Enterprise Information Security and Risk Management (ESS)

Academic Year
Class No.
Description
Section
Start Date
End Date
Location/Format
AY07-08
1104
ESS
07
9/15/2008
12/1/2008
Distributed Learning
AY07-08
1105
ESS
08
9/22/2008
9/26/2008
Fort McNair, DC / e-Resident
AY08-09
1163
ESS
01
11/17/2008
11/21/2008
Fort McNair, DC / e-Resident
AY08-09
1164
ESS
02
1/12/2009
4/3/2009
Distributed Learning
AY08-09
1165
ESS
03
1/26/2009
1/30/2009
Fort McNair, DC / e-Resident
AY08-09
1166
ESS
04
5/4/2009
5/8/2009
Fort McNair, DC / e-Resident
AY08-09
1167
ESS
05
5/4/2009
7/24/2009
Distributed Learning
AY08-09
1168
ESS
06
7/20/2009
7/24/2009
Fort McNair, DC / e-Resident
AY08-09
1169
ESS
07
9/14/2009
9/18/2009
Fort McNair, DC / e-Resident
AY08-09
1170
ESS
08
9/21/2009
12/11/2009
Distributed Learning

Course Description:
This course examines the practical challenges of assessing and managing information security risks when developing an enterprise information security program.  Based upon OMB, NIST, and DOD risk management guidance, the course addresses the key components of an organization’s information security program including the identification, assessment, mitigation, and acceptance of risk.  The course builds upon fundamental information assurance concepts and information security technology, integrating them into scalable, practical working solutions for defending the enterprise.  Security program components, including configuration, incident, system lifecycle, and acquisition are examined from a risk management perspective.  Other topics include program and system security planning, risk assessment, policy, control/countermeasure selection, and continuous performance measurement and monitoring.

Recommended Attendance:
This course is appropriate for managers and practitioners who require a practical perspective on the management of an enterprise information assurance program. 

Prerequisites
None; however, students should take this course as the last course in the NSTISSI No. 4011 Certificate.

Learning Outcomes
Students will be able to recommend an information security program strategy and structure based upon their assessment and management of risks.