Course Outline
Foundational Principles, Social Engineering Mitigation, and Operational Environment
Module 1: Core Cybersecurity Competencies for Public Sector Personnel
-
Overview of Threats: Defining cybersecurity frameworks and the critical role of individual accountability in organizational security.
-
Digital Hygiene and Credential Management: Establishing robust password protocols, utilizing centralized password management tools, and enforcing unique credential requirements for distinct services.
-
Physical Security Protocols: Implementing clear desk and clear screen policies to safeguard sensitive information within operational facilities.
Module 2: Phishing and Social Engineering Threat Intelligence
-
Psychological Analysis of Attacks: Understanding social engineering tactics, including the exploitation of urgency, fear, and authority (e.g., Business Email Compromise).
-
Phishing Mechanics: Techniques for analyzing message headers, validating hidden links, and detecting malicious attachments through practical exercises based on real-world examples.
-
Advanced Attack Vectors: Identifying and mitigating risks associated with voice phishing (vishing) and SMS phishing (smishing).
Module 3: Secure Remote and Mobile Operations
-
Network Security Standards: Evaluating the risks of public Wi-Fi infrastructure and implementing Virtual Private Network (VPN) protocols for secure remote access.
-
Device Integrity Measures: Enforcing disk encryption, screen locking mechanisms, and protocols for handling unverified external storage devices.
-
Bring Your Own Device (BYOD) Governance: Establishing policies for the secure use of personal devices for official business, including strict data separation requirements.
Technical Tools, Regulatory Compliance, and Incident Response
Module 4: Security Architecture in the Microsoft 365 Ecosystem
-
Authentication and Verification: Implementing Multi-Factor Authentication (MFA/2FA) to enhance account access controls.
-
Secure Data Distribution: Managing access permissions in OneDrive and SharePoint to prevent unauthorized broad access (e.g., restricting "anyone with the link" settings).
-
Secure Collaboration: Protocols for using Microsoft Teams securely, including management of external guests and control over shared file visibility.
Module 5: Data Privacy, Regulatory Compliance, and Practical Application
-
Information Classification: Differentiating between public, confidential, sensitive, and personally identifiable information.
-
Regulatory Compliance in Operations: Preventing common data breaches (e.g., erroneous recipients, improper use of BCC) in accordance with privacy regulations such as GDPR.
-
Data Lifecycle Management: Protocols for securely transferring information to authorized third parties and ensuring the complete and secure destruction of documents.
Module 6: Security Incident Detection and Response
-
Incident Recognition: Identifying indicators of compromise, including lost devices, ransomware infections, and phishing link engagement.
-
Reporting Protocols: Defining escalation paths and timeframes for notification to IT Helpdesk, Security Officers, and Data Protection Officers.
-
Immediate Response Actions: Isolating affected devices from the network, maintaining operational calm, and prohibiting unauthorized remediation or evidence alteration.
Requirements
-
Familiarity with basic computer operations and web browser usage.
-
Routine interaction with standard office environments, including email, messaging applications, and document processing tools.
-
No specialized IT expertise is required; all technical concepts are presented in the context of operational value and daily processes.
Intended Audience
- All administrative and office staff, as well as mid-level management, across all departments.
- Hybrid or fully remote workers, for whom this training is particularly recommended.
- Users of the Microsoft 365 ecosystem.
Testimonials (3)
Experience sharing, it's teacher's know-how and valuable.
Carey Fan - Logitech
Course - C/C++ Secure Coding
get to understand more about the product and some key differences between RHDS and open source OpenLDAP.
Jackie Xie - Westpac Banking Corporation
Course - 389 Directory Server for Administrators
the knowledge of the trainer was very high - he knew what he was talking about, and knew the answers to our questions