IT security is the branch of IT that focuses on protecting IT infrastructure and everything related to it (including the information it contains). To this end, there are a number of standards, protocols, methods, rules, tools and laws designed to minimise potential risks to infrastructure or information. The IT security includes software, databases, metadata, records and everything that the organisation values (assets) and which constitutes a risk if it falls into the hands of other people. This sort of information IT Security Technician is known as inside information or confidential information.
IT Security
Introduction
Objectives
-
Understanding the concept and security models, the types of access control and data authentication, and the potential attacks to which computer systems may be exposed.
-
To learn the guidelines and scope of application for the Safety Regulations and the implementation of their Key points of the settings in Windows.
-
Knowing how to apply the data protection legislation in force in Spain: the principles of data protection and how they should be applied.
-
Ensuring continuity of the operations of the critical elements which make up information systems, through actions and procedures.
-
To determine whether individual contingency plans are capable of providing the desired level of support to the section or to the critical processes of the company.
-
Try the effectiveness of the procedures set out in the plan for contingencies.
Table of Contents
TEACHING UNIT 1. COMMONLY ACCEPTED GENERAL CRITERIA REGARDING THE SECURITY OF COMPUTER EQUIPMENT
1. A security model focused on the management of risks associated with the use of information systems
2. List of the most common threats, the risks they entail and the most common safeguards
3. The most common security measures and technologies
4. IT security management as a complement to safeguards and technological measures
TEACHING UNIT 2. BUSINESS IMPACT ANALYSIS
1. Identification of business processes supported by information systems
2. Assessment of the confidentiality, integrity and availability requirements of business processes
3. Identification of the information systems that support business processes and their security requirements
TEACHING UNIT 3. RISK MANAGEMENT
1. Implementation of the risk management process and an overview of the most common alternatives
2. Commonly accepted methodologies for risk identification and analysis
3. Implementation of controls and safeguards to reduce risk
TEACHING UNIT 4. SAFETY IMPLEMENTATION PLAN
1. Assessing the current level of system security against the level required, based on the security requirements of the business processes
2. Selection of security measures to meet the security requirements of information systems
3. Guidance on drawing up the implementation plan for the selected safeguards
TEACHING UNIT 5. PROTECTION OF PERSONAL DATA
1. General principles of personal data protection
2. Infringements and penalties provided for in current legislation on the protection of personal data
3. Identification and registration of files containing personal data used by the organisation
4. Preparation of the security document required by current legislation on the protection of personal data
TEACHING UNIT 6. PHYSICAL AND INDUSTRIAL SYSTEM SECURITY. LOGICAL SYSTEM SECURITY
1. Determining the physical security perimeters
2. The most common physical access control systems for the organisation’s premises and the areas where its IT systems are located
3. Security criteria for the physical location of IT systems
4. Overview of the most common measures to ensure the quality and continuity of the electricity supply to IT systems
5. Climate control and fire safety requirements applicable to IT systems
6. Drawing up physical and industrial safety regulations for the organisation
7. Most commonly used file systems
8. Establishing access control for IT systems to the organisation’s communications network
9. Configuring policies and guidelines for the user directory
10. Setting up access control lists (ACLs) for files
11. Management of user registrations, de-registrations and changes, and the privileges assigned to them
12. Security requirements relating to user access control to the operating system
13. Weak, strong and biometric user authentication systems
14. List of operating system audit logs required to monitor and supervise access control
15. Drawing up regulations governing access control to IT systems
TEACHING UNIT 7. IDENTIFYING SERVICES
1. Identification of the protocols, services and ports used by information systems
2. Using tools to analyse open ports and services to identify those that are not required
3. Use of communication traffic analysis tools to determine the actual use made by information systems of the various protocols, services and ports
TEACHING UNIT 8. IMPLEMENTATION AND CONFIGURATION OF FIREWALLS
1. List of the different types of firewalls by location and function
2. Security criteria for network segregation at the firewall using Demilitarised Zones (DMZs)
3. Use of Virtual Private Networks (VPNs) to establish secure communication channels
4. Defining rules on firewalls
5. List of firewall audit logs required to monitor and supervise its correct operation and security events
6. Setting up firewall monitoring and testing
TEACHING UNIT 9. RISK ANALYSIS OF INFORMATION SYSTEMS
1. Introduction to risk analysis
2. Main types of vulnerabilities, software faults and malicious software, and their ongoing updates, as well as secure programming criteria
3. Characteristics of the various types of malicious code
4. Key elements of risk analysis and their relationship models
5. Qualitative and quantitative risk analysis methodologies
6. Identification of the assets involved in the risk analysis and their valuation
7. Identification of threats that may affect the assets previously identified
8. Analysis and identification of existing vulnerabilities in information systems that could enable threats to materialise, including local analysis, remote white-box analysis and black-box analysis
9. Optimisation of the audit process, vulnerability testing and the audit report
10. Identification of the safeguard measures in place at the time the risk analysis was carried out and their impact on vulnerabilities and threats
11. Identification of risk scenarios, defined as asset-threat pairs that are likely to materialise
12. Assessing the likelihood and impact of the scenarios occurring
13. Determining the risk level for the various asset-threat pairs
14. The organisation’s determination of the risk assessment criteria, on the basis of which it is determined whether a risk is acceptable or not
15. List of the various risk management options
16. Guidance on drawing up a risk management plan
17. Overview of the NIST SP 800 methodology
18. An overview of the Magerit methodology
TEACHING UNIT 10. USE OF TOOLS FOR SYSTEMS AUDITING
1. Operating system tools such as Ping, Traceroute, etc.
2. Network, port and service analysis tools such as Nmap, Netcat, NBTScan, etc.
3. Vulnerability analysis tools such as Nessus
4. Protocol analysers such as WireShark, DSniff, Cain & Abel, etc.
5. Website analysers such as Acunetix, Dirb, Parosproxy, etc.
6. Dictionary and brute-force attacks such as Brutus, John the Ripper, etc.
TEACHING UNIT 11. DESCRIPTION OF FIREWALL-RELATED ASPECTS IN IT SYSTEM AUDITS
1. General principles of firewalls
2. Components of a network firewall
3. List of the different types of firewalls by location and function
4. Network firewall architectures
5. Other network firewall architectures
TEACHING UNIT 12. GUIDELINES FOR CARRYING OUT THE VARIOUS STAGES OF AN INFORMATION SYSTEMS AUDIT
1. Guidance on auditing the existing safety documentation and regulations within the organisation being audited
2. Guidance on drawing up the audit plan
3. Guide to audit testing
4. Guidance on preparing the audit report