<?xml version="1.0" standalone="no" ?>

<!--  AIT_SecurityFundamentals.xml Course Outline in XML format
 *
 * Copyright 2011 Affinity IT Training, LLC. All Rights Reserved.
 *
 -->

<!DOCTYPE FAI:CourseOutline SYSTEM "FAI_CourseOutline.dtd">

<?xml-stylesheet type="text/xsl" href="FAI_CourseOutline.xsl" ?>	

<FAI:CourseOutline FAI:link="AIT_Security_Fundamentals.xml"
     xmlns:FAI="http://www.fisher-assoc.com/DTDs/FAI_CourseOutline.dtd" >

  <FAI:CourseTitle FAI:level="Introduction"  FAI:code="ITSecFunds">
	Fundamentals of IT Security
  </FAI:CourseTitle>  

  <FAI:CourseCategory>CyberSec</FAI:CourseCategory>

  <FAI:SummaryInfo>

    <FAI:CourseDesc FAI:version="Jul10">
   	A primer in IT Security 
	that addresses foundational topics
	including: 
	IT Risk Analysis,
	Network and Platform security, 
	wireless technology,
	cryptography, VPNs, and Firewalls.
	Emphasis is consistently placed on
   	understanding and mitigating risk,
   	defense-in-depth,
   	vulnerability patterns, 
   	Best Practices, 
	and effective countermeasures.
    </FAI:CourseDesc>

    <FAI:CourseDuration>
    	3 Days
    </FAI:CourseDuration>

    <FAI:CourseAudience>
    	Individuals seeking a solid grounding in IT Security;
    	particularly those interested in subsequently learning more about any of the following:
    	Network security, 
	Platform security, 
	Industrial Control System (ICS) security,
	and how to design and implement secure software.
    </FAI:CourseAudience>

    <FAI:CourseObjectives>
    	<FAI:Objective FAI:desc="Be familiar with basic IT Security concepts and terms" />
    	<FAI:Objective FAI:desc="Understand the importance of &quot;Defense-in-Depth&quot;" />
    	<FAI:Objective FAI:desc="Be familiar with a Security Domains framework that facilitates IT Risk recognition and reduction" />
    	<FAI:Objective FAI:desc="Be prepared to recognize and analyze IT Security Risk" />
    	<FAI:Objective FAI:desc="Be prepared to identify IT Security vulnerabilities and implement effective Countermeasures" />
    	<FAI:Objective FAI:desc="Be familar with important internetworking concepts and terms " />
    	<FAI:Objective FAI:desc="Understand the purpose and effective deployment of Firewall and VPN technology" />
    </FAI:CourseObjectives>

    <FAI:CourseSetupList>
      <FAI:Setup FAI:desc="Internet access"  />
      <FAI:Setup FAI:desc="Cryptography Tools (recommended)"  />
      <FAI:Setup FAI:desc="OpenSSL (recommended)"  />
      <FAI:Setup FAI:desc="Lab Router(s), WAP(s), Firewalls (recommended)"  />
      <FAI:Setup FAI:desc="Lab IDPS(s) (recommended)"  />
    </FAI:CourseSetupList>    

    <FAI:CourseTextList>

      <FAI:Text FAI:title="Course Workbook" />

    </FAI:CourseTextList>    

    <FAI:CoursePrerequisiteList>
    </FAI:CoursePrerequisiteList>    

  </FAI:SummaryInfo>  

  <FAI:TopicList>                                  

    <FAI:SuperTopic FAI:title="Introduction">
	<FAI:Topic FAI:title="Welcome"/>
	<FAI:Topic FAI:title="Motivation"/>
	<FAI:Topic FAI:title="Objectives"/>
	<FAI:Topic FAI:title="Prerequisites &amp; Setup"/>
	<FAI:Topic FAI:title="Course Overview"/>
    </FAI:SuperTopic>
    
    <FAI:SuperTopic FAI:title="IT Security Concepts and Terms" >
      <FAI:Topic FAI:title="Malware" />
      <FAI:Topic FAI:title="Vulnerabilities, Threats, and Attacks" />
      <FAI:Topic FAI:title="Vulnerabilities and Threats" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Policies and Procedures" />
      <FAI:Topic FAI:title="Risks and Risk Management" />
      <FAI:Topic FAI:title="Risk Analysis and Mitigation" />
      <FAI:Topic FAI:title="Defense in Depth" />
      <FAI:Topic FAI:title="Security Domains" />
      <FAI:Topic FAI:title="Security vs. Convenience" />
      <FAI:Topic FAI:title="Security Goals" />
      <FAI:Topic FAI:title="Security Resources" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Malware" >
      <FAI:Topic FAI:title="Viruses, Worms, and Trojans... Oh My !" />
      <FAI:Topic FAI:title="Malware Characteristics" />
      <FAI:Topic FAI:title="Countermeasures" />
      <FAI:Topic FAI:title="Malware Detection and Removal" />
      <FAI:Topic FAI:title="Additional Resources" />
      <FAI:Topic FAI:title="Lab Exercise: Don&apos;t Catch Anything !" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Understanding IT Security Risk" >
      <FAI:Topic FAI:title="Risk and Risk Management" />
      <FAI:Topic FAI:title="Threats and Attacker Motivation" />
      <FAI:Topic FAI:title="Internal Threats" />
      <FAI:Topic FAI:title="Examples of IT Security Risk" />
      <FAI:Topic FAI:title="Risk Valuation" />
      <FAI:Topic FAI:title="Risk Analysis and Mitigation" />
      <FAI:Topic FAI:title="Lab Exercise: Closer to Home" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Internetworking Primer" >
      <FAI:Topic FAI:title="IT Security and Internetworking" />
      <FAI:Topic FAI:title="Networking Concepts and Terms" />
      <FAI:Topic FAI:title="The OSI Reference Model" />
      <FAI:Topic FAI:title="TCP/IP" />
      <FAI:Topic FAI:title="IP Addresses" />
      <FAI:Topic FAI:title="Ethernet" />
      <FAI:Topic FAI:title="Internetwork Communications" />
      <FAI:Topic FAI:title="Routers" />
      <FAI:Topic FAI:title="Dynamic Host Control Protocol (DHCP)" />
      <FAI:Topic FAI:title="Domain Name Service (DNS)" />
      <FAI:Topic FAI:title="Address Resolution Protocol (ARP)" />
      <FAI:Topic FAI:title="Transport Layer" />
      <FAI:Topic FAI:title="User Datagram Protocol (UDP)" />
      <FAI:Topic FAI:title="Transport Control Protocol (TCP)" />
      <FAI:Topic FAI:title="What is a Virtual Private Network (VPN) ?" />
      <FAI:Topic FAI:title="Simple Network Management Protocol (SNMP)" />
      <FAI:Topic FAI:title="Lab Exercise: Vulnerabilities" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Introduction to Firewalls" >
      <FAI:Topic FAI:title="What is a Firewall ?" />
      <FAI:Topic FAI:title="Network Address Translation (NAT)" />
      <FAI:Topic FAI:title="Stateless Packet Filtering" />
      <FAI:Topic FAI:title="Stateful Inspection" />
      <FAI:Topic FAI:title="Firewall Policy" />
      <FAI:Topic FAI:title="Firewalls and Network Architecture" />
      <FAI:Topic FAI:title="Testing" />
      <FAI:Topic FAI:title="Unified Policy Approach" />
      <FAI:Topic FAI:title="Best Practices" />
      <FAI:Topic FAI:title="Lab Exercise: Fire Prevention" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="IT Security Macro Patterns" >
      <FAI:Topic FAI:title="Security Domains Revisited" />
      <FAI:Topic FAI:title="What are IT Security Macro Patterns ?" />
      <FAI:Topic FAI:title="Security Domains and Change" />
      <FAI:Topic FAI:title="Risk Management" />
      <FAI:Topic FAI:title="General Security" />
      <FAI:Topic FAI:title="Access Control" />
      <FAI:Topic FAI:title="Physical Security" />
      <FAI:Topic FAI:title="Platform Security" />
      <FAI:Topic FAI:title="Network Security" />
      <FAI:Topic FAI:title="Application Security" />
      <FAI:Topic FAI:title="Lab Exercise: Close to Home" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Introduction to Cryptography" >
      <FAI:Topic FAI:title="Motivation" />
      <FAI:Topic FAI:title="Terms and Concepts" />
      <FAI:Topic FAI:title="Message Integrity" />
      <FAI:Topic FAI:title="Message Integrity: SHA" />
      <FAI:Topic FAI:title="Steganography" />
      <FAI:Topic FAI:title="Encryption Methods" />
      <FAI:Topic FAI:title="Symmetric Encryption" />
      <FAI:Topic FAI:title="Stream Ciphers" />
      <FAI:Topic FAI:title="Encryption Methods: Block Cipher Modes" />
      <FAI:Topic FAI:title="Data Encryption Standard (AES)" />
      <FAI:Topic FAI:title="Advanced Encryption Standard (AES)" />
      <FAI:Topic FAI:title="Secure Key Exchange" />
      <FAI:Topic FAI:title="Asymmetric Encryption (Public Key Cryptography)" />
      <FAI:Topic FAI:title="Overview of Cryptanalysis" />
      <FAI:Topic FAI:title="Lab Exercise: I Said What ?" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Public Key Infrastructure" >
      <FAI:Topic FAI:title="Digital Signatures" />
      <FAI:Topic FAI:title="Digital Certificates" />
      <FAI:Topic FAI:title="Public Key Cryptography" />
      <FAI:Topic FAI:title="Public Key Infrastructure" />
      <FAI:Topic FAI:title="How HTTPS Works" />
      <FAI:Topic FAI:title="X.509 Digital Certificates" />
      <FAI:Topic FAI:title="Example: Digital Certificates" />
      <FAI:Topic FAI:title="Certificate Authorities" />
      <FAI:Topic FAI:title="Trust Models" />
      <FAI:Topic FAI:title="Certificate Validation" />
      <FAI:Topic FAI:title="Certificate Revocation" />
      <FAI:Topic FAI:title="Key Management" />
      <FAI:Topic FAI:title="Lab Exercise: Are You Certifiable ?" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Understanding Virtual Private Networks (VPNs)" >
      <FAI:Topic FAI:title="VPN Technologies Overview" />
      <FAI:Topic FAI:title="Deployment Architectures" />
      <FAI:Topic FAI:title="IPsec Overview" />
      <FAI:Topic FAI:title="Authentication Header (AH)" />
      <FAI:Topic FAI:title="Encapsulated Security Payload (ESP)" />
      <FAI:Topic FAI:title="Internet Key Exchange (IKE)" />
      <FAI:Topic FAI:title="IPComp" />
      <FAI:Topic FAI:title="VPN Operational Overview" />
      <FAI:Topic FAI:title="VPN Implementation" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Wireless Network Security" >
      <FAI:Topic FAI:title="Overview" />
      <FAI:Topic FAI:title="WLAN Technologies and Standards" />
      <FAI:Topic FAI:title="WLAN Vulnerabilities" />
      <FAI:Topic FAI:title="WAP Countermeasures" />
      <FAI:Topic FAI:title="802.11" />
      <FAI:Topic FAI:title="802.11i" />
      <FAI:Topic FAI:title="Best Practices" />
      <FAI:Topic FAI:title="Lab Exercise: On the Air !" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

    <FAI:SuperTopic FAI:title="Intrusion Detection and Prevention Systems" >
      <FAI:Topic FAI:title="Terms and Concepts" />
      <FAI:Topic FAI:title="Motivation" />
      <FAI:Topic FAI:title="Functions" />
      <FAI:Topic FAI:title="Network Based Solutions" />
      <FAI:Topic FAI:title="Detection Technologies" />
      <FAI:Topic FAI:title="Prevention Features" />
      <FAI:Topic FAI:title="IDS/IPS Deployment" />
      <FAI:Topic FAI:title="IDPS Limitations" />
      <FAI:Topic FAI:title="Host Based Solutions" />
      <FAI:Topic FAI:title="Protecting Wireless Networks" />
      <FAI:Topic FAI:title="IDPS Challenges" />
      <FAI:Topic FAI:title="Best Practices" />
      <FAI:Topic FAI:title="Sample Products" />
      <FAI:Topic FAI:title="Lab Exercise: Product Research" />
      <FAI:Topic FAI:title="Quiz" />
    </FAI:SuperTopic>

  </FAI:TopicList>

  <FAI:Appendix FAI:title="Quiz Answers" />
  <FAI:Appendix FAI:title="Acronyms" />
    
</FAI:CourseOutline>

 
