
Start your career in cyber security and IT risk management with a bird's-eye view of core functions. Explore concise concepts you can apply at work and in interviews.
Explore the three lines of defense in cyber security, detailing the IT security, risk management, and IT audit teams and subteams such as IAM, DLP, SIEM, SOC, SIRT, and awareness.
Explore how risk management concepts and documented policies and standards guide security governance, with top-level support driving policy statements, standard controls, training, and compliance across the organization.
Explore the CIA triad of confidentiality, integrity, and availability and how misconfigurations and vulnerabilities threaten data, systems, and IT risk management.
Apply risk assessment methodology by calculating risk as the product of business impact and likelihood. Present results in plain English to reveal underlying factors and aid executive decision making.
Register every discovered risk in a risk register software, assign ownership and target closure dates. Tie outstanding risk items to department KRIs and KPIs to drive a prudent risk culture.
Layer security controls from the secure email gateway through endpoint protection and data loss prevention to stop phishing, malware, and data breaches, even if one control fails.
Maintain an up-to-date hardware inventory detailing ownership, purpose, and basic configurations to support vulnerability management and patching as the golden source, enabling theft detection and legal compliance.
Manage software inventory alongside hardware assets by tracking licenses, assignment, and purpose, enforce an approved software list, and prevent unapproved installations to protect against license infringements and data leaks.
verify a user's claimed identity using three authentication factors: something they know, something they have, and something they are. organizations should implement multi-factor authentication for critical access.
Understand how authorization differs from authentication and how applications use privilege tables to grant access, with Active Directory or single sign-on verifying identity and issuing tokens.
Organizations implement identity and access management to govern the full access lifecycle, from request and approval to provisioning and removal, with periodic, application-criticality reviews and access reassignments for department moves.
Discover how privileged access management (PAM) enforces just-in-time elevation and provisioning, the Palm workflow approvals, a short time window, and multi-factor authentication with comprehensive activity recording for audits.
Learn secure coding practices to reduce software vulnerabilities through manual reviews of critical modules like authentication and financial transactions, plus static, dynamic, and dependency analysis tools.
Record authentication, authorization, transaction, and privilege escalation attempts, regardless of outcome, to support investigations. Forward logs to a central server such as Splunk and restrict access to prevent tampering.
Implement active-active configurations for high availability across production and disaster recovery environments, and back up data to offline storage with periodic restarts for ransomware resilience.
Prioritize security awareness training to address the human element as the weakest link and increase the budget to secure staff from strangers and from clicking email links.
Learn how to segregate environments—development, system integration testing, user acceptance testing, staging, production, and disaster recovery—to prevent cross-environment issues and protect operations.
Implement segregation of duties to prevent fraud and errors by distributing duties across people. Separate development, quality assurance, testing, user acceptance testing, and production releases to maintain checks and balances.
Perform ethical hacking through penetration testing, including reconnaissance, scanning, vulnerability exploitation, and reporting, while comparing black, gray, and white box approaches and in-house versus external testers under regulations.
Understand ITSM onboarding as integrating an application with tools to manage ID services, covering types—general, changes, incidents, and problems—via a ticketing system from request to closure, with metrics for improvement.
Enable self assessment by application and system owners through design adequacy and operational effectiveness tests to validate policy compliance and protect portfolios against insecure password practices.
Compare hot, warm, and cold disaster recovery environments and active-active versus active-passive configurations, noting data loading, server boot times, and cost versus recovery time.
Assess third party risk by reviewing service level agreements, maintaining an inventory of service providers, and auditing vendor controls, policies, and certifications to ensure binding contracts and annual performance reviews.
Identify attack surfaces as entry points attackers exploit to access an organization, with surfaces for outsiders and insiders, including desktops, laptops, tablets, mobile devices, servers, routers, switches, and IoT devices.
Network access control validates devices before granting access to the internal network, separating sanctioned devices from personal ones. It assigns internet-only access or blocks internal connectivity based on policy.
Explore network segmentation and firewalling to limit attacker access by inspecting traffic with rules, and separate corporate, server, and dmz networks for secure, justified traffic.
Compare firewall and intrusion prevention systems, then show how an IPS scans incoming packets for attack signatures and drops traffic, including malformed packets and fingerprinting in the internal network.
Strategically deploy honeypots across critical network segments to monitor inbound traffic and provide early warnings to the IT security team.
Define and enforce a secure baseline for all platforms, monitor deviations, and remedy them; harden endpoints with non-admin accounts, approved software, usb protection, and centralized logging and group policy enforcement.
Explore how antivirus programs protect operating systems with signature-based protection using file hashes, behavior-based monitoring, and sandboxing to detect and quarantine malicious software.
Protect email and web channels by using security mail gateways, as Verizon's report shows 90 percent of cyber attacks come through email, with phishing emails the main threat.
Learn how web protection with secure web gateways defends the organization from web-based attacks by using reputation-based blocking, category-based content filtering, and malware scanning at the network edge.
Data loss prevention solutions safeguard confidential data, including personally identifiable information, by scanning email, web, print, and usb channels with regex patterns and hashing checks to prevent leaks.
Vulnerability scanners map the network, identify devices by IP, fingerprint the operating system and services (including port 22), and compare results to an internal database to reveal vulnerabilities.
Patch management applies security upgrades to platforms and applications in a timely manner through a proactive batch process that deploys patches as vendors release them, with critical patches applied promptly.
Secure IoT device ecosystems by integrating IP phones, printers, and conferencing devices into vulnerability scanning and patch management; segment them on separate networks and firewall rules to allow approved communications.
Generate strong passwords for sites, securely store them, and autofill credentials across platforms; secure access with a single master password and multi-factor authentication, including biometrics or one-time codes.
Learn how applications securely access secrets with a key management service and why hardcoding secrets in code is risky; compare encrypted files and environment variables as alternatives.
Complete the course and apply the cyber security and risk management overview to your enterprise. Share your feedback to help other students.
Access exclusive discount codes for all courses in cyber security and information technology risk management by visiting Resul Nasser's GitHub page and applying the coupon codes on Udemy.
This course provides a bird's eye view into the main concepts of Cyber Security and IT Risk Management as implemented within modern enterprises.
The course explains the below concepts in a concise manner:
Policies and Standards
Confidentiality, Integrity, Availability
Business Impact Assessment
Risk Assessment Methodology
Risk Register
Defense In Depth
Hardware Inventory
Software Inventory
Authentication
Authorization
Identity and Access Management (IAM)
Privileged Access Management (PAM)
Secure Coding
Logging
Backups
Security Awareness
Segregation of Environments
Segregation of Duties
Penetration Testing
ITSM Onboarding
IT Controls Testing
Disaster Recovery
Third Party Risk Assessment
Attack Surfaces
Network Access Control (NAC)
Network Segmentation and Firewalling
Intrusion Prevention System
Honeypots
Platform Hardening
Antivirus
Email Protection
Web Protection
Data Loss Prevention (DLP)
Vulnerability Scanning
Patching
IoT Device Security
Password Managers
Secrets Management Solution
Happy Learning and All the Best!!!