ποΈ
Tutorial 6.1
Introduction to Security Management and Governance
Foundations, security management vs. governance, program lifecycle, and leadership.
Start β
π
Tutorial 6.2
Information Security Governance and Organizational Structures
Board responsibilities, CISO role, steering committees, and governance frameworks.
Start β
β οΈ
Tutorial 6.3
Risk Management Fundamentals
Assets, threats, vulnerabilities, risk appetite, and the risk management process.
Start β
π
Tutorial 6.4
Risk Assessment Methodologies and Frameworks
NIST SP 800-30, ISO 27005, OCTAVE, FAIR, and hybrid approaches.
Start β
π
Tutorial 6.5
Security Policies, Standards, Procedures, and Guidelines
Documentation hierarchy, policy lifecycle, and enforcement.
Start β
π§
Tutorial 6.6
Security Controls and Control Frameworks
Administrative, technical, physical controls; ISO 27001 Annex A, NIST SP 800-53, CIS Controls.
Start β
π
Tutorial 6.7
Security Planning and Program Management
Strategic, tactical, operational planning; PDCA, maturity models, resource management.
Start β
π¨
Tutorial 6.8
Incident Response Planning and Management
Lifecycle (NIST/SANS), team roles, communication, legal considerations.
Start β
π
Tutorial 6.9
Business Continuity and Disaster Recovery
BCP, BIA, RTO/RPO, recovery strategies, backup, and testing.
Start β
π
Tutorial 6.10
Physical and Environmental Security
Layered defense, access controls, environmental controls, and infrastructure protection.
Start β
ποΈ
Tutorial 6.11
Infrastructure Security and Facility Protection
Secure facility design, telecom, data centres, utilities, and ICS/OT security.
Start β
π§βπ»
Tutorial 6.12
Human Factors in Security
Human error, insider threats, social engineering, and security culture.
Start β
π
Tutorial 6.13
Security Awareness, Education, and Training
Awareness vs. training vs. education, program design, and effectiveness measurement.
Start β
π
Tutorial 6.14
Insider Threats and Personnel Security
Employee lifecycle, background checks, monitoring, and offboarding.
Start β
π
Tutorial 6.15
Security Auditing and Compliance
Audit types, evidence, reporting, and regulatory frameworks (ISO, PCI DSS, HIPAA, GDPR).
Start β
π
Tutorial 6.16
Security Metrics, Monitoring, and Reporting
KPIs, KRIs, dashboards, executive reporting, and advanced analytics.
Start β
βοΈ
Tutorial 6.17
Legal Issues in Cybersecurity
Cybercrime laws, privacy regulations, evidence handling, and liability.
Start β
π§
Tutorial 6.18
Ethical Issues and Professional Responsibility
Ethical frameworks, professional codes (ACM, IEEE, ISCΒ²), and public responsibility.
Start β
π
Tutorial 6.19
Emerging Governance, Risk, and Compliance Challenges
Cloud, AI, supply chain, Zero Trust, and privacy governance.
Start β
π§©
Tutorial 6.20
Unit 6 Integration and Comprehensive Case Studies
Synthesis of all topics, integrated framework, and three inβdepth case studies.
Start β