Implementing an Information Security Program
2h 34mIntermediate2020-06-02
Authors

Kip Boyle
Founder and CEO of Cyber Risk Opportunities
Course details
Building and operating an information security program at your organization can be challenging. The scope can be vast and complex. Thinking of all the ways an organization can fail and coming up with actionable measures you can take to prevent issues, mitigate risk, or recover from events is a large undertaking. In this course, Kip Boyle, president of Cyber Risk Opportunities, guides you through the entire process of creating an information security program, rolling it out to your organization, and maintaining it for continuous risk management.
Topics include:
Name the goals of information security.
Cite the benefits of risk management.
Describe the essential functions of an information security program.
Summarize how to define your role in an information security program.
Explain the importance of a plan to measure information risks.
Recognize how questions drive the development of an information security program.
Identify ways to generate ideas to manage top risks.
Describe the audit function.
Topics include:
Name the goals of information security.
Cite the benefits of risk management.
Describe the essential functions of an information security program.
Summarize how to define your role in an information security program.
Explain the importance of a plan to measure information risks.
Recognize how questions drive the development of an information security program.
Identify ways to generate ideas to manage top risks.
Describe the audit function.
Skills covered
Governance, Risk, and ComplianceCybersecurity
Concepts
0. Introduction
- 01 - Protect against cyber attacks
- 02 - What you should know
- 03 - Information security overview
- 04 - Cybersecurity overview
- 05 - Cyber resilience overview
- 06 - Risk management overview
1. Information Security Program Goals
- 07 - Achieve your customers expectations
- 08 - Cyber-attack and failure resilience
- 09 - Compliance with laws and regulations
- 10 - Support executives and the BOD
2. Information Security Program Components
- 11 - Essential functions of a program
- 12 - Determine your role
- 13 - Build a team
- 14 - The need for management
- 15 - The need for leadership
3. Structure an Information Security Program
- 16 - Sources of controls
- 17 - Organize around cyber resilience
- 18 - Design an information security program
4. Measure Information Risks
- 19 - Plan to measure information risks
- 20 - Use a data-driven cyber risk management method
- 21 - Understand the 0 to 10 scale
- 22 - Set target scores for each control
- 23 - Decide where to measure information risk
- 24 - Create a score key for experts
- 25 - Prepare to collect scores from experts
- 26 - Set up a score collection workflow
- 27 - Collect scores from your systems
5. Understand Information Risks
- 28 - The questions that drive us
- 29 - Determine resilience
- 30 - Determine the top five risks
- 31 - Understand the leadership landscape
6. Manage Information Risks
- 32 - Generate ideas to manage top risks
- 33 - Estimate costs
- 34 - Estimate benefits
- 35 - Prepare proposals
7. Demonstrate Compliance and Progress
- 36 - Communicate with executives
- 37 - Communicate with stakeholders
- 38 - Communicate with auditors
8. Use a Workflow to Organize Work
- 39 - Determine measurement frequency
- 40 - Build on baseline measurements
- 41 - Construct an annual program of work
Conclusion
- 42 - Next steps