Security Management
In today's business environment, security remains one of the most pressing IT concerns. In this section, candidates will be exposed to industry standard concepts of Enterprise Identity Management, Server Access Management and Web Application Access Management.
Enterprise User Provisioning
- Delegated user administration
- User self-service
- Password management
Enterprise Identity Management
- Integrated workflow
- Structured management model
- Integrated compliance support
- Comprehensive support of target systems
- Open interfaces
- Connector xpress
- Custom agent (connectors) using VC++
Server Access Management
- Role-Based Granular Access Control
- Superuser Containment and Rights Delegation
- Server Intrusion Prevention
- Automated Policy Distribution
- Self Protection Mechanism
- Centralized and Delegated Administration
- Strong Password Management and Policies
- Complete Audit Trail
- Phased Deployment
- Broad Platform Coverage
Web Application Access Management
- Single Sign-On (SSO)
- Strong authentication management
- Centralized, policy-based authorization and audit
- Dynamic authorization
- Enterprise manageability
- Federation security services
- Custom scripting using TCL (for SSO)
Federated Identity & Access
- Federation Use Cases
- Federation Standards
- Security Assertion Markup Language (SAML)
- Liberty Alliance
- Single Sign-On and Federation
- WS-Security
Network Forensics
- Network traffic recording and visualization
- Pattern and content analysis
Forensics knowledge base
- Investigation and reporting
- Enterprise monitoring
- Forensic analysis of correlated events
- Ca network forensics real-time monitoring
Security Information Management
- Centralized Command and Control
- Auditing Engine
- Advanced Event Correlation
- Correlation Across Multiple Software and Hardware Platforms
- Asset-based Event Prioritization
- Advanced Visualization
- Incident Management
- Remediation
- Policy-based Event Notification
- Advanced Reporting
- iRecorders using C, C++
- Custom reports using Crystal Reports
Module Objective:
- Articulate and present the complete security management architecture.
- Perform the tasks of managing audit security
- Generate reports using a centralized utility