home     about     workbooks     subscribe    

Workbook 1 : E-Commerce Security


LEARN HOW TO:

  • Develop a security policy to protect your organisation's system and data
  • Analyse your exposure to security threats from outside and inside your organisation
  • Manage the additional risks to your organisation via the Internet
  • Protect users from hostile applications and viruses
  • Reduce vulnerabilities by deploying firewalls and using modern cryptology and authentication systems

WORKBOOK BENEFITS:

Modern networks allow companies to internationalise their activities without the classic heavy investment and slow return on investment. The rewards for successfully using modern technology are high yet the risks from casual and organised crime are alarming. This course draws together the advantages, risks and necessary security countermeasures to exploit the fastest growing medium in man's history.

You will be equipped with a thorough understanding of the vulnerabilities and threats encountered with, intranets, extranets, enterprise and local area networks and Internet, and simultaneously provide a down-to-earth exploration of security solutions. With this grounding in computer security principles delegates will be able to analyse the risks to their own systems and implement a workable security policy that will protect information assets from potential intrusion, damage or theft..

WHO SHOULD USE THIS WORKBOOK:

This workbook is intended for those who require skills to evaluate existing security, define security policy and implement effective countermeasures to protect their organisations systems from attack, including IT Managers, Network and Systems Administrators, Systems Security Managers, Consultants and Auditors

order today

Modules:

1. DATABASES

  • Server databases
  • Commercial databases
  • Database vulnerabilities
    • Secure databases
    • Implementation of security mechanisms
  • Data ownership
  • Database classification
  • Clearances
  • Subjects and objects
  • Authorisation rules
  • Database Management Systems
    • Security of DBMS
  • Database Access
  • Automated tools for intrusion detection
  • Evaluation of IDS systems

2. E-COMMERCE STRATEGY
  • Benefits of e-commerce
  • Currently succesful Internet businesses
  • Defining markets
  • E-Government
  • Data mining and e-commerce
  • Organisational response
  • Initial client service
  • Call centre
  • Web site policy
  • Data Warehousing and mining
    • Data Warehouses
    • Multi-dimensional databases
    • Metadata
    • Graphical user interfaces
  • Data warehouse architecture
    • Operational data store
    • Two tier and multi-tier
    • Middleware
  • Data mining and e-commerce
  • Knowledge discovery
  • Data extraction and security
3. E COMMERCE ATTACKS AND THE ATTACKERS
  • Threats to e-commerce
  • Vandalism and sabotage
  • Breaches of privacy and confidentiality
  • Fraud and theft
  • Violations of data integrity
  • Denial of service
  • Organised crime
  • Hackers
    • Packet sniffers
  • Eavesdropping
4. PERSONNEL SECURITY
  • Levels of clearance
  • Screening backgrounds
    • Negative screening
    • Positive screening
    • Standards of living
  • Security issues
  • Systems security manager
  • Responsible persons
5. PROGRAMMING PRACTICES
  • The need for programming controls
  • Waterfall method
  • Libraries
  • Development tools
  • E-commerce and Web software
  • Dangerous CGI scripts
  • Mitigating the danger
  • Stripping input to CGI
  • CGI and Windows
  • Guarding against CGI exploits
  • Server side scripts
  • Client side scripts
  • Applets
  • Security concerns with Java and ActiveX
    • ActiveX containers
    • ActiveX scripting
    • Authenticode
    • Sandbox
  • Manipulating trust
  • Flawed software
  • Bytecode verifier
  • Applet Class loader
  • Applets
6. CRYPTOGRAPHY THE E-COMMERCE CORNERSTONE
  • Rotor systems and crypt
  • DES
  • Triple DES
  • Public Key
  • Clipper
  • PGP
  • SSL
  • Long key length SSL
  • S-HTTP
  • DSS
  • Encryption keys
  • E-mail and PGP
  • Key management and distribution
  • Authentication
  • Certificates
  • Limitations of cryptology
7. SECURITY OF E-COMMERCE
  • E-commerce and electronic transmission
  • Secure Electronic transaction
  • CyberCash
  • DigiCash
  • First Virtual
  • NetBill
  • NetCash
  • NetCheque
  • E-cash
  • Stored value payment systems
  • How e-cash works
  • Securing e-cash
  • Representing e-cash
  • DigiCash
  • CAFÉ
  • CyberCoin
8. SECURITY OF THE COMPUTER ENVIRONMENT
  • E-commerce availability
  • Biometrics
  • Availability
  • Curtilage security
  • Terrorist attacks
  • Costs of disasters
  • Designing a security scheme
9 INSURANCE AND RISK MANGEMENT
  • Consequential loss
  • Recreation costs
  • Insurance level assessment
  • Levels of disaster costing
  • Extra cost of working example
  • Insurance considerations
  • Computer security risk management
  • Asset evaluation
  • Vulnerabilty analysis
  • Threat identification
  • Frequency
  • Loss expectancy
  • Selection of countermeasures
  • Actuarial frequencies
  • Example
  • Risk analysis and management methods
10. ACCESS CONTROLS, AUTHENTICATION AND ACCOUNTABILITY
  • Privilege and child/parent process
  • High risk options
  • Access to sensitive areas
  • Client host name and IP address restrictions
  • User and password authentication
  • Passwords and Unix
  • Passwords and NT
  • Authentication on Webs
  • Kerberos
  • Digital signatures
  • Security axioms
11. BASTION HOSTS
  • Situation of bastion hosts
    • Screening routers
    • DNS
    • Protocols with fixed addresses
    • Filter replacement
    • Application level gateways
    • Circuit level gateways
  • Firewalls
  • Protection from hackers
    • Address space probes
    • ICMP monitoring
    • Log based tolls
    • Dummy accounts
  • Tracing connections
  • Recovery of UNIX and NT
    • Consultation
  • Regain control
    • Document recovery steps
  • Analyse the intrusion
12. INTRANET SECURITY
  • Requirements
  • Firewalls
  • Internal threats
  • IPSec
  • Illegal access throuh pole vaulting
  • Vandalism
    • Viruses
    • Worms
    • Recognising common viruses
    • Macro viruses
  • Anti virus products
13. WORLD WIDE WEB
  • Web Threats
  • Browser security
  • Access restrictions on domain name
  • Access control
  • The server
    • Web server features
    • Server authentication
    • Deadly Web server configuration
    • Flaws
  • CGI Scripts
  • Authentication
  • Integrity
14. EXTRANET SECURITY
  • Partners
  • E-business partners and collaborative software
  • B2B
  • E-collaboration
  • Software to support e-collaboration
    • XML
    • Equos
  • Extranet security
  • Confidentiality
  • VPN
  • SSL
  • Authentication and non-repudiation
  • Certificates
  • Integrity
  • Access controls
  • Middlenet
  • Availability
  • VPN products
15. SECURITY STRATEGY
  • Overview
    • Site security policy
    • Approach to security policy
  • Strategy framework
  • Use of DOD standard

 


Webmaster