Think like a manager

Поділитися
Вставка
  • Опубліковано 31 січ 2025

КОМЕНТАРІ • 71

  • @CISSP-e5d
    @CISSP-e5d 6 місяців тому +1

    I've just done the cisa with a very good score and I can say one thing for sure: the mindset you're developing is the same as that for auditing. I started preparing for the CISSP a few days ago and I find it very similar to auditing. I hope to give you some good news in a few months' time.

    • @GwenBettwyTSI
      @GwenBettwyTSI  4 місяці тому

      There is definitely a common thread through these certs! Best of luck!

  • @RonWonkers
    @RonWonkers 4 місяці тому +1

    I passed CCSP this week on my first attempt! You were absolutely right, this test is really technical but it also has a lot of managerial questions. There were numerous examples of where I clicked the technical answer "Implement DLP/other tooling" but then saw the "Employee background check" or some other people answer. Ended up switching answers on a lot of questions and passed :).

    • @GwenBettwyTSI
      @GwenBettwyTSI  4 місяці тому +2

      That is terrific news! Congratulations!! I believe you have to spot those manager answers when they do show up, otherwise it is very hard to pass this test. Beyond that you really need to understand cloud technology to get through this one!

  • @nivethamathivanan3335
    @nivethamathivanan3335 10 місяців тому +1

    Thank you for the amazing content Gwen. These really helped get hang of the mindset. I have provisionally passed CISSP today.

    • @GwenBettwyTSI
      @GwenBettwyTSI  10 місяців тому

      Congratulations!!! So happy to have helped. 20 years of teaching CISSP I have found a few tricks that sure do help!

  • @ralphmelone8460
    @ralphmelone8460 10 місяців тому +1

    Hi Gwen. I want to thank you for this, and all your videos on the CISSP. I passed my test today. Your insights, tips, tricks on techniques on how to approach questions and answers were invaluable. I found you to be correct, the vast majority of the questions could be answered from a management perspective ( a business & security management perspective). Thanks again!!

    • @GwenBettwyTSI
      @GwenBettwyTSI  10 місяців тому

      Congratulations!!!! So glad you found my video before the test!

  • @billkim8814
    @billkim8814 10 місяців тому +2

    Thanks Gwen, I just passed CISSP provisionally yesterday and I appreciate your Video . Exam was totally different from the practice test but it helped 😂

  • @nickybesters
    @nickybesters 2 роки тому +10

    Nice collection of tips! Also, Luke Ahmed has a book called How To Think Like a Manager which aspiring CISSPs might be interested in.

    • @GwenBettwyTSI
      @GwenBettwyTSI  Рік тому +2

      I do have a think like a manager video here on youtube as well

  • @faheemtayyab3416
    @faheemtayyab3416 Рік тому +1

    Great content. Watched your video yesterday and today I passed cissp. Thank you

  • @mainHERO88
    @mainHERO88 8 місяців тому +1

    Bookmarking 34:52 for remembering the order! Great video!!!

  • @netsnower
    @netsnower Рік тому +1

    GREAT video on CISSP, CCSP test taking tips. It helps get my head on focused on how to approach the exam day

  • @macleank9678
    @macleank9678 2 роки тому +3

    This video was the last one I watched and I passed today. Thanks Gwen

  • @pudgespracticalposts342
    @pudgespracticalposts342 6 місяців тому

    I felt like I bombed CISSP last year and walked out with a pass! Today, I took CCSP and didn’t even get close…and didn’t feel like I did when I completed CISSP, which is to say Dread! Oh well, bought peace of mind and test again in September. Your classes taught me a lot though, so this is clearly my problem!

    • @GwenBettwyTSI
      @GwenBettwyTSI  4 місяці тому

      Consider one of my live classes so that I can help you figure out where your thinking/logic/learning needs to go.

  • @CyberDuece
    @CyberDuece 2 роки тому +2

    Great job as always, thank you for sharing.

  • @waseemal3951
    @waseemal3951 2 роки тому

    I came across this video. Im planning on taking the CISSP in 2 weeks. thanks for this. Hopefully it will help me.

  • @Dogrescuerules
    @Dogrescuerules 2 роки тому

    I failed the CISSP test a year ago, and now have another year of studying. Will try for Jan-Feb again. Appreciate your videos.

    • @GwenBettwyTSI
      @GwenBettwyTSI  2 роки тому

      Thank you and best wishes.

    • @frob530
      @frob530 2 роки тому

      Did you pass ?

    • @Dogrescuerules
      @Dogrescuerules 2 роки тому

      @@frob530 Hi, I am taking the exam April . Spending 2 years on this LOL. I want to know this material like there is no tomorrow 🙏

    • @xpcyberARP
      @xpcyberARP Рік тому +1

      @@Dogrescuerules You pass? lol

  • @yolo12999
    @yolo12999 5 місяців тому

    Thanks Gwen, I passed my CISSP yesterday.

  • @2lotsill
    @2lotsill Рік тому +1

    This is what I was told “put on your CEO hat” answer the question as CEO. Should the answer that down at make sense.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    44:50 Two framed photos on the wall behind you caught my eye, maybe because I am a cocky lone wolf 😄

  • @kalumranatunga8029
    @kalumranatunga8029 2 роки тому

    appreciate ..,great it is helpings me lot
    ..,

  • @tdub1013
    @tdub1013 2 роки тому +3

    This is GOLD!

    • @GwenBettwyTSI
      @GwenBettwyTSI  2 роки тому

      Thanks for leaving a comment! I am glad it was helpful!

  • @peterkarumuna2451
    @peterkarumuna2451 2 роки тому +1

    Excellent !

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    37:19 Indeed. Treat them with respect, support them, and make them loyal to your enterprise. If you want to be cynical about it, it’s safer and cheaper in the long run.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    12:24 I don’t know much about it, but the MFA systems are not infallible.
    I was reading yesterday about Kerberos, and even I (not being particularly smart and definitely not knowledgeable) could see it’s vulnerable. What good is it to rely so much on an authentication server that checks credentials with a database that has had a SQL injection? The SSO that embodies the accessibility principle at the detriment of integrity and confidentiality (since when putting all your eggs in one basket is safe practice?).
    As I said, I don’t know all the terminology, but I hope you will understand the idea.

  • @RonWonkers
    @RonWonkers Рік тому

    Thanks for the video! I passed CISSP 1st try on 140 questions

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    17:34 It is a genuinely good idea to make everyone (and I mean everyone) in an organisation more aware of risks, safety, and being money wise, BUT not at the detriment of other things. Money and technicalities of any safety system are contingent on threats, business landscape, how good you are at playing the money making game. Other things are not contingent on externalities. It’s like a human body- if its immunity is good, it can fend off all sorts of infections. Whereas your security paradigm is mostly reactive, for what I could gather, that’s why Zero Days happen. A virus in your system causes a devastating pandemic because your employees don’t know how to cyber wash their hands properly etc.

  • @sanchitjain0007
    @sanchitjain0007 Рік тому

    Is it just me or it goes blank after 51:00?

  • @macleank9678
    @macleank9678 2 роки тому

    Can we get some CRISC videos from you? thanks

    • @GwenBettwyTSI
      @GwenBettwyTSI  2 роки тому +3

      Maybe someday. I have never done anything with CRISC. I do have a risk book in the works... so maybe someday.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    10:36 I wholeheartedly agree. But my definition of ‘wisely’ doesn’t fit with the common nonsense. What do you invest in? Expensive software, pentesting services, fancy physical security devices? How much less money would you have spent had you invested in people’s training and attitudes? That’s why I’m saying your paradigm is myopic.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    26:20 That’s where the risks assessments are flawed. Take Mitre Att&ck which is a superb endeavour. It cannot help you assess unknown risks and prepare properly (maybe against script kiddies attacks and other small hacker fish).
    All you can reliably assess is your defences. What do all successful attacks have in common? Or, better put, why are they successful? (*Hint* the first and most important layer of the answer is non- technical).

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    39:20 😃 I like your style.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    13:37 Get your priorities right! First and foremost the human wellbeing which includes the lives of people in a hospital, so if you’re a boss who makes money off the backs of ill people, at least you could pay due diligence and part with a part of your profit to ensure that you don’t put their lives in danger by allowing a ransomware attack. Those money greedy CEOs should face criminal prosecution and not be allowed to settle in court by paying their weekly coffee budget.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    27:33 There are sectors that should not be left at their own devices, at the whim of irresponsible corporate managers. Take the energy sector, transport, water supply, healthcare, telecommunications- they should be recognised for what they are i.e. critical infrastructure. Imagine a big water supply company being hacked into. Or a biolab database being compromised (modifying data would be worse than stealing it for corporate espionage purposes).

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    35:27 What for?
    Just to pass this test or the GRC bit of an audit?…

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    4:41 Accessibility principle.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    50:39 I wish. Unfortunately, small people like me are at the mercy of idiots, so it becomes personal.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    9:43 Oh, so it is about people. Allegedly.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    24:42 Yeah, video streaming. I was thinking about that, actually, when I read yesterday about UDP which I understand is much less safe than TCP. In all fairness, ensuring integrity via using HTTPS and TCP is kinda obsolete in the age of deepfakes. Maybe Communication science should not be divorced from the Information Technology.
    PS- I am not referring to your video. I don’t know who you really are, but I think that you are a highly intelligent lady with loads of experience. My criticism pertains to this damned test.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    14:15 What is the average amount paid for a ransomware attack? I don’t know, let’s say $500,000. Spending $499,999 on developing your immunity to attacks by training and checking your staff’s attitudes and safety- related behaviour, sacking a few bad apples, and continuously helping the individuals to attain maturity and good posture is still cheaper.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    0:53 I do, but I don’t like it. Which makes me doubt I will ever work for such managers. Is this test an empathy test? It should test knowledge, attitudes, and cognitive resilience. But not like that- not telling the candidates what they’re tested for. It’s patronising, disrespectful, and dishonest- are these qualities that are part of a manager’s job description? Now I know what job descriptions I will weed out.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    5:45 I want to help them, but they don’t want to be helped because their big egos get in the way. Very well, then, suit yourselves.
    And talking about being rude- isn’t it rude to test people in a covert manner? Isn’t permission based on transparency the thing that makes the difference between pentesting and hacking? Why is psychological hacking, then, allowed? What are the candidates- criminals interrogated by FBI?

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    23:05 Accessibility or marketing? 😏 Up to this point you haven’t said anything confidential.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому

    8:15 Lady, that’s nonsense. Had you discussed something confidential in this call you would have not allowed just everyone to join in, uploaded it on UA-cam,
    etc.

  • @claudiamanta1943
    @claudiamanta1943 9 місяців тому +1

    4:02 No. If you care about people, you care about your colleagues, your clients, and about your dumbarse CEO who has no clue about anything but the bank accounts and ‘networking’ whilst playing golf with other muppets in high positions. If you do care about people, you will do the technical bits related to security. If you don’t, you won’t. Even worse, not cultivating this attitude leads to inside threats. It’s an idiotic and myopic management strategy.