

CISSP Study Plan – Day 40 of 55 | Discretionary Access Control (DAC)
“Access control defines power — and with DAC, that power belongs to the data owner.” – Luke Ahmed Today is Day 40 of Yihenew’s CISSP study plan, focusing on Discretionary Access Control (DAC) — one of the core access models in cybersecurity and a frequent source of confusion on the CISSP exam. DAC grants data owners the discretion to decide who can access their resources. It’s flexible, but with that flexibility comes risk. Understanding DAC helps you recognize where human j
Nov 4


CISSP Study Plan – Day 39 of 55 | CIA vs DAD – Both Matter
“The CIA Triad is the core principle of not only the CISSP exam, but all of cybersecurity.” – Luke Ahmed Today is Day 39 of Yihenew’s CISSP study plan, focusing on one of the most fundamental — yet frequently misunderstood — pairs of concepts: CIA vs DAD . The CIA Triad forms the backbone of every information security decision you’ll make as a CISSP. The DAD Triad , on the other hand, is its opposite — representing the consequences when those principles fail. Understanding b
Nov 4


CISSP Study Plan – Day 38 of 55 | Defense in Depth: From Physical to Technical
“Late nights, early mornings — a recipe to put CISSP after your name! And you did!” – Luke Ahmed Today is Day 38 of Yihenew’s CISSP study plan, focusing on Defense in Depth — the multilayered security strategy that every CISSP must be able to design, justify, and explain. Defense in Depth is not about piling on tools — it’s about ensuring that each control layer complements the others. From physical access to encryption, every layer should serve a purpose in minimizing risk.
Nov 4


CISSP Study Plan – Day 37 of 55 | Data Ownership
“Great to see you studying data ownership on this 37th day! Ownership in general is important, as well as the delegation of data maintenance!” – Luke Ahmed Today is Day 37 of Yihenew’s CISSP study plan, focusing on Data Ownership — one of the most important governance concepts in the CISSP exam. Many candidates overthink encryption and storage mechanisms but overlook a fundamental question: Who owns the data? Understanding ownership clarifies accountability, responsibility,
Nov 4


CISSP Study Plan – Day 36 of 55 | ISO 27001 and Control Frameworks
“Control frameworks not only provide a guide for the organization, but are essential to know for a high-level certification such as the CISSP!” – Luke Ahmed Today is Day 36 of Yihenew’s CISSP study plan, focusing on ISO 27001 , one of the most respected international standards for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) . If you understand how ISO 27001 fits into the CISSP mindset, you’re already thin
Nov 4
