Skip to content
Deep Creek Center home.
  • Scrum
    • Scrum Master Certified
    • Scrum Developer Certified
    • Scrum Product Owner Certified
    • Agile Expert Certified
  • BA / BRM
    • Business Analysis For The IT Professional
    • Modeling Techniques For The Business Analyst
    • Software Quality Assurance
    • Effective Methods Of Software Testing Workshop
    • Effective Use Case Development
    • Business Relationship Management
    • Business Relationship Management Professional (BRMP®)
  • ITIL
    • ITIL 5 Foundations
    • ITIL Specialist: Create, Deliver, and Support
    • ITIL Specialist: Drive Stakeholder Value
    • ITIL Specialist: High Velocity IT
    • ITIL Strategist: Direct, Plan, and Improve
  • Governance
  • Project Management
  • Contact us

Category: Default

Making sense of cloud computing – Part 1

One of our customers asked us to produce a short course on Cloud Computing. While it’s always easy to chalk this up to yet another round of IT Buzzword BINGO, the business models driving the interest in cloud computing are real, important, and must be understood if you want to be able to sustain your service value for your customers. This week, we’re going to look at a number of different aspects of cloud computing and why they matter. We’ll also take an honest look at the challenges that these models create, especially for security and privacy.

Today: Financial Models and Utility Computing

Most IT managers and staff are used to working with tangible service assets they own; hardware, software, tools, and other assorted infrastructure, applications, and platforms. Based on our available resources and organizational capabilities (knowledge, skills, processes, etc.), we would design, plan, develop (or buy), and deploy services in support of our clients. This required the IT organization to use the business’s capital to invest in IT assets, which may or may not be optimally utilized (consider hardware utilization, applications and associated licenses, data center infrastructure and environments, etc.) Capital investments require a substantial commitment of time and upfront money to create a capability, long before a payback period begins (when the new service is delivering value in operations). If the business’s needs evolve, substantial changes in service warranty are needed (capacity, service continuity, security, and availability) and will require re-architecture  re-provisioning, and ultimately waste time and resources.

Most businesses seek a different model (and not just for IT!). Businesses generally prefer operating costs (pay-as-you-go) to capital costs, because we can stop buying it if we don’t need it, or request more capacity or a different level of continuity or security (availability is a bit messier, as we’ll discuss later this week) for an understood price per service. Utility Computing is really nothing more than delivering on the promise of ITIL Service Level Management, where for an understood and agreed price we will deliver an agreed level of service at a defined level of quality. The biggest difference then is WHERE we will deliver it…

In the Cloud Computing context, as with the ITIL Service Model, we seek to deliver value to customers while avoiding the ownership of certain costs and risks. Depending on the level of Cloud Computing your organization may consider, this includes potentially choosing not to own

– Applications – we’ll use providers with SaaS (software-as-a-service) models to host and deliver key software applications, especially generic ones like productivity applications (a la Google docs) and ones where access across a number of devices and locations is a strong benefit (CRM applications like salesforce.com)

– (Development) Platforms – we’ll count on our cloud providers to provide our developers with rich toolsets for building and deploying cloud applications; for example, Microsoft Azure extends .NET developers tools to build in the cloud.

– Infrastructure – we’ll take advantage of the benefits of server virtualization, grid computing use of processing capabiliites, and enormous server farms managed by providers such as Amazon, Google, IBM, and many others to scale our storage, data management, and processing needs as they evolve, and make agility and real Capacity management far more accessible and realistic.

As our ITIL readers know, effective provisioning of whole services to customers involve the correct combination of these three things aligned with the business’s needs and managed to deliver a reliable underpinning of their key business processes. Clearly cloud computing has enormous implications for the entire service lifecycle. To deliver “utility” computing, we must do more than just create pay-as-you-go models; we must actually deliver the right level of utility!

Next time, we’ll talk about Cloud Architecture.

Posted in DefaultTagged cloud computing, Financial Models, Utility Computing

CEH

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Course Description

This class will immerse the student into an interactive environment where they will be shown how to scan, test, hack and secure their own systems. The lab intensive environment gives each student in-depth knowledge and practical experience with the current essential security systems. Students will begin by understanding how perimeter defenses work and then be lead into scanning and attacking their own networks, no real network is harmed. Students then learn how intruders escalate privileges and what steps can be taken to secure a system. Students will also learn about Intrusion Detection, Policy Creation, Social Engineering, DDoS Attacks, Buffer Overflows and Virus Creation. When a student leaves this intensive 5-day class they will have hands-on understanding and experience in Ethical Hacking.

Who Should Attend?

This course will significantly benefit security officers, auditors, security professionals, site administrators, and anyone who is concerned about the integrity of the network infrastructure.

Course Length

5 days

Course Outline

  • Introduction to Ethical Hacking
  • Footprinting and Reconnaissance
  • Scanning Networks
  • Enumeration
  • System Hacking
  • Trojans and Backdoors
  • Viruses and Worms
  • Sniffers
  • Social Engineering
  • Denial of Service
  • Session Hijacking
  • Hacking Webservers
  • Hacking Web Applications
  • SQL Injection
  • Hacking Wireless Networks
  • Hacking Mobile Platforms
  • Evading IDS, Firewalls, and Honeypots
  • Buffer Overflow
  • Cryptography
  • Penetration Testing

Course Director

Patrick von Schlag
Mr. von Schlag has more than 25 years of real-world experience managing IT and business organizations. He has served as a consultant, facilitator, and instructor in support of more than 200 ITSM program deployments, with a focus on practical benefits. He holds all 11 ITIL 2011 certifications and runs an accredited learning consultancy focused on Making ITIL Work ™ in real organizations. His customer list includes The Walt Disney Company, Microsoft, Nike, Sears, US Marine Corps, US Army, US Air Force, 2nd and 5th Fleet US Navy, DISA, IRS, Federal Reserve, The Hartford, Citigroup, Amgen, Los Angeles County, Port of Long Beach, GDIT, Accenture, Serco, Deloitte, and hundreds of other market-leading companies.

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Posted in Default

CISSP

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Course Description

In this course, students will analyze a wide range of information systems security subjects that are organized into 10 domains for CISSP exam certification.

Who Should Attend?

This course is intended for experienced IT security-related practitioners, auditors, consultants, investigators, or instructors, including network or security analysts and engineers, network administrators, information security specialists, and risk management professionals, who are pursuing CISSP training and certification to acquire the credibility and mobility to advance within their current computer security careers or to migrate to a related career. Through the study of all 10 CISSP CBK domains, students will validate their knowledge by meeting the necessary preparation requirements to qualify to sit for the CISSP certification exam. The CISSP exam is intentionally difficult and should not be taken lightly. Even students with years of security experience should assume that they will have additional study time after class. Because the domains are so varied, it is unlikely that any one student will have experience in all 10 domains.

Course Length

5 days

Course Outline

Lesson 1: Information Systems Access Control

  • Data Access Principles
  • System Access and Authentication
  • Penetration Tests

Lesson 2: Security Architecture and Design

  • Security Models
  • Security Modes
  • System Assurance

Lesson 3: Network and Telecommunications Security

  • Data Network Design
  • Remote Data Access
  • Data Network Security
  • Data Network Management

Lesson 4: Information Security Management Goals

  • Organizational Security
  • The Application of Security Concepts

Lesson 5: Information Security Classification and Program Development

  • Information Classification
  • Security Program Development

Lesson 6: Risk Management and Ethics

  • Risk Management
  • Ethics

Lesson 7: Software Development Security

  • Software Configuration Management
  • Software Controls
  • Database System Security

Lesson 8: Cryptography

  • Ciphers and Cryptography
  • Symmetric-Key Cryptography
  • Asymmetric-Key Cryptography
  • Hashing and Message Digests
  • Email, Internet, and Wireless Security
  • Cryptographic Weaknesses

Lesson 9: Physical Security

  • Physical Access Control
  • Physical Access Monitoring
  • Physical Security Methods
  • Facilities Security

Lesson 10: Operations Security

  • Operations Security Control
  • Operations Security Auditing and Monitoring
  • Operational Threats and Violations

Lesson 11: Business Continuity and Disaster Recovery Planning

  • Business Continuity Plan Fundamentals
  • Business Continuity Plan Implementation
  • Disaster Recovery Plan Fundamentals
  • Disaster Recovery Plan Implementation

Lesson 12: Legal, Regulations, Compliance, and Investigations

  • Computer Crime Laws and Regulations
  • Computer Crime Incident Response

Prerequisites

It is highly recommended that students have certifications in Network+ or Security+, or possess equivalent professional experience upon entering CISSP training. It will be beneficial if students have one or more of the following security-related or technology-related certifications or equivalent industry experience: MCSE, MCTS, MCITP, SCNP, CCNP, RHCE, LCE, CNE, SSCP®, GIAC, CISA™, or CISM®. It is highly recommended that students have certifications in Network+ or Security+, or possess equivalent professional experience upon entering CISSP training. It will be beneficial if students have one or more of the following security-related or technology-related certifications or equivalent industry experience: MCSE, MCTS, MCITP, SCNP, CCNP, RHCE, LCE, CNE, SSCP®, GIAC, CISA™, or CISM®.

Course Director

Patrick von Schlag
Mr. von Schlag has more than 25 years of real-world experience managing IT and business organizations. He has served as a consultant, facilitator, and instructor in support of more than 200 ITSM program deployments, with a focus on practical benefits. He holds all 11 ITIL 2011 certifications and runs an accredited learning consultancy focused on Making ITIL Work ™ in real organizations. His customer list includes The Walt Disney Company, Microsoft, Nike, Sears, US Marine Corps, US Army, US Air Force, 2nd and 5th Fleet US Navy, DISA, IRS, Federal Reserve, The Hartford, Citigroup, Amgen, Los Angeles County, Port of Long Beach, GDIT, Accenture, Serco, Deloitte, and hundreds of other market-leading companies.

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Posted in Default

CISM

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Course Description

The focus of this course is in-depth coverage of the four domains required to pass the CISM exam:

  • Information Security Governance
  • Information Risk Management and Compliance
  • Information Security Program Development and Management
  • Information Security Incident Management

Who Should Attend?

Experienced information security managers and those who have information security management responsibilities, including IT consultants, auditors, managers, security policy writers, privacy officers, information security officers, network administrators, security device administrators, and security engineers.

Course Outline

Testing-Taking Tips and Study Techniques

  • Preparation for the CISM exam
  • Submitting Required Paperwork
  • Resources and Study Aids
  • Passing the Exam the First Time

Information Security Governance

  • Asset Identification
  • Risk Assessment
  • Vulnerability Assessments
  • Asset Management

Information Risk Management

  • Asset Classification and Ownership
  • Structured Information Risk Assessment Process
  • Business Impact Assessments
  • Change Management

Information Security Program Development

  • Information Security Strategy
  • Program Alignment of Other Assurance Functions
  • Development of Information Security Architectures
  • Security Awareness, Training, and Education
  • Communication and Maintenance of Standards, Procedures, and Other Documentation
  • Change Control
  • Lifecycle Activities
  • Security Metrics

Information Security Program Management

  • Security Program Management Overview
  • Planning
  • Security Baselines
  • Business Processes
  • Security Program Infrastructure
  • Lifecycle Methodologies
  • Security Impact on Users
  • Accountability
  • Security Metrics
  • Managing Resources

Incident Management and Response

  • Response Management Overview
  • Importance of Response Management
  • Performing a Business Impact Analysis
  • Developing Response and Recovery Plans
  • The Incident Response Process
  • Implementing Response and Recovery Plans
  • Response Documentation
  • Post-Event Reviews

Review and Q&A Session

  • Final Review and Test Prep

Prerequisites

Five years of experience with audit, IT systems, and security of information systems; systems administration experience; familiarity with TCP/IP; and an understanding of UNIX, Linux, and Windows. This advanced course also requires intermediate-level knowledge of the security concepts covered in our Security+ course.

Exam

The CISM exam is offered three times a year (June, September and December) and consists of 200 multiple-choice questions. The CISM exam is focused on the four domains defined by Information Systems Audit and Control Association (ISACA).

Course Director

Patrick von Schlag
Mr. von Schlag has more than 25 years of real-world experience managing IT and business organizations. He has served as a consultant, facilitator, and instructor in support of more than 200 ITSM program deployments, with a focus on practical benefits. He holds all 11 ITIL 2011 certifications and runs an accredited learning consultancy focused on Making ITIL Work ™ in real organizations. His customer list includes The Walt Disney Company, Microsoft, Nike, Sears, US Marine Corps, US Army, US Air Force, 2nd and 5th Fleet US Navy, DISA, IRS, Federal Reserve, The Hartford, Citigroup, Amgen, Los Angeles County, Port of Long Beach, GDIT, Accenture, Serco, Deloitte, and hundreds of other market-leading companies.

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Posted in Default

CISA

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Course Description

The field of information systems is growing and changing at an increasingly fast pace. Organizations are investing in and relying on a secure and efficient IT infrastructure to maintain business and meet business goals and objectives. Information systems auditing plays a crucial role in developing and maintaining this business environment. The information systems auditor is responsible for evaluating security in all aspects of the infrastructure and to also guide business leaders in maintaining a secure organization. This course can enable you to evaluate the security and controls of the organization’s business structure and governance methods; the policies, procedures, and guidelines used; and the overall security of the business environment. In addition, this course will help you in your preparation if you plan to pursue the ISACA® CISA® certification examination. The intended audience for this course is information systems security professionals and internal review auditors and other individuals who have an interest in aspects of information systems audit, controls, and security. While this course will help prepare candidates for the CISA exam, it is not the only preparation that should be used. ISACA requires that the successful CISA candidate have at least five years of professional experience; because of this, the CISA exam will draw on material and experience that is beyond the scope of any single training course, most notably covering database administration, network components and theory, software and operating systems, and hardware devices. Candidates who wish to solidify their understanding of this material might choose to take additional training in these areas if they don’t feel their professional experience is sufficient.

In this course, you will perform evaluations of organizational policies, procedures, and processes to ensure that an organization’s information systems align with overall business goals and objectives.

Course Length

20 hours

Course Outline

The Information Systems Audit Process
Lesson Introduction
ISACA Information Systems Auditing Standards and Guidelines
Develop and Implement an Information Systems Audit Strategy
Plan an Audit
Conduct an Audit
The Evidence Lifecycle
Communicate Issues, Risks, and Audit Results
Support the Implementation of Risk Management and Control Practices
Lesson Lab
Lesson Follow Up

IT Governance
Lesson Introduction
Evaluate the Effectiveness of IT Governance
Evaluate the IT Organizational Structure
Evaluate the IT Strategy
Evaluate IT Policies, Standards, and Procedures for Compliance
Ensure Organizational Compliance
IT Resource Investment, Use, and Allocation Practices
Evaluate IT Contracting Strategies and Policies
Evaluate Risk Management Practices
Performance Monitoring and Assurance Practices
Lesson Lab
Lesson Follow Up

Systems and Infrastructure Lifecycle Management
Lesson Introduction
Determine the Business Case for Change
Evaluate Project Management Frameworks and Governance Practices
Perform Periodic Project Reviews
Evaluate Control Mechanisms for Systems
Evaluate Development and Testing Processes
Evaluate Implementation Readiness
Evaluate a System Migration
Lesson Lab
Lesson Follow Up

Systems and Infrastructure Lifecycle Maintenance
Lesson Introduction
Perform a Post-Implementation System Review
Perform Periodic System Reviews
Evaluate the Maintenance Process
Evaluate the Disposal Process
Lesson Lab
Lesson Follow Up

IT Service Delivery and Support
Lesson Introduction
Evaluate Service Level Management Practices
Evaluate Operations Management
Evaluate Data Administration Practices
Evaluate the Use of Capacity and Performance Monitoring Methods
Evaluate Change, Configuration, and Release Management Practices
Evaluate Problem and Incident Management Practices
Evaluate the Functionality of the IT Infrastructure
Lesson Lab
Lesson Follow Up

Protection of Information Assets
Lesson Introduction
Information Security Design
Encryption Basics
Evaluate the Design, Implementation, and Monitoring of Logical Access Controls
Evaluate the Design, Implementation, and Monitoring of Physical Access Controls
Evaluate the Design, Implementation, and Monitoring of Environmental Controls
Evaluate Network Infrastructure Security
Evaluate the Confidential Information Processes and Procedures
Lesson Lab
Lesson Follow Up

Business Continuity and Disaster Recovery
Lesson Introduction
Evaluate the Adequacy of Backup and Restore
Evaluate the BCP and DRP
Lesson Lab
Lesson Follow Up

Course Director

Patrick von Schlag
Mr. von Schlag has more than 25 years of real-world experience managing IT and business organizations. He has served as a consultant, facilitator, and instructor in support of more than 200 ITSM program deployments, with a focus on practical benefits. He holds all 11 ITIL 2011 certifications and runs an accredited learning consultancy focused on Making ITIL Work ™ in real organizations. His customer list includes The Walt Disney Company, Microsoft, Nike, Sears, US Marine Corps, US Army, US Air Force, 2nd and 5th Fleet US Navy, DISA, IRS, Federal Reserve, The Hartford, Citigroup, Amgen, Los Angeles County, Port of Long Beach, GDIT, Accenture, Serco, Deloitte, and hundreds of other market-leading companies.

[button color=”#000000″ background=”#ff9900″ size=”large” src=”./call-schedule”]Register Now![/button]

Posted in Default

Introducing how-to videos on ITIL core concepts

In the very near future, we willl be introducing a series of short “How to” ITIL videos on this blog that will focus on implementing ITIL core concepts effectively in the real world. Since the ITIL is not a theory, but an aggregation of practical strategies for managing and supporting IT services, many of my customers get caught up in the lingo and don’t spend enough time “doing” ITIL. We’ll look at one section each week from Strategy, Design, Transition, Operation, and Improvement and describe some specific how-tos that have worked for customers of ours that you will likely find effective in your organizations too. Please feel free to react to what you see and post your own advice and guidance based on your experiences!

Posted in Default, ITSMTagged core ITIL concepts, how to, video

Footer

Copyright © 2026. All rights reserved. Deep Creek Center. Privacy Policy | Terms of Service | Sitemap