
Maintain a real-time inventory of all authorized and unauthorized devices and use automated discovery to detect new assets and alert for discrepancies.
Maintain an accurate inventory of authorized and unauthorized software across all devices, including patch levels, and use whitelisting and endpoint security to detect and remove unauthorized programs.
Implement secure configurations for laptops, workstations, and servers; harden images, disable unused accounts and services, close ports, apply patches, and enforce change management with hashing for integrity.
Learn how to secure network devices—firewalls, routers, and switches—by enforcing strict configurations, evaluating exceptions, applying change management, and using encryption and multi-factor authentication to protect data and continuity.
Implement multi layered boundary defense by securing perimeter systems, deploying firewalls, proxies, and DMZs; use network segmentation and IDS/IPS to reduce attack surface and enforce two-factor remote access.
Maintain, monitor, and analyze audit logs as a critical control to expose network attacks, using standardized, verbose logging; write logs to separate servers, synchronize time, and review anomalies weekly.
Explore how attackers exploit application software through input validation failures, including buffer overflows and SQL injection. Learn to secure apps with testing, sanitizing input, and secure coding practices.
Limit and audit administrative privileges to prevent attackers spreading inside the organization. Enforce strong passwords (12 characters, complexity), replace defaults, hash storage, unique accounts, regular changes, and two-factor authentication.
Implement need-to-know access by tiering data and requiring authentication for shared folders, apply NTFS permissions and least-privilege, and audit logs to detect anomalies and confirm tests.
Learn how continuous vulnerability assessment and remediation, through automated authenticated scans and timely patches, reduce attacker access while applying compensating controls when patches cannot be deployed.
We know that what Security Controls is. Security controls are safeguards or countermeasures to avoid, detect, counteract, or minimize security risks to physical property, information, computer systems, or other assets. This intermediate level course covers proven general controls and methodologies that are used to execute and analyze the Top Twenty Most Critical Security Controls. This course allows the security professional to see how to implement controls in their Existing networks through highly effective and cost-effective automation. For management, this training is the best way to distinguish how to assess the effectiveness of these security controls. The most critical security reviews were embraced and enforced by almost all organizations with sensitive information as the highest priority list. These controls were chosen by leading government and private organizations who are experts on how compromised networks/systems evolve and how to mitigate and prevent them from happening. This course helps the students in the preparation for IS20 Certification Exam.
The average salary for Information Assurance Manager is $83,443 per year.