Macquarie University
Cyber Security: GRC Part 2 - Risk Management and Compliance
Macquarie University

Cyber Security: GRC Part 2 - Risk Management and Compliance

Matt Bushby

位教师:Matt Bushby

包含在 Coursera Plus

深入了解一个主题并学习基础知识。
初级 等级

推荐体验

1 周 完成
在 10 小时 一周
灵活的计划
自行安排学习进度
深入了解一个主题并学习基础知识。
初级 等级

推荐体验

1 周 完成
在 10 小时 一周
灵活的计划
自行安排学习进度

您将学到什么

  • Align cyber strategy with business goals and organisational priorities.

  • Implement governance frameworks like NIST and the Three Lines of Defence.

  • Lead cross-functional teams to manage cyber risk and build resilience.

  • Communicate cyber threats effectively to executives and stakeholders.

要了解的详细信息

可分享的证书

添加到您的领英档案

最近已更新!

June 2025

作业

5 项作业

授课语言:英语(English)

了解顶级公司的员工如何掌握热门技能

Petrobras, TATA, Danone, Capgemini, P&G 和 L'Oreal 的徽标

积累特定领域的专业知识

本课程是 Cyber Security: Essentials for Governance, Risk & Compliance 专项课程 专项课程的一部分
在注册此课程时,您还会同时注册此专项课程。
  • 向行业专家学习新概念
  • 获得对主题或工具的基础理解
  • 通过实践项目培养工作相关技能
  • 获得可共享的职业证书

该课程共有5个模块

Every strong security program begins with a clear strategy. In this foundational topic, learners will explore how to design, articulate, and assess an organisational cybersecurity strategy that aligns with broader business goals and effectively secures critical assets. This topic introduces core security principles, including the CIA Triad, Confidentiality, Integrity, and Availability as well as the risks, threats, and vulnerabilities shaping today's cyber landscape. Learners will gain an understanding of how to evaluate an organisation's threat environment, determine cyber risk tolerance, and benchmark maturity using internationally recognised frameworks such as NIST, ISO 27001, and CIS Controls. This module also addresses how to embed cybersecurity into enterprise strategy and culture, transforming it from a technical afterthought into a strategic enabler. Whether you're a current or aspiring cyber leader, this topic sets the stage for developing the mindset, language, and vision needed to lead with impact in a fast-evolving threat landscape. By the end of this topic, learners will be able to describe a tailored cybersecurity strategy, evaluate cyber maturity, and begin aligning security decisions with organisational priorities.

涵盖的内容

1个作业9个插件

Strong governance is the cornerstone of effective cyber security leadership. In this topic, learners will explore how cyber security must be governed at the highest levels of an organisation and why executive oversight, structural clarity, and shared accountability are essential in managing cyber risk at scale. This topic introduces learners to key governance models, including the Three Lines of Defence, and examines the responsibilities of senior management in shaping enterprise-wide cyber security programs. It unpacks how leaders must work across risk, compliance, IT, and operational teams to establish robust governance structures, clear reporting lines, and aligned responsibilities. Learners will also explore global governance frameworks such as the NIST Cybersecurity Framework (CSF), NIST SP 800-53, and the CIS Critical Security Controls, building practical familiarity with their categories, control objectives, and assessment tools. These frameworks provide the structure to define, implement, and evaluate cyber programs aligned with business priorities and risk appetite. By the end of this topic, learners will be able to demonstrate how governance frameworks support strategic oversight, guide risk management decisions, and ensure cyber security is embedded as a shared organisational responsibility, from the boardroom to the frontlines.

涵盖的内容

1个作业14个插件

Cybersecurity is ultimately about managing risk. In this topic, learners will develop the mindset and methods needed to lead cyber risk management efforts across an organisation, balancing security controls with operational needs and business priorities. Building on governance principles, this topic explores the core concepts of cyber risk, including threat modelling, asset classification, risk tolerance, and the evolving nature of digital threats. Learners will walk through structured risk assessment processes, learning how to identify vulnerabilities, assess likelihood and impact, and prioritise mitigation strategies. Through the lens of the Cyber Risk Process Hierarchy, participants will understand how risk management cascades from board-level policy through to day-to-day operational controls. The topic also reinforces the governance structures introduced in Topic 2, such as the Three Lines of Defence (3LOD) model, demonstrating how leadership, management, and assurance functions work together to reduce exposure. By the end of this topic, learners will be equipped to contribute meaningfully to cyber risk discussions, make informed decisions about risk trade-offs, and embed risk-informed thinking into cyber strategy and security programs.

涵盖的内容

1个作业8个插件

In a world of escalating threats and limited resources, effective cybersecurity leadership demands more than intuition, it requires evidence-based decision-making. This topic equips learners with the skills to quantify cyber risks, allowing organisations to prioritise investments and remediation efforts with clarity and confidence. Learners will explore the importance of risk quantification and its role in demonstrating the value of cybersecurity to boards and business leaders. The topic introduces both qualitative and quantitative assessment models, offering a comparison of methods used to calculate risk likelihood, impact, and exposure in financial and operational terms. From risk management concepts to control selection and implementation, learners will evaluate how different frameworks, such as FAIR and NIST, can guide consistent and defensible risk measurement. They will also consider how risk maturity modelling supports continuous improvement and long-term strategy alignment. By the end of this topic, learners will be able to assess organisational risk posture, compare remediation options based on data, and communicate cyber risk in terms that resonate with stakeholders from executives to regulators.

涵盖的内容

1个作业10个插件

In today’s volatile threat landscape, cyber attacks are not a matter of “if”, but “when.” For senior leaders, the true test of cyber resilience lies not just in technical defences, but in how they lead through disruption. This topic arms executive decision-makers with the strategic insights and response frameworks needed to manage cyber crises with confidence. Learners will explore the evolution of cyber attacks, examining real-world case studies and the shifting motivations of attackers, from criminal syndicates to nation-state actors. The topic delves into the cyber kill chain and the anatomy of common attacks, offering practical frameworks for analysis and response. Critically, this topic focuses on the role of senior management in both preparation and response. Learners will examine how leaders make time-critical decisions during incidents, set organisational tone, and coordinate communications with internal and external stakeholders. Through this lens, cyber resilience becomes a leadership responsibility, where risk management, strategic foresight, and trust-building intersect. By the end of the topic, learners will understand the strategic implications of attacks, develop leadership-aligned response strategies, and be ready to build a resilient organisational culture prepared for the next inevitable breach.

涵盖的内容

1篇阅读材料1个作业10个插件

获得职业证书

将此证书添加到您的 LinkedIn 个人资料、简历或履历中。在社交媒体和绩效考核中分享。

位教师

Matt Bushby
Macquarie University
15 门课程7,360 名学生

提供方

从 Computer Security and Networks 浏览更多内容

人们为什么选择 Coursera 来帮助自己实现职业发展

Felipe M.
自 2018开始学习的学生
''能够按照自己的速度和节奏学习课程是一次很棒的经历。只要符合自己的时间表和心情,我就可以学习。'
Jennifer J.
自 2020开始学习的学生
''我直接将从课程中学到的概念和技能应用到一个令人兴奋的新工作项目中。'
Larry W.
自 2021开始学习的学生
''如果我的大学不提供我需要的主题课程,Coursera 便是最好的去处之一。'
Chaitanya A.
''学习不仅仅是在工作中做的更好:它远不止于此。Coursera 让我无限制地学习。'
Coursera Plus

通过 Coursera Plus 开启新生涯

无限制访问 10,000+ 世界一流的课程、实践项目和就业就绪证书课程 - 所有这些都包含在您的订阅中

通过在线学位推动您的职业生涯

获取世界一流大学的学位 - 100% 在线

加入超过 3400 家选择 Coursera for Business 的全球公司

提升员工的技能,使其在数字经济中脱颖而出

常见问题