|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/information-security-risk-assessment-process-iso-270012013/
课程评论:没有评论
课程名称:信息安全风险评估流程 ISO 27001:2013 概述:本课程深入探讨为何公司和机构必须有效管理“关键信息”及其相关的“信息安全风险”。如果信息安全事故发生,会有什么后果和风险?公司和信息安全顾问是如何实际执行信息安全风险评估,以管理和维护信息安全基础设施的?ISO/IEC 27001:2013信息安全管理体系(ISMS)标准对信息安全风险评估和处理有什么规定?本课程将通过实践案例结合标准要求、风险评估模型及技术,为您解答以上问题。ISO 27001是国际上公认的信息安全管理体系标准,也是信息安全领域最受欢迎的标准。它为组织和企业提供了一个信息技术治理框架,以便开发和实施ISO 45001规定的控制措施,从而保障信息资产的安全。 课程概览:在本课程中,您将了解公司和机构如何执行信息安全风险评估,并管理或处理信息安全风险、威胁和脆弱性。课程的设计将为您提供关于信息安全风险评估和管理的概念性与实践性知识,符合ISO 27001标准。 课程主题包括: - 理解ISO 27001信息安全管理系统风险评估 - 理解信息安全、保护及ISO 27001原则 - 信息安全的关键目标与保护措施 - 网络、信息与数据可用性 - 信息资产矩阵与CIA三元组 - 理解风险、活动或事件与负面影响 - 机构和组织面临的不同风险类别 - 理解信息安全风险及其可能的负面影响 - 理解网络安全风险 - 信息资产、数据治理与ISO 27001的保护控制 - 信息安全风险评估及其目的 - 定量计算的风险评估 - 基于资产的风险评估(ABA)- 风险、威胁与脆弱性 - 风险、脆弱性、后果与缓解计划概述 - 理解高、中、低风险水平的风险评估 - 风险矩阵/方法论 - 5x5风险评估矩阵 - 风险评估矩阵的应用 - 风险登记表的准备实例 - 以网络安全风险为例 - 风险处理选项 - 实施控制 - 预防性、侦测性与纠正性控制 - 信息系统防御控制 - ISO 27001 - 风险缓解策略与控制 - 本课程还包括多项选择题(MCQs) 通过本课程,您将能够“准备资产风险、影响与可能性矩阵”、“运用方法论进行风险评估”、“准备脆弱性与威胁矩阵”、“执行风险与财务影响金字塔分析”、“应用处理选项”、“理解控制类别”等等,以适应ISO 27001信息安全管理体系。 其他收益:参加本课程后,您将能够: - 在信息安全职位中应用相关概念 - 与信息安全和信息审计专业人士沟通 - 申请ISO 27001 ISMS已实施或待实施的机构工作 - 在信息安全领域追求职业进阶 - 获得课程完成证明 目标人群:信息系统IS安全、IS审计、IT专业人员及学生;信息安全顾问;风险管理专业人士及学生;内部审计专业人士及学生;金融专业人士及学生;CISA、CISM学生;合规专业人士;任何希望学习ISO 27001信息安全标准要求的人士。
Do you know why is it critical for companies and institutions to manage "Critical Information" and associated "Information Security Risks"? Do you know what happens when IS Security Risks incident occurs? What are the consequences and risks involved? Do you know how companies and IS Consultants, practically perform IS risk assessment to manage and maintain Information Security Infrastructure? What ISO/IEC 27001:2013 ISMS standard prescribes for IS Security Risk Assessment and Treatments?All these questions will be answered through a practical course, where standards' requirements are linked with real-world examples, risk assessment models, and techniques.ISO 27001 is the internationally recognized specification for Information Security Management System (ISMS) and is the most popular standard for Information Security. It serves as an IT Governance framework for organizations and businesses to enable the development and implementation of ISO 45001-prescribed controls to secure information assets.COURSE OVERVIEW In this course, you will get an insight into how companies and institutions perform Information Security IS Risk Assessment and manage or treat IS Risks, Threats, and Vulnerabilities. This course will give you conceptual and practical knowledge about IS Security Risk Assessment and Management as per ISO 27001.COURSE TOPICSUnderstanding ISO 27001 ISMS Risk Assessment Understanding Information Security, Protection, and ISO 27001 PrinciplesKey Objectives of Information Security and ProtectionNetworks, Information, and Data AvailabilityInformation Asset Matrix and CIA TriadUnderstanding Risk, Activity or Event, and Adverse Impact or OutcomeDifferent Categories of Risks Faced by Institutions and OrganizationsUnderstanding Information Security Risks and Possible Adverse ImpactsUnderstanding Cybersecurity RiskInformation Asset, Data Governance and ISO 27001 Protection ControlsInformation Security IS Risk Assessment and Purpose of IS Risk AssessmentRisk Assessment with Quantitative CalculationRisk Assessment - Assets Based Approach ABA - Risks Threats and VulnerabilitiesOverview of Threat, Vulnerability, Consequences and Mitigation PlanRisk Assessment - Understanding High, Medium and Low Risk LevelsRisk Matrix /methodology - 5 by 5 Risk Assessment MatrixUnderstanding When to Use a Risk Assessment MatrixApplication of Risk Assessment Matrix for Risk Rating CalculationRigorous Risk Cases and Risk Assessment AnalysisExample - Preparing Risk Register after Risk Assessment Calculations - Cybersecurity Risk as an ExampleRisk Treatment OptionsImplementing Controls - Preventive, Detective and Corrective ControlsInformation System Defense ControlsISO 27001 - Risk Mitigation Strategy and ControlsMultiple Choice Questions MCQs are also part of this courseYou will be able to "prepare Asset Risk, Impact and Likelihood Matrix", "perform Risk Assessment using Methodology", "prepare Vulnerability and Threat Matrix", "perform Risk and Financial Impact Pyramid Analysis", "apply Treatment Options", "understand Controls Categories" etc. as per ISO 27001 - Information Security Management System.To test your knowledge, the MCQs test is also part of this courseOther Benefits?After attending this course you will be able to:- apply concepts in your IS Security job - communicate with IS Security and IS Audit professionals - apply for jobs in organizations where ISO 27001 ISMS is implemented or to be implemented- pursue a career progression in IS Security domain - get the certificate of course completion etc.Who is this course for:Information System IS Security, IS Audit, IT Professionals and StudentsIS Security ConsultantsRisk Management Professionals and StudentsInternal Audit Professionals and StudentsFinance Professionals and StudentsCISA, CISM studentsCompliance professionalsAnyone who wants to learn the ISO 27001 standard's requirements for Information Security