<?xml version="1.0" standalone="no" ?>

<!--  AIT_SecurityFundamentals.xml Course Outline in XML format
 *
 * Copyright 2010 Affinity IT Training, LLC. All Rights Reserved.
 *
 -->

<!DOCTYPE FAI:CourseOutline SYSTEM "FAI_CourseOutline.dtd">

<?xml-stylesheet type="text/xsl" href="FAI_CourseOutline.xsl" ?>	

<FAI:CourseOutline FAI:link="AIT_Security_Fundamentals.xml"
     xmlns:FAI="http://www.fisher-assoc.com/DTDs/FAI_CourseOutline.dtd" >

  <FAI:CourseTitle FAI:level="Introduction"  FAI:code="ITSecFunds">
	Fundamentals of IT Security
  </FAI:CourseTitle>  

  <FAI:CourseCategory>CyberSec</FAI:CourseCategory>

  <FAI:SummaryInfo>

    <FAI:CourseDesc FAI:version="Jul10">
   	A primer in IT Security concepts 
   	that provides a prerequisite understanding
   	of security fundamentals such as: 
   	understanding and mitigating risk,
   	defense-in-depth,
   	patterns of vulnerability, 
   	and effective countermeasures.
    </FAI:CourseDesc>

    <FAI:CourseDuration>
    	2 Days
    </FAI:CourseDuration>

    <FAI:CourseAudience>
    	Individuals seeking a fundamental understanding of IT Security,
    	particularly those interested in subsequently learning more about one or more of the following:
    	computer network security, 
	platform/system security, 
	Industrial Control System (ICS) security,
	and how to design and implement secure software.
    </FAI:CourseAudience>

    <FAI:CourseObjectives>
    	<FAI:Objective FAI:desc="Be familiar with basic IT Security concepts and terms" />
    	<FAI:Objective FAI:desc="Understand the importance of the strategy of &quot;Defense-in-Depth&quot;" />
    	<FAI:Objective FAI:desc="Be familar with important internetworking concepts and terms " />
    	<FAI:Objective FAI:desc="Be familiar with the TCP/IP network protocol suite" />
    	<FAI:Objective FAI:desc="Understand the purpose and effective deployment of firewall technology" />
    	<FAI:Objective FAI:desc="Be prepared to recognize and analyze IT security risks" />
    	<FAI:Objective FAI:desc="Be familiar with common sources of vulnerability in IT and ICS environments" />
    	<FAI:Objective FAI:desc="Be familiar with approaches to eliminate vulnerabilities and remediate risk" />
    	<FAI:Objective FAI:desc="Understand the role and critical importance of Authentication in cybersecurity" />
    </FAI:CourseObjectives>

    <FAI:CourseSetupList>

      <FAI:Setup FAI:desc="Internet Explorer 6 (or equivalent)"  />
      <FAI:Setup FAI:desc="Internet access preferred"  />

    </FAI:CourseSetupList>    

    <FAI:CourseTextList>

      <FAI:Text FAI:title="Course Workbook" />

    </FAI:CourseTextList>    

    <FAI:CoursePrerequisiteList>
    </FAI:CoursePrerequisiteList>    

  </FAI:SummaryInfo>  

  <FAI:TopicList>                                  

    <FAI:SuperTopic FAI:title="Introduction">
	<FAI:Topic FAI:title="Welcome"/>
	<FAI:Topic FAI:title="Motivation"/>
	<FAI:Topic FAI:title="Objectives"/>
	<FAI:Topic FAI:title="Prerequisites &amp; Setup"/>
	<FAI:Topic FAI:title="Course Overview"/>
    </FAI:SuperTopic>
    
    <FAI:SuperTopic FAI:title="IT Security Concepts and Terms" >
      <FAI:Topic FAI:title="Malware" />
      <FAI:Topic FAI:title="Vulnerabilities, Exploits, and Attacks" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Policies and Procedures" />
      <FAI:Topic FAI:title="Defense in Depth" />
      <FAI:Topic FAI:title="Risks and Priorities" />
      <FAI:Topic FAI:title="Security Domains" />
      <FAI:Topic FAI:title="Security vs. Ease of Use" />
      <FAI:Topic FAI:title="Security Goals" />
      <FAI:Topic FAI:title="Security Resources" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Understanding IT Security Risk" >
      <FAI:Topic FAI:title="What is Risk ?" />
      <FAI:Topic FAI:title="Examples of Risk" />
      <FAI:Topic FAI:title="Discovering Risk" />
      <FAI:Topic FAI:title="Threats and Attacker Motivation" />
      <FAI:Topic FAI:title="Opportunity Costs" />
      <FAI:Topic FAI:title="Risk Characteristics" />
      <FAI:Topic FAI:title="Risk Management" />
      <FAI:Topic FAI:title="Internal vs. External Threats" />
      <FAI:Topic FAI:title="Physical Security" />
      <FAI:Topic FAI:title="Network Security" />
      <FAI:Topic FAI:title="Platform Security" />
      <FAI:Topic FAI:title="Application Security" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Internetworking Primer" >
      <FAI:Topic FAI:title="The OSI Reference Model" />
      <FAI:Topic FAI:title="TCP/IP" />
      <FAI:Topic FAI:title="The Physical Layer" />
      <FAI:Topic FAI:title="The Network Layer" />
      <FAI:Topic FAI:title="IP Addressing" />
      <FAI:Topic FAI:title="The Transport Layer" />
      <FAI:Topic FAI:title="Sockets" />
      <FAI:Topic FAI:title="The Application Layer" />
      <FAI:Topic FAI:title="Popular Applications" />
      <FAI:Topic FAI:title="Switches and Routers" />
      <FAI:Topic FAI:title="LAN Communication" />
      <FAI:Topic FAI:title="Internetwork Communication" />
      <FAI:Topic FAI:title="Address Resolution Protocol (ARP)" />
      <FAI:Topic FAI:title="UDP" />
      <FAI:Topic FAI:title="Internet Control Messaging Protocol (ICMP)" />
      <FAI:Topic FAI:title="TCP" />
      <FAI:Topic FAI:title="Tunneling" />
      <FAI:Topic FAI:title="Source Routing" />
      <FAI:Topic FAI:title="Domain Name Service (DNS)" />
      <FAI:Topic FAI:title="Dynamic Host Control Protocol (DHCP)" />
      <FAI:Topic FAI:title="What is a Virtual Private Network (VPN) ?" />
      <FAI:Topic FAI:title="Simple Network Management Protocol (SNMP)" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Introduction to Firewalls" >
      <FAI:Topic FAI:title="What is a Firewall ?" />
      <FAI:Topic FAI:title="Stateless Packet Filtering" />
      <FAI:Topic FAI:title="Stateful Inspection" />
      <FAI:Topic FAI:title="Stateful Protocol Analysis" />
      <FAI:Topic FAI:title="Application Firewalls" />
      <FAI:Topic FAI:title="Routers and Firewalls" />
      <FAI:Topic FAI:title="Network Access Control" />
      <FAI:Topic FAI:title="Firewalls and Intrusion Prevention Systems" />
      <FAI:Topic FAI:title="Firewall Selection" />
      <FAI:Topic FAI:title="Firewall Policies" />
      <FAI:Topic FAI:title="Deny by Default" />
      <FAI:Topic FAI:title="Unified Policy Approach" />
      <FAI:Topic FAI:title="Firewalls and Network Architecture" />
      <FAI:Topic FAI:title="Firewalls and Network Address Translation" />
      <FAI:Topic FAI:title="Testing" />
      <FAI:Topic FAI:title="Deployment" />
      <FAI:Topic FAI:title="Maintenance" />
      <FAI:Topic FAI:title="Best Practices" />
      <FAI:Topic FAI:title="Project Management Considerations" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Vulnerability Macro Patterns" >
      <FAI:Topic FAI:title="Overpriviliged Users / Programs" />
      <FAI:Topic FAI:title="Weak Security Protocols and Implementations" />
      <FAI:Topic FAI:title="Human Factors" />
      <FAI:Topic FAI:title="Physical Access" />
      <FAI:Topic FAI:title="Out-of-Date Software" />
      <FAI:Topic FAI:title="Poor Configuration Management" />
      <FAI:Topic FAI:title="Poor Change Management" />
      <FAI:Topic FAI:title="Failure to Sufficiently Test" />
      <FAI:Topic FAI:title="False Sense of Security" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Counter Measure Macro Patterns" >
      <FAI:Topic FAI:title="Strong Firewall Deployments and Policies" />
      <FAI:Topic FAI:title="Ubiqitous Malware Protection" />
      <FAI:Topic FAI:title="Intrusion Detection and Intrusion Prevention Systems" />
      <FAI:Topic FAI:title="Secure Communications" />
      <FAI:Topic FAI:title="Security Policies and Procedures" />
      <FAI:Topic FAI:title="Employee Awareness and Vigilance" />
      <FAI:Topic FAI:title="Strong Authentication" />
      <FAI:Topic FAI:title="Strong Password Policies" />
      <FAI:Topic FAI:title="Least Permission" />
      <FAI:Topic FAI:title="Role Based Permissions" />
      <FAI:Topic FAI:title="Permissions Management" />
      <FAI:Topic FAI:title="Configuration Management" />
      <FAI:Topic FAI:title="Contingency Planning" />
      <FAI:Topic FAI:title="Incident Response Planning" />
      <FAI:Topic FAI:title="Adequate Testing Facilities" />
      <FAI:Topic FAI:title="Governance" />
      <FAI:Topic FAI:title="Technical Training" />
      <FAI:Topic FAI:title="Logging and Audit Trails" />
      <FAI:Topic FAI:title="Physical Security" />
      <FAI:Topic FAI:title="Network Security" />
      <FAI:Topic FAI:title="Platform Security" />
      <FAI:Topic FAI:title="Software Security Training" />
      <FAI:Topic FAI:title="Security Reviews" />
      <FAI:Topic FAI:title="Deny by Default: Firewall Policies" />
      <FAI:Topic FAI:title="Penetration Testing" />
      <FAI:Topic FAI:title="Secure Communications" />
      <FAI:Topic FAI:title="Intrusion Detection Systems" />
      <FAI:Topic FAI:title="Intrusion Prevention Systems" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Authentication" >
      <FAI:Topic FAI:title="Purpose" />
      <FAI:Topic FAI:title="Methods" />
      <FAI:Topic FAI:title="Vulnerabilities" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Summary" />
      <FAI:Topic FAI:title="Quiz" />
      <FAI:Topic FAI:title="Lab Exercise" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Case Study: Segregation of Networks" >
      <FAI:Topic FAI:title="Case Study Description" />
      <FAI:Topic FAI:title="Lab Exercise: Risk Identifcation" />
      <FAI:Topic FAI:title="Lab Exercise: Risk Qualification" />
      <FAI:Topic FAI:title="Lab Exercise: Risk Priorities" />
      <FAI:Topic FAI:title="Lab Exercise: Risk Remediation" />
      <FAI:Topic FAI:title="Solutions Presentations/Readout" />
    </FAI:SuperTopic>

  </FAI:TopicList>

  <FAI:Appendix FAI:title="Quiz Answers" />
  <FAI:Appendix FAI:title="Additional Learning Resources" />
    
</FAI:CourseOutline>

 