Skip to content

Module · Introduction to Risk Management

Program: Security Foundations, Governance and Risk

The second module of the program. Where Module 1 asked "what is cybersecurity and how is it governed?", this module asks the natural follow-up: "how do we actually manage the risks that governance is trying to control?" It covers the assessment, ongoing management, proactive modeling, and continuity-planning aspects of the risk discipline.


Submodules

  • Risk Assessment — anatomy of a risk; quantitative six-step method (AV, EF, SLE, ARO, ALE, cost-benefit); qualitative surveys/workshops; hybrid approach.
  • Risk Management — four risk responses (mitigate/transfer/accept/ignore); 3 categories of controls (administrative/technical/physical) × 6 types (deterrent/detective/preventive/corrective/recovery/compensating); NIST RMF six-stage cycle.
  • Threat Modeling — proactive vs reactive threat modeling; three identification approaches (asset / attacker / software); STRIDE categorization; decomposition of trust boundaries, inputs and privileged functions; prioritization via probability × damage, H/M/L and DREAD.
  • Business Continuity Planning (planned)

Personal learning notes — cybersecurity curriculum.