Building and Auditing a Cybersecurity Program
1h 47mBeginner2022-04-18
Authors

Michael Ratemo
Founder and Principal Consultant at Cyber Security Simplified
Course details
If your company has any online presence at all, it should go without saying that you need to devote resources to cybersecurity, as cyber attacks increase and ransomware becomes more commercialized. The goal of this course is to provide a comprehensive methodology with which anyone can use to assess any organization's cybersecurity program, whether you’re an IT or cybersecurity professional, executive, auditor, or a board of directors member. Join cybersecurity professional Michael Ratemo as he teaches you the key elements that make up a cybersecurity program, what to look for when reviewing the various elements, and how to evaluate the effectiveness of the program. Whether you need to build a cybersecurity program from scratch, or understand the state of your organization’s current cybersecurity measures, this course provides valuable information to help you secure your data.
Skills covered
Incident ResponseCybersecurityOne-Off
Concepts
0. Introduction
- 01 - Cybersecurity simplified
- 02 - Creating the cybersecurity program framework
1. Cybersecurity Governance
- 03 - Adopt security frameworks to drive cybersecurity governance
- 04 - Consider laws and regulations in cybersecurity governance
- 05 - Policies, standards, and procedures to govern cybersecurity
- 06 - Roles and responsibilities for cybersecurity governance
- 07 - Cyber risk management program for cybersecurity governance
- 08 - Risk management process to prioritize cyber defense
2. Inventory and Security of Assets
- 09 - Infrastructure asset management for cybersecurity
- 10 - Software asset management for cybersecurity
- 11 - Secure cyber supply chain to reduce risk of external threats
3. Data Protection
- 12 - Establish data security management practices to protect data
- 13 - Encryption to provide confidentiality of data
- 14 - Access management to control unauthorized access
- 15 - Vulnerability management to mitigate security weaknesses
- 16 - Secure configuration process to minimize vulnerabilities
4. Detect Potential Security Threats
- 17 - Network security monitoring to detect cyber threats
5. Respond to Cybersecurity Events
- 18 - Incident management to respond to a cyber attack
6. Recover Capabilities after a Cybersecurity Event
- 19 - Integrating cybersecurity into disaster recovery
- 20 - Data backups to defend against ransomware and cyber threats
7. Secure Applications Including Cloud and Emerging Technologies
- 21 - Application security to mitigate data breaches
- 22 - Cloud security to protect cloud data from threats
Conclusion
- 23 - Additional resources