the Department of Defense Information Technology Security C&A Process

(DITSCAP). (Knowledge)

2. Explain key roles in the C&A process. (Comprehension)

(18)

23-Dec-03 UNCLASSIFIED 18

Technical Management

Technical Management

Sub-Domains

1. Plan technical effort

2. Manage technical effort

1. Identify the responsibilities of a program manager. (Knowledge)

2. Describe processes and tools used to manage technical efforts. (Knowledge)

3. Predict personnel, funding, and other needs based on the level of effort and technical

(19)

U.S. Government IA Regulations

U.S. Government IA Regulations

Sub-Domains

1. National policies – Committee on National Security Systems (CNSS)

2. Civil agency policies

3. Defense agency policies

1. Define common IA terminology used by the U.S. Government. (Knowledge)

2. Interpret all regulations dictating IA

requirements for civil and defense agencies. (Application)

(20)

20 UNCLASSIFIED

Presentation Outline

Presentation Outline

What is ISSE

Why ISSEP

Development of the ISSEP

Concentration Content

(21)

Training Availability

Training Availability

Training is available

The course is two days and

covers the four new domain

areas

(22)

23-Dec-03 UNCLASSIFIED 22

When and Where the ISSEP Exam

When and Where the ISSEP Exam

is Available

is Available

As of 1 June 2003, candidates

can request to take the ISSEP

exam on a space available basis

wherever the CISSP exam is

(23)

Cost of the Exam and Credential

Cost of the Exam and Credential

The introductory cost of the exam is $295.00

The annual maintenance fee for the

credential is $35.00

There are no additional Continuing

Professional Education (CPE) requirements,

but 20 of your 120 required CPEs must be in

the new domain areas

(24)

23-Dec-03 UNCLASSIFIED 24

For More Information

For More Information

(ISC)

2

website for the study guide

and test dates and locations

www.isc2.org

NSA website for more information on

efforts of the Information Assurance

Directorate

References

Related documents

Article Title: When Security meets Software Engineering: A case of modelling secure information systems.. Year of

Organisation Evolution (3) Electrical Engineering Aero Engineering Mechanical Engineering Software Engineering Quality Assurance Systems Engineer Project manager Need Requirements

The Graduate School of Systems and Information Engineering comprises five doctoral and master's programs (Policy and Planning Sciences, Risk Engineering, Computer

• Technical Standards • Procedures Technical Standards Governing Policy Framework (Single Document) Governance Policy Risk Management Resource Management Identity &

It covers both technical issues such as information security, quantitative risk assessment, and assurance, and more business oriented issues such as information leadership,

Ismail, “A framework for integrated risk manage- ment process using survival analysis approach in information security,” in In- formation Assurance and Security (IAS), 2010

NIST Special Publication 800-37: This document is a guide for the security certification and accreditation of Federal Information

The core body of knowledge focuses on technical and human-centered activities including process, requirements, design, integration, verification, validation, industrial