Information Security Management Foundation Programme
1Summary
A single unpatched vulnerability or a badly handled access request can cost an organisation far more than the price of preventing it in the first place. This Information Security Management Foundation Programme by the Arab British Fellowship Training Academy starts from that practical reality – the accelerating spread of digital business, cloud services and always-on connectivity has turned information security from a technical afterthought into a frontline management concern, and this programme builds the foundation professionals need to keep pace with it.
Participants move through the core language of the field – confidentiality, integrity, availability, threats and countermeasures – then into the legislation, standards and technical/physical controls that turn that language into working practice, closing with the frameworks used to keep systems and data resilient when something does go wrong.
2Objectives and target group
Who Should Attend?
- IT professionals who handle information, especially confidential data.
- Entrepreneurs and small business owners who need a working grasp of information security.
- IT auditors and service management staff.
- Helpdesk staff and technical support teams.
Knowledge and Benefits:
After completing the program, participants will be able to master the following:
- Master the core concepts of information security management – confidentiality, integrity, availability, vulnerabilities, threats, risks and countermeasures.
- Understand the national legislation and regulations that shape information security management.
- Recognise the international standards, frameworks and organisations that govern the field.
- Understand the business and technical environments in which information security management operates.
- Categorise controls by type and characteristic, and judge their operational effectiveness.
3Course Content
Module 1: Why Information Security Is a Management Priority
- Threats, risks and vulnerabilities facing modern organisations.
- Approach and organisational structure for managing information security.
Module 2: Legislation, Regulation and Standards
- Legislation and regulations that shape information security obligations.
- Core information security management principles and information risk.
Module 3: Building the Security Framework
- Security measures, procedural and people-focused security controls.
- Technical security controls and their role within the overall framework.
- Software development lifecycle, and physical and environmental security controls.
Module 4: Resilience, Investigation and Cryptography
- Disaster recovery and business continuity management.
- Investigations and digital forensics.
- The role of cryptography in protecting information.