|
所在平台: Coursera |
课程主页: https://www.coursera.org/learn/business-of-cybersecurity-capstone
课程评论:没有评论
课程名称:网络安全业务顶点(The Business of Cybersecurity Capstone) 课程概述:本课程旨在帮助学生熟悉信息安全管理。在完成该课程后,学生将更深入地了解以下内容: - 治理:包括信息安全治理职能的使命、角色和责任,以及信息安全在组织战略规划过程中的作用。 - 各类信息安全政策的理解,以及如何制定和有效使用信息安全政策。 - 风险管理及其过程。 - 影响组织信息安全的相关法律和伦理问题,以及一些常见的信息安全管理实践,如基准测试和绩效评估。 课程大纲: 1. 欢迎信息安全管理:欢迎学生进入课程,并介绍后续的各模块。讲座和阅读内容将广泛介绍安全管理主题,建立后续模块所需的基础术语,同时介绍将用于扩展模拟的案例公司。 2. 信息安全中的治理与战略规划:探讨组织如何构建网络安全职能,进行战略规划,包括信息安全管理团队在组织层级中的位置、首席安全官(CSO)的职能,以及战略规划功能的解释。 3. 风险管理:定义风险管理,探讨组织用于识别和控制风险的过程,包括风险识别和评估的基本技巧,以及可以帮助控制风险的风险控制策略。 4. 合规、法律与伦理:学习组织如何管理快速变化的法律和监管环境带来的复杂问题,概述应了解的法律与法规,以及伦理在工作场所的出现情况。讨论行业标准和政府法规的合规性。 5. 安全程序:探索信息安全管理程序中常见的重要元素,包括绩效测量、技术控制管理和应急计划,并评估模拟公司的事件响应计划。 6. 结论:综合课程内容,完成期末考试和顶点项目。 总结:通过此课程,学生将能更好地理解信息安全管理的重要性及其实践,包括治理、政策、风险管理以及合规与伦理,从而为其在网络安全领域的职业发展奠定坚实的基础。
Name:Welcome to the Management of Information Security
Description:This module provides a welcome to the course and describes the course modules that follow. The lecture and reading will introduce you to the broad topic of security management and establish the basic terminology needed for later modules. Also, you will begin learning about the case company that you will use in an extended simulation that spans the rest of this course as you build on your learning by engaging in real world analysis and reporting on cybersecurity topics.
Name:Governance and Strategic Planning in Information Security
Description:In this module, you will explore how organizations organize the cybersecurity function and engage in strategic planning. This will include coverage of where the information security management team is placed in the organizational hierarchy, what functions does the CSO of an organization fulfill, as well as some explanation of the strategic planning function.You will also develop a simulated organizational plan in a report to executive management as part of the ongoing case study.
Name:Risk Management
Description:This module will define risk management and explore the processes used by organizations to identify and control risk. This will include basic techniques used to identify and assess risk as well as exploration of the risk control strategies that can be used to help control risk. You will also experiment with reading an industry standard risk report that you will summarize and analyze as you assess operational risk for higher management as part of the ongoing case-based project.
Name:Regulatory Compliance, Law and Ethics
Description:In this module you will learn about how organizations must manage the complex issues emerging from the rapidly changing legal and regulatory environment. It will include a short overview of the laws and regulations you should plan to learn about as well as an introduction to how ethics is encountered in the workplace. Then you will engage on a discussion on compliance with industry standards and governmental regulation as a means to move closer to a more secure work environment. As part of the ongoing case study you will be asked to advise management on an ethical dilemma currently facing some of the management team at CHI.
Name:Security Programs
Description:This module explores some of the other important elements commonly found in information security management programs. While you will not cover every security management topic, you will explore performance measurement, managing technical controls, and contingency planning. Then, you will assess and report on the proposed incident response plans of the simulated company as part of the ongoing case study.
Name:Conclusion
Description:In this module, you will synthesize the content in the course, complete a final exam, and complete your Capstone Project.
This course intends to make the student familiar with information security management. When you have finished with this course you will know more about: • Governance: including the mission, roles and responsibilities of the InfoSec governance function, and the strategic planning process and InfoSec’s role in the organization’s strategic planning effort. • You will understand the various types of InfoSec policies and how effective information security policy is created and used. • Risk management and the risk management process • Certain laws and ethical issues impacting information security in the organization. And some common information security management practices such as benchmarking and performance measures.