Course Outline
Module 1 – Foundation
- Introduction to Cyber Security
- Seveity of Security Breaches
- Hacker Tools
- Sources of Transmission
- Regulatory Challenges
- Vulnerable Businesses
- Cost of Cyber Attacks
- System Threat and Vulnerability
- Fundamental Access Controls
- Assurance Authentication
- Functionally Base Measure
- CIA Model
- Control Objective
- Information Security
- NIST standard introduction
- Cyber Security Framework
- Improving Cyber Security Programming
- Designing IT Governance
- ISO Management needs
Module 2 – ISMS Requirements
- Context
- Needs and Expectations
- Scope of ISMS
- Leadership and Commitment
- Leadership
- Information Security Policy
- Organizational Roles
- General Aspects
- Information Security Risk Assesment
- Competance ISMS
- Awareness ISMS
- Communication Sources
- Information Risk Security Assessment
- Operation of ISMS
- Operation Control and Planning
- Monitoring measurement analysis
- Management Review
- Corrective and Improvement
Module 3 – Information Security Operations Controls
- Information Security Controls
- ISO 27001 Operation Controls
- Information Security Policies
- Policies for Information Security
- Information Security in Project Management
- Internal Organization
- Organization of Information Security
- Human Resource Security
- Disciplinary Process
- Infomrmation Security Awareness
- Management Responsibilities
- Asset Management
- Information Classification
- Handling Assets
- Labeling of Information
- Media Handling
- Management Removable Media
- Access Controls
- User Access Management
- User Registration
- Information Security Policies
Module 3.1 – Information Security Operations Controls
- Access Control Programme
- Password Management System
- System and Application Access
- Cryptography
- Policy on Use of Cryptography
- Delivery and Loading Areas
- Physical Entry Controls
- Protecting against External
- Securing Offices
- Working in Secure Areas
- Equipment Siting and Proctection
- Cabling Security
- Equipment Maintenance
- Security of Equipment
- Supporting Utilities
- Operating Security
- Capacity Management
- Logging and Monitoring
- Protection of Log Information
- Control of Operational Software
- Physical Security Perimeter
- Working in Secure Areas
- Delivery Loading Areas
- Clear Desk Policy
- Equipment Maintenance
- Restriction on Software Installation
- Unattended User Equipment
- Information Audit Controls
- Communications Security
- Segregation in Networks
- Information Tester
