|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/iso-27001-cybersecurity-manager-guidelines/
课程评论:没有评论
课程名称:ISO 27001 网络安全管理者指南 课程概述:本课程的目的是为ISO 27001(信息安全管理体系的流行标准)提供网络安全应用指南。通过学习课程内容,您将深入理解组织设计网络安全系统所需的概念、原则和要求。您将了解不同活动和流程中常见的安全威胁,以及组织可以实施的建议控制措施,以应对和保护自身安全。 课程结构包括: - 网络空间和网络安全的定义等介绍性内容 - 机密性、完整性、认证和不可抵赖性等安全系统的重要元素 - 信息分类:方案、级别和标签方面 - 威胁、脆弱性、风险评估(定量和定性方法)及组织应对安全风险的选项 - 内部组织要求,包括高层管理的支持和职责分离 - 移动设备方面,涉及BYOD(自带设备)和COPE(公司拥有的个人启用设备) - 人力资源安全:从筛选到雇佣,合同要求、纪律程序及终止和变更雇佣 - 可移动媒介的使用要求 - 访问控制和认证方面,以及如何管理特权以防止安全漏洞 - 加密学基础,包括数字签名和公钥基础设施 - 常见密码攻击(如暴力破解、彩虹表和生日攻击)及推荐控制措施 - 物理安全和设备相关的控制措施 - 恶意软件方面(病毒、逻辑炸弹、蠕虫、木马、间谍软件、广告软件及勒索软件的详细介绍) - 拒绝服务攻击、社交工程和网络钓鱼 - 密码管理,包括常见密码攻击和控制措施 - 备份方面 - 变更管理过程的要求,以确保安全性不受影响 - 网络安全的原则和控制措施以及无线攻击的预防 - 电子邮件安全要求 - 开发过程中的安全 - 供应商关系及与供应商接入信息资产相关的风险 - 容量管理 - 网络安全事件管理,从检测到关闭及根本原因分析 - 业务连续性及组织如何准备和应对危机情况 - 任何组织必须遵守的合规要求 课程使用简单易懂的解释和示例,并结合案例研究(如巴林银行倒闭、Target安全漏洞和爱德华·斯诺登事件)来说明所描述的概念。在课程结束时,有一个小测验测试您对课程内容的掌握。获取所需的信息,设计、协调和改善网络安全系统,或按照ISO 27001对组织进行审计。
The purpose of this course is to provide cybersecurity guidelines for the application of ISO 27001 (the popular standard for information security management systems).After going through the lessons you will have a good understanding of the concepts, principles and requirements for an organization to design a cybersecurity system.You will understand what are the typical security threats for different activities and processes and the recommended controls that an organization can implement in order to respond and protect itself.The structure of the course includes:- introductory aspects including definitions for the Cyberspace and Cybersecurity.- the concepts of Confidentiality, Integrity, Authentication and Non-Repudiation as critical elements for any security system;- information classification - schemes, levels and labeling aspects- Threats, vulnerability, risk assessment (quantiative and qualitative methods) and the options for an organization to treat security risks.- Internal organization requirements including support from top management and segregation of duties;- aspect on mobile devices - like BYOD (Bring Your Own Device) and COPE (Company Owned Personally Enabled)- human resources security - from screening to employment, the contractual requirements and disciplinary process plus the termination and change of employment- requirements for the use of removable media- access controls and authentication aspects plus how to manage privileges so they won't generate security breaches- cryptography - including basic elements and definitions, digital signature and the public key infrastructure- a short description of most popular cryptograhpic attacks (brute force, rainbow tables or birthday attacks) and recommended controls- controls that refer to physical security and equipment- malware aspects (viruses, logic bombs, worms, trojans, spyware, adware and a detailed presentation of ransomware)- denial of service attacks - social engineering and phishing- password management aspects including common password attacks and controls - backup aspects- requirements for the change management process in an organization so that security is not affected- network security aspects - principles and controls + wireless attacks and how to prevent them- requirements for email security- security in development processes- supplier relationships and risks associated to suppliers' access to information assets of the organization- capacity management- managing cybersecurity incidents - from detection to closure and root cause analysis- business continuity aspects and how an organization should prepare for and respond to crisis situations- compliance requirements that any organization must repsect.The course uses easy to follow explanations and examples with a few case studies along the way (about the Barings bank collapse, the Target security breach or Edward Snowden) to illustrate the concepts described.At the end of the course there is a quiz - with questions from the subject matter.Get the information you need to design, coordinate and improve a cybersecurity system or audit organizations as per ISO 27001.