
Explore how to identify, assess, select, and implement cyber security risk controls to protect digital assets from current and future attacks, and ensure leadership confidence in a skilled response team.
Identify, assess, select, and implement cyber security risk controls to protect digital assets from current and future attacks, guiding senior management to confidence in the security team.
Explore the selection and implementation of cybersecurity risk controls using a six mile wide, foot deep approach, from theory to practical application in real-world environments.
Explore a comprehensive roadmap for identifying, assessing, selecting, and implementing cyber risk controls. Apply these approaches to real incidents, study frameworks, and follow detailed steps to holistically secure business cybersecurity.
Explore a flexible, comprehensive approach to identifying, assessing, selecting and implementing cyber security risk controls to safeguard digital assets and infrastructure after a breach.
Identify root causes and breach impact; assess existing controls, prioritize risks, and implement a layered mix of preventive, detective, and corrective controls; continuously monitor and train.
Apply a comprehensive approach to real data breach cases like Equifax and Colonial Pipeline, linking root causes to controls such as patch management, vulnerability scanning, multi-factor authentication, and data encryption.
Explore security controls, including technical, administrative, and operational types, to mitigate risk, protect confidentiality, integrity, and availability, and guide defense in depth through risk assessments and policies.
Identify data assets and threats, assess risk, and select and implement cybersecurity controls on an ecommerce web server, using WAF, IPS, vulnerability scanners, and incident response.
Explore tools to identify assets, threats, and vulnerabilities for server risk, including open source scanners like Nmap, Nessus, OpenVAS, ZAP, sqlmap, and threat intel platforms, tested in a lab.
Learn to determine likelihood and impact for web server cyber risks using open source tools, vulnerability data, and threat intelligence, then calculate risk with a risk matrix and impact categories.
Document a cybersecurity risk assessment by compiling a comprehensive, living document that covers executive summary, assets, threats, vulnerabilities, likelihood, impact, risk level, and pragmatic mitigation strategies for a web server.
Explore how to structure a cybersecurity risk assessment report from executive summary through assets, threats, vulnerabilities, and mitigation strategies, and learn to identify, assess, and prioritize risks for effective controls.
Governance shapes policy, risk assessment, and resource allocation to enable effective selection and implementation of cyber security controls, aligning with business goals and ensuring compliance.
Explore the challenges, considerations, and disadvantages of implementing cybersecurity frameworks, including oversimplification, integration, and resource constraints, and learn to tailor a pragmatic, risk-based approach with top controls like MFA.
Navigate the challenges of oversimplifying cybersecurity when adopting security frameworks. Tailor and prioritize controls to your risk profile, assets, and workflows.
Explore when to use industry security frameworks to standardize security practices, meet regulatory requirements, and improve cyber security posture, and when a custom security program better fits unique environments.
Learn how to select and implement cybersecurity controls using the cybersecurity framework, from understanding environments and risk assessment to tailoring, implementing, monitoring, and iterating controls in an organizational context.
Apply the nist csf to select and tailor cybersecurity controls for a fictional organization, mapping risks to core functions, then implement, monitor, document, and iterate for continuous improvement.
Develop and implement a 12-month plan to deploy the selected cybersecurity framework controls. Outline responsibilities, timelines, milestones, and continuous monitoring to guide the implementation across the organization.
Define metrics and goals, establish baselines, and continuously monitor and analyze data from security logs and scanners to measure the effectiveness of implemented controls and improve security posture.
Apply a structured, end-to-end process to select and implement cybersecurity risk controls by assessing context, risks, and assets, aligning with objectives, prioritizing controls, and planning, testing, monitoring, and training.
Course resource links are provided.
This course was developed as a means of helping entry-level as well as seasoned cybersecurity professionals, to develop a more holistic rather than isolated approach to implementing controls to address cyber or information security risks. The content of this course is as follows:
SECTION 1 TOPICS
1a-Course Intro
1b-Course Intro- The Case at hand
2-About the course
3-Meet your Instructor-Mentor
4-Course Roadmap
5-Approach to Control Selection_ pt1
6-Approach to Control Selection_ pt2
7-Applying same approach to real Data Breaches at a high-level
8-Introduction to security controls
9-Key considerations for the identification- selection & implementation of controls
10-Risk Assessment-BIA, Control Selection, Cost Benefit Analysis
11-Cost Benefit Analysis associated with controls selection
12-Technology integration, Operational impact, continuous monitoring, Employee training
13-Regulatory Compliance, Incident Response Planning
SECTION 2 TOPICS
14-High-level process of selecting controls to protect eCommerce web server-Pt1
14-High-level process of selecting controls to protect eCommerce web server-Pt2
15-Steps involved in assessing the identified cyber risks in web server
16-Identify assets, identify threats, identify vulnerabilities
17-Determine likelihood, Impact, Calculate risk
18-Documenting Cybersecurity Risk Assessment Report-Pt 2
18-Documenting Cybersecurity Risk Assessment Report-Pt 1
19-The role of governance in the effective selection and implementation of cybersecurity controls
20-Why not implement frameworks that already have recommended controls
21-Challenges, considerations & disadvantages associated with implementing frameworks-Pt 1
21-Challenges, considerations & disadvantages associated with implementing frameworks-Pt 2
22-When to, versus when not to use frameworks for the selection and implementation of controls
23-Selecting and implementing cybersecurity controls based on the NIST Cybersecurity Framework (CSF) Pt1
23-Selecting and implementing cybersecurity controls based on the NIST Cybersecurity Framework (CSF) Pt2
24-Implementation Plan for identified controls
25- Measuring the effectiveness of implemented controls
26-Putting it all together-The Selection and Implementation of Cybersecurity Risks Controls
27-Course Recap-END
ASSIGNMENT-Research