|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/access-control-sscp
课程评论:没有评论
课程名称:访问控制 课程概述: 欢迎参加访问控制课程!本课程提供与用户权限、可访问资源以及用户在系统中可执行操作相关的信息。访问控制帮助管理者在用户级别或组成员资格层面限制和监控系统使用。您将了解不同的访问控制系统及其如何实施,以保护系统和数据,并确保不同层次的机密性、完整性和可用性。 课程目标: 1. 描述如何实现身份验证机制。 2. 识别和操作内部信任架构。 3. 描述身份管理生命周期的管理过程。 4. 实施不同类型的访问控制(基于主题/对象)。 课程大纲: 1. 实施身份验证机制:学习单因素和多因素身份验证、生物识别技术,包括身份、方法、用户注册、新用户的访问级别周期性审查、清除、身份验证、知识、密码重置、大规模锁定、所有权和特性等。 2. 实施身份验证机制:涵盖令牌、单点登录、离线和设备身份验证。 3. 操作内部信任架构:比较网络架构,学习单向信任、双向信任和可传递信任的概念,包括典型的DMZ设计和信任路径。 4. 管理身份管理生命周期:涉及身份管理、授权、证明、供应、维护和权限等模块主题。 5. 实施访问控制:探讨强制访问控制(MAC)、非自由裁量访问控制、自主访问控制(DAC)、基于角色的访问控制(RBAC)、内容相关、基于上下文、时间隔离(基于时间)、基于属性、职能分离、安全架构和模型。 6. 案例研究:基于案例研究的作业,要求学生将课程中获得的知识付诸实践,包括对相关主题的基本理解和与现实世界的关联。 7. 考试:评估学生对课程内容的理解和分析能力。 本课程适合希望深入了解访问控制及其在信息安全中作用的学习者。
Part: 1
Title:Implement Authentication Mechanisms
Description:Module Topics: Single Factor/Multifactor Authentication, Biometrics. In Single Factor/ Multifactor Authentication, you will learn about identity, methods, registration of new users, periodic review of access levels, clearance, authentication, knowledge, password reset, mass lockouts, ownership, and characteristics.
Part: 2
Title:Implement Authentication Mechanisms
Description:Module Topics: Tokens, Single Sign-On, Offline and Device Authentication.
Part: 3
Title:Operate Internetwork Trust Architectures
Description:Module Topics: Comparing Internetwork Architectures, One-way Trust, Two-way Trust, and Transitive Trust. In Comparing Internetwork Architectures, you will learn about typical DMZ design, trust path. In Trust, you will learn about one-way trust, two-way trust, and transitive trust.
Part: 4
Title:Administer Identity Management Life Cycle
Description:Module Topics: Identity Management, Authorization, Proofing, Provisioning, Maintenance, and Entitlement.
Part: 5
Title:Implement Access Controls
Description:Module Topics: Mandatory Access Control (MAC), Non-Discretionary Access Control, Discretionary Access Control (DAC), Role-Based Access Control (RBAC), Content Dependent, Context-Based, Temporal Isolation (Time Based), Attribute-Based, Separation of Duties, Security Architecture and Models.
Part: 6
Title:Case Study
Description:This assignment is based on a case study that will require the student to put into practice the knowledge they have gained through the course. It requires the basic understanding of the topics and the ability to relate those topics to the real world. The objective of review is to determine whether the student has understood the concepts and has performed the necessary analysis to ensure a complete and thorough answer.
Part: 7
Title:Exam
Description:
Welcome to Access Controls! The Access Controls Course provides information pertaining to specify what users are permitted to do, the resources they are allowed to access, and what operations they are able to perform on a system. Access Controls help managers limit and monitor systems use at a user level or group membership. You will understand the different access control systems and how they should be implemented to protect the system and data using the different levels of confidentiality, integrity, and availability. The Access Controls course provides information pertaining to specifying what users are permitted to do, the resources they are allowed to access, and what operations they are able to perform on a system. Access Controls help managers limit and monitor systems use at a user level, and is usually predefined based on authority level or group membership. You will understand the different access control systems and how they should be implemented to protect the system and data using the different levels of confidentiality, integrity, and availability. Objectives 1. Describe how to implement Authentication mechanisms 2. Identify and operate internetwork trust architectures 3. Describe the process of administering identity management life cycle 4. Implement the different types of access controls (Subject/Object based)