• Classroom
  • Online, Instructor-Led
Course Description

This course focuses on legal, ethical and security issues involving data and information assets organizations must address to ensure operational continuity as well as compliance with standards, policies and laws. Students examine various levels of threats to an organization’s data and develop standards, policies, procedures and plans to combat them. Security technology specific to safeguarding data and information assets is also covered.

Learning Objectives

  1. Given an organization which needs a general security policy, provide a brief overview of the guiding principles that should form the basis of that security policy.
  2. Possess a thorough understanding of the common body of knowledge.
  3. Have a working knowledge of security management practices.
  4. Be able to apply and explain how computer law and ethics relates to an organization's computer security practices.
  5. Understand the major security models and be able to integrate one or more of them into an organization's security plan.
  6. Given an organization requiring physical security, be able to establish physical security guidelines for that organization.
  7. Given an organization requiring operational security, be able to establish operational security guidelines for that organization.
  8. Be able to analyze and select the appropriate backup strategy for a given organization.
  9. Be able to establish access control strategies for a given organization.
  10. Be able to understand basic cryptography well enough to analyze different cryptography solutions, and select the appropriate one for a given organization's security needs.
  11. Be able to select the appropriate firewall.
  12. Be able to analyze and select an appropriate Intrusion Detection System.
  13. Explain how software development impacts data security and privacy.

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Cyber Defense Analysis
  • Training, Education, and Awareness
  • Systems Administration
  • Systems Requirements Planning
  • Threat Analysis

Specialty Areas have been removed from the NICE Framework. With the recent release of the new NICE Framework data, updates to courses are underway. Until this course can be updated, this historical information is provided to give better context as to how it can help you with your cybersecurity goals.

Feedback

If you would like to provide feedback for this course, please e-mail the NICCS SO at NICCS@hq.dhs.gov.