CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance

CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance

1h 44mBeginner2021-01-22

Authors

Mike Chapple

Mike Chapple

Teaching Professor at the University of Notre Dame

Course details

Prepare for the Governance, Risk, and Compliance domain of the CompTIA Security+ (SYO-601) Cert Prep test. Instructor Mike Chapple explains how to lay the groundwork for a strong cybersecurity program, manage risk, and comply with legal and regulatory obligations. He recommends books and other resources to help you prepare. Mike teaches you about qualitative and quantitative risk assessment, risk types, and techniques to classify information. He walks you through how to select appropriate security controls, conduct ongoing risk management activities, and use a risk management framework. Mike also covers security policies, standards, guidelines, and procedures; goes over how to handle data security and data breaches; and explores different privacy enhancing technologies. Mike steps through security awareness and training, then closes with suggestions on how to continue preparing for the test.

Skills covered

Governance, Risk, and ComplianceCert PrepCybersecurity

Concepts

Introduction

  • Governance, risk, and compliance
  • What you need to know
  • Study resources

Risk Analysis

  • Risk assessment
  • Quantitative risk assessment
  • Risk types
  • Information classification

Risk Management

  • Risk treatment options
  • Categorizing security controls
  • Ongoing risk management
  • Risk management frameworks
  • Control frameworks
  • Risk visibility and reporting
  • Data security roles

Supply Chain Risk

  • Managing vendor relationships
  • Vendor agreeements
  • Vendor information management
  • Audits and assessments
  • Cloud audits

Security Policies

  • Security policy framework
  • Security policies

Privacy and Compliance

  • Legal and compliance risks
  • Data privacy
  • Data breaches

Privacy Enhancing Technologies

  • Data anonymization
  • Data obfuscation

Security Awareness and Training

  • Security education
  • User habits
  • Separation of duties

Conclusion

  • Continuing your studies
40,000 Toman