Courses

Courses

318 - Systems Security Policies: Capturing IT Security Requirements (1 day)

Course Description
Outline
Audience
Course Level
Prerequisite(s)
Special Notes(s)
Additional Readings/URLs
Date(s)
Fee

Course Description

Unless functional security requirements are translated into realistic technical specifications, the final solution may be overly restrictive and expensive or, worse still, seriously insecure. To help achieve the necessary balance, this course demonstrates how to interpret and extend the Government Security Policy (GSP) and other related policies to system specific requirements, both functional and technical, as part of a system development life cycle.

Top of Page | Haut de la page
Outline
  • Understand the Government Security Policy and related policies
  • Establish system specific security policies regarding:
    • acceptable use
    • access and privilege controls
    • asset sharing
    • configuration management and change control
    • confidentiality, integrity, availability and privacy
    • the use of related technologies, such as wireless devices
Top of Page | Haut de la page
Audience
Project managers, system architects, system (security) administrators and IT security professionals.
Top of Page | Haut de la page
Course Level
Intermediate

Recommended preparation: Course S50 - Certification and Accreditation (C&A;): Achieving Confidence and Accountability, or equivalent

Top of Page | Haut de la page
Prerequisite(s)
None
Top of Page | Haut de la page
Special Note(s)
None
Top of Page | Haut de la page
Additional Readings/Instructor-suggested URLs
Communications Security Establishment
Canadian Handbook on Information Technology Security (MG-9)
http://www.cse-cst.gc.ca/publications/gov-pubs/itsg/mg9-e.html

Threat and Risk Assessment Working Guide (ITSG-04)
http://www.cse-cst.gc.ca/publications/gov-pubs/itsg/itsg04-e.html

SANS Security Policy Project
To view the Security Policy Project, please follow the indicated steps:
  • Click on the hyperlink above.
  • Scroll down to "SANS: Training, Certification and Research" and double-click.
  • Once at the SANS homepage, click on the tab "Sample Policies", located on the red menu.
Top of Page | Haut de la page
Date(s) (E) = English (F) = French  
February 14, 2006 (E)
March 2, 2006 (F)
Top of Page | Haut de la page
Fee
$450 - GoC      $550 - Non-GoC
Top of Page | Haut de la page