Course objectives
After completing this course, students will be able to:
- Harden Enterprise Systems: Implement security baselines for Windows/Linux servers and network devices.
- Architect Secure Networks: Design resilient enclaves using segmentation, firewalls, and secure remote access.
- Manage Identity (IAM): Configure and audit authentication flows, Principle of Least Privilege, and entitlement reviews.
- Execute GRC Tasks: Quantify risk, navigate change management workflows, and align technical controls with regulatory laws.
- Monitor & Log: Set up log aggregation, tune alerts, and understand various telemetry types for threat detection.
- Analyze Vulnerabilities: Identify, prioritize, and mitigate security gaps across the enterprise estate.
Course outlines
- Domain 1: Secure Engineering Fundamentals
- Defensive security terminology and the "Defense in Depth" mindset.
- Strategic planning for long-term infrastructure resilience.
- Creating and maintaining technical documentation (SOW, Proposals).
- Domain 2: Governance, Risk, and Compliance
- Risk Quantification: Identifying and measuring the impact of IT threats.
- Change Management: Navigating the lifecycle of a secure system update.
- Baselines: Creating acceptable cybersecurity baselines using industry frameworks (NIST, CIS).
- Domain 3: Identity and Access Management
- IAM Components: Roles, Groups, and Permissions.
- Authentication: Implementing Multi-Factor Authentication (MFA) and Single Sign-On (SSO).
- Privileged Access: Managing administrative credentials and "Just-in-Time" access.
- Domain 4: Security Administration
- Hardening: Securing the OS, registry, and services against common attack vectors.
- Vulnerability Management: Running scans and coordinating remediation.
- Logging & Alerting: Understanding log types, aggregation methods, and SIEM basics.
- Lab Scenario: Hands-on architecture work where you build a secure environment based on specific business requirements.