Home | Press | Contact Us | Site Map
ecfirst Home
 
 

The Art of Information Security

An Intense 1-Day Strategy Brief

To bring The Art of Information Security to your site, please contact

Lorna Waggoner at 1.877.899.9974 x17

ecfirst.com will tailor the Brief to meet your requirements.

Session Outline

Module 1: Business Security Strategy

  • Business Nervous System
  • Under Siege: Rising Threat
  • Core Security Objectives
  • Role of the Information Security Officer
    • Job Description
    • Role in Organization
  • Regulatory Compliance Challenges

Case Study: Applying Sarbanes-Oxley controls and HIPAA Security safeguards as Best Practices in Your Business


Module 2: Digital Identity Management

  • The Challenge: Passwords & Unique Identifiers
  • Authentication and Authorization
  • Strong Authentication
  • Solution Options:
    • Authentication Tokens
    • Smart Cards
    • Biometrics

Case Study: Fine-tune an identity management policy to take back for your organization.


Module 3: Risk Analysis

  • Comprehensive & Thorough
  • Critical Process Elements
  • Vulnerability Assessment (Penetration Testing)
  • Tools
  • Report Organization
  • Developing a Remediation “Action” Plan

Module 4: Contingency Plans and Disaster Recovery

  • “Availability” Principle
  • Business Impact Analysis (BIA)
  • Data Backup Plan
  • Disaster Recovery Plan
  • Emergency Mode Operation
  • Testing and Revision Procedures
  • Application and Data Criticality Analysis

Case Study: Walk-thru the essential elements of a completed Business Continuity Plan.


Module 5: Wireless Security Challenges

  • Wireless Applications in Business
  • IEEE 802.11 Standards
  • Wireless Network Components
  • Wireless Security Protocols
  • Case Study: Developing a Policy for Wireless Security

Case Study: Design a secure wireless infrastructure. Establish the foundation for a terrific wireless security policy – all in class.


Module 6: Digital Signatures & Certificates

  • Requirements
  • Digital Signatures
  • Digital Certificates
  • Public Key Infrastructure (PKI)

Module 7: Last Line of Defense, Encryption

  • Business Drivers
    • Mobile Devices
    • Wireless Infrastructure
    • Web-based Services
  • Encryption Standards
  • Message Digests (Hashing)

Case Study: Develop a Business Encryption Policy that addresses threats related to the Internet and mobile devices.


Module 8: Security Best Practices

  • Important Standards, Frameworks and References
    • ISO17799/BS7799
    • CobiT Security Baseline
    • NIST
  • Critical Steps for Enterprise Security
  • Enterprise Risk Analysis
    • Vulnerability Assessment (Penetration Testing)
  • Conducting a BIA
  • Security Vision: “Edge” to Core” Defense
  • Remediation: Defense-in-Depth
    • Perimeter Security
    • Malicious Software Defense
    • Wireless Defense
  • Audit Controls and Risk Management

Case Study: Walk-thru an Enterprise Security Strategy Blueprint document. Create a template for your business in class.


BRING THIS PROGRAM TO YOUR SITE

Bring this program on-site. For details please contact Lorna Waggoner at 1.877.899.9974 x17. ecfirst.com will customize this program to meet your content and schedule requirements. Take advantage! Call for details today!


 

 

 

Last updated: May 6, 2005