|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/cissp-bootcamp-course-domain-7-and-domain-8/
课程评论:没有评论
课程名称:CISSP启动营课程:第七领域和第八领域 概述: 本课程涵盖安全操作和软件开发安全两个领域,旨在帮助学员掌握网络安全的关键概念与实践。 **第七领域:安全操作** 1. **安全运营中心(SOC)**:学习SOC的结构、功能及最佳实践,以有效监控和分析组织的安全态势,响应安全事件。 2. **事件响应**:了解识别、分析和响应安全事件的流程,重点在于制定应对计划,以减少事件的影响并预防未来的事件。 3. **灾难恢复规划**:学习制定恢复关键系统和数据的策略与程序,以应对灾难发生时的影响。 4. **业务连续性规划**:涵盖在发生中断情况下,维持关键业务职能的策略与政策。 5. **访问控制与管理**:学习如何基于最小权限、需求知晓和职责分离的原则来授予或拒绝资源访问。 6. **监控与分析**:掌握监控安全事件和数据、分析数据的重要性,以识别安全风险与威胁。 7. **漏洞管理**:探讨识别、评估、优先排序及减轻IT系统与应用程序中的漏洞的过程。 8. **安全评估与测试**:学习评估组织IT系统、应用程序和网络的安全态势所需的技术与方法。 9. **物理安全**:了解保护物理资产(如建筑、设备和人员)所需的安全措施。 **第八领域:软件开发安全** 1. **安全编码实践**:强调用于开发安全、可靠及抗攻击软件的原则与技术。 2. **威胁建模**:学习识别和分析软件系统与应用程序潜在威胁与漏洞的过程。 3. **软件开发生命周期(SDLC)**:了解开发、测试和部署软件的流程和最佳实践。 4. **Web应用程序的安全控制与技术**:涵盖保护Web应用程序免受攻击的措施。 5. **移动应用程序安全**:讨论保护移动应用免受攻击的方法与技术。 该课程由国际信息系统安全认证协会(ISC)组织,致力于维护信息系统安全领域的知识体系,提供认证及培训课程,管理认证考试,并监督合格认证候选人的持续教育。完成课程后,学员将在网络安全领域获得扎实的基础和实用技能。
Domain 7: Security OperationsSecurity Operations Center (SOC): SOC is a centralized facility where cybersecurity professionals monitor and analyze an organization's security posture, detect and respond to security incidents, and manage security-related operations. The domain covers SOC structure, functions, and best practices.Incident Response: Incident response is the process of identifying, analyzing, and responding to security incidents to minimize their impact and prevent future incidents. The domain covers incident response planning, preparation, detection, analysis, containment, eradication, and recovery.Disaster Recovery Planning: Disaster recovery planning is the process of developing strategies, procedures, and policies to recover critical systems and data in the event of a disaster. The domain covers disaster recovery planning phases, strategies, testing, and implementation.Business Continuity Planning: Business continuity planning is the process of developing strategies, procedures, and policies to maintain essential business functions in the event of a disruption. The domain covers business continuity planning phases, strategies, testing, and implementation.Access Control and Management: Access control and management are the processes of granting or denying access to resources based on the principles of least privilege, need-to-know, and separation of duties. The domain covers access control models, techniques, and technologies, as well as access control policies and procedures.Monitoring and Analysis: Monitoring and analysis are the processes of monitoring security events and data, analyzing the data, and identifying security risks and threats. The domain covers monitoring and analysis tools and techniques, log management, and threat intelligence.Vulnerability Management: Vulnerability management is the process of identifying, assessing, prioritizing, and mitigating vulnerabilities in IT systems and applications. The domain covers vulnerability assessment and scanning tools, vulnerability management frameworks, and best practices.Security Assessment and Testing: Security assessment and testing are the processes of evaluating the security posture of an organization's IT systems, applications, and networks. The domain covers security assessment and testing techniques, tools, and methodologies.Physical Security: Physical security is the set of measures used to protect physical assets, such as buildings, equipment, and people. The domain covers physical security measures, access control, surveillance, and environmental controls.Domain 8: Software Development SecuritySecure Coding Practices: Secure coding practices are the principles and techniques used to develop software that is secure, reliable, and resistant to attacks. The domain covers secure coding principles, secure coding standards, and secure coding techniques.Threat Modeling: Threat modeling is the process of identifying and analyzing potential threats and vulnerabilities to software systems and applications. The domain covers threat modeling methodologies, techniques, and tools.Software Development Life Cycle (SDLC): The SDLC is the process of developing, testing, and deploying software. The domain covers the SDLC phases, processes, and best practices, including secure coding practices and testing.Security Controls and Techniques for Web Applications: Web application security is the set of measures used to protect web applications from attacks. The domain covers web application security risks, security controls, and techniques.Mobile Application Security: Mobile application security is the set of measures used to protect mobile applications from attacks. The domain covers mobile application security risks, security controls, and techniques.The CISSP exam is governed by the International Information Systems Security Certification Consortium (ISC). (ISC) is a global not-for-profit organization. It has four primary mission goals:Maintain the Common Body of Knowledge (CBK) for the field of information systems security.Provide certification for information systems security professionals and practitioners.Conduct certification training and administer the certification exams.Oversee the ongoing accreditation of qualified certification candidates through continued education.The (ISC)2 is operated by a board of directors elected from the ranks of its certified practitioners.Subscribe now! The CISSP exam is governed by the International Information Systems Security Certification Consortium (ISC). (ISC) is a global not-for-profit organization.