Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Certificate
Duration 28 hours
Course Outline
DOMAIN 1: CYBERSECURITY CONCEPTS
- 1.1 Understanding of information assurance (IA) principles applied to manage risks associated with the use, processing, storage, and transmission of information or data.
- 1.2 Comprehension of security management frameworks.
- 1.3 Familiarity with risk management processes, including assessment steps and methodologies.
- 1.4 Awareness of the organisation's enterprise information technology (IT) goals and objectives.
- 1.5 Understanding of various operational threat environments (e.g., first-generation [script kiddies], second-generation [non-nation state-sponsored], and third-generation [nation state-sponsored]).
- 1.6 Knowledge of information assurance (IA) principles and organisational requirements pertinent to confidentiality, integrity, availability, authentication, and non-repudiation.
- 1.7 Awareness of common adversary tactics, techniques, and procedures (TTPs) within assigned areas of responsibility (e.g., historical country-specific TTPs, emerging capabilities).
- 1.8 Understanding of different attack classifications (e.g., passive, active, insider, close-in, distribution).
- 1.9 Familiarity with relevant legislation, policies, procedures, and governance requirements.
- 1.10 Knowledge of relevant legal, policy, and governance frameworks concerning work that may impact critical infrastructure.
DOMAIN 2: CYBERSECURITY ARCHITECTURE PRINCIPLES
- 2.1 Understanding of network design processes, including security objectives, operational goals, and trade-offs.
- 2.2 Familiarity with security system design methods, tools, and techniques.
- 2.3 Knowledge of network access, identity, and access management (e.g., public key infrastructure [PKI]).
- 2.4 Understanding of information technology (IT) security principles and methods (e.g., firewalls, demilitarized zones, encryption).
- 2.5 Familiarity with current industry practices for evaluating, implementing, and distributing IT security assessment, monitoring, detection, and remediation tools, utilising standards-based concepts.
- 2.6 Understanding of network security architecture concepts, including topology, protocols, components, and principles (e.g., application of defence in depth).
- 2.7 Knowledge of malware analysis concepts and methodologies.
- 2.8 Familiarity with intrusion detection methodologies and techniques for identifying host- and network-based intrusions via detection technologies.
- 2.9 Understanding of defence in depth principles and network security architecture.
- 2.10 Knowledge of encryption algorithms (e.g., Internet Protocol Security [IPSec], Advanced Encryption Standard [AES], Generic Routing Encapsulation [GRE]).
- 2.11 Familiarity with cryptology.
- 2.12 Understanding of encryption methodologies.
- 2.13 Knowledge of traffic flow across networks (e.g., Transmission Control Protocol and Internet Protocol [TCP/IP], Open Systems Interconnection model [OSI]).
- 2.14 Familiarity with network protocols (e.g., Transmission Control Protocol and Internet Protocol).
DOMAIN 3: SECURITY OF NETWORK, SYSTEM, APPLICATION AND DATA
- 3.1 Understanding of computer network defence (CND) and vulnerability assessment tools, including open-source options, and their capabilities.
- 3.2 Familiarity with basic system administration, network, and operating system hardening techniques.
- 3.3 Awareness of risks associated with virtualisation.
- 3.4 Knowledge of penetration testing principles, tools, and techniques (e.g., Metasploit, NeoSploit).
- 3.5 Understanding of network systems management principles, models, methods (e.g., end-to-end performance monitoring), and tools.
- 3.6 Familiarity with remote access technology concepts.
- 3.7 Knowledge of systems administration concepts.
- 3.8 Familiarity with the Unix command line.
- 3.9 Understanding of system and application security threats and vulnerabilities.
- 3.10 Knowledge of system lifecycle management principles, including software security and usability.
- 3.11 Awareness of local specialised system requirements (e.g., critical infrastructure systems not using standard IT) for safety, performance, and reliability.
- 3.12 Detailed knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] injections, race conditions, covert channels, replay attacks, return-oriented attacks, malicious code).
- 3.13 Understanding of the social dynamics of computer attackers in a global context.
- 3.14 Familiarity with secure configuration management techniques.
- 3.15 Knowledge of the capabilities and applications of network equipment, including hubs, routers, switches, bridges, servers, transmission media, and related hardware.
- 3.16 Understanding of communication methods, principles, and concepts supporting network infrastructure.
- 3.17 Familiarity with common networking protocols (e.g., Transmission Control Protocol and Internet Protocol [TCP/IP]) and services (e.g., web, mail, Domain Name System [DNS]), and how they interact to enable network communications.
- 3.18 Understanding of different types of network communication (e.g., Local Area Network [LAN], Wide Area Network [WAN], Metropolitan Area Network [MAN], Wireless Local Area Network [WLAN], Wireless Wide Area Network [WWAN]).
- 3.19 Knowledge of virtualisation technologies, as well as virtual machine development and maintenance.
- 3.20 Familiarity with application vulnerabilities.
- 3.21 Understanding of information assurance (IA) principles and methods applicable to software development.
- 3.22 Knowledge of risk and threat assessment.
DOMAIN 4: INCIDENT RESPONSE
- 4.1 Understanding of incident categories, response protocols, and timelines.
- 4.2 Familiarity with disaster recovery and business continuity plans.
- 4.3 Knowledge of data backup, backup types (e.g., full, incremental), and recovery concepts and tools.
- 4.4 Understanding of incident response and handling methodologies.
- 4.5 Familiarity with security event correlation tools.
- 4.6 Awareness of investigative implications arising from hardware, operating systems, and network technologies.
- 4.7 Knowledge of processes for seizing and preserving digital evidence (e.g., chain of custody).
- 4.8 Understanding of types of digital forensics data and methods to recognise them.
- 4.9 Familiarity with basic concepts and practices for processing digital forensic data.
- 4.10 Knowledge of anti-forensics tactics, techniques, and procedures (TTPs).
- 4.11 Familiarity with common forensic tool configuration and support applications (e.g., VMware, Wireshark).
- 4.12 Understanding of network traffic analysis methods.
- 4.13 Knowledge of which system files (e.g., log files, registry files, configuration files) contain relevant information and their locations.
DOMAIN 5: SECURITY OF EVOLVING TECHNOLOGY
- 5.1 Awareness of new and emerging information technology (IT) and information security technologies.
- 5.2 Understanding of emerging security issues, risks, and vulnerabilities.
- 5.3 Familiarity with risks associated with mobile computing.
- 5.4 Understanding of cloud concepts relating to data and collaboration.
- 5.5 Awareness of risks involved in migrating applications and infrastructure to the cloud.
- 5.6 Understanding of risks associated with outsourcing.
- 5.7 Familiarity with supply chain risk management processes and practices.
Requirements
There are no specific prerequisites for attending this course.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6400 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (3)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
Speed of response and communication