
Master risk and change management, data classification and privacy, and physical and personnel security within the Security+ operational security domain. Explore hands-on vulnerability scanning and security operations concepts in practice.
Apply CIA principles—confidentiality, integrity, and availability—through authentication, authorization, and auditing. Address evolving challenges from big data, mobile, and the Internet of things with preventive, detective, and corrective controls.
Identify assets, assign tangible and intangible values, and measure risk using qualitative and quantitative assessments. Apply frameworks like octave, fair, and rmf to manage and transfer risk.
Implement configuration change management to minimize risk from patches and vulnerabilities, establishing visibility, governance, baselines, change control, audits, and a CMDB for tracking configuration items.
Operate the GFI LANguard scanner to perform a high-profile then full scan on a Windows host, identifying NetBIOS data, ports and services such as Apache coyote server 1.1 without credentials.
Discover how to identify, classify, and map data to restricted, private, and public categories, assign data steward and custodian roles, and apply data loss prevention controls.
Navigate data privacy within HIPAA, PCI DSS, and EU-US Safe Harbor. Explore threats from surveillance programs and the role of Tor in protecting personal information.
Download the Tor browser bundle, which combines Firefox and Tor software for a user-friendly, proxy-free setup. Establish Tor circuits, verify your IP, and adjust relays to optimize performance.
implement defense in depth for physical security by combining perimeter fencing, lighting, sensors, and surveillance with robust locks and access controls, including multi-factor authentication, plus regular drills and penetration testing.
Apply environmental controls to physical security, preserving the CIA triad by addressing humidity, power threats, and emergencies, and reinforce defense in depth with fire detection and suppression for data centers.
Strengthen the people component of information security by addressing insider threats, background checks, security awareness, privacy protection, and clear HR policies including acceptable use and data stewardship.
Apply hands-on Windows desktop security with User Account Control and Group Policy, tune Windows Defender settings, and use msconfig and registry run keys to diagnose startup malware.
Implement operational security to manage day-to-day risk with deterrence, detection, and compensating controls. Monitor logs, anti-virus, rogue devices, and enforce encryption, strong passwords, and secure remote access.
Develop an organized incident response to limit damage and reduce recovery time. Apply the six-step framework from the SANS Institute: preparation, identification, containment, eradication, recovery, lessons learned.
Explore computer forensics and digital forensics techniques, including acquisition, analysis, reporting, and maintaining a legal chain of custody to preserve and present digital evidence.
Explore disaster recovery through business impact analysis to identify critical systems, set rto and rpo, and implement cold, warm, or hot sites with testing to ensure business continuity.
Define a clear disaster recovery mission, secure stakeholder sponsorship, map business processes with IT and operations, and establish change-controlled milestones to assess outage costs and impacts.
Review the security plus operational security content, including security principals, data and physical security, risk and change management, vulnerability scanning, data privacy, Tor usage, and incident response.
This course is for beginners and IT pros looking to get certified and land an entry level Cyber Security position paying upwards of six figures! There are currently over a million Cyber Security job openings global and demand is greatly outpacing supply which means more opportunity, job security and higher pay for you!
The Security+ exam covers six domains and this course focuses on the second domain which is 'Compliance and Operational Security' domain.
We will cover the foundational principles of information security which include confidentiality, integrity and availability. We will also identify common security services and the mechanisms used to implement those services.
People are arguably the most important link in the chain when it comes to security. Making sure employees, contractors and business partners protect corporate data and that their privacy is protected as well is the responsibility of all involved. This course will help you understand how to strengthen the people component of information security programs.
Data Privacy is a key consideration for business as they leverage personal information for business purposes. I will show you data privacy regulations, threats and protection mechanisms.
Risk Management is what fundamentally drives information security programs. Learn how to measure, manage and validate information security risks. Physical security measures may not be the most glamorous part of information security but they are an important component of the bigger picture. Because if intruders have access to your HW it’s only a matter of time before they get access to the data that’s on it.
A subcomponent of physical security involves the management of environmental controls. In this section we will go over some of the best practices associated with some of these types of controls and how implementing them can enhance security by preserving CIA (Confidentiality, Integrity and Availability).
Data classification is the process of organizing data into categories for its most effective and efficient use. Learn how to effectively classify data and identify classification driven best practices controls.
Once we have a Risk Management program in place we need to implement operational security to manage the day to day aspects of security. You will learn about Operational Security Controls, what they consist of and how they help us to incrementally manage risk on a daily basis.You will learn how to formulate and execute an incident response plan which defines policies, in specific terms, which identify an incident and provide step-by-step processes that should be followed when an incident occurs.
All IT environments require changes to be made on a fairly constant basis for the purpose of upkeep and enhancements. After completing this lesson you will understand best practices for minimizing risk via configuration and change management.
While at first glance DR might not seem like a natural fit with cybersecurity after further analysis we realize that disasters are threats that can inflict much more damage than any hacker. Upon completing this lesson you will understand how to perform disaster recovery planning and design strategies for dealing with disasters.
You will also learn how to conduct forensics investigations using digital forensics technologies and techniques in this lesson.