Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISC2 · Exam prep
Exam-prep training that counts toward CCSP renewal — boot camps, practice review sessions, and structured study tracks aimed at people preparing for the cert itself or a follow-on credential. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 90 CPEs CCSP requires every 3 years — without re-keying each entry into ISC2's portal.
77 results mapped to CCSP, soonest first.
To understand where you’re going, you must first know where you are. But in the world of cloud-native security, where technologies and best practices seem to change by the month, finding your baseline can sometimes feel impossible—let alone benchmarking your peers. To help organizations find their way, the team at Prisma Cloud has put together the second annual State of Cloud-Native Security report, a survey of 3,000 professionals across five countries that helps answer the question What’s happening in cloud-native security today, and what are successful organizations doing right. On January 25, 2022, at 1:00 p.m. Eastern/10:00 a.m. Pacific join Palo Alto Networks, Prisma Cloud, and (ISC)², as we reveal for the first time the trends that are driving the world’s most successful cloud security programs, analyze the best practices that help leading enterprises excel, and demystify the evolving cloud security landscape.
As multi-cloud adoption accelerates, security teams are navigating the delta between each cloud provider’s native capabilities and comprehensive protection from bad actors. Understanding cloud terminology, principles, and security issues is critical. Join (ISC)² and Sysdig March, 29, 1:00 p.m., Eastern/10:00 a.m. Pacific to understand the fundamentals on cloud categories and terms like CSPM (Cloud Security Posture Management), CWPP (Cloud Workload Protection Platform), CNAPP (Cloud-Native Application Protection Platform), etc. so you can move past the acronyms and onto implementing them as best practices. In this session we will: • Debunk new industry acronyms and explain how they fit into your overall cloud security strategy • Explain why native cloud provider tools aren’t always sufficient • Provide CSPM best practices: Detecting misconfigurations, excessive permissions and suspicious activity • Showcase how open-source Falco can be used to detect cloud threats in real-time
This session will focus on methods for security teams to better monitor and secure hybrid cloud environments while logging compliance data. Learn best practices to analyze, prioritize, and investigate security alerts within cloud resources faster and more accurately through a variety of cloud-agnostic security strategies while reducing downtime and security incidents. On July 28, 2022 at 1:00 p.m. Eastern/10:00 am. Pacific Sumo Logic and (ISC)² will: • Discuss business motivations for cloud migration. • Identify common challenges while monitoring applications throughout the migration. • Explore solutions for typical security operations constraints during the migration.
Clar Rosso, CEO of (ISC)2 shares the latest insights on what’s happening at our association. Join us for this quarterly update where we cover the latest developments at (ISC)2, ranging from certification to member benefits, continuing education and events, to major milestones and achievements. Joining Clar this quarter is Dr. Casey Marks, chief product officer and VP of (ISC)2, to discuss the latest in Exams and certifications.
The advantages offered by a cloud-based environment makes it an easy decision for most companies to have apps and data both on-premises and in the cloud. Still, there are numerous critical choices to be made that can transform the complexities of the migration process into a relatively smooth transition—especially regarding application and data security. Join Imperva and (ISC)2 on April 5, 2018 at 1:00PM Eastern as we define the hybrid cloud and talk about best practices to secure your company assets as you start managing and securing them both on-premises and in the cloud.
Over the past year, CrowdStrike’s OverWatch Threat Hunting team has been seeing an increase in adversarial discovery activities around cloud due to rapid adoption of cloud services. As more companies are born in the cloud - Digital Native Businesses - and move to the cloud, ensuring visibility and security has never been more important. CrowdStrike and AWS have a strong history and partnership in delivering state-of-the-art secure cloud computing. Whether organisations move or are born in the cloud, CrowdStrike can help customers achieve visibility across their entire AWS footprint, while securing workloads and leveraging automation best practices for scale, consistency, compliance and speed. Join CrowdStrike CTO, Fabio Fratucello, and AWS Head of Security, Bryce Boland, as they discuss how simplicity and visibility into an organisation’s cloud workload is critical to building a robust cloud security strategy. You’ll also hear from SafetyCulture’s CTO on how this fast growing “unicorn” is achieving scalability and security with CrowdStrike and AWS. Moderated by Global Strategist on Inter-generational Leadership, Holly Ransom, this webinar will dissect the various approaches to cloud security and show you how easily you can achieve full control and visibility, delivered by two global leaders whose success is underpinned by their desire to delight the customer. Join this session to learn how to: - Achieve security and visibility into your cloud footprint from launch - Integrate workload events and alerts with AWS services to reduce response time - Automate response capabilities and integrate with existing workflows to optimise your security posture
How an integrated defense-in-depth platform fills gaps in inconsistencies, misconfigurations and visibility More than ever, organisations are grappling with how to secure cloud-native applications. Composed of a combination of containers, virtual machines, APIs and serverless functions, protecting these applications from development to runtime requires reworking the approach many organisations take toward security. In a new survey from CrowdStrike and Enterprise Strategy Group (ESG), 88% of respondents said their cybersecurity program needs to evolve to secure their cloud-native applications and use of public cloud infrastructure, with many citing challenges around maintaining visibility and consistency across disparate environments. Join CrowdStrike’s Cloud Security Product Marketing Leader David Puzas and Zeki Turedi, CrowdStrike's EMEA CTO as they examine the cloud-native threat landscape and the need for an integrated defense-in-depth strategy. Learn about: - Cloud-native security challenges - How maturity gaps result in inconsistency, misconfigurations and visibility gaps
SIEM systems are pivotal to IT organization’s security operations. Many companies are adopting a hybrid cloud model, and cloud-based SIEMs are becoming common as a result. Regardless of on-prem or cloud deployments, the challenges around SIEM remain the same, from data overload, lack of contextual information, to high costs. Security best practices in deploying SIEMs also remain unchanged, which include establishment of use cases, data ingestion types and development of parsers for various tool vendors. On March 9, 2021 at 1:00pm Eastern, Gigamon and (ISC)2 will present a webinar that will cover solutions to these challenges such as Gigamon’s Application Metadata Intelligence as well as various smart filtering techniques.
As workforces look to remain remote for the long term, the cloud has become ubiquitous. Yet human security professionals relying only on conventional security tools continue to struggle to secure the complexity of today’s hybrid and multi-cloud topologies - in fact, only 22% of organizations feel they have adequate visibility into their cloud applications and infrastructure. Join Darktrace and (ISC)2 on October 22, 2020 at 1:00 p.m. Eastern for a an examination of businesses as they increasingly turn to AI as a uniquely dynamic solution to detect and defend from novel threats that emerge on cloud and SaaS environments – which the global workforce continues to rely on in today’s remote working landscape. The webcast will also explore: · Exploration of the latest cloud and SaaS real-world threat trends · How Darktrace’s groundbreaking AI Immune System technology keeps pace with the dynamic workforce · Case studies and unique threat finds from industry leading customers
The 2021 Cloud Security Report, sponsored by (ISC)2, explores current cloud security trends and challenges, how organizations are responding to security threats in the cloud and reveals tools and best practices organizations are considering. Based on a comprehensive survey of 783 cybersecurity professionals conducted in early 2021 to uncover how cloud user organizations are responding to security threats in the cloud, and what training, certifications and best practices IT cybersecurity leaders are prioritizing in their move to the cloud. Join (ISC)2 on July 21, 2021 at 1:00PM Eastern for highlights of the results and to get key insights including: •A majority of cybersecurity professionals (96%) confirm they are at least moderately concerned about public cloud security, a small increase from last year’s survey. •For the second year in a row, the key barrier to cloud adoption, organizations mention was a lack of qualified staff (39%) as the biggest impediment to faster adoption. •More than half of organizations (57%) expect their cloud budgets to increase over the next 12 months. •When asked how organizations rate their overall security readiness, 73% rate their team’s security readiness average or below average. Of those, 78% believe their teams would benefit from cloud security training and/or certification.
An overall explosion in cryptographic dependencies has given way to an urgent need for enterprises to define their crypto strategies and gain visibility into the many new cryptographic instances that are hidden across their IT environment. As enterprises adopt new IT practices such as DevOps, Internet of Things (IoT), cloud and multi-cloud environments, their cryptographic footprint expands exponentially increasing the risk for business disruption and security threats. This presents an urgent need for enterprises to define new strategies for both crypto and PKI environments in order to balance that risk. A Cryptographic Center of Excellences (CryptoCOE) prepares security, compliance and risk teams for crypto agility and methods for mitigating crypto related threats. Join this session as we discuss important insights on how to protect your digital business with strong digital trust protocols that support the expanding use cases for cryptographical instance.
Today’s network environment can feel like a Cold War-era novel, full of who’s watching whom scenarios and heavily protected intelligence communications. Visibility is critical to an organization’s security posture, and encrypted channel communications can become an obstacle to it when gets to the wrong eyes. Decryption can illuminate what is hidden and restores the advantage you need to see what’s lurking in the shadows. Join Gigamon and (ISC)2 on September 5, 2019 at 1PM Eastern for an examination of decryption best practices, a review of encryption methodologies, the obstacles that impact security, resources and regulatory compliance and what’s changed with TLS 1.3 and how this newer protocol impacts visibility.
Cloud adoption is exploding with nearly 1,300 cloud apps in use in an average enterprise. From suites like Office 365 to collaboration tools like Slack, the cloud has enabled new levels of productivity resulting in enterprises gaining strategic advantages. Enterprises are not the only ones benefitting from cloud adoption. Bad actors are using the cloud to bypass legacy defense mechanisms and harvest credentials, deliver malicious payloads, and steal data. In this webcast, we’ll examine a few recent cloud data breaches and dissect how these breaches occurred and best practices to reduce the chance it will happen to your organization. We will dive into new attack scenarios that involve using the cloud to bypass traditional security tools, how the cloud-enabled kill chain forces a rethinking of how to defend against threats such as phishing and data exfiltration and 5 steps to protect against cloud threats.
With the move to cloud and the multitude of approaches, your ability to effectively monitor and secure workloads gets even more difficult. IT complexity, the rate of change, lack of skills, and organizational silos have made confidently managing security and performance nearly impossible. Visibility is critical. Join Gigamon and (ISC)2 on February 25, 2021 at 1:00pm Eastern for a discussion of the security considerations for on-prem private, public and hybrid clouds. You’ll learn best practices and see how a little planning and design can go a long way. Achieve a secure and viable hybrid cloud implementation and get a high return on your investment. Join our session to learn how.
Organizations are increasingly adopting a cloud-first approach or migrating to the cloud but need to ensure that their environments are secure without losing the core benefit of faster application development and release. In order to keep up with business agility, operational efficiencies can be achieved by automating the deployment of security solutions into AWS environments, and help reduce the mean time for response and remediation. Join us to learn how CrowdStrike can help you achieve visibility across your entire AWS footprint, while securing your workloads and leveraging automation best practices for scale, consistency and speed. This session is presented by Justin Harris, Senior SA, Global Solution Architecture, CrowdStrike & Jaime Franklin, Director of Global Solution Architecture, CrowdStrike
As IT complexity increases at organizations, gaining visibility into a comprehensive asset inventory becomes progressively difficult for information security teams. The convergence of three trends account for this new era of complexity: the increase in the number and types of devices, rapid public cloud adoption, and the looming IoT explosion. Axonius commissioned a research survey with Enterprise Strategy Group (ESG) to uncover what kinds of visibility gaps, challenges, and strategies are top of mind for information security professionals. Join Axonius and (ISC)2 on April 23, 2020 at 1:00PM Eastern for the second of three webinars that will focus on rapid cloud adoption. We have surpassed the Cloud Tipping Point with more than half of all virtual machines (VMs) residing in the cloud and container usage becoming mainstream. Organizations are struggling to solve cloud asset visibility challenges and the resulting security incidents as expected growth adds further complexity. We’ll examine · Detailed research findings on cloud adoption, visibility challenges, and security implications · An understanding of the key asset inventory challenges and how organizations are addressing these issues · Best practices when implementing and improving an asset inventory process · Emerging innovations and approaches to continuous asset discovery and automation
During 2020, the worldwide shift to remote work led to a staggering rise in cybercrime, as criminals targeted gaps in previously secure on-site networks. With over 50% of employers expecting to keep employees working remotely, and payments for a ransomware attacks averaging $100,000, businesses must work proactively to protect their data. It is essential for business to have an effective plan in place to protect at-risk systems, detect and mitigate ransomware attacks in real time, and quickly restore affected systems. Join Synology and (ISC)2 on September 28, 2021 at 1:00 p.m. Eastern/10:00 a.m. as we discuss actionable strategies for ransomware preparedness and look at real-world examples and case studies. Key takeaways include: Actionable ransomware preparedness tips Protecting PC data and the elements of a robust ransomware recovery plan Why and how to backup Microsoft 365 & Google Workspace data Setting up remote backup to a secondary server or cloud
Security teams face increasing challenges from lack of visibility, complex solutions and sophisticated attacks. CrowdStrike can help organizations achieve visibility across their entire AWS footprint, while securing their workloads and leveraging automation best practices for scale, consistency and speed. Key Takeaways: - How CrowdStrike integrations with AWS solutions can help organizations - Where CrowdStrike and AWS work together - The Shared Responsibility Model - Resources to get started with CrowdStrike and AWS today
Does your organization rely heavily on SaaS solutions like Microsoft 365 and Google Workspace? That critical data may be at more risk than you realize. There are hidden risks with compliance issues associated with SaaS solutions and other concerns. Join Synology and (ISC)2 on January 20, 2022 at 1:00 p.m. Eastern as we examine the importance of Cloud backup and the practical strategies that can protect your organization from detrimental data loss. Additionally, we will discuss real-life case studies that exemplify the importance of SaaS backup and walk through the elements of their backup strategies that made them so successful.
With the increased adoption of cloud across nearly every industry, security teams must do more with less and adapt to new infrastructure technologies and threats. Add to that, the growth in organisations moving to DevOps to accelerate app deployment, many security teams have chosen to take a “shift left” approach to improving the security posture of applications throughout the CI/CD pipeline. In theory it means shifting responsibility for security and compliance to developers. In practice, it means enriching CI/CD processes to detect threats and vulnerabilities before they reach production. Although these improvements have improved protection of apps, security is still too often overlooked and addressed only at runtime. Join this webinar roundtable to see how you can incorporate comprehensive security throughout your entire CI/CD pipeline. You’ll hear from industry experts as they discuss - How security teams can enable DevOps teams with the tools needed to add security into the CI/CD pipeline. - The benefits of scanning IaC templates (Terraform® and AWS CloudFormation™) - How to improve the security posture of cloud native apps through continuous CI/CD security including container images and registries in the build-and-deploy phase. - And how to best instill a culture of DevSecOps
Before the rise of cloud computing, enterprises could expect to be responsible for securing the systems in their data centers, their applications — everything. Because of the complexities of the threat landscape and organizational environments, security and DevSecOps teams have struggled to stay ahead. Today, more and more organizations are migrating systems in part or wholly to the cloud, and cloud service providers are ready, willing and able to ease the security burden through the shared responsibility model. We welcome you to come learn the best practices for securing your cloud in this CrowdCast with CrowdStrike and AWS. Attend this webcast to: • Understand the composition of cloud environments and the technologies that are driving adoption • Take a deep dive into the challenges of moving to the cloud and having a cloud infrastructure • Learn key best practices to secure your organization’s public cloud platforms • Find out how automation of DevSecOps processes and controls can help keep pace with the security you need
As organizations move more workloads to the cloud, security teams need to adapt their workflows to keep up. On August 11, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific IANS and (ISC)2 discuss: • Best practices for securing containers, serverless and SaaS/PaaS/IaaS applications • How best to insert security into the software development life-cycle • How to ensure every app in production is as secure as it can be
As organizations migrate more services and applications to the cloud, adversaries have shifted their focus to exploit a broader attack surface. From vulnerability exploitation to credential theft, attackers are going after any weak points that allow them to compromise the ever-growing amount of critical business data and applications hosted in the cloud. We will share insights into today’s top cloud security threats and cloud vulnerabilities, along with best practices to address them. Join the workshop to learn: • The top cloud security threats in 2022 • The main cloud security adversaries • The most targeted cloud vulnerabilities • What you can do to ensure effective cloud security Speakers: • David Puzas (Sr. Product Marketing Manager, Cloud Security), • Scott Fanning (Sr Director, Product Management), • Joshua Shapiro (Sr. Manager, Strategic Threat Advisory Group)
As organizations migrate more services and applications to the cloud, adversaries have shifted their focus to exploit a broader attack surface. From vulnerability exploitation to credential theft, attackers are going after any weak points that allow them to compromise the ever-growing amount of critical business data and applications hosted in the cloud. We will share insights into today’s top cloud security threats and cloud vulnerabilities, along with best practices to address them. Join the workshop to learn: • The top cloud security threats in 2022 • The main cloud security adversaries • The most targeted cloud vulnerabilities • What you can do to ensure effective cloud security Speakers: • David Puzas (Sr. Product Marketing Manager, Cloud Security), • Scott Fanning (Sr Director, Product Management), • Joshua Shapiro (Sr. Manager, Strategic Threat Advisory Group)
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.