
Definitions for the cyberspace. Stakeholders in the cyberspace. Changes brought by the digital world.
What is cybercrime and what are the costs of cybercrime to the global economy. What is the purpose of cybersecurity - protecting the confidentiality, integrity and availability of information. The three directions of cybersecurity: prevention, detection and response. Return of investment for cybersecurity. About Software as a Service, Platform as a Service and Infrastructure as a Service. About ISO 27001 and ISO 27017. Is there a difference between information security and cybersecurity?
Different positions in cybersecurity and a brief descriptions of the main responsibilities and authorities. CISO, cybersecurity manager, cybersecurity architect, security auditor ...
The three elements of the C-I-A triad - Confidentiality, Integrity, Availability and their definitions. Plus another important concept - Non-repudiation.
The purpose of information classification. Common classification schemes in military/ government organizations and the business environment. Information labeling.
Definitions and examples for threats and vulnerabilities.
Ingredients of risk - probability and impact. Quantitative and qualitative methods for risk assessment - details, examples and advantages for each category.
Common options for treating risk and their definitions. The concept of residual risk. Categories of controls - technical, procedural (administrative) and physical.
Why support from senior management is important. The cybersecurity policy.
Common internal organization for cybersecurity. The position of a Chief Information Security Officer (CISO).
The principle of duties segregation or separation. Why is it important and examples. Job rotation principle and mandatory vacations.
The story of the Barings bank collapse and how duties segregation can be a critical aspect.
What is BYOD. Benefits and risks that come along with BYOD. Aspects to be addressed in the BYOD policy. COPE - Company Owned Personally Enabled.
Rules for mobile devices. MDM (Mobile Device Management) and MAM (Mobile Application Management).
Security requirements and responsibilities for each position. Screening candidates. Contractual agreements (NDAs - Non Disclosure Agreements and NCA - Non-Compete Agreements). The disciplinary process. Security requirements for the termination or change of employment.
Security awareness - why it is important and methods. Cybersecurity training for company staff.
The asset inventory. Assigning owners to assets - why and how. Acceptable use policies.
Security risks associated to the use of removable media. Security controls for removable media.
A short presentation of Edward Snowden's story and the huge security breach he created by revealing NSA classified information to the public. The importance of removable media.
What does access control involve. Solutions for access controls. Common authentication factors - type 1, type 2 and type 3 authentication + multi-factor authentication. Disabling access rights of terminated employees.
The principle of least privileges. Guidelines for preventing security breaches due to special privileges
Definition and guidelines for logging. Protection of logs; log retention. Monitoring as the process of reviewing logs.
Brief history of cryptography. Concepts like the cipher and the algorithm. The Kerckhoffs principle. General aspects about symmetric and asymmetric cryptography.
The hash function. Requirements for the hash function. Definition of the digital signature.
Definition for a Public Key Infrastructure. Certification and registration authorities. About digital certificates.
Examples and short description of common cryptographic attacks: brute force, rainbow tables, birthday, man in the middle.
Multiple layers for physical security in a building. Fire protection. Public areas. Secure areas.
Security controls for company equipment. Controls for unattended equipment. Requirements for taking equipment off premises. Wiring closets. Server rooms. Cabling security. Electromagnetic emanation and TEMPEST.
Malware definition. Common types of malware: viruses, logic bombs, worms, trojan horses, worms, spyware, adware, ransomware
Ransomware - encrypting and blocking ransomware. How they work and factors that make certain organizations attractive for ransomware. Recommendation to protect against ransomware. Pay the ransom or not? Leakware or doxware.
Definition of phishing. Types of phishing: deceptive phishing, spear phishing, whaling, pharming. Controls against phishing.
Denial of service attacks - definition and how they work. Distributed Denial of Service (DDoS). DDoS mitigation.
What is social engineering and how it works. Training and awareness against social engineering.
Common password attacks: password guessing, dictionary attacks, keyloggers. Guidelines for password management.
The contents of a backup policy. Differential and incremental backups.
The change process in an organization. The steps for implementing changes in a controlled manner.
Principles and key elements for network security management - networks segregation, firewalls. Wireless networks and common wireless attacks: man in the middle, packet sniffing, evil twin attacks Guidelines for protecting wireless networks.
Contents for an email security policy. Controls for protecting data in emails.
The development lifecycle. The contents of the secure development policy. Outsourcing software development.
Screening suppliers. Security requirements in supplier contracts. Security of the supply chain. Monitoring supplier performance.
The security breach that hit the Target corporation in 2013. How it happened and why.
Capacity management definition. The contents of the capacity plan.
The stages of incident management - detection, response, communication, recovery, root cause analysis for corrective and preventive actions, learning from incidents.
The story of the Uber security breach of 2016. Dealing with the hackers.
The most relevant business continuity activities - business impact analysis; risk assessment; the emergency team; business continuity strategy and business continuity plans. Testing and improving business continuity arrangements.
Security legal compliance. Privacy and the GDPR most relevant requirements. Compliance with other requirements.
The future of cybersecurity. Big data will grow bigger. The Internet of Things.
This course teaches the foundations of cybersecurity management through the lens of ISO/IEC 27001, the leading international standard for information security. You will learn the concepts, principles and controls an organization needs to design and run a cybersecurity program: the typical security threats facing different activities and processes, and the recommended controls to protect against them.
Course structure
Foundations — cyberspace and cybersecurity defined; confidentiality, integrity, authentication and non-repudiation as critical elements of any security system
Information classification — schemes, levels and labelling
Risk management — threats, vulnerabilities, risk assessment (quantitative and qualitative methods), and the options for treating security risks
Organizing security — top management support, segregation of duties, and human resources security from screening and contractual requirements through the disciplinary process to termination and change of employment
Devices and media — mobile device policies including BYOD (bring your own device) and COPE (company owned, personally enabled), and the rules for removable media
Access control and authentication — managing access rights and privileges so they don't become security breaches; password management, common password attacks and their controls
Cryptography — core concepts, digital signatures and public key infrastructure (PKI), plus the most common cryptographic attacks (brute force, rainbow tables, birthday attacks) and how to defend against them
Attacks and malware — viruses, worms, trojans, logic bombs, spyware and adware, with a detailed presentation of ransomware; denial-of-service attacks; social engineering and phishing
Operational security — physical and equipment security, backups, change management, capacity management, email security, network security principles and controls, wireless attacks and their prevention, and security in development processes
Suppliers and third parties — the risks associated with suppliers' access to your information assets
Incident management and continuity — managing cybersecurity incidents from detection to closure and root cause analysis; business continuity and preparing for crisis situations
Compliance — the compliance requirements every organization must respect
Learning from real cases
The concepts are illustrated with easy-to-follow explanations, examples and case studies — including the Barings Bank collapse, the Target security breach and Edward Snowden — plus a quiz at the end to test what you've learned.
Who this course is for
IT professionals moving into cybersecurity or security management roles
Managers and business owners who need to understand how to protect their organization
Professionals supporting an ISO/IEC 27001 information security management system from the technical side
Students and career-changers building cybersecurity fundamentals
Anyone who wants to understand threats — from ransomware to phishing — and the controls that stop them
Get the knowledge you need to design, coordinate and improve a cybersecurity program — or to understand security the way ISO/IEC 27001 approaches it.