About this course
This course is designed to introduce information security best practices to the non-information security professional, beginning information security professional or non-technical business professional.
It provides a broad overview of information security topics including compliance, governance, network design, application security, security processes and development of an information security program. Information security frameworks are introduced to provide the attendee with the basics of information security controls. Case studies and attack methods are presented to illustrate the importance of the various elements of information security programs.
Information security is a growing issue for the entire enterprise, not just for security and IT teams. Heightened attention to corporate governance, increasing reports of targeted attacks, more legislation and regulation, data leakage, BYOD, cloud, and other cyber security problems are in the media daily, and reports of companies battling the fall-out from breaches have enterprise executives focused on better protecting the business and its assets. Information security can be a minefield of potential disasters waiting to happen if not managed correctly and expertly, or if it’s misaligned with business goals.
During this three-day seminar, attendees will learn how to respond to the increased emphasis on information security by gaining an understanding of how to organize and oversee a risk-based enterprise information security program. We will drill down to the critical building blocks of information security, explore the respective roles and responsibilities of the key players, discover industry best practice, legislation, and professional standards. attendees will leave the course with ideas and strategies for improving the security posture of their organization.
This course is geared to individuals with a little or no general familiarity and working knowledge of information security issues. An understanding of technology and other forms of information risk management and security would be useful but are not essential. Members of IT Audit, Information Security, Quality Assurance, and/or Information Technology disciplines would find the course a useful refresher or conduit for furthering their interest in the subject.
Recent reviews
I did take the 5 day Cybersecurity Program training some time ago, so it was nice to brush up on security topics.
A lot of information that was well put together. Only part that needs some working is the amount of slides that we covered made for a few of the "Classroom Discussions" to not be done. Not a huge issue, as we talked about them openly. If a larger class is attending, may need to cut out some of the Class breakout groups or cut out some of the material that's covered. Overall, a great class and very informative.
I enjoyed and learned a lot in the class. With little background in security, I needed a baseline level introduction on the topics, and I think it was well represented. One suggestion I would like to see done is the inclusion of a list of acronyms used in the course, and their translation/explanation. This could either be included in the slides, or preferably in a separate document to use for reference. While the instructor always explained what the acronyms stood for, the repeated use of them further in the class made me forget the meaning of them. I would like something to use for reference.
