|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/information-security-risk-management-iso-27005/
课程评论:没有评论
课程名称:信息安全风险管理(ISO 27005) 课程概述:在当今科技迅速发展的环境中,信息风险管理对各类企业至关重要。无论大小组织,都必须意识到当前的网络威胁可能使他们成为攻击者的理想目标。即便是拥有大量消费者的大型企业,也可能遭遇攻击。对于未做好准备的公司,网络攻击可能导致数据丢失、财务损失、品牌声誉受损以及员工士气下降。仅仅安装抗病毒软件已无法有效抵御攻击,抗病毒只是风险管理的一个方面。 因此,企业必须制定并实施风险管理策略,以降低行业特有的风险,并消除网络攻击的可能性。课程结束时,将有一个项目作业。提供了一份模板用于评估网络安全风险。学员需要利用该模板创建与自己的组织相关的至少五个网络安全风险,评估这些风险的可能性和影响,然后使用风险矩阵计算得分。在制定风险处理计划后,还需对剩余风险进行打分。风险矩阵及预填好的风险集可在文件中找到,可作为学员创建组织特定风险的参考。 通过本课程,学员将掌握信息安全风险管理的基本原则和实践技能,以应对日益严峻的网络安全挑战。
Given how quickly technology is evolving today's businesses, information risk management is crucial. Organizations of all sizes, small and large, need to be aware that the present cyber dangers might turn them into a valuable target for attackers. An attack might happen to even the largest business with a sizable consumer base. A cyberattack on an unprepared company could result in data loss, financial impact, harm to the brand's reputation, and employee morale loss. Installing antivirus software alone is no longer sufficient to stop attacks. One facet of risk management is antivirus.Organizations must create and implement a risk management strategy to reduce the risks that are unique to their industry and get rid of the possibility of cyberattacks. By the end of the course, there is a project. There is a provided template used to assess cyber security risks. You need to use this template to create at least 5 cyber security risks related to your organization. Assess the potentiality and impact of these risks, then calculate the score using a risk matrix. You then have to score the residual risks after creating a risk treatment plan.The matrix of risks is found in the file, the file also have pre-populated set of risks that you can use as a reference to create your organization specific risks.