|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/information-security-fundamentals-best-starting-point/
课程评论:没有评论
**课程名称:**信息安全基础(最佳入门点) **课程概述:** 本课程是信息安全领域的极佳起点,无论是为了温故知新,初次接触,还是为进一步学习打下坚实基础。在混合办公环境中,保护信息安全变得日益复杂。许多人存在不良习惯,或未能及时了解正确的安全程序,以及认识到特定安全策略的必要性。 本课程将带您深入了解信息安全(InfoSec)的基础知识,涵盖以下核心内容: * **信息安全定义**:包括其基本定义、CIA三要素(保密性、完整性、可用性),以及相关可用标准(如 ISO 27001, NIST)。 * **用户授权**:讲解各类身份验证方法,包括密码管理、多因素认证(MFA)、会话管理和 Cookie。 * **资产分类**:介绍资产分类的意义及其管理方法。 * **访问控制**:阐述最小权限原则、文件保护、基于角色的访问控制(RBAC)以及物理安全。 * **网络安全**:介绍网络类型、防火墙、网络分段等概念。 * **常见攻击类型**:深入分析中间人攻击、网络钓鱼、社会工程、暴力破解、恶意软件、拒绝服务攻击(DoS)等。 * **加密技术**:解释加密的原理,以及对称加密与非对称加密的区别。 * **风险管理**:定义风险,并讲解风险的管理方法。 * **事件管理**:概述事件管理流程。 * **常见安全策略**:介绍各类安全策略(如人力资源、自带设备(BYOD)、可移动媒体、供应商管理等)及其应用原因。 * **网络安全意识的重要性**:强调网络安全意识,并介绍常见风险(如网络钓鱼、恶意软件、安全浏览等)。 **课程特点:** * **时长**:2小时40分钟。 * **无先决知识要求**:无需任何技术背景,课程中的技术概念会随堂讲解。 * **易于学习**:课程内容被分解成易于理解和消化的小模块。
This course is perfect for a refresher, introduction, or as a foundation for further learning. Protecting our information within our hybrid working environments is becoming tricky. Many of us have bad habits or aren't up to speed with correct procedures or understanding why a certain policy may be in place.During this course, we cover the fundamentals of Information Security (InfoSec)What is Information Security (definition, CIA, Available Standards eg: 27001, NIST)User Authorisation (Types of Authentication, Passwords, MFA, Sessions, and Cookies)Asset Classification (What is Asset Classification, How can we manage our classifications)Access Control (Principle of least privilege access, Protecting our files, Role-based access, Physical Security)Network Security (Types of Network, Firewalls, Network Segmentation)Types of Attacks (Man in the Middle, Phishing, Social Engineering, Brute Force, Malware, DoS)Encryption (What is Encryption, Asymmetric vs Symmetric)Risk (What is Risk, How we Manage Risk)Incident Management (Overview and process walkthrough)Common Policies and why you may use them (Including HR, BYOD, Removable Media, Supplier Management etc..)Importance of Cyber Awareness - Common Risks (Phishing, Malware, Safe Browsing, etc...)This course runs for 2H40M and no prior technical knowledge is required, any technical aspects referenced are explained as we go. All of the course content is broken down into bite-sized manageable chunks for ease of learning.