
Acquire foundational knowledge in InfoSec and risk management by learning to protect organizational assets through securing information systems, networks, and processes with robust security practices.
Define key information security terms to build a shared vocabulary, including information, data, organization, and non-repudiation, and explain the CIA triad: confidentiality, integrity, and availability, with foundations for risk management.
Learn what information security risk is and why risk management matters, including identifying assets, threats, vulnerabilities, and the impact and likelihood that drive informed decisions, prioritization, and controls.
Learn how information security defines assets, including digital, physical, and reputational types, and create an asset register that assigns owners, classifications, and value to guard against risk.
Understand threats in information security by defining streets and threat actors, including malicious outsiders, insiders, and environmental risks, and apply threat modeling to tailor risk controls.
Identify vulnerabilities as weaknesses in assets that threats exploit, forming the basis of information security risk. Understand how hardware and software vulnerabilities arise and how to identify and mitigate them.
Calculate the risk score with a simple formula to prioritize mitigating controls for a customer database. Explore how impact, likelihood, assets, vulnerabilities, and threats guide scenario-based assessment and mitigation decisions.
Define and measure impact in information security by assessing potential consequences and calculating risk using impact levels based on percentages of annual revenue; apply a practical, customizable framework.
Define likelihood in risk management and calculate it using a frequency-based score, guided by an organization's risk tolerance and a formal likelihood table.
Calculate risk in information security using impact and likelihood, illustrated with real-world examples, to assess and prioritize mitigation for assets like a public NAS and a secret recipe.
Explore how organizations define risk appetite, select treatment strategies, and accept residual risk using a risk matrix, mitigating controls, and assessing vulnerabilities to protect information assets.
Master legal regulations, investigations, and compliance structures that shape information security through GDPR, PCI DSS, audits, risk management, and continuous improvement to protect data and build trust.
Align your organization with legal and regulatory requirements in information security through cross-team collaboration, documentation, and regular audits; recognize software's limits and rely on human oversight for data protection tasks.
Explore how to respond to and undertake investigations in organizations, using legal holds, data preservation, e-discovery, and impartial handling to ensure compliance and protect the organization.
Driven by continuous improvement, this module teaches applying an engineering mindset to optimize security, perform risk assessments, update the risk register, and implement mitigations for redundancy and resilience.
Develop a resilient information security strategy with robust policies, procedures, and playbooks, a security awareness program, and continual improvement through third party risk management and data protection.
Create a structured information security program by developing policies, procedures, and playbooks, conducting risk assessments, and progressively expanding ISMS scope to protect assets.
Establish and maintain a security awareness, education and training program that reinforces information security policies through onboarding, ongoing education, and phishing simulations to engage staff.
Assess third-party cloud risks by applying the shared responsibility model, evaluating data security and compliance, and leveraging service level agreements and vendor security assessment questionnaires to mitigate operational risks.
Drive continual improvement in information security by updating controls and embracing defense in depth. Report progress to stakeholders with data-driven visuals and cost-benefit analyses to justify budgets.
Implement an information security management system to protect assets, identify and classify information assets by value and risk, apply controls like encryption and access control, and securely dispose of assets.
Senior management bears ultimate responsibility for information security and must align security with strategic objectives. Communicate risks to senior management in business terms and implement an information security management system.
Develops an information security management system to identify, measure, and mitigate risks through documented policies and procedures. Aligns with ISO 27,001 standards and GDPR requirements to ensure compliant, secure operations.
Learn to understand and create a statement of applicability for ISO 27001, linking risks to controls. Document implementation status and justify decisions to align with risk-based ISMS.
Explore the fundamentals of information security policy, including approval, publishing, and communication, plus encryption, backups, and objectives for confidentiality, integrity, and availability.
Enhance information security by learning asset management fundamentals, asset inventory, classification, labeling, and secure handling to support risk management and ISO 27001 compliance.
Explore how to build and maintain a comprehensive asset inventory, categorizing assets, assigning owners, scoring criticality, and keeping the inventory updated to reduce risk and strengthen information security.
Classify and label information assets according to a tailored classification policy to determine protection levels. Define and enforce an acceptable use policy that aligns with organizational risk and security needs.
Explore risk management documentation and the risk management process, including identification, assessment, treatment, and monitoring. Learn to evaluate impact and likelihood, prioritize risks, and apply treatment options with clear documentation.
Create and communicate an effective risk assessment report, prioritizing risk treatments and tailoring content for top management and IT teams, including inherent risk levels and reducing residual risk.
Document incident management processes with a high level policy, accessible plans, and asset-based response steps, ensuring cloud and printed backups, timely notifications, system shutdown, and data recovery.
Develop and test incident response and business continuity playbooks to guide fast, structured actions across threats like server damage and DDoS, using tabletop exercises to optimize response times.
Explore IT management documentation and its role in an information security management system, including operating procedures, policies, and disaster recovery planning.
In today's digital landscape, safeguarding information is more critical than ever. This comprehensive course on Udemy is designed to equip you with the essential knowledge and skills needed to excel in the field of Information Security (InfoSec). Whether you're an aspiring InfoSec professional or looking to deepen your understanding, this course will guide you through the core principles and practices required to protect and secure organizational assets.
Chapter 1: InfoSec and Risk Management
This foundational chapter establishes the core principles of InfoSec, ensuring you understand the topics central to the discipline. You'll learn how to assess and manage risks, setting the stage for a secure information environment.
Chapter 2: Protecting the Security of Assets
Discover effective processes to identify and protect the valuable assets of an organization. This chapter will help you avoid common pitfalls that InfoSec professionals often encounter, ensuring you can implement strong security measures.
Chapter 3: Designing Secure Information Systems
Learn how to assess information system architectures for vulnerabilities and implement controls to mitigate these risks. This chapter includes an in-depth exploration of cryptography and other essential security measures.
Chapter 4: Designing and Protecting Network Security
Understand the intricacies of designing secure network systems. You'll learn to select the appropriate network components and ensure their effectiveness in meeting your organization's security requirements.
Chapter 5: Controlling Access and Managing Identity
This chapter delves into both physical and digital access controls, providing insights into selecting and implementing effective identity and access management strategies to safeguard your organization.
Chapter 6: Designing and Managing Security Testing Processes
Embrace a mindset of continuous improvement by learning how to test existing implementations. This chapter covers how to use testing results to optimize and strengthen your InfoSec program.
Chapter 7: Owning Security Operations
Align the day-to-day tasks of maintaining InfoSec with your organization's broader strategies. This chapter provides practical guidance on managing security operations to ensure ongoing protection.
Chapter 8: Improving the Security of Software
Explore the critical role of secure practices in software procurement and development. You'll learn how to enforce secure coding practices and manage software-related risks effectively.
By the end of this course, you will have gained a holistic understanding of Information Security, empowering you to design, implement, and manage security practices that protect both information systems and organizational assets. Join us on this journey to becoming a confident and capable InfoSec professional!