Cybersecurity Advanced & Governance
Most organisations do not fail an audit because a control was missing. They fail because nobody could show that the control had been operating, or who owned it, or when it was last reviewed. This two-day programme is for the person responsible for the security function rather than for the security tooling. It covers how a programme is structured, documented, measured and reported so that it holds up under external examination and continues to run when the person who built it goes on leave.
Programme Agenda
Structuring the Security Function
Where security reports, what it owns versus what it advises on, and the RACI that prevents the same gap being everyone's and no one's. Building authority without accumulating operational work that belongs elsewhere.
Choosing and Combining Control Frameworks
ISO/IEC 27001, the NIST Cybersecurity Framework and CIS Controls compared on what each is good for. Mapping one to another so a single control set answers multiple obligations instead of running parallel programmes.
Policy Architecture That People Follow
The hierarchy from policy to standard to procedure to guideline, and why collapsing it produces documents nobody reads. Ownership, review cycles, exception handling and the approval trail.
Risk Assessment and Treatment in Practice
Asset and process scoping, threat modelling at a level that stays useful, likelihood and impact scales that mean the same thing to two different assessors, and treatment decisions recorded so they can be defended later.
Third-Party and Supply Chain Risk
Tiering suppliers by dependency rather than by spend, due diligence proportionate to tier, contractual security clauses, right to audit, and ongoing monitoring beyond the onboarding questionnaire.
Metrics That Say Something
Moving past counting blocked emails. Coverage, currency, and time-based measures such as mean time to detect and patch latency, chosen so a worsening number triggers a decision rather than an explanation.
Audit and Regulatory Readiness
Evidence design: capturing proof of operation as a by-product of the control rather than assembling it the week before an audit. Managing findings, remediation plans and repeat observations.
Reporting Upward
Translating the programme for an audit committee or board. What belongs in a quarterly pack, how to present a deteriorating position without losing support, and the incident briefing format that works under pressure.
Learning Outcomes:
Structure a security function with clear ownership and defensible authority
Select a control framework and map it against the other obligations you carry
Build a policy hierarchy with review cycles and a working exception process
Run a risk assessment that produces consistent results across assessors
Tier and monitor third-party risk beyond an onboarding questionnaire
Choose metrics that drive decisions rather than describe activity
Produce audit evidence as a by-product of control operation
Report the programme's state to a board without either alarming or reassuring falsely
Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Advanced
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Cybersecurity
- Cyber Security Act 2024 (Act 854) and NACSA Readiness · All levels, 1 day
- Data Breach Response and Incident Management · All levels, 1 day
- Incident Response and Digital Forensics · Intermediate, 2 days
- Cloud Security Fundamentals (AWS, Azure, GCP) · Intermediate, 2 days
- OT and ICS Security · All levels, 2 days
- CompTIA Security+ Certification · Intermediate, 5 days
- CompTIA CySA+ Certification · Intermediate to Advanced, 5 days
- ISC2 Certified in Cybersecurity (CC) · Beginner, 3 days