|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/security-operations-administration-sscp
课程评论:没有评论
课程名称:安全操作与管理 概述:安全操作与管理的任务是识别组织的信息资产以及实施政策、标准、程序和指南所需的文档,以确保机密性、完整性和可用性。您将理解与管理层、信息所有者、保管人和用户合作的必要过程,以便定义适当的数据分类,从而确保对所有纸质和电子信息的正确处理。本课程涵盖基本的安全概念以及这些概念在企业计算机系统及其托管的信息日常操作和管理中的应用。课程还特别强调了伦理考虑,尤其是(ISC)²伦理守则,所有信息安全讨论都在此框架下进行。信息安全专业人员通常在信任的位置上,必须在各方面无可指责。课程也深入探讨了一些核心的信息安全原则,CIA三元组(机密性、完整性和可用性)几乎构成了信息安全的基础,SSCP候选人必须不仅理解这些原则,还能在所有情况下应用它们。此外,课程还涵盖了隐私、最小权限、不可否认性和职务分离等安全概念。 课程目标: 1. 定义伦理守则 2. 描述安全概念 3. 文档化和操作安全控制 4. 描述资产管理过程 5. 实施合规控制 6. 评估合规控制 7. 描述变更管理过程 8. 参与安全意识培训项目 9. 参与物理安全操作 课程大纲: 第一部分:了解并遵守伦理守则与安全概念 - 主题包括(ISC)²伦理守则、组织伦理守则、各种控制类型,及其对应的管理、技术和物理措施。 第二部分:参与资产管理 - 涵盖生命周期、硬件/软件和数据管理,包括安全开发及获取实践。 第三部分:实施和评估合规控制,并参与变更管理职责 - 学习技术、操作和管理控制的实现,安全政策及其生命周期。 第四部分:参与物理安全操作及安全意识培训 - 包含物理安全和建筑安全等主题,涵盖消防预防及检测等内容。 第五部分:案例研究 第六部分:考试 这个课程将帮助您掌握在信息安全领域必需的重要技能和知识,提升您的专业素养。
Part: 1
Title:Understand and Comply with Code of Ethics and Security Concepts
Description:Module Topics: (ISC)2 Code of Ethics, Organizational Code of Ethics, There are usually three types of controls, managerial (sometimes called administrative), Technical (sometimes called logical), and physical (sometimes called operational), Deterrent, Preventative, Detective, and Corrective Controls. Understand and Comply with Code of Ethics: In (ISC)2 Code of Ethics, you will learn about Code of Ethics, and Code of Ethics Canons. In Organizational Code of Ethics, you will learn about how a code of ethics applies to security practitioners, and applying ethical principles. Understand Security Concepts: In Confidentiality, you will learn about consequences of a breach, and ensuring confidentiality. In integrity, you will learn about consequences of integrity failure, availability, and consequences of availability failures. You will also Non-Repudiation. In Privacy, you will understand core guidelines. In least privilege, you will learn about least privilege and cots Applications. You will understand the concept of separation of duties and defense in depth, examples approaches, and additional controls. In Risk based Controls, you will learn about risk assessment data. Security concepts also covers accountability and authorization.
Part: 2
Title:Participate in Asset Management
Description:Module Topics: Life Cycle, Hardware/Software, and Data. In life Cycle, you will learn about the waterfall model, it's benefits and drawbacks, requirements gathering and analysis, requirements definition, system design, implementation, integration, testing, deployment of system, maintenance, additional application development methods, system vulnerabilities, secure development, and acquisition practices, OWASP top ten, guidelines for developers, IT asset management (ITAM), device management, continuous diagnostics and mitigation (CDM), hardware, hardware asset management desired state, hardware asset management data, the SSCP's challenge, impact and results. In Data, you will learn about secure information storage, considerations, encryption vulnerabilities, database encryption, data scrubbing, data deduplication, managing encryption keys, consideration, Information Rights Management (IRM), secure output, data retention and disposal, shredders, security levels, destruction of magnetic media, erasure or reformatting, data wiping, degaussing, and disclosure controls: data leakage prevention.
Part: 3
Title:Implement and Assess Compliance with Controls & Participate in Change Management Duties
Description:Module Topics: Technical Controls, Operational Controls, Managerial Controls, Security Policies, Standards, Guidelines, and Procedures, Implementation and Configuration Management Plan, security Impact Assessment, System Architecture/Interoperability of Systems, Testing Patches, Fixes, and Updates. In technical Controls, you will learn about identification and authentication, logical access controls, public access controls, audit trails. In Operational Controls, you will learn about operational security measures, operational solutions, managerial Controls. In Security Policies, Standards, Guidelines, and Procedures, you will learn about subject-specific security policies, typical policy elements, policy life cycle, components of a security policy, standard guidelines, and procedures.
Part: 4
Title:Participate in Physical Security Operations & Security Awareness Training
Description:Module Topics: Security Awareness Training, Physical Security, Building Security, keys, Locks, and safes, communications and Server Rooms, Restricted and Work Area Security, Utilities and HVAC Considerations, Fire Prevention, Detection, and Suppression. Participate in Physical Security Operations: In Physical Security, you will learn about interior access control elements, and escort and visitor control. In building security, you will learn about doors, perimeter doors, door locks, mantraps, and turnstiles. In Keys, Locks, and Safe, you will learn about types of locks, hi-tech keys, safes, vaults, containers, key control, medeco guide for developing and managing key control. In communications and Server Rooms, you will learn about securing the area, protection from lightning, server rooms, and rack security. In Restricted and Work Area Security, you will learn about restricted work areas, data center security, and the "two- person rule". In Utilities and HVAC Considerations, you will learn about utilities and power uninterruptible power supply, generator, HVAC, air contamination, guidelines, and water issues. In Fire Prevention, Detection, and Suppression, you will learn about fire detection, fire suppression, sprinkler systems, and gas suppression systems.
Part: 5
Title:Case Study
Description:
Part: 6
Title:Exam
Description:
Security operations and administration is the task of identifying an organization's information assets and the documentation needed for policy implementation, standards, procedures, and guidelines to ensure confidentiality, integrity, and availability. You will understand the process necessary for working with management and information owners, custodians, and users so that proper data classifications are defined. This will ensure the proper handling of all hard copy and electronic information. The Security operations and Administration course addresses basic security concepts and the application of those concepts in the day to day operation and administration of enterprise computer systems and the information that they host.Ethical considerations in general, and the (ISC)2 Code of Ethics in particular, provide the backdrop for any discussion of information security and SSCP candidates will be tested on both. Information security professionals often find themselves in positions of trust and must be beyond reproach in every way.Several core principles of information security stand above all others and this domain covers these principles in some depth. It can be said that the CIA triad of confidentiality, integrity and availability forms the basis for almost everything that we do in information security and the SSCP candidate must not only fully understand these principles but be able to apply them in all situations. additional security concepts covered in this domain include privacy, least privilege, non-repudiation and the separation of duties. Course Objectives 1. Define Code of Ethics 2. Describe the security concepts 3. Document and operate security controls 4. Describe the asset management process 5. Implement compliance controls 6. Assess compliance controls 7. Describe the change management process 8. Contribute to the security awareness training program 9. Contribute to physical security operations