Efficiency Squared

Cyber & Security

CISSP Certification Bootcamp

A five-day bootcamp for experienced security professionals preparing for the (ISC)² CISSP exam and for security leaders who need a managerial-level view across the full security program. Aligned to the current CBK effective April 15, 2024.

Format
Live virtual, in-person, or private on-site
Duration
1 week
Level
Advanced
From
$3995.00

About this course

Course overview

The gold-standard cybersecurity credential — taught from a security manager's perspective, not a textbook.

CISSP is the manager's exam, and most prep programs miss that. This bootcamp is built for the candidate who can already configure a firewall, write a policy, or lead an incident response — and now needs to think one level up: which controls matter, how risk is communicated to the business, and which answer is most correct when three of the options are technically defensible.

The five-day cohort runs through every domain in the current CISSP CBK (effective April 15, 2024) with scenario drills, exam-strategy debriefs, and the manager's-perspective approach the CAT-format exam rewards. By Friday afternoon you have a domain-weighted study plan, a personalized weak-topic log, and the readiness routine to walk into your exam appointment.

Learning outcomes

What you'll learn

Every module is tied to an outcome you can bring back to your team the next day.

  • Apply security and risk management concepts including governance, compliance, professional ethics, and security policy
  • Run threat modeling, risk treatment, business impact analysis, and supply-chain risk practices that hold up to audit and executive review
  • Design and evaluate security architectures across on-premises, cloud, hybrid, and edge environments using secure design principles, cryptography, and trusted computing
  • Apply secure network architecture, secure communications, and network access controls to protect enterprise and cloud-connected environments
  • Design identity, authentication, authorization, and lifecycle controls for federated, cloud, and zero-trust environments
  • Run security assessments, audits, and continuous monitoring; lead incident response, BCP/DR, and security operations across the technology stack
  • Apply security in the SDLC, software-supply-chain risk, secure-coding practice, and software-acquisition due diligence
  • Use domain-weighted study planning, the manager's-perspective approach to question selection, and CAT exam strategy to prepare for exam day

Audience

Who it's for

  • Security analysts, engineers, and architects with 4+ years of professional experience who are ready to sit for CISSP
  • Risk, compliance, and audit professionals moving into security leadership
  • Project and program managers responsible for security delivery who need the credential alongside their PM cert
  • Security team leads preparing direct reports for the exam in cohort form
  • Candidates without the (ISC)² experience requirement who plan to certify as Associate of (ISC)² and convert later

Course structure

Syllabus

A structured path from core concepts to applied practice.

Module 1

Day 1 — Security and Risk Management

  • Exam orientation, CAT delivery, and the manager's-mindset approach
  • (ISC)² Code of Professional Ethics and ethical decision-making scenarios
  • Security governance, policy hierarchy, and compliance/regulatory/privacy requirements
  • Threat modeling, risk treatment, business continuity scoping, BIA, and supply-chain risk
  • Practice lab: governance, ethics, and risk-treatment scenario questions
Module 2

Day 2 — Asset Security and Security Architecture & Engineering

  • Information and asset classification, ownership, handling, retention, and data lifecycle
  • Secure design principles, security models, trusted computing, and information-system capabilities
  • Cryptography: symmetric, asymmetric, hashing, PKI, key management, and cryptanalytic attacks
  • Cloud, virtualization, container, IoT, OT, and embedded-systems security
  • Site and facility security; practice lab on architecture, cryptography, and asset classification
Module 3

Day 3 — Communication & Network Security and IAM

  • Secure network design, segmentation, micro-segmentation, and zero trust
  • Secure protocols, transport encryption, secure remote access, VPN, NAC, SD-WAN/SASE
  • Identity lifecycle, MFA, federation, SSO, SAML, OAuth/OIDC, and IDaaS patterns
  • Authorization models (RBAC, ABAC, MAC, DAC) and privileged-access management
  • Practice lab: network and IAM scenarios with manager's-perspective debrief
Module 4

Day 4 — Security Assessment & Testing and Security Operations

  • Assessment, audit, and testing strategies; vulnerability assessment, penetration testing, code review
  • Security data collection, log analysis, KPIs/KRIs, and management reporting
  • Logging, monitoring, SIEM/SOAR, threat intelligence, and continuous monitoring
  • Incident response phases, containment, forensics, and lessons learned
  • Business continuity, disaster recovery, backup, and resilience strategies
Module 5

Day 5 — Software Development Security and Exam Readiness

  • Security in the SDLC, secure coding, and software-development methodologies
  • Software supply-chain risk, third-party software, open-source governance, and SBOMs
  • Application security testing, DAST/SAST, secure DevOps, and runtime protection
  • Domain-weighted review across all eight CISSP CBK domains and timed mixed practice set
  • 30-day study plan, readiness checklist, exam-day strategy, and (ISC)² endorsement walk-through

Public cohorts

Upcoming sessions

Secure your seat in a live, instructor-led cohort. Private team deliveries available on request.

No public cohorts on the calendar yet.

We run this course as a private team cohort on demand, or you can be the first to know when the next public date drops.

Frequently asked questions

Still have questions?

Do I meet the CISSP experience requirement?
(ISC)² requires five years of cumulative paid work experience in two or more of the eight CISSP CBK domains, or four years with a qualifying degree or approved credential. Candidates without the experience requirement can still sit for the exam and become an Associate of (ISC)², converting to full CISSP once they reach the threshold.
How is this different from CompTIA Security+ Prep?
Security+ is the practitioner-tier introduction to the full security stack — broad, hands-on, foundational. CISSP is the manager's-tier credential — depth, governance, risk leadership, and the perspective from which security programs are designed. Most professionals do Security+ first, then CISSP later in their career.
Is the exam included in the price?
No. (ISC)² endorsement, exam voucher, and exam scheduling are handled separately unless explicitly included in a private engagement. We'll walk you through the registration and endorsement process on Day 5.
What's the format of the exam?
CISSP uses computerized adaptive testing (CAT) with 100–150 multiple-choice and advanced-innovative items (drag-and-drop, hotspot) over up to 3 hours. The course's practice labs and final-day simulation use the same item types and pacing.
Can this be delivered as a private cohort?
Yes. We deliver CISSP Bootcamp privately for security teams sitting the exam together, with optional pre-work, custom case studies aligned to your environment, and group exam-day scheduling support.

Bring this training to your team

We deliver private cohorts in-person and online, tailored to your operating context.