Course overview
The course aims to enable students to define and implement the architecture, design, management and controls that assure the security of business environments. The topics include recognition, analysis and assessments of risks, threats, and vulnerabilities, and measures to mitigate them, including implementing a control for a policy using frameworks such as ISO, NIST, ITIL, and CIS. Students will develop a comprehensive understanding of various frameworks, methodologies, and best practices related to information security, enabling them to assess risks, threats, and vulnerabilities effectively and implement appropriate measures to mitigate them.
- Fundamentals of Risk Management and Information Assurance
- Frameworks and Control Strategies
- Assurance and Communications
Course learning outcomes
- Apply the key concepts and principles of information assurance and risk management in an organisational cyber resilience context.
- Select and apply appropriate methods of conducting risk identification, assessment, analysis and impact assessments considering risk appetite and organisational context.
- Design, implement, and manage controls, using policy and procedures to safeguard information assets and mitigate security risks effectively
- Design, implement and assess the security policies, controls, and procedures that align with organisational objectives, ensure compliance, and promote cyber resilience.
- Effectively communicate risk and assurance processes and findings to internal and external stakeholders, supporting informed decision-making and continuous improvement in cyber security governance