CYS403
IN PROGRESSSecurity Risk Management, Governance and Control
CYS403 covers security risk management, governance, and control, including risk assessment methodologies, governance frameworks, security policy development, and compliance and audit practices. This section contains structured study material for understanding how organizations identify, evaluate, and manage information security risk.
This course focuses on establishing the balance between business needs and cybersecurity safeguards. It concentrates on the importance of the risk management framework and the detailed practical risk management framework. Besides, implementing and assessing security policies, as a risk mitigation technique, is discussed deeply based on business requirements. In addition, auditing, governance, controls, compliance, and standards are covered with proper case studies and exercises.
- Identify the issues and concerns indicative to protecting information, systems and users
- Apply the principles of cyber security risk management and a framework of components: identification, protection, detection, response and recovery
- Evaluate the types of policy, how policy is created, how to implement and manage policy, measurement practices, and audit of policy
- Apply cyber security protection mechanisms to help safeguard and protect information, systems and users
- Articulate cyber security imperatives to key decision makers and stakeholders in an organization
- Recognize the importance of compliance and training in information security risk management