Course Outline
Foundations of Information Security in Public Institutions
- Core security principles and their relevance in government organizations.
- Ensuring confidentiality, integrity, and availability in daily operations.
- Common threats affecting public sector information and digital services.
Governance, Policies, and Responsibilities
- Security governance within an institutional context.
- Roles of managers, users, IT teams, service owners, and suppliers.
- Policies, standards, procedures, and accountability.
Risk Management for Information and Services
- Identifying assets, threats, vulnerabilities, and business impacts.
- Fundamentals of risk assessment and prioritization.
- Selecting appropriate treatments and controls.
Information Classification and Data Protection
- Classifying institutional information based on sensitivity and usage.
- Protecting documents, records, databases, and shared files.
- Best practices for storage, transfer, retention, and disposal.
Identity and Access Management
- Fundamentals of user accounts, authentication, and authorization.
- Principles of least privilege, separation of duties, and access reviews.
- Managing access requests, modifications, and revocation.
Secure Use of Systems and Digital Services
- Secure usage of email, web systems, remote access, and shared platforms.
- Common user errors and strategies to avoid them.
- Practical measures for enhancing daily operational security.
IT Service Management Basics and Security Integration
- The relationship between IT services and information security.
- Security considerations in service design, delivery, and support.
- Service requests, incidents, changes, and basic service documentation.
Incident Handling and Service Continuity
- Recognizing security incidents and service disruptions.
- Steps for reporting, escalation, containment, communication, and recovery.
- Backups, recovery planning, and maintaining availability during disruptions.
Security Awareness, Compliance, and Improvement
- Recognizing phishing, social engineering, and unsafe behavior.
- Monitoring controls and identifying practical improvement actions.
Practical Workshop and Action Planning
- Reviewing a public sector security and service management scenario.
- Identifying risks and proposing service and security improvements.
- Creating an action plan for participants' own areas of responsibility.
Requirements
- Foundational knowledge of IT concepts, office systems, and institutional information handling.
- Experience utilizing information systems, email, shared files, and online services in daily tasks.
- No programming experience is necessary.
Audience
- Public sector employees who use, manage, or oversee digital information and services.
- IT staff, system administrators, and service management professionals in government agencies.
- Managers, coordinators, auditors, and compliance officers responsible for digital security and service quality.
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication
Bader Bin rubayan - Lean Business Services
Course - ISO/IEC 27001 Lead Implementer
Risk optimization is more clear than the other subjects