YouTube2Text

ISC2 CC 2026 Complete Course | Updated Exam Outline – Domain 3 — Transcript

by Computer Networks Decoded · 2,785 words · 523 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Welcome to the updated (ISC)² Certified
  2. 0:03in Cybersecurity course. Due to the
  3. 0:06overwhelming response [music] to my
  4. 0:08previous (ISC)² CC course, which has
  5. 0:11helped hundreds of learners successfully
  6. 0:14prepare for and pass their exam, I am
  7. 0:18excited to bring you this completely
  8. 0:20updated course.
  9. 0:22This course has been carefully prepared
  10. 0:24according to the latest (ISC)² CC exam
  11. 0:27outline, effective September 1st, 2026,
  12. 0:30[music]
  13. 0:32covering the new domains, objectives,
  14. 0:34and updated exam content.
  15. 0:37So, whether you are completely new to
  16. 0:39the cybersecurity [music]
  17. 0:40or preparing to earn your (ISC)² CC
  18. 0:43certification, this course will guide
  19. 0:45you through the concepts [music] you
  20. 0:47need to know in a simple, practical, and
  21. 0:50exam-focused way.
  22. 0:52So, let's get started and prepare for
  23. 0:54the updated (ISC)² [music] CC exam
  24. 0:57together.
  25. 1:01Hello everyone, and welcome to the
  26. 1:04domain three of our course, Identity and
  27. 1:08Access Management Concepts.
  28. 1:11This is a short and brief domain, and a
  29. 1:14very straightforward.
  30. 1:16So, let's get started, and our objective
  31. 1:193.1 is Understand Identity Lifecycle
  32. 1:23Management.
  33. 1:26Our first topic is roles definition.
  34. 1:29What are roles? So, before we grant
  35. 1:32access, an organization should define
  36. 1:35roles and responsibilities.
  37. 1:38So, when there is a new employee or when
  38. 1:42there is a promotion of an existing
  39. 1:44employee, and a certain role is given to
  40. 1:48that employee, we should have
  41. 1:51certain criteria that this role can do
  42. 1:54this and that, and this is his or her
  43. 1:57responsibility.
  44. 1:59So, we should have these things defined.
  45. 2:03So, a role describe the functions a user
  46. 2:06can perform and the access required to
  47. 2:09perform those functions.
  48. 2:12For example, these are different roles
  49. 2:15that we may see in our organization.
  50. 2:18Some organization may have more than
  51. 2:20these roles. Some organization may have
  52. 2:22less.
  53. 2:23So, these roles include the human
  54. 2:25resource manager. This is almost present
  55. 2:28everywhere. And inside the IT, we have
  56. 2:31the network administrator, the database
  57. 2:33administrator,
  58. 2:34a security analyst, a finance employee.
  59. 2:38So, things like that. So, these are
  60. 2:40different roles. Uh you can say these
  61. 2:43are different hats
  62. 2:45that employees can wear. So, instead of
  63. 2:48giving each employee, let's suppose you
  64. 2:51have five network administrator, so
  65. 2:54instead of defining
  66. 2:56the permissions for each and
  67. 2:59employee individually,
  68. 3:01we do that for this network
  69. 3:03administrator role. So, whenever there
  70. 3:06is a network administrator, we give him
  71. 3:09or her that role. And that role already
  72. 3:12contain the required
  73. 3:14permissions and responsibility are the
  74. 3:16access that that
  75. 3:18person can have.
  76. 3:21So, this is an efficient way of managing
  77. 3:24the access to resources
  78. 3:27instead of manually assigning these
  79. 3:30permission to each individual each
  80. 3:33individual employee.
  81. 3:35So, for example, when a finance employee
  82. 3:38require access to accounting system, he
  83. 3:40or she is given access to that system
  84. 3:43only.
  85. 3:44But that doesn't mean that they also
  86. 3:46receive the administrative access to
  87. 3:48network devices. So, the administrative
  88. 3:51access to network devices maybe defined
  89. 3:53with that role.
  90. 3:55And the accounting system permissions
  91. 3:58maybe defined in that role. So, that
  92. 4:01employee will be given that hat, and
  93. 4:04that hat will not contain access to
  94. 4:07database or to network or to other
  95. 4:10security systems.
  96. 4:14So, provisioning is the first step in
  97. 4:16the identity and access management, and
  98. 4:19it is the process of creating an
  99. 4:21identity and providing the user with the
  100. 4:24access required to perform their job.
  101. 4:28So, the provisioning may include
  102. 4:30creating the user account for the
  103. 4:32employee, assigning an identity. So, an
  104. 4:35identity may be the username
  105. 4:38or the user ID, assigning roles. For
  106. 4:41example, if he is
  107. 4:43uh a network guy, so he may be assigned
  108. 4:46the role of the network administrator.
  109. 4:49So, granting permission. So, the
  110. 4:51permission will automatically come with
  111. 4:53that role. Providing access to
  112. 4:56applications.
  113. 4:57Then, we may have different applications
  114. 5:00such as
  115. 5:01let's suppose uh for his HR-related
  116. 5:04activities to check on his attendance,
  117. 5:08et cetera, he may be given
  118. 5:10a read-only access to the HR application
  119. 5:13and other portals.
  120. 5:15And similarly, issuing the
  121. 5:17authentication credentials. So,
  122. 5:19authentication credential is again the
  123. 5:21username plus the password.
  124. 5:26User ID plus
  125. 5:28password. So, these are the
  126. 5:29authentication credential.
  127. 5:33Access review. So, this is an important
  128. 5:36topic with respect to cybersecurity.
  129. 5:39So, what is this? So, user access should
  130. 5:42be periodically reviewed to ensure that
  131. 5:45it remains appropriate.
  132. 5:48So, access review can identify so why
  133. 5:51this access review is done? It is done
  134. 5:53to identify excessive permissions. So,
  135. 5:56some employee may have gotten excessive
  136. 5:58permissions that are beyond their roles
  137. 6:02are beyond the permission that are
  138. 6:04required to perform their duties. Some
  139. 6:08where me we may encounter some unused
  140. 6:10accounts. So, these may be of the
  141. 6:12employees that have left the job or that
  142. 6:15have been transferred to another
  143. 6:17department. So, there may be unused
  144. 6:19account.
  145. 6:20So, in access review, we should then
  146. 6:23delete or disable them. Inappropriate
  147. 6:25access again, as we said, the network
  148. 6:28administrator may have access to the
  149. 6:30database as well.
  150. 6:32Role changes. So, if there are role
  151. 6:35changes, for example, an engineer may be
  152. 6:38promoted to a manager role. So, the
  153. 6:41access review should review those things
  154. 6:44that this role does not have the
  155. 6:46previous
  156. 6:47permissions. Privilege accumulation. So,
  157. 6:50this is a related thing that when
  158. 6:53employee
  159. 6:54goes from one department to another or
  160. 6:56got promoted and the previous
  161. 6:59permissions are the previous access is
  162. 7:01not de-provisioned, it may accumulate
  163. 7:05over time.
  164. 7:07And again, the orphaned account is the
  165. 7:10same concept that there may be some
  166. 7:13account
  167. 7:14that are left unused due to their
  168. 7:20employee being promoted or being
  169. 7:23transferred to another department.
  170. 7:26An example is when an employee is moved
  171. 7:28from finance department to IT 6 months
  172. 7:31ago, but he or she still has access to
  173. 7:34the financial reporting system. So, that
  174. 7:37is a role of privilege accumulation. So,
  175. 7:40now that employee has access both to the
  176. 7:43IT as well as financial
  177. 7:46application which is not as per his
  178. 7:49current role.
  179. 7:52So, what is the deprovisioning? So, this
  180. 7:54is the life cycle we are talking about.
  181. 7:56First, we have the provisioning, then
  182. 8:00the usage of those accounts, then
  183. 8:01periodic access review, and the last one
  184. 8:04is the deprovisioning when the account
  185. 8:06are
  186. 8:07the roles are no longer required.
  187. 8:10So, deprovisioning is the process of
  188. 8:12removing or disabling a user's access
  189. 8:14when it is no longer required.
  190. 8:17So, common triggers for deprovisioning
  191. 8:19may include the employee termination,
  192. 8:22employee resignation,
  193. 8:25role changes,
  194. 8:27and contract expiration. So, these are
  195. 8:29some of the triggers that will require
  196. 8:32the deprovisioning of the
  197. 8:35access.
  198. 8:37So, deprovisioning may include disabling
  199. 8:39the user account, revoking the
  200. 8:41application access, removing the account
  201. 8:44group membership, and revoking the
  202. 8:47privileged access.
  203. 8:50So, what are some identity and access
  204. 8:53management framework? So, organization
  205. 8:56can use established framework and
  206. 8:58standards to guide identity and access
  207. 9:01management.
  208. 9:03For example,
  209. 9:05a framework that organization may use is
  210. 9:08NIST SP 800-63.
  211. 9:12So, this framework provides guidance
  212. 9:14related to digital identity and identity
  213. 9:17proofing, authentication, and
  214. 9:20federation.
  215. 9:22Another is the NIST
  216. 9:24cybersecurity framework. So, this one
  217. 9:27provides a broader cybersecurity risk
  218. 9:29management framework that includes
  219. 9:31identity and access related practices.
  220. 9:38Now, coming over to some identity and
  221. 9:40access management tools. So,
  222. 9:42organization use identity and access
  223. 9:45management tools and technology to
  224. 9:47manage the identities and access inside
  225. 9:51their organizations.
  226. 9:53The common identity and access
  227. 9:55management capabilities, technologies,
  228. 9:57or tools include the
  229. 10:00uh
  230. 10:01user account management. So, these are
  231. 10:03the different capabilities that you can
  232. 10:06do using these technologies and tools.
  233. 10:08So, you can uh use these technology and
  234. 10:11tools for user account management,
  235. 10:14authentication, authorization, role
  236. 10:17management, access provisioning, access
  237. 10:20review, and deprovisioning. So, these
  238. 10:22are all the
  239. 10:24uh you can say capabilities
  240. 10:27or the practices that we studied. So, we
  241. 10:31have different type of tools that give
  242. 10:33us all the capabilities that are inside
  243. 10:37the identity and access management life
  244. 10:39cycle.
  245. 10:41So, some common tools or technologies
  246. 10:44for identity and access management
  247. 10:46include directory services.
  248. 10:48We have different identity providers and
  249. 10:51access management platform.
  250. 10:55Another important and related topic is
  251. 10:58the principle of least privilege.
  252. 11:03So, principle of least privilege is a
  253. 11:05user and system are granted only the
  254. 11:09minimum necessary access to perform
  255. 11:11their tasks, reducing the security risk.
  256. 11:16So, as the word least describe that user
  257. 11:20are given the minimum permissions,
  258. 11:23not more, not less that are required to
  259. 11:27perform their
  260. 11:28duties. So, that they do not
  261. 11:32whether intentionally or unintentionally
  262. 11:35abuse their excess permissions.
  263. 11:39So, the purpose of this principle of
  264. 11:42least privilege is that it limits
  265. 11:44potential damage from accidental or
  266. 11:47malicious actions by restricting
  267. 11:50unnecessary privileges.
  268. 11:54So, how it is implemented? So, it is
  269. 11:56implemented by assigning permissions
  270. 11:58based on roles as we studied and
  271. 12:01regularly to review the access rights
  272. 12:04and enforce strict access controls.
  273. 12:10Ben- So, what are the benefits of least
  274. 12:14principle of least privilege?
  275. 12:16The benefit is that it reduces the
  276. 12:19security risk from compromised accounts.
  277. 12:22So, if account if an account of an
  278. 12:25employee is compromised, the least
  279. 12:28privilege will prevent it from having
  280. 12:31excessive
  281. 12:33uh damage because the account has the
  282. 12:36least privilege.
  283. 12:37It also limits the potential damage from
  284. 12:39insider threat. So, if there is
  285. 12:42an employee that is
  286. 12:46you can say insider trend threat due to
  287. 12:48any reason, you can say for example a
  288. 12:51disgruntled employee.
  289. 12:53So, if he or she wants to damage the
  290. 12:56organization intentionally, if
  291. 12:58uh his account or her account has the
  292. 13:01least privilege, the damage will be
  293. 13:04controlled and limited. It also
  294. 13:06simplifies auditing and compliance. So,
  295. 13:09how does it do? So, if an account has
  296. 13:12the limited privilege, we can say that
  297. 13:15if there is certain actions that are
  298. 13:18beyond that account privileges, so we
  299. 13:21can easily say that these actions are
  300. 13:23not attributed to to account. And it
  301. 13:26improves all our overall system
  302. 13:29stability.
  303. 13:32And our objective 3.2 and the last
  304. 13:36objective is to understand logical
  305. 13:39access controls.
  306. 13:43So, our first topic in this objective is
  307. 13:46the segregation of duties, another
  308. 13:48important topic in cybersecurity.
  309. 13:52So, segregation of duties is dividing
  310. 13:55critical task among multiple users to
  311. 13:58prevent fraud, errors, and unauthorized
  312. 14:01actions.
  313. 14:04And the purpose of segregation of duties
  314. 14:06is to ensure that no single individual
  315. 14:09has complete control over sensitive
  316. 14:12operations,
  317. 14:13thus reducing the insider threats.
  318. 14:17So, how it is implemented? It is
  319. 14:19implemented by dividing the
  320. 14:20responsibility. For example, if there is
  321. 14:23a process that has the request, approve,
  322. 14:26and execution. So, instead of giving all
  323. 14:29these functions to a single employee or
  324. 14:32a single role, these can be distributed
  325. 14:35among three different roles, and thus we
  326. 14:39will have the segregation of duties.
  327. 14:41And to enfor- enforce access controls to
  328. 14:45limit the overlapping privileges.
  329. 14:48Benefit of segregation of duties is that
  330. 14:51it enhances accountability. It deters
  331. 14:55the insider threat and strengthens
  332. 14:57overall security.
  333. 15:00So, an example of segregation of duties
  334. 15:03is it is frequently used in financial
  335. 15:06transactions. So, in a financial system,
  336. 15:08segregation of duties ensures that no
  337. 15:10single person can both initiate and
  338. 15:14approve a payment. So, for initiation,
  339. 15:17there will be a separate guy, and for
  340. 15:20approval, there will be
  341. 15:21a separate
  342. 15:23uh
  343. 15:23employee or role.
  344. 15:26So, for example, purchasing, so one
  345. 15:28employee is responsible for creating and
  346. 15:31submitting the purchasing order, so it
  347. 15:35may be this one.
  348. 15:37Then we have the payment processing, so
  349. 15:40a separate employee is then responsible
  350. 15:42for approving those purchase orders and
  351. 15:45issuing payments, for example, this one.
  352. 15:49And then uh for record keeping, a third
  353. 15:52employee or system reconciles the bank
  354. 15:55statements and records the transaction.
  355. 15:59So, for a single process, for example,
  356. 16:01if there is a requirement to purchase
  357. 16:04something, if we divide it into three
  358. 16:07separate duties
  359. 16:09that are assigned to three separate
  360. 16:11roles, thus we have segregation of
  361. 16:13duties.
  362. 16:14And in
  363. 16:16order
  364. 16:17to commit a fraud to purchase a
  365. 16:20fraudulent uh
  366. 16:23thing or to do a fraudulent purchasing,
  367. 16:26all these three
  368. 16:28must
  369. 16:30collaborate
  370. 16:31in order for this to take place, which
  371. 16:34is very difficult.
  372. 16:38So, what are some access control models?
  373. 16:40So, an access control model defines how
  374. 16:43decisions are made about who can access
  375. 16:46which resources and under what
  376. 16:48conditions.
  377. 16:50So, access control models help
  378. 16:52organization to control access
  379. 16:54consistently,
  380. 16:56help security, enforce security
  381. 16:58policies, apply the least privileges,
  382. 17:01and protect the sensitive information.
  383. 17:05So, common access control models include
  384. 17:08DAC, that is discretionary access
  385. 17:10control, mandatory access control, MAC,
  386. 17:13and role-based access control, RBAC, and
  387. 17:16attribute-based
  388. 17:18uh access control, that is a back.
  389. 17:22So what is the discretionary access
  390. 17:25control?
  391. 17:27That is that.
  392. 17:28So it is a flexible
  393. 17:30access control model where the owner
  394. 17:33of a resource determines who can access
  395. 17:36it and what action can they perform. So
  396. 17:40for example, if this is the owner of
  397. 17:42this resource, this owner can decide
  398. 17:46who are who which user are which group
  399. 17:49can have access to that resource.
  400. 17:52So
  401. 17:53the name suggests that it is at the
  402. 17:56discretion of the owner to grant the
  403. 17:59permission. So to remember it, remember
  404. 18:03that discretionary means it is at the
  405. 18:06discretion discretion of the owner to
  406. 18:08grant permission.
  407. 18:10So the key features are that the
  408. 18:12permissions are assigned at the
  409. 18:14discretion of the data owner rather than
  410. 18:16enforced by a central authority.
  411. 18:20So advantage of the system is that it is
  412. 18:23flexible and user-friendly.
  413. 18:26And drawbacks are that it is less
  414. 18:27secure. So as owner may grant excessive
  415. 18:31permission that will increase the risk
  416. 18:33of misuse.
  417. 18:35An example is that a file owner may
  418. 18:38grant or restrict read write access to
  419. 18:41specific users in an operating system
  420. 18:43such as Linux.
  421. 18:48The next access control model is the
  422. 18:51mandatory access control Mac. So this is
  423. 18:54a strict access control model where
  424. 18:56permissions are enforced by a central
  425. 18:59authority based on security
  426. 19:01classifications.
  427. 19:03Key features of this model are that
  428. 19:05users cannot change access permissions.
  429. 19:08Access is determined by system policies
  430. 19:11and security levels.
  431. 19:15Advantage of the system is that it is
  432. 19:17highly secure. So, this is more secure
  433. 19:19than the previous one, that is
  434. 19:21discretionary access control, and it
  435. 19:23minimizes the risk of unauthorized
  436. 19:25access.
  437. 19:27And drawbacks are that it is inflexible
  438. 19:30and it is complex to manage.
  439. 19:33An example is So, this is mostly used
  440. 19:35inside more secure environment such as
  441. 19:38military. So, a military system where
  442. 19:40documents are classified as
  443. 19:42confidential, secret, or top secret.
  444. 19:45And where you only users with the
  445. 19:47appropriate clearance can access them.
  446. 19:49So, the
  447. 19:51confidential documents, or you can say
  448. 19:54the top secret documents can only be
  449. 19:56accessed by users having the top
  450. 19:59clearance.
  451. 20:02And the next
  452. 20:04access control system, and an important
  453. 20:06one,
  454. 20:07is the role-based access control. So,
  455. 20:10remember we were studying a few slides
  456. 20:12back about the different roles
  457. 20:15that we can assign roles such as network
  458. 20:17administrator, database database
  459. 20:19administrator, HR manager. So, this type
  460. 20:23this access control system is used to
  461. 20:25manage that roles.
  462. 20:27So, this is a security model where
  463. 20:29access permissions are assigned based on
  464. 20:32a user's role within an organization.
  465. 20:36So, key feature of this model is that
  466. 20:38users inherit permission based on
  467. 20:41predefined role. For example, admin,
  468. 20:43manager, or an employee, which
  469. 20:46simplifies the access management.
  470. 20:50Advantage of this access control system
  471. 20:52is that it simplifies management, it
  472. 20:55improves scalability, and it ensures
  473. 20:57consistent access rights.
  474. 20:59So, as we studied, let's suppose if we
  475. 21:03have
  476. 21:05this admin hat,
  477. 21:07So,
  478. 21:08we define this role once. We give this
  479. 21:11role different permission, access to
  480. 21:14different resources. For example, here
  481. 21:15we have resource one, two, and three.
  482. 21:18So, this admin role has access to three
  483. 21:21resources. So, whenever there is a new
  484. 21:24user that require these permission, we
  485. 21:26will simply give this role to that user.
  486. 21:30An example, another
  487. 21:32uh if another employee or another user
  488. 21:34come, instead of defining all these
  489. 21:37permission again, we will assign him or
  490. 21:39her this role. So, that's why it
  491. 21:43improves scalability. You define it once
  492. 21:45and then you can assign it to hundred
  493. 21:47and thousands of employees. And it's
  494. 21:51also ensure consistency. So, all these
  495. 21:53admin employees will have the same
  496. 21:57permissions. It will not
  497. 21:59uh there will
  498. 22:00not thing like that that user one will
  499. 22:03have permission to four resources,
  500. 22:05and user two will have access to three
  501. 22:07or five resources. Both are all these
  502. 22:10employees under admin role will have
  503. 22:12access to same resources or they will
  504. 22:15have consistent access rights.
  505. 22:18So, drawback is that it require careful
  506. 22:20role design to avoid excessive
  507. 22:22permission. So, initially when the role
  508. 22:24is designed and the permission of
  509. 22:26permissions are given,
  510. 22:27the care should be taken that the
  511. 22:29permissions are
  512. 22:31as per the requirement. There are no
  513. 22:33excessive permissions.
  514. 22:37An example is that in a company, an HR
  515. 22:40manager can access employee records
  516. 22:42while an IT staff member can manage
  517. 22:45system configurations.
  518. 22:47So, that's all for this
  519. 22:50uh domain. I hope it has been uh
  520. 22:53informative. So, please like, subscribe,
  521. 22:56and stay tuned for the next domain. I
  522. 22:59will upload that video soon. See you
  523. 23:02soon in the next video.

About this transcript

This page contains the full transcript of ISC2 CC 2026 Complete Course | Updated Exam Outline – Domain 3 by Computer Networks Decoded , generated from the public captions YouTube serves with the video. The transcript has 2,785 words across 523 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.