|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-bootcamp-course-domain-5-6/
课程评论:没有评论
**CISSP Bootcamp 课程 - Domain 5 & 6 课程总结** 本课程是为准备CISSP考试的学员量身打造,深入涵盖了CISSP知识体系(CBK)中的第五和第六个领域。 **Domain 5: 身份和访问管理 (Identity and Access Management)** 此部分重点在于管理人和事物(设备、服务)的身份,以及如何授权他们访问资源。内容包括: * **身份管理 (IdM) 实现:** 涵盖单因素/多因素认证 (MFA)、账户管理、会话管理、身份注册和证明、身份联邦管理 (FIM)。 * **认证系统:** 深入讲解 OpenID Connect (OIDC)/Open Authorization (OAuth)、Security Assertion Markup Language (SAML)、Kerberos、Remote Authentication Dial-In User Service (RADIUS)/Terminal Access Controller Access Control System Plus (TACACS+)。 * **授权机制:** 介绍不同类型的访问控制模型,如基于角色的访问控制 (RBAC)、基于规则的访问控制、强制访问控制 (MAC)、自主访问控制 (DAC)、基于属性的访问控制 (ABAC) 和基于风险的访问控制。 * **身份和访问生命周期管理:** 涵盖账户访问审查、账户的配置与去配置(入职/离职和调岗)、角色定义以及权限提升(例如,管理服务账户,sudo 的使用与最小化)。 **Domain 6: 安全评估和测试 (Security Assessment and Testing)** 本领域关注如何设计、验证和执行安全评估与测试策略,以确保安全控制的有效性。内容包括: * **评估、测试和审计策略设计与验证:** 覆盖内部、外部和第三方进行的评估、测试及审计。 * **安全控制测试:** 详细介绍各种测试方法,包括漏洞评估、渗透测试、日志审查、合成交易、代码审查和测试、滥用案例测试、测试覆盖率分析、接口测试、违规攻击模拟和合规性检查。 * **安全过程数据收集:** 涉及账户管理、管理审查和批准、关键绩效和风险指标、备份验证数据、培训和意识、以及灾难恢复 (DR) 和业务连续性 (BC) 相关数据的收集。 * **测试结果分析与报告:** 学习如何分析测试输出并生成报告,包括风险整改、例外处理以及道德披露。 * **安全审计:** 介绍如何执行或协助内外部及第三方的安全审计。 * **资产的物理和逻辑访问控制:** 管理信息、系统、设备、设施和应用程序的物理及逻辑访问。 **CISSP 考试监管机构:** CISSP 考试由国际信息系统安全认证联盟 (ISC) 监管。(ISC) 是一个全球性的非营利组织,其主要使命包括:维护信息系统安全领域的通用知识体系 (CBK),为信息系统安全专业人员提供认证,组织认证培训和管理认证考试,并通过持续教育监督合格认证候选人的持续认证。 (ISC)2 由其认证从业人员中选出的董事会进行管理。
This is an ideal course for any student who is preparing for CISSP. The course content covers Domain 5 and Domain 6 in detail.Design and validate assessment, test, and audit strategiesInternalExternalThird-partyConduct security control testingVulnerability assessmentPenetration testingLog reviewsSynthetic transactionsCode review and testingMisuse case testingTest coverage analysisInterface testingBreach attack simulationsCompliance checksCollect security process data (e.g., technical and administrative)Account managementManagement review and approvalKey performance and risk indicatorsBackup verification dataTraining and awarenessDisaster Recovery (DR) and Business Continuity (BC)Analyze test output and generate reportsRemediationException handlingEthical disclosureConduct or facilitate security auditsInternalExternalThird-partyControl physical and logical access to assetsInformationSystemsDevicesFacilitiesApplicationsManage identification and authentication of people, devices, and servicesIdentity Management (IdM) implementationSingle/Multi-Factor Authentication (MFA)AccountabilitySession managementRegistration, proofing, and establishment of identityFederated Identity Management (FIM)Credential management systemsSingle Sign On (SSO)Just-In-Time (JIT)Federated identity with a third-party serviceOn-premisesCloudHybridImplement and manage authorization mechanismsRole Based Access Control (RBAC)Rule based access controlMandatory Access Control (MAC)Discretionary Access Control (DAC)Attribute Based Access Control (ABAC)Risk based access controlManage the identity access provisioning lifecycleAccount access review (e.g., user, system, service)Provisioning and deprovisioning (E.g., on/off boarding and transfers)Role definition (e.g., people assigned to new roles)Privilege escalation (e.g., manage service accounts, use of sudo, minimizing its use)Implement authentication systemsOPENid Connect (OIDC)/Open Authorization (Oauth)Security Assertion Markup Language (SAML)KerberosRemote Authentication Dial-In User Service (RADIUS)/Terminal Access Controller Access Control System Plus (TACACS+)The CISSP exam is governed by the International Information Systems Security Certification Consortium (ISC). (ISC) is a global not-for-profit organization. It has four primary mission goals:Maintain the Common Body of Knowledge (CBK) for the field of information systems security.Provide certification for information systems security professionals and practitioners.Conduct certification training and administer the certification exams.Oversee the ongoing accreditation of qualified certification candidates through continued education.The (ISC)2 is operated by a board of directors elected from the ranks of its certified practitioners.Subscribe now! The CISSP exam is governed by the International Information Systems Security Certification Consortium (ISC). (ISC) is a global not-for-profit organization.