1. Testing-Taking Tips and Study Techniques
- Preparation for the SSCP Exam
- Submitting Required Paperwork
- Resources and Study Aids
- Passing the Exam the First Time
2. Security Operations and Administration
- Change Control/Configuration Management
- Dual Control, Separation of Duties, Rotation of Duties
- Vulnerability Assessment and Pen-Testing
3. Access Controls
- AAA
- Authentication Methods (Types 1, 2, & 3)
- Authorization - DAC, RBAC, MAC
- Accounting - Logging, Monitoring, Auditing
- Central/Decentralized and Hybrid Management
- Single Sign-On - Kerberos, Radius, Diameter, TACACS
- Vulnerabilities - Emanations, Impersonation, Rouge Infrastructure, Social Engineering
4. Cryptography
- Intro/History
- Symmetric
- Asymmetric
- Hashing
- Cryptosystems - SSL, S/MIME, PGP
- PKI
- Cryptanalysis
5. Malicious Code and Malware
- Layering, Data Hiding, and Abstraction
- Database Security
- AI
- OOD
- Mobil Code
- Malware Architecture Problems - Covert Channels + TOC/TOU, Object Reuse
- Network Vulnerabilities
6. Networks and Telecommunications
- OSI/DoD TCP/IP Models
- TCP/UDP/ICMP/IP
- Ethernet
- Devices - Routers/Switches/Hubs
- Firewalls
- Wireless
- WAN Technologies - X.25/Frame Relay/PPP/ISDN/DSL/Cable
- Voice - PBX/Cell Phones/VOIP
- IPSec
7. Risk, Response, and Recovery
- CIA
- Roles and Responsibilities - RACI
- Asset Management
- Taxonomy - Information Classification
- Risk Management
- Policies, Procedures, Standards, Guidelines, Baselines
- Knowledge Transfer - Awareness, Training, Education
- BIA Policy
- BIA Roles and Teams
- Data Backups, Vaulting, Journaling, Shadowing
- Alternate Sites
- Emergency Response
- Required notifications
- BIA Tests
8. Analysis and Monitoring
- Ethics - Due Care/Due diligence
- Intellectual Property
- Incident Response
- Forensics
- Evidence
- Laws - HIPAA, GLB, SOX
9. Review and Q&A Session
- Final Review and Test Prep