CCSP Stands for Certified Cloud Security Professional .It is a very Popular Certification these days due to increased Trend of Cloud Computing. This Session is on CCSP Domain 6 which is Legal ,Risk and Compliance .This domain has 13 % weightings in CCSP Exam.
In this Video the Speaker talks about the below mentioned Topics .The Key Moments have been breaken down below for your convenience .
00:00 – 03:15 Introduction
03:20 – 14:24 Evaluating Legal Risks Specific to Cloud Computing
14:30 – 21:06 E-Discovery
21:07 – 28:13 Understanding Privacy Issues
28:15 – 33:23 Country Specific Legislation for Private Data
33:25 – 39:32 Generally Accepted Privacy Principles (GAPP)
39:34 – 44:00 Understanding Audit Process and Methodologies
44:01 – 48:11 Lines of Defense
48:12 – 52:06 Type of Audit Reports (SSAE and SOC Reports)
52:07 – 58:50 Type of SOC (Service Organization Control) Reports
58:55 – 01:04:15 Restriction of Audit Scope Statements
01:04:16 -01:08:34 Internal ISMS (Information Security Management System)
01:08:35 – 01:17:14 Difference between Data Owner/Data Controller Vs Data Custodian/Data Processor
01:17:15 – 01:29:01 Understanding Outsourcing and Cloud Contract Design
01:30:01 – 01:31:59 Question Answers
Name: Rehan Bashir
Rehan Bashir is an information security professional with more than 15 years of progressive experience. He has proven ability in helping organizations both in public and private sectors to comply with their cybersecurity requirements. In his career, Rehan acted as a trusted advisor to organizational leaders of cybersecurity programs, helped developed information security policies and advocated for change in cybersecurity policy to support organizational cyberspace. Managed and led multitude of cybersecurity projects which includes security policies and procedures development, risk management and compliance, security audits, enterprise network vulnerability assessments and penetration testing and application security. Areas of expertise include: -Enterprise network and architecture security -Application security -Security project management -Risk management -Audit and compliance (FISMA, NIST, ISO, PCI) -Industrial control systems security -Cloud security -Digital Forensics -Team building and leadership Rehan holds a bachelor degree in addition to numerous security and risk certifications including CISSP, CISA and CAP. Rehan enthusiastically pursues continuous professional development opportunities; he has completed Stanford University’s Cybersecurity and Executive Strategy program.