Cybersecurity money gets approved in risk language, not technical language. Learn to assess, quantify, register and report cyber risk in the terms executives and boards actually act on.
Overview
Syllabus
Module 1
- Risk Is the Business: Cyber Risk & GRC Foundations
- Defining GRC
- Cybersecurity risk versus enterprise risk via COSO and ISO 31000
- Assets, threats, vulnerabilities, likelihood and impact
- Emerging and AI-specific risk
- Inherent versus residual risk
- Risk and control owners
Module 2
- Set the Rules: Governance, Strategy & Accountability
- Policies, standards, procedures and guidelines
- Roles and responsibilities
- Risk appetite and tolerance
- Governance committees and decision authorities
- NIST CSF 2.0 Govern including the GV.SC supply-chain category
- Federal authorizing officials compared to commercial boards and audit committees
Module 3
- Find the Risk: Cyber Risk Assessment
- Scope and context
- Critical assets and business dependencies
- Threat sources and threat-event scenarios
- Vulnerabilities and predisposing conditions
- Likelihood and impact
- NIST SP 800-30 compared with ISO/IEC 27005:2022
Module 4
- Make the Call: Risk Analysis, Quantification & Response
- Interpreting results
- Prioritization
- Acceptance, avoidance, mitigation, transfer and sharing
- Qualitative ratings versus quantification
- The FAIR model and FAIR-MAM
- Escalation
- SEC materiality determination
Module 5
- From Findings to Action: Risk Registers & Treatment Plans
- The risk register per NIST IR 8286A Rev. 1
- Writing risk statements
- Causes, events and consequences
- Risk owners
- Staging risks for enterprise risk management per IR 8286C Rev. 1
- POA&Ms and their basis in OMB Circular A-130