Preventing Information Security Breaches From the Inside Out
1Summary
Every exploited vulnerability starts the same way: a system flaw, an attacker who can reach it, and a tool or technique capable of taking advantage of it. Remove any one of those three elements and the attack surface disappears—which is exactly why vulnerability management, the ongoing cycle of identifying, classifying, remediating and mitigating weaknesses in software and systems, sits at the heart of information security work.
But most organisations misjudge where that surface actually is. The common assumption is that the biggest threat comes from outside; in reality, employees, who can reach company information at almost any time, represent the greater risk. Access control mechanisms help, yet some staff still retain full access to sensitive data, and constant surveillance of employees tends to breed distrust that damages the wider organisation.
This course, developed by the Arab British Fellowship Training Academy using curricula its management continuously updates, works through that tension: how to design a strategy that protects company assets and meets operational needs, while applying preventive information security measures to employees themselves—inside and outside the institution.
2Objectives and target group
Who Should Attend:
- Information security managers and Chief Information Security Officers (CISOs).
- Company owners.
What Participants Will Be Able to Do:
- Raise employees' awareness and self-learning around the general principles and strategy of information security.
- Apply access control mechanisms to protect security system sites, and understand why this matters operationally.
- Operate core security measures, antivirus and firewall software, hacking detection systems, and network disconnection techniques, to guard against vulnerabilities.
3Course Content
Module 1: Understanding Information Security
- What information security means and why it matters to an organisation.
- The risk management strategy behind protecting information assets.
Module 2: Applying Preventive Measures
- Management policy for handling information security in relation to employees.
- Preventive measures that close network security vulnerabilities before they're exploited.