Lesson 1: Information Security Governance and Strategy
- Introduction
- Effective IS Governance
- Key IS Concepts and Issues
- The IS Manager
- Scope and Charter of IS Governance
- Developing an IS strategy-Common Pitfalls
- IS Strategy Objectives
- Determining Current State of Security
- Strategy Resources
- Strategy Constraints
- Action Plan - Immediate Goals
- Action Plan - Intermediate Goals
Lesson 2: Risk Management
- Introduction
- Effective Information Security Risk Management
- Integration into Life Cycle Processes
- Risk Identification and Analysis Methods
- Mitigation Strategies and Prioritization
- Reporting Changes to Management
Lesson 3: Information Security Program Management
- Introduction
- Planning
- Security Baselines
- Business Processes
- Infrastructure
- Malicious Code (Malware)
- Life Cycles
- Impact on End Users
- Accountability
- Security Metrics
- Managing Internal and External Resources
Lesson 4: Information Security Management
- Introduction
- Implementing Effective IS
- Security Controls and Policies
- Standards and Procedures
- Trading Partners and Service Providers
- Security Metrics and Monitoring
- The Change Management Process
- Vulnerability Assessments
- Due Diligence
- Resolution of Non-Compliance Issues
- Culture, Behavior and Security Awareness
Lesson 5: Response Management
- Introduction
- Performing a Business Impact Analysis
- Developing Response and Recovery Plans
- Incident Response Processes
- Testing the Response and Recovery Plans
- Executing Response and Recovery Plans
- Documenting Events
- Post Event Reviews