Zoom Outline PDF View  or  Email Back to Schedule for Vermont


Microsoft Windows Security




SUMMARY:   This course is designed for Administrators and others who have a need to address security issues on their corporate networks. It will be assumed that attendees are familiar with Windows Server Administration and Network administration and Configuration.

DURATION:   5 Days

OBJECTIVES:  

  • Principles of Security
  • Securing Active Directory
  • Securing the Core Operating System
  • Securing Common Services
  • Managing Security Updates
  • Security Assessments and Incident Responses
  • Key Principles of Privacy

COURSE CONTENT:  
  1. Key Principles of Security
    • Risk Management
    • Risk Management Strategies
    • Accepting Risk
    • 10 Laws of Security Administration
  2. Understand the Enemy
    • Assess Own Skills Accurately
    • Detailed Network Documentation
    • Identify the Attacker
    • Levels of Trust
    • Attackers Have Unlimited Resources
  3. User Accounts and Passwords
    • Account Security Options
    • RunAs Service
    • Password Security and Complexity
    • Rights and Permissions Using Groups
    • AD, File, and Registry Permissions
    • Built-In Domain Groups
    • Universal Groups
    • NTLM
    • Kerberos
    • DPAPI
  4. Active Directory Objects and Attributes
    • Active Directory Schema
  5. Group Policy
    • Group Policy
    • Computer-Related Group Policies
    • Preferences vs. Policies
    • User-Related Group Policies
    • Group Policy Containers
    • Block Inheritance
  6. Active Directory Forest and Domains Design
    • Autonomy and Isolation
    • Enterprise Administration Boundaries
    • Physical Security of Domain Controllers
    • Designing DNS for AD Security
    • Single Namespace
    • Designing Authority Delegation
  7. Permissions
    • File and Folder Permissions
    • Assigning DACLs
    • Encrypting File System
    • Securing Registry Permissions
  8. Securing Services
    • Managing Service Permissions
    • Configuring the DACL for a Service
  9. TCP/IP Security
    • Securing TCP/IP
    • Denial of Service
    • Configuring Registry Settings
    • TCP/IP Filtering
    • IPSec
    • ESP
    • Kerberos Authentication
    • X.509 Certificates
    • IPSec Monitoring
  10. Internet Explorer 6 and Office XP
    • Security Settings in IE 6
    • Security Zones
    • ActiveX Controls and Plug-Ins
    • Microsoft VM Options
    • Security Settings in Office XP
  11. Security Templates
    • Security Template Settings
    • Account Policies
    • Local Policies
    • IP Security Policies
    • Security Templates Using Group Policy
  12. Auditing Security Events
    • Determining Events to Audit
    • Audit Policies
    • Monitoring Audited Events
  13. Mobile Computer Security
    • Mobile Computers
    • Security Updates
    • Hardware Protection
    • Boot Protection
    • Data Protection
    • Wireless Networking in Windows XP
  14. Security for Domain Controllers
    • Domain Controller Threats
    • Security on Domain Controllers
    • Physical Security
    • Security Settings by Using Group Policy
    • Protecting Against Domain Controller
    • Failure
    • Auditing
    • Active Directory Communication
    • IPSec Encryption
  15. Security for DNS Servers
    • Threats to DNS Servers
    • Denial-of-Service Attacks on DNS Services
    • Restricting DNS Traffic at the Firewall
  16. Security for Terminal Services
    • Threats to Terminal Services
    • Securing Terminal Services
    • Strengthening Security Configuration of Terminal Server
  17. Security for DHCP Servers
    • Threats to DHCP Servers
    • Securing DHCP Servers
  18. Security for WINS Servers
    • Threats to WINS Servers
    • Securing WINS Servers
  19. Security for Routing and Remote Access
    • Remote Access Solution Components
    • VPN Protocols
    • Threats to Remote Access Solutions
    • Securing Remote Access Servers
    • Securing Remote Access Clients
  20. Security for Certificate Services
    • Threats to Certificate Services
    • Securing Certificate Services
  21. Security for IIS 5.0
    • Implementing Windows 2000 Security
    • Configuring IIS Security
    • Tools to Secure IIS
    • Configuring the FTP Service
  22. Patch Management
    • Types of Patch
    • Development of a Hotfix
    • Windows Update
    • Installing Service Packs
  23. Patch Management Tools
    • Security Patch Bulletin Catalogue
    • Windows Update
    • Automatic Updates
    • Baseline Security Analyser
  24. Security Assessment Tools
    • Assessing Security Configuration
    • Performing Security Assessments
  25. Network Security Assessment
    • Types of Security Assessment
    • Penetration Testing
    • IT Security Audit
    • Conducting Security Assessments
    • Conducting Penetration Tests
  26. Incident Response Planning
    • Creating an Incident Response Team
    • Security Reporting Policy
    • Creating a Communication Plan
  27. Security Incident Response
    • Common Indicators of Security Incidents
    • Analysing a Security Incident
    • Security Investigations
    • Network Monitoring
  28. Importance of Privacy
    • Privacy Definition
    • Formulating an Enterprise Privacy Strategy
  29. Privacy for the Corporate Web Site
    • Defining a Privacy Statement
    • Internet Explorer 6 Privacy Settings
  30. Privacy in the Enterprise
    • Selecting Applications Based Privacy
    • Protecting Employees Privacy
    • Protecting Customers and Business Partners Privacy
JS/03

© 2007 Verhoef Training, Inc.

Schedule Dates

Course offered as
Inhouse or Public


There are no classes scheduled for this subject at this time.

Send us a request for this class

or

contact your account manager for scheduling information.

Contact Us


Copyright © 2007 - Verhoef Group of Companies - All Rights Reserved