| 주제 | 소개 |
|---|
| 주제 1 | - Identity and Access Management: This section explores authentication methods and technologies, authorization and access control models, and the identity management lifecycle.
|
| 주제 2 | - Software Development Security: This section emphasizes securing the software development lifecycle, including application security testing, code review, secure coding practices, and third-party software management.
|
| 주제 3 | - Privacy Management: This section covers privacy principles and regulations, privacy impact assessments, data protection techniques, and the concepts of privacy by design.
|
| 주제 4 | - Regulatory Compliance and Legal Issues: This section addresses risk management and risk assessment methodologies, including threat modeling and vulnerability assessment. It also explores various risk mitigation strategies.
|
| 주제 5 | - Information Security Governance: This section of the exam delves into security management concepts and principles, examining organizational structures and roles in security. It also covers developing and implementing security policies, standards, and procedures.
|
| 주제 6 | - Security Assessment and Testing: This section focuses on security audit principles and methodologies, penetration testing techniques, and the use of security metrics and reporting.
|
| 주제 7 | - Security Architecture and Engineering: This section examines security models and design principles, system and application security, as well as cryptography and key management.
|
| 주제 8 | - Security Operations: In this section, the focus is on security monitoring and analytics, incident response and management, forensics and investigations, and patch and vulnerability management.
|
| 주제 9 | - Asset Security: This section focuses on information and asset classification, data security controls, privacy protection measures, and intellectual property protection.
|