Security Operations and Administration

所在平台: CourseraArchive

课程类别: 其他类别

大学或机构: CourseraNew

课程主页: https://www.coursera.org/archive/security-operations-administration-sscp

课程评论:没有评论

第一个写评论        关注课程

课程简介

(ISC)²

课程大纲

Module Topics: (ISC)2 Code of Ethics, Organizational Code of Ethics, There are usually three types of controls, managerial (sometimes called administrative), Technical (sometimes called logical), and physical (sometimes called operational), Deterrent, Preventative, Detective, and Corrective Controls. Understand and Comply with Code of Ethics: In (ISC)2 Code of Ethics, you will learn about Code of Ethics, and Code of Ethics Canons. In Organizational Code of Ethics, you will learn about how a code of ethics applies to security practitioners, and applying ethical principles. Understand Security Concepts: In Confidentiality, you will learn about consequences of a breach, and ensuring confidentiality. In integrity, you will learn about consequences of integrity failure, availability, and consequences of availability failures. You will also Non-Repudiation. In Privacy, you will understand core guidelines. In least privilege, you will learn about least privilege and cots Applications. You will understand the concept of separation of duties and defense in depth, examples approaches, and additional controls. In Risk based Controls, you will learn about risk assessment data. Security concepts also covers accountability and authorization.

课程评论(0条)

课程详情

Security operations and administration is the task of identifying an organization's information assets and the documentation needed for policy implementation, standards, procedures, and guidelines to ensure confidentiality, integrity, and availability. You will understand the process necessary for working with management and information owners, custodians, and users so that proper data classifications are defined. This will ensure the proper handling of all hard copy and electronic information. The Security operations and Administration course addresses basic security concepts and the application of those concepts in the day to day operation and administration of enterprise computer systems and the information that they host.Ethical considerations in general, and the (ISC)2 Code of Ethics in particular, provide the backdrop for any discussion of information security and SSCP candidates will be tested on both. Information security professionals often find themselves in positions of trust and must be beyond reproach in every way.Several core principles of information security stand above all others and this domain covers these principles in some depth. It can be said that the CIA triad of confidentiality, integrity and availability forms the basis for almost everything that we do in information security and the SSCP candidate must not only fully understand these principles but be able to apply them in all situations. additional security concepts covered in this domain include privacy, least privilege, non-repudiation and the separation of duties. Course Objectives 1. Define Code of Ethics 2. Describe the security concepts 3. Document and operate security controls 4. Describe the asset management process 5. Implement compliance controls 6. Assess compliance controls 7. Describe the change management process 8. Contribute to the security awareness training program 9. Contribute to physical security operations

安全运营和管理:安全运营和管理的任务是识别组织的信息资产以及策略实施,标准,过程和准则所需的文档,以确保机密性,完整性和可用性。您将了解与管理人员和信息所有者,保管人和用户一起工作所必需的过程,以便定义正确的数据分类。这将确保正确处理所有纸质副本和电子信息。       安全操作和管理课程讨论基本安全概念以及这些概念在企业计算机系统的日常操作和管理及其所包含的信息中的应用。一般的道德考量以及(ISC)2特别是,为任何有关信息安全性的讨论提供背景,并且将在两者上测试SSCP候选人。信息安全专业人员经常发现自己处于信任的位置,并且在各个方面都必须无可指责。信息安全的几个核心原则高于其他所有原则,并且该领域在一定程度上涵盖了这些原则。可以说,中央情报局的机密性,完整性和可用性三者构成了我们在信息安全领域所做的几乎所有事情的基础,而SSCP候选人不仅必须充分理解这些原则,还必须能够在所有情况下应用它们。此域中涵盖的其他安全概念包括隐私,最低特权,不可否认性和职责分离。     课程目标 1.制定道德守则 2.描述安全概念 3.记录和操作安全控制 4.描述资产管理过程 5.实施合规控制 6.评估合规控制 7.描述变更管理过程 8.参与安全意识培训计划 9.促进物理安全操作

课程标签

0人关注该课程

主题相关的课程