Course Description
Losses occur when a threat exposes a vulnerability that could harm an asset. Companies use IT risk management frameworks to strategize and differentiate severe and minor risks. Risk is the likelihood or probability that something unexpected is going to occur. This unexpected result could be either a gain or a loss. In the world of information security, most organizations focus on ways to guard against asset losses.
In this Cybersecurity Basics: Defining Security Metrics course, you will learn how to use IT risk management frameworks to assess organizational threats. You will also learn how to assess organizational performance to improve future risk management results.
What You'll Learn
- Understand how IT risk management frameworks are used to assess organizational threats
- Identify the importance of the NIST risk management framework
- Distinguish between compliance and risk management
- Perform a risk assessment and work through its stages
- Evaluate loss and assess risk acceptability
- Select control strategies including transference, mitigation, acceptance, and termination
Key Takeaways
- Losses occur when a threat exposes a vulnerability that could harm an asset.
- Companies use IT risk management frameworks to strategize and differentiate severe and minor risks.
- Risk is the likelihood or probability that something unexpected will occur, and that result could be either a gain or a loss.
- In information security, most organizations focus on ways to guard against asset losses.
- Control strategies for managing risk include transference, mitigation, acceptance, and termination.
Frequently Asked Questions
What will I learn in this course?
You will learn how to use IT risk management frameworks to assess organizational threats and how to assess organizational performance to improve future risk management results.
Does this course cover the NIST risk management framework?
Yes. The learning objectives include identifying the importance of the NIST risk management framework.
What topics are covered in the lessons?
Lessons cover IT risk management frameworks, compliance versus risk management, performing a risk assessment and its stages, evaluating loss, assessing risk acceptability, and selecting control strategies such as transference, mitigation, acceptance, and termination.
What skills does this course help build?
It supports skills in cyber security assessment, cyber security management, information security management, IT risk management, threat assessment, and threat management.
Is this course suitable for beginners in cybersecurity?
It is part of the Cybersecurity Basics series, covering foundational topics on defining security metrics and risk management.









