Free Trial

Safari Books Online is a digital library providing on-demand subscription access to thousands of learning resources.

Overview

Security Operations and Administration

Shon Harris

The fast, powerful way to prepare for your SSCP exam!

Get all the hands-on training you need to pass (ISC)²’s tough SSCP exam, get certified, and move forward in your IT security career! In this online video, the world’s #1 information security trainer walks you through every skill and concept you’ll need to master. This online video contains over four and a half hours of training adapted from Shon Harris’s legendary five-day SSCP boot camps–including realistic labs, scenarios, case studies, and animations designed to build and test your knowledge in real-world settings!

Comprehensive coverage of SSCP domains of knowledge:

     .    Security Definitions

     .    Common Open Standards

     .    Backups

     .    Remote Access

     .    Support Systems

     .    Common Criteria

About the Shon Harris Security Series

This online video is part of a complete library of books, online services, and videos designed to help security professionals enhance their skills and prepare for their certification exams. Every product in this series reflects Shon Harris’s unsurpassed experience in teaching IT security professionals.

Category: Security

System Requirements

OPERATING SYSTEM: Windows 2000, XP, or Vista; Mac OS X 10.4 (Tiger) or later
MULTIMEDIA: DVD drive; 1024 x 768 or higher display; sound card with speakers
COMPUTER: 500MHz or higher CPU; 128MB RAM or more

Subscriber Reviews

Average Rating: 4 out of 5 rating Based on 1 Rating

No Subscribers have provided a review for this video.

Table of Contents

Chapter/Selection

Time

Course Introduction

Play Video

00:17:16

Domain 2 – Security Operations and Administration

Preview

00:01:41

Mainframe Days

Preview

00:00:50

In the Good Old Days – Who Knew?

Preview

00:02:26

Today’s Environment

Preview

00:01:36

Security Definitions

Preview

00:01:14

Vulnerabilities

Preview

00:00:45

Examples of Some Vulnerabilities that Are Not Always Obvious

Preview

00:02:09

Risk – What Does It Really Mean?

Preview

00:02:09

Relationships

Preview

00:02:01

Who Deals with Risk?

Preview

00:01:17

Overall Business Risk

Preview

00:01:30

Who?

Preview

00:00:43

AIC Triad

Preview

00:00:48

Availability

Preview

00:00:51

Integrity

Preview

00:01:05

Confidentiality

Preview

00:00:48

Who Is Watching?

Preview

00:02:04

Social Engineering

Preview

00:04:06

What Security People Are Really Thinking

Preview

00:01:13

Security Concepts

Preview

00:01:00

Security?

Preview

00:04:56

The Bad Guys Are Motivated

Preview

00:02:37

Open Standards

Preview

00:00:14

Common Open Standards

Preview

00:01:42

Without Standards

Preview

00:01:03

“Soft� Controls

Preview

00:04:42

Holistic Security

Preview

00:00:41

Not Always So Easy

Preview

00:00:40

What Is First?

Preview

00:02:16

Different Types of Law

Preview

00:03:21

How Is Liability Determined?

Preview

00:01:21

Examples of Due Diligence

Preview

00:02:00

Prudent Person Rule

Preview

00:02:30

Prudent Person

Preview

00:00:19

Components of Security Program

Preview

00:00:49

A Layered Approach

Preview

00:01:21

In Security, You Never Want Any Surprises

Preview

00:00:51

Building Foundation (1)

Preview

00:00:45

Security Roadmap

Preview

00:03:30

Functional and Assurance Requirements

Preview

00:00:56

Building Foundation (2)

Preview

00:01:26

Most Organizations

Preview

00:02:46

Silo Security Structure

Preview

00:01:21

Islands of Security Needs and Tools

Preview

00:00:33

Get Out of a Silo Approach

Preview

00:01:38

Approach to Security Management

Preview

00:01:04

Result of Battling Management

Preview

00:00:26

Industry Best Practices Standards

Preview

00:01:11

ISO/IEC 17799

Preview

00:01:11

Numbering

Preview

00:01:10

New ISO Standards

Preview

00:01:27

COBIT

Preview

00:01:13

COBIT – Control Objectives

Preview

00:01:37

Information Technology Infrastructure Library

Preview

00:01:54

Security Governance

Preview

00:04:59

Security Program Components

Preview

00:00:28

Policy Framework

Preview

00:01:03

Organizational Policy

Preview

00:00:54

Policy Approved – Now What?

Preview

00:00:51

Issue-Specific Policies

Preview

00:00:45

System-Specific Policies

Preview

00:01:37

Standards

Preview

00:02:13

Baseline (1)

Preview

00:01:18

Data Collection for Metrics (1)

Preview

00:01:16

Guidelines

Preview

00:00:33

Procedures

Preview

00:00:36

Tying Them Together

Preview

00:01:16

Program Support

Preview

00:00:41

Senior Management’s Role

Preview

00:01:05

Security Roles

Preview

00:04:06

Information Classification

Preview

00:00:54

Data Leakage

Preview

00:00:45

Do You Want to End Up in the News?

Preview

00:00:52

Types of Classification Levels

Preview

00:00:47

Data Protection Levels

Preview

00:00:52

Classification Program Steps

Preview

00:02:01

Information Classification Components

Preview

00:01:02

Classification Levels

Preview

00:00:40

Information Classification Criteria

Preview

00:01:14

Criteria Example

Preview

00:00:33

Or Not

Preview

00:00:45

Information Owner Requirements

Preview

00:00:50

Clearly Labeled

Preview

00:01:00

Testing Classification Program

Preview

00:00:59

Employee Management

Preview

00:01:12

Employee Position and Management

Preview

00:00:47

Hiring and Firing Issues

Preview

00:04:49

Security Awareness and Training

Preview

00:01:52

Training Characteristics

Preview

00:00:34

Awareness

Preview

00:00:38

Security Enforcement Issues

Preview

00:00:52

Computer Operations

Preview

00:00:57

What Do We Have?

Preview

00:00:45

Hardware Protection

Preview

00:01:00

ITIL – Problem Management

Preview

00:01:35

Problem Management Procedures for Processing Problems

Preview

00:01:26

Data Output Controls

Preview

00:00:21

Administrative Controls Personnel Controls

Preview

00:03:01

Security Operations Personnel

Preview

00:01:09

Change Control

Preview

00:00:54

Another Example

Preview

00:00:44

Agenda 1

Preview

00:00:57

Library Maintenance

Preview

00:01:05

Media Labels

Preview

00:00:29

Media Controls

Preview

00:00:49

Software Escrow

Preview

00:01:21

Media Reuse

Preview

00:02:47

Zeroization

Preview

00:02:00

Physical Destruction

Preview

00:00:45

Why Not Just Delete the Files?

Preview

00:01:46

Mainframes

Preview

00:00:58

Agenda 2

Preview

00:00:38

HSM

Preview

00:01:08

Off-Line

Preview

00:00:07

Backup Types

Preview

00:01:07

Incremental Backup

Preview

00:01:15

Incremental

Preview

00:02:35

Differential Backup

Preview

00:02:02

Backup Protection

Preview

00:01:16

Agenda 3

Preview

00:01:16

Mean Time Between Failure

Preview

00:00:58

Single Point of Failure

Preview

00:03:21

Mirroring Data

Preview

00:00:42

Disk Duplexing

Preview

00:00:42

Redundant Array of Independent Disks

Preview

00:05:36

Massive Array of Inactive Disks (MAID)

Preview

00:00:49

Redundant Array of Independent Tapes (RAIT)

Preview

00:00:33

Serial Advanced Technology Architecture

Preview

00:00:49

SAN

Preview

00:01:13

Fault Tolerance

Preview

00:02:05

Redundancy Mechanism

Preview

00:01:13

Backup Configuration Files

Preview

00:01:17

Trusted Recovery of Software

Preview

00:01:09

After System Crash

Preview

00:00:50

Security Concerns

Preview

00:01:31

Agenda 4

Preview

00:00:04

Contingency Planning

Preview

00:01:18

Agenda 5

Preview

00:03:19

Remote Access

Preview

00:01:31

Administering Systems Remotely

Preview

00:01:36

Facsimile Security

Preview

00:01:31

Support Systems

Preview

00:01:24

Configuration Management (2)

Preview

00:02:23

Change Control Roles in CM

Preview

00:03:01

Configuration Management Plan

Preview

00:01:19

Change Control-Security Environment

Preview

00:01:20

Process of Change Management

Preview

00:01:33

Baseline (2)

Preview

00:01:24

Risk-based Cost Effective Controls

Preview

00:02:44

Software Programming

Preview

00:00:30

Security Considered at Each Phase

Preview

00:04:23

Waterfall Model

Preview

00:01:41

WaterFall Stages

Preview

00:01:20

Requirement Analysis

Preview

00:01:16

Design

Preview

00:01:01

Development

Preview

00:02:07

Verification

Preview

00:01:44

Operation and Maintenance

Preview

00:02:27

Iterative Development Model

Preview

00:02:32

Exploratory Model

Preview

00:02:29

Rapid Application Development (RAD) Model

Preview

00:01:39

Spiral Model

Preview

00:04:33

Reuse Model

Preview

00:01:34

Computer Aided Software Engineering Model (CASE)

Preview

00:05:07

Extreme Programming

Preview

00:01:53

Trusted Computer System Evaluation Criteria (TCSEC)

Preview

00:01:09

TCSEC

Preview

00:00:40

TCSEC Rating Breakdown

Preview

00:01:57

Evaluation Criteria – ITSEC

Preview

00:01:21

ITSEC Ratings

Preview

00:01:12

Common Criteria

Preview

00:00:27

Security Functional Requirements

Preview

00:00:46

Common Criteria Components

Preview

00:02:03

Common Criteria Requirements

Preview

00:00:40

Common Criteria Outline

Preview

00:01:09

Certification versus Accreditation

Preview

00:00:37

Security Levels

Preview

00:01:01

Modes of Operation

Preview

00:03:12

MAC Modes (Cont.)

Preview

00:00:39

Sets of Ethics

Preview

00:03:26

Computer Ethics Institute

Preview

00:00:36

Internet Architecture Board

Preview

00:02:03

Domain 2 Review

Preview

00:01:42