Introducing Security: Aligning Asset and Risk Management (Coursera)

Offered by (ISC)²,
Introducing Security: Aligning Asset and Risk Management (Coursera)

Course 1 - Introducing Security and Aligning Asset Management to Risk Management. In this course, we're going to start by discussing the security concepts, identifying corporate assets, and discussing the risk management process.

Class Deals by MOOC List - Click here and see Coursera's Active Discounts, Deals, and Promo Codes.

Course 1 Learning Objectives
After completing this course, the participant will be able to: 
L1.1 - Classify information security and security concepts.  
L1.2 - Summarize components of the asset management lifecycle. 
L1.3 - Identify common risks and vulnerabilities. 
L1.4 - Provide examples of appropriate risk treatment. 

Course Agenda
Module 1: Understand Security Concepts (Domain 1 - Security Operations and Administration)
Module 2: Participate in Asset Management (Domain 1 - Security Operations and Administration)
Module 3: Understand the Risk Management Process (Domain 3 - Risk Identification, Monitoring and Analysis)
Module 4: Understand the Risk Treatment Process (Domain 3 - Risk Identification, Monitoring and Analysis)

Who Should Take This Course: Beginners
Experience Required: No prior experience required

Course 1 of 8 in the (ISC)² Systems Security Certified Practitioner (SSCP)

Syllabus

WEEK 1
Module 1: Understand Security
One of the first questions we should ask is, what is information security? Information security can have completely different meanings for different people. 
Module 2: Participate in Asset Management
Asset management deals with the protection of valuable assets to the organization as those assets progress through their lifecycle. Therefore, we need to address the security of assets all through the stages of their lifecycle including creation/collection, identification and classification, protection, storage, usage, maintenance, disposal, retention/archiving and defensible destruction of assets. To properly protect valuable assets, such as information, an organization requires the careful and proper implementation of ownership and classification processes, which can ensure that assets receive the level of protection based on their value to the organization. 
The enormous increase in the collection of personal information by organizations has resulted in a corresponding increase in the importance of privacy considerations. As a result, privacy protection constitutes an important part of asset security.  Appropriate security controls must be chosen to protect the asset as it progresses through its lifecycle, bearing in mind the requirements of each phase and the handling requirements throughout.

WEEK 2
Module 3: Understand the Risk Management Process
In this module we begin to look at the risk management process. Risk management is a critical component of an information security program since it drives the selection of controls used to mitigate business and IT risk. The risk management program manages risk, but it does not eliminate it. All activities have an element of risk associated with them (even doing nothing is risky business), so risk management must be an essential part of every organization’s management and operational plans. 
In the IT department, we tend to see risk from a negative viewpoint; it represents the problems and inconvenience associated with IT systems failure. We see risk as what happens when something goes wrong, and we are under pressure to fix the problem as quickly as possible. However, in the rest of the business, risk is seen as opportunity — the chance to take a risk and make a return on investment — and the larger the risk, the greater the possible reward (or loss).  First, a definition of risk is a measure of the extent to which an entity is threatened by a potential circumstance or event. It is often expressed as a combination of (1) the adverse impacts that would arise if the circumstance or event occurs, and (2) the likelihood of occurrence.   Note that information system-related security risks are those risks that arise from the loss or compromise of any of the information security attributes (CIANA+PS) required of information or information systems. It reflects the potential adverse impacts to organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, other organizations, and the nation.  We see from this definition (which is, first of all, IT based) that risk is associated with threats, impact, and likelihood. But this definition also states that IT risk is a subset of business risk and must be measured by the impact of the risk event on organizational operations, assets, and other third parties.
Module 4: Understand the Risk Treatment Process
The next step after gaining an understanding of the context for the risk management effort (through the Risk Frame process) is to perform the risk assessment. Risk assessment is the process of identifying risk and then evaluating and prioritizing risk based on the level of importance (severity) of the risk. The final deliverable from the risk assessment process is to communicate risk to management often through a Risk Assessment Report (RAR) and by updating the risk register.

WEEK 3
Module 5: Chapter 1 Review
Chapter 1 has shown us how information security exists to support the organization in achieving its goals and priorities by protecting its vital information assets. In doing so, the information security team starts with some very fundamental ideas about information security and applies these to understand the potential risks to those assets. We’ve looked at the most important attributes or characteristics of information security, which the mnemonic CIANA+PS represents: confidentiality, integrity, availability, non-repudiation, authenticity, privacy, and safety. These are the touchstones, the criteria, by which we as information security specialists must measure our successes and our failures. 
Managing information risk is a primary part of the information security job. Chapter 1 has begun the process of showing us how to manage these risks, within the framework and context of how the organization manages its information assets. Subsequent chapters and their activities will continue to examine these ideas and concepts.  Last, but certainly not least, chapter 1 reminds us that we are members of the professional cadre of information security specialists. Businesses and governments, as well as individuals and organizations, must be able to trust that their day-to-day activities are using reliable, trustworthy information as their fuel. The ethical duties of due care and due diligence, which we examined in this chapter, provide each of us with the guideposts needed as we put our skills and knowledge to work.  In chapter 2, we examine the actions needed to develop a security culture within the organization. We will delve into using policies to enforce security requirements and how we can safeguard our information systems and ensure their use only by authorized users.

Go to Class
MOOC List is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Related Courses

Cybersecurity for Everyone (Coursera) Coursera
University of Maryland, College Park

Cybersecurity for Everyone (Coursera)

Cybersecurity affects everyone, including in the delivery of basic products and services. If you or your organization want to better understand how to address your cybersecurity, this is the course for you and your colleagues to take -- from seasoned professionals to your non-technical colleagues. Your instructor, Dr. Charles Harry, has served on the front lines with the NSA (National Security Agency) and as an expert advising corporate and institutional leaders on managing cybersecurity risk.

Sep 21st 2026
5-12 Weeks
Investment Management in an Evolving and Volatile World by HEC Paris and AXA Investment Managers (Coursera) Coursera
HEC Paris

Investment Management in an Evolving and Volatile World by HEC Paris and AXA Investment Managers (Coursera)

Have you ever wanted to invest in financial markets, but were always afraid that you didn’t have the proper tools or knowledge to make informed decisions? Have you ever wondered how investment management companies operate and what fund managers do? AXA Investment Managers, in partnership with HEC Paris, will introduce you to the most important ideas and concepts in investment management, to help you better understand your financial future.

Sep 14th 2026
4 Weeks
Cloud Computing Fundamentals on Alibaba Cloud (Coursera) Coursera
Alibaba Cloud Academy

Cloud Computing Fundamentals on Alibaba Cloud (Coursera)

Looking to dive into the world of Alibaba Cloud with a comprehensive introduction to the range of products and solutions offered by Alibaba Cloud? Fundamental Architecting on Alibaba Cloud is a course designed for users looking to start this journey with a look into Alibaba Cloud's core products. Fundamental Architecting looks into storage, networking, auto-scaling, and security solutions as well as scenarios to best combine these products to create a complete cloud-based architecture.

Sep 14th 2026
5-12 Weeks
Financial Forecasting and Reporting (Coursera) Coursera
University of Colorado Boulder

Financial Forecasting and Reporting (Coursera)

This course discusses how public projects are evaluated using cost-benefit analysis. Learners discover how interest rates and prices for stocks and bonds are determined. Techniques are presented on how to create departmental budgets for engineering cost centers and pro forma statements for profit centers. Learners then work with corporate financial statements to assess a company’s financial health, including recent measures of environmental, social, and corporate governance (ESG).

Sep 14th 2026
4 Weeks
Introduction to Applied Cryptography (Coursera) Coursera
University of London

Introduction to Applied Cryptography (Coursera)

This course is a non-mathematical introduction to the role that cryptography plays in providing digital security for everyday applications such as the internet, mobile phones, wireless networks and cryptocurrency. In this introductory course you will develop an understanding of the functionality and purpose of the main cryptographic tools we use today. You will learn how to make decisions about which cryptographic tools are most appropriate to deploy in specific settings. You will also explore the wider infrastructure surrounding cryptography and how this impacts the overall security of systems deploying cryptography.

Sep 14th 2026
4 Weeks
Tencent Cloud Solutions Architect Associate (Coursera) Coursera
Tencent Cloud

Tencent Cloud Solutions Architect Associate (Coursera)

This course is primarily aimed at cloud professionals that are interested in learning about Tencent Cloud‘s cloud architectures. The course equips learners with a foundational knowledge in cloud architecture design and prepares them to take the Tencent Cloud Solutions Architect Associate examination. After completing this course, learners will be able to design cloud solutions that incorporate the principles of high availability, high security, high scalability, and cost optimization.

Sep 14th 2026
5-12 Weeks
Trust and Security with Google Cloud (Coursera) Coursera
Google Cloud

Trust and Security with Google Cloud (Coursera)

As organizations move their data and applications to the cloud, they must address new security challenges. The Trust and Security with Google Cloud course explores the basics of cloud security, the value of Google Cloud's multilayered approach to infrastructure security, and how Google earns and maintains customer trust in the cloud.

Sep 21st 2026
5-12 Weeks
IBM Data Privacy for Information Architecture (Coursera) Coursera
IBM

IBM Data Privacy for Information Architecture (Coursera)

Data privacy controls how information is collected, used, shared, and disposed of, in accordance with policies or external laws and regulations. In this course, students will gain an understanding of what data privacy is along with how to identify and understand typical data protection and privatization objectives that an enterprise may have, and how to choose a data protection approach.

Sep 14th 2026
5-12 Weeks