特價全科證書
Office 辦公室應用

這個頁面上的內容需要較新版本的 Adobe Flash Player。

取得 Adobe Flash Player


想定期知道最新課程及優惠嗎?
免費訂閱本中心的課程通訊!
觀看課程通訊
Reasonable Spread:
Permission email marketing

CISSP 國際認可證書課程
(教授新 Syllabus)

  • 課程時間
  • 課程簡介
  • 課程特點
  • 考試須知
  • 課程內容

傳統服務:課程上堂時間表
編號 日期 (dd/mm) 星期 時間 課時 地點 費用 導師  
PS0870EM  05/08 - 02/09
5/8, 12/8, 19/8, 26/8, 2/9
 下載詳細上課日期
2:30pm - 9:30pm (dinner: 5:30pm-6:30pm) 30 旺角 $2,980 Franco 按此報名

*** 質素保證:免費於任何地點試睇首 3 小時課堂錄影,從而可預先了解導師及教材的質素,才報讀課程來上堂。***
請致電與本中心職員預約。 查看各地點電話
旺角 2332-6544
觀塘 3563-8425
北角 3580-1893
沙田 2151-9360
元朗 3523-1560
溫哥華 604-2845638

免費補堂: 學員可於另一班課堂補上或於任何地點補看課堂錄影,從而可銜接往後的課堂!
免費重讀: 學員可於自課程結束後三個月內於另一班課堂重上或於任何地點不限次數地重看課堂錄影,從而可反覆重溫整個課程!


推介服務:課堂錄影隨時睇
編號 地點 可預約星期及時間 學費低至 8 折  
PS1206MV 旺角 一至五:10:30 - 22:30   六及日:10:30 - 21:30
公眾假期:11:00 - 19:00
$2,980 9 折後只需 $2,682 按此報名
PS1206OV 觀塘 一至日:12:30 - 22:00 (星期三及公眾假期休息) $2,980 8 折後只需 $2,384 按此報名
PS1206PV 北角 一至日:12:30 - 22:00 (星期三及公眾假期休息) $2,980 8 折後只需 $2,384 按此報名
PS1206SV 沙田 一至日:12:30 - 22:00 (星期三及公眾假期休息) $2,980 8 折後只需 $2,384 按此報名
PS1206YV 元朗 一至日:12:30 - 22:00 (星期三及公眾假期休息) $2,980 8 折後只需 $2,384 按此報名
PS1206VV 溫哥華 按此顯示溫哥華每天辦公時間
Mon09:30 - 19:00
Tue14:00 - 21:00
Wed休息
Thu09:30 - 19:00
Fri14:00 - 21:00
Sat10:30 - 19:00
Sun10:30 - 19:00
公眾假期休息
CD$373 8 折後只需 CD$298 按此報名

免費試睇: 首 3 小時,請致電與本中心職員預約。 查看各地點電話
旺角 2332-6544
觀塘 3563-8425
北角 3580-1893
沙田 2151-9360
元朗 3523-1560
溫哥華 604-2845638
免費重睇: 學員可於享用時期內於報讀地點不限次數地重看課堂錄影,從而可反覆重溫整個課程!
導師解答: 學員可於觀看某一課堂錄影後提出相關的問題,課程導師會樂意為學員以單對單的形式解答!
課時: 30 小時
享用時期: 報讀日至 10 星期內,進度由您控制,可快可慢。
課堂錄影導師: Franco
課堂錄影隨時睇: 詳情及示範片段



近年系統和網絡技術發展一日千里,大家開發解決方案 ( Solution ) 或處理電子資訊時除需要考慮功能外,更須注意資訊保安。一旦出現資訊安全事故 ( 例如客戶資料外洩 ),商譽或金錢上的損失均無法想像。故此資訊保安已成為 I.T. 界的 "必修科",僱主聘用 I.T. 同事時亦要求具備資訊保安知識及相關認證,例如 CISSP (Certified Information Systems Security Professional) 。

CISSP 證書制度是由 International Information Systems Security Certification Consortium ( 簡稱 ISC2 ) 建立,CISSP 是一張中立 ( Vendor Neutral) 的認證,當中所涉及的知識不限制於個別器材軟件生產商 (Vendor)。故此 CISSP 的知識應用層面十分廣泛。CISSP 的考試內容主要圍繞下列 10 個 CBK (Common Body of Knowledge)

  • Information Security Governance and Risk Management
  • Access Control
  • Cryptography
  • Physical (Environmental) Security
  • Security Architecture and Design
  • Business Continuity and Disaster Recovery Planning
  • Telecommunications and Network Security
  • Software Development Security
  • Operations Security
  • Legal, Regulations, Investigations and Compliance



CISSP

若要考取 CISSP,同學須要

  1. 具備 5 年資訊保安相關的工作經驗。如具備大學學位,則須要4年資訊保安相關的工作經驗
  2. 通過 CISSP 考試 (我們備有大量練習令學員更易通過考試)
  3. 通過 Endorsement 過程
    (本中心的 CISSP 學員可向本中心免費申請 Endorsement 的協助,而本中心會按照 ISC2 指引來免費提供 Endorsement 服務。)
  4. 通過 ISC2 的審核

備註:申請者如未具有足夠的工作經驗,依然可以參加 CISSP,考試後成為 Assoicate of ISC2,當累積足夠的工作經驗時,便可以申請成為 CISSP。



課程費用: HK$2,980
課程時數: 合共 30 小時 (共 10 堂)
適合人仕: 對資訊保安有興趣的人仕
授課語言: 以廣東話為主,輔以英語
課程筆記: 本中心導師親自編寫英中對照筆記


1. Franco Tsang 親自教授: 本課程由擁有 CISSP, CCIE, RHCE, MCITP 實力經驗俱備的 Franco Tsang 親自教授。
2. Franco 親自編寫筆記: Franco 親自編寫英中對照筆記,令你無須「死鋤」如字典般厚及不適合香港讀書格調的書本。
3. 理論與實習並重: Franco 會在課堂上作出大量示範,務求令同學理解抽象的資訊保安概念,以及如何將 CISSP 的知識應用在日常工作上。我們亦有大量練習令學員更易通過考試。
4. 免費重讀: 學員可於自課程結束後三個月內免費重讀本課程。


ISC2 會定期在香港舉行 CISSP 考試,通常每兩個月舉行一次。

如要報名參加考試,可到 ISC2 的網站註冊帳戶並以信用卡繳付考試費。CISSP 的考試費用為599美元。如果在考試前 16 天報名及繳款,可以 Early Bird Price 549 美元參加考試。

CISSP 考試共有 250 條多項選擇題,當中有 25 條題目用作研究,不會計分,考生不能分辨題目是否用作研究,故此所有題目須全力作答。考試 1000 分滿,合格分數為 700 分。考試後 4-6 星期 ISC2 會以電郵通知考試成績。

考試合格後,下一步便是通過 Endorsement。考生須得到另一名 ISC2 Certified 的人士推薦,並為考生簽署 Endorsement Form。

本中心的 CISSP 學員可向本中心免費申請 Endorsement 的協助,而本中心會按照 ISC2 指引來免費提供 Endorsement 服務。

最後,ISC2 會隨機抽樣為考生所提供的文件進行 Audit. 通過 Audit 後便可成為 CISSP。

Recently, the following Systematic CISSP course students applied for our help and we endorsed them successfully (including 2009-syllabus and 2012-syllabus examinations):

  • Alan Cheung
  • Alan Kwong
  • Alfred Chan
  • Antony Chan
  • Ben Wong
  • Charlaes Ho
  • Chris Ngai
  • Cody Wong
  • David Leung
  • Derek Au
  • Eddie Ho
  • Edmond Chan
  • Eric Wong
  • Eric Wu
  • H. Y. Lin
  • Ivan Chow
  • J. Chan
  • Joseph Lau
  • Justin Mok
  • K. S. Li
  • K.W. Tse
  • Kelvin Tse
  • Kene Lai
  • Kenneth Shum
  • Maverick Wong
  • P. Yau
  • Paul Wong
  • Roy Fong
  • Roy Yiu
  • Sammy Leung
  • Samson Tai
  • Simon Leung
  • Simon Yu
  • Stephanie Chan
  • Steve Wong
  • Steven Tsoi
  • Tony Lo
  • Tony Wong
  • V. Tang
  • Vincent Chan
  • X. Yao
  • Y. K. Kong
  • Zero Ho

Congratulations to them!!





Chapter 1: Access Controls
1.1 Introduction of Access Controls
1.2 Access Control Policy
1.3 Threats of Access Controls
1.4 Access to System
1.5 Access to Data
1.6 Access Control Monitoring
1.7 Types of Controls
1.8 Access Control Assurance
1.9 Conclusion

Chapter 2: Information Security Governance and Risk Management
2.1 Introduction
2.2 Security Management
2.3 Security Management Responsibilities
2.4 Top-Down Approach VS Bottom-Up Approach
2.5 Security Administration and Supporting Control
2.6 Definitions for security terms
2.7 Security through Obscurity
2.8 Security Frameworks
2.9 Job Controls
2.10 Roles and Responsibility
2.11 Reporting Model
2.12 Security Policies, Procedures, Standards and Baselines
2.13 Security Planning
2.14 Personal Security
2.15 Security Awareness Training
2.16 Risk Assessment (Risk Analysis)
2.17 Qualitative Risk Analysis
2.18 Quantitative Risk Analysis
2.19 Risk Handling
2.20 Ethics Code of Conduct
2.21 ISC2 Code of Ethics
2.22 Common Computer Ethics Fallacies

Chapter 3: Cryptography
3.1 Definitation
3.2 Two methods of Cryptography
3.3 Classic Cryptography
3.4 One-Time Pad (OTP)
3.5 Symmetric Cipher
3.6 DES (Data Encryption Stanard)
3.7 Double DES
3.8 Triple DES
3.9 AES (Advanced Encryption Standard)
3.10 IDEA (International Data Encryption Algorithm)
3.11 RC4
3.12 RC5 and RC6
3.13 Blowfish
3.14 Asymmetric algorithms
3.15 RSA
3.16 Diffie-Hellmann Algorithm
3.17 El Gamal
3.18 Elliptic Curve Cryptography (ECC)
3.19 Hybrid Cryptography
3.20 Message Integrity Control
3.21 Checksum
3.22 Hash Function
3.23 MD5 (Message Digest Algorithm)
3.24 SHA / SHA-1 (Secure Hash Algorithm)
3.25 MAC (Message Authentication Code)
3.26 Hashed MAC (HMAC)
3.27 Digital Signature
3.28 Digital Signature Standard (DSS)
3.29 Digital Certificates
3.30 Certificate Authority (CA)
3.31 Public Key Infrastructure (PKI)
3.32 Link Encryption and End-to-End Encryption
3.33 Cryptanalysis and Attacks
3.34 PGP (Pretty Good Privacy)
3.35 S/MINE (Secure/Multipurpose Internet Mail Extension)

Chapter 4: Physical (Environmental) Security
4.1 Introduction to Physical (Environmental) Security
4.2 Goal of Physical Security
4.3 The most important concern
4.4 Threats to Physical Security
4.5 CPTED (Crime Prevention Through Environment Design)
4.6 Site Location and Selection
4.7 Entry Points
4.8 Physical Infrastructure System
4.9 Layered Defense Model
4.10 Computer Equipment and Object Protection
4.11 Conclusion of Physical (Environmental) Security

Chapter 5: Secure Architecture and Design
5.1 Common Computer Architecture
5.2 CPU (Central Processing Unit)
5.3 Memory Management
5.4 TCB (Trust Computer Base)
5.5 Reference Monitor
5.6 Computer Architecture Protection Concepts
5.7 Security Models
5.8 State Machine Model
5.9 Lattice Model
5.10 The Bell-LaPadula Model
5.11 Biba Model
5.12 The Clark-Wilson Model
5.13 The Information Flow Model
5.14 Covert Channels
5.15 Overt Channels
5.16 The Noninterference Model
5.17 The Brewer and Nash Model (Chinese Wall Model)
5.18 The Graham-Denning Model
5.19 The Harrison-Ruzzo-Ulman Model
5.20 Security Architecture Assurance Mechanisms
5.21 The Orange Book (TCSEC)
5.22 ITSEC (Information Technology Security Evaluation Criteria)
5.23 Common Criteria
5.24 Certification and Accreditation
5.25 Certification
5.26 Accreditation

Chapter 6: Business Continuity and Disaster Recover Planning
6.1 What is Disaster Recovery
6.2 What is Business Continuity
6.3 The definition of Disaster
6.4 Types of disasters
6.5 BCP Phases
6.6 BCP Phases proposed by ISC2
6.7 BCP Phase 1: Project Initiation
6.8 BCP Phase 2: BIA
6.9 BCP Phase 3: Continuity / Recovery Strategy
6.10 BCP Phase 4: Detail Plan Design and Development
6.11 BCP Phase 5: Testing and Maintenance
6.12 BCP Testing
6.13 General Practices for Testing
6.14 Plan Maintenance
6.15 Recovery Process
6.16 Conclusion of this chapter

Chapter 7: Telecommunication and Network Security
7.1 OSI Reference Model
7.2 TCP
7.3 UDP
7.4 Port
7.5 IP
7.6 Network Topology
7.7 Transmission Method
7.8 Cabling
7.9 LAN Protocol - ARP
7.10 LAN Protocol – DHCP
7.11 LAN Protocol - ICMP
7.12 Basic Routing Concepts
7.13 Routing Protocols
7.14 Networking Equipment – Routers
7.15 Networking Equipment – Switches
7.16 Firewall
7.17 Network Services and Protocol
7.18 Remote Access
7.19 VPN
7.20 SSH
7.21 Wireless Technology
7.22 Wireless Application Protocol

Chapter 8: Software Development Security
8.1 Today’s Software Environment
8.2 Programming Language
8.3 Programming elements and procedures (Using Java)
8.4 Threats in the Software Environment
8.5 Application Development Security Protections and Controls
8.6 Software Development Methods
8.7 Object-Oriented Technology and Programming
8.8 Data Structure
8.9 Distributed Object-Oriented Systems
8.10 Malicious Software (Malware)
8.11 Database Management System (DBMS)
8.12 DBMS Model
8.13 Database Interface Languages
8.14 Data Warehouse
8.15 Metadata
8.16 DBMS Controls
8.17 SET Protocol

Chapter 9: Operations Security
9.1 Introduction to Operations Security
9.2 The role of operations department
9.3 Operations Staff
9.4 Threats to Operations
9.5 Types of Control in Operations Security
9.6 Administrative Management in Operations Security
9.7 Media Types and Protection Methods
9.8 Trusted Recovery / System Recovery
9.9 Common Jargons in Operations
9.10 Configuration Management
9.11 Patch Management

Chapter 10: Legal, Regulations, Investigations and Compliance
10.1 Today’s Information Security Environment
10.2 Information Security and Computer Crime
10.3 Major Legal Systems Worldwide
10.4 Intellectual Property Laws
10.5 Privacy Protection
10.6 Due care and Due diligence
10.7 Computer Forensics
10.8 Rules of Evidence
10.9 Chain of Custody
10.10 Computer Evidence
10.11 Incidence Response
10.12 Goals of Incidence Response
10.13 Various attack types
10.14 Processes of the incident response
10.15 Successful factors in incident response
10.16 Interviewing and Interrogation
10.17 Conclusion of Legal, Regulations, Compliance and Investigation


 

更多綜合課程
  法律課程
  • 代理人的法律責任
  • 公司董事和合夥人的法律責任
  • 婚姻的法律責任
  • 遺產繼承的合法權益
  英文課程
  • 商業寫作:級別 1 2 3 4
 
• 英文文法: 起步級別 (免費)
級別 1 2 3
級別 4 5 6
深造 1 2 3
  • IPA 拼音:級別 1 2 3 4
  普通話課程
  • 基礎普通話拼音課程 (免費)
  • 進階普通話拼音課程
  • 普通話會話:級別 1 2 3
  西班牙語文課程
  • 級別 1 2 3
  中醫課程
  • 濕疹與皮膚敏感病
  • 暗瘡與色斑 | 鼻敏感與感冒
  • 脫髮與白髮 | 從五官看健康
  攝影課程
  • 攝影初級
  • 攝影中級 (風景專題)
  • 戶外實景攝影實習
  風水命理課程
  • 2012家居風水擺設 (免費)
  • 紫微斗數:級別 1 2 3
  • 子平八字:級別 1 2 3
  • 八字風水:級別 1 2 3
  • 奇門遁甲:級別 1 2 3

這個頁面上的內容需要較新版本的 Adobe Flash Player。

取得 Adobe Flash Player