Course Description:

Course Description:


In an era of escalating cyber threats, adequate security requires more than just firewalls; it demands robust governance and strategic leadership. This course explores the principles of Enterprise Information Security Management, focusing on how to govern, risk-manage, and operate a secure environment at scale.

We will dissect the critical intersection of people, processes, and technology, covering essential topics such as Identity and Access Management (IAM), security assessment strategies, and disaster recovery planning. Ideal for those moving into senior roles, this course establishes the foundational knowledge required to lead security initiatives and implement defence-in-depth architectures across complex enterprises.

This curriculum is structured to align with global industry bodies of knowledge for advanced security practitioners, including the following topics:

  • Security and Risk Management sets up the governance, compliance, and risk frameworks needed to align security efforts with business objectives. This baseline guarantees that each security measure has a clear strategic purpose, appropriate budget allocation, and legal backing.

  • Asset Security involves identifying, classifying, and managing data throughout its lifecycle to ensure protection controls are proportional to the asset's value. You cannot effectively secure or legally defend data without knowing its location, ownership, and value.

  • Security Architecture and Engineering explains how to incorporate security models and cryptography during system design to ensure systems are "secure by design." This approach helps prevent critical vulnerabilities that are costly or impossible to fix after deployment.

  • Communication and Network Security connects secure design principles with network architecture, ensuring the core pathways for data transfer are structurally sound. If the foundational blueprint is flawed, operational monitoring alone cannot keep the environment secure.

  • Identity and Access Management (IAM) describes how to verify identities and restrict access, serving as the primary safeguard against unauthorised entry. Strong IAM controls prevent attackers from impersonating legitimate users and moving through your systems unnoticed.

  • Security Assessment and Testing verifies the effectiveness of security controls through detailed audits and penetration testing. This "trust but verify" approach uncovers hidden vulnerabilities so they can be addressed before attackers exploit them.

  • Security Operations implements daily security measures, including incident response and disaster recovery, to maintain business continuity. This enables quick detection of threats and rapid recovery after disruptions.

  • Software Development Security applies best practices to the Software Development Lifecycle (SDLC) to prevent coding vulnerabilities from the start. Fixing flaws during development is safer and more cost-effective than patching live systems. Establishes the governance, compliance, and risk frameworks necessary to align security initiatives with business goals. This foundation ensures that every security measure has a strategic direction, budget justification, and legal enforceability.

Principles of Information Security Management

Buy nowLearn more
  • Course Description:

1. Security and Risk Management (1 - 2h)

  • A Strategic Governance and Risk Architecture
  • Cybersecurity Architecture: Fundamentals of Confidentiality, Integrity, and Availability (12 min)
  • Risky Business: Strengthening Cybersecurity with Risk Analysis (12 min)
  • Controls Categories (12 min)
  • Zero Trust (7 min)
  • Cyber Risk Management: Essentials for the Practical CISO (1 hr)

2. Asset Security (0.5 - 1h)

  • Asset Security
  • Data Security: Protect your critical data (or else) (6 min)
  • SSD Data destruction (10 min reading)
  • Google Data Center Security: 6 Layers Deep (2 min)
  • Data Governance (10 min)

3. Security Architecture and Engineering (3 - 4 hrs)

  • Security Architecture and Engineering
  • Cryptography: Crash Course Computer Science (12 min)
  • The Adventure of Alice and the Encrypted Message (14 min)
  • Steganography (3 min)
  • Virtualization Explained (5 min)
  • Cybersecurity Architecture: Who Are You? Identity and Access Management (30 min)
  • Cloud security guidance (30 min - reading)
  • Full SANS Webcast | Decoding the Shared Responsibility Model (49 min)
  • Buffer Overflows (3 min)
  • Stack vs Heap Memory - Simple Explanation ( 5 min)
  • What are hardware security modules (HSM), why we need them and how they work. (7 min)
  • How Access Control Systems Work | Point Monitor Corporation (6 min)

4 - Communication and Network Security (2 - 3 hrs)

  • Network Security basics
  • Understanding the OSI Model (12 min)
  • Cybersecurity Architecture: Networks (27 min)
  • Internet Networks & Network Security | Google Cybersecurity Certificate (1 hr)
  • How does HTTPS work? What's a CA? What's a self-signed Certificate? (11 min)
  • Kerberos (3 min)

5 - Identity and Access Management (1- 2hr)

  • Identity and Access Management (12 min)
  • Cybersecurity Architecture: Who Are You? Identity and Access Management (31 min)
  • OAuth terminologies and flows explained (24 min)

6. Security Assessment and Testing

  • Key Terminology
  • Building a Cybersecurity Framework (8 min)
  • NIST Cybersecurity Framework 2.0 (5 min)
  • SOC 1 vs SOC 2 Audits: What’s the Difference? (5 min)
  • CertMike Explains SOC Audits (8 min)

7 - Security Operations

  • The Incident Scene & Evidence Collection
  • Malware (21 min)
  • Attack Frameworks (8 min)
  • How Hackers Steal Passwords: 5 Attack Methods Explained (13 min)
  • Examples: Data resilience, RAID and storage

8- Software Development Security

  • Software Development Security
  • Cybersecurity Architecture: Application Security (16 min)
  • Container Security Explained (6 min)
  • Threat Modeling in the Age of AI - Susanna Cox (45 min)