• Classroom
  • Online, Instructor-Led
Course Description

Conducted properly, information security risk assessments provide managers with the feedback needed to understand threats to corporate assets, determine vulnerabilities of current controls, and select appropriate safeguards. Performed incorrectly, they can provide the false sense of security that allows potential threats to develop into disastrous losses of proprietary information, capital, and corporate value.

Based on best practices and approaches detailed in, The Security Risk Assessment Handbook: A Complete Guide for Performing Security Risk Assessments, Second Edition this course gives you detailed instruction on how to conduct a risk assessment effectively and efficiently. Trusted to assess security for leading organizations (Hospitals, Universities, Retailers, Pharmaceuticals) and government agencies, including CIA, NSA, and NATO, Douglas Landoll unveils the little-known tips, tricks, and techniques used by savvy security professionals in the field. He details time-tested methods to help you,

This course covers all of the elements of conducting an information security risk assessment from the statement of work to the final report. Walking you through the process of conducting an effective security assessment, it provides the tools and up-to-date understanding you need to select the security measures best suited to your organization.

Learning Objectives

At the completion of this course attendees will be able to:

  • Better negotiate the scope and rigor of security assessments
  • Effectively interface with security assessment teams
  • Effectively assess any security control (administrative, technical, or physical)
  • Gain an improved understanding of final report recommendations
  • Deliver insightful comments on draft reports

Framework Connections

The materials within this course focus on the NICE Framework Task, Knowledge, and Skill statements identified within the indicated NICE Framework component(s):

Specialty Areas

  • Cyber Defense Analysis
  • Cyber Defense Infrastructure Support
  • Cyber Investigation
  • Cyber Operational Planning
  • Cyber Operations
  • Cybersecurity Management
  • Digital Forensics
  • Executive Cyber Leadership
  • Exploitation Analysis
  • Incident Response
  • Network Services
  • Risk Management
  • Systems Analysis
  • Systems Architecture
  • Test and Evaluation
  • Threat Analysis
  • Vulnerability Assessment and Management

Specialty Areas have been removed from the NICE Framework. With the recent release of the new NICE Framework data, updates to courses are underway. Until this course can be updated, this historical information is provided to give better context as to how it can help you with your cybersecurity goals.