<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Governance in CISSP Study Group</title>
    <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77279#M1853</link>
    <description>&lt;P&gt;I think that our friends in Exam Admin are best suited to answer this question but from my recollection, the exam can be fluid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I mean by that is the Common Body of Knowledge, outlines the areas that may be covered at a very high level and does not necessarily go down to the individual technology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1533099493"&gt;@CBMExamTeam&lt;/a&gt;&amp;nbsp;would you be kind enough to provide a more accurate description????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2025 14:41:37 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2025-02-21T14:41:37Z</dc:date>
    <item>
      <title>Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77259#M1851</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&amp;nbsp; I have a question regarding Security Governance?&lt;/P&gt;&lt;P&gt;Is the list below what's covered on the 2025 CISSP exam or some were removed or more needs to be added?&lt;/P&gt;&lt;TABLE width="165"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="165"&gt;BS 7799&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ISO-17799&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ISO-2700 Series&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;COBIT and COSO&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;OCTAVE&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;ITIL&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Thu, 20 Feb 2025 23:34:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77259#M1851</guid>
      <dc:creator>SMURF</dc:creator>
      <dc:date>2025-02-20T23:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77279#M1853</link>
      <description>&lt;P&gt;I think that our friends in Exam Admin are best suited to answer this question but from my recollection, the exam can be fluid.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What I mean by that is the Common Body of Knowledge, outlines the areas that may be covered at a very high level and does not necessarily go down to the individual technology.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1533099493"&gt;@CBMExamTeam&lt;/a&gt;&amp;nbsp;would you be kind enough to provide a more accurate description????&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:41:37 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77279#M1853</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2025-02-21T14:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77280#M1854</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1224160221"&gt;@SMURF&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/715155969"&gt;@dcontesti&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My best advice would be to refer to the CISSP Exam Outline (&lt;A href="https://edge.sitecorecloud.io/internationf173-xmc4e73-prodbc0f-9660/media/Project/ISC2/Main/Media/documents/exam-outlines/CISSP-Exam-Outline-April-2024-English.pdf" target="_blank" rel="noopener"&gt;CISSP&amp;nbsp;-&amp;nbsp;English&lt;/A&gt;&amp;nbsp;) and the current training material.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Although it will involve purchase if you don't already have it, you might also try one of our Official Study Guides&amp;nbsp;&lt;A href="https://www.isc2.org/certifications/cissp/cissp-self-study-resources#Textbooks" target="_blank"&gt;https://www.isc2.org/certifications/cissp/cissp-self-study-resources#Textbooks&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wishing you the best with your exam!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 14:59:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77280#M1854</guid>
      <dc:creator>CBMExamTeam</dc:creator>
      <dc:date>2025-02-21T14:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77289#M1857</link>
      <description>&lt;P&gt;I agree with the others that the exam objectives are the best to reference for what need to know.&amp;nbsp; It will not be granular on any framework but definitely should add NIST and COBIT when talking about frameworks.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 18:51:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77289#M1857</guid>
      <dc:creator>nkeaton</dc:creator>
      <dc:date>2025-02-21T18:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77341#M1862</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/1224160221"&gt;@SMURF&lt;/a&gt;&amp;nbsp;ISO/IEC 27001 &amp;amp; 2 supersedes both BS 7799 and ISO 17799.&lt;BR /&gt;&lt;BR /&gt;I would include NIST CSF and the RMF.&lt;BR /&gt;&lt;BR /&gt;Octave is more an IT Risk Management methodology then a security governance one.&lt;BR /&gt;&lt;BR /&gt;I don't think I've ever had to deal with COSO in my work in security &amp;amp; governance.&amp;nbsp; Anything in it I had to deal with as more incorporated into COBIT or SOC reports.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 16:03:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77341#M1862</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2025-02-24T16:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Governance</title>
      <link>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77838#M1887</link>
      <description>&lt;P&gt;Thank you !&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 18:09:54 GMT</pubDate>
      <guid>https://community.isc2.org/t5/CISSP-Study-Group/Security-Governance/m-p/77838#M1887</guid>
      <dc:creator>SMURF</dc:creator>
      <dc:date>2025-03-12T18:09:54Z</dc:date>
    </item>
  </channel>
</rss>

