Q-CERT banner

main navigation areas

Information Security for Technical Staff

This five-day course is designed to provide participants with practical techniques for protecting the security of an organization's information assets and resources, beginning with concepts and proceeding on to technical implementations.

The course focuses on understanding and applying the concept of survivability through the effective management of risk, threats, policy, system configuration, availability, and personnel. The course also addresses incident response and provides a technical foundation for working with TCP/IP security and cryptography. The final section of the course helps participants learn to design a secure network architecture managing host systems, securing network services and infrastructure, working with firewalls, and understanding intrusion detection and prevention.

The principles, strategies, and practices covered are applicable to most system platforms and network environments. To illustrate important concepts and security technologies, demonstrations and exercises will include implementations applicable to Linux and Windows systems as well as Cisco Internetworking equipment.

The course involves extensive hands-on laboratories utilizing heterogeneous network environment, scenario-based exercises, lecture/briefings, and open discussion to help participants develop their understanding of the problems and strategies for securing information systems and networks.

Hands-on labs and demonstrations include subjects such as: Scanning and enumeration; Enigmail and Mozilla Thunderbird email client use of the OpenPGP standard; Windows Group Policy and Security templates; securing remote access with IPSec; assessing networks with Nessus; intrusion detection and prevention with Snort; as well as information on personal and enterprise firewalls, password cracking, and extensive hacking/hardening of Linux, Windows, and Cisco platforms in both wireless and cabled networks. Each student will have the use of a laptop for the duration of the course, as well as access to a wide variety of networked systems.

Audience

Technical staff members who manage or support networked information systems and have

Prerequisites

There are no prerequisites for this course.

Topics

Objectives

This course will help participants to