Information Security Management and Auditing

  1. Information Security Risk Management
    1. Risk Management Fundamentals
      1. Risk Concepts and Terminology
        1. Risk Management Principles
          1. Risk Management Lifecycle
          2. Risk Assessment Process
            1. Risk Context Establishment
              1. Organizational Risk Appetite
                1. Risk Criteria Definition
                  1. Stakeholder Identification
                  2. Asset Identification and Valuation
                    1. Asset Inventory Development
                      1. Asset Classification Systems
                        1. Asset Valuation Techniques
                        2. Threat Identification and Analysis
                          1. Threat Categories
                            1. Threat Sources and Actors
                              1. Threat Intelligence
                              2. Vulnerability Assessment
                                1. Vulnerability Identification Methods
                                  1. Vulnerability Scanning Tools
                                    1. Manual Assessment Techniques
                                    2. Risk Analysis and Evaluation
                                      1. Likelihood Assessment
                                        1. Impact Analysis
                                          1. Risk Calculation Methods
                                            1. Risk Rating and Prioritization
                                          2. Risk Assessment Methodologies
                                            1. Qualitative Risk Assessment
                                              1. Risk Matrices
                                                1. Scenario Analysis
                                                  1. Expert Judgment
                                                  2. Quantitative Risk Assessment
                                                    1. Single Loss Expectancy (SLE)
                                                      1. Annual Loss Expectancy (ALE)
                                                        1. Return on Security Investment (ROSI)
                                                        2. Hybrid Assessment Approaches
                                                          1. Semi-quantitative Methods
                                                            1. Combining Qualitative and Quantitative Techniques
                                                          2. Risk Treatment Strategies
                                                            1. Risk Mitigation
                                                              1. Control Implementation
                                                                1. Control Effectiveness Evaluation
                                                                  1. Residual Risk Assessment
                                                                  2. Risk Acceptance
                                                                    1. Risk Tolerance Levels
                                                                      1. Management Approval Processes
                                                                        1. Documentation Requirements
                                                                        2. Risk Avoidance
                                                                          1. Activity Elimination
                                                                            1. Process Redesign
                                                                            2. Risk Transfer
                                                                              1. Insurance Coverage
                                                                                1. Contractual Risk Sharing
                                                                                  1. Outsourcing Considerations
                                                                                2. Risk Monitoring and Review
                                                                                  1. Continuous Risk Monitoring
                                                                                    1. Key Risk Indicators (KRIs)
                                                                                      1. Automated Monitoring Systems
                                                                                        1. Risk Dashboard Development
                                                                                        2. Periodic Risk Reviews
                                                                                          1. Risk Register Maintenance
                                                                                            1. Risk Assessment Updates
                                                                                              1. Reporting and Communication