NCA ECC - Business Resiliency Expert - Controls 2-9 to 4-2

所在平台: Udemy

课程主页: https://www.udemy.com/course/nca-ecc-advanced-operations-resilience-and-ot-part-3/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:NCA ECC - 商业韧性专家 - 控制2-9到4-2 课程概述:本高级课程完成了对国家网络安全局(NCA)基本网络安全控制(ECC)框架的学习,重点关注网络安全运营(家庭3)、第三方与云安全(家庭4)以及网络安全韧性(家庭5)这几个重要领域。该课程专为经验丰富的网络安全专业人员、事件响应团队、供应商管理者和业务持续规划人员设计,旨在帮助参与者在沙特阿拉伯复杂的网络安全环境中应对重大网络挑战。 参与者将深入了解如何将事件响应进行操作化,安全管理外部关系(包括云服务提供商),并建立强大的组织韧性,以应对重大网络中断。课程超越基本合规,强调将这些高级控制整合到组织的战略和运营结构中,以确保在不断演变的威胁面前提供全面的保护和持续性。通过实际场景和深入分析,学员将学习如何应对维持高水平网络安全成熟度的复杂性。 主要学习目标: 完成本课程后,参与者将能够: 1. 实施高级网络安全运营(控制家庭3): - 管理网络安全事件和威胁:制定和执行成熟的事件响应计划,进行深入的威胁情报分析,并有效管理从检测到恢复的网络安全事件生命周期。 - 开展取证调查:学习数字取证调查的原则和技术,以收集证据、确定根本原因,并支持法律或纪律行动。 - 管理信息披露:建立安全流程以处理和披露敏感的网络安全信息,确保遵守隐私和数据保护法规。 - 监督安全软件开发:将网络安全实践整合到整个软件开发生命周期中,包括安全编码和测试。 2. 保护第三方和云环境(控制家庭4): - 管理第三方网络安全风险:制定强大的框架来评估、管理和监控与供应商、供应商及其他第三方相关的网络安全风险。 - 实施云网络安全控制:理解并应用NCA ECC针对安全云计算和托管的具体要求,解决云服务提供商(CSP)和云服务租户(CST)在沙特阿拉伯语境下的责任。 3. 构建网络安全韧性(控制家庭5): - 将网络安全融入业务持续管理(BCM):将网络安全韧性方面无缝嵌入组织的整体业务连续性和灾难恢复计划,以确保关键功能能在网络相关中断中“站稳脚跟”和恢复。 - 制定网络危机沟通计划:创建有效的沟通策略,以管理公众和内部利益相关者在重大的网络安全事件期间和之后的沟通。 - 进行韧性测试和演练:计划并执行演练、桌面演习和全面模拟,以测试网络安全韧性计划的有效性并识别改进领域。 该课程对首席信息安全官(CISO)、安全架构师、事件响应经理、业务持续经理、第三方风险管理者、云安全工程师以及负责组织整体安全和韧性的高级IT/网络安全专业人士至关重要。

课程评论(0条)

课程详情

This advanced course completes the journey through the National Cybersecurity Authority's (NCA) Essential Cybersecurity Controls (ECC) framework, focusing on the critical domains of Cybersecurity Operations (Family 3), Third-Party and Cloud Security (Family 4), and Cybersecurity Resilience (Family 5). Designed for seasoned cybersecurity professionals, incident response teams, vendor managers, and business continuity planners, this program equips participants with the expertise to manage complex cyber challenges in the Saudi Arabian landscape.Participants will gain a deep understanding of how to operationalize incident response, securely manage external relationships including cloud service providers, and build robust organizational resilience against significant cyber disruptions. The course moves beyond basic compliance, emphasizing the integration of these advanced controls into an organization's strategic and operational fabric to ensure comprehensive protection and continuity in the face of evolving threats. Through practical scenarios and in-depth analysis, attendees will learn to navigate the intricacies of maintaining a high level of cybersecurity maturity.Key Learning Objectives:Upon completion of this course, participants will be able to:Implement Advanced Cybersecurity Operations (Control Family 3):Manage Cybersecurity Incidents and Threats: Develop and execute mature incident response plans, conduct thorough threat intelligence analysis, and effectively manage the lifecycle of cybersecurity incidents from detection to recovery.Conduct Forensic Investigations: Learn the principles and techniques for digital forensic investigations to gather evidence, determine root causes, and support legal or disciplinary actions.Manage Information Disclosure: Establish secure processes for handling and disclosing sensitive cybersecurity information, ensuring compliance with privacy and data protection regulations.Oversee Secure Software Development: Integrate cybersecurity practices into the entire software development lifecycle, from design to deployment, including secure coding and testing.Secure Third-Party and Cloud Environments (Control Family 4):Manage Third-Party Cybersecurity Risks: Develop robust frameworks for assessing, managing, and monitoring cybersecurity risks associated with vendors, suppliers, and other third parties.Implement Cloud Cybersecurity Controls: Understand and apply specific NCA ECC requirements for secure cloud computing and hosting, addressing responsibilities for both cloud service providers (CSPs) and cloud service tenants (CSTs) within the KSA context.Build Cybersecurity Resilience (Control Family 5):Integrate Cybersecurity into Business Continuity Management (BCM): Seamlessly embed cybersecurity resilience aspects into the organization's overall business continuity and disaster recovery plans to ensure critical functions can withstand and recover from cyber-related disruptions.Develop Cyber Crisis Communication Plans: Create effective communication strategies for managing public and internal stakeholders during and after a significant cybersecurity incident.Conduct Resilience Testing and Exercises: Plan and execute drills, tabletop exercises, and full-scale simulations to test the effectiveness of cybersecurity resilience plans and identify areas for improvement.This course is indispensable for Chief Information Security Officers (CISOs), Security Architects, Incident Response Managers, Business Continuity Managers, Third-Party Risk Managers, Cloud Security Engineers, and senior IT/cybersecurity professionals who are responsible for the comprehensive security and resilience of their organizations in Saudi Arabia.

课程标签

0人关注该课程

主题相关的课程