|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/constructs-of-information-security-management-system/
课程评论:没有评论
课程名称:信息安全管理体系的构建 课程概述:在当今数字世界中,网络威胁是对组织最明显和迫在眉睫的危险之一。网络安全是一个技术、人员、流程和控制密切协作以阻止信息泄露的领域,从而拯救组织免受财务和声誉损失。信息安全是网络安全的基础,它使组织能够防御信息资产的侵犯。任何组织的网络安全计划都是IT和电信基础设施、应用程序、数据和人员安全的结合。这些数据,也称为信息,对组织的生存至关重要。因此,在组织采取的任何网络安全倡议中,信息安全管理具有根本性的重要性。在数字经济的新阶段,组织正努力保护其被称为信息的数字资产。信息安全管理体系(ISMS)是组织为积极应对内外部信息安全威胁而采用的一种框架。信息安全漏洞的风险已大大超越以往,这些风险不仅涉及金钱,还包括品牌形象、企业崩溃、财产损失等。在数字技术的五个轴心(社交、移动、分析、云和万物互联)正在颠覆传统商业方式的情况下,不采纳这些技术会质疑组织的基本生存能力。随着这些技术的应用,信息安全漏洞的威胁面倍增。然而,仅靠技术并不足以形成完美的网络防御机制。高达90%的信息安全漏洞都归因于员工或合作伙伴及其对信息安全的意识。因而,一个良好的信息安全管理体系不仅仅依赖于技术,而是以人员、流程、政策和指导方针为治理原则,并随着网络世界中新兴威胁向量的变化而不断演进的战略。实际上,新的员工在加入组织时需要签署信息安全保密和合规文件,但这真的有效吗?组织是否将员工之间的非正式闲聊视为一种威胁?为什么不能创造一种信息安全成为员工习惯的工作文化,像个人和家庭安全一样根植于他们的习惯中?本课程旨在帮助学员理解信息安全管理体系的各个组成部分,明确技术人员在组织中信息安全管理的人员、流程、政策和控制的重要性。对于所有寻求进入公司职业并成为良好公司公民的人,这门课程都是必修课。同时,这也是进入信息安全管理领域、并逐渐晋升至信息安全顶尖职位(即首席信息安全官CISO)的第一步。课程将从企业架构师的角度剖析信息安全的神话,系统地构建从信息到信息安全,再到ISMS的各个元素,首先介绍信息特性的基础,即保密性、完整性和可用性(CIA)。众所周知,信息安全是迈向网络安全的重要基石,因此学习ISMS基础知识对每个人都是必要的。作为额外内容,本课程还为希望从技术部署角度理解企业安全架构的专业人士增加了三节讲座。这将有助于在职专业人士决定需要实施哪些技术元素以保护企业信息,并准备应对网络攻击。首席企业安全官(CISO)也可以借此进行技术要素的复习。
Cyber threats are one of the most clear and present danger looming over organisation in the current digital world. Cyber security is an area where technology, people, process and control work together hand-in-gloves to thwart any information leak and hence saving organisation from financial and reputational loss. Information security is fundamental to cyber security as it prepares the organisation to defend the breach of information assets. Any organisation's cyber security programs is a combination of security of IT and telecom infrastructure, application, data and people. This is the data, also called as Information, that is vital for organisation's survival. Hence, Information security management is of fundamental importance in any cyber security initiative adopted my organisations. In the new age of digital economy, organisations are struggling to protect their digital asset also called as Information. The Information security management system a.k.a ISMS is one of the framework for organisations to adopt to become proactive to the internal as well as external threat to information security. The risk of information security breach is far-fetched than the old days phenomenon. These RISKs are not only monetary but also brand image, collapse of a business, property damage etc. The five axes of digital technology viz. Social, Mobility, Analytics, Cloud and Internet of Everything(IOE) are disrupting the conventional method of doing business. Not adopting these technologies is questioning the basic survivability of organisation. As these technologies are getting adopted, the threat surface for information security breach has multiplied many folds. However, only technology does not lead to a super cyber defence mechanism. As high as, 90% of the information security breach has been attributed to employee or partners and their awareness of information security. Hence, a good information security management system does not have technology as the only facet, but it has people, process, policy and guidelines as the governing principles with ever evolving strategy tuned to the emerging threat vectors in cyber world. As a matter of fact, a new employee is required to sign information security non-disclosure and compliance document when they join an organisation. But is that effective? Do organisations see the informal chit-chat among employee a threat? Why can't they create a work culture where information security become a habit of employees like the personal and family security engrained in their habits. This course is all about understanding the components of information security management systems. It will bring clarity to technical person about the importance of people, process, policy and controls that governs the information security management in an organisation. This is a must course for all seeking a corporate career and being a good corporate citizen. Also, this is the first step for seeking a career in information security management with a gradual rise to the top position in Information security domain in corporate also called as Chief Information Security Officer(CISO). This course dissects the information security myth from enterprise architect's point of view with the course name titled ‘Constructs of Information Security Management System'. It systematically builds from information to information security to all elements of ISMS starting with fundamental of information characteristics also called as Confidentiality, Integrity, Availability(CIA). As you know information security is the major building block toward a step toward cyber security, learning ISMS basics is a must for all. As a bonus lecture, three lectures has been addd for the professionals who wants to understand the Enterprize Security Architecture from a technology deployment perspective. This will help the working professional to decide which all technology elements to be implemented in order to secure the enterprise information and be ready to response to a cyber attack. The Chief Enterprize Security Officer (CISO) will have a refresher on technology elements.