CompTIA Security+ (SY0-601) Cert Prep: 10 Governance, Risk, and Compliance
1h 44mBeginner2021-01-22
Authors

Mike Chapple
Teaching Professor at the University of Notre Dame
Course details
Prepare for the Governance, Risk, and Compliance domain of the CompTIA Security+ (SYO-601) Cert Prep test. Instructor Mike Chapple explains how to lay the groundwork for a strong cybersecurity program, manage risk, and comply with legal and regulatory obligations. He recommends books and other resources to help you prepare. Mike teaches you about qualitative and quantitative risk assessment, risk types, and techniques to classify information. He walks you through how to select appropriate security controls, conduct ongoing risk management activities, and use a risk management framework. Mike also covers security policies, standards, guidelines, and procedures; goes over how to handle data security and data breaches; and explores different privacy enhancing technologies. Mike steps through security awareness and training, then closes with suggestions on how to continue preparing for the test.
Skills covered
Governance, Risk, and ComplianceCybersecurityCert Prep
Concepts
0. Introduction
- 01 - Governance, risk, and compliance
- 02 - What you need to know
- 03 - Study resources
1. Risk Analysis
- 04 - Risk assessment
- 05 - Quantitative risk assessment
- 06 - Risk types
- 07 - Information classification
2. Risk Management
- 08 - Risk treatment options
- 09 - Categorizing security controls
- 10 - Ongoing risk management
- 11 - Risk management frameworks
- 12 - Control frameworks
- 13 - Risk visibility and reporting
- 14 - Data security roles
3. Supply Chain Risk
- 15 - Managing vendor relationships
- 16 - Vendor agreeements
- 17 - Vendor information management
- 18 - Audits and assessments
- 19 - Cloud audits
4. Security Policies
- 20 - Security policy framework
- 21 - Security policies
5. Privacy and Compliance
- 22 - Legal and compliance risks
- 23 - Data privacy
- 24 - Data breaches
6. Privacy Enhancing Technologies
- 25 - Data anonymization
- 26 - Data obfuscation
7. Security Awareness and Training
- 27 - Security education
- 28 - User habits
- 29 - Separation of duties
Conclusion
- 30 - Continuing your studies