EdX

Cybersecurity Risk Management (edX)

Cybersecurity Risk Management (edX)

Learn key principles of risk analysis, risk assessment and risk mitigation for information security using both qualitative and quantitative methodologies. Cybersecurity risk management guides a growing number of IT decisions. Cybersecurity risks continue to have critical impacts on overall IT risk modeling, assessment and mitigation.

Class Deals by MOOC List - Click here and see EdX's Active Discounts, Deals, and Promo Codes.

In this course, you will learn about the general information security risk management framework and its practices and how to identify and model information security risks and apply both qualitative and quantitative risk assessment methods. Understanding this framework will enable you to articulate the business consequences of identified information security risks. These skills are essential for any successful information security professional.
The goal of this course is to teach students the risk management framework with both qualitative and quantitative assessment methods that concentrate on the information security (IS) aspect of IT risks. The relationship between the IT risk and business value will be discussed through several industry case studies.
First, you will learn about the principles of risk management and its three key elements: risk analysis, risk assessment and risk mitigation. You will learn to identify information security related threats, vulnerability, determine the risk level, define controls and safeguards, and conduct cost-benefit analysis or business impact analysis.
Second, we will introduce the qualitative and quantitative frameworks and discuss the differences between these two frameworks. You will learn the details of how to apply these frameworks in assessing information security risk.
Third, we will extend the quantitative framework with data mining and machine learning approaches that are applicable for data-driven risk analytics. You will explore the intersection of information security, big data and artificial intelligence.
Finally, you will analyze a series of extended case studies, which will help you to comprehend and generalize the principles, frameworks and analytical methods in actual examples.
This offering is part of the RITx Cybersecurity MicroMasters Program that prepares students to enter and advance in the field of computing security.

What you'll learn

  • Information security risk management framework and methodologies
  • Identifying and modeling information security risks
  • Qualitative and quantitative risk assessment methods
  • Articulating information security risks as business consequences

Syllabus

Week 1: Evolution of Information Security
Week 2: Risk Management Process, Framework and Life Cycle
Week 3: Quantitative versus Qualitative Risk Assessment
Week 4: Defining Information Security Metrics
Week 5: Analysis Techniques
Week 6: Automating Metrics Calculations and Tools
Weeks 7 & 8: Industry case studies

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Risk & Return (edX) EdX
Columbia University,ColumbiaX

Risk & Return (edX)

Learn how to measure the risk and return of equity and debt; and compute the weighted average of cost of capital. In this course, you will learn to estimate the expected return of equity and debt. You will also learn to estimate the weighted average cost of capital (WACC), the opportunity cost of capital you should use when discounting the free cash flows to value a firm.

Self Paced
Self-Paced
CS50's Introduction to Computer Science (edX) EdX
HarvardX,Harvard University

CS50's Introduction to Computer Science (edX)

An introduction to the intellectual enterprises of computer science and the art of programming. This is CS50, Harvard University's introduction to the intellectual enterprises of computer science and the art of programming for majors and non-majors alike, with or without prior programming experience. An entry-level course taught by David J. Malan, CS50 teaches students how to think algorithmically and solve problems efficiently.

Self Paced
Self-Paced
Ciberseguridad. Bases y estructuras para la protección de la información (edX) EdX
Universidad Anáhuac,AnahuacX

Ciberseguridad. Bases y estructuras para la protección de la información (edX)

Sé capaz de blindar tu información y la de tu empresa contra las amenazas informáticas y conoce los fundamentos del fascinante mundo de la ciberseguridad. En la actualidad el acceso a las bases de datos, a las redes de computadoras y la información en la nube es esencial para desempeñar gran parte de nuestras actividades cotidianas.

Self Paced
Self-Paced
Climate Change: Financial Risks and Opportunities (edX) EdX
Imperial College Business School,Imperial College London

Climate Change: Financial Risks and Opportunities (edX)

Explore the risks and opportunities that climate change presents to financial markets, hearing from a range of investment industry leaders and scientific researchers. Do you want to know more about how a warming planet is changing the landscape for investing? Geared towards professionals working in financial markets, this course provides a solid introduction to the financial risks and opportunities arising from man-made climate change.

Self Paced
Self-Paced
Fundamentos de Ciberseguridad: un enfoque práctico (edX) EdX
Inter-American Development Bank - IDB,Universidad Carlos III de Madrid - UC3M,IDBx,UC3Mx

Fundamentos de Ciberseguridad: un enfoque práctico (edX)

Aprende a pensar como un hacker, pero actúa como un experto en ciberseguridad. ¿Has oído hablar de los ataques que reciben las grandes compañías o los bancos a través de sus sistemas informáticos? ¿Sabes detectar un archivo infectado por un virus? O ¿conoces medidas de seguridad para proteger un equipo o una red de ciber-ataques?

Self Paced
Self-Paced
Introduction to Software Side Channels and Mitigations (edX) EdX
Graz University of Technology,TUGrazX

Introduction to Software Side Channels and Mitigations (edX)

Side channels exist in the real world, but they also exist in computers and can be exploited directly from software. This is a substantial computer security problem today, that we need to learn about to be able to stop attacks. In this course, you will learn and practice basic software-based side channels and understand the thought process to utilize a side channel. You will then learn how to mitigate or avoid side channels in software.

Self Paced
5-12 Weeks
Análisis del riesgo de desastres y cambio climático en proyectos de infraestructura (edX) EdX
Inter-American Development Bank - IDB,IDBx

Análisis del riesgo de desastres y cambio climático en proyectos de infraestructura (edX)

Fortalece tus capacidades técnicas y toma decisiones, incorporando el análisis de riesgo de desastres naturales y resiliencia al cambio climático en el diseño de proyectos de infraestructura. El cambio climático es un hecho y afecta a muchos aspectos de nuestra vida. Cada vez las temperaturas son más extremas y los desastres naturales más recurrentes. No podemos evitar que ocurran las inundaciones, terremotos, tornados…

Self Paced
Self-Paced
Transient-Execution Attacks: Understanding Meltdown and Spectre (edX) EdX
Graz University of Technology,TUGrazX

Transient-Execution Attacks: Understanding Meltdown and Spectre (edX)

Beyond software-based side-channel attacks there is a new class of attacks called transient-execution attacks. These attacks go beyond leaking meta-data and directly retrieve secret data but they use side channels as an data exfiltration mechanism to transmit the secret data to an attacker-controlled application. We will look at the most prominent of these attacks: Meltdown, Spectre, Foreshadow, and ZombieLoad. You will implement some of these attacks yourself and learn how to mitigate them.

Self Paced
Self-Paced
Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX) EdX
Graz University of Technology,TUGrazX

Between Physical and Sofware: Fault Attacks, Side Channels, and Mitigations (edX)

Fault attacks (sometimes also called active side-channel attacks ) are a very powerful means that goes beyond just leaking secrets from an application or device, to actively manipulating it. We will look at fault attacks that can be triggered from software, namely Rowhammer and Plundervolt. We will also learn that some transient-execution attacks have some similarities to fault attacks. You will implement some of these attacks yourself and learn how they are mitigated.

Self Paced
Self-Paced