From the course: Certified Information Systems Auditor (CISA) Cert Prep
Unlock this course with a free trial
Join today to access over 24,100 courses taught by industry experts.
Information security strategy
From the course: Certified Information Systems Auditor (CISA) Cert Prep
Information security strategy
- [Instructor] Now moving right along, let's go ahead and take a look at strategic planning. So this is a critical part of what our governing entities do for us, is they help us take those stakeholder needs, goals and objectives and turn them into strategy. So we've got a definition here from ISACA, which is obviously very relevant since ISACA oversees the CISA exam. So in information security and risk management, so you hear ISRM all the time, provides an organization with a roadmap. So a general direction, not every little specific step along the way, but if I'm going from North Carolina to California, I'm going to get on I-40 and I'm going to drive on I-40 through a bunch of states. But not every little step, every little speed limit, every little exit. So strategy's going to be broad, right? And it's going to have the goals and objectives to make sure that we align our information security program to the business goals of the organization, right? And that's everything. That's what…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
(Locked)
Enterprise risk management8m 30s
-
(Locked)
Introduction to IT governance8m 46s
-
(Locked)
IT frameworks9m 20s
-
(Locked)
Frameworks continued11m 38s
-
(Locked)
Enterprise architecture4m 55s
-
(Locked)
Evaluation of controls3m 36s
-
(Locked)
Evaluation criteria8m 11s
-
(Locked)
Information security strategy8m 9s
-
(Locked)
Information security program6m 44s
-
(Locked)
Quality control and security management3m 40s
-
(Locked)
Roles and responsibilities7m 7s
-
(Locked)
-
-
-