Cyber Security Third Party Risk

所在平台: Udemy

课程主页: https://www.udemy.com/course/cyber-security-third-party-risk/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:网络安全第三方风险 课程概述:本课程旨在帮助组织理解网络安全第三方风险管理的重要性,以及组织需要采取的步骤。您将全面掌握现代组织面临的网络安全第三方风险,以及您所在的行业可以采取的措施来帮助管理这些风险,从而保护自身安全。 主要内容包括: - 了解网络安全第三方风险的背景和背景如何相互交融。 - 学习网络安全第三方风险对组织的重要性,并分析一些高曝光安全漏洞是如何因第三方关系而发生的。 - 掌握如何评估与供应商及其提供服务相关的网络安全第三方风险,理解“固有风险”的概念,并利用“CIA三角”模型(保密性、完整性和可用性)评估风险,从而优先安排尽职调查活动。 - 了解关键标准和法规对组织在网络安全第三方风险管理方面的要求,包括ISO 27000、PCI DSS、网络安全基本保障、GDPR、DORA和NIS 2等。 - 学习对第三方的网络安全状况进行尽职调查的不同方法,包括定制问卷的设计技巧,以及如何从SOC 2报告和第三方ISO 27001认证中获得最大收益。 - 了解法律合同在解决网络安全第三方风险中的重要性及合同谈判的必要性。 - 了解您所需的网络安全第三方风险管理项目文档,包括政策、程序和模板的示例。 - 学习在网络风险第三方风险管理生命周期中,与供应商及关键利益相关者沟通的重要性,以及如何管理第三方安全控制措施中的缺口整改。 本课程将为您提供实用的知识和工具,帮助您有效管理网络安全第三方风险。

课程评论(0条)

课程详情

Understand why Cyber Security Third Party Risk Management is so important for organisations and what steps your organisation needs to take.You will get a firm grasp of the cyber security third party risk today's organisations face and what steps organisations and industries like yours can take to help manage this risk and protect themselves.· Gain a solid understanding of the background and context to Cyber Security Third Party Risk, by looking at the Cyber Security and Third Party Risk backgrounds, and how they "meld" together.· Learn about the importance of cyber security third party risk for organisations, and see how some of the latest high profile security breaches on organisations have been a result of their third party relationships· Learn how to assess cyber security third party risk associated with your suppliers and the services their provide. Understand the concepts of Inherent Risk how to assess this using "CIA Triad" of confidentiality , integrity and availability and how we can use these to prioritise due diligence activities.· Learn what key standards and regulations require organisations to do regarding cyber security third party risk, including ISO 27000, PCI DSS, Cyber Essentials, the GDPR, DORA and NIS 2.· Learn about the different approaches to undertake due diligence of your third party's cyber security posture, including design tips for custom questionnaires, and how to gain the most from SOC 2 reports and third party ISO 27001 certifications. · Learn about the importance of legal contracts in addressing cyber security third party risk, and the importance of contract negotiation· Understand and see samples of the documentation your cyber security third party risk management programme will require including samples of policy, procedures and templates.· Learn about the importance of communications with suppliers and key stakeholders during the cyber risk third party risk management lifecycle, and how to manage the remediation of gaps within your third party's security controls measures.

课程标签

0人关注该课程

主题相关的课程