Welcome to RecertHero!
Submit bugs, feature requests, and feedbackISC2 · Free
Free continuing-education opportunities that count toward CISSP-ISSAP renewal — vendor webinars, community talks, and free courses. RecertHero estimates the CPE value of every opportunity, so you can plan toward the 60 CPEs CISSP-ISSAP requires every 3 years — without re-keying each entry into ISC2's portal.
35 results mapped to CISSP-ISSAP, soonest first.
It’s now or never to modernize security. Our networks can no longer stretch to the apps living in the cloud and teams working remotely, plus cyber threats routinely exploiting the excessive trust built into them. Network transformation projects are always daunting – especially when you can never know exactly what your business will need tomorrow. New risks to mitigate, standards to comply with, and use cases to scale will inevitably emerge. Join (ISC)² and Cloudflare April 20, 2022 at 2:00 p.m. Eastern, 11 a.m. Pacific to hear Cloudflare Field Technologist, Trey Guinn share perspectives on how to both fast-track and future-proof your security approach. He has seen organizations commit to network and security architectures that were complex and costly to keep changing to adapt to future needs. Trey will advise us on the most important principles to evaluate new technology platforms with confidence that it’ll enable your organization to evolve and innovate faster than ever before. In this webinar you’ll also hear about: • The most pressing business and IT drivers of digital transformation • The emergence of the Internet as the new corporate network • The key criteria to evaluate Zero Trust security and SASE networking investments
Recently, we saw the disastrous effects of numerous far-reaching supply chain breaches and third-party code vulnerabilities, including SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. Unfortunately, we can expect to see more of the same in 2022 and beyond. When we consider these latest cyber events, it’s important to prepare—with the right people, processes, and tools—for what’s unquestionably yet to come. This is why every organization must be sure to have a robust third-party security risk strategy in place. Join Panorays Co-Founder and CTO, Demi Ben-Ari as he shares tips on how to best reduce supply chain risk and contain attacks. Plus he’ll discuss: 1. Why supply chain security is critically important right now 2. What actually happened with SolarWinds, Kaseya, Log4shell, Okta and Spring4Shell. 3. How to take action when a supply chain attack happens, and how to minimize the blast radius.
No doubt, you’ve heard the buzz about zero trust. Zero trust isn’t a product but rather a journey. While the end goal is worthwhile, like most things in security, getting there won’t be fast or easy. In this live session, June 28, 2022 at 1:00 p.m Eastern/10:00 a.m. Pacific IANS Faculty and (ISC)² discuss: • Exactly what a strong zero trust architecture requires • Concrete steps to take and products to consider to that help keep you moving on the right path • Ways to measure progress, set realistic milestones and ensure goals are obtainable
Palo Alto Networks Unit 42 cloud threat researchers wanted to understand how supply chain attacks occur in the cloud native applications. To gain insight into this growing threat, they analyzed data from a variety of public data sources around the world. Additionally, they executed a red team exercise at the request of a large SaaS provider against their cloud-based software development environment. Unit 42’s findings indicate that many organizations are still have a long way to go in achieving supply chain security in the cloud. Join Palo Alto Network and (ISC)2 on November 16, 2021 at 1:00p.m. Eastern for the Unit 42 Cloud Threat Report and how supply chain attacks in the cloud can occur and provide actionable recommendations organizations can adopt to protect their cloud native supply chains.
With the move to cloud and the multitude of approaches, your ability to effectively monitor and secure workloads gets even more difficult. IT complexity, the rate of change, lack of skills, and organizational silos have made confidently managing security and performance nearly impossible. Visibility is critical. Join Gigamon and (ISC)2 on February 25, 2021 at 1:00pm Eastern for a discussion of the security considerations for on-prem private, public and hybrid clouds. You’ll learn best practices and see how a little planning and design can go a long way. Achieve a secure and viable hybrid cloud implementation and get a high return on your investment. Join our session to learn how.
Cryptography is omnipresent. Every business unit uses crypto in some shape or form. A marketing web page uses a TLS certificate to assert its identity. A CRM solution that stores customer data uses symmetric key cryptography to encrypt data at rest. An organization's digital security is only as strong as its business units' weakest crypto practices. This has forced organizations to rethink the way teams consume crypto services and driven the need for centralized orchestration and control. Join AppviewX and (ISC)2 on May 6, 2021, at 1:00 PM Eastern Time for a discussion on how a Crypto Service Mesh orchestrates all the diverse crypto services in an organization, abstracts the nitty-gritty details, and provides a standardized, user-friendly, policy-controlled way for different business units to consume these services. We’ll examine: · How various business units consume crypto today · An introduction to Crypto Service Mesh · How a Crypto Service Mesh weaves together people, process, and technology
Zero Trust has generated a great deal of “buzz” in the last few years. Many solution providers tout the benefits of Zero Trust, but the approach may not be a fit for you and your organization. Join iboss and (ISC)2 on May 4, 2021 at 1:00PM Eastern as we explore the evolution of network security design principles in order to gain a deeper understanding of how technology can be leveraged to meet evolving user needs and the behavioral and technological direction behind SASE and Zero Trust.
72% of enterprises are actively prioritizing zero trust. Unfortunately, many companies still rely on traditional castle-and-moat network infrastructure. Deploying zero trust with legacy parts is a daunting task. The cloud-first world requires a fundamentally different approach to zero trust which is decoupled from the underlying network, allowing a direct, fast, and secure connection from users to applications regardless of location. Join us for this live replay session as Zscaler and (ISC)² discuss: - Identifying clear signs that your firewalls are unfit for zero trust - Making your case to break free from legacy approaches and adopt zero trust - Learning how Zscaler Cloud-gen firewall can help you get there faster
“How can we implement a zero trust strategy?” is a question asked by nearly every security team that wants to avoid increasing their attack surface and being the victim of a high-profile breach. A zero trust strategy is rooted in the principle of “never trust, always verify” — which minimizes risk by securing sensitive data, systems, and services. However, all too often security teams discover that they don't have the visibility they need to do this. The first step to implementing a zero trust strategy and achieving exceptional security hygiene? Building and maintaining an inventory of your critical assets. Please join Axonius and (ISC)² on August 23 at 1:00pm Eastern/10:00 a.m. Pacific as we share how teams can approach zero trust principles and how keeping an asset inventory can help answer the toughest zero trust questions: What device is trying to access corporate assets? What vulnerabilities exist on my applications and services? Which users have access to critical resources? Is my zero trust application managed or unmanaged?
Applying zero trust architectures in an iterative way – one project at a time – has proven a sustainable method to deepen zero trust capabilities across a program. On September 20, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific, IANS and (ISC)² discuss specific zero trust use cases to help accelerate your organization’s zero trust maturation, including: • Walking through zero trust use cases within various domains: people, devices, applications • Discussing the available tooling options and considerations necessary to implement the use case • Words of caution and recommendations to help your organization advance in its zero trust journey
Never Trust, Always Verify. Cloud workloads are constantly evolving and changing. Third-party providers operate outside of company networks. With data in various places, companies can't keep up with who and what have access, and they don't know how critical data might be being exploited. Now you can take an evolutionary step in security with a Zero Trust framework that eliminates implied trust with continuous validation at every stage of a digital interaction, enables developer teams to modernize applications with cloud native development, allows security teams to strengthen defenses across the application lifecycle. On September 28, 2022 at 1:00 p.m. Eastern / 10:00 a.m. Pacific, join Palo Alto Networks and (ISC)² to learn how you can apply an enterprise-wide Zero Trust strategy with integrated capabilities for complete cloud native application protection in your organization. You’ll also find out why organizations that tightly integrate DevSecOps principles into their development lifecycles are: - Over 7X more likely to have strong or very strong security postures - 9X more likely to have low levels of security friction
Technology and identities are inseparable today. Together they drive digital transformation and fuel business innovation. However, they also represent a tremendous attack surface. Statistically most data breaches have an identity angle. The rates of successful attack are causing organizations to rethink their security strategy by putting identity security at the core of their cyber initiatives. The challenge organizations face is how to protect the connection between technology and identities without compromising the power that this pairing provides. This can be a daunting task for any organization. The good news is that years of research and development have taught us there are best practices to consider. Whether you are seeking information on how to get started, how to lower cyber insurance costs, how to move towards zero trust, or how to enhance your already seasoned identity programs, this session will offer insights and information to assist you on your journey. Join SailPoint and (ISC)² October 25, 2022 at 1:00 p.m. Eastern/10:00 a.m. Pacific as they talk about Identity Security with focus on: -Understanding risks posed by the marriage of technology and identity -Discussing how your identity security program impacts your end users – and why it’s a good thing! -Discovering how to develop a clear roadmap for your Identity Security program
You can’t protect what you can’t see. This is true — especially for cybersecurity teams attempting to manage and shrink the attack surface of their organization. According to the Cloud Security Alliance, misconfigurations are responsible for up to 63% of security incidents. To combat this misgiving, organizations should perform an attack surface assessment to identify critical assets and risks associated with them. An attack surface assessment is an effort that's focused on increasing visibility by examining the entry points to all of your assets and data. This assessment is unique to each organization, leading to the detection of assets, vulnerabilities, and misconfigurations. In this session, January 17, 2023 at 1:00 p.m., Eastern/ 10:00 a.m. Pacific Axonius and (ISC)2 will share insights on how an attack surface assessment can help you with: • Discovering asset identification and inventory • Identifying previously unknown misconfigurations and vulnerabilities • Prioritizing security risks
Public key infrastructure (PKI) today is ubiquitous – it’s in the cloud, it’s on the manufacturing floor, it’s everywhere. Why? Because, in a Zero Trust world, every device, every workload, and every connected thing must be authenticated and verified. There’s just one problem. Because of its extensive use, PKI has become incredibly complex to manage. Different teams and applications have unique trust requirements, use cases, technical and security needs, creating a distributed fabric of PKI tools and infrastructure. So, how do you manage this new “Decentralized PKI”? Join Keyfactor and (ISC)2 July 20, 2023 at 1:00 p.m. Eastern/ 10:00 a.m. Pacific as we discuss the ins and outs of decentralized PKI, best practices for management, and how to consolidate where possible. During this webinar, you’ll learn: • How the usage of PKI has evolved and expanded • New threats, regulatory mandates and changes to PKI • Key considerations for different PKI and CA tools • Best practices for managing “Decentralized PKI”
The Domain Name System (DNS) is essentially the central nervous system of the internet—everyone needs it to work because without DNS services, digital business could come to a halt. Cybercriminals know this too, and exploit DNS services to launch their attacks while simultaneously attacking the DNS services of their targets. Therefore, it’s not only important to protect your organization’s DNS service, but also to use the data available from DNS services to more rapidly detect and surgically block threat activity such as phishing, DNS tunneling-based data exfiltration, and ransomware. On March 2, 2023 join Infoblox and ISC2 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear best practices for an effective DNS security architecture.
Join us for this live webinar where we’ll tell you all about newly enhanced Official ISC2 Online Self-Paced Training for ISSAP. Find out how it provides a clear-cut and comprehensive review of the domains for a more structured and intuitive learning experience. We’ll also share details about the new second path to earning the ISSAP.
Join us for this live webinar where we’ll tell you all about newly enhanced ISC2 Online Self-Paced CSSLP Training with AI-driven adaptive learning. Find out how this dynamic experience pinpoints areas that require focus and guides you through every stage of your personalized exam prep. You’ll study smarter, not harder, and go into the CSSLP exam with confidence. You’ll learn: • Why it makes training more efficient busy professionals • What makes it a more efficient route to exam readiness • How artificial intelligence tailors learning to your needs • And much more Friday, March 8, 2024 at 1pm ET Save your spot now.
With generative AI now ever-present in most organizations, the next frontier for security practitioners is understanding where AI capabilities like machine learning, deep learning and natural language processing can best increase cybersecurity efficiency and effectiveness in their organizations. How can generative AI help your team respond to incidents, discover and patch vulnerabilities, or assist with programming? Or all the above? And what do teams need to consider in order to identify, review, assess risk and develop the use cases before putting them into production? Join IANS and ISC2 November 30, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear about strategy toward using generative AI within their security programs. Walk away with insights and tangible recommendations for how to: - Identify the use cases where AI can bring value to your security organization - Understand the limitations and risks of AI capabilities and where you should proceed with caution - Determine the skills, tools and domain experts needed for use case evaluation - Develop your AI use case risk assessment framework - Recognize where and how AI can enable your security teams, but not replace them
The CISA Zero Trust Maturity Model is filled with concepts and language appropriate for federal agencies, but it doesn’t always translate to the private sector, and certainly not to smaller, less-mature mid-market organizations. In this live session on April 18, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific IANS and ISC2 host a webinar to explain: • Which metrics to consider and which to avoid • Ways to use metrics to communicate with nontechnical stakeholders and/or the board • Examples of maturity models to track the long-term progress of a zero trust program
Ever wonder what Policy-Based Access Control (PBAC) is? Why is Policy-Based Access Control Crucial to the Modern Business and how PBAC overcomes the management and scalability challenges of RBAC and ABAC? In this webinar, you will gain a clearer understanding of how PBAC differs from traditional access control models and learn how to use effective policies to protect sensitive data and ensure regulatory compliance. Whether you are an IT professional, an IAM expert, a security architect, or a decision-maker responsible for safeguarding critical information assets, this webinar hosted by PlainID will provide you with practical insights and best practices to enhance your organization's access control strategy.
"You can't protect what you can't see" and "it takes a village" are familiar expressions within security and risk teams. Visibility and policy enforcement are fundamental pillars in cybersecurity and critical components within a holistic API security strategy. But the existing landscape complicates those efforts. Why? Architecture is becoming de-centralized and distributed, transforming apps into a digital fabric of business logic interconnected by APIs. Yet the enterprise catalog continues to be powered by a mix of legacy and modern apps across data centers, clouds, and at the edge. This hybrid, multi-cloud digital world introduces major risks driven by third-party integrations, inconsistent security controls across cloud providers, and continuous code updates across complex software supply chains and CI/CD pipelines. So how can you secure APIs in this modern digital fabric? Well, it takes a village. Join this webinar March 9, 2023 at 1:00 p.m. Eastern/10:00 a.m. Pacific to hear: • The challenges of API security in a hybrid, multi-cloud digital world • How to get a handle on API and tool sprawl • Insights on trends and solutions for API security
Join us for this live Q&A where our panel of experts will answer all of your questions about the Certified Information Systems Security Professional (CISSP) Concentrations in architecture, engineering and management before you sit for the exam. We’ll go over certification requirements, the domains, self-study resources, training options and more to help you build confidence so you’re ready on exam day. You’ll learn: • How the ISSAP, ISSEP and ISSMP concentrations build upon the CISSP • Why vendor-neutral certification is in demand • What training tools are available • And much more Save your spot now.
Digital transformation is not just about adopting new technologies but also about re-evaluating traditional security strategies for your modern business. As organizations pivot towards cloud-based environments and remote and hybrid work models, the traditional security perimeter has dissolved, necessitating a shift to Secure Service Edge (SSE) models. Join HPE and ISC2 for this session to learn: -How digital transformation has led organizations towards security transformation -Why security transformation is best achieved with a Security Service Edge (SSE) approach. -How SSE works for the modern business -How you can get started today
Are passwords on the brink of extinction, and what does a password-free era hold in store? In this enlightening session, delve into the comprehensive report by Delinea on the present and future trajectory of passwords. Gain invaluable insights from Delinea's survey of IT and cybersecurity leaders, along with practical strategies to contextualize the findings, including dispelling common password myths. Discover the dynamic evolution of passwords, bolstered by robust, user-friendly authentication methods such as Multi-Factor Authentication, biometrics, and Artificial Intelligence. Explore how Privileged Access Management (PAM) is evolving to address evolving needs, navigating the intricacies of workflow, technical nuances, and compliance imperatives to craft a forward-looking strategy. Witness how PAM streamlines password management, alleviates operational burdens, and empowers granular control over critical secrets.
ImportantRecertHero is an independent aggregator. Credit estimates are guidance only — always verify with your certifying body.