CISSP Platinum Training DVD
-
Torrent:
-
Category:
-
Private Client:Hide your personal activity while downloading torrents with TorrentPrivacy.com
-
Size:8711 MB
-
Seeds/Leechs:
-
Added:04/21/2008
-
Last check:2009-11-25 14:02:07
-
Tracker:http://elbitz.net
-
Comments:Please seed after download<br /> <br /> Domain 1 - Information Security and Risk Management<br /> Information Security and Risk Management<br /> Mainframe Days<br /> In the Good Old Days –Who Knew?<br /> Today’s Environment<br /> Security Definitions<br /> Vulnerabilities<br /> Examples of Some Vulnerabilities that Are Not Always Obvious<br /> Risk – What Does It Really Mean?<br /> Relationships<br /> Who Deals with Risk?<br /> Overall Business Risk<br /> Who?<br /> AIC Triad<br /> Availability<br /> Integrity<br /> Confidentiality<br /> Who Is Watching?<br /> Social Engineering<br /> What Security People Are Really Thinking<br /> Security Concepts<br /> Security?<br /> The Bad Guys Are Motivated<br /> If Not Obscurity – Then What?<br /> Open Standards<br /> Common Open Standards<br /> Without Standards<br /> “Soft” Controls<br /> Logical Controls<br /> Physical Controls<br /> Are There Gaps?<br /> Understanding Drivers<br /> Holistic Security<br /> Not Always So Easy<br /> What Is First?<br /> Different Types of Law<br /> How Is Liability Determined?<br /> Examples of Due Diligence<br /> Examples of Due Care<br /> Prudent Person Rule<br /> Prudent Person<br /> Taking the Right Steps<br /> Regulations<br /> Why Do We Need Regulations?<br /> Risk Management<br /> Why Is Risk Management Difficult?<br /> Necessary Level of Protection Is Different for Each Organization<br /> Security Team/Committee<br /> Risk Management Process<br /> Planning Stage – Team<br /> Analysis Paralysis<br /> Planning Stage – Scope<br /> Planning Stage – Analysis Method<br /> Risk Management Tools<br /> Defining Acceptable Levels<br /> Acceptable Risk Level<br /> Collecting and Analyzing Data Methods<br /> What Is a Company Asset?<br /> Data Collection – Identify Assets<br /> Data Collection – Assigning Values<br /> Asset Value<br /> Data Collection – Identify Threats<br /> Data Collection – Calculate Risks<br /> Scenario Based – Qualitative<br /> Risk Approach<br /> Qualitative Analysis Steps<br /> Want Real Answers?<br /> Qualitative Risk Analysis Ratings<br /> Qualitative Risks<br /> Quantitative Analysis Steps<br /> Quantitative Analysis<br /> How Often Will This Happen?<br /> ARO Values and Their Meaning<br /> Calculate ALE<br /> ALE Value Uses<br /> Relationships<br /> Calculate Risks – ALE Example<br /> Your Turn!<br /> ALE Calculation<br /> Can a Purely Quantitative Analysis Be Accomplished?<br /> Risk Types<br /> Examples of Types of Losses<br /> Delayed Loss<br /> Cost/Benefit Analysis<br /> Cost of a Countermeasure<br /> Cost/Benefit Analysis Countermeasure Criteria<br /> Calculating Cost/Benefit<br /> Controls<br /> Control Selection Requirements<br /> Quantitative Analysis<br /> Quantitative Analysis Disadvantages<br /> Qualitative Analysis Approach<br /> Qualitative Analysis Disadvantages<br /> Can You Get Rid of All Risk?<br /> Calculating Residual Risk<br /> Uncertainty Analysis<br /> Dealing with Risk<br /> Management’s Response to Identified Risks<br /> Risk Acceptance<br /> Risk Analysis Process Summary<br /> Components of Security Program<br /> A Layered Approach<br /> In Security, You Never Want Any Surprises<br /> Building Foundation<br /> Security Roadmap<br /> Functional and Assurance Requirements<br /> Building Foundation<br /> Most Organizations<br /> Silo Security Structure<br /> Islands of Security Needs and Tools<br /> Get Out of a Silo Approach<br /> Security Is a Process<br /> Approach to Security Management<br /> Result of Battling Management<br /> Industry Best Practices Standards<br /> ISO/IEC 17799<br /> Pieces and Parts<br /> Numbering<br /> New ISO Standards<br /> COBIT<br /> Inside of COBIT<br /> COBIT – Control Objectives<br /> Measurements<br /> Information Technology Infrastructure Library<br /> Security Governance<br /> Security Program Components<br /> Policy Framework<br /> Policy Types<br /> Organizational Policy<br /> Policy Approved – Now What?<br /> Issue-Specific Policies<br /> ASP Policy Example<br /> System-Specific Policies<br /> Standards<br /> Standard Example<br /> Baseline<br /> Data Collection for Metrics<br /> Guidelines<br /> Procedures<br /> Tying Them Together<br /> Program Support<br /> Entity Relationships<br /> Senior Management’s Role<br /> Security Roles<br /> Custodian<br /> Auditor<br /> Access<br /> Information Classification<br /> Information Classification Program<br /> Data Leakage<br /> Do You Want to End Up in the News?<br /> Types of Classification Levels<br /> Data Protection Levels<br /> Classification Program Steps<br /> Information Classification Components<br /> Procedures and Guidelines<br /> Classification Levels<br /> Information Classification Criteria<br /> Criteria Example<br /> Or Not<br /> Information Owner Requirements<br /> Clearly Labeled<br /> Testing Classification Program<br /> Who Is Always Causing Problems?<br /> Employee Management<br /> Employee Position and Management<br /> Hiring and Firing Issues<br /> A Few More Items<br /> Unfriendly Termination<br /> Security Awareness and Training<br /> Training Characteristics<br /> Awareness<br /> Security Enforcement Issues<br /> Answer This Question<br /> Domain 1 Review<br /> Domain 2 - Access Control Domain Objectives<br /> Agenda 1<br /> Definitions<br /> Access Control Mechanism Examples<br /> Technical Controls<br /> Administrative Controls<br /> Access Control Characteristics<br /> Preventive Controls<br /> Preventive - Administrative Controls<br /> Preventive – Physical Controls<br /> Preventive - Technical Controls<br /> Control Combinations<br /> Detective - Administrative Control<br /> Detective Examples<br /> Administrating Access Control<br /> OS, Application, Database<br /> Administrating Access Control<br /> Authorization Creep<br /> Accountability and Access Control<br /> Trusted Path<br /> Fake Login Pages Look Convincing<br /> Who Are You?<br /> Identification Issues<br /> Authentication Mechanisms Characteristics<br /> Strong Authentication<br /> Fraud Controls<br /> Internal Control Tool: Separation of Duties<br /> Authentication Mechanisms in Use Today<br /> Biometrics Technology<br /> Biometric Devices<br /> Example<br /> Verification Steps<br /> What a Person Is<br /> Why Use Biometrics?<br /> Biometric Type<br /> Identification or Authentication?<br /> Iris Sampling<br /> Iris<br /> Finger Scan<br /> Hand Geometry<br /> Facial Recognition<br /> Comparison<br /> Biometrics Verification<br /> Issues<br /> Downfalls to Biometric Use<br /> Biometrics Error Types<br /> Crossover Error Rate<br /> Biometric System Types<br /> Passwords<br /> Password Generators<br /> Password “Shoulds”<br /> Support Issues<br /> Password Attacks<br /> Attack Steps<br /> Many Tools to Break Your Password<br /> Rainbow Table<br /> Passwords Should NOT Contain…<br /> What’s Left?<br /> Countermeasures for Password Cracking<br /> Cognitive Passwords<br /> One-Time Password Authentication<br /> Synchronous Token<br /> One Type of Solution<br /> Synchronous Steps<br /> Administrator Configures<br /> Challenge Response Authentication<br /> Asynchronous Token Device<br /> Asynchronous Steps<br /> Challenge Response Authentication<br /> Cryptographic Keys<br /> Passphrase Authentication<br /> Key Protection<br /> Memory Cards<br /> Memory Card Characteristics<br /> Smart Card<br /> Characteristics<br /> Card Types<br /> Smart Card Attacks<br /> Software Attack<br /> Side Channel Attack<br /> Side Channel Data Collection<br /> Microprobing<br /> Identity Management<br /> How Are These Entities Controlled?<br /> Some Current Issues<br /> Management<br /> Typical Chaos<br /> Different Identities<br /> Identity Management Technologies<br /> Directory Component<br /> Enterprise Directory<br /> Directory Responsibilities<br /> Authoritative Sources<br /> Meta Directory<br /> Directory Interactions<br /> Web Access Management<br /> Web Access<br /> Password Management<br /> Legacy Single Sign-On<br /> Account Management Systems<br /> Provisioning Component<br /> Provisioning<br /> Not Just Computers<br /> Profile Update<br /> Working Together<br /> Enterprise Directory<br /> Identity Management Solution Components<br /> Right for Your Company<br /> What you need to know<br /> Federated Identity<br /> Identity Theft<br /> Fake Login Tools<br /> How Do These Attacks Work?<br /> Attempts to Get Your Credentials<br /> How Do These Work?<br /> Instructional Emails<br /> Knowing What You Are Disposing of Is Important<br /> Other Examples<br /> Another Danger to Be Aware of… Spyware<br /> Is Someone Watching You?<br /> What Does This Have to Do with My Computer?<br /> Sometimes You Know that Software Is Installing on Your System<br /> New Spyware Is Being Identified Every Week<br /> Spyware Comes in Many Different Forms<br /> How to Prevent Spyware<br /> Different Technologies<br /> Single Sign-on Technology<br /> Single Sign-on<br /> Directory Services as a Single Sign-on Technology<br /> Active Directory<br /> Some Technologies Can Combine Services<br /> Security Domain<br /> Domains of Trust<br /> Domain Illustration<br /> Thin Clients<br /> Example<br /> Kerberos as a Single Sign-on Technology<br /> Kerberos Components Working Together<br /> Pieces and Parts<br /> More Components of Kerberos<br /> KDC Components<br /> Kerberos Steps<br /> Tickets<br /> Ticket Components<br /> Authenticators<br /> Steps of Validation<br /> Kerberos Security<br /> Why Go Through All of this Trouble?<br /> Issues Pertaining to Kerberos<br /> Kerberos Issues<br /> SESAME as a Single Sign-on Technology<br /> SESAME Steps for Authentication<br /> Combo<br /> Models for Access<br /> Access Control Models<br /> Discretionary Access Control Model<br /> ACL Access<br /> File Permissions<br /> Enforcing a DAC Policy<br /> Security Issues<br /> Mandatory Access Control Model<br /> MAC Enforcement Mechanism – Labels<br /> Formal Model<br /> Software and Hardware<br /> Software and Hardware Guards<br /> Where Are They Used?<br /> SELinux<br /> MAC Versus DAC<br /> Role-Based Access Control<br /> RBAC Hierarchy<br /> RBAC and SoD<br /> Acquiring Rights and Permissions<br /> Rule-Based Access Control<br /> Firewall Example<br /> Access Control Matrix<br /> Capability Tables<br /> User Capability Tables<br /> Temporal Access Control<br /> Access Control Administration<br /> Access Control Methods<br /> Centralized Approach<br /> Remote Centralized Administration<br /> RADIUS<br /> RADIUS Steps<br /> RADIUS Characteristics<br /> TACACS+ Characteristics<br /> Diameter Characteristics<br /> Diameter Protocol<br /> Mobile IP<br /> Diameter Architecture<br /> Two Pieces<br /> AVP<br /> Decentralized Access Control Administration<br /> Controlling Access to Sensitive Data<br /> Protecting Access to System Logs<br /> Accountability = Auditing Events<br /> Agenda 2<br /> IDS<br /> IDS Steps<br /> Network IDS Sensors<br /> Host IDS<br /> Combination<br /> Types of IDSs<br /> Signature-Based Example<br /> Behavior-Based IDS<br /> Statistical Anomaly<br /> Statistical IDS<br /> Protocol Anomaly<br /> What Is a Protocol Anomaly?<br /> Protocol Anomaly Issues<br /> Traffic Anomaly<br /> IDS Response Mechanisms<br /> Responses to Attacks<br /> IDS Issues<br /> Intrusion Prevention System<br /> Differences<br /> Vulnerable IDS<br /> Trapping an Intruder<br /> Domain 2 Review<br /> Domain 3 - Cryptography Objectives<br /> Services Provided by Cryptography<br /> Cryptographic Definitions<br /> Cipher<br /> Cryptanalysis<br /> A Few More Definitions<br /> Need Some More Definitions?<br /> Now This Would be Hard Work<br /> Symmetric Cryptography – Use of Secret Keys<br /> Historical Uses of Symmetric Cryptography – Hieroglyphics<br /> Scytale Cipher<br /> Substitution Ciphers<br /> Simple Substitution Cipher Atbash<br /> Simple Substitution Cipher Caesar Cipher<br /> Caesar Cipher Example<br /> Simple Substitution Cipher ROT13<br /> Historical Uses<br /> Polyalphabetic Cipher – Vigenere Cipher<br /> Polyalphabetic Substitution<br /> Vigenere Algorithm<br /> Enigma Machine<br /> U-Boats had Enigma Machines<br /> Code Book<br /> Historical Uses of Symmetric Cryptography – Running Key and Concealment<br /> Agenda 1<br /> Transposition Ciphers<br /> Key and Algorithm Relationship<br /> Does Size Really Matter?<br /> It Does with Key Sizes<br /> Key space<br /> Ways of Breaking Cryptosystems – Brute Force<br /> Brute Force Components<br /> Ways of Breaking Cryptosystems – Frequency Analysis<br /> Strength of a Cryptosystem<br /> Do You Know What You are Doing?<br /> Developing Cryptographic Solutions In-House<br /> Characteristics of Strong Algorithms<br /> Open or Closed More Secure?<br /> Agenda 2<br /> Types of Ciphers Used Today<br /> Type of Symmetric Cipher – Block Cipher<br /> S-Boxes Used in Block Ciphers<br /> Binary Mathematical Function 1<br /> Type of Symmetric Cipher – Stream Cipher<br /> Symmetric Characteristics<br /> Initialization Vectors<br /> Security Holes<br /> Strength of a Stream Cipher<br /> Let’s Dive in Deeper<br /> Symmetric Key Cryptography<br /> Out-of-Band Transmission<br /> Symmetric Key Management Issue<br /> Symmetric Algorithm Examples<br /> Symmetric Downfalls<br /> Why?<br /> Asymmetric Cryptography<br /> Key Functions<br /> Public Key Cryptography Advantages<br /> Asymmetric Algorithm Disadvantages<br /> Confusing Names<br /> Symmetric versus Asymmetric<br /> Asymmetric Algorithm Examples<br /> Questions 1<br /> When to Use Which Key<br /> Using the Algorithm Types Together<br /> Encryption Steps<br /> Receiver's Public Key Is Used to Encrypt the Symmetric Key<br /> Receiver’s Private Key Is Used to Decrypt the Symmetric Key<br /> Digital Envelope<br /> E-mail Security<br /> Secret versus Session Keys<br /> Asymmetric Algorithms We Will Dive Into<br /> Asymmetric Algorithm – Diffie-Hellman<br /> Diffie-Hellman<br /> Key Agreement Schemes<br /> Asymmetric Algorithm – RSA<br /> Factoring Large Numbers<br /> RSA Operations<br /> RSA Key Size<br /> El Gamal<br /> ECC<br /> ECC Benefits<br /> Asymmetric Mathematics<br /> Asymmetric Security<br /> Mathematics<br /> Symmetric Ciphers We Will Dive Into<br /> Symmetric Algorithms – DES<br /> Block Cipher<br /> Double DES<br /> Evolution of DES<br /> Modes of 3DES<br /> Encryption Modes<br /> Block Cipher Modes – CBC<br /> IV and CBC<br /> CBC Example<br /> Different Modes of Block Ciphers –ECB<br /> ECB versus CBC<br /> Block Cipher Modes – CFB and OFB<br /> CFB and OFB Modes<br /> Counter Mode<br /> Modes Summary<br /> Symmetric Cipher – AES<br /> IDEA<br /> RC4<br /> RC5<br /> Agenda 3<br /> Data Integrity<br /> Hashing Steps<br /> Protecting the Integrity of Data<br /> Hashing Algorithms<br /> Data Integrity Mechanisms<br /> Hashing Strength<br /> Question 1<br /> Weakness in Using Only Hash Algorithms<br /> More Protection in Data Integrity<br /> MAC<br /> HMAC – Sender<br /> HMAC – Receiver<br /> Another Look<br /> What Services<br /> Authentication Types<br /> CBC-MAC<br /> MAC Using Block Ciphers<br /> Integrity?<br /> What Services?<br /> Question 2<br /> Digital Signatures<br /> One More Look 1<br /> U.S. Government Standard<br /> What is…<br /> Not Giving up the Farm<br /> Zero Knowledge Proof<br /> Message Integrity Controls<br /> Security Issues in Hashing<br /> Example of a Birthday Attack<br /> Birthday Attack Issues<br /> Key Management<br /> Key Backup<br /> Key Management (Cont.)<br /> Key Usage<br /> Cryptoperiod<br /> M-of-N<br /> Key Types<br /> Agenda 4<br /> Why Do We Need a PKI?<br /> PKI and Its Components<br /> Components of PKI<br /> PKI<br /> PKI Steps<br /> RA Roles<br /> CA<br /> Let’s Walk Through an Example<br /> Digital Certificates<br /> Certificate<br /> Signing the Certificate<br /> Verifying the Certificate<br /> Trusted CA’s<br /> Non-Trusted CA<br /> One More Look 2<br /> What Do You Do with a Certificate?<br /> Components of PKI, Repository, and CRLs<br /> Revoked?<br /> CRL Process<br /> Different Uses for Certificates<br /> Lifecycle of a Certificate<br /> Cross Certification<br /> PKI and Trust<br /> Agenda 5<br /> Historical Uses of Symmetric Cryptography – Vernam Cipher<br /> Binary Mathematical Function 2<br /> One-Time Pad in Action<br /> One-Time Pad Characteristics<br /> Steganography<br /> Steganography Utilities<br /> Digital Watermarking<br /> Link versus End-to-End Encryption<br /> End-to-End Encryption<br /> Encryption Location<br /> Email Standards<br /> You Decide<br /> Non-Hierarchical<br /> Secure Protocols<br /> SSL Connection Setup<br /> Example - SSL<br /> Validating Certificate<br /> Secure Protocols (Cont.)<br /> SSL and the OSI Model<br /> E-Commerce<br /> How Are You Doing?<br /> Hard the First Times Through<br /> Secure Email Standard<br /> Agenda 6<br /> Network Layer Protection<br /> IPSec Key Management<br /> IPSec Handshaking Process<br /> VPN Establishment<br /> SAs in Use<br /> Key Issues Within IPSec<br /> Configuration of SA Parameters<br /> IPSec Configuration Options<br /> IPSec Is a Suite of Protocols<br /> AH and ESP Modes<br /> IPSec Modes of Operation<br /> VPN Establishment (Cont.)<br /> Review<br /> Questions 2<br /> Attack Types<br /> Attacks on Cryptosystems<br /> Known-Plaintext Attack<br /> Chosen-Plaintext Attack<br /> Chosen-Ciphertext Attack<br /> Adaptive Attacks<br /> Side Channel Attacks<br /> Domain 3 Review<br /> Domain 4 - Physical Security Objectives<br /> Physical Security – Threats<br /> Different Types of Threats<br /> Categories of Threats<br /> Wake Up Call<br /> Not Just Hacking<br /> Number One Priority<br /> Legal Issues<br /> Planning Phase<br /> Physical Security Program Goals<br /> Measurable Results<br /> Planning Process<br /> Risk Assessment Needs to be Carried Out<br /> Deterrence<br /> Deterrence Options<br /> Delay<br /> Another Delay Approach<br /> Layered Defense Model<br /> Layers of Defense<br /> Detection<br /> Assessment<br /> Response<br /> Weak Link in the Chain<br /> Part of the Overall Security Program<br /> Controls with the Same Goals<br /> Agenda 1<br /> Threat Categories<br /> Crime Prevention through Environmental Design<br /> Crux of Approach<br /> Protection Built In<br /> CPTED Examples<br /> Natural Access Control<br /> Access Control<br /> CPTED Main Strategies<br /> Target Hardening<br /> Access Barriers<br /> Facility Site Selection<br /> Urban Camouflage<br /> Facility Construction<br /> Earthquake Protection<br /> Construction Materials<br /> Rebar Encased in Concrete<br /> Pentagon with Reinforcements<br /> Fire Resistance Walls<br /> Data Center<br /> Data Center Protection<br /> Designing a Secure Site<br /> Levels of Protection<br /> Door Types<br /> Hollow-Core Doors<br /> Solid Core Doors<br /> Bullet Proof Door<br /> Door Component<br /> Door Lock Types<br /> Window Types<br /> Controlling Access<br /> Sensitive Areas<br /> Possible Threats<br /> Security Zones<br /> Various Sensors<br /> Lock Types<br /> Controlling Keys<br /> Smart Locks<br /> Lock Picking<br /> Entry Access Control<br /> Facility Access<br /> Wireless Proximity Devices<br /> Device Types<br /> Piggybacking<br /> Entrance Protection<br /> Mantraps<br /> Door Configurations<br /> External Boundary Protection<br /> Perimeter Protection – Fencing<br /> Detection Fencing<br /> Detecting Intruders<br /> Fencing Characteristics<br /> Fencing Issues<br /> Gates<br /> What Level of Protection is Needed?<br /> Bollards<br /> Perimeter Protection – Lighting<br /> Properly Laid Out<br /> Lighting Issues<br /> Perimeter Security – Security Guards<br /> Guard Tasks<br /> Security Guards<br /> Monitoring<br /> Level of Detail that is Required<br /> CCTV<br /> Items to Consider about CCTVs<br /> CCTV Components<br /> CCTV Lens Types<br /> CCTV Components (Cont.)<br /> Agenda 2<br /> Types of Physical Intrusion Detection Systems<br /> Intrusion Detection Characteristics<br /> Electro-Mechanical Sensors<br /> Volumetric Sensors<br /> Alarm Systems<br /> Securing Mobile Devices<br /> Stolen Laptops (partial list..)<br /> Agenda 3<br /> HVAC Attributes<br /> Environmental Considerations<br /> Who’s Got Gas?<br /> Documentation of Procedures<br /> Electrical Power<br /> Backup Power<br /> Problems with Steady Power Current<br /> Power Interference<br /> Disturbances<br /> Protection Against Electromagnetic Discharge<br /> Definitions<br /> Power Preventive Measures<br /> Device Protection<br /> Consistent Power Flow<br /> Static Electricity<br /> Agenda 4<br /> Fire Prevention<br /> Not Allowed<br /> Components of Fire<br /> Fire Sources<br /> Automatic Detector Mechanisms<br /> Fire Detection<br /> Fire Suppression Agents<br /> Fire Types<br /> Emergency Power Off Switch<br /> Employees Need to be Trained<br /> Fire Suppression Systems<br /> Fire Extinguishers<br /> Emergency Procedures<br /> Drills and Testing<br /> Water Detectors<br /> Full Program<br /> Domain 5 - Security Architecture and Design Objectives<br /> Agenda 1<br /> Computer Architecture<br /> Central Processing Unit (CPU)<br /> Registers<br /> Arithmetic Logic Unit<br /> Control Unit<br /> Processing Data<br /> Register Types<br /> Program Status Word (PSW)<br /> Trust Levels<br /> Process<br /> Memory Segment Assignment<br /> Threads<br /> Process and Thread<br /> Process States<br /> Agenda 2<br /> Interrupts<br /> Interrupt Masking<br /> Process Table<br /> Moving Information<br /> Stacks<br /> Buses<br /> Processor and Buses<br /> 32-Bit versus 64-Bit<br /> Working Together<br /> Multiprocessing<br /> Multiprocessor<br /> System Functionality<br /> Multitasking Types<br /> Multitasking<br /> Deadlock<br /> Agenda 3<br /> Memory Types<br /> Cache Types<br /> Read Only Memory<br /> Virtual Memory<br /> Swapping<br /> Types of Memory<br /> Architecture Components<br /> Memory Manager Responsibilities<br /> Memory Protection<br /> Memory Manager Responsibilities (Cont.)<br /> Memory Addressing<br /> Base and Limit Addresses<br /> Shared Memory<br /> Memory Protection (Cont.)<br /> Memory Leaks<br /> Agenda 4<br /> CPU and OS<br /> System Protection – Levels of Trust<br /> Trust Levels (Cont.)<br /> System Protection - Protection Rings<br /> What Does It Mean to Be in a Specific Ring?<br /> System Protection – Layering<br /> System Call Interfaces<br /> API Application Programming Interface<br /> System Protection - Application Program Interface<br /> Process Protection<br /> Process Isolation<br /> Virtual Mapping<br /> Process ID<br /> Virtual Machines<br /> VMWare<br /> Input/Output Devices<br /> I/O Addressing<br /> Device Types<br /> Device Drivers<br /> Security Issues<br /> Software Complexity<br /> Types of Compromises<br /> Agenda 5<br /> Trusted Computing Base<br /> TCB<br /> Hardened Kernel<br /> Execution Domains<br /> Simple Definition<br /> Main Functions of TCB<br /> Process Activation<br /> Execution Domain Switching<br /> Security Perimeter<br /> Evaluation<br /> System Protection - Reference Monitor<br /> Security Kernel Requirements<br /> Tying Concepts Together<br /> Agenda 6<br /> Security Levels<br /> MAC Modes<br /> Modes of Operation<br /> MAC Modes (Cont.)<br /> Agenda 7<br /> Enterprise Architecture<br /> Objectives<br /> Without an Enterprise Security Architecture<br /> Can’t Just Wing It<br /> Just Right<br /> Breaking Down the Components<br /> Strategic Alignment<br /> Business Enablement<br /> Process Enhancement<br /> Process Enhancement Requires…<br /> Security Foundation<br /> Security Effectiveness<br /> Are We Doing it Right?<br /> Integration of Components<br /> How Do We Do All of This?<br /> Security Enterprise Architecture<br /> Industry Model<br /> Security Roadmap<br /> Trust Zones<br /> Infrastructure Level<br /> Application Layer<br /> Component Layer<br /> Business Process Layer<br /> Holistic Security<br /> Agenda 8<br /> Access Control Models<br /> Policy versus Model<br /> State Machine<br /> Information Flow<br /> Information Flow Model<br /> Bell-LaPadula<br /> Rules of Bell-LaPadula<br /> Rules Clarified<br /> Tranquility Types<br /> Biba<br /> Definition of Integrity<br /> Biba Access Rules<br /> Clark-Wilson<br /> Goals of Model<br /> Clark Wilson Components<br /> Clark-Wilson (Cont.)<br /> Clark-Wilson Model<br /> Non-Interference Model<br /> Lattice-Based Access Control<br /> Lattice Approach<br /> Understanding Lattice<br /> Access Control Matrix Model<br /> Access Control Matrix<br /> Brewer and Nash Model – Chinese Wall<br /> Brewer and Nash<br /> Take-Grant Model<br /> Graham-Denning Model<br /> Agenda 9<br /> Trusted Computer System Evaluation Criteria (TCSEC)<br /> TCSEC<br /> TCSEC Rating Breakdown<br /> Evaluation Criteria - ITSEC<br /> ITSEC Ratings<br /> ITSEC – Good and Bad<br /> Common Criteria<br /> Common Criteria Standard<br /> Security Functional Requirements<br /> Security Assurance Requirements<br /> Common Criteria Components<br /> Common Criteria Requirements<br /> Package Ratings<br /> Common Criteria Outline<br /> Certification Versus Accreditation<br /> Domain 5 Review<br /> Domain 6 - Law, Investigation and Ethics Objectives<br /> Not Just Fun and Games<br /> Examples of Computer Crimes<br /> Who Perpetrates These Crimes?<br /> Types of Motivation for Attacks<br /> A Few Attack Types<br /> Dumpster Diving<br /> Telephone Fraud<br /> Privacy of Sensitive Data<br /> Privacy Issues – U.S. Laws as Examples<br /> European Union Principles on Privacy<br /> Routing Data Through Different Countries<br /> Employee Privacy Issues<br /> Agenda 1<br /> Civil Law<br /> Criminal Law<br /> Administrative Law<br /> U.S. Federal Laws<br /> Trade Secret<br /> Copyright<br /> More Intellectual Property Laws<br /> Software Licensing<br /> Software Piracy<br /> Digital Millennium Copyright Act<br /> Agenda 2<br /> Computer Crime and Its Barriers<br /> Countries Working Together<br /> Worldwide Cybercrime<br /> Security Principles for International Use<br /> Determine if a Crime Has Indeed Been Committed<br /> Bringing in Law Enforcement<br /> Citizen versus Law Enforcement Investigation<br /> Investigation of Any Crime<br /> Role of Evidence in a Trial<br /> Evidence Requirements<br /> Chain of Custody<br /> How Is Evidence Processed?<br /> Hearsay Evidence<br /> Hearsay Rule Exception<br /> Agenda 3<br /> Preparing for a Crime Before It Happens<br /> Incident Handling<br /> Evidence Collection Topics<br /> Computer Forensics<br /> Hidden Secrets<br /> Trying to Trap the Bad Guy<br /> Companies Can Be Found Liable<br /> Sets of Ethics<br /> (ISC)2<br /> Computer Ethics Institute<br /> Internet Architecture Board<br /> Domain 6 Review<br /> Domain 7 - Telecommunications and Networking<br /> Agenda 1<br /> OSI Model<br /> OSI Layers<br /> Networking Communications<br /> An Older Model<br /> Data Encapsulation<br /> Application Layer<br /> OSI – Application Layer<br /> Presentation Layer<br /> OSI – Presentation Layer<br /> OSI – Session Layer<br /> Client/Server Model<br /> Client/Server Session Layer<br /> Transport Layer<br /> Transport Layer Analogy<br /> Transport Protocols<br /> OSI – Network Layer<br /> Here to There<br /> Network Layer<br /> OSI – Data Link<br /> Data Link<br /> Sublayers<br /> OSI – Physical Layer<br /> Physical Layer<br /> Layers Working Together<br /> Protocols at Each Layer<br /> Devices Work at Different Layers<br /> Types of Networks<br /> Network Topologies – Physical Layer<br /> Topology Type – Bus<br /> Topology Type – Ring<br /> Topology Type – Star<br /> Network Topologies – Mesh<br /> Mesh Topologies<br /> Summary of Topologies<br /> Agenda 2<br /> LAN Media Access Technologies<br /> Media Access<br /> One Goal of Media Access Technologies<br /> Collision Domain<br /> Back Off, Buddy<br /> Carrier Sense Multiple Access<br /> CSMA/Collision Avoidance (CSMA/CA)<br /> Media Access Technologies – Ethernet<br /> Media Access Technologies – Token Passing<br /> Token’s Role<br /> Other Technologies<br /> Media Access Technologies – Polling<br /> Agenda 3<br /> Cabling Types – Coaxial<br /> Coaxial<br /> Cabling Types – Twisted Pair<br /> Cable Types<br /> Types of Cabling – Fiber<br /> Multimode vs. Single Mode<br /> Signal and Cable Issues<br /> Signaling Issues<br /> Transmission Types – Analog and Digital<br /> Transmission Types – Synchronous<br /> Asynchronous<br /> Transmission Types – Baseband<br /> Transmission Types – Broadband<br /> Cabling Issues – Plenum-Rated<br /> Transmission Types – Number of Receivers<br /> Internet Group Management Protocol<br /> Multicasting<br /> Network Technologies<br /> Extranet<br /> Network Technologies (Cont.)<br /> EDI Evolution<br /> Networking Devices<br /> Network Device – Repeater<br /> Network Device – Hub<br /> Networking Device – Bridge<br /> Forwarding Table Example<br /> Network Devices – Switch<br /> Virtual LAN<br /> VLAN<br /> Interfaces and VLANs<br /> Sniffers<br /> Networking Devices – Router<br /> Hops<br /> Routers<br /> Bridges Compared to Routers<br /> Network Devices – Gateway<br /> Agenda 4<br /> Port and Protocol Relationship<br /> Client Ports<br /> Conceptual Use of Ports<br /> TCP/IP Suite<br /> UDP versus TCP<br /> TCP Segment<br /> SYN Flood<br /> Teardrop Attack<br /> Source Routing<br /> Source Routing Types<br /> IP Address Ranges<br /> IPv6<br /> Protocols<br /> Protocols – ARP<br /> IP to MAC Mapping<br /> How ARP Works<br /> ARP Poisoning<br /> ICMP Packets<br /> A Way Hackers Use ICMP<br /> Ping Steps<br /> Protocols – SNMP<br /> SNMP in Action<br /> SNMP<br /> SNMP Output<br /> POP3 and SMTP<br /> Protocols – SMTP<br /> Mail Relay<br /> Protocols – FTP, TFTP, Telnet<br /> Protocols – RARP and BootP<br /> DHCP – Dynamic Host Configuration Protocol<br /> Agenda 5<br /> Networking Device – Bastion Host<br /> Network Configurations<br /> DMZ Configurations<br /> Firewall Comparisons<br /> Network Devices – Firewalls<br /> Firewall Types – Packet Filtering<br /> Packet Filtering Firewall<br /> Packet Filtering Firewall Weaknesses<br /> Packet Filtering<br /> Rule Set Example<br /> Firewall Types – Proxy Firewalls<br /> Firewall Types – Circuit-Level Proxy Firewall<br /> Circuit-Level Proxy<br /> Firewall Types – Application-Layer Proxy<br /> Application-Layer Proxy Advantages<br /> Application-Layer Proxy Disadvantages<br /> Dedicated Proxy Servers<br /> Firewall Types – Stateful<br /> State Table<br /> Compare<br /> Firewall Types – Kernel Proxies<br /> Firewall based VPN Devices<br /> Best Practices<br /> Firewall Placement<br /> Packet Filtering (Cont.)<br /> Screened Host<br /> Firewall Architecture Types – Multi- or Dual-Homed<br /> Screened Subnet<br /> Agenda 6<br /> Dial-Up Protocols and Authentication Protocols<br /> Dial-Up Protocol – SLIP<br /> Dial-Up Protocol – PPP<br /> PPP<br /> PPP versus SLIP<br /> Authentication Protocols – PAP<br /> Authentication Protocols – CHAP<br /> Authentication Protocol – EAP<br /> Data Inspection<br /> Virtual Private Network Technologies<br /> What Is a Tunneling Protocol?<br /> Analogy<br /> Examples<br /> Tunneling Protocols – PPTP<br /> Tunneling Protocols – L2TP<br /> L2TP Encapsulation<br /> Tunneling Protocols – IPSec<br /> IPSec Basic Features<br /> IPSec Transport Mode<br /> IPSec Tunnel Mode<br /> Security Associations (SAs)<br /> Combining Sas<br /> Iterated Tunnelling<br /> Agenda 7<br /> SDLC and HDLC<br /> Layer 3 at Layer 2<br /> MPLS<br /> Multiprotocol Label Switching<br /> Quality of Service (QoS)<br /> QoS Services<br /> Autonomous Systems<br /> Routing Protocols<br /> Routing<br /> Routing Protocols (Cont.)<br /> OSPF<br /> OSPF Packet Values<br /> IGRP<br /> BGP<br /> Routing Protocol Attacks<br /> Metropolitan Area Network Technologies<br /> MAN Technologies – FDDI<br /> FDDI<br /> SONET Rings<br /> MAN Technologies – SONET<br /> Connecting Networks<br /> Network Services<br /> Network Service – DNS<br /> DNS Server Structure<br /> Name Resolving Steps<br /> Split DNS<br /> Host Name Resolution Attacks<br /> Network Service – NAT<br /> Types of NAT<br /> PAT<br /> NIS<br /> Storing Data<br /> NIS+ Authentication<br /> Agenda 8<br /> WAN Technologies Are Circuit or Packet Switched<br /> PSTN<br /> Connecting to the PSTN<br /> Circuit Switching<br /> Steps of Connections<br /> Multiplexing<br /> Types of Multiplexing<br /> TDM Process<br /> Statistical Time Division Multiplexing<br /> FDM<br /> FDM Process<br /> Packet Switching<br /> Circuit versus Packet Switching<br /> WAN Technologies – Packet Switched<br /> WAN Technologies – X.25<br /> X.25<br /> WAN Technologies – Frame Relay<br /> WAN Example<br /> Frame Relay<br /> PVC and SVC<br /> WAN Technologies – ATM<br /> Cell Switching<br /> Wide Area Network Technologies<br /> Dedicated Lines<br /> WAN Technologies – ISDN<br /> On-Demand<br /> ISDN Service Types<br /> WAN Technologies – DSL<br /> DSL<br /> ADSL<br /> SDSL<br /> WAN Technologies – Cable Modem<br /> Cable Modems<br /> Cable Network<br /> Satellites<br /> Hybrid Connection<br /> Satellite Coverage<br /> Satellite Supplying Different Subscribers<br /> Network Perimeter Security<br /> Complexity only Increases<br /> A Layered Approach<br /> Agenda 9<br /> Traditional Voice Network<br /> PSTN (Cont.)<br /> Private Branch Exchange<br /> PBX Vulnerabilities<br /> PBX Best Practices<br /> IP Telephony<br /> Voice Over IP<br /> Combination of Old and New<br /> IP Telephony Components<br /> Media Gateways<br /> PBX and VoIP<br /> Voice over…<br /> IP Telephony Issues<br /> Telephony Protection Mechanisms<br /> Telephony Security<br /> IP Telephony with Wireless<br /> IP Phones Security<br /> Mobile Technology Generations<br /> Mobile Phone Security<br /> Mobile Device Security<br /> Cell Phone<br /> Agenda 10<br /> Wireless Technologies – Access Point<br /> Wireless Frequencies<br /> Alphabet Soup of Standards<br /> Spread Spectrum<br /> OFDM<br /> Where does Spread Spectrum Work?<br /> 802.11n<br /> Wireless Technologies – Access Point (Cont.)<br /> Architectures<br /> Wireless Technologies – Service Set ID<br /> Authenticating to an AP<br /> 802.11 Authentication<br /> Wireless Technologies – WEP<br /> WEP Problems<br /> Wireless Technologies – More WEP Woes<br /> Lack of Integrity<br /> WEP Security Issues<br /> Frequency Management<br /> 802.11 Security Solutions<br /> 802.1x<br /> 802.1x Authentication<br /> Types of 802.11 Security<br /> IEEE 802.11i Standard<br /> Wireless EAP<br /> Wireless Technologies – Common Attacks<br /> Wireless Technologies – War Driving<br /> NetStumbler Example<br /> Wireless Reconnaissance Output<br /> Warchalking<br /> Countermeasures<br /> Wireless Attacks<br /> Wormhole Attack<br /> Wireless Technologies – WAP<br /> Wireless Technologies – WTLS<br /> i-mode<br /> Bluetooth<br /> Instant Messaging<br /> IM Threats<br /> IM Countermeasures<br /> IM Secure Infrastructure<br /> Domain 7 Review<br /> Domain 8 - Business Continuity Objectives<br /> Needs for BCP<br /> Is Your Organization Prepared?<br /> Is Your Company Prepared?<br /> 9/11 Changed Mentalities About BCP<br /> Disaster affected Many<br /> America is Rebuilding<br /> Partial FEMA Disaster List for 2005<br /> Do We have a Plan?<br /> DRP Focus<br /> BCP Focus<br /> Comparing the Two<br /> What is the Purpose of a BCP?<br /> More Reasons to have Plans in Place<br /> Framework<br /> BCP is a Core Component of Every Security Program<br /> Steps of BCP Process<br /> Different BCP Model<br /> Documentation<br /> Documentation and Approval<br /> BCP Policy Outlines<br /> BCP Policy Sample<br /> Who is In Charge and Who Can We Blame?<br /> What’s Needed in a Team?<br /> BCP Development Team<br /> Project Sizing<br /> Properly Determining Scope is Important<br /> BCP Risk Analysis Steps<br /> BIA Steps<br /> Data Gathering<br /> Information from Different Sources<br /> Analysis<br /> Critical Functions<br /> How to Identify the Most Critical Company Functions<br /> Interdependencies<br /> Well, of course an Organization Knows How it Works!<br /> Business Silos<br /> Understanding the Enterprise<br /> BIA Steps (Cont.)<br /> Identifying Functions’ Resources<br /> Who Connects to Who?<br /> BIA Steps (Cont..)<br /> Maximum Tolerable Downtime<br /> MTD<br /> Example<br /> MTD Definitions<br /> BIA Steps (Cont...)<br /> Range of Threats to Consider<br /> Thinking Outside of the Box What if….<br /> Biological Threats<br /> BIA Steps (Cont….)<br /> Potential Disasters<br /> Risk Approach<br /> Ranking by Risk Level<br /> Potential Losses<br /> Include all RISK Components<br /> What Have We Completed Up to Now?<br /> BIA Steps (Cont…..)<br /> Recovery Strategies<br /> Alternate Business Process Procedures<br /> Business Process Reconstruction<br /> Recovery Strategies (Cont.)<br /> Facility Recovery<br /> Facility Backups – Hot Site<br /> Facility Backups – Warm Site<br /> Facility Backups – Cold Site<br /> Compatibility Issues with Offsite Facility<br /> Tertiary Sites<br /> Subscription Costs<br /> Multiple Processing Centers<br /> Location, Location, Location<br /> Choosing Site Location<br /> Other Offsite Approaches<br /> Security does Not Stop<br /> More Options<br /> Rolling Hot Site<br /> Recovery Strategies (Cont..)<br /> Supply and Technology Recovery<br /> VoIP<br /> Equipment Replacement<br /> What Items Need to Be Considered?<br /> Priorities<br /> Anything Else?<br /> Replacements<br /> Executive Succession Planning<br /> Recovery Strategies (Cont...)<br /> User Environment Recovery<br /> Recovery Strategies (Cont….)<br /> Data Recovery Technologies<br /> Co-Location<br /> Data Recovery<br /> Backup Redundancy<br /> Recovering Data<br /> Automated Backup Technologies<br /> Tape Vaulting<br /> Data Recovery (Cont.)<br /> Clustering for Fault Tolerance<br /> Clustering<br /> Disk or Database Shadowing<br /> Which Option to Use<br /> Cost Effective Measures<br /> Resources, Time, Solutions<br /> Determining Recovery Solutions<br /> Cost and Recovery Times<br /> Proactive<br /> BIA Steps (Cont…...)<br /> Recovery Solutions<br /> Preventative Measures<br /> Reviewing Insurance<br /> Results from the BIA<br /> Now Ready to Develop the Plan<br /> Basic Structure of BCP<br /> Products That Can Help<br /> Plan Components<br /> Teams to Be Developed<br /> External Groups<br /> Policy Components<br /> Activation Phase<br /> Damage Assessment<br /> Notifying Personnel<br /> Plan Activation<br /> Emergency Response<br /> Policy Components (Cont.)<br /> Next Phases<br /> Recovery Procedures<br /> Documentation of Recovery Steps<br /> Policy Components (Cont..)<br /> Reconstitution Phase<br /> Reconstitution Items<br /> Returning to Original Facility<br /> Who goes First?<br /> Disaster Hit – Now What?<br /> Termination of BCP<br /> Life Cycle<br /> Who has the Plan?<br /> Backup of the Backup Plan<br /> Results<br /> Types of Tests to Choose From<br /> Test Objectives<br /> Training Requirements<br /> Lessons Learned<br /> What Is Success?<br /> Out of Date?<br /> BCP Plans Commonly and Quickly Become Out of Date<br /> Keeping it Current<br /> Change Control<br /> Resulting Plan Should Contain…<br /> Phases of the BCP<br /> Domain 8 Review<br /> Domain 9 - Application Security<br /> How Did We Get Here?<br /> Why Are We Not Improving at a Higher Rate?<br /> Usual Trend of Dealing with Security<br /> Where to Implement Security<br /> Agenda 1<br /> Software Development Tools<br /> CASE Tools<br /> New Paradigm of Coding<br /> Security Issues<br /> Language Types<br /> Turn into Machine Code<br /> New and Old<br /> Object-Oriented Programming<br /> Classes and Objects<br /> Objects<br /> Object Characteristics<br /> Functions and Messages<br /> Encapsulation<br /> Modularity of Objects<br /> Object-Oriented Programming Characteristic<br /> Polymorphism<br /> Another Characteristic of OOP<br /> Module Characteristics<br /> Low Cohesion<br /> Levels of Cohesion<br /> Coupling<br /> Agenda 2<br /> Distributed Computing<br /> Distributed Computing – ORBs<br /> Common Object Request Broker Architecture<br /> COM Architecture<br /> DCOM Architecture<br /> Enterprise Java Beans<br /> J2EE Platform Example<br /> Linking Through COM<br /> Mobile Code with Active Content<br /> World Wide Web OLE<br /> ActiveX Security<br /> Java and Applets<br /> Sandbox<br /> Java and Bytecode<br /> Agenda 3<br /> Database Systems<br /> Database Model<br /> Timeline<br /> Hierarchical Database<br /> Network Database<br /> Object-Oriented Database<br /> Benefits of OO Database Model<br /> Object Relational Database<br /> Relational Database<br /> Database Models – Relational Components<br /> Relational Database Entities<br /> Primary Key<br /> Foreign Key<br /> Database Integrity<br /> Different Modeling Approaches<br /> Database Access Methods<br /> Accessing Databases<br /> ODBC<br /> OLE DB<br /> OLE DB Database Access<br /> ActiveX Data Objects (ADO)<br /> Java Database Connectivity<br /> Database Connectivity<br /> eXtensible Markup Language<br /> XML Database<br /> Agenda 4<br /> Database Security Mechanisms<br /> Databases are Busy Beasts<br /> Rollback Control<br /> Checkpoint Control<br /> Checkpoint Protection<br /> Lock Controls<br /> Deadlock Example<br /> Two-Phase Commit<br /> Lock Controls Help to Provide ACID<br /> Inference Attack<br /> Database View Control<br /> Common Components<br /> Agenda 5<br /> Data Warehousing<br /> Warehouse Creation<br /> Using a Data Warehouse<br /> Metadata<br /> Database Component<br /> Data Mart<br /> Potential Malicious Traffic Tunneling through Port 80<br /> URL Interpretation<br /> Common Database Attacks<br /> Agenda 6<br /> OLTP<br /> Online Transaction Processing<br /> OLTP Requirements<br /> Online Analytical Processing<br /> Knowledge Management<br /> Knowledge Components<br /> HR Example<br /> Knowledge Discovery in Databases<br /> Data Mining<br /> Approaches to Knowledge Management<br /> Expert Systems<br /> Expert System Components<br /> Artificial Neural Networks<br /> Data, Information, Knowledge<br /> Comparing Types<br /> Agenda 7<br /> Software Development Models<br /> System Life Cycle<br /> Project Development – Phases I and II<br /> Project Development – Phases III and IV<br /> Phase V<br /> Project Development – Phases VI and VII<br /> Testing Types<br /> Levels of Tests<br /> Data Contamination Controls<br /> Best Practices for Testing<br /> Test for Specific Threats<br /> Verification versus Validation<br /> Evaluating the Resulting Product<br /> Agenda 8<br /> Controlling How Changes Take Place<br /> Change Control Process<br /> Administrative Controls<br /> Agenda 9<br /> Common Information Flow<br /> Vulnerabilities at Different Layers<br /> Tier Approach and Communication Components<br /> Tiered Network Architectures<br /> Sensitive Data Availability<br /> Cookies<br /> Find Out Where You Have Been<br /> Pulling Data<br /> Web Server Error Pages<br /> Steps of Interaction<br /> Provide the Hackers with Tools<br /> Common Web Server Flaws<br /> Improper Data Validation<br /> Uniform Resource Locator (URL)<br /> Directory Traversal<br /> Buffer Overflow<br /> Cross-Site Scripting Attack<br /> Common SQL Injection Attack<br /> Attacking Mis-configurations<br /> CGI Information<br /> Logging Activities<br /> Are ALL Patches Applied?<br /> Microsoft Example Best Practices<br /> Authorize Access<br /> Isolation for Protection<br /> Authentication<br /> Protecting Traffic<br /> Maintain Server Software<br /> Common Issues<br /> Best Practices<br /> Agenda 10<br /> Rolling ‘em Out<br /> Patching Issues<br /> Agenda 11<br /> Virus<br /> Boot Sector Invasion<br /> Few Other Types<br /> Types of Viruses<br /> How Do They Work?<br /> More Malware<br /> Trojans<br /> Blended Malware<br /> A Back Orifice Attack!<br /> NetBus<br /> Hoaxes<br /> Agenda 12<br /> Malware Protection Types<br /> Signature Scanning<br /> Monitoring Activities<br /> Monitoring for Changes<br /> More Bad Stuff<br /> Attack Characteristics<br /> Disclosing Data in an Unauthorized Manner<br /> Covert Storage Channel<br /> Covert Timing Channel<br /> Circumventing Access Controls<br /> Attacks<br /> TOC/TOU Examples<br /> Attack Type – Race Condition<br /> Attacking Through Applications<br /> How Buffers and Stacks Are Supposed to Work<br /> How a Buffer Overflow Works<br /> Watching Network Traffic<br /> Traffic Analysis<br /> Functionally Two Different Types Of Rootkits<br /> Examples of Trojaned Files<br /> Domain 9 Review<br /> Domain 10 - Operations Security Objectives<br /> Computer Operations<br /> Operations Security Involves<br /> What Do We Have?<br /> Hardware Protection<br /> Licensing Issues<br /> Software Installation<br /> ITIL – Problem Management<br /> Problem Management<br /> Areas of Problem Management<br /> Problem Management Procedures for Processing Problems<br /> Higher Level Look<br /> Data Output Controls<br /> Administrative Controls Personnel Controls<br /> Non-Employees<br /> Security Operations Personnel<br /> Change Control<br /> Configuration Management<br /> Another Example<br /> Agenda 1<br /> Resource Protection<br /> Library Maintenance<br /> Media Labels<br /> Media Controls<br /> Software Escrow<br /> Media Reuse<br /> Weak Link<br /> Liabilities of Insecure Disposal of Information<br /> Devastating to the Company<br /> Results of Data Leakage<br /> Object Reuse<br /> Safe Disposal<br /> Degaussing<br /> Zeroization<br /> Physical Destruction<br /> Remaining Data<br /> Purging<br /> Why Not Just Delete the Files?<br /> Formatting Media<br /> Mainframes<br /> Agenda 2<br /> Different Types of Backups<br /> Backups<br /> HSM<br /> Off-Line<br /> Backup Types<br /> Incremental Backup<br /> Incremental<br /> Differential Backup<br /> Differential<br /> Backup Protection<br /> Continuous Threat<br /> Agenda 3<br /> Devices Will Fail<br /> Mean Time Between Failure<br /> Mean Time to Repair<br /> Single Point of Failure<br /> Countermeasures<br /> Redundant and Fault Tolerance<br /> Mirroring Data<br /> Disk Duplexing<br /> Direct Access Storage Device<br /> Redundant Array of Independent Disks<br /> Massive Array of Inactive Disks (MAID)<br /> Redundant Array of Independent Tapes (RAIT)<br /> Serial Advanced Technology Architecture<br /> SAN<br /> Fault Tolerance<br /> Network Redundancy<br /> Mesh Network<br /> Redundancy Mechanism<br /> Backup Configuration Files<br /> Some Threats to Computer Operations<br /> Trusted Recovery of Software<br /> After System Crash<br /> Security Concerns<br /> Agenda 4<br /> Contingency Planning<br /> Agenda 5<br /> Remote Access Security<br /> Authentication<br /> Remote Access<br /> Administering Systems Remotely<br /> Facsimile Security<br /> Securing Data in Motion<br /> Support Systems<br /> Agenda 6<br /> Before Carrying Out Vulnerability Testing<br /> Testing for Vulnerabilities<br /> Vulnerability Assessments<br /> Security Testing Issues<br /> Vulnerability Scanning<br /> Basic Scanner<br /> More Functionality<br /> Data Leakage – Keystroke Logging<br /> Looking at Keystrokes<br /> Password Cracking<br /> One of Many Tools<br /> War Dialing<br /> PhoneSweep<br /> Wardialing Output<br /> Detailed PhoneSweep Output<br /> War Driving<br /> Wireless Reconnaissance Output<br /> Wireless Reconnaissance<br /> Wireless Attacks<br /> MAC Filtering<br /> Penetration Testing<br /> Testing Steps<br /> Testing Methodology<br /> Automated Pen Testing Tools Canvas Operation<br /> Penetration Testing<br /> Automated Pen Testing Tools Core Impact Operation<br /> Post-Testing and Assessment Steps<br /> Penetration Testing Variations<br /> Types of Testing<br /> Protection Mechanism – Honeypot<br /> Log Reviews
-
Alternative download:CISSP Platinum Training DVD might also be available on Usenet. Get the UseNet Client - Highspeed Access To 300TB of Videos, Games and Music!
Files
| File | Size |
|---|---|
dvd1.ISO |
947 MB |
dvd1.MDS |
4.2 KB |
dvd10.ISO |
614 MB |
dvd10.MDS |
4.2 KB |
dvd2.ISO |
1207 MB |
dvd2.MDS |
4.2 KB |
dvd3.ISO |
1280 MB |
dvd3.MDS |
4.2 KB |
dvd4.ISO |
439 MB |
dvd4.MDS |
4.2 KB |
dvd5.ISO |
773 MB |
dvd5.MDS |
4.2 KB |
dvd6.ISO |
1610 MB |
dvd6.MDS |
4.2 KB |
dvd7.ISO |
326 MB |
dvd7.MDS |
4.2 KB |
dvd8.ISO |
744 MB |
dvd8.MDS |
4.2 KB |
dvd9.ISO |
769 MB |
dvd9.MDS |
4.2 KB |
Add comment
Related torrents
More torrents, related to CISSP Platinum Training DVD

News:








dvd1.ISO
FireFox Plugin

External comments