Thanks to this Postgraduate Diploma in Computer Security you will be able to detect the various risks, identify the various vulnerabilities in these systems, and recognise the tactics used by ethical hacking which can be used, amongst other functions. You’ll start by understanding the basics of IT security, and why it’s so important to apply it in the digital society which we now find ourselves in, as it has become a fundamental necessity. Security breaches put puts personal and financial information at risk and that of businesses, causing losses that could drive companies into bankruptcy and making it essential to implement security strategies across all the systems we use in our environment.
Computer Cybersecurity
Introduction
Objectives
-
Understanding the information society and the key factors in the design and implementation of secure systems.
-
Identify and analyse risks in information systems, by assessing vulnerabilities and threats.
-
Explore the ethical hacking, including understanding legal aspects and carrying out vulnerability tests.
-
To design and implement policies on effective security measures, avoiding common mistakes.
-
Implement strategies security principles such as the principle of least privilege and the defence in depth.
-
To develop skills for implementing security measures in personal systems and corporate networks.
-
Mastering the installation, configuration and testing of firewalls and proxy servers.
Table of Contents
TEACHING UNIT 1. INTRODUCTION AND BASIC CONCEPTS
The information society
Design, development and implementation
Success factors in information security
TEACHING UNIT 2. RISKS INHERENT IN INFORMATION SYSTEMS
Risk analysis in information systems
Identification of vulnerabilities and threats to information systems
Types of malicious code
Elements of risk analysis and their interrelationships
Control methods for risk analysis
The assets involved in risk analysis and their valuation
Threats that may affect the identified assets
Details of existing vulnerabilities in information systems
TEACHING UNIT 3. ETHICAL HACKING
What is ethical hacking?
Legal aspects of ethical hacking
Ethical hacker profiles
Vulnerability testing
Sniffing
Types of security testing in web environments
TEACHING UNIT 4. SECURITY POLICIES
An Introduction to Security Policies
Why are policies important?
What should a security policy contain?
What a security policy should not contain
How to draw up an IT security policy
Ensuring that decisions on strategy and policy are implemented
TEACHING UNIT 5. SAFETY STRATEGIES
Lower privilege
Defence in depth
Point of conflict
The weakest link
Fail-safe position
An established stance of denial: what is not prohibited
Established permission policy: what is not permitted
Universal participation
Diversification of defence
Simplicity
TEACHING UNIT 6. IMPLEMENTATION OF ACTIVE SAFETY MECHANISMS
Attacks and countermeasures in personal systems
Corporate network security
Potential risks associated with network services
TEACHING UNIT 7. IMPLEMENTATION OF REMOTE ACCESS TECHNIQUES
Basic elements of perimeter security
Demilitarised zones
Secure subnet architecture
Virtual private networks. VPN
Advantages and disadvantages compared with dedicated lines
Encryption techniques. Public key and private key
Remote access servers
TEACHING UNIT 8. INSTALLATION AND CONFIGURATION OF FIREWALLS
Using and filtering the firewall
Types of firewalls
Installation of firewalls
Firewall filtering rules
Functional tests. Survey
TEACHING UNIT 9. INSTALLATION AND CONFIGURATION OF «PROXY» SERVERS»
Types of «proxy». Features and functions
Installation of «proxy» servers»
Installation and configuration of «proxy» clients»
Configuring caching on a «proxy»
Filter settings
Authentication methods on a «proxy»
TEACHING UNIT 10. IMPLEMENTATION OF HIGH-AVAILABILITY SOLUTIONS
Analysis of high-availability configurations
System virtualisation
The potential of system virtualisation
Virtualisation tools
Configuring and using virtual machines
High availability and virtualisation
Service simulation using virtualisation