ENTERPRISE DATA PROTECTIONENGINEERING MASTERCLASS

Protecting Sensitive and Personal Data in Windows Enterprise Environments

ข้อมูลได้กลายเป็นหนึ่งในทรัพย์สินที่สำคัญที่สุดขององค์กร โดยเฉพาะข้อมูลส่วนบุคคล ข้อมูลลูกค้า ข้อมูลประชาชน ข้อมูลบุคลากร ข้อมูลทางการเงิน เอกสารสำคัญ และฐานข้อมูลขององค์กร การมี Firewall, Antivirus หรือระบบรักษาความปลอดภัยเครือข่ายเพียงอย่างเดียว ไม่เพียงพอที่จะป้องกันข้อมูลจากการถูกเข้าถึง คัดลอก ขโมย ทำลาย หรือส่งออกไปยังภายนอกองค์กร

หลักสูตร Enterprise Data Protection Engineering Masterclass ออกแบบขึ้นเพื่อให้ผู้เรียนสามารถสร้าง
มาตรการปกป้องข้อมูลแบบครบวงจร ครอบคลุม Data at Rest, Data in Transit และ Data in Use รวมถึง Data Loss Prevention, Insider Threat Detection, Security Monitoring, Protected Backup และ Cyber Recovery โดยใช้ Microsoft Windows Enterprise Environment เป็นระบบหลัก และ Linux เฉพาะระบบสนับสนุนบางส่วน

หลักสูตรเน้น Security Engineering และการพิสูจน์ประสิทธิผลของมาตรการป้องกัน ไม่ผูกติดกับผลิตภัณฑ์ใด
ผลิตภัณฑ์หนึ่ง ผู้เรียนจะได้ลงมือสร้าง กำหนด Policy ทดสอบ ตรวจสอบเหตุการณ์ ตอบสนองและกู้คืนข้อมูล
ผ่านสถานการณ์จำลองที่ใกล้เคียงกับองค์กรจริง

วัตถุประสงค์ของหลักสูตร

  • ประเมินความเสี่ยงต่อข้อมูลสำคัญและสร้าง Sensitive Data Inventory
  • ออกแบบ Data Classification และ Data Handling Policy
  • ควบคุมสิทธิ์ด้วย Active Directory, RBAC, Least Privilege และ Windows File Server Security
  • ปกป้องข้อมูลขณะจัดเก็บด้วย BitLocker, EFS และ Enterprise Encryption Strategy
  • ปกป้องข้อมูลระหว่างรับส่งด้วย SMB Encryption, TLS/HTTPS, PKI และ Certificate-based Authentication
  • ออกแบบ Data Loss Prevention สำหรับ USB, Email, Web/Cloud, Clipboard และ Printing
  • ตรวจจับการเข้าถึงหรือเปลี่ยนแปลงข้อมูลผิดปกติด้วย Windows Auditing, Sysmon และ Wazuh
  • ใช้ AI ช่วยทำ Event Correlation, Timeline Analysis, Risk Assessment และ Incident Reporting
  • ออกแบบ Protected/Immutable Backup และทดสอบ Cyber Recovery
  • จัดทำ Data Breach Incident Response Procedure และ Enterprise Data Protection Architecture

หลักสูตรนี้เหมาะสมกับ

  • IT Manager / Infrastructure Manager
  • Cybersecurity Manager / Security Engineer / SOC Analyst
  • System Administrator / Windows Server Administrator
  • Network & Security Administrator
  • Data Protection Officer (DPO)
  • IT Auditor / Internal Auditor / Risk Management
  • เจ้าหน้าที่ IT ของหน่วยงานภาครัฐ รัฐวิสาหกิจ และองค์กรที่จัดเก็บข้อมูลส่วนบุคคลหรือข้อมูลสำคัญจำนวนมาก

ความรู้พื้นฐานของผู้เข้าอบรม

  • Microsoft Windows 10/11 และ Windows Server เบื้องต้น
  • Active Directory เบื้องต้น
  • TCP/IP Networking
  • Cybersecurity Fundamentals
  • ไม่จำเป็นต้องมีความรู้ Linux เชิงลึก

รูปแบบการอบรม

องค์ประกอบสัดส่วนแนวทาง
Concept / Architecture20%แนวคิด การออกแบบ Best Practice และ Common Failure
Hands-on / Simulation80%ติดตั้ง ตั้งค่า ทดสอบ ตรวจจับ ตอบสนอง และกู้คืน

รายละเอียดหลักสูตร

DAY 1: Protecting Sensitive Data at Rest & Controlling Access

Module 1: Understanding Enterprise Data Protection

  • Modern Data Breach and Data Exfiltration Scenarios
  • External Attack, Insider Threat and Compromised Account
  • Data Discovery, Collection, Staging and Exfiltration
  • Ransomware and Data Extortion
  • Enterprise Data Lifecycle: Create, Store, Access, Share, Transfer, Backup, Archive and Destroy
  • Sensitive Data, Personal Data, PII, Citizen Information and Business-Critical Information

Module 2: Data Discovery & Classification

  • Sensitive Data Discovery and Unmanaged Data
  • Building Sensitive Data Inventory
  • Data Classification: Public, Internal, Confidential, Restricted and Highly Restricted
  • Data Handling Rules for Storage, Email, USB, Printing, Cloud, Backup, Retention and Destruction

Module 3: Identity and Access Protection

  • Active Directory as Identity Foundation
  • Security Groups and Administrative Separation
  • Least Privilege, Need-to-Know and Role-Based Access Control
  • AGDLP / AGUDLP
  • NTFS and Share Permissions
  • Permission Inheritance and Effective Access
  • Access-Based Enumeration
  • FSRM

Module 4: Protecting Data at Rest

  • Full-Disk, Volume and File-Level Encryption
  • BitLocker, TPM and Recovery Key
  • BitLocker Group Policy Deployment
  • BitLocker To Go
  • EFS and Data Recovery
  • Key Storage, Recovery, Rotation and Separation of Duties

Hands-on Workshops

  • Lab 1: Build the Enterprise Data Protection Lab Environment
  • Lab 2: Build a Synthetic Citizen and Sensitive Data Repository
  • Lab 3: Discover Sensitive Data with PowerShell
  • Lab 4: Find Dangerous File Server Permissions
  • Lab 5: Implement Enterprise Role-Based Access Control
  • Lab 6: Build a Data Classification & Handling Matrix
  • Lab 7: Protect Windows Endpoints with BitLocker
  • Lab 8: Protect Removable Media with BitLocker To Go and Group Policy
  • Lab 9: Harden Windows File Server with Least Privilege, ABE and FSRM

DAY 2: Protecting Data in Transit & Preventing Data Leakage

Module 5: Protecting Data in Transit

  • Risks of Unencrypted Communication
  • SMB Encryption and SMB Signing
  • Disabling SMBv1
  • TLS/HTTPS Protection
  • Certificate Authentication and Lifecycle

Module 6: Enterprise PKI & Secure Access

  • Active Directory Certificate Services
  • Enterprise CA and Certificate Templates
  • Auto Enrollment and Revocation
  • Mutual TLS
  • Separate Administrative Accounts
  • RDP Hardening and Windows Firewall Restrictions
  • Administrative Workstation and Jump Server Concepts
  • PowerShell Remoting Security and Administrative Logging

Module 7: Enterprise Data Loss Prevention

  • Endpoint, Network, Email and Cloud DLP
  • USB, External Disk, Email Attachment, Web Upload and Cloud Storage
  • Clipboard, Printing, Screenshot and Archive Risks
  • Monitor, Alert, Warn and Block
  • User Justification, Exception and Approval Workflow
  • Microsoft Purview / Commercial DLP Evaluation Concepts

Module 8: Insider Threat Protection

  • Malicious, Negligent and Compromised Insider
  • Privileged User Risk
  • Abnormal File Access
  • Mass File Reading / Copy
  • Data Staging and Archive Creation
  • Off-hours Access
  • Behavior-based Detection

Hands-on Workshops

  • Lab 10: Capture and Compare Unprotected versus Protected Traffic
  • Lab 11: Protect File Transfer with SMB Encryption
  • Lab 12: Harden SMB with Signing and Legacy Protocol Removal
  • Lab 13: Build an Enterprise PKI with AD CS
  • Lab 14: Protect an Internal Web Application with HTTPS
  • Lab 15: Implement Mutual TLS
  • Lab 16: Secure Administrative Access
  • Lab 17: Test and Prevent USB Data Leakage
  • Lab 18: Implement Enterprise DLP Policy using a Trial/Enterprise Platform

DAY 3: Detecting Data Breach, AI Analysis & Cyber Recovery

Module 9: Monitoring Sensitive Data

  • Windows Advanced Audit Policy
  • Object Access and File System Auditing
  • Logon and Removable Storage Auditing
  • Sysmon: Process, File, Network and PowerShell Telemetry
  • Windows Event Forwarding
  • Wazuh Centralized Monitoring

Module 10: File Integrity & Data Exfiltration Detection

  • File Integrity Baseline
  • Create, Modify, Rename and Delete Detection
  • Hash Verification
  • User and Process Attribution
  • Unusual User / Time / Volume
  • Mass File Access and Data Staging
  • AI-assisted Event Correlation, Timeline Reconstruction, Risk Scoring, RCA and MITRE ATT&CK Mapping

Module 11: Ransomware & Backup Protection

  • Backup Threat Model and Credential Separation
  • Backup Network Isolation and Encryption
  • Offline, Off-site and Immutable Backup
  • RPO, RTO and Retention
  • Restore Testing and Integrity Verification
  • Ransomware Recovery Workflow: Detect, Isolate, Restore, Validate and Return to Production

Module 12: Data Breach Incident Response

  • Alert Validation and Data Impact Assessment
  • Account Containment and Endpoint Isolation
  • Evidence Preservation and Incident Timeline
  • Identifying Data Access and Possible Exfiltration
  • Credential / Key / Certificate Rotation
  • Data Restore and Integrity Verification
  • Technical Incident Report, Root Cause, Corrective Action and Executive Reporting

Hands-on Workshops

  • Lab 19: Enable Advanced Auditing for Sensitive Data
  • Lab 20: Deploy Sysmon Security Telemetry
  • Lab 21: Deploy Wazuh File Integrity Monitoring
  • Lab 22: Detect an Insider Data Exfiltration Scenario
  • Lab 23: Perform AI-Assisted Data Breach Investigation
  • Lab 24: Implement Protected Backup and Recovery
  • Lab 25: Perform a Safe Ransomware Recovery Exercise