Module · Introduction to Risk Management
Program: Security Foundations, Governance and Risk
The second module of the program. Where Module 1 asked "what is cybersecurity and how is it governed?", this module asks the natural follow-up: "how do we actually manage the risks that governance is trying to control?" It covers the assessment, ongoing management, proactive modeling, and continuity-planning aspects of the risk discipline.
Submodules
- Risk Assessment — anatomy of a risk; quantitative six-step method (AV, EF, SLE, ARO, ALE, cost-benefit); qualitative surveys/workshops; hybrid approach.
- Risk Management — four risk responses (mitigate/transfer/accept/ignore); 3 categories of controls (administrative/technical/physical) × 6 types (deterrent/detective/preventive/corrective/recovery/compensating); NIST RMF six-stage cycle.
- Threat Modeling — proactive vs reactive threat modeling; three identification approaches (asset / attacker / software); STRIDE categorization; decomposition of trust boundaries, inputs and privileged functions; prioritization via probability × damage, H/M/L and DREAD.
- Business Continuity Planning (planned)