Cybersecurity and Information Security

  1. Governance, Risk Management, and Compliance
    1. Information Security Governance
      1. Governance Framework
        1. Board Oversight
          1. Executive Responsibility
            1. Organizational Structure
            2. Security Policies and Procedures
              1. Policy Development
                1. Policy Implementation
                  1. Policy Maintenance
                    1. Procedure Documentation
                    2. Security Awareness and Training
                      1. Awareness Programs
                        1. Role-based Training
                          1. Security Culture
                            1. Training Effectiveness
                          2. Risk Management
                            1. Risk Management Framework
                              1. Risk Management Process
                                1. Risk Governance
                                  1. Risk Communication
                                  2. Risk Assessment
                                    1. Asset Identification
                                      1. Threat Identification
                                        1. Vulnerability Assessment
                                          1. Impact Analysis
                                            1. Likelihood Assessment
                                            2. Risk Analysis
                                              1. Qualitative Risk Analysis
                                                1. Quantitative Risk Analysis
                                                  1. Risk Modeling
                                                  2. Risk Treatment
                                                    1. Risk Mitigation
                                                      1. Risk Transfer
                                                        1. Risk Acceptance
                                                          1. Risk Avoidance
                                                          2. Risk Monitoring
                                                            1. Risk Indicators
                                                              1. Risk Reporting
                                                                1. Risk Review
                                                              2. Compliance Management
                                                                1. Regulatory Compliance
                                                                  1. GDPR Compliance
                                                                    1. Data Protection Principles
                                                                      1. Individual Rights
                                                                        1. Breach Notification
                                                                          1. Data Protection Officer
                                                                          2. HIPAA Compliance
                                                                            1. Protected Health Information
                                                                              1. Administrative Safeguards
                                                                                1. Physical Safeguards
                                                                                  1. Technical Safeguards
                                                                                  2. PCI DSS Compliance
                                                                                    1. Cardholder Data Protection
                                                                                      1. Security Requirements
                                                                                        1. Compliance Validation
                                                                                        2. SOX Compliance
                                                                                          1. Internal Controls
                                                                                            1. Financial Reporting
                                                                                              1. IT General Controls
                                                                                            2. Security Standards and Frameworks
                                                                                              1. NIST Cybersecurity Framework
                                                                                                1. Framework Core
                                                                                                  1. Implementation Tiers
                                                                                                    1. Framework Profiles
                                                                                                    2. ISO 27001/27002
                                                                                                      1. Information Security Management System
                                                                                                        1. Security Controls
                                                                                                          1. Certification Process
                                                                                                          2. CIS Controls
                                                                                                            1. Basic Controls
                                                                                                              1. Foundational Controls
                                                                                                                1. Organizational Controls
                                                                                                              2. Audit and Assessment
                                                                                                                1. Internal Audits
                                                                                                                  1. Audit Planning
                                                                                                                    1. Audit Execution
                                                                                                                      1. Audit Reporting
                                                                                                                      2. External Audits
                                                                                                                        1. Third-party Assessments
                                                                                                                          1. Certification Audits
                                                                                                                            1. Regulatory Examinations
                                                                                                                            2. Continuous Monitoring
                                                                                                                              1. Control Monitoring
                                                                                                                                1. Compliance Monitoring
                                                                                                                                  1. Risk Monitoring