Security concepts and practices
Course 1 – 9 hours
Course Details: Course 1 – Security Concepts and Practices This is the first course in the SSCP specialization. In this course we will focus on the key aspects of security concepts and practices, starting with the importance of Codes of Ethics. We will then address the basic principles of information security and continue to describe security measures, their implementation, maintenance, and evaluation.
- Remember the ISC2 Code of Ethics.
- Explain the importance of the code of ethics in an organization in the field of cybersecurity.
- Compare the security concepts of confidentiality, integrity, and availability.
- Exercise responsibility in the implementation of certain information security measures.
- Explain the concept of non-denial.
- Discuss the concept of minimum powers.
- Note the importance of separation of duties.
- Distinguish between technological, physical, and administrative security measures.
- Link security measures to considerations of assessing compliance requirements and organizational needs.
- Note the importance of periodic auditing and review of security measures.
- Classify different types of security measures or technologies according to their different functions.
- Summarize asset security at all stages of their life cycle.
- Review the operational requirements of change management.
- Categorize security education and awareness strategies.
- Define metrics to evaluate the effectiveness of a security education and awareness program.
- Identify strategies that can be used to collaborate with physical security operations.
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: Security concepts, access controls
Access controls
Course 2 – 5 hours
Course Details: Course 2 – Access Controls This is the second course in the SSCP specialization. In this course, we will explore the businesses that need to control how their systems, services, resources, and data are only accessible to those authorized to do so.
- Categorize identity management strategies and authentication methods.
- Discuss the importance of trust from a security perspective.
- Compare trust levels between different relationships and network architectures.
- Explain the implications of trust between third-party connections.
- Differentiate between identity management lifecycle activities.
- Classify different models of access controls.
- Define the components, methods, and resources used when managing access control models.
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: Access control
Risk identification, monitoring and analysis
Course 3 – 6 hours
Course Details: Course 3 – Identifying, Monitoring, and Analyzing Risks This is the third course in the SSCP specialization. In this course, we will explore how to manage the risks associated with information systems.
- Identify common risks and vulnerabilities.
- Describe risk management concepts.
- Get to know risk management frameworks.
- Provide examples of appropriate risk tolerance.
- Provide examples of appropriate risk management.
- Identify risks of non-compliance with laws and regulations.
- Identify appropriate methods for implementing risk management frameworks.
- Specify the scope and summary of the risk review.
- Identify the components of a risk review.
- Describe vulnerability assessment activities.
- Review the steps for monitoring, event detection, and data loss prevention.
- Classify the use of tools to collect information about the technological environment.
- Identify events that interest us.
- Choose methods for managing log files.
- Describe tools and methods for analyzing the results of monitoring efforts.
- Identify communication requirements when documenting and reporting monitoring results.
Who should take this course:
Beginners
Experience Required: No prior experience required.
What you can purchase: Risk management
Response and recovery to events
Course 4 – 4 hours
Course Details: Course 4 – Incident Response and Recovery This is the fourth course in the SSCP specialization. This course will focus on incident response and recovery.
- Identify the components of incident response policy.
- Evaluate the role of the security specialist in supporting forensic investigations.
- Explain how the security specialist supports business continuity planning activities.
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: Information Security
Cryptography
Course 5 – 5 hours
Course Details: Course 5 – Cryptography This is the fifth course in the SSCP specialization. In this course we will explore the field of cryptography.
- Understand the effects of cryptography on confidentiality, integrity, and authentication.
- Determine the requirements for cryptography when working with sensitive data.
- Identify cryptography standards in the industry.
- Define the concept of non-denial.
- Differentiate between common cryptographic techniques.
- Identify the benefits and requirements of non-denial.
- Compare the power of different algorithms.
- Describe the process of identifying and handling cryptographic attacks.
- Define the features and requirements of secure services and protocols.
- Discuss common uses for secure services and protocols.
- Explain the limitations and vulnerabilities in implementing secure protocols.
- Summarize the basic key management concepts.
- Describe the features of the Web of Trust (WoT).
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: Cryptography
Network and communications security
Course 6 – 9 hours
Course Details: Course 6 – Network and Communications Security. In this course we will explore network security.
- Get to know the layers of the OSI model.
- Identify commonly used ports and protocols.
- Choose appropriate countermeasures for various network attacks.
- Summarize best practices for creating a secure online environment.
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: Network security
Systems and application security
Course 7 – 10 hours
Course Details: Course 7 – Systems and Application Security. This course deals with significant changes in recent years in how we use our data.
- Categorize different types of malware.
- Determine how to implement anti-malware measures.
- Identify different types of harmful activities.
- Develop strategies to reduce harmful activities.
- Describe different social engineering methods.
- Explain the role of behavioral analysis technologies in identifying and mitigating threats.
- Explain the role and functionality of a Host-Based Intrusion Prevention System (HIPS).
- Evaluate the benefits of application whitelisting.
- Explain the concept of endpoint encryption.
- Describe the role and functionality of the Trusted Platform Module (TPM).
- Identify the steps to implement secure browsing practices.
- Explain the concept of endpoint detection and response (EDR).
- Identify deployment techniques for mobile devices.
- Explain the concept of containerization.
- Explain how encryption contributes to mobile device management.
- Describe the mobile application management (MAM) process.
- Distinguish between different cloud deployment models.
- Describe virtualization technologies and their role in ensuring cloud security.
- Identify legal and regulatory issues related to cloud security.
- Determine strategies for implementing data storage, processing, and transmission.
- Explain the requirements and references related to third-party services.
- Explain the concept of the shared responsibility model in cloud storage services.
- Identify steps to manage and protect hypervisor environments.
- Explain how to deploy, configure, and maintain virtual appliances.
- Determine the process for managing container environments.
- Describe best practices for managing storage in virtual environments.
- Develop strategies to ensure business continuity and resilience in virtual environments.
- Analyze potential threats and attacks targeting virtual environments.
Who should take this course:
Beginners
Experience Required: No prior experience required.
Skills you will acquire: System and application security