Available now

Domain 5: Protection of Information Assets

Security controls and the evidence that shows they work. Joint largest domain on the exam.

26%
of the exam
16
lessons
48
exam questions
117
minutes

Start here

Information Security Governance and Frameworks

  1. 1Information Security Governance and FrameworksSecurity is a governance responsibility, not just an IT task. The exam tests who is ultimately accountable, and the difference between a policy, a standard and a procedure.7 min · 3 questions · video
  2. 2Data Classification and Asset OwnershipYou protect data according to its value, so first you have to know its value. The exam tests that classification comes first and that the business owner, not IT, assigns it.7 min · 3 questions · video
  3. 3Privacy and Data Protection PrinciplesSecurity protects data; privacy governs whether you should have collected it at all. The exam tests the difference, and that encrypting data you should not hold does not fix a privacy problem.7 min · 3 questions · video
  4. 4Identity and Access Management: AuthenticationProving who you are is not the same as saying who you are. The exam tests what really makes authentication multi-factor, and why a shared account has no accountability.8 min · 3 questions · video
  5. 5Access Control Models and Least PrivilegeGive people the minimum access their job needs, and no more. The exam tests least privilege, the access-control models, and how privilege quietly creeps beyond what a role requires.7 min · 3 questions · video
  6. 6Privileged Access ManagementAdministrator accounts can switch off the controls that protect everything else, which is why they get the tightest handling. The exam tests why privileged access is the priority and how it is controlled.7 min · 3 questions · video
  7. 7User Access Provisioning and ReviewGranting access is easy to get right and easy to forget to undo. The exam tests the leaver who keeps access, and the periodic review that catches what provisioning missed.7 min · 3 questions · video
  8. 8Physical and Environmental ControlsLogical controls mean nothing if someone can walk out with the server or the room floods. The exam tests tailgating, and why environmental controls protect the availability of everything else.7 min · 3 questions · video
  9. 9Network Architecture and SegmentationA flat network turns one compromise into a total one. The exam tests why segmentation contains a breach, what a DMZ is for, and why network location is no basis for trust.7 min · 3 questions · video
  10. 10Firewalls, IDS/IPS and Secure AccessA firewall decides what may pass; detection tells you what did. The exam tests the difference between an IDS that alerts and an IPS that blocks, and why a VPN protects traffic over untrusted networks.7 min · 3 questions · video
  11. 11Cryptography FundamentalsEncryption hides data, hashing proves it has not changed, and they are not the same thing. The exam tests symmetric versus asymmetric keys, what hashing provides, and where non-repudiation comes from.8 min · 3 questions · video
  12. 12PKI and Key ManagementCryptography rarely fails at the algorithm; it fails at the keys. The exam tests the role of a certificate authority, which key signs and which verifies, and why key management is the hard part.8 min · 3 questions · video
  13. 13Endpoint, Mobile and Cloud SecurityMoving to the cloud does not move the accountability for your data. The exam tests the shared responsibility model, the risk of data on personal devices, and why a misconfigured bucket is your fault.8 min · 3 questions · video
  14. 14Security Awareness and Attack MethodsThe strongest controls are bypassed by fooling a person. The exam tests why awareness training is the control for social engineering, and how to recognise the common attack methods.7 min · 3 questions · video
  15. 15Security Testing and MonitoringA scan lists the weaknesses; a penetration test proves what they'd cost you. The exam tests that distinction, and why logs no one reads are not a detective control at all.7 min · 3 questions · video
  16. 16Incident Response and Digital ForensicsThe last lesson of the course. When an attack lands, contain it before you clean it, and preserve evidence you might need to prove. The exam tests the response order and chain of custody.8 min · 3 questions · video

Independent training produced by Marco Cavani. Not affiliated with, endorsed by, or sponsored by ISACA. CISA is a registered trademark of ISACA. Domain structure reflects the published exam content outline and is not reproduced from ISACA materials.

Stay ahead of cyber threats

Get the latest cybersecurity reports, threat intelligence, and IT governance insights delivered straight to your inbox. No spam. Unsubscribe any time.

No spam. Unsubscribe at any time.