COURSE · CY4

Cyber-Security Governance, Risk & Compliance

ממשל אבטחת סייבר, סיכון וציות

structured risk, control frameworks, auditable evidence, and incident governance

Managing cyber-security through risk, frameworks, audit, and response.

Year 313 weeks2h lecture + 2h practiceProject-based

About this course

Manage cyber-security as an organizational discipline through risk assessment, security policy, compliance frameworks, and incident response.

Course format. Thirteen weeks, four contact hours each: a two-hour lecture (concepts and theory) and a two-hour practice session. The course is project-based; teams carry one running project end to end and present it three times, in weeks 5, 8, and 13.
What you will build

Authored a complete security governance program for a case-study organization, producing a prioritized SP 800-30 risk register, a CSF 2.0 profile, an ISO/IEC 27001 ISMS with statement of applicability, tailored SP 800-53 controls, an auditable policy suite, a mock internal audit, and a tabletop-validated incident response plan.

Expected outcomes

  • Conduct qualitative and quantitative risk assessments producing a heat-mapped risk register with Crown Jewels asset classification, inherent and residual risk scores, and risk appetite statements traceable to business impact analysis (RTO, RPO, MTTR).
  • Map organizational controls to NIST CSF 2.0 (Identify, Protect, Detect, Respond, Recover, Govern) and ISO/IEC 27001 Annex A, producing a Statement of Applicability with audit evidence for each selected control.
  • Configure and interpret Cloud Security Posture Management tools to detect misconfigurations, enforce CIS control benchmarks, identify toxic-combination risks, and prioritize findings by exploitability and business impact.
  • Design a SIEM threat detection pipeline with cloud API audit log collection, behavioral anomaly detection, cross-account log aggregation, correlation rules, alert tuning, and playbook-driven triage workflows.
  • Conduct a mock ISO 27001 internal audit with evidence collection, control testing, and findings classified as Observation, Nonconformity, or Major Nonconformity, with corrective action plans linked to the risk register.
  • Produce board-level security posture reports with MTTD, patch cadence, and phishing click-rate KPIs, and build a cross-framework regulatory compliance matrix covering GDPR Article 32, HIPAA Security Rule safeguards, and PCI-DSS requirements 1-12.

Key topics

  • Risk assessment
  • Standards (ISO 27001, NIST)
  • Policy & audit
  • Incident response

Theoretical foundations

The concepts and results this course rests on.

  • information asset classification: Crown Jewels analysis, sensitivity labels, and CMDB integration as the inventory foundation for risk
  • risk assessment methodology: threat likelihood, business impact, inherent vs residual risk, and risk appetite statements
  • NIST CSF 2.0: Identify, Protect, Detect, Respond, Recover, and Govern functions and their mapping to organizational security outcomes
  • ISO/IEC 27001 ISMS: scope definition, Statement of Applicability, Annex A control selection, and audit evidence requirements
  • Cloud Security Posture Management: automated misconfiguration scanning, CIS control policy enforcement, toxic-combination detection, and exploitability-weighted findings prioritization
  • business impact analysis and recovery objectives: RTO, RPO, MTTR, MTO, and tiered criticality classification
  • SIEM and threat detection pipeline: cloud API audit log collection, behavioral anomaly detection, cross-account aggregation, correlation rules, log normalization, alert tuning, and playbook-driven triage
  • security audit methodology: audit universe, evidence collection, test of controls, and findings classification (Obs/NC/Major NC)
  • regulatory compliance mapping: GDPR Article 32, HIPAA Security Rule safeguards, PCI-DSS requirements 1-12, and cross-framework harmonization
  • security metrics and KPI reporting: mean time to detect, patch cadence, phishing click rate, and board-level risk dashboards

Prerequisites

This is a Year-3 course. It assumes the mandatory CS core: data structures and algorithms, operating systems, computer networks, databases, software engineering, and the core mathematics (linear algebra, probability and statistics, calculus, discrete mathematics). It additionally requires the specific prior courses listed below.

Course-specific prerequisites:

  • Software engineering
  • Basic information-security concepts

Weekly schedule 13 weeks · lecture + practice

Foundations
Wk 1
Asset classification and Crown Jewels analysis
LectureDefine GRC, governance accountability, and information asset classification: Crown Jewels analysis, sensitivity labels, and CMDB integration (P1).
PracticeUse NIST SP 800-30 risk templates to build an asset inventory and sensitivity register for the fictitious organization.
ProjectSelect the organization and produce its context, scope, and Crown Jewels asset register.
Risk
Wk 2
Risk assessment methodology
LectureCover threat likelihood, business impact, inherent vs residual risk, risk appetite statements, and qualitative vs quantitative risk methods (P2).
PracticeUse the CVSS calculator to score identified vulnerabilities; run OpenVAS/GVM for automated asset scanning and initial exposure discovery.
ProjectAdd a threat-and-vulnerability list with CVSS scores to the project.
Wk 3
Risk register and heat-map prioritization
LecturePresent the SP 800-30 risk assessment process, risk-rating matrices, and heat-map visualization of residual risk against appetite (P2).
PracticeUse Qualys Community Edition for vulnerability discovery; build the heat-mapped risk register with NIST SP 800-30 templates.
ProjectAdd a complete prioritized risk register with inherent and residual risk scores to the project.
Frameworks
Wk 4
NIST CSF 2.0 and threat-informed control mapping
LectureExplain NIST CSF 2.0 functions (Identify, Protect, Detect, Respond, Recover, Govern) and RMF lifecycle stages (P3).
PracticeUse ATT&CK Navigator to map detected threat techniques to CSF 2.0 outcomes and identify control coverage gaps.
ProjectAdd a CSF 2.0 current-state profile with coverage gap analysis to the project.
Wk 5
Program specification and risk assessmentPresentation
LectureDiscuss how risk results drive the security program; introduce ISO 27001 ISMS structure and BIA concepts including RTO, RPO, and tiered criticality (P4, P6).
PracticeTeam presentation: each team defends its risk register, CSF 2.0 profile, and proposed security program scope.
ProjectFreeze the security program specification and risk assessment.
Management systems
Wk 6
ISO/IEC 27001 ISMS and Statement of Applicability
LecturePresent the ISO/IEC 27001 management-system model, PDCA cycle, Statement of Applicability, and Annex A control selection with audit evidence requirements (P4).
PracticeDraft the SoA using an ISO 27001 control checklist; run OpenSCAP with a CIS benchmark profile for automated compliance scanning.
ProjectAdd the ISMS scope and Statement of Applicability to the project.
Cloud posture
Wk 7
Cloud Security Posture Management
LectureExplain CSPM: automated misconfiguration scanning, CIS control policy enforcement, toxic-combination detection, and findings prioritization by exploitability and business impact (P5).
PracticeUse Wiz for CSPM toxic-combination scanning and AWS GuardDuty for cloud API anomaly detection; review and prioritize a findings report.
ProjectAdd a CSPM findings report with prioritized remediations to the project.
Wk 8
Controls, ISMS, and CSPM reviewPresentation
LectureCover BIA recovery objectives: RTO, RPO, MTTR, MTO, and tiered criticality classification for control prioritization (P6).
PracticeTeam presentation: interim review of ISMS, SoA, control mappings, and CSPM findings.
ProjectPresent the interim program with control suite, SoA, and CSPM posture.
Threat detection
Wk 9
SIEM and threat detection pipeline
LectureExplain cloud API audit log collection, behavioral anomaly detection, cross-account log aggregation, SIEM correlation rules, log normalization, alert tuning, and playbook-driven triage workflows (P7).
PracticeIntegrate MISP threat intelligence feeds; configure AWS GuardDuty correlation rules and alert thresholds; draft a playbook-driven triage workflow.
ProjectAdd a SIEM detection pipeline design with correlation rules and triage playbook to the program.
Audit
Wk 10
Security audit methodology
LectureCover audit universe, evidence collection, test of controls, sampling, and findings classification as Observation, Nonconformity, or Major Nonconformity (P8).
PracticeConduct a mock ISO 27001 internal audit using the ISO 27001 control checklist; run OpenSCAP for evidence-backed control testing.
ProjectAdd a mock internal audit report with classified findings to the project.
Wk 11
Corrective actions and remediation tracking
LectureExplain corrective action plans, risk acceptance, residual risk re-scoring, and continuous monitoring (P8 continued).
PracticeRun OpenVAS/GVM for remediation verification scanning; update the risk register with post-remediation residual scores using NIST SP 800-30 templates.
ProjectAdd a corrective-action plan with updated residual risk scores to the program.
Compliance and KPIs
Wk 12
Regulatory compliance mapping and security KPIs
LecturePresent GDPR Article 32, HIPAA Security Rule safeguards, PCI-DSS requirements 1-12, and cross-framework harmonization (P9); and MTTD, patch cadence, phishing click rate, and board dashboards (P10).
PracticeUse ATT&CK Navigator for regulatory-to-threat mapping; enrich the KPI dashboard with MISP threat intelligence context.
ProjectAdd a regulatory compliance matrix and board-ready security posture report with KPIs.
Capstone
Wk 13
Final GRC program and defensePresentation
LectureReview the complete GRC program: how risk register, CSF profile, SoA, audit evidence, and KPI dashboard trace end-to-end from Crown Jewels through remediation.
PracticeTeam presentation: final program delivery with oral defense to a simulated steering committee.
ProjectDeliver the complete GRC program: heat-mapped risk register, CSF 2.0 profile, ISO 27001 SoA, audit report, regulatory matrix, and board posture report.
AI tools in this course.

Students use AI assistants as GRC drafting partners: generating first-draft policies, procedures, and statements of applicability, mapping assessed risks to SP 800-53 controls and CSF 2.0 outcomes, and summarizing long standards such as ISO/IEC 27001 and SP 800-30 into working checklists. They prompt the assistant to expand a risk register, to phrase controls so they are auditable, and to produce tabletop incident scenarios and interview questions for the mock audit. AI also helps reconcile evidence against control requirements and turn raw findings into executive-ready risk narratives, but students verify every citation, control mapping, and obligation against the authoritative source, since an AI that invents a control reference or misstates a regulatory duty would make the program fail an audit.

Student project

Teams conduct a complete GRC engagement on a fictitious mid-size company: perform a risk assessment producing a heat-mapped risk register, map controls to NIST CSF 2.0 and ISO 27001 Annex A, conduct a mock ISO 27001 internal audit with evidence collection, and produce a board-ready security posture report with a prioritized remediation roadmap.

Requirements

  • Build a working system, not a set of disconnected exercises.
  • Be original: a new system that solves a real problem, not a re-implementation of a tutorial or course demo.
  • Show real depth: real data, real users or realistic load, and engineering trade-offs that are measured rather than assumed.
  • Carry one running project from specification to a deployed, defensible result across the whole term.
  • Work in a team of three or four and defend the design at each of the three presentations (weeks 5, 8, and 13).

Example projects

Hospital ISMS programFintech risk-and-control frameworkSaaS startup compliance roadmapManufacturer ISO 27001 readinessUniversity incident response planCloud provider control mappingRetailer audit-and-remediation programPublic-sector GRC blueprint

Assessment & grading

Grading is project-based, with no written exam. Teams of three or four present one running project three times.

ComponentWhat it coversWeight
Project · SpecificationPresentation 1 (week 5): problem, objectives, and architecture20%
Project · InterimPresentation 2 (week 8): the working system demonstrated live30%
Project · FinalPresentation 3 (week 13): end-to-end demo with oral defense50%

Tools & platforms

  • Eramba: GRC and risk-management platform
  • OpenSCAP: automated control compliance scanning
  • Wazuh: continuous monitoring and audit evidence
  • NIST CPRT: control and framework reference toolkit
  • MITRE ATT&CK Navigator: threat-informed control mapping
  • FAIR-U: quantitative risk-analysis training tool
  • draw.io: architecture and data-flow diagramming
  • Git: version control for policies and evidence
  • GRC spreadsheet templates: risk registers and SoA tracking
  • TheHive: incident case management and response

Free online courses

Existing free, video-based courses this course can build on, for self-study or as a teaching basis.

Primary literature

Seminal works for advanced study.

References

Books and resources link to an online or publisher page.

Role in each concentration

ConcentrationRole
Intelligent Software SystemsElective
Networking & Cyber SecurityCore · Semester 2
AI & RoboticsElective
AI and Quantum Computing for FinanceCore · Semester 1
Immersive Systems & Game DevelopmentElective
Defense Technologies & Autonomous SystemsElective