-
Differentiate cybersecurity standards, frameworks, regulations, and controls used in governance, risk, and compliance programs
Assessment Strategies
Quiz, Written Product
Criteria
Define cybersecurity standards, frameworks, regulations, and controls
Distinguish between standards, frameworks, regulations, and controls
Classify organizational requirements into appropriate categories
Explain relationships among standards, frameworks, regulations, and controls
Summarize benefits of a structured governance approach
-
Analyze and compare major cybersecurity standards and frameworks
Assessment Strategies
Case Study, Written Product, Presentation
Criteria
Compare NIST CSF, RMF, SP 800-53, CIS Controls, PCI DSS, and ISO 27001
Identify primary objectives of each framework
Analyze similarities and differences
Determine appropriate framework selection
Examine strengths and limitations
Summarize implementation considerations
-
Apply risk management principles to support cybersecurity decision making
Assessment Strategies
Scenario Response, Written Product
Criteria
Identify assets, threats, and vulnerabilities
Determine risk likelihood and impact
Calculate risk using established methodologies
Prioritize risks
Recommend risk treatment options
Communicate risk information
-
Conduct cybersecurity risk assessments using qualitative and quantitative methodologies
Assessment Strategies
Project, Report
Criteria
Define assessment scope and objectives
Gather threat and vulnerability information
Apply qualitative methods
Apply quantitative methods
Analyze results
Rank identified risks
Document findings
-
Evaluate organizational compliance requirements related to industry standards, regulations, laws, and contractual obligations
Assessment Strategies
Case Study, Research Paper
Criteria
Identify applicable requirements
Analyze compliance obligations
Determine regulatory impacts
Compare compliance requirements
Evaluate noncompliance risks
Document requirements
-
Map cybersecurity and privacy controls to framework and regulatory requirements
Assessment Strategies
Project, Written Product
Criteria
Identify security and privacy controls
Align controls with framework requirements
Create control crosswalk documentation
Identify overlapping control requirements
Document compliance evidence
Recommend improvements
-
Conduct cybersecurity framework and control gap analyses
Assessment Strategies
Project, Report, Presentation
Criteria
Review current-state practices
Compare practices against requirements
Identify missing or ineffective controls
Prioritize gaps
Document findings
Recommend corrective actions
-
Assess the effectiveness of administrative, technical, and physical security controls
Assessment Strategies
Case Study, Scenario Response, Report
Criteria
Classify controls
Evaluate effectiveness
Analyze assessment evidence
Determine residual risk
Recommend enhancements
Document results
-
Develop recommendations for implementing and improving a cybersecurity GRC program
Assessment Strategies
Project, Presentation
Criteria
Analyze governance requirements
Develop implementation priorities
Recommend standards and frameworks
Create improvement plans
Justify recommendations
-
Communicate governance, risk, and compliance findings and analyze real-world cybersecurity incidents
Assessment Strategies
Case Study, Presentation, Written Product
Criteria
Analyze governance failures
Analyze risk deficiencies
Evaluate compliance failures
Identify corrective actions
Prepare executive-level reports
Present findings to diverse audiences