
Recognize why IT security matters in projects and products, from cars to online shops, and follow a pragmatic guideline that highlights technology, organizational, and human factors, including data protection considerations.
Enforce IT security in projects to safeguard long-term value and prevent vulnerabilities that invite hackers. Align governance and budget with security concepts early to mitigate liability and ensure IoT security.
Integrate information security from the very start by applying the seven protection goals: confidentiality, authenticity, integrity, liability, availability, time stamping, privacy, and ensure authentication, authorization, and security standards and contracts.
Security is a process managed by technology, organization, and the human factor. The course explains IT security measures, data protection, patch management, logging, audits, and ongoing process adjustments.
Explore information security standards for project managers and how to implement them across projects, using ISO 27000, PCI, DSP, CIPA, and the Open Web Application Security Project top 10 guidelines.
Integrate data privacy and data protection laws into IT projects from the outset by including a data protection adviser, ensuring country-specific requirements and IT security compliance.
Assess IT security across network, virtualization, OS, and application layers. Implement security requirements catalogs, organizational measures, secure programming, and practices like patch management, penetration testing, monitoring, backups, and access controls.
Integrate IT security and data protection early, apply security standards to control suppliers and partners, and acknowledge that budget constraints may require external help to avoid costly follow-ups.
Despite many accepted IT security standards, many IT projects fail at IT security. This also includes for instance (‘smart’) products that just include information technology in small proportion. What needs to be considered, what mistakes and pitfalls to avoid?
Most IT projects have a tight budget. Only in rare cases, a project manager has access to unlimited financial resources. This applies to projects of both large and small businesses alike but usually the smaller the company the bigger the problem. If security cannot be used as a (unique) selling point for a product or for the development of a system, the project manager often has a hard job to acquire proper and adequate resources for security.
No matter if you are a manager in a small company or even on your own or if you are part of a large enterprise with information security management in place. This pragmatic guide helps you to understand information security on a high level and how to integrate security in your project or product. What needs to be done for long-term success and why? The author, Computer Scientist Frank Hissen, explains it in a few practical steps from over 15 years of experience as IT security consultant:
Motivation: IT Security Holes in Projects and Products
Enforce IT Security in Projects
IT Security in Projects: From the very beginning!
Security is a Process
IT Security Standards
Do the same for Data Privacy / Protection Laws!
Checklist for Project Managers
Conclusion
Furthermore, all students can download the course material as ebook (included in section 1).