The goal of this course to:
13/10/2021 - Cyber security for Risk Managers
Er zijn nog 7 plaatsen beschikbaar
This course brings value to junior risk managers, internal and external auditors, treasurers and corporate financial professionals.
Expert level: This training will provide advanced characteristics on a specific topic. In order to grasp the concepts of this training, thorough knowledge is required (enhancement).
Review of key threats for the financial sector, based on industry reports and incidents made public.
We will apply the concepts explained previously to a specific scenario, which participants will need to solve in a crisis management game. The scenario features a realistic attack. Round after round, participants (which each have to take on a defined management role) act as the executive committee of the company and must process the information received and make the decisions, hoping that these will help control the attack and minimize business impact. At the end of the game, an explanation of the attack and the related mechanisms is given, and a brief summary of the counter measures that are recommended is provided – so that participants gain a concrete set of examples of how security controls can juggle an attack.
Introduction to the different external compliancy requirements for the Financial sector as well as tips & tricks on how to ensure (internal) compliance. We will also touch upon the impact of the EBA guidelines, the GDPR and the NIS on Cyber Security.
Starting from the ISO27005 framework, we will introduce a typical methodology for information security risk assessments, as well as briefly touch upon other known methodologies.
We will complement this theoretical introduction with two examples of risk assessment methodologies, one for a web application, and another for a third party supplier. There, we will introduce key security frameworks available to the risk manager to design an approach that addresses state of the art security controls exhaustively (e.g. ISO27002, CSA questionnaire, …) or select key controls to address most prominent risk areas (e.g. 20 critical security controls).
This session will focus on how to integrate Information Security in the overall Operational Risk Management process, from a methodology and governance point of view.
Duration: 1 day training
Hours: 9h - 17h (6 lessons per day)
Location: This training will be given online.
How do you start the webinar? You will receive a login and password by email to access our platform. In the platform you will find a link. By clicking on the scheduled date the webinar will start via Webex.
In order to receive training points, it is important to enter your own name and surname in Webex, follow the entire training day and answer the questions suggested by the trainer. Do not follow the training with several people on the same PC.
Type of training:
During Live Webinars you see the presentation and the trainer live via your screen. You can communicate with the trainer and ask questions.