SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals

Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact UsAs the practice of IT security matures, the capabilities of security practitioners must improve in the area of risk management to keep pace with the growth of the security issues in IT industry. In particular, US Federal guidance in the form of National Institute of Standards and Technology (NIST) special publications, provide only introductory coverage of risk management methods. The Software Engineering Institute's Continuous Risk Management (CRM) process, a cyclic risk management paradigm, is tailored to the domain of IT security to produce an enterprise risk management methodology suitable for Federal government organizations. This process builds upon the basics of the NIST guidance and adds the possibility of managing risks from diverse systems, providing the high-level perspective of security risks that is currently lacking. The resulting management-level processes are scalable from a small organization to a nationwide enterprise, providing a foundational practice for IT security planning. An enterprise risk management workflow model is presented to illustrate the 'big picture' of risk management, the key to developing a 'keen eye' for IT security risks as a part of the overall IT management doctrine.