1 – Background & Introduction
2 – Scoping the Problem
- Cybersecurity risks & controls
- Cyber risk to critical infrastructure
- Mitigating cyber risk: steps 2 – 5
3 – The Controls Factory Model
- Cybersecurity Controls Model
- The Engineering Center
- The Technical Center
- The Business Center
4 – Cyber Threats & Vulnerabilities
- Cyber Kill Chain® Model
- The cyber threat landscape
- Vulnerabilities & control gaps
5 – Digital Assets, Identities & Business Impact
- Protecting our digital assets
- Asset management
- Business applications
- Security practices
- Business environment
- Governance & risk assessment
- Risk management & supply chain
6 – NIST Cybersecurity Framework – Design & Build
- NIST CSF: mapping the core functions
7 – Technology Programme – Design & Build
- The technology programme
- Critical Security Control 01 – 20
8 – Security Operations Center (SOC)
- Overview of security operations
- SOC technology
- SOC staffing
- SOC processes/procedures
- SOC services
- SOC options
9 – Testing & Assurance of the Technology Programme
- PCI DSS: overview & mapping
- Building & maintaining a secure network & secure systems
- Protecting cardholder data
- Maintaining a vulnerability management programme
- Implementing strong access control measures
- Regularly monitoring & testing networks
- Maintaining an information security policy
10 – Design & Build of the Business Center
- Controls Factory Model – Business Center
- ISO 27002 Control Clause A.5 to A.18
11 – Developing Cyber Workforce Competencies
- The Controls Factory Model – developing the cyber workforce
- The NICE Cybersecurity Workforce Framework (NCWF)
- Securely Provision
- Operate and Maintain
- Oversee and Govern
- Protect and Defend
- Analyze
- Collect and Operate
- Investigate
12 – Design & Build of the Cyber Risk Programme
- Controls Factory Model – Cyber Risk Programme
- AICPA Description Criteria – categories 1 to 19
13 – Assessing the Cybersecurity Programme
- Sample assessment
- Summary design of the cybersecurity programme
14 – The Risk Management Framework
- AICPA cyber risk categories
- FTC compliance with the framework