Lesson 1: Security Policies (Password, Access Control, BYOD, Email, etc.)
Security policies are written rules that guide how employees, IT teams, and systems must behave to maintain security.
A company with weak or no policies = easy target.
1. Password Policy
Defines:
Purpose:
2. Access Control Policy
Defines how users are given access:
Purpose:
3. Acceptable Use Policy (AUP)
Defines how employees use:
Includes:
No downloading pirated software
No installing unknown apps
No connecting unauthorized USB drives
4. BYOD (Bring Your Own Device) Policy
If employees use personal devices for work:
Purpose:
5. Email & Communication Policy
6. Remote Work Policy
Covers:
Lesson 2: Risk Management
Risk management identifies, analyzes, and reduces risks to acceptable levels.
1. Key Terms
Threat
Anything that can cause harm
(e.g., hacker, malware, natural disaster)
Vulnerability
Weakness that could be exploited
(e.g., unpatched system)
Risk
Risk = Threat × Vulnerability × Impact
2. Risk Assessment Steps
Impact types:
High → Medium → Low
(using risk scoring)
Controls:
3. Risk Treatment Options
Lesson 3: Business Continuity & Disaster Recovery (BC/DR)
BC/DR ensures the organization continues running even during:
1. Business Continuity Plan (BCP)
A BCP focuses on keeping the business running during disruption.
Includes:
2. Disaster Recovery Plan (DRP)
A DRP focuses on restoring systems after a disaster.
Covers:
3. Key Metrics in BC/DR
RTO (Recovery Time Objective)
How long systems can be down before it becomes critical.
Example:
Bank website RTO = minutes
HR system RTO = 4 hours
RPO (Recovery Point Objective)
How much data loss is acceptable.
Example:
Database RPO = 5 minutes
Email RPO = 1 hour
4. Types of Backups
5. High Availability (HA)
Techniques to reduce downtime:
Lesson 4: Compliance Standards (ISO 27001, GDPR, PCI-DSS, etc.)
Compliance ensures organizations meet legal and industry security requirements.
1. ISO 27001 — Information Security Management System (ISMS)
Most recognized global security standard.
Organizations must implement:
Used by:
2. GDPR — General Data Protection Regulation
Protects personal data of EU citizens.
Key principles:
Non-compliance = heavy fines.
3. PCI-DSS — Payment Card Industry Data Security Standard
Applies to organizations dealing with:
Requirements:
Used by:
4. HIPAA (Health sector)
Applies to healthcare systems.
Focus:
5. Ethiopian Data Protection Practices
Although Ethiopia does not yet have a GDPR-level law, organizations follow:
Lesson 5: Incident Documentation & Reporting
Incident response means documenting and responding to security incidents.
1. What is a Security Incident?
Examples:
2. Incident Response Steps
Detect incident via:
Short-term:
Long-term:
Remove malware or malicious access.
Restore:
Ensure normal operations.
Document:
Use findings to improve:
3. Incident Reporting
Reports include:
Useful for audits and compliance.
Module 8 Summary
Students now understand:
This module answers the question:
“How do organizations build long-term, policy-driven, compliant security?”