Skip to main content
10151132 Cybersecurity Standards and Frameworks
Course Information
Description
Delves into the diverse landscape of cybersecurity standards and frameworks. Study industry focused and internationally recognized standards such as the NIST Cybersecurity Framework, ISO/IEC 27001, CIS Critical Security Controls, and PCI DSS. Through case studies and practical exercises, learn to apply these frameworks to enhance organizational cybersecurity posture and align with industry best practices.
Total Credits
0

Course Competencies (Course Outcomes)
  1. Differentiate cybersecurity standards, frameworks, regulations, and controls used in governance, risk, and compliance programs
    Assessment Strategies
    Quiz, Written Product
    Criteria
    Define cybersecurity standards, frameworks, regulations, and controls
    Distinguish between standards, frameworks, regulations, and controls
    Classify organizational requirements into appropriate categories
    Explain relationships among standards, frameworks, regulations, and controls
    Summarize benefits of a structured governance approach

  2. Analyze and compare major cybersecurity standards and frameworks
    Assessment Strategies
    Case Study, Written Product, Presentation
    Criteria
    Compare NIST CSF, RMF, SP 800-53, CIS Controls, PCI DSS, and ISO 27001
    Identify primary objectives of each framework
    Analyze similarities and differences
    Determine appropriate framework selection
    Examine strengths and limitations
    Summarize implementation considerations

  3. Apply risk management principles to support cybersecurity decision making
    Assessment Strategies
    Scenario Response, Written Product
    Criteria
    Identify assets, threats, and vulnerabilities
    Determine risk likelihood and impact
    Calculate risk using established methodologies
    Prioritize risks
    Recommend risk treatment options
    Communicate risk information

  4. Conduct cybersecurity risk assessments using qualitative and quantitative methodologies
    Assessment Strategies
    Project, Report
    Criteria
    Define assessment scope and objectives
    Gather threat and vulnerability information
    Apply qualitative methods
    Apply quantitative methods
    Analyze results
    Rank identified risks
    Document findings

  5. Evaluate organizational compliance requirements related to industry standards, regulations, laws, and contractual obligations
    Assessment Strategies
    Case Study, Research Paper
    Criteria
    Identify applicable requirements
    Analyze compliance obligations
    Determine regulatory impacts
    Compare compliance requirements
    Evaluate noncompliance risks
    Document requirements

  6. Map cybersecurity and privacy controls to framework and regulatory requirements
    Assessment Strategies
    Project, Written Product
    Criteria
    Identify security and privacy controls
    Align controls with framework requirements
    Create control crosswalk documentation
    Identify overlapping control requirements
    Document compliance evidence
    Recommend improvements

  7. Conduct cybersecurity framework and control gap analyses
    Assessment Strategies
    Project, Report, Presentation
    Criteria
    Review current-state practices
    Compare practices against requirements
    Identify missing or ineffective controls
    Prioritize gaps
    Document findings
    Recommend corrective actions

  8. Assess the effectiveness of administrative, technical, and physical security controls
    Assessment Strategies
    Case Study, Scenario Response, Report
    Criteria
    Classify controls
    Evaluate effectiveness
    Analyze assessment evidence
    Determine residual risk
    Recommend enhancements
    Document results

  9. Develop recommendations for implementing and improving a cybersecurity GRC program
    Assessment Strategies
    Project, Presentation
    Criteria
    Analyze governance requirements
    Develop implementation priorities
    Recommend standards and frameworks
    Create improvement plans
    Justify recommendations

  10. Communicate governance, risk, and compliance findings and analyze real-world cybersecurity incidents
    Assessment Strategies
    Case Study, Presentation, Written Product
    Criteria
    Analyze governance failures
    Analyze risk deficiencies
    Evaluate compliance failures
    Identify corrective actions
    Prepare executive-level reports
    Present findings to diverse audiences