Group Purchasing
Group Purchasing

LDR414: SANS Training Program for CISSP® Certification

LDR414Cybersecurity Leadership
  • 6 Days (Instructor-Led)
  • 51 Hours (Self-Paced)
Course authored by:
Eric ConradSeth Misenar
Eric Conrad & Seth Misenar
LDR414: SANS Training Program for CISSP® Certification
Course authored by:
Eric ConradSeth Misenar
Eric Conrad & Seth Misenar
  • GIAC Information Security Professional (GISP)
  • 51 CPEs

    Apply your credits to renew your certifications

  • In-Person, Virtual or Self-Paced

    Attend a live, instructor-led class at a location near you or remotely, or train on your time over 4 months

  • Intermediate Skill Level

    Course material is geared for cyber security professionals with hands-on experience

Accelerate your CISSP® certification journey with an intensive review course designed by leading cybersecurity practitioners to prepare you for the current 2024 version of the exam.

Course Overview

LDR414 training provides security professionals with a focused, comprehensive preparation for the 2024 CISSP® examination. As a leading CISSP training resource, the course delivers a structured breakdown of the eight security domains established by (ISC)², addressing the core knowledge requirements for certification. Students develop critical analytical skills to interpret and respond to exam questions effectively while gaining practical understanding of information security principles. The curriculum examines how security domains interconnect within enterprise environments, moving beyond theoretical concepts to operational implementation. This targeted approach equips participants with both the technical knowledge needed for certification success and the professional competencies required in high-level security positions. Organizations benefit from staff who can apply standardized security frameworks across complex infrastructures. This course also serves as preparation for the GISP certification (GIAC Information Security Professional), which maps closely to CISSP® objectives and validates foundational cybersecurity knowledge.

Comprehensive CISSP® Domain Proficiency for Certification

SANS LDR414: SANS Training Program for CISSP® Certification is an accelerated review course that is specifically designed to prepare students to successfully pass the CISSP® exam.

The course focuses solely on the 8 domains of knowledge, as determined by (ISC)2, that form a critical part of the CISSP® exam. Each domain of knowledge is dissected into its critical components, and those components are then discussed in terms of their relationship with one another and with other areas of information security.

By taking this CISSP® training course, students will have a detailed coverage of the 8 domains of knowledge, the analytical skills required to pass the CISSP® exam, the technical skills required to understand each question, and the foundational information needed to become a Certified Information Systems Security Professional (CISSP®)

External Product Notice

The CISSP® exam itself is not hosted by SANS. You will need to make separate arrangements to take the CISSP® exam. Please note as well that the GISP exam offered by GIAC is NOT the same as the CISSP® exam offered by (ISC)2.

What You'll Learn

  • Deep analysis of the 8 domains of CISSP® knowledge
  • Advanced exam question analysis and answering techniques
  • Critical information security principles with domain examples
  • Practical application of security concepts to real scenarios
  • Effective study strategies for CISSP® exam success

Business Takeaways

  • Achieve globally recognized industry-standard certification
  • Satisfy DoD 8140 IAT Level III requirements
  • Satisfy DoD 8140 IAM Levels II and III requirements
  • Satisfy DoD 8140 IASAE Level II requirements
  • Demonstrate baseline knowledge of security personnel
  • Apply security best practices to enterprise environments
  • Advance career opportunities in information security

Course Syllabus

Explore the course syllabus below to view the full range of topics covered in LDR414: SANS Training Program for CISSP® Certification.

Section 1Introduction, Security and Risk Management

In this first section, LDR414 introduces the specific requirements needed to obtain CISSP® certification. The 2024 exam update will be discussed in detail. We will cover the general security principles needed to understand the 8 domains of knowledge, with specific examples for each domain.

Topics covered

  • Introductory
  • Overview of 8 Domains
  • Domain 1: Security and Risk Management

Overview

The first of the 8 domains, Security and Risk Management, will be discussed using real-world scenarios to illustrate the critical points.

Full Topic Details

  • Introductory Material
    • Overview of the exam
    • Focus of 2024 exam updates
    • What is required to become a CISSP®?
    • Maintaining a CISSP®
    • Exam overview
    • Test-taking tips and tricks
  • Overview of the 8 Domains
    • Domain 1: Security and Risk Management
    • Domain 2: Asset Security
    • Domain 3: Security Engineering
    • Domain 4: Communication and Network Security
    • Domain 5: Identity and Access Management (IAM)
    • Domain 6: Security Assessment and Testing
    • Domain 7: Security Operations
    • Domain 8: Software Development Security
  • Domain 1: Security and Risk Management
    • Confidentiality, integrity, availability, authenticity, and non-repudiation
    • Security governance principles
    • Compliance
    • Supply Chain Risk Management (SCRM) concepts
    • Legal and regulatory Issues
    • General Data Protection Regulation (GDPR)
    • California Consumer Privacy Act
    • Personal Information Protection Law
    • Software Bill of Materials (SBOM)
    • Ethics
    • Policies, standards, procedures, and guidelines
    • Risk management concepts
    • Product tampering and counterfeits
    • Threat modeling
    • Security champions
    • Gamification
    • Security Operations Center (SOC) reports
    • Education, training, and awareness

Section 2Asset Security and Security Engineering (Part 1)

This section covers data classification across sectors, ownership roles, and secure data retention and destruction. It also introduces key topics from Security Engineering, including Data Loss Prevention (DLP), Cloud Access Security Brokers (CASB), microservices, containerization, serverless computing, and High-Performance Computing (HPC).

Topics covered

  • Domain 2: Asset Security
  • Domain 3: Security Engineering (Part 1)

Overview

This section continues the discussion of the Security Engineering domain, including a deep dive into cryptography. The focus is on real-world implementation of core cryptographic concepts, including the three types of cryptography: symmetric, asymmetric, and hashing. Quantum cryptography and fault injection will be discussed, as well as salts and rainbow tables. This domain covers new topics added to the 2024 exam, including Secure Access Service Edge (SASE). We will round out Domain 3 with a look at physical security before turning to Domain 4, Communication and Network Security. The discussion will cover a range of protocols and technologies, from the Open Systems Interconnection (OSI) model to storage area networks. Newer exam topics for the will be discussed, including micro-segmentation, Virtual eXtensible Local Area Network (VXLAN), Software-Defined Wide Area Network (SD-WAN). This domain also covers new topics added to the 2024 exam, including Infiniband, Compute Express Link, Network Functions Virtualization (NFV), virtual domains, and distributed firewalls.

Full Topic Details

  • Domain 2: Asset Security
    • Data and asset classification
    • Tangible and intangible assets
    • Data owners
    • System owners
    • Business/Mission owners
    • Privacy
    • Data processors
    • Data remanence
    • Limitation on collection of sensitive data
    • Digital Rights Management (DRM)
    • Data retention
    • Data destruction
    • Data Loss Prevention (DLP)
    • Cloud Access Security Broker (CASB)
    • Baselines
    • Scoping and Tailoring
  • Domain 3: Security Engineering (Part 1)
    • Secure design principles
    • Security models
    • Controls and countermeasures
    • Virtualization
    • Microservices
    • Containerization
    • Serverless
    • Trusted Platform Module (TPM)
    • Industrial Control Systems (ICS)
    • Embedded systems
    • Database security
    • Cloud computing
    • Secure Access Service Edge(SASE)
    • Supervisory Control and Data Acquisition (SCADA)
    • eXtensible Markup Language (XML)
    • OWASP
    • The Internet of Things

Section 3Security Engineering (Part 2): Communication and Network Security

This section covers core cryptographic concepts and physical security, including new topics like SASE and quantum cryptography. It then shifts to Communication and Network Security, focusing on protocols, devices, and emerging technologies such as VXLAN, SD-WAN, and NFV.

Topics covered

  • Domain 3: Security Engineering (Part 2)
  • Domain 4: Communication and Network Security

Overview

This section continues the discussion of the Security Engineering domain, including a deep dive into cryptography. The focus is on real-world implementation of core cryptographic concepts, including the three types of cryptography: symmetric, asymmetric, and hashing. Quantum cryptography and fault injection will be discussed, as well as salts and rainbow tables. This domain covers new topics added to the 2024 exam, including Secure Access Service Edge (SASE). We will round out Domain 3 with a look at physical security before turning to Domain 4, Communication and Network Security. The discussion will cover a range of protocols and technologies, from the Open Systems Interconnection (OSI) model to storage area networks. Newer exam topics for the will be discussed, including micro-segmentation, Virtual eXtensible Local Area Network (VXLAN), Software-Defined Wide Area Network (SD-WAN). This domain also covers new topics added to the 2024 exam, including Infiniband, Compute Express Link, Network Functions Virtualization (NFV), virtual domains, and distributed firewalls.

Full Topic Details

  • Domain 3: Security Engineering (Part 2)
    • Cryptography
      • Symmetric
      • Asymmetric
      • Hash
      • Quantum cryptography
      • Public Key Infrastructure (PKI)
      • Digital signatures
      • Non-repudiation
      • Salts
      • Rainbow tables
      • Pass the hash
      • Cryptanalysis
      • Fault injection
      • Implementation attacks
  • Facility design considerations
  • Physical security
    • Safety
    • Data center security
    • Handling evidence
    • HVAC
    • Fire prevention and suppression
  • Domain 4: Communication and Network Security
    • Network architecture
    • OSI model
    • TCP/IP
    • Multilayer protocols
    • Storage protocols
      • Network Attached Storage (NAS)
      • Fibre Channel over Ethernet (FCoE)
      • iSCSI
      • Infiniband
      • Compute Express Link (CXL)
  • Voiceover IP
  • Wireless
    • 802.11
    • WPA2 and WPA3
    • Zigbee
  • Network devices
    • Switches
    • Routers
    • Firewalls
    • Distributed Firewalls
    • Proxies
    • Content distribution networks
    • Virtual routing and forwarding
    • Virtual domain
    • Network Functions Virtualization (NFV)
    • Remote meeting technology
    • Telecommuting
    • Remote access and VPN
      • SSH
      • VPN
      • IPsec
      • SSL/TLS
  • Port isolation
  • VLANs
  • Software-defined networks
  • Micro-segmentation
  • Virtual eXtensible Local Area Network (VXLAN)
  • Software-Defined Wide Area Network (SD-WAN)

Section 4Identity and Access Management

This section focuses on secure methods of identification, authentication, and authorization. It highlights modern approaches like multi-factor authentication, federated identity, and third-party services such as SAML, OIDC, and OAuth. The section also addresses credential management and access control models like RBAC and ABAC.

Topics covered

  • Domain 5: Identity and Access Management (IAM)

Overview

Controlling access to data and systems is one of the primary objectives of information security. Domain 5, Identity and Access Management, strikes at the heart of access control by focusing on the identification, authentication, and authorization of accounts. Password-based authentication represents a continued weakness, so Domain 5 stresses multi-factor authentication, biometrics, and secure credential management. The 2024 CISSP® exam underscores the increased role of external users and service providers, and mastery of Domain 5 requires an understanding of credential management systems, federated identity, SSO, SAML, cloud identity, and third-party identity and authorization services like OpenID Connect (OIDC) and Open Authorization (Oauth).

Full Topic Details

  • Domain 5: Identity and Access Management (IAM)
    • Physical and logical access
    • Credential management systems
    • Just-In-Time (JIT)
    • SSO
    • LDAP
    • Multi-factor authentication
    • Password-less authentication
    • Biometrics
    • Accountability
    • Session management
    • SAML
    • Credential management
  • Third-party identity services
  • On-premises, cloud, and hybrid identity
  • Authorization mechanisms
    • MAC
    • DAC
    • Rule-based
    • RBAC
    • ABAC
  • Provisioning

Section 5Security Assessment and Security Operations

This section covers Domain 6 (Security Assessment) and Domain 7 (Security Operations), focusing on evaluating and maintaining security controls. It includes testing strategies, vulnerability assessments, monitoring, and incident response. The section also explores advanced topics like AI-driven tools, cloud security, and disaster recovery planning.

Topics covered

  • Domain 6: Security Assessment
  • Domain 7: Security Operations

Overview

This course section covers Domain 6 (Security Assessment) and Domain 7 (Security Operations). Security Assessment covers types of security tests, testing strategies, and security processes. Security Operations covers investigatory issues, including eDiscovery, logging and monitoring, and provisioning. We will discuss cutting-edge technologies such as cloud, and we'll wrap up day five with a deep dive into disaster recovery.

Full Topic Details

  • Domain 6: Security Assessment
    • Assessment and test strategies
    • Security control testing
      • Vulnerability assessment
      • Penetration testing
      • Log reviews
      • Synthetic transactions and benchmarks
      • Misuse case testing
      • Test coverage analysis
      • Responsible disclosure
  • Security testing strategies
    • Interface testing
    • Breach attack simulations
    • Red, blue, and purple team exercises
  • Security process
    • Account management
    • Management review
    • Training and awareness
    • Disaster recovery and business continuity
    • Exception handling
  • Internal and third-party audits
  • Domain 7: Security Operations
    • Investigations
      • Evidence collection and handling
      • Reporting and documenting
      • Forensics
  • Operational, criminal, civil, and regulatory investigations
  • eDiscovery
  • Logging and monitoring
    • Intrusion detection and prevention
    • SIEM
    • Continuous monitoring
    • Egress monitoring
    • User and Entity Behavior Analytics (UEBA)
    • Tools based on machine learning and Artificial Intelligence (AI)
  • Provisioning
    • Asset inventory
    • Configuration management
    • Physical, virtual, and cloud assets
    • Software as a Service (SaaS)
  • Security operations
    • Need-to-know and least privilege
    • Service-level agreements
    • System resilience
    • Quality of Service (QoS)
    • Threat feeds
    • Threat hunting
  • Incident management
  • Firewalls
  • IDS and IPS
  • Honeypots and honeynets
  • Vulnerability management
  • Change management processes
  • Recovery strategies
  • Disaster recovery processes
  • Disaster recovery plans

Section 6Software Development Security

This section covers Domain 8 (Software Development Security), focusing on building security into the software development lifecycle. We review traditional and modern development methodologies, secure coding practices, and emerging topics like DevSecOps, IAST, and CI/CD. We also address vulnerability management and software security testing techniques.

Topics covered

  • Domain 8: Software Development Security

Overview

The final course section examines Domain 8 (Software Development Security), which describes the requirements for secure software. Security should be "baked in" as part of network design from day one, since it is always less effective when it is added later to a poor design. We will discuss classic development models, including waterfall and spiral methodologies. We will then turn to more modern models, including agile software development methodologies. New content for the CISSP® exam update will be discussed, including DevOps. We will wrap up the course by discussing security vulnerabilities, secure coding strategies, and testing methodologies.

Full Topic Details

  • Domain 8: Software Development Security
    • Software development lifecycle
    • Software development methodologies
      • Waterfall
      • Spiral
      • Agile
      • Integrated Product Team (IPT)
  • Software capability maturity models
    • Capability Maturity Model Integration (CMMi)
    • Software Assurance Maturity Model (SAMM)
  • Change management
  • DevOps
  • DevSecOps
  • Scaled Agile Framework (SAFe)
  • Software Component/Composition Analysis (SCA)
  • Interactive Application Security Test (IAST)
  • Continuous Integration/Continuous Delivery (CI/CD)
  • Security Orchestration, Automation, and Response (SOAR)
  • Security vulnerabilities
    • Bounds checking
    • Input/output validation
    • Buffer overflow
    • Privilege escalation
  • Secure coding
  • Code repositories
  • Programming interfaces
  • Software-defined security
  • Assessing software security
    • Black box testing
    • White box testing
    • Fuzzing
  • Security of Application Programming Interfaces (APIs)

Things You Need To Know

A laptop is required to access digital course books, MP3 audio files, and practice questions. Ensure your device can connect to the internet, open PDFs, play audio files, and run a web browser for full access to the learning platform.

LDR414 training is recommended for a diverse range of individuals, including:

  • Security professionals who want to understand the concepts covered on the CISSP® exam as determined by (ISC)2.
  • Managers who want to understand the critical areas of information security.
  • System, security, and network administrators who want to understand the pragmatic applications of the CISSP® domains.
  • Security professionals and managers looking for practical ways to apply the 8 domains of knowledge to their current activities.

In short, if you desire a CISSP®, or your job requires it, LDR414 is the training for you.

  • Printed and electronic course books for each of the 8 domains
  • 320 questions to test knowledge and preparation for each domain
  • MP3 audio files of the complete course lectures
  • Unlimited access to all practice questions that never expires
  • A digital index for quick-reference to all material

The GIAC Information Security Professional (GISP) certification validates a practitioner's knowledge of the 8 domains of cybersecurity knowledge as determined by ISC2 that form a critical part of CISSP® exam. GISP certification holders will be able to demonstrate knowledge of asset security, communications and network security, identity and access management, security and risk management, security assessment and testing, security engineering, security operation, and software development security.

  • Asset Security
  • Communications and Network Security
  • Identity and Access Management
  • Security Assessment and Testing
  • Security Engineering
  • Security Operation
  • Security and Risk Management
  • Software Development Security

More Certification Details

Participants should have a basic understanding of information security concepts and terminology. While there are no strict prerequisites, familiarity with fundamental security principles will help you get the most from this course. LDR414 is designed for security professionals preparing to take the CISSP® exam.

CISSP® (Certified Information Systems Security Professional) is a globally recognized certification that validates expertise in designing, implementing, and managing an enterprise-wide cybersecurity program. It demonstrates proficiency across eight security domains and is a premier credential for senior security practitioners, managers, and executives. The LDR414™ course is CISSP training.

LDR414 training is part of the Cybersecurity Leadership curriculum. Other courses that are grouped along LDR414 as Leadership Specializations include LDR520: Emerging Trends for Cyber Leaders: AI and Cloud and LDR521: Security Culture for Leaders, among others.

Earning your CISSP® certification through LDR414 training will enhance your career by providing a globally recognized credential that validates your cybersecurity expertise. The certification satisfies DoD 8140 requirements, demonstrating your ability to design, implement, and manage enterprise security programs, which can lead to advanced positions and higher compensation in the cybersecurity field.

CISSP more than a certification—it’s a career catalyst, often required for leadership roles like CISO, Security Architect, or Risk Manager. Beyond signaling technical competence, CISSP reflects a practitioner’s commitment to ethical conduct and lifelong learning.

Relevant Job Roles

Security Manager Training, Salary, and Career Path

Cybersecurity Leadership

Daily focus is on the leadership of technical teams. Includes titles such as Manager, Information Security Specialist, and Program/Project Leader.

Explore learning path

Authorizing Official/Designated Representative (DCWF 611)

DoD 8140: Cybersecurity

Responsible for accepting system risk on behalf of the organization, ensuring acceptable security levels for mission, reputation, and operations.

Explore learning path

Course Schedule and Pricing

Have Questions?Contact Us
  • Location & instructor

    Virtual (OnDemand)

    Instructed by
    Date & Time
    OnDemand (Anytime)Self-Paced, 4 months access
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Riyadh Cyber Leaders 2026

    Riyadh, SA & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,900 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Network Security 2026

    Las Vegas, NV, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS London November 2026

    London, GB & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    £7,160 GBP*Prices exclude applicable taxes | EUR price available during checkout
    Registration Options
  • Location & instructor

    SANS Cyber Defense Initiative 2026

    Washington, DC, US & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Live Online: Jan 2027 (EDT)

    Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Amsterdam March 2027

    Amsterdam, NL & Virtual (live)

    Instructed by
    Date & Time
    Fetching schedule..
    Course price
    €8,230 EUR*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS 2027

    Orlando, FL, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANS Security West 2027

    San Diego, CA, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
  • Location & instructor

    SANSFIRE 2027

    Washington, DC, US & Virtual (live)

    Date & Time
    Fetching schedule..
    Course price
    $8,780 USD*Prices exclude applicable local taxes
    Registration Options
Showing 10 of 10

Benefits of Learning with SANS

Bryan Simon: Teacher Standing Next to Smartboard and Explaining Concept

Get feedback from the world’s best cybersecurity experts and instructors

OnDemand Mobile App

Choose how you want to learn - online, on demand, or at our live in-person training events

Close Up of Woman Holding a Pen and Documents

Get access to our range of industry-leading courses and resources