Zero Trust Networking: The Future of Network Security

所在平台: Udemy

课程主页: https://www.udemy.com/course/zero-trust-networks-and-architecture-concepts-training/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:零信任网络:网络安全的未来 课程概述:零信任是一种安全模型,假设所有网络流量都是不可信的,访问必须经过验证。该在线培训课程旨在提供关于零信任网络的全面理解以及如何实施这些网络。在课程中,您将学习零信任的关键概念和最佳实践,包括“永不信任,始终验证”的原则以及多因素身份验证的使用。您将了解如何利用零信任创建一个抵御网络威胁的安全网络环境。 课程内容将涵盖零信任的技术、管理和组织方面,并学习如何利用零信任来满足法规和行业标准的要求。此外,您将了解最新的威胁和漏洞,以及如何利用零信任来保护免受这些威胁。课程还包括动手练习,演示在现实世界中实施零信任的情况,您将学习如何在不同的网络环境中(包括本地、云和混合网络)实施零信任。 此外,课程将介绍零信任网络的不同组成部分,包括微分段、网络访问控制和身份与访问管理。您还将学习实施零信任所需的不同工具和技术,如防火墙、VPN和身份访问管理系统。另一个重点是零信任架构,在这里您将学习不同的架构模型和设计与实施零信任网络的最佳实践。您还将了解在零信任网络中使用的不同协议和标准,如SSL/TLS、SAML和OAuth。 课程还将涵盖零信任网络的管理和监控,学习不同的监控和管理工具及维护零信任网络的最佳实践。此外,您将学习与零信任网络相关的合规和监管要求及如何满足这些要求。 本课程面向负责实施和维护安全网络环境的IT专业人员、安全专业人员和网络管理员。完成课程后,您将对零信任网络有深入理解,并能够创建一个抵御网络威胁且符合法规和行业标准的安全网络环境。 在本课程中,您将学习以下概念,每个概念进一步划分为主题: 1) 零信任基础 - 零信任历史 - 零信任概念 - 零信任的必要性 - 零信任解决的问题 2) 当前状态与实施挑战 - 零信任的演变 - 零信任的现状 - 零信任实施中的挑战 3) NIST关于构建零信任架构的指导 - 零信任架构简介 - NIST零信任架构的六个关键原则 - NIST零信任架构的逻辑组件(第一部分和第二部分) 4) 构建零信任网络的五个基本步骤 - 定义攻击面 - 实施网络流量控制 - 规划零信任网络 - 设计零信任策略 - 监控和维护网络 - 其他学习材料:关于零信任的指南 5) 示例:使用条件访问策略实施零信任 - 六大基础支柱 - Azure条件访问策略概述 - 使用多因素身份验证实施条件访问 6) 零信任架构的使用案例 - 维护合规性 - 安全云迁移 - DevOps和持续交付 总之,实现零信任不需要采用任何新技术,而是对网络安全进行“永不信任,始终验证”的新方法,旨在消除任何信任,相比传统的基于边界的安全方法,后者假设用户身份未被破坏,所有人类参与者都是可被信任的。相信我们网络内部的任何事物的观念是根本有缺陷的,这在新闻中频繁出现的数据泄露事件中得到了证实,其中大多数数据泄露是由于特权凭证的滥用造成的。

课程评论(0条)

课程详情

Zero Trust is a security model that assumes that all network traffic is untrusted and requires verification before access is granted. This online training course is designed to provide a comprehensive understanding of Zero Trust networks and how to implement them.Throughout the course, you will learn the key concepts and best practices of Zero Trust, including the principle of "never trust, always verify" and the use of multi-factor authentication. You will learn how to use Zero Trust to create a secure network environment that is resistant to cyber threats.The course will cover the technical, management, and organizational aspects of Zero Trust, and you will learn how to use Zero Trust to comply with regulations and industry standards. Additionally, you will learn about the latest threats and vulnerabilities and how to use Zero Trust to protect against them.The course includes hands-on exercises that demonstrate the implementation of Zero Trust in real-world situations. You will learn how to implement Zero Trust in different network environments, including on-premises, cloud, and hybrid networks.You will also learn about the different components of a Zero Trust network, including micro-segmentation, network access control, and identity and access management. Additionally, you will learn about the different tools and technologies that are used to implement Zero Trust, such as firewalls, VPNs, and identity and access management systems.Another focus of the course is on the Zero Trust architecture, where you will learn about the different architectural models and best practices for designing and implementing Zero Trust networks. Additionally, you will learn about the different protocols and standards that are used in Zero Trust networks, such as SSL/TLS, SAML, and OAuth.The course will also cover the management and monitoring of Zero Trust networks, where you will learn about the different monitoring and management tools and best practices for maintaining a Zero Trust network. Additionally, you will learn about the different compliance and regulatory requirements that are associated with Zero Trust networks and how to meet these requirements.This course is designed for IT professionals, security professionals, and network administrators who are responsible for implementing and maintaining secure network environments. By the end of the course, you will have a deep understanding of Zero Trust networks and how to implement them, and you will be able to create a secure network environment that is resistant to cyber threats and compliant with regulations and industry standards. In this course you will learn following concepts and each Concept has further topics1) Some Basics about Zero TrustHistory of Zero TrustWhat is Zero TrustWhy Zero TrustIssues Solved by Zero Trust2) Zero Trust: Current State and Implementation challengesEvolution of Zero TrustPresent State of Zero TrustChallenges in Zero trust Implementation3) NIST Guidance on building Zero Trust ArchitectureWhat Is Zero-Trust Architecture (ZTA)?NIST's 6 Key Tenets of Zero Trust ArchitecturePart 1: Overview of NIST Zero Trust ArchitecturePart 2: Logical Components NIST Zero Trust ArchitecturePart 3: Logical Components NIST Zero Trust Architecture4) The 5 Basic Steps to Building a Zero Trust NetworkStep 1: Define Attack SurfaceStep 2 - Implement Controls Around Network TrafficStep 3: Plan your Zero Trust NetworkStep 4: Design Your Zero Trust PolicyStep 5: Monitor and maintain networksAdditional Learning: Guides on Zero Trust5) Demo:Implement Zero Using Conditional Access PoliciesSix foundational pillarOverview of Azure Conditional Access PoliciesImplement Conditional access using MFA6) Zero Trust Architecture - Use CasesMaintain ComplianceSecuring Cloud MigrationsDevOps and Continuous DeliveryIn summary, achieving Zero-Trust does not require adoption of any new technologies. It's simply a new approach to cybersecurity to "never trust, always verify," or to eliminate any and all trust, as opposed to the more common perimeter-based security approach that assumes user identities have not been compromised, all human actors are responsible and can be trusted. The concept of trusting anything internal to our networks is fundamentally flawed as evidenced by all the data breaches in the news, with most of the breaches caused by misuse of privileged credentials.

课程标签

0人关注该课程

主题相关的课程