
Explore information systems as interrelated components that collect, process, store, and distribute data to support decision-making and control, including e-commerce, TPS, MIS, DSS, and AI applications.
Protect information and information systems from unauthorized access, disruption, modification, or destruction by applying the CIA triad: confidentiality, integrity, availability, and the three A's—authentication, authorization, and accounting.
Information security protects businesses as information technology and the internet expand, countering cybercrime, including malware, social engineering, phishing, spam, botnets, financial frauds, data theft, industrial espionage, and denial of service.
explore how security breaches and cyber attacks cause multimillion-dollar losses, disrupt operations, and damage reputation, including defaced websites and downtime scenarios.
Learn a holistic approach to information security that protects assets across hardware, software, data, procedures, records, and even human resources, including emails and conversations, to prevent breaches.
Protect information and information systems using availability, integrity, authentication, confidentiality, and non repudiation within the identify, protect, detect, respond, recover paradigm, and support continuous monitoring and a recovery plan.
Learn how information risk management identifies, assesses, controls, and reviews risks to protect information assets from physical damage, human actions, equipment malfunctions, attacks, data misuse, and application errors.
Identify risks and apply both qualitative and quantitative risk analysis to rate likelihood and impact, using risk matrices to prioritize, monitor, and manage threats, vulnerabilities, and asset values.
Explore defense in depth through layered security that protects systems even when one control fails, integrating people, technology, and operations with monitoring and security metrics.
Master contingency planning by integrating business impact analysis, incident response, disaster recovery, and business continuity, including preparation, identification, containment, eradication, and recovery, plus hot, warm, and cold sites.
Apply information security concepts from the ground up, starting with physical security and data security, then address systems and network security, policies, and employee training and awareness.
Explain how physical security protects facilities, data, and personnel through facility requirements, access controls, and administrative, technical, and physical controls, with contingency operations and offsite backups.
Develop data classification using a system that analyzes structured and unstructured data, assigns value tags, and classifies data into public, private, confidential, and restricted levels to guide risk and governance.
Explore access control models—role based access control (RBC), discretionary access control (DAC), and mandatory access control (MAC)—and how roles, ownership, and security labels determine who can view data.
Information security relies on robust systems and networks, with firewalls enforcing policies at network borders. Packet filtering, stateful inspection, and application and circuit level gateways provide layered protection.
Learn how virtual private networks encrypt internet connections for secure remote work. Distinguish IDS as detection tools from IPS as automated blocks using signatures or anomalies and updated threat databases.
Explain the relationship between wi-fi and LAN, and review IEEE 802.11 standards. Describe WEP's vulnerabilities using RC4 with a 40-bit key, a 24-bit IV, and CRC-32, and why WPA emerged.
Explore WPA, designed to fix WEP flaws, and learn how TKIP provides dynamic 128-bit keys, longer initialization vectors, MIC, and frame counters, plus WPA vulnerabilities including eavesdropping and dictionary attacks.
Explore how WPA2, using AES-128 CCMP and CBC-MAC, secures wireless networks, compare personal and enterprise deployments, and examine vulnerabilities like man-in-the-middle and key reinstallation attacks.
Explain WPA3 personal and enterprise, including SAE (simultaneous authentication of equals), Dragonfly handshake, forward secrecy, and Wi-Fi Easy Connect for devices with no screen or limited input.
Strengthen web and web application security by detecting, preventing, and responding to threats such as sql injections, xss, csrf, and dos attacks, using web application firewalls, encryption, and security reviews.
Explore how an information security policy defines rules, responsibilities, and controls to protect confidentiality, integrity, and availability, with data classifications, access controls, encryption, backups, data protection regulations, and security awareness.
Security awareness training provides ongoing awareness, training, and education for the workforce to reduce information security risks with concise, actionable, and evidence-based guidance.
Enable security monitoring by collecting and analyzing log files with SIEM and log management tools to detect threats, trigger alerts, and support incident response and forensics across environments.
Learn to build an incident response plan with digital forensics, guiding security teams through preparation, detection and analysis, containment, eradication, and recovery, with roles, continuity, and communications.
Explore five-step digital forensics—identification, preservation, analysis, documentation, and presentation—covering computer, network, mobile, wireless, email, and memory forensics, with tools like Wireshark and Autopsy.
Drive continuous security improvement by evaluating effectiveness through a metrics-based program that captures, analyzes, and visualizes smart-aligned information security metrics for executive management, including patched devices, incidents, and response times.
Conduct vulnerability assessment and penetration testing across hosts, networks, databases, and applications through a four-phase process: identification, results analysis, risk assessment, and remediation, using automated scanners and threat intel.
Penetration testing, by an ethical hacker, identifies vulnerabilities in systems, networks, or web apps through planning and reconnaissance, scanning, gaining access, maintaining access, and web application firewall configuration analysis.
A basic security awareness guide on Information Security, Cyber Security & Privacy for BEGINNERS AND NON-TECHIES, to keep your online and offline devices safe!
This ~2 hour course provides a clear, non technical explanation on Information Security and Cyber Security.
This course offers solutions which can be used in the implementation of an Information Security Management System, it also provides guidance on how to protect yourself from cyber threats.
This course will help you gain a perfect understanding on Information Security through REAL LIFE EXAMPLES AND QUIZ QUESTIONS!
PLEASE DO TAKE A LOOK AT THE VIDEOS PROVIDED FOR FREE BEFORE ENROLLING IN THIS COURSE!
This course is divided into 4 parts:
The first part acts as an introduction to the course, it provides you with definitions such as, Information Systems, Information Security, the purpose of Information Security, the CIA Triad and AAA .
The second part speaks about Risk Management and Qualitative & Quantitative Risk Analysis. We also talk about Contingency Planning in the case of a disaster or disruption of services.
The third part is where, in my opinion, things get serious, as it contains a very simple and clear explanation on how to protect yourself from threats to your Information System along with REAL LIFE EXAMPLES to help you better understand the concept. We basically talk about Physical, Data, Systems & Network, Wireless and Web Application Security. Also provided in this section is how to develop an Information System Policy along with examples of policies, and how to conduct a Security Awareness Training.
The fourth part is about Security Monitoring and Effectiveness, the tools needed to maintain an effective monitoring strategy. We'll also see how to develop an Incident Response Plan and how to conduct a Forensics Investigation. Finally in this course we'll see how to evaluate the effectiveness of an Information Security System with Metrics and Vulnerability Assessment.
This Information Security Awareness Course is NOT a technical or operational security guide. NO CODING!
PLEASE DO TAKE A LOOK AT THE COURSE CONTENT BEFORE ENROLLING IN THIS COURSE!