Pakistan Computer Emergency Response Team

The Security Standard


HOME | ABOUT US | SERVICES | ADVISORIES | RESOURCES | DEFACEMENT ARCHIVE | MEMBERS AREA | TRAINING | CONTACT US

Copyright | Disclaimer

 

 

 


 

CERTIFIED INFORMATION SYSTEMS SECURITY PROFESSIONAL (CISSP) TRAINING BOOT CAMP

Starting Data: 5th October

Last Date for Registration: 2nd October

Duration: 5 Days (9:00am - 3:00pm daily)

Fee: Rs.40,000/-

Course Package Includes:CISSP Classroom Notes and a CD with CISSP Resources

Venue: Suite 807, Aramex SMS Tower (old Kawish Crown Plaza), Main Shahrah-e-Faisal, Karachi - Pakistan

Who Teaches the Class?
Security Assessment and Penetration Testing Expert, Qazi Mohammad Misbahuddin Ahmed is the pioneer of Security Assessment and Penetration Testing services in Pakistan. He holds a Bachelor in Computer Science and MBA-MIS along with the following industry leading certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Penetration Testing Specialist (CPTS)
  • Certified Ethical Hacker (CEH)
  • COBIT based IT Governance Exam (COBIT)
  • Information Technology Infrastructure Library (ITIL v3)
  • Associate Member of Business Continuity Institute (AMBCI)

He has performed several penetration tests, forensic analysis and incident response procedures for many national and multi-national companies. He has served as a member of Network Security Taskforce working under the Technology Resource Mobilization Unit of Ministry of IT&T, Government of Pakistan. He has conducted several workshops for high profile companies and is a regular speaker at many IT events and conferences like E-Merge, IT Expo, ProCOM, ITCN Asia ProQuest and also served as a coordinator and Judge at the ITCN Asia ProQuest Hacking Competition.

Qazi Ahmed is routinely called to comment and discuss on IT security events and has been featured on several TV channels like GEO, ARY Digital, Indus News, PTV and newspapers, magazines and newsletters like Spider, @internet, YAHOO!, CISCO, Newsbytes, Wall Street Journal, India Times, Hindustan Times etc.

Qazi Ahmed is also credited for finding the most severe security vulnerability ever discovered in Microsoft .NET Passport services affecting millions of people worldwide. Qazi Ahmed also enjoys the membership of renowned worldwide High IQ society, Mensa.

Recently Qazi Ahmed has been selected as an honoree for the Asia-Pacific Information Security Leadership Achievements (ISLA) Program 2008 in the Senior IT Security Professional category by the International Information Systems Security Certification Consortium (ISC2).

Our information security training sessions have been attended by professionals from organizations such as:

  • Ministry of Defence
  • Pakistan Atomic Energy Commission
  • Ernst & Young
  • Juma Al Majid Group (UAE)
  • Unilever
  • Habibsons Bank (UK)
  • Allied Bank Limited
  • Qasim International Container Terminal
  • Agha Khan University
  • Dubai Islamic Bank
  • Qatar Airways
  • Central College London (UK)
  • Union Bank
  • Alliance Frances
  • Central Depository Company
  • Karachi Electricity Supply Corporation
  • Getz Pharma
  • Xpert2go Inc. (USA)
  • Compunet Online (ISP)
  • Lucky Textile Mills
  • Nadra
  • Agha Khan Education Service
  • Hamdard University Network
  • Habib Bank AG Zurich
  • Nakshbandi Industries
  • Sidat Hyder Morshed Associates

COURSE TOPICS

Day 1

Module 1 - Access Control

Steps of Access Control, Access Control Mechanisms, Authentication, Biometrics, Password Practices, Synchronous One-Time Password Generator, Asynchronous One-Time Password Generator, Token Devices, Passphrase, Authentication Mechanisms, Single Sign-On Technologies, Kerberos Components, Access Control Models, Discretionary Access Control, Mandatory Access Control, Security Labels, Role-based Access Control, Role-based Access Model, Lattice-based Access Control, Rule-based Access Control, Centralized Access Control Administration, Decentralized Access Control Administration, RADIUS Steps, TACACS Steps, Technical Controls, Physical Controls, Accountability, Log Protection, Social Engineering, IDS, Penetration Testing, Attack Strategies

Module 2 - Network and Telecommunications Security

TCP\IP, IP, UDP Versus TCP, Networks, Intranet and Extranet, Network Wiring, Network Topologies, LAN Media Access Technologies, Protocols, Networking Devices, Firewalls, Bastion Host, Demilitarized Zone, Virtual Private Network, Tunneling Protocols, Wide Area Network, Remote Access, Dial-up and RAS, PBX Protection, Physical and Data Link Layer, Wireless Application Protocol, Wired Equivalent Privacy (WEP) , Possible WLAN Attacks, War Driving, Countermeasures


Day 2

Module 3 - Information Security and Risk Management

Evolution of Security Management, Security through Obscurity, Control Types, Due Care and Due Diligence, CIA Triad, Possible Threats, Security Controls, Security Models, Risk Management, Steps of a Risk Analysis, Security Policies, Approach to Security Management, Data Classification, Commercial versus Military Classifications, Employee Management

Module 4 - Applications and Systems Development

Applications and Systems Development Objectives, Project Development, Verification versus Validation, Administrative Control, Change Control, Configuration Management Issues, Software Development, Application Development Methodology, Object-Oriented Programming, Module Interaction, Cohesive and Coupling, Distributed Computing, Java Security, Database Systems, Database Security Mechanisms, Data Mining, Artificial Intelligence, Artificial Neural Networks, Malicious Code, Attack Types, Smurf Attack, SYN Attack, Timing Attacks


Day 3

Module 5 - Cryptography

History of Cryptography, Scytale Cipher, Cryptography in War, Protection of Encryption, Keys and Text, Breaking Encryption Systems, Attack on Cipher Types, Government and Cryptography, Clipper Chip, Escrowing Keys, Cipher Types, S-boxes in Block Ciphers, Stream Cipher, Symmetric versus Asymmetric, Key Distribution, Public Key Cryptography, Key Management, Data Encryption, Creation of a Session Key with Diffie-Hellman, Key recovery, Secured and Signed Message, Types of Symmetric Algorithms, DES Conceptually, Advanced Encryption Standard, Message Integrity, Hashing Algorithms, Digital Signature, Message Integrity, Public Key Infrastructure, Certificate Details, CA Hierarchy, Cross-certification, CA Communication, One-Time Pad, E-mail Security, Secure Protocols, SET, IPSec, Attacks Types

Module 6 - Security Architecture and Design

Computer Architecture Components, Central Processing Unit (CPU), Storage Types, Memory Mapping, Hardware Segmentation, Process versus Thread, OSI Model, Data Encapsulation, Application Layer, Presentation Layer, Session Layer, Transport Layer, Network Layer, Data Link and Physical Layers, Protocols at Each Layer, Systems Self Protection, Resource Access, Process Isolation, Layered Approach, Protection Rings, Trusted Computing Base, Security Perimeter, Reference Monitor, Security Kernel, Operating States, Security Models, State Machine Models, Bell-LaPadula Model, Biba Model, Clark-Wilson Model, Non-Interference Model, Information Flow Model, Brewer and Nash Model - Chinese Wall Security Policy, Trusted Computer System Evaluation Criteria (TCSEC), Information Technology Security Evaluation Criteria (ITSEC), Common Criteria, Timing Attacks


Day 4

Module 7 - Operations Security

Operations Security Objectives, Operational Controls, Control Types, Audit Data, Configuration Management, Trusted Recovery, Facsimile Security, Operational Duties, Network Availability, RAID Levels, Redundancy Mechanism, Backups, Threats and Attacks

Module 8 - Business Continuity and Disaster Recovery Planning

Disaster Recovery Issues, Impacting Business, Possible Threats, Categories of Disruptions, Results from the BIA, Disaster Recovery Plan, Developing a Recovery Team, Backup Alternatives, Facility Backups, Electronic Vaulting, Off-Site Storage, Testing and Drills, Maintenance, Phases of Plan, Preventions


Day 5

Module 9 - Legal, Regulations, Compliance and Investigations

Law, Investigation, and Ethics Objectives, Ethics, Computer Crime Issues, Attack Types, Phone Fraud, Legal Liability, Risk Assessment, Privacy Issues, International Issues, Types of Common Laws, Criminal Law, Civil Law, New Federal Policies, Intellectual Property Laws, Responding to a Computer Crime, Incident Handling, Incident Response, Forensics, Evidence

Module 10 - Physical (Environmental) Security

Physical Security Components, Threats, Facility Location, Facility Construction, Facility Attributes, Physical Security Controls, Hardware Backups, Electrical Power, Environmental Considerations, Fire Prevention, Entrance Protection, Audit Trails, Exterior Boundary Protection, Perimeter Issues, Perimeter Protection, Security Guards, Monitoring, Intrusion Detection Systems

 


All rights reserved. Copyright© PakCERT 2000-2008