ISCAP - Information Systems Certification & Accreditation Process + Top 20 Controls
urse Name: Information Security Certification Accreditation & Process + Top 20 Security Controls
Maps to SANS Security 440 & ISC2 CAP (Certification and Accreditation Professional)
Certification Track: (Certified Information Systems Security Auditor) & ICS2 CAP
Duration: 5 days
Language: English
Format: Instructor-led & Live Virtual Training
Prerequisites:
•A minimum of 12 months experience in networking technologies
•Sound knowledge of TCP/IP
•Knowledge of Microsoft packages
•Network+, Microsoft, Security+
•Basic Knowledge of Linux is essential
Student Materials:
•Student Workbook
•Student Reference Manual
•Mile2 Shirt & Pen
Who Should Attend?
•Information System Security Officers
•Certifiers
•System Managers
•State and Local Governments
COURSE OVERVIEW
This course covers proven tools and methodologies needed to execute and analyze the Top Twenty Most Critical Security Controls. Nearly all organizations containing sensitive information are adopting these Security Controls, listed below, as the highest priority list of what must be substantiated before anything else.
These controls were chosen by leading government and private organizations who are experts on how attacks work and what can be done to prevent them from happening. The controls were selected as the best way to block known attacks as well as help search for and alleviate any damage from the attacks that are successful. This course allows the security professional to see how to implement controls in your existing network though highly effective and economical automation. For management, this training is the best way to distinguish how you will assess whether these security controls are effectively being administered.
UPON COMPLETION
Upon completion, students will be able to confidently undertake the ISC2 CAP and SANS Security 440 certification examination. Students will enjoy an in-depth course that is continuously updated to maintain and incorporate the ever changing security environment. This course offers up-to-date proprietary laboratories and case studies that have been researched and developed by leading security professionals from around the world.
COURSE DETAILS
1.I. IS Auditing
Foundation of Standards
Requirements of an Auditor
Skills necessary for an Audit
Mandatory vs. Discretionary wording of regulations
Types of Audits
How to communicate with Auditee
Auditor Leadership duties
2.II. The Audit Process
Developing and implementing a risk based audit strategy
How to structure an Audit
Implementing principles of quality into audit
Maintaining independence while implementing risk management and control practices
Understanding qualifications and competence requirements
Conducting Audits in accordance with standards, guidelines, and best practices
Identifying and implementing types of controls
Acquiring and utilizing audit evidence
E-discovery and the various challenges
Audit documentation and reports
3.III. Key Elements of Certification and Accreditation
4.IV. Certification and Accreditation Roles and Responsibilities
5.V. Certification and Accreditation Life Cycle
6.VI. Why Certification and Accreditation Programs Fail
7.VII. Project Planning
8.VIII. Inventory Process
9.IX. Data Sensitivity and Criticality Assessments
10.X. System Security Plans
11.XI. Interconnected Security Systems Coordination
12.XII. Minimum Security Baselines and Best Practices
13.XIII. Assessing Risk
14.XIV. Security Procedures
15.XV. Certification Testing
16.XVI. Remediation Planning
17.XVII. Essential Documentation for Certification and Accreditation
18.XVIII. Final Discussion on Twenty Critical Controls for Effective Cyber Defense
Certification and Accreditation Process
I. Introduction
II. Phase I – Initiation
a. Prepare Documentation
b. Notify Officials and Identify Resources
c. Analyze, Update and Accept System Security Plan
III. Phase II – Certification
a. Assess and Evaluate Security Controls
b. Document Security Certification
IV. Phase III- Accreditation
a. Make Security Accreditation Decision
b. Document Security Accreditation
V. Phase IV – Monitoring
a. Manage and Control Configuration
b. Monitor Security Controls
c. Report & Document Status