Upgrade to Pro — share decks privately, control downloads, hide ads and more …

CISA Series - Domain 5 – Protection of Informat...

Sponsored · Ship Features Fearlessly Turn features on and off without deploys. Used by thousands of Ruby developers.

CISA Series - Domain 5 – Protection of Information Assets.

Welcome to Part 6A of the CISA Certification Series, where we begin exploring Domain 5 – Protection of Information Assets.

This domain is one of the most important and highest-weighted sections of the CISA exam, focusing on how organisations protect the confidentiality, integrity, and availability of information assets.
We look at key concepts including:

• Information security frameworks and standards
• Security governance and policies
• Data classification and ownership
• Access control concepts
• Physical and environmental security
• Identity and access management
• Security awareness and responsibilities
• Protection of information assets in modern environments

Avatar for Alison

Alison PRO

May 21, 2026

More Decks by Alison

Other Decks in Business

Transcript

  1. CISA Series – Part 6A Domain 5 Protection of Information

    Assets INFORMATION ASSET SECURITY AND CONTROL
  2. Key Takeaway Domain 5 Part A is all about protecting

    information assets through governance, access control, security architecture, and operational controls. The key concept to remember is that security is layered and interconnected and organizations must: • Establish frameworks, standards, policies, and procedures • Define ownership and accountability for information assets • Implement strong identity and access management • Protect networks, systems, mobile devices, and cloud environments • Classify and encrypt sensitive information • Apply monitoring, logging, and security baselines • Reduce risk through preventive controls and governance Next, we move into: Domain 5 — Part B: Security Event Management This section focuses on: •Threats and attack methods •Malware and cyber attacks •Security monitoring •IDS/IPS and SIEM •Incident response •Security testing •Threat intelligence •Digital forensics and evidence collection
  3. Disclaimer Based on practical experience and interpretation Not affiliated with

    any organization • Like • Share • Subscribe • Follow the series Thank You