Site Sections => About Us | Consultancy | Training | Software | Publications | Open Source | Support | Open Standards | FAQ | Jobs
Site Style Info

Securing Hosts Using Cisco Security Agent (HIPS) — A 2-Day Course

Synopsis

HIPS is a two-day, lab-intensive training course which develops the knowledge and skills to deploy, configure and administer the Cisco Security Agent product to protect server and workstation hosts. It takes a task-oriented approach, using lecture and hands-on labs to teach the skills. The Cisco Security Agent functions to protect from intrusions, as compared to simply detecting attempted intrusions.

Course Objectives

After completing this course, students will be able to:

  • Describe the need for network security; understand attack types, methods and Cisco security wheel
  • CSA overview - functionality, components and architecture
  • CSAMC install - overview, system requirements for management console
  • CSAMC quick start configuration - configure a group, build an agent kit, view registered hosts, configure a policy, attach a policy to a group and generate rule programs
  • CSAMC administration - accessing and using the management console
  • Configure groups and manage hosts.Build agent kits and distributing software updates
  • Develop a security policy
  • Configure policies and rules for Windows and UNIX
  • Use system correlation and heuristics
  • Understand and configure application classes
  • Configure variables - file sets, network address sets, network services, registry sets, COM component sets
  • Use CSA Profiler for data analysis and as policy creation tool
  • Configure and manage event logging, alerts and reports
  • Understand and use CSAMC utilities - start/stop service for servers and agent, webmgr utility, backup configurations, COM extract utility and export / import configurations

Intended Audience

  • Engineers who support sales of Cisco security product solutions
  • Cisco Channel Partners, who sell, implement and maintain secure networks
  • Cisco Customers who implement and maintain secure networks

Prerequisites

  • Valid CCNA or equivalent knowledge
  • 6 months practical experience of configuring Cisco IDS Routers
  • Competency in using the Windows NT Operating system
  • Familiarity with implementing network security policies and the following networking concepts:
    • Perimeter Security System Components
    • Perimeter Router
    • Firewall
    • Bastion Host/Servers and Hosts

Certification

The HIPS course is recommended as preparation for exam:

  • 642-513

HIPS is part of the Cisco Certified Security Professional (CCSP) Certification Path.

Publicly scheduled dates, locations, and prices

Central London — £895 (+VAT)

  • 4–5 Aug 2008
  • 18–19 Sep 2008

Outline Course Contents

Security Fundamentals

  • Need for Network Security
  • Network Security Policy
  • Network Attack Taxonomy

Cisco Security Agent Overview

  • Defense in Depth
  • Cisco Security Agent Architecture
  • Anatomy of an Attack and Response
  • Key Features of Cisco Security Agent

Cisco Security Agent Quick Start Installation

  • CSAMC System Requirements
  • CSA System Requirements
  • Installing the CSAMC
  • Configuring the CSAMC
  • Installing the CSA

Cisco Security Agent Management Center Administration

  • Using Cisco Securinty Agent Management Center

Using Event Logs and Generating Reports

  • The Event Log and Event Monitor
  • Configuring Event Sets
  • Configuring Alerts
  • Generating Reports

Configuring Groups and Managing Hosts

  • Configuring Groups
  • Building and Agent Kit
  • Managing Hosts
  • Deploying Scheduled Software Updates

Building Policies

  • Developing a Security Policy
  • Rule Basics
  • Policy Components
  • Configuring and Managing Policies
  • Rules common to Windows and Unix
  • Windows-Only Rules
  • Unix-only Rules

Defining Application Classes

  • About Application Classes
  • Configuring Static Application Classes
  • Dynamic Application Classes

Working with Variables

  • Data Sets
  • File Sets
  • Network Address & Services Sets
  • Registry Sets
  • COM Component Sets

Using Cisco Security Agent Profiler

  • Basics of Profiler
  • Configuring an Analysis Job
  • Starting Analysis
  • The profiler Policy
  • Profiler Reports

Cisco training UK enquiries

UK Training enquiries and feedback form.

Cisco training UK prices

For publicly scheduled training (individual places), see our UK training schedule.

In-house training for company groups is charged at a daily rate per group — see our In-House UK Training Guidelines.

Publicly Scheduled Training Locations

We currently run public training courses in the following locations:

  • London, UK
  • Leeds, West Yorkshire, UK
  • Birmingham, West Midlands, UK
  • Carshalton, Surrey, UK
  • Chester, North West, UK
  • Coventry, West Midlands, UK
  • Edinburgh, Scotland, UK
  • Glasgow, Scotland, UK
  • Harwell, Oxfordshire, UK
  • Manchester, North West, UK
  • Milton Keynes, Buckinghamshire, UK
  • Newark, Nottinghamshire, UK
  • Reading, Berkshire, UK
  • Slough, Berkshire, UK
  • Stevenage, Hertfordshire, UK
  • Wakefield, West Yorkshire, UK
  • Wokingham, Berkshire, UK

Most UK public training courses are available on a monthly basis.

Please see the individual course outlines or our public training schedule for details.

In-house (on-site) training locations

We deliver in-house courses at client premises and/or training facilities in any part of the world which is practically and commercially accessible.

Our In-house training guidelines outline our basic requirements and our UK pricing structure. To estimate costs for training in other countries, simply convert to your local currency and then make a rough calculation of our tutor's costs for travelling to and staying at your location.


West Yorkshire Office

GBdirect Ltd
Training Division
Bradford Design Exchange
34 Peckover Street
BRADFORD
BD1 5BD
West Yorkshire
United Kingdom

training@gbdirect.co.uk

Training: 0800 651 0338
General: +44 (0)870 200 7273
Finance: +44 (0)1353 615 174

Please call between 0900 and 1700 (UK time) on Monday to Friday


South East Regional Office

GBdirect Ltd
Training Division
18 Lynn Rd
ELY
CB6 1DA
Cambridgeshire
United Kingdom

training@gbdirect.co.uk

Training: 0800 651 0338
General: +44 (0)870 200 7273
Finance: +44 (0)1353 615 174

Please call between 0900 and 1700 (UK time) on Monday to Friday


Please note:
Non-training enquiries should be directed, initially, to our UK national office in Bradford (West Yorkshire), even if the enquiry concerns services delivered in London or South/East England. Clients in London and the South East will typically be handled by staff working in the London or Cambridge areas.