|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/selection-and-implementation-of-cybersecurity-risks-controls/
课程评论:没有评论
**课程名称:** 安全控制的选择与实施 **课程概述:** 本课程旨在帮助入门级和经验丰富的网络安全专业人士,发展一种更全面而非孤立的方法来实施控制,以应对网络或信息安全风险。课程内容涵盖了安全控制的识别、选择、实施和绩效度量的整个生命周期,并强调了成本效益分析、技术集成、运营影响、员工培训、法规遵从和事件响应规划等关键考虑因素。 **课程内容要点:** * **课程介绍与方法论:** 介绍课程目标、案例分析以及控制选择的系统性方法。 * **安全控制基础:** 深入探讨安全控制的概念、识别、选择和实施的关键考虑因素。 * **风险评估与管理:** 学习风险评估、业务影响分析(BIA)、成本效益分析在控制选择中的应用。 * **技术与运营集成:** 关注技术集成、运营影响、持续监控和员工培训在实施控制中的作用。 * **法规遵从与事件响应:** 强调法规遵从和事件响应规划对于安全控制的重要性。 * **电子商务Web服务器安全案例:** 通过具体案例,详细阐述保护电子商务Web服务器的安全控制选择和实施过程,包括风险评估的步骤(识别资产、威胁、漏洞,确定可能性、影响,计算风险),以及撰写风险评估报告。 * **框架的应用与考量:** 探讨现有安全框架(如NIST CSF)的优势、挑战、适用场景以及如何基于框架选择和实施控制。 * **实施与评估:** 制定控制实施计划,并学习度量已实施控制的有效性。 * **综合应用与复习:** 将所学知识融会贯通,完成对安全控制选择与实施的全面理解,并进行课程回顾。 * **课程作业:** 研究。 **核心学习目标:** 学员将能够: * 采用一种全面的视角来处理网络或信息安全风险。 * 系统地识别、评估和选择适当的安全控制。 * 理解并应用风险评估和成本效益分析来支持控制决策。 * 考虑技术、运营、人员和法规方面的因素以确保控制的有效性。 * 能够基于行业标准和框架(如NIST CSF)实施安全控制。 * 制定安全控制的实施计划并衡量其绩效。
This course was developed as a means of helping entry-level as well as seasoned cybersecurity professionals, to develop a more holistic rather than isolated approach to implementing controls to address cyber or information security risks. The content of this course is as follows:SECTION 1 TOPICS1a-Course Intro1b-Course Intro- The Case at hand2-About the course3-Meet your Instructor-Mentor4-Course Roadmap5-Approach to Control Selection_ pt16-Approach to Control Selection_ pt27-Applying same approach to real Data Breaches at a high-level8-Introduction to security controls9-Key considerations for the identification- selection & implementation of controls10-Risk Assessment-BIA, Control Selection, Cost Benefit Analysis11-Cost Benefit Analysis associated with controls selection12-Technology integration, Operational impact, continuous monitoring, Employee training13-Regulatory Compliance, Incident Response PlanningSECTION 2 TOPICS14-High-level process of selecting controls to protect eCommerce web server-Pt114-High-level process of selecting controls to protect eCommerce web server-Pt215-Steps involved in assessing the identified cyber risks in web server16-Identify assets, identify threats, identify vulnerabilities 17-Determine likelihood, Impact, Calculate risk18-Documenting Cybersecurity Risk Assessment Report-Pt 218-Documenting Cybersecurity Risk Assessment Report-Pt 119-The role of governance in the effective selection and implementation of cybersecurity controls 20-Why not implement frameworks that already have recommended controls21-Challenges, considerations & disadvantages associated with implementing frameworks-Pt 121-Challenges, considerations & disadvantages associated with implementing frameworks-Pt 222-When to, versus when not to use frameworks for the selection and implementation of controls23-Selecting and implementing cybersecurity controls based on the NIST Cybersecurity Framework (CSF) Pt123-Selecting and implementing cybersecurity controls based on the NIST Cybersecurity Framework (CSF) Pt224-Implementation Plan for identified controls25- Measuring the effectiveness of implemented controls26-Putting it all together-The Selection and Implementation of Cybersecurity Risks Controls27-Course Recap-ENDASSIGNMENT-Research