课程大纲
1. 风险管理简介
2. 风险评估方法
3. ISO 27005 资讯安全风险管理框架和流程模型
4. 资讯资产的分类和识别
5. 对资讯资产的威胁定义
6. 识别这些威胁可能利用的漏洞
7. 风险分析:使用量表和简单计算进行风险评分
8. 风险分析工具简介
9. 风险评估和验收策略
10. 风险处理和缓解控制措施的选择
11. 风险评估和管理的审查和持续改进
12. 风险沟通和谘询
13. 将 ISO 27005 资讯安全风险管理框架整合到 ISO 27001 ISMS 中
客户评论 (5)
报告和规则设置。
Jack - CFNOC- DND
课程 - Micro Focus ArcSight ESM Advanced
机器翻译
The fact that there were practical examples with the content
Smita Hanuman - Standard Bank of SA Ltd
课程 - Basel III – Certified Basel Professional
The trainer was extremely clear and concise. Very easy to understand and absorb the information.
Paul Clancy - Rowan Dartington
课程 - CGEIT – Certified in the Governance of Enterprise IT
The trainer was very motivated and knowledgeable. The trainer was not only capable of information transfer, she also brought it with humor to lighten the dry theoretical training subject.
Marco van den Berg - ZiuZ Medical B.V.
课程 - HIPAA Compliance for Developers
I genuinely enjoyed the real examples of the trainer.