Learning Security Frameworks

English | MP4 | AVC 1280×720 | AAC 48KHz 2ch | 0h 47m | 329 MB

Security frameworks are designed to help organizations boost their security posture. Such frameworks provide security practitioners—and their business partners—with a common set of practices to follow, as well as a baseline that makes it easier to report on improvements. In this course, join Mandy Huth as she covers the top four frameworks available, goes over how the frameworks compare, and shares how you can actually map your security controls across multiple frameworks. Mandy also shows how to determine your core security set, stepping through how to define what you’ll do and how you’ll measure it, and then prove that you did what you sought out to do. Throughout the course, she shares best practices that can help you start leveraging a security framework in your own company.

Topics include:

  • Picking the right security framework
  • Why are security frameworks important?
  • Global, federal, and state cybersecurity regulations
  • PCI and credit card payments
  • CIS critical security controls
  • Comparing the top four security frameworks
  • Mapping process and technical controls
  • Augmenting frameworks with GRCs
  • Developing a security mindset
1 Picking the right security framework
2 Who uses security frameworks
3 Why are security frameworks important
4 Definitions
5 Overview of the major frameworks
6 Other frameworks to consider
7 Cybersecurity regulations
8 Risk assessment and the SIG
9 PCI and credit card payments
10 CIS critical security controls
11 NIST 800-53 Guidance for US companies
12 ISO 27001 A global approach with certification
13 How the frameworks compare
14 Mapping process controls
15 Mapping technical controls
16 Deciding on a framework
17 The control families
18 The measures
19 The assurances
20 Augmenting frameworks with GRCs
21 Developing a security mindset
22 Next steps