VOOZH about

URL: https://www.coursera.org/learn/packt-it-governance-mastering-security-and-risk-management

⇱ IT Governance: Mastering Security & Risk Management | Coursera


IT Governance: Mastering Security & Risk Management

Keep adding new skills with 10,000+ programs for $239 (usually $399). Save now.

IT Governance: Mastering Security & Risk Management

Included with

Ask Coursera

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

2 weeks to complete
at 10 hours a week
Flexible schedule
Learn at your own pace

Gain insight into a topic and learn the fundamentals.
Intermediate level

Recommended experience

2 weeks to complete
at 10 hours a week
Flexible schedule
Learn at your own pace

What you'll learn

  • Understand and apply ISO 27001 frameworks to strengthen IT governance.

  • Conduct effective risk assessments and create robust information security policies.

  • Manage information security compliance and monitor security incidents.

Details to know

Shareable certificate

Add to your LinkedIn profile

Recently updated!

June 2026

Assessments

26 assignments

Taught in English

There are 26 modules in this course

This course offers an in-depth understanding of IT governance, focusing on information security, risk management, and frameworks such as ISO 27001. It provides actionable insights into securing your IT systems and aligning with international regulations.

This course provides a comprehensive overview of IT governance and information security, focusing on practical frameworks like ISO 27001 and real-world risk management strategies. It equips learners with the knowledge to build and maintain secure IT environments while aligning security practices with business goals. Designed for professionals seeking to enhance their expertise, it offers actionable insights and expert guidance. This course is ideal for IT professionals, information security managers, and those involved in cybersecurity. A foundational understanding of IT systems and security concepts is recommended. Learners will gain the skills to strengthen their organization's security posture and align it with regulatory requirements. This course provides a structured approach to understanding and implementing IT governance, with a focus on information security frameworks and best practices, guiding readers through various security threats and solutions. © Alan Calder and Steve Watkins 2002, 2003, 2005, 2008, 2012, 2015, 2020, 2024. The authors have asserted the rights of the author under the Copyright, Designs and Patents Act, 1988, to be identified as the authors of this work. Editions one, two, three, four, five, six and seven published by Kogan Page. This edition published in the United Kingdom in 2024 by IT Governance Publishing. Every possible effort has been made to ensure that the information contained in this book is accurate at the time of going to press, and the publisher and the author cannot accept responsibility for any errors or omissions, however caused. Any opinions expressed in this book are those of the author, not the publisher. Websites identified are for reference only, not endorsement, and any website visits are at the reader’s own risk. No responsibility for loss or damage occasioned to any person acting, or refraining from action, as a result of the material in this publication can be accepted by the publisher or the author. Apart from any fair dealing for the purposes of research or private study, or criticism or review, as permitted under the Copyright, Designs and Patents Act 1988, this publication may only be reproduced, stored or transmitted, in any form, or by any means, with the prior permission in writing of the publisher or, in the case of reprographic reproduction, in accordance with the terms of licences issued by the Copyright Licensing Agency. Enquiries concerning reproduction outside those terms should be sent to the publisher at the following address: IT Governance Publishing Ltd Unit 3, Clive Court Bartholomew’s Walk Cambridgeshire Business Park Ely, Cambridgeshire CB7 4EA United Kingdom www.itgovernancepublishing.co.uk

This module explores the growing importance of information security in today's digital landscape, examining the increasing threats to organizational data and the impact of cyber crime and cyber warfare. Learners will also review key legislation shaping information security practices and understand why robust security measures are essential for organizations.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 25 minutes
  • Introduction6 minutes
  • Information Insecurity6 minutes
  • Cyber War9 minutes
  • Legislation4 minutes
1 assignmentTotal 16 minutes
  • The Critical Role of Information Security16 minutes

This module explores the evolution and key principles of corporate governance frameworks, focusing on the UK Corporate Governance Code, the FRC Guidance on Risk Management, and the Sarbanes-Oxley Act. Learners will examine how these regulations shape risk management, internal controls, and compliance in organizations. The module also introduces the COSO ERM Framework as a standard for effective risk oversight.

What's included

4 readings1 assignment

4 readingsTotal 23 minutes
  • Introduction4 minutes
  • The Corporate Governance Code7 minutes
  • Sarbanes-Oxley4 minutes
  • COSO ERM Framework8 minutes
1 assignmentTotal 16 minutes
  • Corporate Governance and Risk Management Fundamentals16 minutes

This module introduces the ISO/IEC 27001 standard and its role within the broader ISO/IEC 27000 series, highlighting the benefits of certification and best practices for implementing an information security management system (ISMS). Learners will explore structured approaches to ISMS implementation, integration with other management systems, and the importance of leadership and communication in achieving compliance.

What's included

1 video7 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
7 readingsTotal 36 minutes
  • Introduction6 minutes
  • The ISO/IEC 27000 Series of Standards4 minutes
  • ISO/IEC 270026 minutes
  • Structured Approach to Implementation5 minutes
  • Management System Integration6 minutes
  • Leadership5 minutes
  • Communication4 minutes
1 assignmentTotal 16 minutes
  • ISO 27001 Fundamentals and Implementation16 minutes

This module explores how organizations can effectively structure and manage their information security programs in alignment with ISO 27001. Learners will examine key roles, responsibilities, and processes, including management reviews, cross-functional forums, and the importance of specialist advice and external contacts. By the end, participants will understand how to coordinate information security efforts across an organization.

What's included

1 video7 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
7 readingsTotal 40 minutes
  • Introduction6 minutes
  • Management Review5 minutes
  • The Cross-Functional Management Forum7 minutes
  • Chairperson4 minutes
  • Allocation of Information Security Responsibilities5 minutes
  • Specialist Information Security Advice6 minutes
  • Contact with Authorities7 minutes
1 assignmentTotal 16 minutes
  • Information Security Governance and Management16 minutes

This module explores the foundational elements of crafting an effective information security policy, emphasizing the critical role of top management commitment and clear policy statements. Learners will examine the importance of defining key security terms and aligning policy with recognized standards such as ISO 27001. By the end, participants will understand how to articulate and scope an information security policy within an organizational context.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 21 minutes
  • Introduction6 minutes
  • Who?6 minutes
  • What?4 minutes
  • A Policy Statement5 minutes
1 assignmentTotal 16 minutes
  • Information Security Policy and Scope Fundamentals16 minutes

This module guides learners through the process of conducting an information security risk assessment in alignment with ISO 27001, including defining boundaries, identifying critical assets, and evaluating threats and vulnerabilities. Learners will also explore how to select appropriate controls and develop a Statement of Applicability and risk treatment plan. By the end, participants will understand how to document and justify security decisions within an ISMS framework.

What's included

1 video9 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
9 readingsTotal 54 minutes
  • Introduction6 minutes
  • Approach to Risk Assessment8 minutes
  • Quantitative Risk Analysis6 minutes
  • Identify the Boundaries6 minutes
  • Identify Criticality: The Relationships Between Assets and Objectives5 minutes
  • Identify Potential Threats and Vulnerabilities (Likelihood)6 minutes
  • Selection of Controls and Statement of Applicability5 minutes
  • Statement of Applicability Example6 minutes
  • Risk Treatment Plan6 minutes
1 assignmentTotal 16 minutes
  • Risk Assessment and Control Implementation16 minutes

This module explores the key principles and controls for managing mobile devices and enabling secure remote work in accordance with ISO 27002 standards. Learners will gain insights into developing effective policies and operational procedures to support remote and hybrid working environments.

What's included

1 video2 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
2 readingsTotal 12 minutes
  • Introduction7 minutes
  • Remote Working5 minutes
1 assignmentTotal 16 minutes
  • Securing Remote and Mobile Work16 minutes

This module explores the critical role of human resources in supporting information security management systems (ISMS) according to ISO 27001 and ISO 27002 standards. Learners will examine best practices for employee screening, employment terms, ongoing management responsibilities, and disciplinary processes to ensure organizational security. By the end, participants will understand how HR policies and procedures contribute to a secure information environment.

What's included

1 video5 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
5 readingsTotal 34 minutes
  • Introduction5 minutes
  • Screening7 minutes
  • Terms and Conditions of Employment5 minutes
  • During Employment11 minutes
  • Disciplinary Process6 minutes
1 assignmentTotal 16 minutes
  • Human Resources Security Fundamentals16 minutes

This module explores the principles and practices of managing information assets within an organization, focusing on asset classification, acceptable use policies, and secure handling procedures. Learners will gain insights into international classification systems and the implementation of controls for different asset sensitivity levels.

What's included

1 video5 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
5 readingsTotal 33 minutes
  • Introduction10 minutes
  • Acceptable Use of Information and Other Assets6 minutes
  • Unified Classification Markings6 minutes
  • Sec16 minutes
  • SEC35 minutes
1 assignmentTotal 16 minutes
  • Understanding Information Asset Management Principles16 minutes

This module explores best practices and policies for secure information exchange within and between organizations, focusing on compliance with relevant legislation. Learners will examine formal agreements, email and social media usage, and strategies for managing internet use to protect information integrity and confidentiality. Practical guidance on developing and enforcing acceptable use policies is also provided.

What's included

1 video5 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
5 readingsTotal 31 minutes
  • Introduction8 minutes
  • Agreements on Information Transfers6 minutes
  • Email and Social Media6 minutes
  • Misuse of the Internet and Web Filtering5 minutes
  • Internet Acceptable Use Policy6 minutes
1 assignmentTotal 16 minutes
  • Information Security in Organizational Exchanges16 minutes

This module explores the principles and practices of restricting access to sensitive information within organizations. Learners will examine common hacker techniques, industry standards like ISO 27002, and the balance between security and operational needs. By the end, you'll understand how to implement and evaluate effective access control policies.

What's included

1 video3 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
3 readingsTotal 18 minutes
  • Introduction4 minutes
  • Hacker Techniques9 minutes
  • Access Control5 minutes
1 assignmentTotal 16 minutes
  • Understanding Access Control and Security Policies16 minutes

This module explores the principles and best practices for managing user access within information systems, focusing on formal processes for assigning and revoking access rights. Learners will examine key ISO 27002 controls related to access control and secret authentication information, such as passwords. By the end, participants will understand how to implement secure and compliant user access management procedures.

What's included

1 video3 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
3 readingsTotal 22 minutes
  • Introduction10 minutes
  • Access Rights5 minutes
  • Management of Secret Authentication Information7 minutes
1 assignmentTotal 16 minutes
  • Understanding Access Control and Security Practices16 minutes

This module explores the critical role of supplier relationships in supply chain risk management, with a focus on information security. Learners will examine best practices for integrating security controls into supplier agreements, managing risks in the ICT supply chain, and adapting to changes in third-party services. By the end, participants will understand how to safeguard organizational assets through effective supplier management.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 18 minutes
  • Introduction5 minutes
  • Addressing Security Within Supplier Agreements4 minutes
  • Managing Information Security in the ICT Supply Chain5 minutes
  • Managing Changes to Supplier Services4 minutes
1 assignmentTotal 16 minutes
  • Managing Supplier Relationships in ICT16 minutes

This module explores the principles and best practices for safeguarding physical assets and environments in accordance with ISO 27002. Learners will examine entry controls, secure area requirements, and strategies to mitigate risks from environmental and external threats. By the end, participants will understand how to implement effective physical and environmental security measures within an organization.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 22 minutes
  • Introduction7 minutes
  • Physical Entry6 minutes
  • Securing Offices, Rooms and Facilities5 minutes
  • Protecting Against External and Environmental Threats4 minutes
1 assignmentTotal 16 minutes
  • Physical and Environmental Security Fundamentals16 minutes

This module explores best practices for safeguarding organizational equipment, including protection against physical threats, utility failures, and data breaches. Learners will examine ISO 27002 controls related to equipment security, cabling, and secure disposal or reuse of assets. Practical strategies for minimizing risks and ensuring business continuity are emphasized.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 21 minutes
  • Introduction6 minutes
  • Supporting Utilities4 minutes
  • Cabling Security6 minutes
  • Secure Disposal or Reuse of Equipment5 minutes
1 assignmentTotal 16 minutes
  • Securing Physical and Environmental Assets16 minutes

This module explores strategies for preventing unauthorized access to systems and applications by implementing effective access restrictions and secure authentication processes. Learners will gain an understanding of key ISO 27002 controls and best practices for safeguarding information services.

What's included

1 video2 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
2 readingsTotal 11 minutes
  • Introduction5 minutes
  • Secure Authentication6 minutes
1 assignmentTotal 16 minutes
  • System and Application Access Control Fundamentals16 minutes

This module introduces the principles and policies behind cryptographic controls for information protection. Learners will explore the role of digital signatures in ensuring authenticity and integrity of electronic documents, and understand how cryptographic decisions fit into broader risk assessment processes.

What's included

1 video2 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
2 readingsTotal 12 minutes
  • Introduction6 minutes
  • Digital Signatures6 minutes
1 assignmentTotal 16 minutes
  • Cryptography Fundamentals and Security Practices16 minutes

This module explores the essential practices for maintaining secure and effective operations within an information security management system. Learners will examine the importance of documented procedures, structured change management, and robust information backup strategies aligned with ISO 27001 and ISO 27002 standards. By the end, participants will understand how these controls contribute to organizational resilience and compliance.

What's included

1 video3 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
3 readingsTotal 17 minutes
  • Introduction4 minutes
  • Change Management6 minutes
  • Information Backup7 minutes
1 assignmentTotal 16 minutes
  • Operations Security Fundamentals16 minutes

This module explores essential strategies for detecting, preventing, and responding to various forms of malicious software, including viruses, phishing, and mobile threats. Learners will gain practical knowledge about anti-malware tools, user awareness, and the evolving landscape of cyber attacks targeting both computers and handheld devices.

What's included

1 video4 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
4 readingsTotal 29 minutes
  • Introduction5 minutes
  • Anti-malware Software5 minutes
  • Phishing and Pharming9 minutes
  • Airborne Viruses10 minutes
1 assignmentTotal 16 minutes
  • Malware Defense and Data Protection Fundamentals16 minutes

This module explores essential strategies for securing organizational networks, including network segmentation, secure wireless deployment, and controlled access to network services. Learners will examine best practices for managing routers, switches, and extranets in alignment with ISO 27001 and ISO 27002 standards. By the end, participants will understand how to implement and evaluate effective network security controls.

What's included

1 video6 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
6 readingsTotal 33 minutes
  • Introduction5 minutes
  • Segregation in Networks6 minutes
  • Extranets4 minutes
  • Wireless Networks5 minutes
  • Access to Networks and Network Services7 minutes
  • Routers and Switches6 minutes
1 assignmentTotal 16 minutes
  • Network Security Fundamentals16 minutes

This module explores the processes and challenges involved in acquiring, developing, and maintaining information and communication technology (ICT) systems, with a focus on security considerations. Learners will examine key issues in e-commerce security and review essential security technologies and controls relevant to modern organizations.

What's included

1 video3 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
3 readingsTotal 17 minutes
  • Introduction5 minutes
  • E-commerce Issues6 minutes
  • Security Technologies6 minutes
1 assignmentTotal 14 minutes
  • Security in System Acquisition and Development14 minutes

This module explores how information security is integrated throughout the systems development lifecycle, emphasizing secure architecture, engineering principles, and structured security testing. Learners will gain practical knowledge of best practices for embedding security controls in development and acceptance processes.

What's included

1 video3 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
3 readingsTotal 17 minutes
  • Introduction6 minutes
  • Secure Systems Architecture and Engineering Principles4 minutes
  • Security Testing in Development and Acceptance7 minutes
1 assignmentTotal 16 minutes
  • Development and Support Processes Knowledge Check16 minutes

This module explores the integration of monitoring, logging, and incident management within information security frameworks, focusing on ISO 27002 controls. Learners will discover best practices for protecting log data, establishing incident response procedures, and leveraging incident reports for continual improvement. Practical guidance on reporting events and software malfunctions is also provided.

What's included

1 video6 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
6 readingsTotal 34 minutes
  • Introduction6 minutes
  • Protection of Log Information5 minutes
  • Incident Management - Responsibilities and Procedures5 minutes
  • Reporting Information Security Events7 minutes
  • Reporting Software Malfunctions6 minutes
  • Learning from Incidents5 minutes
1 assignmentTotal 16 minutes
  • Security Incident Management Fundamentals16 minutes

This module explores how organizations can ensure the continuity of both business operations and information security during major disruptions. Learners will examine best practices for business continuity planning, including risk assessment, plan development, testing, and maintenance, with a focus on integrating information security into every stage.

What's included

1 video5 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
5 readingsTotal 31 minutes
  • Introduction5 minutes
  • Business Continuity and Risk Assessment6 minutes
  • Business Continuity Planning Framework9 minutes
  • Testing, Maintaining, and Reassessing Business Continuity Plans7 minutes
  • Information Security Continuity4 minutes
1 assignmentTotal 16 minutes
  • Business Continuity and Information Security Planning16 minutes

This module explores key compliance requirements for information security management, focusing on major UK, EU, and US legislation, as well as international standards related to data protection and organizational records. Learners will gain an understanding of how to identify, interpret, and implement compliance controls within an ISO 27001 framework.

What's included

1 video9 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
9 readingsTotal 55 minutes
  • Introduction7 minutes
  • UK Legislation5 minutes
  • The Freedom of Information Act 20006 minutes
  • The Electronic Communications Act 20006 minutes
  • GLBA6 minutes
  • DORA5 minutes
  • Software Copyright7 minutes
  • Protection of Organizational Records6 minutes
  • Personal Information Management System (PIMS)7 minutes
1 assignmentTotal 16 minutes
  • Compliance in Information Security16 minutes

This module guides learners through the ISO 27001 audit process, emphasizing the significance of certification and the steps involved in the initial audit stages. Participants will gain insights into how organizations prepare for and undergo formal assessments of their Information Security Management Systems (ISMS).

What's included

1 video2 readings1 assignment

1 videoTotal 1 minute
  • Overview1 minute
2 readingsTotal 15 minutes
  • Introduction6 minutes
  • Initial Audit9 minutes
1 assignmentTotal 16 minutes
  • ISO 27001 Audit Fundamentals16 minutes

Instructor

Offered by

Why people choose Coursera for their career

👁 Image

Felipe M.

Learner since 2018
"To be able to take courses at my own pace and rhythm has been an amazing experience. I can learn whenever it fits my schedule and mood."
👁 Image

Jennifer J.

Learner since 2020
"I directly applied the concepts and skills I learned from my courses to an exciting new project at work."
👁 Image

Larry W.

Learner since 2021
"When I need courses on topics that my university doesn't offer, Coursera is one of the best places to go."
👁 Image

Chaitanya A.

"Learning isn't just about being better at your job: it's so much more than that. Coursera allows me to learn without limits."

Frequently asked questions

Yes, you can preview the first video and view the syllabus before you enroll. You must purchase the course to access content not included in the preview.

If you decide to enroll in the course before the session start date, you will have access to all of the lecture videos and readings for the course. You’ll be able to submit assignments once the session starts.

Once you enroll and your session begins, you will have access to all videos and other resources, including reading items and the course discussion forum. You’ll be able to view and submit practice assessments, and complete required graded assignments to earn a grade and a Course Certificate.

If you complete the course successfully, your electronic Course Certificate will be added to your Accomplishments page - from there, you can print your Course Certificate or add it to your LinkedIn profile.

This course is currently available only to learners who have paid or received financial aid, when available.

Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.

Financial aid available,