This course is a comprehensive study of the techniques used to protect information infrastructure and assets, with a primary focus on the Defense In Depth model that emphasizes the role of people, process and technology. Topics include security problems in computing, networks and distributed systems, and the criticality of the CIS triad; confidentiality, integrity and availability of technology-based resources.
Learning Objectives
- Develop solutions based on data developed from security assessments to prepare comprehensive security plans that include security procedures, training, and technology.
- Design for implementation the preventive, detective and corrective tools and procedures used to monitor the information security posture of an organization.
- Review operating system and application vulnerability assessments and compliance auditing across multiple platform and application environments.
- Assist in the selection, configuration, and maintenance of security software and utilities in line with the vulnerability assessment life-cycle.
- Develops and implement automated procedures to conduct assessments.
- Works with organizational management to develop information security standards, procedures and guidelines across multiple platform and application environments.
- Develops the development, testing and implementation of security policy, standards and risk mitigation techniques.
- Provides technical expertise and support in risk assessments and in implementation of information security planning and procedures.
- Develops and maintains an ongoing IT security awareness and employee training program.
Framework Connections
The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):
Specialty Areas
- Risk Management
- Program/Project Management and Acquisition
- Strategic Planning and Policy
- Systems Architecture
Feedback
If you would like to provide feedback on this course, please e-mail the NICCS team at NICCS@mail.cisa.dhs.gov. Please keep in mind that NICCS does not own this course or accept payment for course entry. If you have questions related to the details of this course, such as cost, prerequisites, how to register, etc., please contact the course training provider directly. You can find course training provider contact information by following the link that says “Visit course page for more information...” on this page.