Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Certificate
Course Outline
DOMAIN 1: CYBERSECURITY CONCEPTS
- 1.1 Understanding information assurance (IA) principles applied to managing risks associated with the use, processing, storage, and transmission of information or data.
- 1.2 Familiarity with security management practices.
- 1.3 Understanding of risk management processes, including the steps and methods used for risk assessment.
- 1.4 Awareness of the organization’s enterprise information technology (IT) goals and objectives.
- 1.5 Knowledge of distinct operational threat environments, such as first-generation (script kiddies), second-generation (non-state-sponsored), and third-generation (state-sponsored) actors.
- 1.6 Understanding IA principles and organizational requirements related to confidentiality, integrity, availability, authentication, and non-repudiation.
- 1.7 Awareness of common adversary tactics, techniques, and procedures (TTPs) within areas of responsibility, including historical country-specific TTPs and emerging capabilities.
- 1.8 Knowledge of various attack classifications, including passive, active, insider, close-in, and distribution attacks.
- 1.9 Understanding of relevant laws, policies, procedures, and governance requirements.
- 1.10 Awareness of legal, policy, and governance frameworks relating to work that may impact critical infrastructure.
DOMAIN 2: CYBERSECURITY ARCHITECTURE PRINCIPLES
- 2.1 Understanding network design processes, including security objectives, operational goals, and associated tradeoffs.
- 2.2 Familiarity with security system design methods, tools, and techniques.
- 2.3 Knowledge of network access and identity and access management, including public key infrastructure (PKI).
- 2.4 Understanding IT security principles and methods, such as firewalls, demilitarized zones (DMZs), and encryption.
- 2.5 Knowledge of current industry methods for evaluating, implementing, and disseminating IT security assessment, monitoring, detection, and remediation tools, utilizing standards-based concepts.
- 2.6 Understanding network security architecture concepts, including topology, protocols, components, and principles like defense in depth.
- 2.7 Knowledge of malware analysis concepts and methodologies.
- 2.8 Familiarity with intrusion detection methodologies and techniques for identifying host- and network-based intrusions.
- 2.9 Understanding defense in depth principles and network security architecture.
- 2.10 Knowledge of encryption algorithms, such as Internet Protocol Security (IPSec), Advanced Encryption Standard (AES), and Generic Routing Encapsulation (GRE).
- 2.11 Understanding of cryptology.
- 2.12 Knowledge of encryption methodologies.
- 2.13 Understanding how traffic flows across networks, including Transmission Control Protocol and Internet Protocol (TCP/IP) and the Open Systems Interconnection (OSI) model.
- 2.14 Knowledge of network protocols, including TCP/IP
DOMAIN 3: SECURITY OF NETWORK, SYSTEM, APPLICATION AND DATA
- 3.1 Understanding computer network defense (CND) and vulnerability assessment tools, including open-source options and their capabilities.
- 3.2 Knowledge of basic system administration, as well as network and operating system hardening techniques.
- 3.3 Understanding the risks associated with virtualization.
- 3.4 Familiarity with penetration testing principles, tools, and techniques, such as Metasploit and NeoSploit.
- 3.5 Understanding network systems management principles, models, methods (e.g., end-to-end performance monitoring), and tools.
- 3.6 Knowledge of remote access technology concepts.
- 3.7 Understanding systems administration concepts.
- 3.8 Familiarity with the Unix command line.
- 3.9 Knowledge of system and application security threats and vulnerabilities.
- 3.10 Understanding system lifecycle management principles, including software security and usability.
- 3.11 Knowledge of local specialized system requirements, such as critical infrastructure systems that may not use standard IT for safety, performance, and reliability.
- 3.12 Knowledge of specific system and application security threats and vulnerabilities, including buffer overflows, mobile code, cross-site scripting, PL/SQL injections, race conditions, covert channels, replay attacks, return-oriented attacks, and malicious code.
- 3.13 Understanding the social dynamics of computer attackers in a global context.
- 3.14 Familiarity with secure configuration management techniques.
- 3.15 Knowledge of the capabilities and applications of network equipment, including hubs, routers, switches, bridges, servers, transmission media, and related hardware.
- 3.16 Understanding communication methods, principles, and concepts that support network infrastructure.
- 3.17 Knowledge of common networking protocols (e.g., TCP/IP) and services (e.g., web, mail, DNS) and how they interact to enable network communication.
- 3.18 Understanding different types of network communication, such as LAN, WAN, MAN, WLAN, and WWAN.
- 3.19 Knowledge of virtualization technologies and the development and maintenance of virtual machines.
- 3.20 Understanding application vulnerabilities.
- 3.21 Knowledge of IA principles and methods applicable to software development.
- 3.22 Familiarity with risk threat assessment.
DOMAIN 4: INCIDENT RESPONSE
- 4.1 Understanding incident categories, response protocols, and response timelines.
- 4.2 Knowledge of disaster recovery and business continuity plans.
- 4.3 Understanding data backup types (e.g., full, incremental) and recovery concepts and tools.
- 4.4 Familiarity with incident response and handling methodologies.
- 4.5 Knowledge of security event correlation tools.
- 4.6 Understanding the investigative implications of hardware, operating systems, and network technologies.
- 4.7 Knowledge of processes for seizing and preserving digital evidence, such as maintaining the chain of custody.
- 4.8 Understanding types of digital forensics data and how to identify them.
- 4.9 Knowledge of basic concepts and practices for processing digital forensic data.
- 4.10 Familiarity with anti-forensics tactics, techniques, and procedures (TTPs).
- 4.11 Knowledge of common forensic tool configuration and support applications, such as VMware and Wireshark.
- 4.12 Understanding network traffic analysis methods.
- 4.13 Knowledge of which system files (e.g., logs, registry, configuration) contain relevant information and their locations.
DOMAIN 5: SECURITY OF EVOLVING TECHNOLOGY
- 5.1 Understanding new and emerging IT and information security technologies.
- 5.2 Knowledge of emerging security issues, risks, and vulnerabilities.
- 5.3 Understanding the risks associated with mobile computing.
- 5.4 Knowledge of cloud concepts related to data and collaboration.
- 5.5 Understanding the risks of migrating applications and infrastructure to the cloud.
- 5.6 Knowledge of risks associated with outsourcing
- 5.7 Understanding supply chain risk management processes and practices
Requirements
There are no specific prerequisites required to enroll in this course
28 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.