Course Objectives Consumers, Organisations and Governments are all susceptible, in one way or another, to Cyber Threats, which has become big business and continues to be increasingly sophisticated. To this end it is vital for all organisations to implement a cybersecurity (cs) framework to prevent, detect, monitor and take corrective action as a means to limiting exposure to cyber threats. Cyber threats could prove to be very costly and result in reputational damage. The Cybersecurity Framework should include the policies, processes, procedures and best practices to manage cybercrime in different forms. Cyber Threats are so serious that it should be on the board agenda where board members should be concerned about how cyber-safe their organisations are. And so too, Internal audit should be giving the Management and Board reasonable assurance on cybersecurity controls. Practical sessions in class will provide guidance on the application of the Cyber Security, governance, risks and controls. Course Content - What is cybersecurity (CS), how did it originate, why is it so important.
- CS Concepts, CS Domains including CS Domains including “Cloud Computing”.
- Cyber threat types/categories such as cybercrime, cyber-attacks and cyberterrorism.
- Cybersecurity Management.
- Establishing or enhancing a Cybersecurity System.
- Cybersecurity best practices and generic frameworks overview and NIST generic controls
- Cybersecurity strategies & Controls
| What Will Participants Learn? - Develop an acceptable level of confidence to discuss Cybersecurity concerns at all levels to ensure appropriate controls are in place or planned for.
- Understand the different types of cybersecurity threats
- Understand what cybersecurity is, its origin and why it is critically required.
- Understand the different concepts and domains and the required guidelines to auditing CS controls.
- Understand CS strategies to enhance cyber security.
Who should attend? Level 1 | Entry or introductory level for those requiring a fundamental understanding of Cybersecurity governance, risk and controls. | Level 2 | Internal auditors who are required to know what Cybersecurity controls that should be in place and guidelines on how to audit these. | |