Lorsque vous vous inscrivez à ce cours, vous êtes également inscrit(e) à cette Spécialisation.
Apprenez de nouveaux concepts auprès d'experts du secteur
Acquérez une compréhension de base d'un sujet ou d'un outil
Développez des compétences professionnelles avec des projets pratiques
Obtenez un certificat professionnel partageable
Il y a 3 modules dans ce cours
This course provides a practical, hands-on approach to applying the Factor Analysis of Information Risk (FAIR) methodology in cyber risk management. Students will learn how to leverage industry research, use FAIR for decision-making, and report on the materiality of cyber incidents using FAIR-MAM (Materiality Assessment Methodology). Through real-world CISO lectures and exercises, participants will gain the skills to quantify and communicate cyber risk effectively in financial terms.
This course is tailored for senior executives and decision-makers overseeing or guiding cyber risk management within their organizations. Ideal participants will have:
Leadership and Strategic Oversight: Participants should hold or aspire to hold leadership roles such as Chief Executive Officer (CEO), Chief Information Security Officer (CISO), Chief Risk Officer (CRO), or senior management positions where they are responsible for setting and implementing risk management strategies.
Experience with Financial or Business Risk: Executives with experience managing financial risk or business continuity planning will find the course particularly valuable, as it covers the intersection of cyber risk and financial decision-making.
Commitment to Continuous Improvement: A mindset geared toward continuous improvement in risk management practices, with a willingness to explore and adopt new methodologies, such as the FAIR model, to enhance their organization's cyber resilience.
This course is designed to equip senior leaders with the practical skills and insights necessary to integrate the FAIR model into their organization’s broader risk management strategy, ensuring a more quantitative and business-aligned approach to managing cyber risks.
This module focuses on enhancing cyber risk management practices through industry research, risk quantification using FAIR, and evolving approaches to cyber risk. It covers recent trends, empirical studies, and the application of FAIR to mature security programs. The module explores how quantitative risk analysis can improve decision-making and discusses the evolution of cyber risk management, including the integration of FAIR with frameworks like NIST CSF.
Inclus
10 vidéos11 lectures10 devoirs8 sujets de discussion
Afficher les informations sur le contenu du module
10 vidéos•Total 45 minutes
Introduction to Practical Applications of FAIR™ for CRM•2 minutes
(Optional) Cyentia IRIS Xtreme (Information Risk Insights Study Xtreme)•60 minutes
Quantitative Decision Analysis•10 minutes
FAIR Risk Analysis Example•30 minutes
FAIR-U Tool - Risk Analysis Training Application•60 minutes
NIST-CSF 2.0 Takes a Major Step to Acknowledge Cyber Risk as a Business Risk•30 minutes
FAIR Risk Management•10 minutes
10 devoirs•Total 27 minutes
Graded Assessment -1•9 minutes
Assessment for CRM Research at MIT Sloan•2 minutes
Assessment of Forrester’s Cyber Risk Management Research•2 minutes
Assessment for Data Integrity•2 minutes
Assessment of Missing GAAP for CRM•2 minutes
Assessment for FAIR Enables Business Decisions•2 minutes
Assessment of Effective Operational Risk Management: Quantifying Risk Reduction and Setting Risk Appetite•2 minutes
Assessment for FAIR Enables Security Programs to Mature•2 minutes
Assessment of FAIR Enables a Proactive Approach to CRM•2 minutes
Assessment of Adopting the FAIR Model•2 minutes
8 sujets de discussion•Total 50 minutes
Introduce Yourself•5 minutes
4 Critical Areas Boards Need to Address•10 minutes
Automating FAIR•5 minutes
Multi-party Incidents•5 minutes
Quantitative Decision Analysis•10 minutes
Data Gathering•5 minutes
NIST-CSF 2.0 + FAIR•5 minutes
FAIR Enables Accuracy•5 minutes
FAIR Improves Decision-making
Module 2•4 heures à terminer
Détails du module
This module explores how the Factor Analysis of Information Risk (FAIR) framework enhances decision-making processes in cyber risk management. Participants will delve into the complexities of trade-off decisions, learn effective cyber risk quantification techniques, and discover how to optimize decision-making using FAIR. Through a combination of videos, readings, and real-world use cases from various industries, learners will gain practical insights into applying FAIR to improve business objectives and communicate more effectively with executive stakeholders.
Inclus
11 vidéos6 lectures12 devoirs1 évaluation par les pairs6 sujets de discussion
Afficher les informations sur le contenu du module
11 vidéos•Total 57 minutes
FAIR’s Primary Purpose•6 minutes
Financial Services CRM Trade-offs •4 minutes
Healthcare Use Case Example•4 minutes
FAIR Helps CISOs Manage Budget •5 minutes
Risk Buy-Down with FAIR•5 minutes
Cyber Insurance Use Case with FAIR•6 minutes
Optimizing Decision-Making with FAIR•5 minutes
Mastering FAIR for Global Technology Risk•4 minutes
Credit Monitoring Use Case•5 minutes
Health Insurance Business Use Case•5 minutes
NASA (Mission-focused) FAIR Use Case•6 minutes
6 lectures•Total 87 minutes
Managing Cybersecurity Surprises: The Executive’s Perspective•10 minutes
Understanding Cyber Risk Quantification: A Buyer’s Guide•15 minutes
Putting a Price on Risk | How to Prioritize Your Cybersecurity Budget in 2024•12 minutes
Quantifying Risk to Reduce Premiums•30 minutes
4 Steps to a Smarter Risk Heat Map•10 minutes
Three Types of Risk Skeptics•10 minutes
12 devoirs•Total 33 minutes
Graded Assessment 2•11 minutes
Assessment of FAIR'S Primary Purpose•2 minutes
Assessment of Financial Service Trade-offs•2 minutes
Assessment for Healthcare Use Case Example•2 minutes
Assessment of FAIR Helps CISOs Manage Budget•2 minutes
Assessment of Risk Buy-Down with FAIR•2 minutes
Assessment for Cyber Insurance Use Case with FAIR•2 minutes
Assessment for Optimizing Decision Making with FAIR•2 minutes
Assessment of Mastering FAIR for Global Technology Risk•2 minutes
Assessment of Credit Monitoring Use Case•2 minutes
Assessment of Health Insurance Business Use Case•2 minutes
Assessment of NASA (Mission-focused) FAIR Use Case•2 minutes
1 évaluation par les pairs•Total 30 minutes
Peer Review•30 minutes
6 sujets de discussion•Total 35 minutes
Managing Cybersecurity Surprises•5 minutes
Cybersecurity Budgets•5 minutes
Cyber Insurance Terms•5 minutes
Risk Quantification Improves Debates•5 minutes
Risk Skeptic•10 minutes
Business Value Use Cases•5 minutes
Reporting Materiality of a Cyber Incident
Module 3•5 heures à terminer
Détails du module
This module explores the critical concept of materiality in the context of cyber incidents and its implications for reporting to the Securities and Exchange Commission (SEC). Participants will gain a comprehensive understanding of how to define, assess, and communicate the materiality of cyber events. The module covers the SEC's guidelines, the FAIR-MAM (Factor Analysis of Information Risk - Materiality Assessment Methodology) framework, and practical use cases. Through expert insights, case studies, and interactive discussions, learners will develop the skills necessary to accurately determine the financial impact of cyber incidents and ensure compliance with SEC regulations.
Inclus
10 vidéos7 lectures5 devoirs1 évaluation par les pairs2 sujets de discussion
Afficher les informations sur le contenu du module
10 vidéos•Total 41 minutes
SEC Materiality Reporting•3 minutes
What is Materiality?•3 minutes
HowMaterialIsThatHack.org Overview•3 minutes
Cyber-Hack Disclosure•2 minutes
Introduction to FAIR-MAM•7 minutes
Forrester’s Analysis of FAIR-MAM•5 minutes
Safe Security Automates FAIR-MAM•5 minutes
The Uber Cyber Breach: CISO’s Personal Liability Story•6 minutes
FAIR-MAM Use Case Examples•4 minutes
FAIR-MAM Built for SEC Rulings•4 minutes
7 lectures•Total 200 minutes
U.S. SEC’s Statement for Reporting Materiality of a Cyber Incident•30 minutes
How Material is that Hack•10 minutes
Cyber-Hack Disclosure Reference Doc•10 minutes
FAIR-MAM Whitepaper•30 minutes
Are You Ready to Comply with the SEC “Material’ Cyber Risk Rules•30 minutes
CISOs and Personal Liability | How to Not Be Singled Out by the SEC (Optional)•30 minutes
(Optional) How to Achieve SEC Compliance with Real-time and Automated FAIR™ Solution•60 minutes
5 devoirs•Total 12 minutes
Graded Assessment - 3•4 minutes
Assessment of What is Materility•2 minutes
Assessment of Cyber-Hack Disclosure•2 minutes
Assessment of Forrester's Analysis of FAIR-MAM•2 minutes
Assessment of The Uber Cyber Breach: CISO’s Personal Liability StoryUntitled•2 minutes
Ajoutez ce titre à votre profil LinkedIn, à votre curriculum vitae ou à votre CV. Partagez-le sur les médias sociaux et dans votre évaluation des performances.
The FAIR Institute is a research-driven non-profit organization dedicated to advancing the discipline of cyber and operational risk management through education, standards, and collaboration.
Pour quelles raisons les étudiants sur Coursera nous choisissent-ils pour leur carrière ?
Felipe M.
Étudiant(e) depuis 2018
’Pouvoir suivre des cours à mon rythme à été une expérience extraordinaire. Je peux apprendre chaque fois que mon emploi du temps me le permet et en fonction de mon humeur.’
Jennifer J.
Étudiant(e) depuis 2020
’J'ai directement appliqué les concepts et les compétences que j'ai appris de mes cours à un nouveau projet passionnant au travail.’
Larry W.
Étudiant(e) depuis 2021
’Lorsque j'ai besoin de cours sur des sujets que mon université ne propose pas, Coursera est l'un des meilleurs endroits où se rendre.’
Chaitanya A.
’Apprendre, ce n'est pas seulement s'améliorer dans son travail : c'est bien plus que cela. Coursera me permet d'apprendre sans limites.’
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.