Contact
SYS_TIME [ 00 00 00 ]

CYS403

IN PROGRESS

Security Risk Management, Governance and Control

CYS403 covers security risk management, governance, and control, including risk assessment methodologies, governance frameworks, security policy development, and compliance and audit practices. This section contains structured study material for understanding how organizations identify, evaluate, and manage information security risk.

Course Code CYS403
Credit Hours 3
Prerequisites CYS401

This course focuses on establishing the balance between business needs and cybersecurity safeguards. It concentrates on the importance of the risk management framework and the detailed practical risk management framework. Besides, implementing and assessing security policies, as a risk mitigation technique, is discussed deeply based on business requirements. In addition, auditing, governance, controls, compliance, and standards are covered with proper case studies and exercises.

0x01Cybersecurity — Emerging TechnologiesIDX_01
0x02Security Risk Management, Governance & ControlIDX_02
0x03Threat & Vulnerability ManagementIDX_03
0x04Cybersecurity Policy FrameworkIDX_04
0x05The Risk Management LifecycleIDX_05
0x06Risk ProfilingIDX_06
0x07Formulating a RiskIDX_07
0x08Risk Exposure FactorsIDX_08
0x09Security Controls & ServicesIDX_09
0x0ARisk Evaluation & Mitigation StrategiesIDX_0A
0x0BRisk Assessment TechniquesIDX_0B
0x0CCyber Risk Governance & StandardsIDX_0C
0x0DBuilding a Risk Management Plan from ScratchIDX_0D
  • Identify the issues and concerns indicative to protecting information, systems and users
  • Apply the principles of cyber security risk management and a framework of components: identification, protection, detection, response and recovery
  • Evaluate the types of policy, how policy is created, how to implement and manage policy, measurement practices, and audit of policy
  • Apply cyber security protection mechanisms to help safeguard and protect information, systems and users
  • Articulate cyber security imperatives to key decision makers and stakeholders in an organization
  • Recognize the importance of compliance and training in information security risk management
0x01Quizzes10%
0x02Major Exam20%
0x03Assignments10%
0x04Attendance5%
0x05Project15%
0x06Final Examination40%