Workshop
08. Practical Windows Security Hardening
Trainer
Memet Anwar (ID)
Date
TBA
Duration
1 Day
Price
Rp. 3.000.000,-
Requirement
Participants are required to bring their own laptops. Participants are expected to have basic understanding and some experiences in administering Active Directory, group policy, IIS, and Exchange server. Knowledge about security risk of those services would be very useful, but it is not required in order to comprehend the workshop material.
Overview
This workshop will discuss some of the practices used to enhance the security of Windows network environment and its related services. Popular services that will be covered are Active Directory and its group policy, IIS, and Exchange server. Hardening methods will include well-known security checklists, architectural design, the use of Microsoft's and 3rd party security tools, and more advanced techniques such as scripting/coding and integration of open-source software for added protection.
top ^
Course Outline
Introduction
Active Directory and Group Policy
Secure Windows 2003-based Active Directory design
System hardening usering group policy (desktop lockdown, server hardening)
Scripting and tools for Windows domain security administration (security update distribution, AD scripting, remote execution of administration command)
Internet Information Service (IIS)
IIS 6.0 hardening checklists and tools (urlscan, application firewalls, well-known checklists)
Secure IIS 6.0 web application deployment (secure application design, low privilege operation, n-tier in IIS, DMZ isolation)
Exchange Server
Exchange 2003 security features (built-in anti-spam, encryptions, and filters. Alternatives for secure mobile access.
Extending Exchange server (spam assassing integration, custom filter development, etc.)
top ^
About the tutor
TBA
For questions regarding event registration, please call +62-21-570-5800 (Ms. Astri). For general questions, please email bcs2006@bellua.com or send an empty message to bcs-announce-subscribe@bellua.com to receive future event information.
< back
top ^