Course Outline
Foundations of Information Security in Public Institutions
- Core security principles and their relevance to government organisations.
- Confidentiality, integrity, and availability in daily operations.
- Common threats affecting public sector information and digital services.
Governance, Policies, and Responsibilities
- Security governance within an institutional context.
- Roles of managers, users, IT teams, service owners, and suppliers.
- Policies, standards, procedures, and accountability.
Risk Management for Information and Services
- Identifying assets, threats, vulnerabilities, and business impacts.
- Conducting basic risk assessments and prioritising risks.
- Selecting appropriate treatments and controls.
Information Classification and Data Protection
- Classifying institutional information based on sensitivity and usage.
- Protecting documents, records, databases, and shared files.
- Best practices for storage, transfer, retention, and disposal.
Identity and Access Management
- Fundamentals of user accounts, authentication, and authorisation.
- Principles of least privilege, separation of duties, and access reviews.
- Managing access requests, changes, and revocation.
Secure Use of Systems and Digital Services
- Secure utilisation of email, web systems, remote access, and shared platforms.
- Common user errors and strategies to avoid them.
- Practical measures for safer daily operations.
IT Service Management Basics and Security Integration
- The relationship between IT services and information security.
- Security considerations in service design, delivery, and support.
- Managing service requests, incidents, changes, and basic service documentation.
Incident Handling and Service Continuity
- Recognising security incidents and service disruptions.
- Procedures for reporting, escalation, containment, communication, and recovery.
- Backup strategies, recovery planning, and maintaining availability during disruptions.
Security Awareness, Compliance, and Improvement
- Identifying phishing, social engineering, and unsafe behaviour.
- Adhering to institutional policies, audit requirements, and regulatory expectations.
- Monitoring controls and identifying practical improvement actions.
Practical Workshop and Action Planning
- Reviewing a public sector security and service management scenario.
- Identifying risks and proposing service and security improvements.
- Developing an action plan for participants' own areas of responsibility.
Requirements
- A foundational understanding of IT concepts, office systems, and the handling of institutional information.
- Experience using information systems, email, shared files, and online services in daily operations.
- No programming experience is necessary.
Target Audience
- Public sector staff involved in using, managing, or supervising digital information and services.
- IT personnel, system administrators, and service management professionals in government institutions.
- Managers, coordinators, auditors, and compliance officers responsible for digital security and service quality.
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Risk optimization is more clear than the other subjects