{"product_id":"the-official-isc2-ccsp-cbk-reference-hardback-9781119909019","title":"The Official (ISC)2 CCSP CBK Reference (Hardback) 9781119909019","description":"\u003cfont face=\"Georgia\"\u003e\r\n\u003cp\u003e\u003cfont size=\"6\"\u003eThe Official (ISC)2 CCSP CBK Reference\u003c\/font\u003e\u003cbr\u003e\r\n\r\n\r\n\r\n\r\n\r\n\u003c\/p\u003e\n\u003cp\u003e\u003cfont size=\"4\"\u003eAaron Kraus (Author)\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e9781119909019, Wiley\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003eHardback, published 17 November 2022\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e352 pages\u003cbr\u003e23.4 x 18.8 x 2.5 cm, 0.635 kg\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\r\n\r\n\r\n\u003cp align=\"justify\"\u003e\u003cstrong\u003e\u003cfont size=\"3\"\u003e\u003cp\u003e\u003cb\u003eThe only official body of knowledge for CCSP—the most popular cloud security credential—fully revised and updated\u003c\/b\u003e. \u003c\/p\u003e\n\u003cp\u003eCertified Cloud Security Professional (CCSP) certification validates the advanced technical skills needed to design, manage, and secure data, applications, and infrastructure in the cloud. This highly sought-after global credential has been updated with revised objectives. The new third edition of \u003ci\u003eThe Official (ISC)\u003csup\u003e2\u003c\/sup\u003e Guide to the CCSP CBK \u003c\/i\u003eis the authoritative, vendor-neutral common body of knowledge for cloud security professionals.  \u003c\/p\u003e\n\u003cp\u003eThis comprehensive resource provides cloud security professionals with an indispensable working reference to each of the six CCSP domains: Cloud Concepts, Architecture and Design; Cloud Data Security; Cloud Platform and Infrastructure Security; Cloud Application Security; Cloud Security Operations; and Legal, Risk and Compliance. Detailed, in-depth chapters contain the accurate information required to prepare for and achieve CCSP certification. Every essential area of cloud security is covered, including implementation, architecture, operations, controls, and immediate and long-term responses. \u003c\/p\u003e\n\u003cp\u003eDeveloped by (ISC)\u003csup\u003e2\u003c\/sup\u003e, the world leader in professional cybersecurity certification and training, this indispensable guide: \u003c\/p\u003e\n\u003cul\u003e \u003cli\u003eCovers the six CCSP domains and over 150 detailed objectives\u003c\/li\u003e \u003cli\u003eProvides guidance on real-world best practices and techniques\u003c\/li\u003e \u003cli\u003eIncludes illustrated examples, tables, and diagrams \u003c\/li\u003e\n\u003c\/ul\u003e\n\u003cp\u003e\u003ci\u003eThe Official (ISC)\u003csup\u003e2\u003c\/sup\u003e Guide to the CCSP CBK \u003c\/i\u003eis a vital ongoing resource for IT and information security leaders responsible for applying best practices to cloud security architecture, design, operations and service orchestration.\u003c\/p\u003e\u003c\/font\u003e\u003c\/strong\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003e\u003cp\u003eForeword to the Fourth Edition xxi\u003c\/p\u003e \u003cp\u003eIntroduction xix\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 1 Cloud Concepts, Architecture, and Design 1\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eUnderstand Cloud Computing Concepts 2\u003c\/p\u003e \u003cp\u003eCloud Computing Definitions 2\u003c\/p\u003e \u003cp\u003eCloud Computing Roles and Responsibilities 3\u003c\/p\u003e \u003cp\u003eKey Cloud Computing Characteristics 7\u003c\/p\u003e \u003cp\u003eBuilding Block Technologies 11\u003c\/p\u003e \u003cp\u003eDescribe Cloud Reference Architecture 14\u003c\/p\u003e \u003cp\u003eCloud Computing Activities 14\u003c\/p\u003e \u003cp\u003eCloud Service Capabilities 15\u003c\/p\u003e \u003cp\u003eCloud Service Categories 17\u003c\/p\u003e \u003cp\u003eCloud Deployment Models 18\u003c\/p\u003e \u003cp\u003eCloud Shared Considerations 21\u003c\/p\u003e \u003cp\u003eImpact of Related Technologies 27\u003c\/p\u003e \u003cp\u003eUnderstand Security Concepts Relevant to Cloud Computing 33\u003c\/p\u003e \u003cp\u003eCryptography and Key Management 33\u003c\/p\u003e \u003cp\u003eIdentity and Access Control 34\u003c\/p\u003e \u003cp\u003eData and Media Sanitization 36\u003c\/p\u003e \u003cp\u003eNetwork Security 37\u003c\/p\u003e \u003cp\u003eVirtualization Security 39\u003c\/p\u003e \u003cp\u003eCommon Threats 41\u003c\/p\u003e \u003cp\u003eSecurity Hygiene 41\u003c\/p\u003e \u003cp\u003eUnderstand Design Principles of Secure Cloud Computing 43\u003c\/p\u003e \u003cp\u003eCloud Secure Data Lifecycle 43\u003c\/p\u003e \u003cp\u003eCloud- Based Business Continuity and Disaster Recovery Plan 44\u003c\/p\u003e \u003cp\u003eBusiness Impact Analysis 45\u003c\/p\u003e \u003cp\u003eFunctional Security Requirements 46\u003c\/p\u003e \u003cp\u003eSecurity Considerations for Different Cloud Categories 48\u003c\/p\u003e \u003cp\u003eCloud Design Patterns 49\u003c\/p\u003e \u003cp\u003eDevOps Security 51\u003c\/p\u003e \u003cp\u003eEvaluate Cloud Service Providers 51\u003c\/p\u003e \u003cp\u003eVerification against Criteria 52\u003c\/p\u003e \u003cp\u003eSystem\/Subsystem Product Certifications 54\u003c\/p\u003e \u003cp\u003eSummary 56\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 2 Cloud Data Security 57\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eDescribe Cloud Data Concepts 58\u003c\/p\u003e \u003cp\u003eCloud Data Lifecycle Phases 58\u003c\/p\u003e \u003cp\u003eData Dispersion 61\u003c\/p\u003e \u003cp\u003eData Flows 62\u003c\/p\u003e \u003cp\u003eDesign and Implement Cloud Data Storage Architectures 63\u003c\/p\u003e \u003cp\u003eStorage Types 63\u003c\/p\u003e \u003cp\u003eThreats to Storage Types 66\u003c\/p\u003e \u003cp\u003eDesign and Apply Data Security Technologies and Strategies 67\u003c\/p\u003e \u003cp\u003eEncryption and Key Management 67\u003c\/p\u003e \u003cp\u003eHashing 70\u003c\/p\u003e \u003cp\u003eData Obfuscation 71\u003c\/p\u003e \u003cp\u003eTokenization 73\u003c\/p\u003e \u003cp\u003eData Loss Prevention 74\u003c\/p\u003e \u003cp\u003eKeys, Secrets, and Certificates Management 77\u003c\/p\u003e \u003cp\u003eImplement Data Discovery 78\u003c\/p\u003e \u003cp\u003eStructured Data 79\u003c\/p\u003e \u003cp\u003eUnstructured Data 80\u003c\/p\u003e \u003cp\u003eSemi- structured Data 81\u003c\/p\u003e \u003cp\u003eData Location 82\u003c\/p\u003e \u003cp\u003eImplement Data Classification 82\u003c\/p\u003e \u003cp\u003eData Classification Policies 83\u003c\/p\u003e \u003cp\u003eMapping 85\u003c\/p\u003e \u003cp\u003eLabeling 86\u003c\/p\u003e \u003cp\u003eDesign and Implement Information Rights Management 87\u003c\/p\u003e \u003cp\u003eObjectives 88\u003c\/p\u003e \u003cp\u003eAppropriate Tools 89\u003c\/p\u003e \u003cp\u003ePlan and Implement Data Retention, Deletion, and Archiving Policies 89\u003c\/p\u003e \u003cp\u003eData Retention Policies 90\u003c\/p\u003e \u003cp\u003eData Deletion Procedures and Mechanisms 93\u003c\/p\u003e \u003cp\u003eData Archiving Procedures and Mechanisms 94\u003c\/p\u003e \u003cp\u003eLegal Hold 95\u003c\/p\u003e \u003cp\u003eDesign and Implement Auditability, Traceability, and Accountability of Data Events 96\u003c\/p\u003e \u003cp\u003eDefinition of Event Sources and Requirement of Event Attribution 97\u003c\/p\u003e \u003cp\u003eLogging, Storage, and Analysis of Data Events 99\u003c\/p\u003e \u003cp\u003eChain of Custody and Nonrepudiation 100\u003c\/p\u003e \u003cp\u003eSummary 101\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 3 Cloud Platform and Infrastructure Security 103\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eComprehend Cloud Infrastructure and Platform Components 104\u003c\/p\u003e \u003cp\u003ePhysical Environment 104\u003c\/p\u003e \u003cp\u003eNetwork and Communications 106\u003c\/p\u003e \u003cp\u003eCompute 107\u003c\/p\u003e \u003cp\u003eVirtualization 108\u003c\/p\u003e \u003cp\u003eStorage 110\u003c\/p\u003e \u003cp\u003eManagement Plane 111\u003c\/p\u003e \u003cp\u003eDesign a Secure Data Center 113\u003c\/p\u003e \u003cp\u003eLogical Design 114\u003c\/p\u003e \u003cp\u003ePhysical Design 116\u003c\/p\u003e \u003cp\u003eEnvironmental Design 117\u003c\/p\u003e \u003cp\u003eAnalyze Risks Associated with Cloud Infrastructure and Platforms 119\u003c\/p\u003e \u003cp\u003eRisk Assessment 119\u003c\/p\u003e \u003cp\u003eCloud Vulnerabilities, Threats, and Attacks 122\u003c\/p\u003e \u003cp\u003eRisk Mitigation Strategies 123\u003c\/p\u003e \u003cp\u003ePlan and Implementation of Security Controls 124\u003c\/p\u003e \u003cp\u003ePhysical and Environmental Protection 124\u003c\/p\u003e \u003cp\u003eSystem, Storage, and Communication Protection 125\u003c\/p\u003e \u003cp\u003eIdentification, Authentication, and Authorization in Cloud Environments 127\u003c\/p\u003e \u003cp\u003eAudit Mechanisms 128\u003c\/p\u003e \u003cp\u003ePlan Disaster Recovery and Business Continuity 131\u003c\/p\u003e \u003cp\u003eBusiness Continuity\/Disaster Recovery Strategy 131\u003c\/p\u003e \u003cp\u003eBusiness Requirements 132\u003c\/p\u003e \u003cp\u003eCreation, Implementation, and Testing of Plan 134\u003c\/p\u003e \u003cp\u003eSummary 138\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 4 Cloud Application Security 139\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eAdvocate Training and Awareness for Application Security 140\u003c\/p\u003e \u003cp\u003eCloud Development Basics 140\u003c\/p\u003e \u003cp\u003eCommon Pitfalls 141\u003c\/p\u003e \u003cp\u003eCommon Cloud Vulnerabilities 142\u003c\/p\u003e \u003cp\u003eDescribe the Secure Software Development Life Cycle Process 144\u003c\/p\u003e \u003cp\u003eNIST Secure Software Development Framework 145\u003c\/p\u003e \u003cp\u003eOWASP Software Assurance Maturity Model 145\u003c\/p\u003e \u003cp\u003eBusiness Requirements 145\u003c\/p\u003e \u003cp\u003ePhases and Methodologies 146\u003c\/p\u003e \u003cp\u003eApply the Secure Software Development Life Cycle 149\u003c\/p\u003e \u003cp\u003eCloud- Specific Risks 149\u003c\/p\u003e \u003cp\u003eThreat Modeling 153\u003c\/p\u003e \u003cp\u003eAvoid Common Vulnerabilities during Development 156\u003c\/p\u003e \u003cp\u003eSecure Coding 156\u003c\/p\u003e \u003cp\u003eSoftware Configuration Management and Versioning 157\u003c\/p\u003e \u003cp\u003eApply Cloud Software Assurance and Validation 158\u003c\/p\u003e \u003cp\u003eFunctional and Non- functional Testing 159\u003c\/p\u003e \u003cp\u003eSecurity Testing Methodologies 160\u003c\/p\u003e \u003cp\u003eQuality Assurance 164\u003c\/p\u003e \u003cp\u003eAbuse Case Testing 164\u003c\/p\u003e \u003cp\u003eUse Verified Secure Software 165\u003c\/p\u003e \u003cp\u003eSecuring Application Programming Interfaces 165\u003c\/p\u003e \u003cp\u003eSupply- Chain Management 166\u003c\/p\u003e \u003cp\u003eThird- Party Software Management 166\u003c\/p\u003e \u003cp\u003eValidated Open- Source Software 167\u003c\/p\u003e \u003cp\u003eComprehend the Specifics of Cloud Application Architecture 168\u003c\/p\u003e \u003cp\u003eSupplemental Security Components 169\u003c\/p\u003e \u003cp\u003eCryptography 171\u003c\/p\u003e \u003cp\u003eSandboxing 172\u003c\/p\u003e \u003cp\u003eApplication Virtualization and Orchestration 173\u003c\/p\u003e \u003cp\u003eDesign Appropriate Identity and Access Management Solutions 174\u003c\/p\u003e \u003cp\u003eFederated Identity 175\u003c\/p\u003e \u003cp\u003eIdentity Providers 175\u003c\/p\u003e \u003cp\u003eSingle Sign- on 176\u003c\/p\u003e \u003cp\u003eMultifactor Authentication 176\u003c\/p\u003e \u003cp\u003eCloud Access Security Broker 178\u003c\/p\u003e \u003cp\u003eSummary 179\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 5 Cloud Security Operations 181\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eBuild and Implement Physical and Logical Infrastructure for Cloud Environment 182\u003c\/p\u003e \u003cp\u003eHardware- Specific Security Configuration Requirements 182\u003c\/p\u003e \u003cp\u003eInstallation and Configuration of Virtualization Management Tools 185\u003c\/p\u003e \u003cp\u003eVirtual Hardware–Specific Security Configuration Requirements 186\u003c\/p\u003e \u003cp\u003eInstallation of Guest Operating System Virtualization Toolsets 188\u003c\/p\u003e \u003cp\u003eOperate Physical and Logical Infrastructure for Cloud Environment 188\u003c\/p\u003e \u003cp\u003eConfigure Access Control for Local and Remote Access 188\u003c\/p\u003e \u003cp\u003eSecure Network Configuration 190\u003c\/p\u003e \u003cp\u003eOperating System Hardening through the Application of Baselines 195\u003c\/p\u003e \u003cp\u003eAvailability of Stand- Alone Hosts 196\u003c\/p\u003e \u003cp\u003eAvailability of Clustered Hosts 197\u003c\/p\u003e \u003cp\u003eAvailability of Guest Operating Systems 199\u003c\/p\u003e \u003cp\u003eManage Physical and Logical Infrastructure for Cloud Environment 200\u003c\/p\u003e \u003cp\u003eAccess Controls for Remote Access 201\u003c\/p\u003e \u003cp\u003eOperating System Baseline Compliance Monitoring and Remediation 202\u003c\/p\u003e \u003cp\u003ePatch Management 203\u003c\/p\u003e \u003cp\u003ePerformance and Capacity Monitoring 205\u003c\/p\u003e \u003cp\u003eHardware Monitoring 206\u003c\/p\u003e \u003cp\u003eConfiguration of Host and Guest Operating System Backup and Restore Functions 207\u003c\/p\u003e \u003cp\u003eNetwork Security Controls 208\u003c\/p\u003e \u003cp\u003eManagement Plane 212\u003c\/p\u003e \u003cp\u003eImplement Operational Controls and Standards 212\u003c\/p\u003e \u003cp\u003eChange Management 213\u003c\/p\u003e \u003cp\u003eContinuity Management 214\u003c\/p\u003e \u003cp\u003eInformation Security Management 216\u003c\/p\u003e \u003cp\u003eContinual Service Improvement Management 217\u003c\/p\u003e \u003cp\u003eIncident Management 218\u003c\/p\u003e \u003cp\u003eProblem Management 221\u003c\/p\u003e \u003cp\u003eRelease Management 221\u003c\/p\u003e \u003cp\u003eDeployment Management 222\u003c\/p\u003e \u003cp\u003eConfiguration Management 224\u003c\/p\u003e \u003cp\u003eService Level Management 225\u003c\/p\u003e \u003cp\u003eAvailability Management 226\u003c\/p\u003e \u003cp\u003eCapacity Management 227\u003c\/p\u003e \u003cp\u003eSupport Digital Forensics 228\u003c\/p\u003e \u003cp\u003eForensic Data Collection Methodologies 228\u003c\/p\u003e \u003cp\u003eEvidence Management 230\u003c\/p\u003e \u003cp\u003eCollect, Acquire, and Preserve Digital Evidence 231\u003c\/p\u003e \u003cp\u003eManage Communication with Relevant Parties 234\u003c\/p\u003e \u003cp\u003eVendors 235\u003c\/p\u003e \u003cp\u003eCustomers 236\u003c\/p\u003e \u003cp\u003ePartners 238\u003c\/p\u003e \u003cp\u003eRegulators 238\u003c\/p\u003e \u003cp\u003eOther Stakeholders 239\u003c\/p\u003e \u003cp\u003eManage Security Operations 239\u003c\/p\u003e \u003cp\u003eSecurity Operations Center 240\u003c\/p\u003e \u003cp\u003eMonitoring of Security Controls 244\u003c\/p\u003e \u003cp\u003eLog Capture and Analysis 245\u003c\/p\u003e \u003cp\u003eIncident Management 248\u003c\/p\u003e \u003cp\u003eSummary 253\u003c\/p\u003e \u003cp\u003e\u003cb\u003eChapter 6 Legal, Risk, and Compliance 255\u003c\/b\u003e\u003c\/p\u003e \u003cp\u003eArticulating Legal Requirements and Unique Risks within the Cloud Environment 256\u003c\/p\u003e \u003cp\u003eConflicting International Legislation 256\u003c\/p\u003e \u003cp\u003eEvaluation of Legal Risks Specific to Cloud Computing 258\u003c\/p\u003e \u003cp\u003eLegal Frameworks and Guidelines 258\u003c\/p\u003e \u003cp\u003eeDiscovery 265\u003c\/p\u003e \u003cp\u003eForensics Requirements 267\u003c\/p\u003e \u003cp\u003eUnderstand Privacy Issues 267\u003c\/p\u003e \u003cp\u003eDifference between Contractual and Regulated Private Data 268\u003c\/p\u003e \u003cp\u003eCountry- Specific Legislation Related to Private Data 272\u003c\/p\u003e \u003cp\u003eJurisdictional Differences in Data Privacy 277\u003c\/p\u003e \u003cp\u003eStandard Privacy Requirements 278\u003c\/p\u003e \u003cp\u003ePrivacy Impact Assessments 280\u003c\/p\u003e \u003cp\u003eUnderstanding Audit Process, Methodologies, and Required Adaptations for a Cloud Environment 281\u003c\/p\u003e \u003cp\u003eInternal and External Audit Controls 282\u003c\/p\u003e \u003cp\u003eImpact of Audit Requirements 283\u003c\/p\u003e \u003cp\u003eIdentify Assurance Challenges of Virtualization and Cloud 284\u003c\/p\u003e \u003cp\u003eTypes of Audit Reports 285\u003c\/p\u003e \u003cp\u003eRestrictions of Audit Scope Statements 288\u003c\/p\u003e \u003cp\u003eGap Analysis 289\u003c\/p\u003e \u003cp\u003eAudit Planning 290\u003c\/p\u003e \u003cp\u003eInternal Information Security Management System 291\u003c\/p\u003e \u003cp\u003eInternal Information Security Controls System 292\u003c\/p\u003e \u003cp\u003ePolicies 293\u003c\/p\u003e \u003cp\u003eIdentification and Involvement of Relevant Stakeholders 296\u003c\/p\u003e \u003cp\u003eSpecialized Compliance Requirements for Highly Regulated Industries 297\u003c\/p\u003e \u003cp\u003eImpact of Distributed Information Technology Model 298\u003c\/p\u003e \u003cp\u003eUnderstand Implications of Cloud to Enterprise Risk Management 299\u003c\/p\u003e \u003cp\u003eAssess Providers Risk Management Programs 300\u003c\/p\u003e \u003cp\u003eDifferences between Data Owner\/Controller vs. Data Custodian\/Processor 301\u003c\/p\u003e \u003cp\u003eRegulatory Transparency Requirements 302\u003c\/p\u003e \u003cp\u003eRisk Treatment 303\u003c\/p\u003e \u003cp\u003eRisk Frameworks 304\u003c\/p\u003e \u003cp\u003eMetrics for Risk Management 307\u003c\/p\u003e \u003cp\u003eAssessment of Risk Environment 307\u003c\/p\u003e \u003cp\u003eUnderstand Outsourcing and Cloud Contract Design 309\u003c\/p\u003e \u003cp\u003eBusiness Requirements 309\u003c\/p\u003e \u003cp\u003eVendor Management 311\u003c\/p\u003e \u003cp\u003eContract Management 312\u003c\/p\u003e \u003cp\u003eSupply Chain Management 314\u003c\/p\u003e \u003cp\u003eSummary 316\u003c\/p\u003e \u003cp\u003eIndex 317\u003c\/p\u003e\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\u003cp\u003e\u003cfont size=\"3\"\u003eSubject Areas: Education [\u003ca title=\"See our other books on Education\" href=\"https:\/\/freshlyprintedbooks.co.uk\/search?q=%22Education%20%5BJN%5D%22\"\u003eJN\u003c\/a\u003e]\u003c\/font\u003e\u003c\/p\u003e\r\n\r\n\r\n\u003c\/font\u003e","brand":"Sybex","offers":[{"title":"Brand New","offer_id":52458472505624,"sku":"9781119909019","price":43.49,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0730\/2037\/5320\/files\/9781119909019.jpg?v=1785373794","url":"https:\/\/freshlyprintedbooks.co.uk\/products\/the-official-isc2-ccsp-cbk-reference-hardback-9781119909019","provider":"Freshly Printed Books","version":"1.0","type":"link"}