Udemy
    •  
    •  
    •  
    •  
    •  
    •  
    •  
    •  
Turn what you know into an opportunity and reach millions around the world.
Learn More
Your cart is empty.
Keep shopping
Cybersecurity Management with ISO/IEC 27001
Rating: 4.4 out of 5(9,698 ratings)
22,073 students

Cybersecurity Management with ISO/IEC 27001

Design and run a cybersecurity program — threats, controls, risk assessment and incident response, guided by ISO 27001
Last updated 7/2026
English
Arabic [Auto],German [Auto],

What you'll learn

  • Principles and concepts in cybersecurity
  • Threats and vulnerabilities
  • Risks and controls
  • Best practices for a succesful cybersecurity program
  • How ISO/IEC 27001 requirements apply to cybersecurity
  • Common attacks, how they work and how they can be prevented

Course content

1 section48 lectures4h 4m total length
  • Introduction2:34
  • The Cyberspace4:58

    Definitions for the cyberspace. Stakeholders in the cyberspace. Changes brought by the digital world.

  • Cybersecurity5:18

    What is cybercrime and what are the costs of cybercrime to the global economy. What is the purpose of cybersecurity - protecting the confidentiality, integrity and availability of information. The three directions of cybersecurity: prevention, detection and response. Return of investment for cybersecurity. About Software as a Service, Platform as a Service and Infrastructure as a Service. About ISO 27001 and ISO 27017. Is there a difference between information security and cybersecurity?

  • Positions in cybersecurity6:59

    Different positions in cybersecurity and a brief descriptions of the main responsibilities and authorities. CISO, cybersecurity manager, cybersecurity architect, security auditor ...

  • Confidentiality - Integrity - Availability5:16

    The three elements of the C-I-A triad - Confidentiality, Integrity, Availability and their definitions. Plus another important concept - Non-repudiation.

  • Information classification4:51

    The purpose of information classification. Common classification schemes in military/ government organizations and the business environment. Information labeling.

  • Threats and vulnerabilities3:00

    Definitions and examples for threats and vulnerabilities.

  • Risk assessment5:28

    Ingredients of risk - probability and impact. Quantitative and qualitative methods for risk assessment - details, examples and advantages for each category.

  • Treating risk5:51

    Common options for treating risk and their definitions. The concept of residual risk. Categories of controls - technical, procedural (administrative) and physical.

  • Support from top management4:16

    Why support from senior management is important. The cybersecurity policy.

  • Internal organization5:14

    Common internal organization for cybersecurity. The position of a Chief Information Security Officer (CISO).

  • Segregation of duties4:35

    The principle of duties segregation or separation. Why is it important and examples. Job rotation principle and mandatory vacations.

  • The Barings Bank collapse4:21

    The story of the Barings bank collapse and how duties segregation can be a critical aspect.

  • Bring your own device (BYOD)7:22

    What is BYOD. Benefits and risks that come along with BYOD. Aspects to be addressed in the BYOD policy. COPE - Company Owned Personally Enabled.

  • Mobile devices4:46

    Rules for mobile devices. MDM (Mobile Device Management) and MAM (Mobile Application Management).

  • Human resources security8:32

    Security requirements and responsibilities for each position. Screening candidates. Contractual agreements (NDAs - Non Disclosure Agreements and NCA - Non-Compete Agreements). The disciplinary process. Security requirements for the termination or change of employment.

  • Awareness and training4:10

    Security awareness - why it is important and methods. Cybersecurity training for company staff.

  • Asset management4:23

    The asset inventory. Assigning owners to assets - why and how. Acceptable use policies.

  • Removable media4:39

    Security risks associated to the use of removable media. Security controls for removable media.

  • The interesting story of Edward Snowden6:14

    A short presentation of Edward Snowden's story and the huge security breach he created by revealing NSA classified information to the public. The importance of removable media.

  • Access control4:25

    What does access control involve. Solutions for access controls. Common authentication factors - type 1, type 2 and type 3 authentication + multi-factor authentication. Disabling access rights of terminated employees.

  • Privileged access rights3:02

    The principle of least privileges. Guidelines for preventing security breaches due to special privileges

  • Logging and monitoring4:18

    Definition and guidelines for logging. Protection of logs; log retention. Monitoring as the process of reviewing logs.

  • Cryptography basics5:44

    Brief history of cryptography. Concepts like the cipher and the algorithm. The Kerckhoffs principle. General aspects about symmetric and asymmetric cryptography.

  • Digital signature4:50

    The hash function. Requirements for the hash function. Definition of the digital signature.

  • Public key infrastructure3:37

    Definition for a Public Key Infrastructure. Certification and registration authorities. About digital certificates.

  • Cryptographic attacks4:23

    Examples and short description of common cryptographic attacks: brute force, rainbow tables, birthday, man in the middle.

  • Physical security7:19

    Multiple layers for physical security in a building. Fire protection. Public areas. Secure areas.

  • Equipment8:00

    Security controls for company equipment. Controls for unattended equipment. Requirements for taking equipment off premises. Wiring closets. Server rooms. Cabling security. Electromagnetic emanation and TEMPEST.   

  • Malware7:04

    Malware definition. Common types of malware: viruses, logic bombs, worms, trojan horses, worms, spyware, adware, ransomware

  • Ransomware6:07

    Ransomware - encrypting and blocking ransomware. How they work and factors that make certain organizations attractive for ransomware. Recommendation to protect against ransomware. Pay the ransom or not? Leakware or doxware.

  • Phishing5:50

    Definition of phishing. Types of phishing: deceptive phishing, spear phishing, whaling, pharming. Controls against phishing.

  • Denial of service (DOS and DDOS)4:21

    Denial of service attacks - definition and how they work. Distributed Denial of Service (DDoS). DDoS mitigation.

  • Social engineering2:52

    What is social engineering and how it works. Training and awareness against social engineering.

  • Password management8:27

    Common password attacks: password guessing, dictionary attacks, keyloggers. Guidelines for password management.

  • Backup2:59

    The contents of a backup policy. Differential and incremental backups.

  • Change management3:19

    The change process in an organization. The steps for implementing changes in a controlled manner.

  • Network security management8:07

    Principles and key elements for network security management - networks segregation, firewalls. Wireless networks and common wireless attacks: man in the middle, packet sniffing, evil twin attacks Guidelines for protecting wireless networks.

  • Email security3:58

    Contents for an email security policy. Controls for protecting data in emails.

  • Security in development processes4:45

    The development lifecycle. The contents of the secure development policy. Outsourcing software development.

  • Supplier relationships5:34

    Screening suppliers. Security requirements in supplier contracts. Security of the supply chain. Monitoring supplier performance.

  • The Target security breach5:28

    The security breach that hit the Target corporation in 2013. How it happened and why.

  • Capacity management2:56

    Capacity management definition. The contents of the capacity plan.

  • Incident management5:54

    The stages of incident management -  detection, response, communication, recovery, root cause analysis for corrective and preventive actions, learning from incidents.

  • The case of Uber2:44

    The story of the Uber security breach of 2016. Dealing with the hackers.

  • Business continuity management6:32

    The most relevant business continuity activities - business impact analysis; risk assessment; the emergency team; business continuity strategy and business continuity plans. Testing and improving business continuity arrangements.

  • Compliance4:47

    Security legal compliance. Privacy and the GDPR most relevant requirements. Compliance with other requirements.

  • Looking to the future4:41

    The future of cybersecurity. Big data will grow bigger. The Internet of Things.

  • ISO 27001. Cybersecurity manager

Requirements

  • Familiarity with information security concepts
  • A general understanding of IT

Description

This course teaches the foundations of cybersecurity management through the lens of ISO/IEC 27001, the leading international standard for information security. You will learn the concepts, principles and controls an organization needs to design and run a cybersecurity program: the typical security threats facing different activities and processes, and the recommended controls to protect against them.

Course structure

  • Foundations — cyberspace and cybersecurity defined; confidentiality, integrity, authentication and non-repudiation as critical elements of any security system

  • Information classification — schemes, levels and labelling

  • Risk management — threats, vulnerabilities, risk assessment (quantitative and qualitative methods), and the options for treating security risks

  • Organizing security — top management support, segregation of duties, and human resources security from screening and contractual requirements through the disciplinary process to termination and change of employment

  • Devices and media — mobile device policies including BYOD (bring your own device) and COPE (company owned, personally enabled), and the rules for removable media

  • Access control and authentication — managing access rights and privileges so they don't become security breaches; password management, common password attacks and their controls

  • Cryptography — core concepts, digital signatures and public key infrastructure (PKI), plus the most common cryptographic attacks (brute force, rainbow tables, birthday attacks) and how to defend against them

  • Attacks and malware — viruses, worms, trojans, logic bombs, spyware and adware, with a detailed presentation of ransomware; denial-of-service attacks; social engineering and phishing

  • Operational security — physical and equipment security, backups, change management, capacity management, email security, network security principles and controls, wireless attacks and their prevention, and security in development processes

  • Suppliers and third parties — the risks associated with suppliers' access to your information assets

  • Incident management and continuity — managing cybersecurity incidents from detection to closure and root cause analysis; business continuity and preparing for crisis situations

  • Compliance — the compliance requirements every organization must respect

Learning from real cases

The concepts are illustrated with easy-to-follow explanations, examples and case studies — including the Barings Bank collapse, the Target security breach and Edward Snowden — plus a quiz at the end to test what you've learned.

Who this course is for

  • IT professionals moving into cybersecurity or security management roles

  • Managers and business owners who need to understand how to protect their organization

  • Professionals supporting an ISO/IEC 27001 information security management system from the technical side

  • Students and career-changers building cybersecurity fundamentals

  • Anyone who wants to understand threats — from ransomware to phishing — and the controls that stop them

Get the knowledge you need to design, coordinate and improve a cybersecurity program — or to understand security the way ISO/IEC 27001 approaches it.

Who this course is for:

  • Cybersecurity managers
  • Information security officers
  • ISO/IEC 27001 auditors and consultants
  • Security professionals
  • Professionals tasked with implementing or administrating a management system as per ISO 27001
  • Security practitioners interested in the ISO 27001 framework
  • People looking for a career in cyber security
  • IT professionals looking to enhance their knowledge