ICAB5238B Build a highly secure firewall
|
|
|
- Eugenia Sharp
- 10 years ago
- Views:
Transcription
1 ICAB5238B Build a highly secure firewall Release: 1
2 ICAB5238B Build a highly secure firewall Modification History Not Applicable Unit Descriptor Unit descriptor This unit defines the competency required to build high level security and network functionality into a network by configuring a firewall appropriately. No licensing, legislative, regulatory or certification requirements apply to this unit at the time of publication. Application of the Unit Application of the unit Licensing/Regulatory Information Refer to Unit Descriptor Pre-Requisites Prerequisite units Approved Page 2 of 9
3 Employability Skills Information Employability skills This unit contains employability skills. Elements and Performance Criteria Pre-Content Elements describe the essential outcomes of a unit of competency. Performance criteria describe the performance needed to demonstrate achievement of the element. Where bold italicised text is used, further information is detailed in the required skills and knowledge section and the range statement. Assessment of performance is to be consistent with the evidence guide. Approved Page 3 of 9
4 Elements and Performance Criteria ELEMENT 1. Establish match between firewall appliance and business needs 2. Configure firewall appliance 3. Secure perimeter using firewall appliance PERFORMANCE CRITERIA 1.1. Match features and capabilities of firewall appliance to business security needs and asset protection 1.2. Match features and capabilities of firewall appliance to business accounting needs and asset protection 1.3. Match features and capabilities of firewall device to remote access needs and asset protection 1.4. Monitor and manage firewall appliance logs, reports and performance both on-site and remotely 2.1. Configure attack guards and intrusion detection 2.2. Identify and apply IPSec configuration tasks 2.3. Test and verify VPN configuration 3.1. Configure appropriate access-defined and access control lists using objects and nested objects as appropriate 3.2. Apply filtering of traffic in line with security requirements 3.3. Configure authentication, authorisation and accounting (AAA) services supporting remote access protocols in line with security requirements 3.4. Document and securely store settings Required Skills and Knowledge REQUIRED SKILLS AND KNOWLEDGE This section describes the skills and knowledge required for this unit. Required skills Ability to develop enterprise policies, strategies and procedures Ability to undertake a network security risk assessment Ability to implement security strategies and configure network security software and hardware Implementing LAN, VPN, WLAN and WAN solutions Cost-benefit comparison Troubleshooting/debugging Required knowledge Approved Page 4 of 9
5 REQUIRED SKILLS AND KNOWLEDGE Security threats, including eavesdropping, data interception, data corruption, data falsification, authentication issues Organisational issues surrounding security Security perimeters and their functions Types of VPNs, including site-to-site, user-to-site internet traffic and extranets The function and operation of virtual private networking (VPN) concepts, including encryption, firewalls, packet tunnelling and authentication Common VPN issues, including, bandwidth, dynamic security environment Network protocols and operating systems Security protocols, standards and data encryption Configuring routers and switches Cryptography LAN, WLAN and WAN solutions TCP/IP protocols and applications Auditing and penetration testing techniques Screened subnets Virus detection software Audit and intrusion detection systems Approved Page 5 of 9
6 Evidence Guide EVIDENCE GUIDE The evidence guide provides advice on assessment and must be read in conjunction with the performance criteria, required skills and knowledge, range statement and the Assessment Guidelines for the Training Package. Overview of assessment Critical aspects for assessment and evidence required to demonstrate competency in this unit Evidence of the following is essential: Assessment must confirm the ability to develop, implement and maintain basic security functionality for either VPN, LANs or WLANs. To demonstrate competency in this unit the person will require access to: Network technical requirements Network infrastructure including servers and security hardware and software Context of and specific resources for assessment The breadth, depth and complexity covering planning and initiation of alternative approaches to skills or knowledge applications across a broad range of technical and/or management requirements, evaluation and coordination would be characteristic. Assessment must ensure: The demonstration of competency may also require self-directed application of knowledge and skills, with substantial depth in some areas where judgement is required in planning and selecting appropriate equipment, services and techniques for self and others. Applications involve participation in development of strategic initiatives as well as personal responsibility and autonomy in performing complex technical operations or organising others. It may include participation in teams including teams concerned with planning and evaluation functions. Group or team coordination may also be involved. Approved Page 6 of 9
7 EVIDENCE GUIDE Method of assessment The purpose of this unit is to define the standard of performance to be achieved in the workplace. In undertaking training and assessment activities related to this unit, consideration should be given to the implementation of appropriate diversity and accessibility practices in order to accommodate people who may have special needs. Additional guidance on these and related matters is provided in ICA05 Section 1. Competency in this unit should be assessed using summative assessment to ensure consistency of performance in a range of contexts. This unit can be assessed either in the workplace or in a simulated environment. However, simulated activities must closely reflect the workplace to enable full demonstration of competency. Assessment will usually include observation of real or simulated work processes and procedures and/or performance in a project context as well as questioning on underpinning knowledge and skills. The questioning of team members, supervisors, subordinates, peers and clients where appropriate may provide valuable input to the assessment process. The interdependence of units for assessment purposes may vary with the particular project or scenario. Guidance information for assessment Holistic assessment with other units relevant to the industry sector, workplace and job role is recommended. An individual demonstrating this competency would be able to: Demonstrate understanding of a broad knowledge base incorporating theoretical concepts, with substantial depth in some areas Analyse and plan approaches to technical problems or management requirements Transfer and apply theoretical concepts and/or technical or creative skills to a range of situations Evaluate information, using it to forecast for planning or research purposes Approved Page 7 of 9
8 EVIDENCE GUIDE Take responsibility for own outputs in relation to broad quantity and quality parameters Take some responsibility for the achievement of group outcomes Maintain knowledge of industry products and services Range Statement RANGE STATEMENT The range statement relates to the unit of competency as a whole. It allows for different work environments and situations that may affect performance. Bold italicised wording, if used in the performance criteria, is detailed below. Essential operating conditions that may be present with training and assessment (depending on the work situation, needs of the candidate, accessibility of the item, and local industry and regional contexts) may also be included. Assets may include: data and information intellectual property physical assets Authentication, Authorisation and Accounting (AAA) Remote access security approach that controls network access by requiring user identification and restricting access to only particular resources, and maintains records of use for billing and network audit Unit Sector(s) Unit sector Build Co-requisite units Co-requisite units Approved Page 8 of 9
9 Co-requisite units Competency field Competency field Approved Page 9 of 9
Release: 1. ICAB5230B Maintain custom software
Release: 1 ICAB5230B Maintain custom software ICAB5230B Maintain custom software Modification History Not Applicable Unit Descriptor Unit descriptor This unit defines the competency required to maintain
ICANWK406A Install, configure and test network security
ICANWK406A Install, configure and test network security Release: 1 ICANWK406A Install, configure and test network security Modification History Release Release 1 Comments This Unit first released with
ICAS4134C Provide first-level remote help desk support
ICAS4134C Provide first-level remote help desk support Release: 1 ICAS4134C Provide first-level remote help desk support Modification History Not Applicable Unit Descriptor Unit descriptor This unit defines
ICAI4099A Build an intranet
ICAI4099A Unit Descriptor Unit Sector Build an intranet This unit defines the competency required to design, build and implement an intranet for a client. It does not however cover aspects relating to
ICAB4136B Use structured query language to create database structures and manipulate data
ICAB4136B Use structured query language to create database structures and manipulate data Release: 1 ICAB4136B Use structured query language to create database structures and manipulate data Modification
Release: 1. ICAS5203B Evaluate and select a web hosting service
Release: 1 ICAS5203B Evaluate and select a web hosting service ICAS5203B Evaluate and select a web hosting service Modification History Not Applicable Unit Descriptor Unit descriptor This unit defines
ICAS4108B Complete database back-up and recovery
ICAS4108B Complete database back-up and recovery Release: 1 ICAS4108B Complete database back-up and recovery Modification History Not Applicable Unit Descriptor Unit descriptor This unit defines the competency
ICAA5141C Design and develop dynamic websites to meet technical requirements
ICAA5141C Unit Descriptor Employability Skills Prerequisite Unit(s) Unit Sector Design and develop dynamic websites to meet technical requirements This unit defines the competency required to produce a
Monitor and administer network security
ICAS4124A Unit Descriptor Unit Sector Monitor and administer network security This unit defines the competency required to monitor and administer security functions on a network according to organisational
Release: 1. ICANWK502A Implement secure encryption technologies
Release: 1 ICANWK502A Implement secure encryption technologies ICANWK502A Implement secure encryption technologies Modification History Release Release 1 Comments This Unit first released with ICA11 Information
ICTTEN2209A Build and maintain a secure network
ICTTEN2209A Build and maintain a secure network Release: 1 ICTTEN2209A Build and maintain a secure network Modification History Not Applicable Unit Descriptor Unit descriptor This unit describes the performance
ICAI3020B Install and optimise operating system software
ICAI3020B Unit Descriptor Employability Skills Unit Sector Install and optimise operating system software This unit defines the competency required to install operating system software and to make adjustments
ICTTEN5204A Produce technical solutions from business specifications
ICTTEN5204A Produce technical solutions from business specifications Release: 1 ICTTEN5204A Produce technical solutions from business specifications Modification History Not Applicable Unit Descriptor
Release: 1. ICANWK607A Design and implement wireless network security
Release: 1 ICANWK607A Design and implement wireless network security ICANWK607A Design and implement wireless network security Modification History Release Release 1 Comments This Unit first released with
Release: 1. CPPSEC4015A Maintain networked security system
Release: 1 CPPSEC4015A Maintain networked security system CPPSEC4015A Maintain networked security system Modification History Not Applicable Unit Descriptor Unit descriptor This unit of competency specifies
PSPCRT409B Administer court fines and debt management
PSPCRT409B Administer court fines and debt management Release: 2 PSPCRT409B Administer court fines and debt management Modification History PSPCRT409B Release 1: PSPCRT409B Release 2: Unit Descriptor Layout
ICANWK616A Manage security, privacy and compliance of cloud service deployment
ICANWK616A Manage security, privacy and compliance of cloud service deployment Release 1 ICANWK616A Manage security, privacy and compliance of cloud service deployment Modification History Release Release
CISCO IOS NETWORK SECURITY (IINS)
CISCO IOS NETWORK SECURITY (IINS) SEVENMENTOR TRAINING PVT.LTD [Type text] Exam Description The 640-553 Implementing Cisco IOS Network Security (IINS) exam is associated with the CCNA Security certification.
Release: 1. BSBPMG503A Manage project time
Release: 1 BSBPMG503A Manage project time BSBPMG503A Manage project time Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes, skills and knowledge
Release: 1. ICADBS603A Determine suitability of database functionality and scalability
Release: 1 ICADBS603A Determine suitability of database functionality and scalability ICADBS603A Determine suitability of database functionality and scalability Modification History Release Release 1 Comments
Release: 1. ICASAS407A Conduct pre-installation audit for software installation
Release: 1 ICASAS407A Conduct pre-installation audit for software installation ICASAS407A Conduct pre-installation audit for software installation Modification History Release Release 1 Comments This Unit
ICAWEB405A Monitor traffic and compile website traffic reports
ICAWEB405A Monitor traffic and compile website traffic reports Release: 1 ICAWEB405A Monitor traffic and compile website traffic reports Modification History Release Release 1 Comments This Unit first
FNSRSK601A Develop and implement risk mitigation plan
FNSRSK601A Develop and implement risk mitigation plan Revision Number: 1 FNSRSK601A Develop and implement risk mitigation plan Modification History Not applicable. Unit Descriptor Unit descriptor This
FNSIBK605A Manage insurance brokerage service performance
FNSIBK605A Manage insurance brokerage service performance Revision Number: 1 FNSIBK605A Manage insurance brokerage service performance Modification History Not applicable. Unit Descriptor Unit descriptor
Release: 1. ICADBS601A Build a data warehouse
Release: 1 ICADBS601A Build a data warehouse ICADBS601A Build a data warehouse Modification History Release Release 1 Comments This Unit first released with ICA11 Information and Communications Technology
BSBINM501A Manage an information or knowledge management system
BSBINM501A Manage an information or knowledge management system Release: 1 BSBINM501A Manage an information or knowledge management system Modification History Not applicable. Unit Descriptor Unit descriptor
Revision Number: 1. BSBADM307B Organise schedules
Revision Number: 1 BSBADM307B Organise schedules BSBADM307B Organise schedules Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes, skills
ICASAS505A Review and update disaster recovery and contingency plans
ICASAS505A Review and update disaster recovery and contingency plans Release: 1 ICASAS505A Review and update disaster recovery and contingency plans Modification History Release Release 1 Comments This
BSBLEG515A Apply legal principles in wills and probate matters
BSBLEG515A Apply legal principles in wills and probate matters Revision Number: 1 BSBLEG515A Apply legal principles in wills and probate matters Modification History Not applicable. Unit Descriptor Unit
ICTTEN6172A Design and configure an IP- MPLS network with virtual private network tunnelling
ICTTEN6172A Design and configure an IP- MPLS network with virtual private network tunnelling Release: 1 ICTTEN6172A Design and configure an IP-MPLS network with virtual private network tunnelling Modification
ICTTEN4051A Install configuration programs on PC based customer equipment
ICTTEN4051A Install configuration programs on PC based customer equipment Release: 1 ICTTEN4051A Install configuration programs on PC based customer equipment Modification History Not Applicable Unit Descriptor
Appendix A: Configuring Firewalls for a VPN Server Running Windows Server 2003
http://technet.microsoft.com/en-us/library/cc757501(ws.10).aspx Appendix A: Configuring Firewalls for a VPN Server Running Windows Server 2003 Updated: October 7, 2005 Applies To: Windows Server 2003 with
Release: 1. FNSILF302A Process a life insurance application
Release: 1 FNSILF302A Process a life insurance application FNSILF302A Process a life insurance application Modification History Release Release 1 Comments This Unit of Competency first released with FNS10
How To Manage A Network Safely
ICANWK303A Configure and administer a network operating system Release: 1 ICANWK303A Configure and administer a network operating system Modification History Release Release 1 Comments This Unit first
BSBHRM502A Manage human resources management information systems
BSBHRM502A Manage human resources management information systems Revision Number: 1 BSBHRM502A Manage human resources management information systems Modification History Not applicable. Unit Descriptor
Release 1. ICAICT814A Develop cloud computing strategies for a business
Release 1 ICAICT814A Develop cloud computing strategies for a business ICAICT814A Develop cloud computing strategies for a business Modification History Release Release 1 Comments This version first released
LGAGOVA610B Implement computerised asset management systems
LGAGOVA610B Implement computerised asset management systems Revision Number: 1 LGAGOVA610B Implement computerised asset management systems Modification History Not applicable. Unit Descriptor Unit Descriptor
Release: 1. CPCCBC4026A Arrange building applications and approvals
Release: 1 CPCCBC4026A Arrange building applications and approvals CPCCBC4026A Arrange building applications and approvals Modification History Not Applicable Unit Descriptor Unit descriptor This unit
LMFGN3002B Estimate and cost job
LMFGN3002B Estimate and cost job Revision Number: 1 LMFGN3002B Estimate and cost job Modification History Not applicable. Unit Descriptor Unit descriptor This unit covers the competency to estimate materials,
Cisco Certified Security Professional (CCSP)
529 Hahn Ave. Suite 101 Glendale CA 91203-1052 Tel 818.550.0770 Fax 818.550.8293 www.brandcollege.edu Cisco Certified Security Professional (CCSP) Program Summary This instructor- led program with a combination
Release: 1. ICASAS206A Detect and protect from spam and destructive software
Release: 1 ICASAS206A Detect and protect from spam and destructive software ICASAS206A Detect and protect from spam and destructive software Modification History Release Release 1 Comments This Unit first
ICTTEN8195B Evaluate and apply network security
ICTTEN8195B Evaluate and apply network security Release 1 ICTTEN8195B Evaluate and apply network security Modification History Release Release 2 Comments This version first released with ICT10 Integrated
MEM11015B Manage warehouse inventory system
MEM11015B Manage warehouse inventory system Release: 1 MEM11015B Manage warehouse inventory system Modification History Not Applicable Unit Descriptor Unit descriptor This unit covers monitoring warehouse
Release: 1. ICAICT604A Identify and implement business innovation
Release: 1 ICAICT604A Identify and implement business innovation ICAICT604A Identify and implement business innovation Modification History Release Release 1 Comments This Unit first released with ICA11
CCNA Security 2.0 Scope and Sequence
CCNA Security 2.0 Scope and Sequence Last Updated August 26, 2015 Target Audience The Cisco CCNA Security course is designed for Cisco Networking Academy students seeking career-oriented, entry-level security
ICANWK613A Develop plans to manage structured troubleshooting process of enterprise networks
ICANWK613A Develop plans to manage structured troubleshooting process of enterprise networks Release: 1 ICANWK613A Develop plans to manage structured troubleshooting process of enterprise networks Modification
Release: 1. ICADBS502A Design a database
Release: 1 ICADBS502A Design a database ICADBS502A Design a database Modification History Release Release 1 Comments This Unit first released with ICA11 Information and Communications Technology Training
ICANWK501A Plan, implement and test enterprise communication solutions
ICANWK501A Plan, implement and test enterprise communication solutions Release: 1 ICANWK501A Plan, implement and test enterprise communication solutions Modification History Release Release 1 Comments
BSBGOV403A Analyse financial reports and budgets
BSBGOV403A Analyse financial reports and budgets Revision Number: 1 BSBGOV403A Analyse financial reports and budgets Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes
PSPWPR401A Process incoming workplace relations enquiries
PSPWPR401A Process incoming workplace relations enquiries Revision Number: 1 PSPWPR401A Process incoming workplace relations enquiries Modification History Not applicable. Unit Descriptor Unit descriptor
ICTTEN5168A Design and implement an enterprise voice over internet protocol and a unified communications network
ICTTEN5168A Design and implement an enterprise voice over internet protocol and a unified communications network Release: 1 ICTTEN5168A Design and implement an enterprise voice over internet protocol and
MSACMT260A Use planning software systems in manufacturing
MSACMT260A Use planning software systems in manufacturing Revision Number: 1 MSACMT260A Use planning software systems in manufacturing Modification History Not applicable. Unit Descriptor Unit descriptor
Release: 1. ICADBS412A Build a database
Release: 1 ICADBS412A Build a database ICADBS412A Build a database Modification History Release Release 1 Comments This Unit first released with ICA11 Information and Communications Technology Training
BSBMKG506B Plan market research
BSBMKG506B Plan market research Revision Number: 1 BSBMKG506B Plan market research Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes, skills
BSBMKG508A Plan direct marketing activities
BSBMKG508A Plan direct marketing activities Revision Number: 1 BSBMKG508A Plan direct marketing activities Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance
Revision Number: 1. BSBFIA302A Process payroll
Revision Number: 1 BSBFIA302A Process payroll BSBFIA302A Process payroll Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes, skills and knowledge
Release: 1. TAEPDD501A Maintain and enhance professional practice
Release: 1 TAEPDD501A Maintain and enhance professional practice TAEPDD501A Maintain and enhance professional practice Modification History Version Comments TAEPDD501A Released with TAE10 Training and
FNSRTS309A Maintain main bank account
FNSRTS309A Maintain main bank account Revision Number: 1 FNSRTS309A Maintain main bank account Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes,
ICANWK504A Design and implement an integrated server solution
ICANWK504A Design and implement an integrated server solution Release: 1 ICANWK504A Design and implement an integrated server solution Modification History Release Release 1 Comments This Unit first released
ICANWK402A Install and configure virtual machines for sustainable ICT
ICANWK402A Install and configure virtual machines for sustainable ICT Release: 1 ICANWK402A Install and configure virtual machines for sustainable ICT Modification History Release Release 1 Comments This
Release 1. BSBPMG415A Apply project risk-management techniques
Release 1 BSBPMG415A Apply project risk-management techniques BSBPMG415A Apply project risk-management techniques Modification History Release Release 1 Comments This version first released with BSB07
ICANWK414A Create a common gateway interface script
ICANWK414A Create a common gateway interface script Release: 1 ICANWK414A Create a common gateway interface script Modification History Release Release 1 Comments This Unit first released with ICA11 Information
Release 1. BSBPMG412A Apply project cost-management techniques
Release 1 BSBPMG412A Apply project cost-management techniques BSBPMG412A Apply project cost-management techniques Modification History Release Release 1 Comments This version first released with BSB07
8. Firewall Design & Implementation
DMZ Networks The most common firewall environment implementation is known as a DMZ, or DeMilitarized Zone network. A DMZ network is created out of a network connecting two firewalls; i.e., when two or
ICASAS420A Provide first-level remote help-desk support
ICASAS420A Provide first-level remote help-desk support Release: 1 ICASAS420A Provide first-level remote help-desk support Modification History Version ICASAS420A Comments This version first released with
ICA60208 Advanced Diploma of Information Technology (Network Security)
ICA60208 Advanced Diploma of Information Technology (Network Security) Release: 1 ICA60208 Advanced Diploma of Information Technology (Network Security) Modification History Not Applicable Approved Page
How To Understand The Unit Of Competency
BSBSMB303A Organise finances for the micro business Revision Number: 1 BSBSMB303A Organise finances for the micro business Modification History Not applicable. Unit Descriptor Unit descriptor This unit
Release: 1. BSBPMG606A Direct human resources management of a project program
Release: 1 BSBPMG606A Direct human resources management of a project program BSBPMG606A Direct human resources management of a project program Modification History Not applicable. Unit Descriptor Unit
Revision Number: 1. MSACMG802A Audit the use of competitive tools
Revision Number: 1 MSACMG802A Audit the use of competitive tools MSACMG802A Audit the use of competitive tools Modification History Not applicable. Unit Descriptor Unit descriptor This unit covers auditing
Release: 1. BSBPMG509A Manage project procurement
Release: 1 BSBPMG509A Manage project procurement BSBPMG509A Manage project procurement Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance outcomes,
ICTSUS4183A Install and test renewable energy system for ICT networks
ICTSUS4183A Install and test renewable energy system for ICT networks Release: 1 ICTSUS4183A Install and test renewable energy system for ICT networks Modification History Not Applicable Unit Descriptor
ICTTEN4215A Install and configure internet protocol TV in a service provider network
ICTTEN4215A Install and configure internet protocol TV in a service provider network Release: 1 ICTTEN4215A Install and configure internet protocol TV in a service provider network Modification History
BSBHRM403A Support performance management process
BSBHRM403A Support performance management process Revision Number: 1 BSBHRM403A Support performance management process Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes
CPPSEC4016A Install networked security system
CPPSEC4016A Install networked security system Release: 1 CPPSEC4016A Install networked security system Modification History Not Applicable Unit Descriptor Unit descriptor This unit of competency specifies
Release: 1. BSBFIM501A Manage budgets and financial plans
Release: 1 BSBFIM501A Manage budgets and financial plans BSBFIM501A Manage budgets and financial plans Modification History Not applicable. Unit Descriptor Unit descriptor This unit describes the performance
Release: 1. ICA60308 Advanced Diploma of Information Technology (E-Security)
Release: 1 ICA60308 Advanced Diploma of Information Technology (E-Security) ICA60308 Advanced Diploma of Information Technology (E-Security) Modification History Not Applicable Approved Page 2 of 8 Description
ICANWK610A Design and build integrated VoIP networks
ICANWK610A Design and build integrated VoIP networks Release: 1 ICANWK610A Design and build integrated VoIP networks Modification History Release Release 1 Comments This Unit first released with ICA11
ICANWK401A Install and manage a server
ICANWK401A Install and manage a server Release: 1 ICANWK401A Install and manage a server Modification History Release Release 1 Comments This Unit first released with ICA11 Information and Communications
ICAPRG529A Apply testing techniques for software development
ICAPRG529A Apply testing techniques for software development Release: 1 ICAPRG529A Apply testing techniques for software development Modification History Release Release 1 Comments This Unit first released
FNSIBK404A Provide a claims service to an insurance broking client
FNSIBK404A Provide a claims service to an insurance broking client Revision Number: 1 FNSIBK404A Provide a claims service to an insurance broking client Modification History Not applicable. Unit Descriptor
