Cybersecurity Specialization: Governance Risk and Compliance (AA-CSF-Spec-GRC)


Course Description

In an ever-changing political and criminal landscape, there is an increasing need for people with specialized and up-to-date knowledge of current cybersecurity laws, regulations, and best practices. The skills gap this need creates in an organization exposes the organization to liability.

Cybersecurity Specialization: Governance, Risk, and Compliance will give you an understanding of the current laws and regulations that drive the creation of a governance system of rules, practices, and processes by which a company is directed and controlled. Understanding the fundamentals of the implementation of a risk management strategy will help your organization achieve compliance through policy management, control creation, and assessment of the effectiveness of controls. In this course, you will learn to set up processes to enforce compliant behaviors in your organization, including the enforcement of a systemic culture of documentation, verification, audits, remediation, follow-through, responsibility, and authority.

The course uses a challenge-based design focusing on what a learner should be able to do at the end of the course and back on the job. The practice opportunities and challenge activities resemble (as much as possible) tasks the learner would be asked to perform in a real-life situation.

Course Outline

Why Does GRC Matter?

  • Terms and definitions
  • Assets, value
  • Increasing importance of Governance, Risk, and Compliance

Industry Compliance

  • Essence of compliance
  • Industry Standards: Payment Card Industry (PCI)
  • Industry Standards: Sarbanes-Oxley (SOX) Act
  • Industry Standards: Financial Industry Regulatory Authority (FINRA)
  • Industry Standards: General Data Protection Regulation (GDPR)
  • Compliance and company policy

Privacy Compliance

  • Impact of privacy
  • Personally identifiable information (PII), protected health information (PHI)
  • Data architecture
  • Data handling
  • Encryption
  • Health Insurance Portability and Accountability Act (HIPAA)
  • Health Information Technology for Economic and Clinical Health (HITECH) Act
  • Gramm-Leach-Bliley Act (GLBA)
  • Privacy best practices

Risk Assessment

  • CIA triad
  • Threat modeling
  • Risk assessment
  • Quantitative vs. qualitative risk assessment
  • Risk assessment models
  • Risk likelihood and impact
  • Risk tolerance
  • Risk appetite
  • Business impact analysis (BIA)
  • Risk mitigation strategies

Risk Management

  • Risk management strategies: Mitigation, avoidance, transference, acceptance
  • Risk Management Framework (RMF)
  • RMF vs. CAP
  • Risk maturity level
  • Residual risk
  • Continuous monitoring and incident response
  • Patch management and the Common Vulnerability Scoring System (CVSS)

Corporate Culture

  • Enterprise-wide attitudes to security and risk
  • FUD: Fear, uncertainty, and doubt
  • Governance failures in the real world
  • Buy-in
  • NICE, best practices, role-based training
  • Aligning risk management with business goals
  • Authorized use policies
  • Tools: Training, rewards and consequences, hiring practices
  • Ongoing monitoring and tracking

Governance and Policy

  • Business continuity plan (BCP)
  • Disaster recovery plan (DRP)
  • Business impact analysis (BIA)
  • Single point of failure
  • Redundancy
  • BCP dependency chain
  • Rapid information sharing
  • RACI chart
  • Discussion: Fast vs. good vs. cheap

Course Look Around

  • eGRC: Archer and OpenPages
  • Real-time access to information
  • Reporting
  • Relevance
  • Interoperability
  • Savings through reduced complexity

Course Objectives

  • Develop a strategy to mitigate compliance risk based on laws governing Information Technology and reporting requirements to various regulatory bodies
  • Contribute to a risk management strategy that will frame an organizationís risk tolerance along with defining and enabling managers to understand the levels of risk they are allowed to take
  • Create policies supported by controls that utilize frameworks and standards to minimize risk to an acceptable level
  • Determine the mechanisms to raise the organizationís risk maturity level
  • Support both top-down and bottom-up approaches to enterprise security by acquiring management buy-in and improving employee attitudes to security
  • Contribute to a business continuity plan that prioritizes business processes
  • Select an eGRC tool to help manage risk based on requirements and capabilities

Course Prerequisites

There are no prerequisites for this course.

Course Information

Length: 3 day

Format: Lecture and Lab

Delivery Method: n/a

Max. Capacity: 16



Schedule

Contact Us

UPCOMING COURSES
Date
Geography & Location
Days
Cost
CLC
GTR
Jan 21, 2025 - 3 day(s)
Jan 21, 2025
AMER
Remote-EST
AMER, Remote-EST
3
$2550 USD
$2550 USD
Mar 24, 2025 - 3 day(s)
Mar 24, 2025
AMER
Remote-EST
AMER, Remote-EST
3
$2550 USD
$2550 USD

Do you have more questions? We're delighted to assist you!

1-877-797-2799
info@firefly.cloud

Labs

  • Challenge: Why does GRC matter?
  • Challenge: Collaborate on compliance solutions
  • Challenge: Identify and classify PII
  • Challenge: Calculate risk
  • Challenge: Choose a risk management strategy
  • Challenge: Adjust corporate culture
  • Challenge: Develop a DRP and integrate it with the BCP
  • Challenge: Explore eGRC tools


Who Should Attend

  • Mid-career professionals who are interested in a career in risk analysis and management of cybersecurity processes, tools, and people.
  • Students should have at least two years of experience in cybersecurity but can come to this course from a variety of backgrounds, including but not limited to auditing, project management, DevOps, and engineering.