|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/information-security-manager-for-2025-exams/
课程评论:没有评论
课程名称:信息安全经理2025考试 课程概述:信息安全经理认证确认您评估风险、实施有效治理并主动应对事件的能力。重点关注人工智能和区块链等新兴技术,确保您的技能符合不断变化的安全威胁和行业要求。通过解决数据泄露和勒索软件攻击等IT专业人员关注的关键问题,本认证确保您走在变革的前沿。 课程结构: 1. **信息安全治理(17%)** - 企业治理的文化、法规和结构 - 信息安全策略的分析、规划和发展 - 确保高层在信息安全治理中的权威性 内容包括:组织文化、法律法规要求、组织结构及角色;信息安全战略开发、治理框架、战略规划(预算、资源、商业案例)。 2. **信息安全风险管理(20%)** - 分析和识别潜在的信息安全风险、威胁和漏洞 - 管理层所需的信息安全风险识别与应对信息 内容包括:新兴风险和威胁环境、漏洞和控制缺陷分析;风险处理选项、风险和控制所有权、监控和报告。 3. **信息安全项目(33%)** - 信息安全资源、资产分类与框架 - 管理信息安全项目,包括安全控制、测试、沟通和报告 内容包括:信息安全项目资源(人力、工具、技术)、信息资产识别与分类、行业标准和框架;信息安全控制设计与选择、实施与集成、评估与测试。 4. **事件管理(30%)** - 风险管理与准备、如何准备企业应对事件 - 事件管理工具与评估方法 内容包括:事件响应计划、业务影响分析、业务连续性计划、灾难恢复计划;事件管理工具与技术、事件调查与评估、事件响应沟通。 通过本课程,您将能够提升信息安全领域的专业能力,应对新兴技术带来的挑战,并有效管理信息安全项目和事件。
Information Security Manager The certification affirms your ability to assess risks, implement effective governance, and proactively respond to incidents. With a highlight on emerging technologies such as AI and blockchain, it guarantees your skillset meets evolving security threats and industry requirements. By addressing top-of-mind concerns like data breaches and ransomware attacks, crucial for IT professionals, this certification ensures you are staying ahead of the pace of change.17% DOMAIN 1 - INFORMATION SECURITY GOVERNANCEThis domain will provide you with a thorough insight into the culture, regulations and structure involved in enterprise governance, as well as enabling you to analyze, plan and develop information security strategies. Together, this will affirm high-level credibility in information security governance to stakeholders.A-ENTERPRISE GOVERNANCEOrganizational CultureLegal, Regulatory and Contractual RequirementsOrganizational Structures, Roles and ResponsibilitiesB-INFORMATION SECURITY STRATEGYInformation Security Strategy DevelopmentInformation Governance Frameworks and StandardsStrategic Planning (e.g., Budgets, Resources, Business Case)20% DOMAIN 2 - INFORMATION SECURITY RISK MANAGEMENTThis domain empowers you to analyze and identify potential information security risks, threats and vulnerabilities as well as giving you all the information about identifying and countering information security risks you will require to perform at management level.A-INFORMATION SECURITY RISK ASSESSMENTEmerging Risk and Threat LandscapeVulnerability and Control Deficiency AnalysisRisk Assessment and AnalysisB-INFORMATION SECURITY RISK RESPONSERisk Treatment / Risk Response OptionsRisk and Control OwnershipRisk Monitoring and Reporting33% DOMAIN 3 - INFORMATION SECURITY PROGRAMThis domain covers the resources, asset classifications and frameworks for information security as well as empowering you to manage information security programs, including security control, testing, comms and reporting and implementation.A-INFORMATION SECURITY PROGRAM DEVELOPMENTInformation Security Program Resources (e.g., People, Tools, Technologies)Information Asset Identification and ClassificationIndustry Standards and Frameworks for Information SecurityInformation Security Policies, Procedures and GuidelinesInformation Security Program MetricsB-INFORMATION SECURITY PROGRAM MANAGEMENTInformation Security Control Design and SelectionInformation Security Control Implementation and IntegrationsInformation Security Control Testing and EvaluationInformation Security Awareness and TrainingManagement of External Services (e.g., Providers, Suppliers, Third Parties, Fourth Parties)Information Security Program Communications and Reporting30% DOMAIN 4 - INCIDENT MANAGEMENTThis domain provides in-depth training in risk management and preparedness, including how to prepare a business to respond to incidents and guiding recovery. The second module covers the tools, evaluation and containment methods for incident management.A-INCIDENT MANAGEMENT READINESSIncident Response PlanBusiness Impact Analysis (BIA)Business Continuity Plan (BCP)Disaster Recovery Plan (DRP)Incident Classification/CategorizationIncident Management Training, Testing and EvaluationB-INCIDENT MANAGEMENT OPERATIONSIncident Management Tools and TechniquesIncident Investigation and EvaluationIncident Containment MethodsIncident Response Communications (e.g., Reporting, Notification, Escalation)Incident Eradication and RecoveryPost-Incident Review Practices