Course Outline
Foundations of Information Security in Public Institutions
- Core security principles and their importance in government organizations.
- The role of confidentiality, integrity, and availability in daily operations.
- Common threats targeting public sector information and digital services.
Governance, Policies, and Responsibilities
- Security governance within an institutional setting.
- The roles of managers, users, IT teams, service owners, and suppliers.
- Policies, standards, procedures, and accountability mechanisms.
Risk Management for Information and Services
- Identifying assets, threats, vulnerabilities, and business impacts.
- Conducting basic risk assessments and prioritizing risks.
- Selecting appropriate treatments and controls.
Information Classification and Data Protection
- Classifying institutional information based on sensitivity and usage.
- Protecting documents, records, databases, and shared files.
- Best practices for storage, transfer, retention, and disposal.
Identity and Access Management
- Fundamentals of user accounts, authentication, and authorization.
- Implementing least privilege, separation of duties, and access reviews.
- Managing access requests, changes, and revocation.
Secure Use of Systems and Digital Services
- Secure usage of email, web systems, remote access, and shared platforms.
- Common user errors and strategies to avoid them.
- Practical measures for safer daily operations.
IT Service Management Basics and Security Integration
- The relationship between IT services and information security.
- Security considerations in service design, delivery, and support.
- Service requests, incidents, changes, and basic service documentation.
Incident Handling and Service Continuity
- Recognizing security incidents and service disruptions.
- Steps for reporting, escalation, containment, communication, and recovery.
- Backups, recovery planning, and maintaining availability during disruptions.
Security Awareness, Compliance, and Improvement
- Identifying phishing, social engineering, and unsafe behavior.
- Aligning work with institutional policies, audit requirements, and regulatory expectations.
- Monitoring controls and identifying practical improvement actions.
Practical Workshop and Action Planning
- Reviewing a public sector security and service management scenario.
- Identifying risks and proposing improvements for services and security.
- Developing an action plan tailored to participants' areas of responsibility.
Requirements
- A foundational understanding of IT concepts, office systems, and institutional information handling.
- Experience using information systems, email, shared files, and online services in daily work activities.
- No programming experience is necessary.
Audience
- Public sector staff involved in using, managing, or overseeing digital information and services.
- IT personnel, system administrators, and service management professionals within government institutions.
- Managers, coordinators, auditors, and compliance officers responsible for digital security and service quality.
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication