Personnel & Third-Party Security

所在平台: Coursera

课程主页: https://www.coursera.org/learn/internal-risk-mitigation

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:人员与第三方安全 课程概述:在本课程中,您将全面了解实施有效的教育、培训和意识提升程序的过程。您还将学习人员安全在保护组织资产、知识产权和实物资产方面的作用。课程将介绍有效的供应商风险管理(VRM)所需的步骤,包括尽职调查、合同、监控与评估以及终止。通过当前案例研究,您将与关键概念进行互动,并有机会提交作业,将所学材料应用于实际情况。 课程大纲: 第1部分:教育、培训与意识 描述:欢迎来到人员与第三方安全的第一模块!对于组织内的许多角色而言,了解安全威胁的教育、培训和意识至关重要。这不仅仅是用户的责任,管理员、IT人员、安全人员和风险评估师也可能做出错误决策。本模块将深入探讨如何实施有效的教育、培训和意识提升程序。 第2部分:人员安全 描述:欢迎来到第二模块!人员安全在保护组织资产方面发挥着关键作用,例如客户数据等知识产权和其他实物资产。组织会根据人员使用组织资产的安全要求进行定义,然后使用技术和物理控制来加以实施。通过人员安全控制,我们旨在减少与资产相关的滥用、盗窃或欺诈行为。 第3部分:供应商风险管理 描述:欢迎来到第三模块!本模块将介绍有效的供应商风险管理(VRM)所需的步骤,包括尽职调查、合同、监控和评估以及终止。关于VRM,虽然我们无法完全消除所有风险,但可以努力降低风险。关键是确保没有“不可接受”的风险。 第4部分:收购策略 描述:欢迎来到人员与第三方安全的第四个也是最后一个模块!假设您刚刚购买了新的硬件、软件,或与另一家公司合并。您如何确保这些行动不会降低您的网络安全态势并增加外部和内部威胁的风险?将网络安全风险考虑纳入收购策略可以帮助应对这些问题。

课程大纲

Part: 1

Title:Education, Training, & Awareness

Description:Welcome to the first module of Personnel & Third Party Security! Education, training, and awareness of security threats are important for many actors within an organization. It’s not only your users who make bad decisions, it’s also administrators, IT staff, security staff, and risk assessors. In this module we will dive into the process of implementing effective education, training, and awareness programs.

Part: 2

Title:Personnel Security

Description:Welcome to Module 2! Personnel security plays a critical role in protecting an organization’s assets, for example intellectual property, such as customer data or physical assets. Organizations define their security requirements around personnel’s use of organizational assets and then use technical and physical controls to implement them. Through personnel security controls, we work towards a reduction in the misuse, theft, or fraud related to our assets.

Part: 3

Title:Vendor Risk Management

Description:Welcome to Module 3! In this module we will introduce the steps required for effective Vendor Risk Management (VRM), including: due diligence, contracting, monitoring and accessing, as well as termination. When it comes to VRM, we cannot completely eliminate all risk, however, we may be able to reduce risk. The key is to ensure there is no "unacceptable" risk.

Part: 4

Title:Acquisition Strategy

Description:Welcome to the fourth and final module of Personnel & Third-Party Security! Imagine you just bought new hardware, software, or merged with another company. How do you ensure that these actions do not reduce your cyber security posture and increase your risk to external and internal threats? Introducing cyber security risk considerations into acquisition strategy can help deal with these concerns.

课程评论(0条)

课程详情

In this course, you will learn all about the process of implementing effective education, training, and awareness programs. You will also study the role personnel security plays in protecting an organization’s assets, intellectual property, and physical assets. You will also be introduced to the steps required for effective Vendor Risk Management (VRM), including: due diligence, contracting, monitoring & accessing, and termination. Throughout the course, you will engage with current case studies that illustrate the key concepts in your lessons. You will also have the chance to submit assignments in which you will apply the material in a practical application.

课程标签

0人关注该课程

主题相关的课程