Risk Management: Use of Access Controls to Protect Assets (Coursera)

Offered by (ISC)²,
Risk Management: Use of Access Controls to Protect Assets (Coursera)

Course 2: Understanding Risk Management Options and the Use of Access Controls to Protect Assets. In this course, we will focus on understanding risk management options and the use of access controls to protect assets.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

We will start by examining the basic steps that must be in place to develop a security culture within the organization and impacting policies. We will also look into how to write and use them to enforce security requirements. Then we will move on to the actual business of controlling how our systems, services, resources, and data can be accessed safely by authorized persons. We will also cover access control models like MAC, DAC, RBAC, and conclude the chapter with an examination of both LAN and WAN identity management.
Course 2 Learning Objectives
After completing this course, the participant will be able to: 
L2.1 - Provide examples of the types of functional security controls and policies for identified scenarios. 
L2.2 - Classify various access control models. 
L2.3 - Identify components of identity management lifecycle. 
L2.4 - Recognize access control and authentication methods.

Course Agenda
Module 1: Document, Implement, and Maintain Functional Security Controls (Domain 1 - Security Operations and Administration)
Module 2: Access Controls Models (Domain 1 - Security Operations and Administration, Domain 2 - Access Controls)
Module 3: Identity Management Lifecycle (Domain 2 - Access Controls)
Module 4: Implement and Maintain Authentication Methods (Domain 2 - Access Controls, Domain 6 - Network and Communication Security)

Who Should Take This Course: Beginners
Experience Required: No prior experience required

Course 2 of 8 in the (ISC)² Systems Security Certified Practitioner (SSCP)

Syllabus

WEEK 1
Module 1: Document, Implement, and Maintain Functional Security Controls
In this module we are going to start looking at the pieces that make up a security program. Now that we have examined the process of risk management, we have the information needed to justify the controls and other actions taken to secure and protect the assets of the organization. The core principle of information security must be remembered, which is that security exists solely for the purpose of supporting and enabling the business mission. Our goal as security professionals is not just to be secure but rather to secure the business. Our organizations do not hire us because they are really interested in security; they hire us because management realizes that security is necessary in order for the business to survive.  
Senior managers and leaders within the organization focus on achieving efficient use of every resource they have available to them, so that they can maximize the organization’s effectiveness within the marketplaces it serves. Whether it is a for-profit business, a nonprofit organization, or a government agency, the organization (in the words of the motto of the UK’s Royal Air Force Police) has to survive to operate. It has to control the losses due to inefficient business processes, bad weather or criminal attacks.  Simply put, information security that minimizes losses and protects high-value assets, processes, goals, and objectives pays for itself, and thus commands support and resources from senior management. Security efforts that do not directly support defending those priorities won’t.  The explosive growth in cyber fraud activities during the pandemic of 2020-2021 and the increase in ransomware and other attacks alike demonstrates how the attackers are learning faster than the defenders. Let’s turn that around, starting with how we think about turning security needs and requirements into effective control strategies.
Module 2: Access Controls Models
It could be argued that access controls are the heart of an information security program. Earlier in this course we have looked at the foundation of security through risk management and policy, and the leadership of information security through management involvement and strategic planning, but in the end, security all comes down to “who can get access to our assets (buildings, data, systems, etc.) and what can they do when they get access?” 
Access controls are not just about restricting access, but also about allowing access. It is about granting the correct level of access to authorized personnel and processes but denying access to unauthorized functions or individuals.

WEEK 2
Module 3: Identity Management Lifecycle
This part of the course examines the process of identity management. Identity management (IM) is often described using the IAAA model (sometimes called the AAA model). This represents the steps of identification, authentication, authorization, and accounting (sometimes incorrectly called audit; we’ll see why as we go along). Identity management includes establishing, maintaining, and removing identities on our systems. Access control focuses on the real-time tasks necessary to validate that an attempt to access a resource is being done by a recognized, accepted entity using an identity known to the system, and that the attempt is seeking to use privileges that are appropriate and valid for that entity, that resource, and current circumstances. 
Prior to the widespread use of web pages that allow site visitors to create an account (an identity) on that host system, most security professionals and organizational managers thought of IM and AAA as happening on two very different time scales, or as driven by two very different types of events:  IM activities were viewed as being driven by large-scale events, such as joining the organization, going through a major change in roles or job responsibilities, and then leaving the organization.   AAA activities then occur on a real-time basis with every connection (sign-on) attempt and every access request to resources made by any one of the accounts and user IDs created for that person.  As the concept of identity management has had to expand to include nonhuman users and entities, this view of IM and AAA time horizons has changed in related ways. A company hires human users and acquires endpoints or server devices. It signs partnership agreements with other organizations to set up federated access control mechanisms so that both can share information assets in controlled, secure ways. Each of these are IM activities that happen once (or a few times) in the lifecycle of that entity’s relationship with the organization.  And just as a human user might go through a thousand resource access attempts during a single workday (or even in a short session), so too might a nonhuman entity performing its assigned or allowed tasks.
Module 4: Implement and Maintain Authentication Methods
 The implementation of access management contains its own challenges. Audits in many organizations often reveal that the identity management processes used are flawed, resulting in many users who have access permissions that they have accumulated over the years that are not aligned with their current business needs. This is a problem where privacy regulations require accountability and tracking of access permissions, and it can lead to financial penalties, security breaches, and embarrassment for the organization. The idea of an identity and access management (IAM) system is to automate the process and reduce the administrative overhead, while improving reporting and the ability to monitor the access levels granted to users. Some of the features of IAM systems include an automated process for users to request and be granted access to systems, a streamlined process for new users and for password resets. 

WEEK 3
Module 5: Chapter 2 Review
It’s not an exaggeration to say that access control is the heart of the information systems security problem. Everything we do as security professionals drives down to this problem set; risk management sets requirements for access control to achieve, and the design, configuration, and operation of the information infrastructures the organization uses must reflect the access control decisions that have been made. 
Access control technologies may very well represent the most hotly contested “real estate” in the battle between cyber defenders and cyberattackers.  This chapter has provided you with a rich, detailed, and in-depth orientation and introduction to many aspects of the access control need and problem, while it has also shown you ways to solve that problem and address that need.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Kali Linux (Coursera) Coursera
Board Infinity

Kali Linux (Coursera)

"Introduction to Kali Linux" is a meticulously designed course to guide beginners through the essentials of Kali Linux, a powerful tool for cybersecurity. Spanning two modules, the course begins with a comprehensive introduction to Kali Linux, its installation, navigation, and essential tools. It then advances into practical applications, covering network monitoring, ethical hacking principles, penetration testing, and vulnerability assessment.

Aug 17th 2026
2 Weeks
Tencent Cloud Solutions Architect Associate (Coursera) Coursera
Tencent Cloud

Tencent Cloud Solutions Architect Associate (Coursera)

This course is primarily aimed at cloud professionals that are interested in learning about Tencent Cloud‘s cloud architectures. The course equips learners with a foundational knowledge in cloud architecture design and prepares them to take the Tencent Cloud Solutions Architect Associate examination. After completing this course, learners will be able to design cloud solutions that incorporate the principles of high availability, high security, high scalability, and cost optimization.

Aug 17th 2026
5-12 Weeks
Security & Safety Challenges in a Globalized World (Coursera) Coursera
Leiden University

Security & Safety Challenges in a Globalized World (Coursera)

Security and safety challenges rank among the most pressing issues of modern times. Challenges such as, cyber-crime, terrorism, and environmental disasters impact the lives of millions across the globe. These issues also rank high on the agenda of politicians, international organizations and businesses. They also feature prominently in the public conscience and in governmental policies.

Aug 10th 2026
5-12 Weeks
Exam Prep: AWS Certified Solutions Architect - Associate (Coursera) Coursera
AWS

Exam Prep: AWS Certified Solutions Architect - Associate (Coursera)

This new intermediate-level course from Amazon Web Services (AWS) is designed to help you to assess your preparedness for the AWS Certified Solutions Architect - Associate exam. You will learn how to prepare for the exam by exploring the exam’s topic areas and how they map to architecting on AWS. You will review sample certification questions in each domain, practice skills with hands-on exercises, test your knowledge with practice question sets, and learn strategies for identifying incorrect responses by interpreting the concepts that are being tested in the exam.

Aug 10th 2026
4 Weeks
Risks to Crop Production in Agriculture (Coursera) Coursera
University of Illinois at Urbana-Champaign

Risks to Crop Production in Agriculture (Coursera)

Learners will be able to describe the crop production cycles of agriculture for annual and permanent crops, explain the financial characteristics and risks of food production, discuss the various types of land ownership and rental agreements for the use of agricultural land, and describe personal, external, and food production risks that influence decision-making in agriculture.

Aug 17th 2026
5-12 Weeks
Cloud Computing Fundamentals on Alibaba Cloud (Coursera) Coursera
Alibaba Cloud Academy

Cloud Computing Fundamentals on Alibaba Cloud (Coursera)

Looking to dive into the world of Alibaba Cloud with a comprehensive introduction to the range of products and solutions offered by Alibaba Cloud? Fundamental Architecting on Alibaba Cloud is a course designed for users looking to start this journey with a look into Alibaba Cloud's core products. Fundamental Architecting looks into storage, networking, auto-scaling, and security solutions as well as scenarios to best combine these products to create a complete cloud-based architecture.

Aug 17th 2026
5-12 Weeks
Introduction to Applied Cryptography (Coursera) Coursera
University of London

Introduction to Applied Cryptography (Coursera)

This course is a non-mathematical introduction to the role that cryptography plays in providing digital security for everyday applications such as the internet, mobile phones, wireless networks and cryptocurrency. In this introductory course you will develop an understanding of the functionality and purpose of the main cryptographic tools we use today. You will learn how to make decisions about which cryptographic tools are most appropriate to deploy in specific settings. You will also explore the wider infrastructure surrounding cryptography and how this impacts the overall security of systems deploying cryptography.

Aug 17th 2026
4 Weeks
Mercados financieros (Coursera) Coursera
Yale University

Mercados financieros (Coursera)

Una síntesis de las ideas, métodos e instituciones que permiten que la sociedad humana pueda gestionar los riesgos y promover la actividad empresarial. Un énfasis en las habilidades de liderazgo con conocimientos financieros profundos. Descripción de las prácticas actuales y el análisis de prospectos a futuro. Introducción a los principios de gestión de riesgos y de las finanzas conductuales para comprender el funcionamiento en el mundo real de las industrias de valores, seguros y el sector bancario.

Aug 17th 2026
5-12 Weeks
IBM Data Privacy for Information Architecture (Coursera) Coursera
IBM

IBM Data Privacy for Information Architecture (Coursera)

Data privacy controls how information is collected, used, shared, and disposed of, in accordance with policies or external laws and regulations. In this course, students will gain an understanding of what data privacy is along with how to identify and understand typical data protection and privatization objectives that an enterprise may have, and how to choose a data protection approach.

Aug 17th 2026
5-12 Weeks
Information Systems Auditing, Controls and Assurance (Coursera) Coursera
The Hong Kong University of Science and Technology - HKUST

Information Systems Auditing, Controls and Assurance (Coursera)

Information systems (IS) are important assets to business organizations and are ubiquitous in our daily lives. With the latest IS technologies emerging, such as Big Data, FinTech, Virtual Banks, there are more concerns from the public on how organizations maintain systems’ integrity, such as data privacy, information security, the compliance to the government regulations. Management in organizations also need to be assured that systems work the way they expected. IS auditors play a crucial role in handling these issues.

Aug 10th 2026
4 Weeks