Camp Fire Academy
Learning path
Complete UI/UX Masterclass UI/UX Design Foundations UI/UX Design Intermediate Advanced UX Strategy
Specialisations
Fintech & Banking UI/UX UI/UX with AI Training UX for Leaders Design Thinking Figma Training
Most requested
AI for Workplace Productivity Excel for Business Power BI & Business Intelligence Cybersecurity Awareness PDPA Compliance Data Protection Officer Browse the full catalogue →
For teams
Corporate & In-House Training LMS & Self-Paced Learning Events
Company
About Contact Verify Certificate WhatsApp

Cybersecurity Advanced & Governance

Most organisations do not fail an audit because a control was missing. They fail because nobody could show that the control had been operating, or who owned it, or when it was last reviewed. This two-day programme is for the person responsible for the security function rather than for the security tooling. It covers how a programme is structured, documented, measured and reported so that it holds up under external examination and continues to run when the person who built it goes on leave.

Programme Agenda

Structuring the Security Function

Where security reports, what it owns versus what it advises on, and the RACI that prevents the same gap being everyone's and no one's. Building authority without accumulating operational work that belongs elsewhere.

Choosing and Combining Control Frameworks

ISO/IEC 27001, the NIST Cybersecurity Framework and CIS Controls compared on what each is good for. Mapping one to another so a single control set answers multiple obligations instead of running parallel programmes.

Policy Architecture That People Follow

The hierarchy from policy to standard to procedure to guideline, and why collapsing it produces documents nobody reads. Ownership, review cycles, exception handling and the approval trail.

Risk Assessment and Treatment in Practice

Asset and process scoping, threat modelling at a level that stays useful, likelihood and impact scales that mean the same thing to two different assessors, and treatment decisions recorded so they can be defended later.

Third-Party and Supply Chain Risk

Tiering suppliers by dependency rather than by spend, due diligence proportionate to tier, contractual security clauses, right to audit, and ongoing monitoring beyond the onboarding questionnaire.

Metrics That Say Something

Moving past counting blocked emails. Coverage, currency, and time-based measures such as mean time to detect and patch latency, chosen so a worsening number triggers a decision rather than an explanation.

Audit and Regulatory Readiness

Evidence design: capturing proof of operation as a by-product of the control rather than assembling it the week before an audit. Managing findings, remediation plans and repeat observations.

Reporting Upward

Translating the programme for an audit committee or board. What belongs in a quarterly pack, how to present a deteriorating position without losing support, and the incident briefing format that works under pressure.

Learning Outcomes:
Structure a security function with clear ownership and defensible authority
Select a control framework and map it against the other obligations you carry
Build a policy hierarchy with review cycles and a working exception process
Run a risk assessment that produces consistent results across assessors
Tier and monitor third-party risk beyond an onboarding questionnaire
Choose metrics that drive decisions rather than describe activity
Produce audit evidence as a by-product of control operation
Report the programme's state to a board without either alarming or reassuring falsely

Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: Advanced
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included

Frequently Asked Questions

Information security managers, IT managers who have inherited security ownership, risk and compliance officers, internal auditors covering technology, and anyone preparing to take a security function through certification or regulatory examination.

Working familiarity with IT operations and with at least one control framework or audit process. This is the advanced tier: participants who are new to security are better served by Practical Cybersecurity for Business and IT first.

No. It uses ISO 27001 as one of three reference frameworks and covers what implementation involves, but it does not lead to a lead implementer or lead auditor certificate. Organisations often run this first to decide whether certification is the right goal.

Roughly half. Participants draft a policy structure, score a risk assessment against a common scale, design an evidence approach for two controls, and build a board reporting pack from a supplied scenario.

Yes, this programme is HRD Corp SBL-KHAS claimable. Our team can assist your HR department with the documentation required for the grant application.

Yes. Any programme can be booked as a team day. Everyone works the same brief together, so your people come away having built something and knowing each other better.

If you are claiming under HRD Corp, the session has to fall at least 14 days after your HRD Corp approval. If you are not claiming, the date is flexible and we work around your calendar.

Put them on the self-paced e-learning instead. Your team works through the modules on our LMS in their own time, sits the assessment, and earns the same certificate, so nobody has to clear a full day together.

More in Cybersecurity