CISSP Certified Information Systems Security Professional (Online-Canlı)

Eğitim Süresi

5 GÜN

Kontenjan

12

Ön Koşullar

Herhangi bir ön koşul bulunmamaktadır.

Eğitim Hakkında

Güvenlik profesyonellerine yönelik olan bu kurs, güvenlik alanına ve kullanılan teknolojilere dair tüm bilgileri ele almaktadır. Kurs, bilgi sistemleri güvenlik profesyonelleri için ortak bilgi yapısını (CBK) oluşturan sekiz alandaki bilgileri ele almakta olup öğrencilere de CISSP sertifikasyonuna hazırlanmalarında yardımcı olmaktadır.

Kurs, CBK’da açıklanan kavram ve tekniklerin gerçek dünyaya uygulanması imkanlarının ele alındığı, güvenlik sürecine teori tabanlı bir yaklaşım sunmaktadır. Ayrıca güvenlik yönetimi, mimari ve mühendisliğe iyi bir giriş sunmaktadır.

Kurs, doğrudan CBK’ya yönelik sekiz oturumdan oluşmakta olup her birinde eğitmen tarafından yönlendirilen, teori bazlı tartışmalar yer almaktadır ve herhangi bir uygulamalı laboratuvar da yoktur.

 

Eğitim İçeriği

Module 1. Security and Risk Management

  • Understand and apply concepts of confidentiality, integrity and availability
  • Apply security governance principles
  • Compliance
  • Understand legal and regulatory issues that pertain to information security in a global context
  • Understand professional ethics
  • Develop and implement documented security policy, standards, procedures, and guidelines
  • Understand business continuity requirements
  • Contribute to personnel security policies
  • Understand and apply risk management concepts
  • Understand and apply threat modelling
  • Integrate security risk considerations into acquisition strategy and practice
  • Establish and manage information security education, training, and awareness

 

Module 2. Asset Security

  • Classify information and supporting assets
  • Determine and maintain ownership
  • Protect privacy
  • Ensure appropriate retention
  • Determine data security controls
  • Establish handling requirements

 

Module 3. Security Engineering

  • Implement and manage engineering processes using secure design principles
  • Understand the fundamental concepts of security models
  • Select controls and countermeasures based upon systems security evaluation models
  • Understand security capabilities of information systems
  • Assess and mitigate the vulnerabilities of security architectures, designs, and solution elements
  • Assess and mitigate the vulnerabilities in web-based systems
  • Assess and mitigate vulnerabilities in mobile systems
  • Assess and mitigate vulnerabilities in embedded devices and cyber-physical systems
  • Apply cryptography
  • Apply secure principles to site and facility design
  • Design and implement physical security

 

Module 4. Communication & Network Security

  • Apply secure design principles to network architecture
  • Secure network components
  • Design and establish secure communication channels
  • Prevent or mitigate network attacks

 

Module 5. Identity & Access Management 

  • Control physical and logical access to assets
  • Manage identification and authentication of people and devices
  • Integrate identity as a service
  • Integrate third-party identity services
  • Implement and manage authorization mechanisms
  • Prevent or mitigate access control attacks
  • Manage the identity and access provisioning lifecycle

 

Module 6. Security Assessment & Testing

  • Design and validate assessment and test strategies
  • Conduct security control testing
  • Collect security process data
  • Analyse and report test outputs
  • Understand the vulnerabilities of security architectures

 

Module 7. Security Operations

  • Understand and support investigations
  • Understand requirements for investigation types
  • Conduct logging and monitoring activities
  • Secure the provisioning of resources
  • Understand and apply foundational security operations concepts
  • Employ resource protection techniques
  • Conduct incident management
  • Operate and maintain preventative measures

 

Module 8. Software Security Development

  • Understand and apply security in the software development lifecycle
  • Enforce security controls in development environments
  • Assess the effectiveness of software security
  • Assess security impact of acquired software

 

Eğitime Kimler Katılabilir

  • Güvenlik Yöneticileri
  • Firewall Yöneticileri
  • Güvenlik Test Uzmanları
  • İç/Dış Denetçiler
  • IT Müfettişleri
  • Sistem Yöneticileri