From the course: CompTIA SecurityX (CAS-005) Cert Prep

Unlock this course with a free trial

Join today to access over 24,300 courses taught by industry experts.

Security program documentation

Security program documentation

- Let's begin our journey with a quote, a quote from Sun Tzu in "The Art of War." That Chinese general wrote the book centuries ago. Sun Tzu told us that tactics before strategy is the noise before defeat. One thing about Security X, a lot of it is about tactics and your technologies. That makes it a little bit different, let's say, than the CISSP, which is more about security management. So we had to begin, especially in the first domain, from a high-level governance and strategy point of view. We're going to begin with security program standards. Standards are typically mandatory security requirements that must be followed. They're specific, they're detailed. They offer clear criteria that has to be met. Standards ensure consistency and often compliance across your entire enterprise. Some common examples include ISO 27001, NIST 800-53, there's also the Cybersecurity Framework, the CSF from NIST. DOD has their CMMC, their maturity model certification. And of course SOC 2. And we'll…

Contents