Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Certificate
Course Outline
DOMAIN 1: CYBERSECURITY CONCEPTS
- 1.1 Understanding information assurance (IA) principles utilized to manage risks associated with the use, processing, storage, and transmission of data.
- 1.2 Comprehension of security management practices.
- 1.3 Awareness of risk management processes, including the steps and methods for assessing risk.
- 1.4 Familiarity with the organization’s enterprise information technology (IT) goals and objectives.
- 1.5 Knowledge of distinct operational threat environments, such as first-generation [script kiddies], second-generation [non-nation state sponsored], and third-generation [nation state sponsored] threats.
- 1.6 Understanding of information assurance (IA) principles and organizational requirements pertaining to confidentiality, integrity, availability, authentication, and non-repudiation.
- 1.7 Awareness of common adversary tactics, techniques, and procedures (TTPs) within the assigned area of responsibility, including historical country-specific TTPs and emerging capabilities.
- 1.8 Knowledge of various attack classifications, such as passive, active, insider, close-in, and distribution attacks.
- 1.9 Understanding of applicable laws, policies, procedures, and governance requirements.
- 1.10 Awareness of relevant laws, policies, procedures, and governance standards related to work impacting critical infrastructure.
DOMAIN 2: CYBERSECURITY ARCHITECTURE PRINCIPLES
- 2.1 Understanding of network design processes, including security objectives, operational goals, and associated trade-offs.
- 2.2 Knowledge of security system design methods, tools, and techniques.
- 2.3 Familiarity with network access, identity, and access management, including public key infrastructure [PKI].
- 2.4 Understanding of information technology (IT) security principles and methods, such as firewalls, demilitarized zones, and encryption.
- 2.5 Awareness of current industry methods for evaluating, implementing, and disseminating IT security assessment, monitoring, detection, and remediation tools, utilizing standards-based concepts.
- 2.6 Knowledge of network security architecture concepts, including topology, protocols, components, and principles, such as the application of defence in depth.
- 2.7 Understanding of malware analysis concepts and methodologies.
- 2.8 Knowledge of intrusion detection methodologies and techniques for identifying host- and network-based intrusions.
- 2.9 Familiarity with defence in depth principles and network security architecture.
- 2.10 Understanding of encryption algorithms, including internet Protocol Security [IPSEC], Advanced Encryption Standard [AES], and Generic Routing Encapsulation [GRE].
- 2.11 Knowledge of cryptology.
- 2.12 Understanding of encryption methodologies.
- 2.13 Knowledge of traffic flow across networks, covering Transmission Control Protocol and Internet Protocol [ITCP/IP] and the Open System Interconnection model [OSI].
- 2.14 Familiarity with network protocols, such as Transmission Control Protocol and Internet Protocol.
DOMAIN 3: SECURITY OF NETWORK, SYSTEM, APPLICATION AND DATA
- 3.1 Understanding of computer network defence (CND) and vulnerability assessment tools, including open-source options, and their respective capabilities.
- 3.2 Knowledge of basic system administration, network, and operating system hardening techniques.
- 3.3 Awareness of risks associated with virtualization.
- 3.4 Understanding of penetration testing principles, tools, and techniques, such as metasploit and neosploit.
- 3.5 Knowledge of network systems management principles, models, methods (e.g., end-to-end performance monitoring), and tools.
- 3.6 Familiarity with remote access technology concepts.
- 3.7 Understanding of systems administration concepts.
- 3.8 Proficiency with the Unix command line.
- 3.9 Knowledge of system and application security threats and vulnerabilities.
- 3.10 Understanding of system lifecycle management principles, including software security and usability.
- 3.11 Awareness of local specialized system requirements, such as those for critical infrastructure systems that may not use standard IT, for safety, performance, and reliability.
- 3.12 Detailed knowledge of system and application security threats and vulnerabilities, including buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] injections, race conditions, covert channels, replay attacks, return-oriented attacks, and malicious code.
- 3.13 Understanding of the social dynamics of computer attackers in a global context.
- 3.14 Knowledge of secure configuration management techniques.
- 3.15 Awareness of the capabilities and applications of network equipment, including hubs, routers, switches, bridges, servers, transmission media, and related hardware.
- 3.16 Understanding of communication methods, principles, and concepts that support network infrastructure.
- 3.17 Knowledge of common networking protocols (e.g., Transmission Control Protocol and Internet Protocol [TCP/IP]) and services (e.g., web, mail, Domain Name System [DNS]), and their interaction to provide network communications.
- 3.18 Familiarity with different types of network communication, including Local Area Network [LAN], Wide Area Network [WAN], Metropolitan Area Network [MAN], Wireless Local Area Network [WLAN], and Wireless Wide Area Network [WWAN].
- 3.19 Knowledge of virtualization technologies and virtual machine development and maintenance.
- 3.20 Understanding of application vulnerabilities.
- 3.21 Familiarity with information assurance (IA) principles and methods applicable to software development.
- 3.22 Knowledge of risk threat assessment.
DOMAIN 4: INCIDENT RESPONSE
- 4.1 Understanding of incident categories, response protocols, and response timelines.
- 4.2 Knowledge of disaster recovery and continuity of operations plans.
- 4.3 Familiarity with data backup, types of backups (e.g., full, incremental), recovery concepts, and tools.
- 4.4 Understanding of incident response and handling methodologies.
- 4.5 Knowledge of security event correlation tools.
- 4.6 Awareness of the investigative implications of hardware, operating systems, and network technologies.
- 4.7 Understanding of processes for seizing and preserving digital evidence, such as maintaining the chain of custody.
- 4.8 Knowledge of types of digital forensics data and how to identify them.
- 4.9 Familiarity with basic concepts and practices for processing digital forensic data.
- 4.10 Understanding of anti-forensics tactics, techniques, and procedures (TTPS).
- 4.11 Knowledge of common forensic tool configuration and support applications, such as VMWare and Wireshark.
- 4.12 Understanding of network traffic analysis methods.
- 4.13 Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and where to locate them.
DOMAIN 5: SECURITY OF EVOLVING TECHNOLOGY
- 5.1 Awareness of new and emerging information technology (IT) and information security technologies.
- 5.2 Understanding of emerging security issues, risks, and vulnerabilities.
- 5.3 Knowledge of risks associated with mobile computing.
- 5.4 Familiarity with cloud concepts related to data and collaboration.
- 5.5 Understanding of risks involved in migrating applications and infrastructure to the cloud.
- 5.6 Awareness of risks associated with outsourcing.
- 5.7 Knowledge of supply chain risk management processes and practices.
Requirements
This course does not require any specific prior qualifications or prerequisites for attendance.
28 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.