

CISSP Study Plan – Day 37 of 55 | Data Ownership
“Great to see you studying data ownership on this 37th day! Ownership in general is important, as well as the delegation of data maintenance!” – Luke Ahmed Today is Day 37 of Yihenew’s CISSP study plan, focusing on Data Ownership — one of the most important governance concepts in the CISSP exam. Many candidates overthink encryption and storage mechanisms but overlook a fundamental question: Who owns the data? Understanding ownership clarifies accountability, responsibility,
Nov 4, 2025


CISSP Study Plan – Day 36 of 55 | ISO 27001 and Control Frameworks
“Control frameworks not only provide a guide for the organization, but are essential to know for a high-level certification such as the CISSP!” – Luke Ahmed Today is Day 36 of Yihenew’s CISSP study plan, focusing on ISO 27001 , one of the most respected international standards for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS) . If you understand how ISO 27001 fits into the CISSP mindset, you’re already thin
Nov 4, 2025


CISSP Study Plan – Day 35 of 55 | MTD, RPO, and RTO
“To anyone reading this — if you don't understand BCP/DRP for the CISSP, you will fail the exam. Yani made sure he knew it completely.” – Luke Ahmed Today is Day 35 of Yihenew’s CISSP study plan, focusing on three of the most exam-critical metrics in Business Continuity and Disaster Recovery (BCP/DRP) — MTD, RPO, and RTO . These terms aren’t just definitions — they are management decisions about how much downtime and data loss your organization can afford before the busines
Nov 4, 2025


CISSP Study Plan – Day 34 of 55 | Role-Based Access Control (RBAC)
“You used every second studying without waste — the outcome was always obvious: CISSP!” – Luke Ahmed Today is Day 34 of Yihenew’s CISSP study plan, focusing on Role-Based Access Control (RBAC) — one of the most widely implemented and exam-tested access models in the CISSP. RBAC is about assigning permissions to roles , not individuals. This ensures consistent access control management, reduced administrative burden, and tighter alignment between business functions and system
Nov 4, 2025


CISSP Study Plan – Day 33 of 55 | SAML (Security Assertion Markup Language)
“Rain or shine a CISSP will do what they have to do.” – Luke Ahmed Today is Day 33 of Yihenew’s CISSP study plan, focusing on SAML — Security Assertion Markup Language , one of the most important identity federation standards every CISSP must understand. SAML allows users to authenticate once and access multiple systems or services across domains — it’s the foundation of Single Sign-On (SSO) in enterprise environments. Knowing how and why SAML works connects directly to yo
Nov 4, 2025


CISSP Study Plan – Day 32 of 55 | Threat Modeling
“Highlighting and note taking — your secret resource for the exam and THE best way to maintain subject matter retention.” – Luke Ahmed Today is Day 32 of Yihenew’s CISSP study plan, focusing on Threat Modeling — the art of predicting, identifying, and reducing potential threats before they happen. Threat modeling is where technical knowledge meets foresight. You’re not reacting to incidents — you’re designing systems with security built in from the start. Key Areas Covered
Nov 4, 2025


CISSP Study Plan – Day 31 of 55 | Your Mistakes Are Your Best Study Resource
“Everyone goes on their own pace, and you did it perfectly. Not only that, your entire journey is documented — now that's a powerful statement!” – Luke Ahmed Today is Day 31 of Yihenew’s CISSP study plan, focusing on one of the most overlooked yet powerful tools in your entire journey — your mistakes. Every wrong answer, every confusing question, every note you had to rewrite three times — that’s not failure. That’s progress recorded. Mistakes are data points showing where yo
Nov 4, 2025


CISSP – A Journey That Continues Beyond the Exam
This was the toughest exam I’ve taken so far and, in my opinion, it’s much more challenging than the CCSP I passed last year. For me, studying wasn't just about preparing for an exam—it was a genuine passion to improve myself in all 8 domains. The journey... Right from the start, I chose LukeAhmed’s course from https://www.studynotesandtheory.com/ (the same one that helped me pass the CCSP last year), and I truly believe it offers the best explanations and structure for CISS
Oct 30, 2025


CISSP Study Plan – Day 30 of 55 | Penetration Testing and the CISSP Exam
"It's a lonely journey, but man, that ending is worth it!!" – Luke Ahmed Today is Day 30 of Yihenew’s CISSP study plan, focusing on penetration testing — a critical concept that blends technical skill with management-level understanding of risk validation. Key Areas Covered: Purpose of Pen Testing — to simulate real-world attacks and test how effective existing controls are, both technically and procedurally. Pen Test vs. Vulnerability Scan — vulnerability scans identify p
Oct 4, 2025


CISSP Study Plan – Day 29 of 55 | Understanding the Risk Management Framework (RMF)
"It's been 5 years since I wrote that book, so good to see it in your hands. The ultimate measure of its success will be the completion...
Oct 4, 2025
