Information Security Governance Under International Standards

A structured, applied course in information security governance — designed to be used the week you return.

📍 Tunis🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Guard force performance on information security governance reflects supervision, not instruction. Most security failures involving the wider corporate security practice agenda exploit a process gap rather than a technical one. The programme suits teams tackling this part of corporate security practice together as readily as individuals attending alone. The method assumes participants will be challenged on their handling of information security governance and prepares them for it. Content is organised around the decisions practitioners actually face in the practice within corporate security practice, not around theory headings. Progress on the wider corporate security practice agenda is usually lost in the gap between approval and execution. Comparative studies of information security governance across sectors find the same handful of failure points recurring. Participants gain a realistic view of what this aspect of corporate security practice costs and what it returns. Work concludes with a self-assessment of the wider corporate security practice agenda that participants can repeat annually.

Expected Learning Outcomes

01

Review information security governance after each incident, exercise and change of threat.

02

Assess the current state of information security governance against a structured set of criteria rather than impressions.

03

Manage guard force competence, supervision and performance on information security governance.

04

Communicate the purpose of information security governance to those who have to comply with it.

05

Review contracts and agreements for the obligations they create around information security governance.

06

Plan the response and escalation for incidents involving information security governance.

07

Exercise and test arrangements for information security governance under realistic conditions.

Who Should Attend

01

Security managers and officers responsible for information security governance.

02

Business continuity and crisis managers covering information security governance.

03

Control room and monitoring staff operating information security governance.

04

Information security staff whose remit overlaps information security governance.

05

Department heads accountable for the results of information security governance.

06

Risk managers assessing the exposure created by information security governance.

Course Modules

01

Information security governance: incident response and escalation

2 sessions · 8 points

Session 1The decisions in information security governance that cannot be delegated

  • Rank the weaknesses in information security governance by consequence rather than by ease of fixing.
  • Verify identity checks applied at entry points relevant to information security governance.
  • Confirm vetting standards applied to staff and contractors in information security governance.
  • Identify vulnerabilities in information security governance and rank them by consequence, not ease of fix.

Session 2Layering controls on information security governance so one failure is not fatal

  • Prepare the summary of information security governance that senior management will read.
  • Assess contractor and third-party exposure within information security governance.
  • Build the internal briefing that explains information security governance to those affected.
  • Review surveillance coverage for information security governance against likely approach routes.
02

Information security governance: surveillance, monitoring and control rooms

2 sessions · 8 points

Session 1Making the investment case for information security governance

  • Check that information security governance still works when volumes rise unexpectedly.
  • Check that controls on information security governance cover deterrence, detection, delay and response.
  • Report on information security governance in terms that support an investment decision.
  • Define acceptance criteria for information security governance in advance.

Session 2Supervising the guard force on information security governance

  • Establish evidence handling and chain of custody for information security governance.
  • Review information security governance after every incident, exercise or change in threat.
  • Confirm recorded material from information security governance is retained long enough to be useful.
  • Confirm access control on information security governance cannot be routinely bypassed.
03

Information security governance: threat assessment and intelligence

2 sessions · 8 points

Session 1Moving information security governance from approval to execution

  • Name a single owner for each element of information security governance.
  • Identify single points of dependency in information security governance and reduce them.
  • Anticipate the objections information security governance will raise and prepare the answers.
  • Supervise and spot-check performance on information security governance rather than relying on reports.

Session 2Insider risk inside information security governance

  • Define the first response actions for an incident involving information security governance.
  • Set out how exceptions to information security governance are requested and approved.
  • Test the procedure for information security governance against a realistic scenario.
  • Assign responsibility for keeping documentation of information security governance current.
04

Information security governance: governance, assurance and investment case

2 sessions · 8 points

Session 1Access control on information security governance that people do not bypass

  • Benchmark the organisation's information security governance against comparable operations.
  • Exercise the plan for information security governance under realistic conditions and record failures.
  • Compare the cost of information security governance with the cost of its absence.
  • Establish what evidence demonstrates information security governance is under control.

Session 2Keeping information security governance alive after the initial push

  • Define the trigger that would require information security governance to be redesigned.
  • Plan the sequence in which improvements to information security governance will be introduced.
  • Set escalation criteria and out-of-hours contacts for information security governance.
  • Protect sensitive information relating to information security governance from casual disclosure.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.