CISSP 通俗考点短文库

教材:ISC2 CISSP Official Study Guide, 10th Edition (2024, Sybex) · 共 1899 页 / 21 章 目标:把手册「全面消化」成多篇通俗短文,对每个考点用大白话讲清楚。 学习方式:滚动周计划,每周 6–8 小时(无考试死线,按节奏兜底)。


一、已锁定方案(设计树已共识)

决策
范围 全 8 域(按书本章节顺序 Ch1→Ch21)
粒度 按「小节 / 单个考点」拆成多篇短文(加厚版每篇 800–1200 字,含原书定义+对比表 / 真实案例 / 考试怎么考)
单篇结构(加厚版) ①一句话秒懂 ②原书核心定义+对比表 ③生活类比(精简) ④真实案例 ⑤相关概念梳理(+表) ⑥考试怎么考(题型+混淆项) ⑦自测(附解析)
术语 中文为主,关键英文术语括注(CISSP 题为英文)
自测题 改编自原书每章 Review Questions,附解析
交付 本目录 cissp-notes/,每篇一个 .md + 本总索引
排期 完整周计划(见 cissp-study-plan.md,已覆盖 8 域 21 章 + 总复盘)

加厚标准定型说明(2026-08-23):初版(300–600 字、偏类比)经用户反馈”太简单”后,用 grilling 校准并确认样品(原 02-security-concepts-PROTOTYPE.md,已转正)。定型为上方加厚版:保留口语开头,但补「原书精确定义 + 对比表 / 真实案例 / 考试怎么考」三块干货,篇幅 800–1200 字。后续 Ch2 起直接套用,不再每篇征询。

二、文章模板(加厚版,每篇统一)

# <考点名>(中英)
> 来源:Chapter X · <小节>
> 域:Domain N <名称>
> 模板:原书定义+对比表 / 真实案例 / 考试怎么考
① 一句话秒懂
② 原书核心定义 + 对比表(引 Sybex 措辞,考试常考定义对应)
③ 生活类比(精炼,不当主角)
④ 真实案例(概念落地,知名事件)
⑤ 相关概念梳理 + 对比表
⑥ 考试怎么考(题干样式 + 常见混淆项)
⑦ 自测(改编自原书 Review Questions,附解析)

三、章节 → 域 映射与进度

标题 状态
Ch1 Security Governance Through Principles and Policies D1 ✅ 8 篇已生成(加厚标准
Ch2 Personnel Security and Risk Management Concepts D1 ✅ 7 篇已生成(加厚版)
Ch3 Business Continuity Planning D1 ✅ 4 篇已生成(加厚版)
Ch4 Laws, Regulations, and Compliance D1 ✅ 6 篇已生成(加厚版)
Ch5 Protecting Security of Assets D1 ✅ 5 篇已生成(加厚版)
Ch6 Cryptography and Symmetric Key Algorithms D3 ✅ 4 篇已生成(加厚版)
Ch7 PKI and Cryptographic Applications D3 ✅ 6 篇已生成(加厚版)
Ch8 Principles of Security Models, Design, and Capabilities D3 ✅ 6 篇已生成(加厚版)
Ch9 Security Vulnerabilities, Threats, and Countermeasures D3 ✅ 9 篇已生成(加厚版)
Ch10 Implementing Physical Security D3 ✅ 8 篇已生成(加厚版)
Ch11 Secure Network Architecture and Components D4 ✅ 10 篇已生成(加厚版)
Ch12 Secure Communications / Network Components D4 ✅ 9 篇已生成(加厚版)
Ch13 Security Network Management D4 ✅ 8 篇已生成(加厚版)
Ch14 Controlling and Monitoring Access D5 ✅ 8 篇已生成(加厚版)
Ch15 Security Assessment and Testing D6 ✅ 5 篇已生成(加厚版)
Ch16 Foundational Security Operations D7 ✅ 6 篇已生成(加厚版)
Ch17 Incident Response / Detection & Prevention D7 ✅ 6 篇已生成(加厚版)
Ch18 Disaster Recovery / BCP D7 ✅ 6 篇已生成(加厚版)
Ch19 Investigations, Ethics (Software Dev Security) D8 ✅ 3 篇已生成(加厚版)
Ch20 Systems Development Controls / Databases D8 ✅ 3 篇已生成(加厚版)
Ch21 Malicious Code and Application Attacks D8 ✅ 7 篇已生成(加厚版)

说明:Sybex 章节顺序大体对应 8 大域顺序,生成按 Ch1→Ch21 推进;精确的「章→域」以原书 Objective Map 为准,生成到对应章时再校准。

四、已生成文章索引

Domain 1 · Ch1 Security Governance Through Principles and Policies(加厚版)

Domain 1 · Ch2 Personnel Security and Risk Management Concepts(加厚版)

Domain 1 · Ch3 Business Continuity Planning(加厚版)

Domain 1 · Ch4 Laws, Regulations, and Compliance(加厚版)

Domain 1 进度(Ch1–Ch4):共 25 篇加厚短文已落地。

Domain 2 · Ch5 Protecting Security of Assets(加厚版)

Domain 3 · Ch6 Cryptography and Symmetric Key Algorithms(加厚版)

Domain 3 · Ch7 PKI and Cryptographic Applications(加厚版)

Domain 3 · Ch8 Principles of Security Models, Design, and Capabilities(加厚版)

Domain 3 · Ch9 Security Vulnerabilities, Threats, and Countermeasures(加厚版)

Domain 3 进度:Ch6–Ch10 共 33 篇加厚短文已落地;Ch8(安全模型与设计)、Ch9(漏洞/威胁/对策)、Ch10(物理安全)已补全,Domain 3(安全架构与工程)全 5 章走完。下一批进入 Domain 4(通信与网络安全),自 Ch11(安全网络架构与组件) 起。

Domain 3 · Ch10 Implementing Physical Security(加厚版)

Domain 3 收官:Ch6–Ch10 共 33 篇。注:Ch10 在 Sybex 中属 Domain 3(安全架构与工程),虽名为”物理安全”,但考纲将其归入该域。

Domain 4 · Ch11 Secure Network Architecture and Components(加厚版)

Domain 4 进度:Ch11 共 10 篇加厚短文已落地,开启 Domain 4(通信与网络安全)。下一批继续 Ch12(安全网络组件与通信信道) → Ch13(网络攻击与防御),走完 Domain 4。

Domain 4 · Ch12 Secure Communications / Network Components(加厚版)

Domain 4 · Ch13 Security Network Management(加厚版)

Domain 4 收官:Ch11–Ch13 共 27 篇,Domain 4(通信与网络安全)全 3 章走完。下一批进入 Domain 5(身份与访问管理)Ch14

Domain 5 · Ch14 Controlling and Monitoring Access(加厚版)

Domain 5 进度:Ch14 共 8 篇,Domain 5(身份与访问管理,权重 ~13%)一轮走完。下一批进入 Domain 6(安全评估与测试)Ch15

Domain 6 · Ch15 Security Assessment and Testing(加厚版)

Domain 6 进度:Ch15 共 5 篇,Domain 6(安全评估与测试,权重 ~12%)一轮走完。下一批进入 Domain 7(安全运营)Ch16–Ch18

Domain 7 · Ch16 Foundational Security Operations(加厚版)

Domain 7 · Ch17 Incident Response / Detection & Prevention(加厚版)

Domain 7 · Ch18 Disaster Recovery / BCP(加厚版)

Domain 7 收官:Ch16–Ch18 共 18 篇,Domain 7(安全运营,权重 ~16%)全 3 章走完。下一批进入 Domain 8(软件开发安全)Ch19–Ch21,即全书最后一域。

Domain 8 · Ch19 Investigations, Forensics & Ethics(加厚版)

Domain 8 · Ch20 Systems Development Controls / Databases(加厚版)

Domain 8 · Ch21 Malicious Code and Application Attacks(加厚版)

Domain 8 收官 & 全书完成:Ch19–Ch21 共 13 篇,Domain 8(软件开发安全,权重 ~10%)全 3 章走完。至此全书 8 域 21 章全部覆盖,累计 135 篇加厚短文。 配套全局思维导图见 mind-map.html,打卡清单见 checklist.md


本库由「学习规划师」工作流生成:先 grilling 锁定方案 → 抽取原书小节原文 → 按模板产出通俗短文 → 配滚动周计划。



Table of contents


This site uses Just the Docs, a documentation theme for Jekyll.