Skip to content

Program 1 · Security Foundations, Governance and Risk

Status: in progress

The foundation of the curriculum. Introduces the bigger picture of what cybersecurity is, how it relates to risk management, and the strategies that emerge from that relationship.

This program is the first step in the introduction. It is the smallest of the five programs by scope but sets the conceptual vocabulary — CIA/CIAS Triad, threats, vulnerabilities, risk, countermeasures, governance, compliance, policies, frameworks — that every subsequent program builds on.


Modules

Module 1 · Security Governance & Compliance

Fundamental goals of cybersecurity, cybersecurity governance, legal and regulatory compliance, and cybersecurity policies and procedures.

  • Introduction to Cybersecurity — CIA/CIAS Triad, threats, vulnerabilities, risk, countermeasures, cybersecurity mind map.
  • Cybersecurity Governance — top-down alignment of security with the business; precision vs accuracy; CISSP/CISM context; precise definitions of threat, vulnerability, risk, and standard risk treatments.
  • Legal and Regulatory Compliance — aligning with the legal/regulatory landscape; governance vs control frameworks; NIST CSF; audits; why compliance ≠ security; practical playbook anchored in the ISO/IEC 27000 family.
  • Cybersecurity Policies and Procedures — policies (why) → standards (what) → procedures (how); playbooks and SOPs; the nine-policy starter set (AUP, ACP, IR, DR, BCP, etc.).
  • Future of Cybersecurity Compliance — NIS2, DORA, CRA, EU AI Act, SEC disclosure rules, NIST CSF 2.0.

Module 2 · Introduction to Risk Management

Assessing, managing, modeling, and continuity-planning around cybersecurity risk.

  • Risk Assessment — anatomy of a risk; quantitative six-step method (AV, EF, SLE, ARO, ALE, cost-benefit); qualitative surveys/workshops; hybrid approach.
  • Risk Management — four risk responses; 3 control categories × 6 types; NIST RMF six-stage cycle.
  • Threat Modeling — proactive vs reactive; asset/attacker/software approaches; STRIDE; decomposition; DREAD.
  • Business Continuity Planning (planned)

Additional modules will be added as the program progresses.


Where this program feeds into

  • Program 2 · DevSecOps and Secure Software Delivery picks up the "policies and controls" thread and applies it to the software delivery lifecycle.
  • Program 3 · Application Security — OWASP Top 10 and Threat Modeling makes the "threats and vulnerabilities" thread concrete for web applications.
  • Program 4 · Data, Privacy and AI Security extends confidentiality and compliance into the data and ML domain.

Personal learning notes — cybersecurity curriculum.