The UK's foremost source of independent advice, guidance, networking and services for IT professionals
Search
Search By Topic

BS7799 and ISO9001 (Registration number: 928858)
System Security Planning
27th to 29th January 2009, Manchester

The System Security Planning Course expands on the one-day workshop to help you create specific security arrangements for your business. We cover the asset identification/risk assessment and treatment process to create the outline spreadsheet covered in the workshop but go into much more detail of the different security techniques and practices.

Successful delegates come through:

  • With a good understanding of how to define system security requirements, and a good understanding of a variety of generic security threats and vulnerabilities, and be able to identify and analyse particular security problems for a given application.
  • Being able to prioritise requirements, and match requirements to solutions and countermeasures commensurate with associated risks.
  • Having a good understanding of the correlation of business processes to technology in relation to security requirements.
  • Being familiar with the relevant industry security standards and the regulation, and their application.
  • Appreciating the application of security techniques and technologies in solving real-life security problems in practical systems.

After the course, you have a month to complete a system security plan for one of two case studies - one a for network, one for an application.

The plan has to cover:

  • System objectives (Purpose, Information life cycle and classification. Relevant topics for compliance, Regulation, Standards, Responsibilities)
  • An asset register, risk assessment, treatment and countermeasures
  • Business continuity and disaster recovery
  • User training and awareness
  • Quality assurance regime

The syllabus takes in:

The need for information assurance:

  • Security Breaches
  • Introduction to business continuity
  • System Lifecycles
  • Trust

Introduction to standards

  • Plan-do-check-act lifecycles
  • Overview of Information security management standards

Information security management

  • Security Policy
  • Security Organisation
  • Asset Classification and Control
  • Personnel Security
  • Physical and Environmental Security
  • Communications and Operations Management
  • Access Control
  • System Development and Maintenance
  • Incident management
  • Business Continuity Management
  • Compliance

Risk management

Vulnerabilities

Solutions and countermeasures

  • Entity authentication
  • Message security
  • Intrusion detection/prevention
  • Firewalls
  • Anti-virus software
  • Virtual Private Networks (VPN)

Active security

  • Audits, reviews, vulnerability scanners, and penetration testing
  • Computer forensics
Adding delegates
  1. Choose a venue/date from the drop-down list entitled 'Select Special Option'
  2. Enter each delegate's details in the form
  3. Click the Add to basket button
  4. Repeat this process for each delegate
  5. When you have finished, go to the checkout to review your order and pay


 
Delegate Details

Title
  
First name
  
Last name
  
Job Title
  
Telephone
  
Email address
  
Company name
  
Address 1
  
Address 2
  
Town
  
County
  
Postcode
  
Country
   Price £1,200.00


Return to previous page
 
Other related products:
 
Security - From risk to treatment Security - From risk to treatment
26th February 2009, London
19th March 2009, Edinburgh

This one-day intensive workshop delivers a pragmatic framework for risk management that keeps up to date with standards, best practice and compliance.
Price: £495.00 Add to basket
   
IT Governance IT Governance
Manchester, 27th November
London, 3rd December 2008
Edinburgh, 5th February 2009
Cardiff, 31st March 2009

Price: £495.00 Add to basket
   
Information Security Management Information Security Management
A comprehensive guide to standards for information security management
Price: £50.00