Designing and Implementing Effective Cybersecurity Controls

Designing and Implementing Effective Cybersecurity Controls

35mIntermediate2024-03-25

Authors

Mani Keerthi Nagothu

Mani Keerthi Nagothu

Course details

In this course, learn the fundamentals of how security controls are designed and the relationship between vulnerability, threat, risk, and control in an organization. Instructor Mani Keerthi Nagothu details the risk terminology used in cyber risk assessments and the importance of a defense-in-depth approach for organizations. Understand the basics of cybersecurity standards, frameworks, and best practices to design controls. Get hands-on experience by going through an example ransomware attack and find out how to build controls to defend against these attacks.

Skills covered

Governance, Risk, and ComplianceNetwork SecurityCybersecurityOne-Off

Concepts

Introduction

  • Importance of controls
  • What you should know

A Holistic Approach to Cybersecurity

  • Using a defense-in-depth strategy
  • Understanding vulnerability, threat, risk, and control

Decoding Risk

  • Risk management process
  • Risk response and mitigation

Designing Effective Controls

  • Types of security controls
  • Security control actions
  • Designing controls

Standards, Frameworks, and Best Practices

  • Understanding ISO 27001
  • Exploring the NIST Cybersecurity Framework
  • Leveraging best practices - CIS Top 18

Ransomware Attack

  • Designing controls for initial access
  • Designing controls for lateral movement
  • Designing controls for execution and impact

Conclusion

  • Next steps
40,000 Toman