|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/practical-compliance-management-for-grc-professionals/
课程评论:没有评论
Coursera 课程“GRC 专业人士的实用合规管理”综合概述: 本课程专为希望获得 GRC(治理、风险、合规)领域实践经验的学员设计,尤其侧重于合规管理。课程分为两个主要部分: **第一部分:基础知识** 本部分旨在为学员打下坚实的 GRC 理论基础,内容涵盖: * **GRC 概述:** 深入理解 GRC 的概念、重要性、优势及面临的挑战。 * **风险管理:** 学习风险管理的定义、流程,以及如何识别、评估和处理风险。 * **合规管理:** 掌握合规管理的概念、流程,如何识别法规和标准、评估合规风险,并制定和实施合规管理计划。 * **监控与评估:** 学习如何监控合规情况,评估合规管理计划的有效性,并进行持续改进。 **第二部分:实践操作活动** 这部分是课程的核心亮点,学员将有机会在真实的平台环境中进行大约 10 小时的引导式实验,以获得宝贵的动手操作经验。具体训练内容包括: 1. **合规管理:** 学习如何认证和管理 ISO 27001、PCI-DSS、NIST、SOC2 等多种合规计划。 2. **风险管理:** 实践资产、第三方和业务风险的管理。 3. **数据保护计划:** 学习如何建立和运营数据保护计划。 4. **内部控制与审计:** 记录内部控制措施及其审计记录。 5. **政策管理:** 记录政策、程序、标准等,并管理其审查流程。 6. **事件管理:** 在一个地方记录和管理安全事件的整个生命周期。 7. **资产管理:** 定义和审查主要用于风险和数据保护计划的资产。 8. **项目管理:** 管理 GRC 计划的积极和被动改进。 9. **例外管理:** 记录和管理风险、合规和政策例外情况的整个生命周期。 10. **业务连续性计划:** 学习制定和管理业务连续性计划。 通过这两部分的学习,学员将全面掌握 GRC 的理论知识,并通过实际操作获得在 GRC 岗位上所需的关键技能。
This course is for people who need to develop and gain the relevant practical hands-on experiences to apply for a role in GRC. For example compliance management.The course is divided into two sections as follows:SECTION 1-FundamentalsUnderstand the principles of governance, risk management, and compliance (GRC).Identify and assess risks to an organization's compliance with regulations and standards.Develop and implement a compliance management program.Monitor and evaluate the effectiveness of the compliance management program.Course OutlineModule 1: Introduction to GRCWhat is GRC?The importance of GRCThe benefits of GRCThe challenges of GRCModule 2: Risk ManagementWhat is risk management?The risk management processIdentifying risksAssessing risksTreating risksModule 3: Compliance ManagementWhat is compliance management?The compliance management processIdentifying regulations and standardsAssessing compliance risksDeveloping and implementing a compliance programModule 4: Monitoring and EvaluationMonitoring complianceEvaluating the effectiveness of the compliance programContinuous improvementSECTION 2-PRACTICAL HANDS-ON ACTIVITIESStudent will be introduced to a real-live platform environment that will allow them to practice all of the below GRC activities to develop their practical experience. This consists of approximately 10 hours of lab guided exercises.1. -Compliance Management- Learn how to certify and manage a ISO 27001, PCI-DSS, NIST, SOC2, etc. program2. -Risk Management-Learn how to implement Asset, Third Party and Business Risk Management3. -Data Protection Program-Learn how to implement ad operate a data protection program4. -Internal Controls & Audits- Record your internal controls and their audit records5. -Policy Management- record your policies, procedures, standards etc., and manage their reviews6. -Incident Management- Record and manage security incidents lifecycle in one place7. -Asset Management- Define and review assets primarily used in Risks and Data Protection programs8. -Project Management- Manage proactive and reactive improvements to your GRC program9. -Exception Management- Record and manage risks, compliance and policy exceptions lifecycle10. -Business Continuity Plans