Online Course – ISC2 Certified Systems Security Practitioner (SSCP) Certification

Advance your IT career with cyber skills. Gain flexibility with self-paced learning.

Suggested by: Coursera (What is Coursera?)

Professional Certificate

Beginners

No prior knowledge required

Time to complete the course

7-day free trial

No unnecessary risks

Skills you will acquire in the course

  • Access Controls
  • Communications Security
  • Data Security
  • Risk Identification
  • Java Cryptographic Architecture
  • Network Security
  • Risk Monitoring

What you will learn in the course

Courses for which the course is suitable

  • Information Security Specialist
  • Information Security Analyst
  • Information Security Manager
  • Risk Management Specialist
  • Cryptography expert
  • Secure Network Manager
  • Incident Response Specialist
  • Systems and Application Security Manager

Internship – 7-part course series

Pursue better job opportunities in information security and prove your security knowledge. The SSCP professional training certificate shows employers that you have the information security fundamentals to protect against cyber attacks – and provides a clear path to SSCP certification.

Learn at your own pace with 120 days of access to content tailored to the latest ISC2 SSCP exam topics.

3 steps to career advancement:

  • Register for the course
  • Get access for 120 days
  • Register and test yourself on the SSCP certification exam.

Upon completion of the SSCP Professional Certificate Program, you will be able to:

  • Master seven courses that prepare you for the Systems Security Certified Practitioner (SSCP) certification exam as detailed below:
    • Course 1 – Security Concepts and Practices
    • Course 2 – Access Control
    • Course 3 – Risk Identification, Monitoring and Analysis
    • Course 4 – Incident Response and Recovery
    • Course 5 – Cryptography
    • Course 6 – Network and Communications Security
    • Course 7 – Systems and Application Security
  • You will receive a program completion certificate.
  • You will understand how to implement, monitor, and manage your organization’s infrastructure in accordance with information security policies and procedures that ensure the confidentiality, integrity, and availability of data.

Hands-on Learning Project

Each course includes content that will require students to apply the knowledge they have acquired during the course. Successful completion of each course will require a basic understanding of the topics studied and the ability to relate them to the real world. The goal of each project is to determine whether students have understood the course concepts and can use them in a practical context.

Details of the courses that make up the specialization

Security concepts and procedures

Course 1
Duration: 9 hours
Rating: 4.6 (15 ratings)

Course details
What will you learn?
Course 1 – Security Concepts and Procedures
This is the first course under the SSCP specialization.

In this course, we will focus on the key aspects of security concepts and practices, starting with the importance of ethical codes. We will discuss the basic principles of information security and move on to describe security controls, their implementation, maintenance, and evaluation. We will also discuss the identification of company assets and the change management lifecycle. We will also clarify the importance of awareness and training, and finally explore physical security activities.

Learning objectives of course 1
After completing the course, the participant will be able to:

  • Mention the ISC2 Code of Ethics.
  • Explain the importance of an organizational code of ethics in the field of cyber.
  • Compare security concepts: confidentiality, integrity, and availability.
  • Implement responsibility in implementing data protection controls.
  • Explain the concept of non-repudiation.
  • Discuss the concept of a minimum right.
  • Point out the importance of separation of duties.
  • Distinguish between technical, physical, and administrative security controls.
  • Link security controls to compliance requirements and organizational needs.
  • State the importance of periodic auditing and reviewing security controls.
  • Categorize different types of controls or technologies based on their role in the overall security structure.
  • Summarize asset security at all stages of their life cycle.
  • Examine the operational requirements of change management.
  • Categorize security education and awareness strategies.
  • Define metrics to evaluate the effectiveness of a security education and awareness program.
  • Identify strategies that security personnel can use to collaborate with physical security operations.

Who should take this course: Beginners
Experience Required: No prior experience required.


Access controls

Course 2
Duration: 5 hours

Course details
What will you learn?
Course 2 – Access Controls
This is the second course under the SSCP specialization.

In this course, we will examine the business of controlling how systems, services, resources, and data can be securely accessed only by those authorized to do so. We will discuss authentication methods, trust, the identity management lifecycle, and access control models.

Learning objectives of course 2
After completing the course, the participant will be able to:

  • Classify authentication methods for implementing identity management and access control.
  • Discuss the importance of trust from a security perspective.
  • Compare levels of trust between different relationships and Internet architectures.
  • Explain the implications of trust in relationships with third parties.
  • Distinguish between identity management lifecycle activities.
  • Classify different access control models.
  • Define the elements, methods, and processes used when managing access control models.

Who should take this course: Beginners
Experience Required: No prior experience required.


Risk identification, monitoring and analysis

Course 3
Duration: 6 hours

Course details
What will you learn?
Course 3 – Risk Identification, Monitoring and Analysis
This is the third course under the SSCP specialization.

In this course, we will explore how to manage risks associated with information systems. It is time to bring these ideas together in the context of an ongoing maturity model, measurement, and management that focuses on the present. Risk alignment is best done at strategic and long-term planning levels; while risk maturity can be most effective when addressing the day-to-day aspects of business operations. This is a process often referred to as operationalizing the risk management approach.

Learning objectives of course 3
After completing the course, the participant will be able to:

  • Identify common risks and vulnerabilities.
  • Describe concepts in risk management.
  • Identify risk management frameworks.
  • Provide examples of appropriate risk tolerance.
  • Provide examples of appropriate risk management.
  • Identify the risks of violating laws and regulations.
  • Identify appropriate methods for implementing risk management frameworks.
  • Specify the scope and audit environment of the risk.
  • Identify risk audit components.
  • Describe vulnerability assessment activities designed to test all aspects of network and system security.
  • Review the steps for managing monitoring, incident detection, and data loss prevention.
  • Categorize the use of tools that collect information about the technological environment to examine the organization’s security posture.
  • Identify suspicious events and focus on those that could be part of an attack or hack.
  • Choose methods for managing log files.
  • Describe tools and methods for analyzing the results of monitoring efforts.
  • Identify communication requirements when documenting and reporting monitoring results on security platforms.

Who should take this course: Beginners
Experience Required: No prior experience required.


Response and consolidation of faults

Course 4
Duration: 4 hours

Course details
What will you learn?
Course 4 – Fault Response and Consolidation
This is the fourth course under the SSCP specialization.

In this course, we will focus on incident response and consolidation. We will explore the incident lifecycle as defined by NIST and continue with an in-depth look at supporting forensic investigations. We will also expand on these ideas and issues around the topic of business continuity and disaster recovery.

Learning objectives of course 4
After completing the course, the participant will be able to:

  • Identify the components of the incident response policy and members of the Incident Response Team (IRT).
  • Evaluate the role of the security officer in supporting forensic investigations.
  • Explain how the security officer supports business continuity planning and disaster recovery activities.

Who should take this course: Beginners
Experience Required: No prior experience required.


Cryptography

Course 5
Duration: 5 hours
Rating: 5.0 (10 ratings)

Course details
What will you learn?
Course 5 – Cryptography
This is the fifth course under the SSCP specialization.

In this course, we will explore the field of cryptography, including public key infrastructures (PKI), certificates, and digital signatures. This is where we enter the realm of confidentiality, integrity, and availability, as we use cryptography to protect data from unauthorized disclosure and improper protection, and use encryption to regulate users’ ability to connect to systems and applications.

Learning objectives of course 5
After completing the course, the participant will be able to:

  • Identify the effects of cryptography on confidentiality, integrity, and authenticity.
  • Determine the requirements for cryptography in handling sensitive data.
  • Identify best industry standards and recommendations in the field of cryptography.
  • Define the entropy of cryptography.
  • Distinguish between common cryptographic techniques used to strengthen the security of sensitive data including omission, implementation, symmetric/asymmetric encryption, and elliptic curve-based encryption.
  • Identify the characteristics and requirements of non-repudiation.
  • Compare the strength of different encryption algorithms and keys.
  • Describe the process of identifying and handling cryptographic attacks.
  • Define the characteristics of the implementation process for secure services and functions.
  • Discuss common use cases for secure services and functions.
  • Explain limitations and vulnerabilities in implementing secure populations.
  • Summarize basic key management concepts.
  • Describe the characteristics of the Web of Trust (WoT) in the context of cryptographic protocols.

Who should take this course: Beginners
Experience Required: No prior experience required.


Network and communications security

Course 6
Duration: 9 hours

Course Details
What you’ll learn
Course 6 – Network and Communications Security
Welcome to Course 6: Network and Communications Security. As we know, the massive growth in networks, connections, and communications has paved the way for an unprecedented shift in business, personal, and government services to electronic forms, exposed online. The growth of digital business and e-commerce has greatly expanded the threat landscape. Fraudsters, criminals, unscrupulous competitors, states, and non-state actors can take harmful actions against others around the world. In recent decades, the world has operated on what is essentially a single network culture. A single set of protocols and standards has been used to support most of the culture of the Internet, the Web, e-commerce, and digital services. These standards include the International Organization for Standardization’s seven-layer model. This exam is designed to deepen security professionals’ knowledge of these models.

Learning objectives of course 6
After completing the course, the participant will be able to:

  • Identify the layers of the OSI model, the functions and attacks at each layer.
  • Identify commonly used ports and protocols.
  • Choose appropriate response measures for various network attacks.
  • Summarize the practices that are essential for creating secure network environments.

Course fee
Module 1: Applying the Basic Concepts of Networks (Domain 6 – Network and Communication Security)
Module 2: Port and Protocol Security (Area 6 – Network and Communications Security)
Module 3: Network Attacks and Response Measures (Area 6 – Network and Communications Security)
Module 4: Network Security Management (Area 6 – Network and Communications Security)

Who should take this course: Beginners
Experience Required: No prior experience required.


Systems and application security

Course 7
Duration: 10 hours

Course details
What will you learn?
Course 7 – Systems and Application Security
This is the seventh course under the SSCP specialization.

This course discusses two major influences on our data usage in recent years: the shift to mobile and cloud-based services. First, we use our data in real time through data services offered to smartphones, Wi-Fi, and other devices. Second, many of the enhanced functions we take for granted in our personal and professional lives are enabled by cloud services, where we store or process our data.

Learning objectives of course 7
After completing the course, the participant will be able to:

  • Categorize different types of malware.
  • Determine how to implement malware response measures.
  • Identify different types of malicious actions.
  • Develop strategies to reduce malicious actions.
  • Describe different social engineering methods used by attackers.
  • Explain the role of behavioral analysis technologies in identifying and preventing threats.
  • Explain the role and operation of Host-Based Intrusion Prevention Systems (HIPS), Host-Based Intrusion Detection Systems (HIDS), and Host-Based Firewalls.
  • Evaluate the benefits of application certification in securing endpoint devices.
  • Explain the concept of end-device encryption and its role in securing end devices.
  • Describe the role and operation of the Trusted Platform Module (TPM) in providing hardware-based security capabilities.
  • Identify the steps in implementing secure browsing practices using digital certificates and secure communication protocols.
  • Explain the concept of Endpoint Detection and Response (EDR) and its role in providing real-time monitoring, detection, investigation, and response capabilities to identify and mitigate advanced threats and security incidents on endpoints.
  • Identify deployment techniques for mobile devices.
  • Explain the concept of containerization and how it contributes to effective management of mobile devices.
  • Explain how encryption contributes to effective management of mobile devices.
  • Describe the Mobile Application Management (MAM) process to effectively manage the mobile application lifecycle.
  • Distinguish between public, private, hybrid, and community deployment models in cloud security.
  • Distinguish between different service models and their impact on cloud security practices.
  • Describe virtualization technologies and their role in providing cloud security.
  • Identify legal and regulatory issues related to cloud security.
  • Determine strategies for implementing data storage, processing, and transfer while maintaining cloud security.
  • Explain the requirements and considerations related to third-party and external cloud security services.
  • Explain the shared responsibility model in cloud storage.
  • Identify steps for managing and securing hypervisor environments.
  • Explain how to deploy, configure, and maintain virtual appliances within virtual environments.
  • Determine the process for managing container environments.
  • Describe the best practices for managing storage in virtual environments.
  • Develop strategies for achieving business continuity and resilience in virtual environments.
  • Analyze potential threats and attacks targeting virtual environments.

Who should take this course: Beginners
Experience Required: No prior experience required.