
Explore the constructs of information security management system, focusing on information as an asset, risk management, asset classification, threats, vulnerabilities, controls, and governance in a digital transformation era.
Define information as a valuable corporate asset that needs protection across its creation, transmission, and use. Identify risks and security controls (technical, physical, and logical) to ensure business continuity.
Examine the challenges of information management, highlighting the dominance of unstructured data on hard drives, the risk of lost knowledge, and five domains of availability, integrity, confidentiality, privacy, and non-repudiation.
Explore the factors of production—land, labor, capital, and entrepreneurship—and see how information and knowledge become a critical asset driving production and competitive advantage.
Learn how security and risk integration protect information as an asset in both personal and office environments, identify key business drivers, and mitigate data loss, fraud, and penalties.
Define information security as safeguarding an organisation's data to ensure availability, confidentiality, and integrity, through the CIA triad, safety in IT and OT integration, and best practices.
Learn how information risk management fits into an information security management system by identifying assets and threats, conducting risk assessment, applying controls, and communicating risk to protect crown jewels.
Learn to identify information assets and their types—information, software, physical, paper, service, and people—and how roles, asset registers, and CIA-based classification secure them.
Understand threats, vulnerabilities, and risk, and how counter measures protect information and operations. Learn threat origins, threat agents, and asset classifications to reduce exposure.
Explore control categories including administrative, operational, physical, and technical controls, and learn about preventive, detective, corrective, recovery, deterrent, and compensatory controls, with defense in depth.
Learn how information security governance ties law, organizational policy, standards, processes, and guidelines into a complete system, applying least privilege, defense in depth, minimization, zoning, and awareness.
Formalize the information security management system (ISMS) and explain its essential role for business, using policy, procedures, and risk-based controls to protect information assets including availability, integrity, and confidentiality.
Understand that company business is the key to implementing an ISMS that improves data protection, privacy, IT governance, compliance, cost efficiency, market edge, and the ISO 27001 framework.
Explore the ISO 27000 family and related standards that shape an information security management system, including ISO 27001, 27002, 27005, and the PDCA cycle for implementation.
Discover enterprise security architecture that connects people, process, and technology, highlighting identity and access management, vulnerability management, and intrusion prevention across networks, mobility, cloud, and IoT to protect data.
Design and implement an enterprise identity and access management architecture, including federated identity, entitlements and access certification, with adaptive access and siem integration for secure employee and partner access.
Explore security intelligence and event management within a security operations center, focusing on real-time data, logs, and threat intel guiding siem for enterprise monitoring.
Cyber threats are one of the most clear and present danger looming over organisation in the current digital world. Cyber security is an area where technology, people, process and control work together hand-in-gloves to thwart any information leak and hence saving organisation from financial and reputational loss. Information security is fundamental to cyber security as it prepares the organisation to defend the breach of information assets. Any organisation’s cyber security programs is a combination of security of IT and telecom infrastructure, application, data and people. This is the data, also called as Information, that is vital for organisation’s survival. Hence, Information security management is of fundamental importance in any cyber security initiative adopted my organisations.
In the new age of digital economy, organisations are struggling to protect their digital asset also called as Information. The Information security management system a.k.a ISMS is one of the framework for organisations to adopt to become proactive to the internal as well as external threat to information security. The risk of information security breach is far-fetched than the old days phenomenon. These RISKs are not only monetary but also brand image, collapse of a business, property damage etc.
The five axes of digital technology viz. Social, Mobility, Analytics, Cloud and Internet of Everything(IOE) are disrupting the conventional method of doing business. Not adopting these technologies is questioning the basic survivability of organisation. As these technologies are getting adopted, the threat surface for information security breach has multiplied many folds. However, only technology does not lead to a super cyber defence mechanism. As high as, 90% of the information security breach has been attributed to employee or partners and their awareness of information security.
Hence, a good information security management system does not have technology as the only facet, but it has people, process, policy and guidelines as the governing principles with ever evolving strategy tuned to the emerging threat vectors in cyber world.
As a matter of fact, a new employee is required to sign information security non-disclosure and compliance document when they join an organisation. But is that effective? Do organisations see the informal chit-chat among employee a threat? Why can’t they create a work culture where information security become a habit of employees like the personal and family security engrained in their habits.
This course is all about understanding the components of information security management systems. It will bring clarity to technical person about the importance of people, process, policy and controls that governs the information security management in an organisation. This is a must course for all seeking a corporate career and being a good corporate citizen. Also, this is the first step for seeking a career in information security management with a gradual rise to the top position in Information security domain in corporate also called as Chief Information Security Officer(CISO).
This course dissects the information security myth from enterprise architect's point of view with the course name titled ‘Constructs of Information Security Management System’. It systematically builds from information to information security to all elements of ISMS starting with fundamental of information characteristics also called as Confidentiality, Integrity, Availability(CIA). As you know information security is the major building block toward a step toward cyber security, learning ISMS basics is a must for all.
As a bonus lecture, three lectures has been addd for the professionals who wants to understand the Enterprize Security Architecture from a technology deployment perspective. This will help the working professional to decide which all technology elements to be implemented in order to secure the enterprise information and be ready to response to a cyber attack. The Chief Enterprize Security Officer (CISO) will have a refresher on technology elements.