TEACHING UNIT 1. COMMONLY ACCEPTED GENERAL CRITERIA FOR COMPUTER EQUIPMENT SECURITY
1. A security model focused on managing risks related to the use of information systems
2. List of the most common threats, the risks they pose, and the most common safeguards
3. Most common safeguards and security technologies
4. IT security management as a complement to safeguards and technological measures
LEARNING UNIT 2. BUSINESS IMPACT ANALYSIS
1. Identification of business processes supported by information systems
2. Assessment of the confidentiality, integrity, and availability requirements of business processes
3. Determining the information systems that support business processes and their security requirements
LEARNING UNIT 3. RISK MANAGEMENT
1. Applying the risk management process and presenting the most common alternatives
2. Commonly accepted methodologies for risk identification and analysis
3. Implementation of controls and safeguards to reduce risk
LEARNING UNIT 4. SECURITY IMPLEMENTATION PLAN
1. Determining the current security level of systems compared to the required level based on the security requirements of business processes
2. Selection of safeguards to meet the security requirements of information systems
3. Guidance for developing the implementation plan for the selected safeguards
LEARNING UNIT 5. PROTECTION OF PERSONAL DATA
1. General principles of personal data protection
2. Violations and penalties provided for in current legislation regarding the protection of personal data
3. Identification and registration of files containing personal data used by the organization
4. Preparation of the security document required by current legislation on the protection of personal data
TEACHING UNIT 6. PHYSICAL AND INDUSTRIAL SECURITY OF SYSTEMS. LOGICAL SYSTEM SECURITY
1. Determination of physical security perimeters
2. Most common physical access control systems for the organization’s facilities and the areas where computer systems are located
3. Security criteria for the physical location of computer systems
4. Overview of the most common measures to ensure the quality and continuity of the power supply to computer systems
5. Climate control and fire protection requirements applicable to computer systems
6. Development of physical and industrial security policies for the organization
7. Most commonly used file systems
8. Establishment of access controls for IT systems to the organization’s communications network
9. Configuration of user directory policies and guidelines
10. Establishment of access control lists (ACLs) for files
11. Management of user registrations, deactivations, and modifications, as well as their assigned privileges
12. Security requirements related to user access control to the operating system
13. Weak, strong, and biometric user authentication systems
14. List of operating system audit logs required to monitor and supervise access control
15. Development of access control policies for computer systems
TEACHING UNIT 7. SERVICE IDENTIFICATION
1. Identification of the protocols, services, and ports used by information systems
2. Use of port and open service analysis tools to determine which ones are unnecessary
3. Using communication traffic analysis tools to determine the actual use that information systems make of the various protocols, services, and ports
TEACHING UNIT 8. IMPLEMENTATION AND CONFIGURATION OF FIREWALLS
1. List of the different types of firewalls by location and functionality
2. Security criteria for network segmentation at the firewall using Demilitarized Zones (DMZs)
3. Use of Virtual Private Networks (VPNs) to establish secure communication channels
4. Definition of firewall rules
5. List of firewall audit logs necessary for monitoring and supervising proper operation and security events
6. Establishing firewall monitoring and testing
TEACHING UNIT 9. RISK ANALYSIS OF INFORMATION SYSTEMS
1. Introduction to risk analysis
2. Main types of vulnerabilities, software flaws, and malicious software, including their ongoing updates, as well as secure programming criteria
3. Characteristics of the different types of malicious code
4. Key elements of risk analysis and their relationship models
5. Qualitative and quantitative risk analysis methodologies
6. Identification of Assets Involved in Risk Analysis and Their Assessment
7. Identification of Threats That May Affect Previously Identified Assets
8. Analysis and Identification of Existing Vulnerabilities in Information Systems That Could Allow Threats to Materialize, Including Local Analysis, Remote White-Box Analysis, and Black-Box Analysis
9. Optimization of the audit process, verification of vulnerabilities, and preparation of the audit report
10. Identification of existing safeguards at the time the risk analysis is conducted and their effect on vulnerabilities and threats
11. Establishment of risk scenarios, defined as asset-threat pairs that could materialize
12. Determination of the probability and impact of the scenarios materializing
13. Establishment of the risk level for the various asset-threat pairs
14. Determination by the organization of risk assessment criteria, based on which it is determined whether a risk is acceptable or not
15. List of the various risk management alternatives
16. Guidance for developing the risk management plan
17. Overview of the NIST SP 800 methodology
18. Overview of the Magerit methodology
TEACHING UNIT 10. USE OF TOOLS FOR SYSTEM AUDITING
1. Operating system tools such as Ping, Traceroute, etc.
2. Network, port, and service analysis tools such as Nmap, Netcat, NBTScan, etc.
3. Vulnerability analysis tools such as Nessus
4. Protocol analyzers such as WireShark, DSniff, Cain & Abel, etc.
5. Web page analyzers such as Acunetix, Dirb, Parosproxy, etc.
6. Dictionary and brute-force attacks such as Brutus, John the Ripper, etc.
TEACHING UNIT 11. DESCRIPTION OF FIREWALL ASPECTS IN COMPUTER SYSTEM AUDITS
1. General Principles of Firewalls
2. Components of a Network Firewall
3. List of Different Types of Firewalls by Location and Functionality
4. Network Firewall Architectures
5. Other Network Firewall Architectures
TEACHING UNIT 12. GUIDELINES FOR CONDUCTING THE VARIOUS PHASES OF AN INFORMATION SYSTEMS AUDIT
1. Guidelines for auditing the existing security documentation and policies at the audited organization
2. Guidelines for developing the audit plan
3. Guidelines for conducting audit tests
4. Guidelines for preparing the audit report