Course objectives
After completing this course, students will be able to:
- Execute the Access Lifecycle: Manage the full cycle from request and approval to granting and eventual revocation.
- Master Access Control Models: Apply RBAC (Role-Based), ABAC (Attribute-Based), and DAC (Discretionary) models in real-world scenarios.
- Maintain the Access Matrix: Keep a valid and accurate record of who has access to what, ensuring it is ready for audit at any time.
- Conduct Access Reviews: Lead "Access Recertification" campaigns to identify and remove "privilege creep."
- Secure Identification & Authentication: Implement and troubleshoot identification protocols and multi-factor authentication (MFA).
- Incident Response: Identify and resolve incidents related to unauthorized access or stolen credentials.
Course outlines
- Phase 1: Foundations of Access
- Domain 1: Security Objectives: Understanding the CIA Triad (Confidentiality, Integrity, Availability) in the context of access.
- Domain 2: Threats: Identifying internal (insider threat) and external (hacker) risks to access systems.
- Domain 3: Access Controls: Selective restrictions of access to physical and digital assets.
- Phase 2: Identity & Rights Lifecycle
- Domain 4: Rights Management: The policies for granting authorized individuals the right to access services.
- Domain 5: Identification: Assigning unique values to users to track their activity.
- Domain 6: Authorization: Defining what an identified user is allowed to do.
- Domain 7: Authentication: Verifying the user is who they claim to be (Passwords, Biometrics, Tokens).
- Phase 3: Monitoring & Compliance
- Domain 8: Access Control Matrix: The central framework for mapping users to permissions.
- Domain 9: Logging & Monitoring: Recording user activities to ensure accountability.
- Domain 10: Event Management: Managing and investigating suspicious access events or breaches.