Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Performing a Technical Security Audit and Assessment

Performing a Technical Security Audit and Assessment

1h 55mIntermediate2024-05-20

Authors

Marc Menninger

Marc Menninger

Cybersecurity Director

Course details

This course follows a proven methodology for conducting thorough and effective technical security audits and assessments based on guidelines from NIST. Learn how to develop the testing methodology essential for technical security reviews. Discover how to identify and analyze targets, use key technical testing tools, identify and mitigate findings, and more. Performing technical information security audits and assessments is essential to protecting information assets. By the end of this course, you'll know how to determine if your network is secure.

Learning objectives
Cite the three phases of external security assessments.
Explain the reasons for conducting a log review.
Explain what network sniffing is and why it’s used.
Describe when to use a file integrity checking tool.
Differentiate between active network discovery and passive network discovery.
Explain how to scan for vulnerabilities.
Relate the three techniques useful for validating target vulnerabilities.
Explain the four-stage methodology of conducting penetration tests.

Skills covered

Governance, Risk, and ComplianceCybersecurityOne-Off

Concepts

0. Introduction

  • 01 - Understanding technical security audits and assessments
  • 02 - What are technical security assessments
  • 03 - Who this course is for

1. Overview of Technical Security Assessments

  • 04 - Develop a technical security assessment methodology
  • 05 - Overview of technical security assessment techniques
  • 06 - Select your testing viewpoint
  • 07 - Challenge - Pick the right technical security assessment
  • 08 - Solution - Pick the right technical security assessment

2. Conduct Technical Security Reviews

  • 09 - Baseline skill sets for security reviews
  • 10 - Conduct documentation reviews
  • 11 - Conduct log reviews
  • 12 - Conduct ruleset reviews
  • 13 - Conduct system configuration reviews
  • 14 - Conduct network sniffing
  • 15 - Network sniffing tool demo - Wireshark
  • 16 - Conduct file integrity checking
  • 17 - File integrity checking tool demo
  • 18 - Challenge - Pick the right reviews
  • 19 - Solution - Pick the right reviews

3. Identify and Analyze Targets

  • 20 - Baseline skill sets target identification and analysis
  • 21 - Conduct network discovery
  • 22 - Network discovery tool demo
  • 23 - Challenge - Install and run Nmap
  • 24 - Solution - Install and run Nmap
  • 25 - Identify network ports and services
  • 26 - Network ports and services discovery tool demo
  • 27 - Scan for vulnerabilities
  • 28 - Vulnerability scanning tool demo
  • 29 - Scan wireless networks

4. Validate Target Vulnerabilities

  • 30 - Baseline skill sets for target vulnerability validation
  • 31 - Crack passwords
  • 32 - Password cracking tool demo
  • 33 - Challenge - Install and run a password cracker
  • 34 - Solution - Install and run a password cracker
  • 35 - Conduct penetration tests
  • 36 - Penetration testing tool demo
  • 37 - Conduct social engineering

5. Planning Technical Security Assessments

  • 38 - Develop a security assessment policy
  • 39 - Prioritize and schedule the assessments
  • 40 - Select and customize techniques
  • 41 - Select the assessors
  • 42 - Select the location
  • 43 - Select tools and resources
  • 44 - Develop the assessment plan
  • 45 - Challenge - Write a security assessment methodology
  • 46 - Solution - Write a security assessment methodology
  • 47 - Legal considerations

6. Executing the Technical Security Assessment

  • 48 - Coordinate the assessment
  • 49 - Conduct the assessment
  • 50 - Conduct the analysis
  • 51 - Challenge - Categorize assessment findings
  • 52 - Solution - Categorize assessment findings
  • 53 - Data handling considerations

7. Post-Testing Activities

  • 54 - Recommend mitigation actions
  • 55 - Challenge - Recommend mitigation actions
  • 56 - Solution - Recommend mitigation actions
  • 57 - Report the results
  • 58 - Implement remediation and mitigation

Conclusion

  • 59 - Begin your testing journey

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal