1. Information Protection Overview (for Executives)
Overview
The Information Protection Overview course focuses on key business and
legal issues driving global requirements for more effective Information
Protection and Network Security.
Information Protection Overview establishes the foundation for
the complete Information Protection Team Training Series with its
focus on People, Policy and Process. It forms the foundation for
further ACCTTS courses such as Understanding
Risk Factors.
Who Should Attend
- Executives, Directors & Senior Managers responsible for crafting
or maintaining Enterprise Information Protection Strategies & Policies.
- Any persons who must implement or monitor Information Assurance and
Privacy Policy Decisions.
Job Title examples include the following or direct reports of:
- Chief Executive Officer
- President
- Chief Compliance Director
- Chief Operating Officer
- Chief Knowledge Officer
- Chief Privacy Officer
- Chief Legal Officer
- Chief Financial Officer
- Chief Information Officer
- Executive Vice Presidents
- Vice Presidents
- Outside Counsel & Advisors
Courses in This Series
A11A: Quick
Intro to CyberCrime Fighting for All Stakeholders
Simple Computing Safeguards for Small Business and Home Computer Users
Concepts covered:
- Password protection practices
- Using strong (non-shared) authentication
- Making regular backups of critical data
- Using effective software protection from malware
malware
(MALicious WARE) Software designed to destroy, aggravate
and otherwise make life unhappy or frustrating.See virus, macro virus,
Word macro virus, Worms and Trojan horse
- Proper email procedures
- Secure home office connectivity policies
- Understanding firewalls and gateways
- Resources to help educate and protect
A11S: Information
Protection Overview (for Executives)
Overview
This orientation session is designed for non-technical executives and
professionals who need to understand the key business issues and compliance
laws driving their organizations information protection and network
security practices. At the end of the four-hour seminar, you will know
how to evaluate the effectiveness of your organizations information
security policies. Learn the right questions to ask your staff. Understand
the risks that cyber crimes and cyber terrorist attacks pose for your
organization. Find out what can be done to prevent attacks and to minimize
their impact. Sample corporate information security policies are also
included that you can take back to use in your organization.
The course uses real world examples to show how competitors or Cyber-criminals
may compromise data integrity or disrupt your networks availability
and reliability. It anchors our team training series with a focus on
People, Policy and Process.
Focus
- Participant workshops reinforce both risk assessment and mitigation
methods in a straight-forward common sense format with a take-home executive
risk assessment checklist and policy template.
- Overview and guidelines for preparing, responding to and following-up
after digital disruptions.
Who Should Attend
The audience for this course includes:
- CEOs
- CIOs
- Presidents
- Directors
- Compliance Officers
- Senior Managers
- Anyone responsible for crafting enterprise information protection
strategies & policies
Outcomes
What you will learn:
- Are we at risk?
- Who and what are the threats?
- How do we prepare for the inevitable?
- How do we determine if we have been attacked?
- How do we stop an attack in progress?
- What do we do?
- Who do we notify?
- How do we recover from an attack?
Outline
|
Section
|
Topic
|
|
1
|
Course Objectives & Overview / CBS "Cyber Thief"
Video (15 Min)
|
|
2
|
Cyber Crime:
A Most Unnatural Disaster |
|
3
|
An Ounce of Prevention - AVOID Being
Victimized! |
|
4
|
Breakout-1:
Assessing Risks
& Security Incident Response Team (SIRT) Preparation |
|
5
|
Prudent Protection Practices & Safeguards |
|
6
|
A Pound of Cure - Detection and Correcton
|
|
7
|
Breakout-2:
Responding to "Cyber Attack" - Digital Disruption Simulations
|
|
8
|
Forensics & Dr. Quincy, ME - Analyzing
Root Causes |
|
9
|
Q&A Review
with Overall Evaluation |
Length
1/2 Day
Materials
Workbook, Workshop Guide & Information Protection Policy Templates
A12A: Introduction
to CyberEthics for All Stakeholders
Overview
This half-day seminar introduces participants to CyberEthics, the ethical
possibilities and dangers in the developing IT world. This practical
course gives day-to-day network users basic knowledge and tools to engage
evolving ethical issues of appropriate network use, and appropriate
response to misuse. Participants will emerge motivated and equipped
to be careful and proactive.
Focus
The course shows how the smallest network action or event can have
wider consequences. Consequences can be positive or negative, and affect
not just for the person(s) involved, but for the whole organization.
Participants learn to identify these ethical situations, and leverage
their new knowledge for positive outcomes.
Who Should Attend
This course is designed for any routine users of Web/Internet-based
communications and business systems. It is particularly appropriate
for sales personnel, account managers and administrators, and PR staff.
Outcomes
Participants will:
- Gain a basic knowledge of ethical theory and processes.
- Better understand the implications and impact of cyber-based work.
- Gain first stage knowledge of ethics in a cyber environment.
- Feel equipped to recognize and evaluate emergent issues.
- Understand the need to be proactive and careful within the vision
and structure of their corporation.
- Learn practical rules and principles to apply in the cyber world
(based on the Brooking Institute's Ten Commandments for CyberEthics).
Method and Materials
The seminar employs a mix of exercises, case studies, and small group
work to provide, memorable, hands on, team based learning.
In order to encourage review and continuing education, course materials
include:
- A complete summary of the classwork
- Three self-administered exercises
- A short and straightforward bibliography and reference list.
A12S: Introduction
to CyberEthics for Senior Management
Overview
This two-hour seminar gives corporate leaders an overall understanding
of the evolving impact of CyberEthics, and the means to lead and make
sense of an increasingly fragmented medium.
Focus
The focus of this seminar is threefold
- Understanding the angers and possibilities inherent in global, unregulated
Cyber business
- Leading and managing with vision in an area where rules address
only yesterday's issues.
- Providing information and strategies for coherent, ethical and
proactive corporate response to emergent cyber issues.
Who Should Attend
- The course is most suited to those generating corporate vision and
policy, and the senior managers who implement it.
Method and Materials
- Presentations and discussion are reinforced by three exercises providing
common experience for participants to reflect upon, individually and
in small teams, during the seminar and later.
- Comprehensive written resources accompany the seminar.
Topics
- Ethics - a survey of principles and practice before the IT revolution.
- CyberEthics - principles and practice after the IT revolution.
- Compliance and reaction versus proactivity - the case for visionary
policy in a rapidly changing environment.
- The way forward: possible strategies and principles, defensive and
preemptive, to move more confidently into the CyberEthical world.
|