IT Governance: Mastering Security & Risk Management
Keep adding new skills with 10,000+ programs for $239 (usually $399). Save now.
IT Governance: Mastering Security & Risk Management
Included with
Ask Coursera
Recommended experience
Recommended experience
What you'll learn
Understand and apply ISO 27001 frameworks to strengthen IT governance.
Conduct effective risk assessments and create robust information security policies.
Manage information security compliance and monitor security incidents.
Skills you'll gain
- Cyber Governance
- Governance Risk Management and Compliance
- Incident Response
- Information Assurance
- Information Systems Security
- Business Continuity
- Governance
- IT Service Management
- Cryptography
- Cybersecurity
- Security Controls
- Security Management
- Risk Management
- Cyber Security Strategy
- IT Management
- Incident Management
- Computer Security Incident Management
- Cryptographic Protocols
- IT Security Architecture
- ISO/IEC 27001
Details to know
June 2026
26 assignments
See how employees at top companies are mastering in-demand skills
There are 26 modules in this course
This course offers an in-depth understanding of IT governance, focusing on information security, risk management, and frameworks such as ISO 27001. It provides actionable insights into securing your IT systems and aligning with international regulations.
This course provides a comprehensive overview of IT governance and information security, focusing on practical frameworks like ISO 27001 and real-world risk management strategies. It equips learners with the knowledge to build and maintain secure IT environments while aligning security practices with business goals. Designed for professionals seeking to enhance their expertise, it offers actionable insights and expert guidance. This course is ideal for IT professionals, information security managers, and those involved in cybersecurity. A foundational understanding of IT systems and security concepts is recommended. Learners will gain the skills to strengthen their organization's security posture and align it with regulatory requirements. This course provides a structured approach to understanding and implementing IT governance, with a focus on information security frameworks and best practices, guiding readers through various security threats and solutions. © Alan Calder and Steve Watkins 2002, 2003, 2005, 2008, 2012, 2015, 2020, 2024. The authors have asserted the rights of the author under the Copyright, Designs and Patents Act, 1988, to be identified as the authors of this work. Editions one, two, three, four, five, six and seven published by Kogan Page. This edition published in the United Kingdom in 2024 by IT Governance Publishing. Every possible effort has been made to ensure that the information contained in this book is accurate at the time of going to press, and the publisher and the author cannot accept responsibility for any errors or omissions, however caused. Any opinions expressed in this book are those of the author, not the publisher. Websites identified are for reference only, not endorsement, and any website visits are at the reader’s own risk. No responsibility for loss or damage occasioned to any person acting, or refraining from action, as a result of the material in this publication can be accepted by the publisher or the author. Apart from any fair dealing for the purposes of research or private study, or criticism or review, as permitted under the Copyright, Designs and Patents Act 1988, this publication may only be reproduced, stored or transmitted, in any form, or by any means, with the prior permission in writing of the publisher or, in the case of reprographic reproduction, in accordance with the terms of licences issued by the Copyright Licensing Agency. Enquiries concerning reproduction outside those terms should be sent to the publisher at the following address: IT Governance Publishing Ltd Unit 3, Clive Court Bartholomew’s Walk Cambridgeshire Business Park Ely, Cambridgeshire CB7 4EA United Kingdom www.itgovernancepublishing.co.uk
This module explores the growing importance of information security in today's digital landscape, examining the increasing threats to organizational data and the impact of cyber crime and cyber warfare. Learners will also review key legislation shaping information security practices and understand why robust security measures are essential for organizations.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 25 minutes
- Introduction•6 minutes
- Information Insecurity•6 minutes
- Cyber War•9 minutes
- Legislation•4 minutes
1 assignment•Total 16 minutes
- The Critical Role of Information Security•16 minutes
This module explores the evolution and key principles of corporate governance frameworks, focusing on the UK Corporate Governance Code, the FRC Guidance on Risk Management, and the Sarbanes-Oxley Act. Learners will examine how these regulations shape risk management, internal controls, and compliance in organizations. The module also introduces the COSO ERM Framework as a standard for effective risk oversight.
What's included
4 readings1 assignment
4 readings•Total 23 minutes
- Introduction•4 minutes
- The Corporate Governance Code•7 minutes
- Sarbanes-Oxley•4 minutes
- COSO ERM Framework•8 minutes
1 assignment•Total 16 minutes
- Corporate Governance and Risk Management Fundamentals•16 minutes
This module introduces the ISO/IEC 27001 standard and its role within the broader ISO/IEC 27000 series, highlighting the benefits of certification and best practices for implementing an information security management system (ISMS). Learners will explore structured approaches to ISMS implementation, integration with other management systems, and the importance of leadership and communication in achieving compliance.
What's included
1 video7 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
7 readings•Total 36 minutes
- Introduction•6 minutes
- The ISO/IEC 27000 Series of Standards•4 minutes
- ISO/IEC 27002•6 minutes
- Structured Approach to Implementation•5 minutes
- Management System Integration•6 minutes
- Leadership•5 minutes
- Communication•4 minutes
1 assignment•Total 16 minutes
- ISO 27001 Fundamentals and Implementation•16 minutes
This module explores how organizations can effectively structure and manage their information security programs in alignment with ISO 27001. Learners will examine key roles, responsibilities, and processes, including management reviews, cross-functional forums, and the importance of specialist advice and external contacts. By the end, participants will understand how to coordinate information security efforts across an organization.
What's included
1 video7 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
7 readings•Total 40 minutes
- Introduction•6 minutes
- Management Review•5 minutes
- The Cross-Functional Management Forum•7 minutes
- Chairperson•4 minutes
- Allocation of Information Security Responsibilities•5 minutes
- Specialist Information Security Advice•6 minutes
- Contact with Authorities•7 minutes
1 assignment•Total 16 minutes
- Information Security Governance and Management•16 minutes
This module explores the foundational elements of crafting an effective information security policy, emphasizing the critical role of top management commitment and clear policy statements. Learners will examine the importance of defining key security terms and aligning policy with recognized standards such as ISO 27001. By the end, participants will understand how to articulate and scope an information security policy within an organizational context.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 21 minutes
- Introduction•6 minutes
- Who?•6 minutes
- What?•4 minutes
- A Policy Statement•5 minutes
1 assignment•Total 16 minutes
- Information Security Policy and Scope Fundamentals•16 minutes
This module guides learners through the process of conducting an information security risk assessment in alignment with ISO 27001, including defining boundaries, identifying critical assets, and evaluating threats and vulnerabilities. Learners will also explore how to select appropriate controls and develop a Statement of Applicability and risk treatment plan. By the end, participants will understand how to document and justify security decisions within an ISMS framework.
What's included
1 video9 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
9 readings•Total 54 minutes
- Introduction•6 minutes
- Approach to Risk Assessment•8 minutes
- Quantitative Risk Analysis•6 minutes
- Identify the Boundaries•6 minutes
- Identify Criticality: The Relationships Between Assets and Objectives•5 minutes
- Identify Potential Threats and Vulnerabilities (Likelihood)•6 minutes
- Selection of Controls and Statement of Applicability•5 minutes
- Statement of Applicability Example•6 minutes
- Risk Treatment Plan•6 minutes
1 assignment•Total 16 minutes
- Risk Assessment and Control Implementation•16 minutes
This module explores the key principles and controls for managing mobile devices and enabling secure remote work in accordance with ISO 27002 standards. Learners will gain insights into developing effective policies and operational procedures to support remote and hybrid working environments.
What's included
1 video2 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
2 readings•Total 12 minutes
- Introduction•7 minutes
- Remote Working•5 minutes
1 assignment•Total 16 minutes
- Securing Remote and Mobile Work•16 minutes
This module explores the critical role of human resources in supporting information security management systems (ISMS) according to ISO 27001 and ISO 27002 standards. Learners will examine best practices for employee screening, employment terms, ongoing management responsibilities, and disciplinary processes to ensure organizational security. By the end, participants will understand how HR policies and procedures contribute to a secure information environment.
What's included
1 video5 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
5 readings•Total 34 minutes
- Introduction•5 minutes
- Screening•7 minutes
- Terms and Conditions of Employment•5 minutes
- During Employment•11 minutes
- Disciplinary Process•6 minutes
1 assignment•Total 16 minutes
- Human Resources Security Fundamentals•16 minutes
This module explores the principles and practices of managing information assets within an organization, focusing on asset classification, acceptable use policies, and secure handling procedures. Learners will gain insights into international classification systems and the implementation of controls for different asset sensitivity levels.
What's included
1 video5 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
5 readings•Total 33 minutes
- Introduction•10 minutes
- Acceptable Use of Information and Other Assets•6 minutes
- Unified Classification Markings•6 minutes
- Sec1•6 minutes
- SEC3•5 minutes
1 assignment•Total 16 minutes
- Understanding Information Asset Management Principles•16 minutes
This module explores best practices and policies for secure information exchange within and between organizations, focusing on compliance with relevant legislation. Learners will examine formal agreements, email and social media usage, and strategies for managing internet use to protect information integrity and confidentiality. Practical guidance on developing and enforcing acceptable use policies is also provided.
What's included
1 video5 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
5 readings•Total 31 minutes
- Introduction•8 minutes
- Agreements on Information Transfers•6 minutes
- Email and Social Media•6 minutes
- Misuse of the Internet and Web Filtering•5 minutes
- Internet Acceptable Use Policy•6 minutes
1 assignment•Total 16 minutes
- Information Security in Organizational Exchanges•16 minutes
This module explores the principles and practices of restricting access to sensitive information within organizations. Learners will examine common hacker techniques, industry standards like ISO 27002, and the balance between security and operational needs. By the end, you'll understand how to implement and evaluate effective access control policies.
What's included
1 video3 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
3 readings•Total 18 minutes
- Introduction•4 minutes
- Hacker Techniques•9 minutes
- Access Control•5 minutes
1 assignment•Total 16 minutes
- Understanding Access Control and Security Policies•16 minutes
This module explores the principles and best practices for managing user access within information systems, focusing on formal processes for assigning and revoking access rights. Learners will examine key ISO 27002 controls related to access control and secret authentication information, such as passwords. By the end, participants will understand how to implement secure and compliant user access management procedures.
What's included
1 video3 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
3 readings•Total 22 minutes
- Introduction•10 minutes
- Access Rights•5 minutes
- Management of Secret Authentication Information•7 minutes
1 assignment•Total 16 minutes
- Understanding Access Control and Security Practices•16 minutes
This module explores the critical role of supplier relationships in supply chain risk management, with a focus on information security. Learners will examine best practices for integrating security controls into supplier agreements, managing risks in the ICT supply chain, and adapting to changes in third-party services. By the end, participants will understand how to safeguard organizational assets through effective supplier management.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 18 minutes
- Introduction•5 minutes
- Addressing Security Within Supplier Agreements•4 minutes
- Managing Information Security in the ICT Supply Chain•5 minutes
- Managing Changes to Supplier Services•4 minutes
1 assignment•Total 16 minutes
- Managing Supplier Relationships in ICT•16 minutes
This module explores the principles and best practices for safeguarding physical assets and environments in accordance with ISO 27002. Learners will examine entry controls, secure area requirements, and strategies to mitigate risks from environmental and external threats. By the end, participants will understand how to implement effective physical and environmental security measures within an organization.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 22 minutes
- Introduction•7 minutes
- Physical Entry•6 minutes
- Securing Offices, Rooms and Facilities•5 minutes
- Protecting Against External and Environmental Threats•4 minutes
1 assignment•Total 16 minutes
- Physical and Environmental Security Fundamentals•16 minutes
This module explores best practices for safeguarding organizational equipment, including protection against physical threats, utility failures, and data breaches. Learners will examine ISO 27002 controls related to equipment security, cabling, and secure disposal or reuse of assets. Practical strategies for minimizing risks and ensuring business continuity are emphasized.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 21 minutes
- Introduction•6 minutes
- Supporting Utilities•4 minutes
- Cabling Security•6 minutes
- Secure Disposal or Reuse of Equipment•5 minutes
1 assignment•Total 16 minutes
- Securing Physical and Environmental Assets•16 minutes
This module explores strategies for preventing unauthorized access to systems and applications by implementing effective access restrictions and secure authentication processes. Learners will gain an understanding of key ISO 27002 controls and best practices for safeguarding information services.
What's included
1 video2 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
2 readings•Total 11 minutes
- Introduction•5 minutes
- Secure Authentication•6 minutes
1 assignment•Total 16 minutes
- System and Application Access Control Fundamentals•16 minutes
This module introduces the principles and policies behind cryptographic controls for information protection. Learners will explore the role of digital signatures in ensuring authenticity and integrity of electronic documents, and understand how cryptographic decisions fit into broader risk assessment processes.
What's included
1 video2 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
2 readings•Total 12 minutes
- Introduction•6 minutes
- Digital Signatures•6 minutes
1 assignment•Total 16 minutes
- Cryptography Fundamentals and Security Practices•16 minutes
This module explores the essential practices for maintaining secure and effective operations within an information security management system. Learners will examine the importance of documented procedures, structured change management, and robust information backup strategies aligned with ISO 27001 and ISO 27002 standards. By the end, participants will understand how these controls contribute to organizational resilience and compliance.
What's included
1 video3 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
3 readings•Total 17 minutes
- Introduction•4 minutes
- Change Management•6 minutes
- Information Backup•7 minutes
1 assignment•Total 16 minutes
- Operations Security Fundamentals•16 minutes
This module explores essential strategies for detecting, preventing, and responding to various forms of malicious software, including viruses, phishing, and mobile threats. Learners will gain practical knowledge about anti-malware tools, user awareness, and the evolving landscape of cyber attacks targeting both computers and handheld devices.
What's included
1 video4 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
4 readings•Total 29 minutes
- Introduction•5 minutes
- Anti-malware Software•5 minutes
- Phishing and Pharming•9 minutes
- Airborne Viruses•10 minutes
1 assignment•Total 16 minutes
- Malware Defense and Data Protection Fundamentals•16 minutes
This module explores essential strategies for securing organizational networks, including network segmentation, secure wireless deployment, and controlled access to network services. Learners will examine best practices for managing routers, switches, and extranets in alignment with ISO 27001 and ISO 27002 standards. By the end, participants will understand how to implement and evaluate effective network security controls.
What's included
1 video6 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
6 readings•Total 33 minutes
- Introduction•5 minutes
- Segregation in Networks•6 minutes
- Extranets•4 minutes
- Wireless Networks•5 minutes
- Access to Networks and Network Services•7 minutes
- Routers and Switches•6 minutes
1 assignment•Total 16 minutes
- Network Security Fundamentals•16 minutes
This module explores the processes and challenges involved in acquiring, developing, and maintaining information and communication technology (ICT) systems, with a focus on security considerations. Learners will examine key issues in e-commerce security and review essential security technologies and controls relevant to modern organizations.
What's included
1 video3 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
3 readings•Total 17 minutes
- Introduction•5 minutes
- E-commerce Issues•6 minutes
- Security Technologies•6 minutes
1 assignment•Total 14 minutes
- Security in System Acquisition and Development•14 minutes
This module explores how information security is integrated throughout the systems development lifecycle, emphasizing secure architecture, engineering principles, and structured security testing. Learners will gain practical knowledge of best practices for embedding security controls in development and acceptance processes.
What's included
1 video3 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
3 readings•Total 17 minutes
- Introduction•6 minutes
- Secure Systems Architecture and Engineering Principles•4 minutes
- Security Testing in Development and Acceptance•7 minutes
1 assignment•Total 16 minutes
- Development and Support Processes Knowledge Check•16 minutes
This module explores the integration of monitoring, logging, and incident management within information security frameworks, focusing on ISO 27002 controls. Learners will discover best practices for protecting log data, establishing incident response procedures, and leveraging incident reports for continual improvement. Practical guidance on reporting events and software malfunctions is also provided.
What's included
1 video6 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
6 readings•Total 34 minutes
- Introduction•6 minutes
- Protection of Log Information•5 minutes
- Incident Management - Responsibilities and Procedures•5 minutes
- Reporting Information Security Events•7 minutes
- Reporting Software Malfunctions•6 minutes
- Learning from Incidents•5 minutes
1 assignment•Total 16 minutes
- Security Incident Management Fundamentals•16 minutes
This module explores how organizations can ensure the continuity of both business operations and information security during major disruptions. Learners will examine best practices for business continuity planning, including risk assessment, plan development, testing, and maintenance, with a focus on integrating information security into every stage.
What's included
1 video5 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
5 readings•Total 31 minutes
- Introduction•5 minutes
- Business Continuity and Risk Assessment•6 minutes
- Business Continuity Planning Framework•9 minutes
- Testing, Maintaining, and Reassessing Business Continuity Plans•7 minutes
- Information Security Continuity•4 minutes
1 assignment•Total 16 minutes
- Business Continuity and Information Security Planning•16 minutes
This module explores key compliance requirements for information security management, focusing on major UK, EU, and US legislation, as well as international standards related to data protection and organizational records. Learners will gain an understanding of how to identify, interpret, and implement compliance controls within an ISO 27001 framework.
What's included
1 video9 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
9 readings•Total 55 minutes
- Introduction•7 minutes
- UK Legislation•5 minutes
- The Freedom of Information Act 2000•6 minutes
- The Electronic Communications Act 2000•6 minutes
- GLBA•6 minutes
- DORA•5 minutes
- Software Copyright•7 minutes
- Protection of Organizational Records•6 minutes
- Personal Information Management System (PIMS)•7 minutes
1 assignment•Total 16 minutes
- Compliance in Information Security•16 minutes
This module guides learners through the ISO 27001 audit process, emphasizing the significance of certification and the steps involved in the initial audit stages. Participants will gain insights into how organizations prepare for and undergo formal assessments of their Information Security Management Systems (ISMS).
What's included
1 video2 readings1 assignment
1 video•Total 1 minute
- Overview•1 minute
2 readings•Total 15 minutes
- Introduction•6 minutes
- Initial Audit•9 minutes
1 assignment•Total 16 minutes
- ISO 27001 Audit Fundamentals•16 minutes
Instructor
Why people choose Coursera for their career
Frequently asked questions
Yes, you can preview the first video and view the syllabus before you enroll. You must purchase the course to access content not included in the preview.
If you decide to enroll in the course before the session start date, you will have access to all of the lecture videos and readings for the course. You’ll be able to submit assignments once the session starts.
Once you enroll and your session begins, you will have access to all videos and other resources, including reading items and the course discussion forum. You’ll be able to view and submit practice assessments, and complete required graded assignments to earn a grade and a Course Certificate.
More questions
Financial aid available,
