آموزش راهنمای جامع مدیریت امنیت و انطباق در AWS - آخرین آپدیت

دانلود Complete Guide to AWS Security and Compliance Management

نکته: ممکن هست محتوای این صفحه بروز نباشد ولی دانلود دوره آخرین آپدیت می باشد.
نمونه ویدیوها:
توضیحات دوره: درک و پیاده‌سازی موفق مفاهیم امنیتی برای استفاده از AWS به عنوان راهکار سازمانی شما ضروری است. در این دوره، مدرس (Sharif Nijim) توصیه‌های کاربردی را با مثال‌های عملی ترکیب کرده است تا متخصصان IT را با نحوه ایجاد یک زیرساخت امن در خدمات ابری آمازون (AWS) آشنا کند. در این دوره مدل مسئولیت مشترک امنیتی را که وظایف را بین شرکت شما و AWS تقسیم می‌کند، بررسی خواهیم کرد. همچنین عمیقاً وارد مفاهیم کلیدی مدیریت هویت و دسترسی (IAM) از جمله کاربران، گروه‌ها، نقش‌ها و پالیسی‌ها می‌شویم. یاد بگیرید چگونه یک زیرساخت امن در AWS ایجاد کنید و چندین چالش عملی را برای توسعه راهکارهای مستقل در زمینه‌های نقش‌های IAM، سرویس KMS، S3 و مقابله با نشت داده‌ها به اتمام برسانید.

سرفصل ها و درس ها

مقدمه Introduction

  • بررسی کلی امنیت AWS AWS security overview

  • آنچه باید بدانید What you should know

1. مبانی امنیت AWS 1. AWS Security Foundations

  • پیکربندی سرویس اعلان ساده (SNS) Configuring Simple Notification Service

  • درک مفهوم CloudWatch Understanding CloudWatch

  • نصب رابط خط فرمان (CLI) برای مک Installing the command line interface (CLI) for Mac

  • پیاده‌سازی تفکیک وظایف Implementing separation of duties

  • درک مسئولیت مشترک Understanding shared responsibility

  • رابط خط فرمان (CLI) برای ویندوز The command line interface (CLI) for Windows

  • درک هشدار‌های CloudWatch Understanding CloudWatch alarms

  • فعال‌سازی CloudTrail Enabling CloudTrail

  • استفاده از هشدار CloudWatch Using a CloudWatch alarm

  • درک چشم‌انداز امنیتی AWS Understanding the AWS security landscape

  • درک مفهوم CloudTrail Understanding CloudTrail

  • درک تفکیک وظایف Understanding separation of duties

2. مفاهیم IAM در AWS 2. IAM Concepts in AWS

  • درک سرویس توکن امنیتی (STS) Understanding Security Token Service

  • فعال‌سازی دسترسی‌های مالی Enabling financial access

  • ایجاد یک استخر شناسایی Cognito Creating a Cognito identity pool

  • درک مجوزهای تایید شده (Verified Permissions) Understanding Verified Permissions

  • درک پالیسی‌های IAM Understanding IAM policies

  • درک مفهوم Cognito Understanding Cognito

  • درک گروه‌های IAM Understanding IAM groups

  • چالش: مدیر ارشد (Super admin) Challenge: Super admin

  • اعتبارسنجی دسترسی فدرال Validating federated access

  • اعتبارسنجی یک نقش IAM Validating an IAM role

  • ایجاد یک پالیسی دسترسی موقت Creating a temporary access policy

  • توضیح محدودیت‌های دسترسی Illustrating access restrictions

  • ایمن‌سازی دسترسی‌های مالی Securing financial access

  • پیکربندی پالیسی‌های IAM Configure IAM policies

  • اعتبارسنجی دسترسی موقت Validating temporary access

  • راهکار: نقش‌های IAM Solution: IAM roles

  • پیکربندی نقش‌های IAM Configuring IAM roles

  • درک دسترسی فدرال Understanding federated access

  • ایجاد یک استخر کاربر Cognito Creating a Cognito user pool

  • فعال‌سازی دسترسی فدرال Enabling federated access

  • ایجاد یک نقش دسترسی موقت Creating a temporary access role

  • راهکار: مدیر ارشد Solution: Super admin

  • درک مدیریت هویت و دسترسی (IAM) Understanding Identity and Access Management

  • راهکار چالش IAM IAM challenge solution

  • چالش: نقش‌های IAM Challenge: IAM roles

  • پیکربندی نقش‌های IAM Configuring IAM roles

  • پیکربندی پالیسی رمز عبور Configuring a password policy

  • پیکربندی گروه‌های IAM Configure IAM groups

  • پیکربندی کاربران IAM: کنسول وب Configure IAM users: Web console

  • چالش IAM IAM challenge

  • پیکربندی کاربران IAM: رابط خط فرمان Configure IAM users: CLI

  • گسترش CloudWatch Extending CloudWatch

  • بررسی شبیه‌ساز پالیسی IAM Exploring IAM policy simulator

  • نصب عامل (Agent) CloudWatch Install CloudWatch agent

3. دسترسی‌های چند حسابی 3. Multi-Account Access

  • درک مدیر دسترسی به منابع (RAM) Understanding Resource Access Manager

  • اعتبارسنجی مرکز هویت IAM Validating IAM Identity Center

  • درک مفهوم Organizations Understanding Organizations

  • درک مرکز هویت IAM Understanding IAM Identity Center

  • بررسی مرکز هویت IAM Exploring IAM Identity Center

  • درک مفهوم Control Tower Understanding Control Tower

  • بررسی مدیر دسترسی به منابع (RAM) Exploring Resource Access Manager

4. شناسایی و پاسخگویی 4. Detection and Response

  • بررسی Amazon Detective Exploring Amazon Detective

  • درک Amazon Inspector Understanding Amazon Inspector

  • درک Amazon Security Lake Understanding Amazon Security Lake

  • حذف سرور منبع Removing a source server

  • بررسی نتایج AWS Config Exploring AWS Config results

  • درک IoT Device Defender Understanding IoT Device Defender

  • پیکربندی بازیابی فاجعه الاستیک (EDR) Configuring Elastic Disaster Recovery

  • درک AWS GuardDuty Understanding AWS GuardDuty

  • درک Amazon Detective Understanding Amazon Detective

  • بررسی بازیابی فاجعه الاستیک AWS Exploring AWS Elastic Disaster Recovery

  • پیکربندی یک سرور منبع Configuring a source server

  • درک بازیابی فاجعه الاستیک AWS Understanding AWS Elastic Disaster Recovery

  • بررسی Amazon Inspector Exploring Amazon Inspector

  • رفع یافته‌های Inspector Resolving an Inspector finding

  • بررسی AWS GuardDuty Exploring AWS GuardDuty

  • بررسی بسته‌های انطباق (Conformance Packs) Exploring conformance packs

  • بررسی نتایج IAM Access Analyzer Exploring IAM Access Analyzer results

  • فعال‌سازی AWS Config Enabling AWS Config

  • درک AWS Config Understanding AWS Config

  • درک IAM Access Analyzer Understand IAM Access Analyzer

5. حفاظت از شبکه و اپلیکیشن 5. Network and Application Protection

  • درک AWS Shield Understand AWS Shield

  • درک فایروال شبکه AWS Understanding AWS Network Firewall

  • درک AWS Firewall Manager Understanding AWS Firewall Manager

  • پیکربندی فایروال اپلیکیشن وب (WAF) Configuring Web Application Firewall

  • درک DNS Firewall Understanding DNS Firewall

  • درک فایروال اپلیکیشن وب (WAF) Understand Web Application Firewall

  • اعتبارسنجی فایروال اپلیکیشن وب Validating Web Application Firewall

  • پیکربندی DNS Firewall Configuring DNS Firewall

  • درک AWS Verified Access Understand AWS Verified Access

  • بررسی فایروال اپلیکیشن وب Exploring Web Application Firewall

6. حفاظت از داده‌ها و عملیات 6. Data Protection and Operations

  • فعال‌سازی چرخش خودکار با Secrets Manager Enabling autorotation with Secrets Manager

  • درک Incident Manager Understanding Incident Manager

  • درک رمزنگاری پرداخت Understanding Payment Cryptography

  • ایجاد یک کلید KMS چند منطقه‌ای Creating a multi-region KMS key

  • حذف یک راز از Secrets Manager Deleting a Secrets Manager secret

  • پیاده‌سازی Systems Manager Implementing Systems Manager

  • درک سرویس مدیریت کلید (KMS) Understanding Key Management Service

  • بررسی نتایج Macie Exploring Macie results

  • استفاده از گواهینامه خصوصی Using a private certificate

  • فعال‌سازی رمزنگاری پیش‌فرض EBS Enabling EBS default encryption

  • ایجاد یک راز چند منطقه‌ای Creating a multi-region secret

  • درک Systems Manager Understanding Systems Manager

  • استفاده از Parameter Store Using Parameter Store

  • اتوماسیون چرخش کلید KMS Automating KMS key rotation

  • وصله کردن (Patching) با Systems Manager Patching with Systems Manager

  • استفاده از Secrets Manager Using Secrets Manager

  • ایجاد یک گواهینامه خصوصی Creating a private certificate

  • ایجاد گروه‌های منابع (Resource Groups) Creating Resource Groups

  • درک Secrets Manager Understanding Secrets Manager

  • استفاده از KMS و یک نقش IAM Using KMS and an IAM role

  • ایجاد یک کلید KMS Creating a KMS key

  • درک Amazon Macie Understanding Amazon Macie

  • رفع عدم انطباق با Systems Manager Resolving compliance with Systems Manager

  • پیکربندی یک Job در Macie Configuring a Macie job

  • درک AWS CloudHSM Understanding AWS CloudHSM

  • ایجاد یک مرجع گواهینامه خصوصی (Private CA) Creating a private certificate authority

  • حذف یک کلید KMS Deleting a KMS key

  • استفاده از KMS در S3 Using a KMS in S3

  • چالش: KMS Challenge: KMS

  • درک Certificate Manager Understand Certificate Manager

  • راهکار: KMS Solution: KMS

7. مدیریت دسترسی S3 7. S3 Access Management

  • بررسی نقاط دسترسی S3 (Access Points) Exploring S3 Access Points

  • اعتبارسنجی پالیسی سفارشی IAM S3 Validating custom IAM S3 policy

  • درک دسترسی عمومی در S3 Understanding public access in S3

  • بهترین روش‌های دسترسی عمومی S3 S3 public access best practices

  • درک نقاط دسترسی S3 Understanding S3 Access Points

  • راهکار: چالش چرخه عمر S3 Solution: S3 lifecycle challenge

  • درک S3 Access Grants Understanding S3 Access Grants

  • چالش: چالش تکثیر (Replication) S3 Challenge: S3 replication challenge

  • بررسی URLهای پیش‌امضا شده Exploring pre-signed URLs

  • مدیریت S3 با IAM Managing S3 with IAM

  • درک لیست‌های کنترل دسترسی S3 (ACL) Understanding S3 access control lists

  • بهره‌گیری از پالیسی‌های IAM S3 در EC2 Leveraging S3 IAM policies in EC2

  • بررسی گزینه‌های مدیریت S3 Exploring S3 management options

  • توضیح پالیسی‌های Bucket S3 با CLI Illustrating S3 bucket policies with CLI

  • دسترسی خصوصی به S3 Accessing S3 privately

  • درک طرح‌های حفاظت از داده‌ها Understanding data protection schemes

  • چالش: چالش چرخه عمر S3 Challenge: S3 lifecycle challenge

  • ایجاد یک پالیسی Bucket S3 Creating an S3 bucket policy

  • محدود کردن دسترسی S3 با IAM Restricting S3 access with IAM

  • پیکربندی دسترسی خصوصی S3 Configuring private S3 access

  • بهترین روش‌های امنیت و انطباق S3 S3 security and compliance best practices

  • راهکار: چالش تکثیر S3 Solution: S3 replication challenge

8. ممیزی‌های امنیتی در AWS 8. Security Audits in AWS

  • چرخش کلیدهای دسترسی Rotating access keys

  • آماده‌سازی برای ممیزی امنیتی Prepare for a security audit

  • درک AWS Security Hub Understanding AWS Security Hub

  • بررسی Trusted Advisor Exploring Trusted Advisor

  • درک Audit Manager Understanding Audit Manager

  • بررسی Audit Manager Exploring Audit Manager

  • درک Trusted Advisor Understanding Trusted Advisor

  • درک AWS Artifact Understand AWS Artifact

  • استفاده از AWS Security Hub Using AWS Security Hub

جمع‌بندی Conclusion

  • گام‌های بعدی Next steps

نمایش نظرات

آموزش راهنمای جامع مدیریت امنیت و انطباق در AWS
جزییات دوره
11h 51m
148
(آخرین آپدیت)
4,744
- از 5
دارد
دارد
دارد
Sharif Nijim
جهت دریافت آخرین اخبار و آپدیت ها در کانال تلگرام عضو شوید.

Google Chrome Browser

Internet Download Manager

Pot Player

Winrar

Sharif Nijim Sharif Nijim

استادیار تدریس در دانشگاه نوتردام

شریف نجیم استادیار تدریس در دانشگاه نوتردام است.

شریف در حال حاضر دوره های کارشناسی و کارشناسی ارشد تجزیه و تحلیل کسب و کار و فناوری اطلاعات را در دانشکده تجارت مندوزا در دانشگاه نوتردام تدریس می کند ، جایی که به عنوان استادیار فناوری اطلاعات ، تجزیه و تحلیل و عملیات. حوزه های اصلی تمرکز او شامل رایانش ابری ، تجزیه و تحلیل و معماری سازمانی است.

قبل از موقعیت فعلی خود ، شریف مدیر تضمین کیفیت و پروژه های ویژه TravelClick بود. او همچنین بنیانگذار و در هیئت مدیره یک شرکت یکپارچه سازی داده های مشتری خدمت کرد و بیش از یک دهه صرف ساخت سیستم های معاملاتی ، پشتیبانی تصمیم گیری و یکپارچه سازی داده های مشتری در کلاس سازمانی کرد.