資訊安全已成為科技行業中最關鍵的領域之一。隨著數據洪流和網絡威脅不斷演進,掌握資訊安全的專業知識與技能,變得比以往任何時候都來得重要。
為了讓您能在此專業領域脫穎而出,我們特別推出了本課程。本課程由深具經驗的專家精心設計,目的是為了確保學員能夠獲得全面而堅實的資訊安全基礎知識,並成功考取專業認證資格。課程內容緊貼 ISC2 於 2026 年 9 月 1 日生效之最新考試大綱,涵蓋資訊安全原則、管治、風險及合規 (GRC)、身份及存取管理 (IAM)、網絡與雲端安全、事故回應及 AI 基礎概念等全部範圍。
無論您是 IT 專業人員、期望轉換跑道進入資訊安全領域的職場人士、或是大學在學學生及應屆畢業生,本課程都將是您理想的選擇。CC 是國際認可的入門級網絡安全認證,無須任何工作經驗或學歷要求,考試更可選擇中文應考,特別適合首次接觸資訊安全的人士。透過本課程,您不僅能開啟資訊安全領域的職業生涯,亦同時為未來的進階認證如 SSCP、CISSP 奠定堅實的基礎。
中心的 CC (Certified in Cybersecurity) 國際認可證書課程由 Franco Tsang 籌備多時,精心編排,全課程共 10 堂 30 小時。由上堂、溫習、實戰練習、模擬試題到應考策略,均為你度身訂造,作出有系統的編排。務求真正教識你,又令你考試及格。
| 課程名稱: |
CC - Certified in Cybersecurity 國際認可證書課程 - 簡稱:Cybersecurity Training Course |
| 課程時數: | 合共 30 小時 (共 10 堂) |
| 適合人士: | 任何人士,無須經驗。 |
| 授課語言: | 以廣東話為主,輔以英語 |
| 課程筆記: | 本中心導師親自編寫英文為主筆記,而部份英文字附有中文對照。 |
| 1. Franco Tsang (CCIE #19772) 親自教授: | 本課程由擁有 Triple CCIE, CISA, CISM, CRISC, CDPSE, CISSP, ITILv3 Expert, ITIL 4 Managing Professional, ITIL 4 Strategic Leader, PMP 等專業認證的 Franco Tsang 親自教授。 |
| 2. Franco Tsang 親自編寫筆記: | Franco 親自編寫筆記,令你無須「死鋤」如字典般厚及不適合香港讀書格調的書本。 |
| 3. 提供模擬考試題目: | 本中心為學員提供充足的模擬考試題目,每條考試題目均附有標準答案。而較難理解的題目,均會附有 Franco 的解釋。 |
| 4. 深入淺出: | Franco 會在課堂上深入淺出地講解相關概念,務求令同學理解抽象的管理概念。 |
| 5. 免費重讀: | 傳統課堂學員可於課程結束後三個月內免費重看課堂錄影。 |
首先自行前往 ISC2 網站建立 ISC2 Account 並以該 ISC2 Account 登入,登入後依從該網站指示完善您的個人資料 (如姓名、電話號碼及電郵地址等等)。 重要:您必須按照在考試中心出示的身份證上的資料來填寫您的資料。如果不完全匹配,您將無法參加考試,且不會獲退還任何費用。 提交 ISC2 的網上電子表格後,您將被重定向到 Pearson VUE 網站,在那�堭z將能夠安排在本中心考試及繳付 US$199 之考試費。 考試當日到達本中心時必須出示下列兩項有效之身份證明文件,否則考生不可進行考試,而已繳付之考試費亦不會退回:
考試題目由考試中心傳送到你要應考的電腦,考試時以電腦作答,並採用電腦自適應 (CAT) 模式。考試題目格式為 100 至 125 條題目,題型包括多項選擇題及進階題型 (Advanced Item Types),考試時間為 2 小時。合格分數為 700 out of 1000 points。考試語言可選擇英語、中文(簡體)、日語、德語或西班牙語。 |
| 課程名稱:CC - Certified in Cybersecurity 國際認可證書課程 - 簡稱:Cybersecurity Training Course |
Domain 1: Security Principles (24%)
1.1 Understand cybersecurity concepts
- Confidentiality
- Integrity
- Availability
- Authentication, Authorization, Accounting (AAA)
- Non-repudiation
- Privacy
1.2 Understand risk management concepts
- Risk management lifecycle
- Risk management processes
1.3 Understand governance concepts
- Regulations and laws
- Frameworks and guidelines
- Policies, standards (e.g., International Organization for Standardization (ISO), Center for Internet Security), procedures
1.4 Understand cybersecurity controls
- Technical controls
- Administrative controls
- Physical controls
1.5 Maintain professional and ethical conduct
- Professional code of conduct
- Due care and due diligence
- ISC2 Code of Ethics
Domain 2: Security Governance (17.3%)
2.1 Plan Governance, Risk, and Compliance (GRC)
- Purpose
- Importance
- Frameworks and tools
2.2 Understand redundancy
- Business Continuity (BC)
- Disaster Recovery (DR)
2.3 Understand security awareness
- Organizational culture (e.g., importance of security, security leadership)
- Concepts (e.g., social engineering, password protection, phishing)
2.4 Measure cybersecurity effectiveness
- Key metrics, Key Risk Indicators (KRI)
- Dashboards, score cards, reports
Domain 3: Identity and Access Management (IAM) Concepts (20%)
3.1 Understand identity life cycle management
- Roles definition
- Provision
- Review
- Deprovision
- Frameworks and tools
3.2 Understand logical access controls
- Principle of Least Privilege (PoLP)
- Separation of Duties (SoD)
- Access control models
Domain 4: Networking and Cloud Security Concepts (21.3%)
4.1 Understand network security
- Concepts (e.g., Open Systems Interconnection (OSI) model, Transmission Control Protocol/Internet Protocol (TCP/IP) model, Internet Protocol version 4 (IPv4), Internet Protocol version 6 (IPv6), Virtual Private Network (VPN))
- Firewalls (e.g., ports, applications)
- Wireless (e.g., Wi-Fi, Bluetooth)
- Embedded systems (e.g., Industrial Control System (ICS)), Internet Of Things (IoT)
4.2 Understand network security architecture
- Comprehending network segmentation (e.g., Firewall zones, Virtual Local Area Network (VLAN), micro-segmentation)
- Defense in Depth
- Zero Trust (ZT)
4.3 Understand cloud security
- Characteristics (e.g., Broad network access, rapid elasticity, measured service, on-demand self-service, resource pooling)
- Service models
- Deployment models
- Shared security model (e.g., roles and responsibilities)
Domain 5: Security Operations and Incident Response (17.3%)
5.1 Understand data security
- Data handling (e.g., classification, labeling, masking, and sanitization)
- Encryption (e.g., symmetric, asymmetric, hashing, quantum resistant cryptography)
5.2 Understand security operations
- Logging and monitoring security events
- Security event triage (e.g., incident use cases, prioritization, correlation)
- Threat actors (e.g., types, motivations)
- Cyber threat intelligence
- Threat frameworks
5.3 Understand Incident Response (IR)
- Data handling policy implementing Incident Response Plan (IRP)
- Incident Response (IR) exercises (e.g., testing, tabletop)
5.4 Understand asset protection
- Asset lifecycle management (e.g., End Of Life (EOL) software and devices)
- Configuration and change management
5.5 Understand security testing
- Security readiness testing (e.g., blue teaming, purple teaming, red teaming)
- Application testing (e.g., vulnerability scanning, static analysis, dynamic analysis, threat modeling)
- Physical penetration testing (e.g., phishing, tailgating, impersonation)
The course content above may change at any time without notice in order to better reflect the content of the examination.
付款。