ISC2 CC 2026 Complete Course | Updated Exam Outline – Domain 3 — Transcript
Full transcript
- 0:00Welcome to the updated (ISC)² Certified
- 0:03in Cybersecurity course. Due to the
- 0:06overwhelming response [music] to my
- 0:08previous (ISC)² CC course, which has
- 0:11helped hundreds of learners successfully
- 0:14prepare for and pass their exam, I am
- 0:18excited to bring you this completely
- 0:20updated course.
- 0:22This course has been carefully prepared
- 0:24according to the latest (ISC)² CC exam
- 0:27outline, effective September 1st, 2026,
- 0:30[music]
- 0:32covering the new domains, objectives,
- 0:34and updated exam content.
- 0:37So, whether you are completely new to
- 0:39the cybersecurity [music]
- 0:40or preparing to earn your (ISC)² CC
- 0:43certification, this course will guide
- 0:45you through the concepts [music] you
- 0:47need to know in a simple, practical, and
- 0:50exam-focused way.
- 0:52So, let's get started and prepare for
- 0:54the updated (ISC)² [music] CC exam
- 0:57together.
- 1:01Hello everyone, and welcome to the
- 1:04domain three of our course, Identity and
- 1:08Access Management Concepts.
- 1:11This is a short and brief domain, and a
- 1:14very straightforward.
- 1:16So, let's get started, and our objective
- 1:193.1 is Understand Identity Lifecycle
- 1:23Management.
- 1:26Our first topic is roles definition.
- 1:29What are roles? So, before we grant
- 1:32access, an organization should define
- 1:35roles and responsibilities.
- 1:38So, when there is a new employee or when
- 1:42there is a promotion of an existing
- 1:44employee, and a certain role is given to
- 1:48that employee, we should have
- 1:51certain criteria that this role can do
- 1:54this and that, and this is his or her
- 1:57responsibility.
- 1:59So, we should have these things defined.
- 2:03So, a role describe the functions a user
- 2:06can perform and the access required to
- 2:09perform those functions.
- 2:12For example, these are different roles
- 2:15that we may see in our organization.
- 2:18Some organization may have more than
- 2:20these roles. Some organization may have
- 2:22less.
- 2:23So, these roles include the human
- 2:25resource manager. This is almost present
- 2:28everywhere. And inside the IT, we have
- 2:31the network administrator, the database
- 2:33administrator,
- 2:34a security analyst, a finance employee.
- 2:38So, things like that. So, these are
- 2:40different roles. Uh you can say these
- 2:43are different hats
- 2:45that employees can wear. So, instead of
- 2:48giving each employee, let's suppose you
- 2:51have five network administrator, so
- 2:54instead of defining
- 2:56the permissions for each and
- 2:59employee individually,
- 3:01we do that for this network
- 3:03administrator role. So, whenever there
- 3:06is a network administrator, we give him
- 3:09or her that role. And that role already
- 3:12contain the required
- 3:14permissions and responsibility are the
- 3:16access that that
- 3:18person can have.
- 3:21So, this is an efficient way of managing
- 3:24the access to resources
- 3:27instead of manually assigning these
- 3:30permission to each individual each
- 3:33individual employee.
- 3:35So, for example, when a finance employee
- 3:38require access to accounting system, he
- 3:40or she is given access to that system
- 3:43only.
- 3:44But that doesn't mean that they also
- 3:46receive the administrative access to
- 3:48network devices. So, the administrative
- 3:51access to network devices maybe defined
- 3:53with that role.
- 3:55And the accounting system permissions
- 3:58maybe defined in that role. So, that
- 4:01employee will be given that hat, and
- 4:04that hat will not contain access to
- 4:07database or to network or to other
- 4:10security systems.
- 4:14So, provisioning is the first step in
- 4:16the identity and access management, and
- 4:19it is the process of creating an
- 4:21identity and providing the user with the
- 4:24access required to perform their job.
- 4:28So, the provisioning may include
- 4:30creating the user account for the
- 4:32employee, assigning an identity. So, an
- 4:35identity may be the username
- 4:38or the user ID, assigning roles. For
- 4:41example, if he is
- 4:43uh a network guy, so he may be assigned
- 4:46the role of the network administrator.
- 4:49So, granting permission. So, the
- 4:51permission will automatically come with
- 4:53that role. Providing access to
- 4:56applications.
- 4:57Then, we may have different applications
- 5:00such as
- 5:01let's suppose uh for his HR-related
- 5:04activities to check on his attendance,
- 5:08et cetera, he may be given
- 5:10a read-only access to the HR application
- 5:13and other portals.
- 5:15And similarly, issuing the
- 5:17authentication credentials. So,
- 5:19authentication credential is again the
- 5:21username plus the password.
- 5:26User ID plus
- 5:28password. So, these are the
- 5:29authentication credential.
- 5:33Access review. So, this is an important
- 5:36topic with respect to cybersecurity.
- 5:39So, what is this? So, user access should
- 5:42be periodically reviewed to ensure that
- 5:45it remains appropriate.
- 5:48So, access review can identify so why
- 5:51this access review is done? It is done
- 5:53to identify excessive permissions. So,
- 5:56some employee may have gotten excessive
- 5:58permissions that are beyond their roles
- 6:02are beyond the permission that are
- 6:04required to perform their duties. Some
- 6:08where me we may encounter some unused
- 6:10accounts. So, these may be of the
- 6:12employees that have left the job or that
- 6:15have been transferred to another
- 6:17department. So, there may be unused
- 6:19account.
- 6:20So, in access review, we should then
- 6:23delete or disable them. Inappropriate
- 6:25access again, as we said, the network
- 6:28administrator may have access to the
- 6:30database as well.
- 6:32Role changes. So, if there are role
- 6:35changes, for example, an engineer may be
- 6:38promoted to a manager role. So, the
- 6:41access review should review those things
- 6:44that this role does not have the
- 6:46previous
- 6:47permissions. Privilege accumulation. So,
- 6:50this is a related thing that when
- 6:53employee
- 6:54goes from one department to another or
- 6:56got promoted and the previous
- 6:59permissions are the previous access is
- 7:01not de-provisioned, it may accumulate
- 7:05over time.
- 7:07And again, the orphaned account is the
- 7:10same concept that there may be some
- 7:13account
- 7:14that are left unused due to their
- 7:20employee being promoted or being
- 7:23transferred to another department.
- 7:26An example is when an employee is moved
- 7:28from finance department to IT 6 months
- 7:31ago, but he or she still has access to
- 7:34the financial reporting system. So, that
- 7:37is a role of privilege accumulation. So,
- 7:40now that employee has access both to the
- 7:43IT as well as financial
- 7:46application which is not as per his
- 7:49current role.
- 7:52So, what is the deprovisioning? So, this
- 7:54is the life cycle we are talking about.
- 7:56First, we have the provisioning, then
- 8:00the usage of those accounts, then
- 8:01periodic access review, and the last one
- 8:04is the deprovisioning when the account
- 8:06are
- 8:07the roles are no longer required.
- 8:10So, deprovisioning is the process of
- 8:12removing or disabling a user's access
- 8:14when it is no longer required.
- 8:17So, common triggers for deprovisioning
- 8:19may include the employee termination,
- 8:22employee resignation,
- 8:25role changes,
- 8:27and contract expiration. So, these are
- 8:29some of the triggers that will require
- 8:32the deprovisioning of the
- 8:35access.
- 8:37So, deprovisioning may include disabling
- 8:39the user account, revoking the
- 8:41application access, removing the account
- 8:44group membership, and revoking the
- 8:47privileged access.
- 8:50So, what are some identity and access
- 8:53management framework? So, organization
- 8:56can use established framework and
- 8:58standards to guide identity and access
- 9:01management.
- 9:03For example,
- 9:05a framework that organization may use is
- 9:08NIST SP 800-63.
- 9:12So, this framework provides guidance
- 9:14related to digital identity and identity
- 9:17proofing, authentication, and
- 9:20federation.
- 9:22Another is the NIST
- 9:24cybersecurity framework. So, this one
- 9:27provides a broader cybersecurity risk
- 9:29management framework that includes
- 9:31identity and access related practices.
- 9:38Now, coming over to some identity and
- 9:40access management tools. So,
- 9:42organization use identity and access
- 9:45management tools and technology to
- 9:47manage the identities and access inside
- 9:51their organizations.
- 9:53The common identity and access
- 9:55management capabilities, technologies,
- 9:57or tools include the
- 10:00uh
- 10:01user account management. So, these are
- 10:03the different capabilities that you can
- 10:06do using these technologies and tools.
- 10:08So, you can uh use these technology and
- 10:11tools for user account management,
- 10:14authentication, authorization, role
- 10:17management, access provisioning, access
- 10:20review, and deprovisioning. So, these
- 10:22are all the
- 10:24uh you can say capabilities
- 10:27or the practices that we studied. So, we
- 10:31have different type of tools that give
- 10:33us all the capabilities that are inside
- 10:37the identity and access management life
- 10:39cycle.
- 10:41So, some common tools or technologies
- 10:44for identity and access management
- 10:46include directory services.
- 10:48We have different identity providers and
- 10:51access management platform.
- 10:55Another important and related topic is
- 10:58the principle of least privilege.
- 11:03So, principle of least privilege is a
- 11:05user and system are granted only the
- 11:09minimum necessary access to perform
- 11:11their tasks, reducing the security risk.
- 11:16So, as the word least describe that user
- 11:20are given the minimum permissions,
- 11:23not more, not less that are required to
- 11:27perform their
- 11:28duties. So, that they do not
- 11:32whether intentionally or unintentionally
- 11:35abuse their excess permissions.
- 11:39So, the purpose of this principle of
- 11:42least privilege is that it limits
- 11:44potential damage from accidental or
- 11:47malicious actions by restricting
- 11:50unnecessary privileges.
- 11:54So, how it is implemented? So, it is
- 11:56implemented by assigning permissions
- 11:58based on roles as we studied and
- 12:01regularly to review the access rights
- 12:04and enforce strict access controls.
- 12:10Ben- So, what are the benefits of least
- 12:14principle of least privilege?
- 12:16The benefit is that it reduces the
- 12:19security risk from compromised accounts.
- 12:22So, if account if an account of an
- 12:25employee is compromised, the least
- 12:28privilege will prevent it from having
- 12:31excessive
- 12:33uh damage because the account has the
- 12:36least privilege.
- 12:37It also limits the potential damage from
- 12:39insider threat. So, if there is
- 12:42an employee that is
- 12:46you can say insider trend threat due to
- 12:48any reason, you can say for example a
- 12:51disgruntled employee.
- 12:53So, if he or she wants to damage the
- 12:56organization intentionally, if
- 12:58uh his account or her account has the
- 13:01least privilege, the damage will be
- 13:04controlled and limited. It also
- 13:06simplifies auditing and compliance. So,
- 13:09how does it do? So, if an account has
- 13:12the limited privilege, we can say that
- 13:15if there is certain actions that are
- 13:18beyond that account privileges, so we
- 13:21can easily say that these actions are
- 13:23not attributed to to account. And it
- 13:26improves all our overall system
- 13:29stability.
- 13:32And our objective 3.2 and the last
- 13:36objective is to understand logical
- 13:39access controls.
- 13:43So, our first topic in this objective is
- 13:46the segregation of duties, another
- 13:48important topic in cybersecurity.
- 13:52So, segregation of duties is dividing
- 13:55critical task among multiple users to
- 13:58prevent fraud, errors, and unauthorized
- 14:01actions.
- 14:04And the purpose of segregation of duties
- 14:06is to ensure that no single individual
- 14:09has complete control over sensitive
- 14:12operations,
- 14:13thus reducing the insider threats.
- 14:17So, how it is implemented? It is
- 14:19implemented by dividing the
- 14:20responsibility. For example, if there is
- 14:23a process that has the request, approve,
- 14:26and execution. So, instead of giving all
- 14:29these functions to a single employee or
- 14:32a single role, these can be distributed
- 14:35among three different roles, and thus we
- 14:39will have the segregation of duties.
- 14:41And to enfor- enforce access controls to
- 14:45limit the overlapping privileges.
- 14:48Benefit of segregation of duties is that
- 14:51it enhances accountability. It deters
- 14:55the insider threat and strengthens
- 14:57overall security.
- 15:00So, an example of segregation of duties
- 15:03is it is frequently used in financial
- 15:06transactions. So, in a financial system,
- 15:08segregation of duties ensures that no
- 15:10single person can both initiate and
- 15:14approve a payment. So, for initiation,
- 15:17there will be a separate guy, and for
- 15:20approval, there will be
- 15:21a separate
- 15:23uh
- 15:23employee or role.
- 15:26So, for example, purchasing, so one
- 15:28employee is responsible for creating and
- 15:31submitting the purchasing order, so it
- 15:35may be this one.
- 15:37Then we have the payment processing, so
- 15:40a separate employee is then responsible
- 15:42for approving those purchase orders and
- 15:45issuing payments, for example, this one.
- 15:49And then uh for record keeping, a third
- 15:52employee or system reconciles the bank
- 15:55statements and records the transaction.
- 15:59So, for a single process, for example,
- 16:01if there is a requirement to purchase
- 16:04something, if we divide it into three
- 16:07separate duties
- 16:09that are assigned to three separate
- 16:11roles, thus we have segregation of
- 16:13duties.
- 16:14And in
- 16:16order
- 16:17to commit a fraud to purchase a
- 16:20fraudulent uh
- 16:23thing or to do a fraudulent purchasing,
- 16:26all these three
- 16:28must
- 16:30collaborate
- 16:31in order for this to take place, which
- 16:34is very difficult.
- 16:38So, what are some access control models?
- 16:40So, an access control model defines how
- 16:43decisions are made about who can access
- 16:46which resources and under what
- 16:48conditions.
- 16:50So, access control models help
- 16:52organization to control access
- 16:54consistently,
- 16:56help security, enforce security
- 16:58policies, apply the least privileges,
- 17:01and protect the sensitive information.
- 17:05So, common access control models include
- 17:08DAC, that is discretionary access
- 17:10control, mandatory access control, MAC,
- 17:13and role-based access control, RBAC, and
- 17:16attribute-based
- 17:18uh access control, that is a back.
- 17:22So what is the discretionary access
- 17:25control?
- 17:27That is that.
- 17:28So it is a flexible
- 17:30access control model where the owner
- 17:33of a resource determines who can access
- 17:36it and what action can they perform. So
- 17:40for example, if this is the owner of
- 17:42this resource, this owner can decide
- 17:46who are who which user are which group
- 17:49can have access to that resource.
- 17:52So
- 17:53the name suggests that it is at the
- 17:56discretion of the owner to grant the
- 17:59permission. So to remember it, remember
- 18:03that discretionary means it is at the
- 18:06discretion discretion of the owner to
- 18:08grant permission.
- 18:10So the key features are that the
- 18:12permissions are assigned at the
- 18:14discretion of the data owner rather than
- 18:16enforced by a central authority.
- 18:20So advantage of the system is that it is
- 18:23flexible and user-friendly.
- 18:26And drawbacks are that it is less
- 18:27secure. So as owner may grant excessive
- 18:31permission that will increase the risk
- 18:33of misuse.
- 18:35An example is that a file owner may
- 18:38grant or restrict read write access to
- 18:41specific users in an operating system
- 18:43such as Linux.
- 18:48The next access control model is the
- 18:51mandatory access control Mac. So this is
- 18:54a strict access control model where
- 18:56permissions are enforced by a central
- 18:59authority based on security
- 19:01classifications.
- 19:03Key features of this model are that
- 19:05users cannot change access permissions.
- 19:08Access is determined by system policies
- 19:11and security levels.
- 19:15Advantage of the system is that it is
- 19:17highly secure. So, this is more secure
- 19:19than the previous one, that is
- 19:21discretionary access control, and it
- 19:23minimizes the risk of unauthorized
- 19:25access.
- 19:27And drawbacks are that it is inflexible
- 19:30and it is complex to manage.
- 19:33An example is So, this is mostly used
- 19:35inside more secure environment such as
- 19:38military. So, a military system where
- 19:40documents are classified as
- 19:42confidential, secret, or top secret.
- 19:45And where you only users with the
- 19:47appropriate clearance can access them.
- 19:49So, the
- 19:51confidential documents, or you can say
- 19:54the top secret documents can only be
- 19:56accessed by users having the top
- 19:59clearance.
- 20:02And the next
- 20:04access control system, and an important
- 20:06one,
- 20:07is the role-based access control. So,
- 20:10remember we were studying a few slides
- 20:12back about the different roles
- 20:15that we can assign roles such as network
- 20:17administrator, database database
- 20:19administrator, HR manager. So, this type
- 20:23this access control system is used to
- 20:25manage that roles.
- 20:27So, this is a security model where
- 20:29access permissions are assigned based on
- 20:32a user's role within an organization.
- 20:36So, key feature of this model is that
- 20:38users inherit permission based on
- 20:41predefined role. For example, admin,
- 20:43manager, or an employee, which
- 20:46simplifies the access management.
- 20:50Advantage of this access control system
- 20:52is that it simplifies management, it
- 20:55improves scalability, and it ensures
- 20:57consistent access rights.
- 20:59So, as we studied, let's suppose if we
- 21:03have
- 21:05this admin hat,
- 21:07So,
- 21:08we define this role once. We give this
- 21:11role different permission, access to
- 21:14different resources. For example, here
- 21:15we have resource one, two, and three.
- 21:18So, this admin role has access to three
- 21:21resources. So, whenever there is a new
- 21:24user that require these permission, we
- 21:26will simply give this role to that user.
- 21:30An example, another
- 21:32uh if another employee or another user
- 21:34come, instead of defining all these
- 21:37permission again, we will assign him or
- 21:39her this role. So, that's why it
- 21:43improves scalability. You define it once
- 21:45and then you can assign it to hundred
- 21:47and thousands of employees. And it's
- 21:51also ensure consistency. So, all these
- 21:53admin employees will have the same
- 21:57permissions. It will not
- 21:59uh there will
- 22:00not thing like that that user one will
- 22:03have permission to four resources,
- 22:05and user two will have access to three
- 22:07or five resources. Both are all these
- 22:10employees under admin role will have
- 22:12access to same resources or they will
- 22:15have consistent access rights.
- 22:18So, drawback is that it require careful
- 22:20role design to avoid excessive
- 22:22permission. So, initially when the role
- 22:24is designed and the permission of
- 22:26permissions are given,
- 22:27the care should be taken that the
- 22:29permissions are
- 22:31as per the requirement. There are no
- 22:33excessive permissions.
- 22:37An example is that in a company, an HR
- 22:40manager can access employee records
- 22:42while an IT staff member can manage
- 22:45system configurations.
- 22:47So, that's all for this
- 22:50uh domain. I hope it has been uh
- 22:53informative. So, please like, subscribe,
- 22:56and stay tuned for the next domain. I
- 22:59will upload that video soon. See you
- 23:02soon in the next video.
About this transcript
This page contains the full transcript of ISC2 CC 2026 Complete Course | Updated Exam Outline – Domain 3 by Computer Networks Decoded , generated from the public captions YouTube serves with the video. The transcript has 2,785 words across 523 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.