|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/governance-risk-and-compliance-grc/
课程评论:没有评论
课程名称:治理、风险与合规 (GRC) 与数据隐私 课程概述:本课程旨在为各行业的学徒、学生和专业人士提供治理、风险管理与合规(GRC)及数据隐私的全面理解。课程内容涵盖如何将公司治理结构、质量和风险流程、合规与数据隐私活动整合,以更好地支持公司战略目标的实现。此课程涉及ISACA的CRISC认证课程内容,部分CISM的内容,同时可作为CISSP相关领域的辅助学习资料,还探讨了GDPR及其他数据隐私活动在GRC框架内的应用。此外,课程通过TOGAF和SABSA的视角讨论企业安全架构的概念,强调其建筑设计的思想,而非技术实施。无论您是信息安全/网络安全专家、风险管理从业者,还是希望提升该领域知识的个人,本课程都将为您提供在当前或未来职位上所需的框架和工具。 主要课程目标: 1. 深入理解治理、风险与合规的原则、框架和行业最佳实践。 2. 发展识别、评估和减轻组织风险的技能与专业知识。 3. 探索组织必须遵循的法律与监管要求,以及确保全面合规的策略。 4. 理解数据隐私及其在GRC中的适用性。 5. 能够设计和实施符合各自组织需求的有效GRC项目。 6. 培养与GRC相关的批判性思维、问题解决和伦理决策能力。 7. 为参训者准备ISACA公认的风险认证CRISC,及为CISM、CISSP和CGEIT认证做补充学习。 8. 概述TOGAF和SABSA,描述企业安全架构及其在GRC工作中的相关性。 目标受众: 本课程面向广泛的专业人士,包括: - 网络安全培训期间的学徒 - 进入信息安全和网络安全领域的本科及研究生 - 希望获得CRISC认证,并为CISM、CISSP和CGEIT提供额外资源的人士 - 风险管理、数据隐私、合规、内部审计、法律和公司治理领域的专业人士 - 其他业务领域希望全面理解GRC及其实际应用的人士 预期成果: 1. 学员将深入理解GRC原则,能够有效参与组织的风险管理和合规活动。 2. 参与者将获得开发和实施符合组织需求的强大GRC项目的必要技能。 3. 课程将增强参与者的批判性思维、问题解决和伦理决策能力。 4. 学员将更好地为风险管理、合规、内部审计和公司治理角色的职业生涯做好准备。 讲师简介:我在IT领域有近二十五年的经验,自2009年以来专注于信息安全。目前担任高级信息安全职务,并持有众多IT、安全、风险管理及数据隐私相关认证。我致力于帮助每一位参与者成功,相信您将在本课程中学到很多知识。所有参加本课程的学员均可获得我的支持,您将受到知识丰富且经验丰富的导师的指导。
This course on Governance, Risk Management Compliance (GRC) and Data Privacy is designed to equip apprentices, students, and professionals across various industries with a deep understanding of this holistic approach to organizational security and risk management, quality management and regulatory responsibilities. It involves aligning a company's governance structure, quality and risk processes, and compliance and data privacy activities to better enable the achievement of the company's strategic goals. This means it covers ISACA's CRISC certification, a decent portion of CISM and can be used as secondary study for the relevant CISSP domains, as well as placing GPDR and other data privacy activities within the broader business GRC realm. It also looks at what is an Enterprise Security Architecture through the lenses of TOGAF and SABSA, which isn't about the technical implementation; think of building a house where you get an architect to to design it and you ensure the construction is aligned to best practices and your goals. Whether you are an InfoSec/Cyber specialist, a risk management practitioner, or simply seeking to enhance your knowledge in this domain, this course will provide you with the necessary framework and tools to excel in your current or future role. It teaches you the fundamentals of GRC, including what GRC is and why it is important; the key components of GRC; how to implement a GRC program; what Data Privacy is beyond protection and; how to use GRC to improve your company's performance.Key Course Objectives:1. Provide a thorough comprehension of the principles, frameworks, and industry best practices in governance, risk, and compliance.2. Develop the skills and expertise required to identify, assess, and mitigate risks within an organizational context.3. Explore the legal and regulatory requirements that organizations must adhere to, and the strategies for ensuring comprehensive compliance.4. Understand Data Privacy and its applicability to GRC beyond data protection.5. Enable participants to design and implement effective GRC programs tailored to the specific needs of their respective organizations.6. Foster critical thinking, problem-solving, and ethical decision-making abilities in the context of GRC.7. Prepare participants for ISACA's industry-recognized risk certifications CRISC, as well as complement studies towards CISM, CISSP and CGEIT certifications.8. Outlines TOGAF and SABSA in describing what Enterprise Security Architecture is and its relevance for your GRC work.Target Audience:This course caters to a diverse range of professionals, including:- Apprentices during their cybersecurity training- Undergraduate and postgraduate students transitioning into information security and cybersecurity- Individuals seeking to pursue CRISC, and as an extra resource towards CISM, CISSP and CGEIT.- Professionals in risk management, data privacy, compliance, internal audit, legal, and corporate governance roles- Individuals from other business areas who seek to gain a comprehensive understanding of GRC and its practical applications to better their productivity without the jargon.Expected Outcomes:1. Students/professionals will gain a deep understanding of GRC principles, enabling them to contribute effectively to risk management and compliance initiatives in organizations.2. Participants will acquire the necessary skills to develop and implement robust GRC programs tailored to the needs of their respective organizations.3. The course will enhance critical thinking, problem-solving, and ethical decision-making skills among participants.4. Students/professionals will be better prepared to pursue careers in risk management, compliance, internal audit, and corporate governance roles.I have been in IT for almost two and a half decades and in information security since 2009. I currently hold a senior Information Security role. I hold numerous IT, security, risk management and data privacy-related certifications. I am committed to helping each and every one of you to succeed, and I am confident that you will learn a lot in this course. Everyone who takes this course gets access to support from myself. Rest assured you are in knowledgeable and experienced hands.