2Security management
- 2.1Information Asset Management and Risk Assessment
Learn how to identify and classify information assets, the risk assessment procedure (risk identification, risk analysis, risk evaluation), how to choose among the risk treatment options (risk reduction, risk avoidance, risk transfer, risk acceptance), the difference between quantitative and qualitative risk analysis, and the residual risk that remains after treatment.
- 2.2ISMS and Information Security Policy
Learn about the ISMS (information security management system), the international standard ISO/IEC 27001, the operating cycle PDCA, the three-tier structure of information security policy, standards, and procedures, the Statement of Applicability (SoA) prepared for certification, and the meaning of ISMS certification.
- 2.3Types of Controls and the Security Organization
Learn the four categories of controls (technical, physical, human/personnel, and organizational controls), separation of duties and the principle of least privilege, organizational structures such as the CISO (Chief Information Security Officer) and a security committee, and the role of education and training.
- 2.4Incident Management and CSIRT
Learn the incident response process (detection/reporting -> triage -> containment -> eradication -> recovery -> post-incident activity), the difference in roles between CSIRT and SOC, internal reporting and escalation, evidence preservation and digital forensics, and the roles of the external organizations JPCERT/CC and JVN.
- 2.5Business Continuity Management
Learn the difference between BCP (business continuity plan) and BCM (business continuity management), the meaning and calculation of RTO (recovery time objective) and RPO (recovery point objective), disaster countermeasures (alternate sites, redundancy), and backup strategy (full, differential, and incremental backup, and the 3-2-1 rule).

