
Define the role of a security analyst and the common body of knowledge that supports it. Explore the security challenges and evolving concerns in information security.
Explore the common body of knowledge and certifications, view security through the CIA triad plus authentication and non-repudiation, and assess risk, auditing, and threat landscapes.
Discover what it means to be a security analyst, the expertise needed, and the demand for qualified professionals to become consummate information security specialists.
Explore the threat landscape, identifying internal and external threats and the hackers behind them, to gain a realistic understanding of the risks faced by security analysts and penetration testers.
Identify threats in the security analyst role, including disgruntled employees, data leakage, and physical risks, and use Sci Security.org and us-cert.gov for proactive threat assessment.
Explore the internal and external threat landscape, identify who the hackers are, and explain why their threats matter. Learn how internet-based threat intelligence from very reliable sources informs defense.
Discover how policies and procedures shape a company's security posture and determine which security controls protect the enterprise.
Compare policies and procedures, align with standards, and implement practical security policies covering acceptable use, types of policies, due diligence, and outsourcing considerations.
Explore different types of policies and procedures with concrete examples, highlight acceptable use policy as a critical enterprise guideline, and examine SES policies as an industry-standard resource for security frameworks.
Explore risk assessment principles with a simple equation linking risk, vulnerabilities, threats, and organizational impact; learn how security controls offset risk and the symbiotic role of security awareness.
Identify and manage risk through practical risk assessment, including accepting, removing, mitigating, or transferring risk, and strengthen security awareness with effective controls.
Learn to manage and evaluate risk with key questions and a simple equation, apply vulnerability assessment tools, and understand how security awareness shapes risk.
Explore how system auditing relates to vulnerability assessment and penetration testing and why penetration testing matters, with an introduction to scope that defines what is tested and sets limits.
Learn how auditing, vulnerability assessment, and penetration testing evaluate security controls against policies and procedures, using frameworks and infrastructure framing to identify risks, report findings, and support compliance.
Explore how penetration testing, vulnerability assessment, and security auditing relate and define a proper penetration test scope to set clear boundaries for the assessment.
Explore the types of penetration tests, including destructive and non-destructive, internal and external, and how much information testers may have before testing. Define the three testing phases and activities.
Explains non-destructive and destructive penetration tests, blue team vs red team, and black, white, and gray box approaches, plus external and internal testing, reconnaissance, attack, and post-attack phases.
Explore internal, external, destructive, and non-destructive penetration testing, and compare black box, gray box, and white box approaches while outlining the pre-attack, attack, and post-attack phases.
Examine the methodologies used in penetration testing and adopt a methodical, organized approach to security assessments, mirroring hackers' disciplined tactics against corporate and government entities.
Apply a methodical penetration testing methodology to plan, document with date-time stamps, and deliver repeatable results aligned to a target’s security posture, using open-source standards, checklists, and clear reporting.
Explore the methodical nature of penetration testing and apply a solid methodology to stay organized, focused, and professional, guided by open source planning and execution guidelines.
Navigate the legal concerns and risks of penetration testing to protect both tester and client. Outline the rules of engagement and the documentation required to perform a penetration test.
Define clear customer-driven rules of engagement and SOW for penetration testing, secure authorization and NDAs, and align scope, deliverables, timing, and ROI to protect data and reputation.
Identify legal concerns and risks in penetration testing, and outline the properly signed documentation and rules of engagement required to conduct a penetration test legally and professionally.
This course is designed for anyone who wants to understand the analysis of data security. More than ever, information security analysts are needed to rescue companies when they have been hacked or breached, as well as to put in place controls and counter-measures to avert cyber attacks.
Gain the skills required to detect and mitigate information and cyber security threats and vulnerabilities. The security analyst role is an entry point to many other security specialties and is highly in-demand in today’s evolving threat environment.
In the fast moving world of cyber security, with new threats evolving daily, up to date knowledge and skills that involves protecting systems and networks of companies and other assets containing mission-critical data as well as designing and developing new security solutions routinely to stay ahead of the hackers and cyber attackers.
Learn the essential prerequisites for your career success! ENROLL TODAY!