Designing and Implementing Effective Cybersecurity Controls
35mIntermediate2024-03-25
Authors

Mani Keerthi Nagothu
Course details
In this course, learn the fundamentals of how security controls are designed and the relationship between vulnerability, threat, risk, and control in an organization. Instructor Mani Keerthi Nagothu details the risk terminology used in cyber risk assessments and the importance of a defense-in-depth approach for organizations. Understand the basics of cybersecurity standards, frameworks, and best practices to design controls. Get hands-on experience by going through an example ransomware attack and find out how to build controls to defend against these attacks.
Skills covered
Governance, Risk, and ComplianceNetwork SecurityCybersecurityOne-Off
Concepts
0. Introduction
- 01 - Importance of controls
- 02 - What you should know
1. A Holistic Approach to Cybersecurity
- 03 - Using a defense-in-depth strategy
- 04 - Understanding vulnerability, threat, risk, and control
2. Decoding Risk
- 05 - Risk management process
- 06 - Risk response and mitigation
3. Designing Effective Controls
- 07 - Types of security controls
- 08 - Security control actions
- 09 - Designing controls
4. Standards, Frameworks, and Best Practices
- 10 - Understanding ISO 27001
- 11 - Exploring the NIST Cybersecurity Framework
- 12 - Leveraging best practices - CIS Top 18
5. Ransomware Attack
- 13 - Designing controls for initial access
- 14 - Designing controls for lateral movement
- 15 - Designing controls for execution and impact
Conclusion
- 16 - Next steps