What study approach did you take for CISSP -for anyon who has passed and had no exp.

in SSCP
Hi,
As title says im interested on study approaches taken by anyone who has passed the CISSP and did not have any/little infosec
experience before doing so.
Thanks
As title says im interested on study approaches taken by anyone who has passed the CISSP and did not have any/little infosec
experience before doing so.
Thanks
Comments
I know its not a bad book just not my reading style.
Example: Bell-LaPadula - no read up, no write down - why would you want to do this? Well, I wouldn't want someone without the appropriate clearance to read extremely sensitive data restricted for only specific people - so "no read up" makes sense.
Well what about writing down? So let's assume people with a high level of security clearance are communicating with one another and editing documentation. We must assume that the contents of their communication and documents they are working on are also extremely sensitive, and we wouldn't want to risk information leakage - so writing anything to a lower security level may cause data leakage or a security exposure, since anyone with less than that high level of security clearance could potentially see it. They could also begin to infer information - take the data they have access to at their security level, combine this data with the information that was unintentionally 'leaked' from a higher level - begins to paint a larger picture.