← Cybersecurity Professional Programme

Module 05Strategic1.5 weeks

Strategic Security

The strategic side of cybersecurity: governance, risk management and compliance. More theoretical and standards-driven, with practical exercises that reinforce executing tasks and aligning to compliance and governance frameworks.

01

Learning outcomes

  • Distinguish governance, risk and compliance and explain what each produces
  • Map controls to a recognised framework such as NIST CSF or ISO/IEC 27001
  • Build and score a risk register with treatment decisions
  • Draft an enforceable security policy and the evidence that proves it works
02

What this module covers

Governance, Risk, and Compliance (GRC)Security frameworks and standardsRisk managementSecurity programs and policies
03

Lessons

Lesson 1What GRC actually is

DisciplineQuestion answeredArtefact produced
GovernanceWho decides, and how is security directed?Policies, roles, steering committee
RiskWhat could hurt us and what do we do about it?Risk register with treatments
ComplianceCan we prove we meet obligations?Control evidence, audit reports

GRC is where security stops being a technical opinion and becomes a business decision with an owner, a budget and a deadline.

Lesson 2Frameworks and standards

  • NIST Cybersecurity Framework — Govern, Identify, Protect, Detect, Respond, Recover
  • ISO/IEC 27001 — a certifiable information security management system (ISMS)
  • CIS Critical Security Controls — prioritised, prescriptive technical controls
  • PCI DSS — mandatory where cardholder data is processed
  • GDPR / national data protection law — legal obligations around personal data

Frameworks are not competitors. A typical organisation uses NIST CSF to structure the programme, CIS Controls to implement it, and ISO 27001 or PCI DSS to certify it.

Lesson 3Risk management in practice

A risk register turns vague worry into tracked decisions. Each entry names the asset, the threat, the vulnerability, an inherent score, the control, a residual score, an owner and a review date.

TreatmentMeaningExample
MitigateReduce likelihood or impactEnforce MFA on remote access
TransferShift financial impactCyber insurance, contractual clause
AvoidStop the activityDecommission the legacy portal
AcceptDocument and live with itSigned-off low residual risk

Only a business owner can accept a risk — never the security team on their behalf. Acceptance must be written, time-bound and reviewed.

Lesson 4Security programs and policies

  • Policy — mandatory statement of intent, approved by leadership
  • Standard — the specific requirement (e.g. minimum TLS 1.2)
  • Procedure — the step-by-step method to comply
  • Guideline — recommended, non-mandatory good practice

A policy nobody can comply with produces shadow IT. Write for the people who must follow it, define exceptions and their approval path, and pair every requirement with the evidence that will demonstrate it at audit.

04

Guided hands-on activity

Build a risk register and a policy

  1. 1.List five assets for a fictional 40-person company (customer database, laptops, email, website, backups).
  2. 2.For each asset, record a realistic threat and vulnerability, then score likelihood and impact 1–5 and multiply for an inherent risk score.
  3. 3.Choose a treatment for each risk and name the control, the owner and a review date; recalculate the residual score.
  4. 4.Map every control you chose to a NIST CSF function (Govern, Identify, Protect, Detect, Respond, Recover).
  5. 5.Draft a one-page Acceptable Use or Access Control policy with purpose, scope, requirements, exceptions and the evidence that proves compliance.

Teaching point

Ask of every line: who owns this, and what document would you hand an auditor? If you cannot answer both, the entry is not finished.

05

Knowledge Check

Question 1 of 4

Which artefact is the primary output of the risk discipline?