Call toll free 1(866)471-0059
    Call direct +1-708-689-0131
What‘s New   About InfoSec   Course Catalog   Contact Us
 
The InfoSec Institute Advantage:
The Planet's Most Comprehensive Training Experience
Small Class Size
Hands On Security Training
Cutting-Edge Course Content
Satisfaction Guarantee
World Renown Instructors
Boot Camp Style Training
Luxury Accommodations
 
Enterprise Security Awareness:
Security Awareness for IT Users
Security Awareness for PCI DSS
Security Awareness for IT Pros
Security Awareness for Software Developers
Hands-On Security Training:
Ethical Hacking
Advanced Ethical Hacking
Penetration Testing - 10 Day
Expert Penetration Testing
Intrusion Prevention
Computer Forensics Training
Advanced Computer Forensics
Data Recovery Training
Forensics & Data Recovery - 10 Day
Security Architecture Design
Application Security
SCADA Security
Reverse Engineering Training
Advanced Reverse Engineering Malware
Fundamentals of Information Security
Incident Response and Network Forensics
VOIP Security Course
Wireless Security Training
PCI Compliance Training
On-Site Training
Certification Preparation Training:
CEH Boot Camp
CISSP Boot Camp
CISA Boot Camp
CISM Boot Camp
ECSA/LPT Boot Camp
Security+ Boot Camp
CAP Boot Camp
PMP Boot Camp
On-Site Training
8570.1 Compliance Training:
Learn More About 8570 Compliance
IAT1: A+ Boot Camp
IAT1: Network+ Boot Camp
IAT2: Security+ Boot Camp
IAT3: CISSP Boot Camp
IAT3: CISA Boot Camp
IAM1: CAP Boot Camp
IAM1: Security+ Boot Camp
IAM2: CISM Boot Camp
IAM2: CAP Boot Camp
IAM2: CISSP Boot Camp
IAM3: CISM Boot Camp
IAM3: CISSP Boot Camp
On-Site Training
IT Audit & Project Management Training:
CISA Boot Camp
CISM Boot Camp
CGEIT Boot Camp
CRISC Boot Camp
PMP Boot Camp
CAPM Training
On-Site Training
Information Assurance Training:
CAP Boot Camp
DIACAP Training
5 Day C&A Boot Camp
5 Day DIACAP Validator Training
On-Site Training
Secure Software Development:
Secure Coding for .NET - C#/ASP.NET
Secure Coding for Java & JEE
Application Security Training
On-Site Training
Technical IT Training:
A+ Boot Camp
Network+ Boot Camp
8 Day A+/Network+ Boot Camp
Data Recovery Training
On-Site Training
Online Professional Development:
Hacker Training Online
Advanced Hacking Online
Penetration Testing Online
Intrusion Prevention Online
Reverse Engineering Online
Computer Forensics Training
SCADA Security Online
Data Recovery Online
Security Architecture Online
Application Security Online
CISSP Boot Camp Online
CISM Boot Camp Online
CISA Boot Camp Online
Small Class Size
Bring a Friend Discount
Hands-On Instruction
World Renown Instructors
 
 
 
Enterprise Security Architecture and Assessment

Learn the essentials of Enterprise Security Design for security engineering with this hands on information security course. This course will bring you up to speed on the latest security-specific architecture.

Most importantly, Enterprise Security Architecture and Design shows you to implement the myriad of security technologies available on the market today in an effective and cost efficient manner.

A detailed outline of this course follows:

Day 1:
Module 1—Human Factors of Security
The human factors that make implementing security difficult; Primary personality types
encountered and their motivations for (or against) security initiatives; how social awareness can help corporate security efforts succeed.


Module 2—Objectives of Security
The Active Defense approach to security; “Defense in Depth” model; Interaction between written and electronic policy; Layered approach to security including Perimeter Security, Network Security, Host Based Security, and Human Awareness

Module 3—What The Hackers Know
Information on some of the quick and easy tools available for finding information that can be used in a more coordinated attack by hackers; Some common tools that identify network assets; How to show both technical and business
managers the amount of information that is
exposed via the network

Lab—CHEOPS, Site TelePort Pro, NTOP, NmapFE, KMAP

Module 4—Enemies and Their Motivation
The most common hacker personality types; The reasons they participate in these activities;
Common targets for these individuals

Day 2:
Module 5—Assessing Vulnerabilities
Practical application of risk assessment to an organization; Basic understanding of vulnerability
categories; Conducting an assessment; Commonly found weak links in an assessment; Reviewing how ‘breaking’ into your own network can be a practical way to get an accurate assessment of your risk

Lab—Vulnerability Assessment, exploit usage and windows password weaknesses

Module 6—Objectives of Risk Management
Identifying specific areas where safeguards are needed to prevent deliberate or inadvertent unauthorized disclosure, modification, or unauthorized use of information, and denial of service

• How much protection is required
• How much exists
• The most economical way of providing it
• Reducing the identified risk to an acceptable level

Lab—Risk Assessment and Costs

Module 7—Defining Security Policy
Developing computer security policies and procedures for Corporations that have systems connected to the Internet. Provide practical guidance to administrators trying to secure their information and services.

Module 8—Developing Electronic Policy
Security tools by and large require that you create electronic policies from the written security policy in order to enforce compliance on the network we examine e-policies, often referred to as electronic or enforceable policies, and how they are used.

Lab—Translate Written Policy into E-Policy

Module 14—Identifying Attack Signatures

• Identifying signature by category of attack
• Identifying normal attack flow
• Identifying inspection and evasion of IDS
• Identifying potential false positives of IDS
• Identifying limitations in IDS monitoring

Lab—Integrity verification and log monitoring

Day 3:
Module 9—Policy Enforcement with Technology
Keeping the organization in compliance with their policies; Training and awareness programs;
Enforcement using technical tools, Checking compliance and enforcing policy

Lab—Responding to CERT Alerts

Module 10—Electronic Policy Baselines for Systems
Developing good security through system baselines; Using scripts to automate baseline implementation; Tools for detecting system changes

Lab-Security Configuration Manager

Module 11—Structured Monitoring
Identifying policy and procedures; Log procedures using the Defense in Depth model; Identifying Critical and Weak link systems; Centralized, Remote, and
Decentralized Monitoring; Hardening the Monitoring Stations; Minimizing Management Consoles

Day 4:
Module 12—Intrusion Detection and Centralized Monitoring
Setup of a centralized monitoring system for a corporation; Identify cost effective placement of
monitoring devices; Remote administration of monitoring systems

Lab—Snort & Packet Analysis

Module 13— Overcoming Difficulty in Monitoring
Intrusion Detection: Differentiation of what is relevant to the Intrusion sequence, what is not relevant, and what is not part of the sequence.

Lab—Analyzing Attacks

Day 5:
Module 15—Justifying the Cost of Security
A business case is made for Return of Security Investment by showing some areas where security saves money on labor and other items.

Module 16—Incident Investigation Methods
Incident investigation: the process, tools, and methods

• Avoiding “contaminating” evidence
• Definitions of common response terms
• Identification of business and legal considerations
• Understanding of the time sensitivity of response

Module 17—Understanding the Logs
Tools and methods for identifying critical information contained in the log files

Lab—IIS Log Analysis

Module 18—Security Planning for Electronic Business
Overview of the considerations necessary to securely and successfully implement electronic business over the Internet. Identifying the business structure required for conducting electronic business, identifying and minimizing the threats to electronic commerce, including threats that may involve electronic commerce ‘partners’.