Course Outline
Foundations of Information Security in Public Institutions
- Core security principles and their importance in government organizations.
- Confidentiality, integrity, and availability in daily operations.
- Common threats affecting public sector information and digital services.
Governance, Policies, and Responsibilities
- Security governance within an institutional environment.
- Roles of managers, users, IT teams, service owners, and suppliers.
- Policies, standards, procedures, and accountability.
Risk Management for Information and Services
- Identifying assets, threats, vulnerabilities, and business impacts.
- Basic risk assessment and risk prioritization.
- Selecting practical treatments and controls.
Information Classification and Data Protection
- Classifying institutional information based on sensitivity and usage.
- Protecting documents, records, databases, and shared files.
- Best practices for storage, transfer, retention, and disposal.
Identity and Access Management
- Basics of user accounts, authentication, and authorization.
- Least privilege, separation of duties, and access reviews.
- Managing access requests, changes, and revocation.
Secure Use of Systems and Digital Services
- Secure use of email, web systems, remote access, and shared platforms.
- Common user errors and how to avoid them.
- Practical measures for safer daily operations.
IT Service Management Basics and Security Integration
- The relationship between IT services and information security.
- Security considerations in service design, delivery, and support.
- Service requests, incidents, changes, and basic service documentation.
Incident Handling and Service Continuity
- Recognizing security incidents and service disruptions.
- Reporting, escalation, containment, communication, and recovery steps.
- Backups, recovery planning, and maintaining availability during disruptions.
Security Awareness, Compliance, and Improvement
- Recognizing phishing, social engineering, and unsafe behavior.
- Aligning work with institutional policies, audit needs, and regulatory expectations.
- Monitoring controls and identifying practical improvement actions.
Practical Workshop and Action Planning
- Reviewing a public sector security and service management scenario.
- Identifying risks and proposing service and security improvements.
- Creating an action plan for participants' own areas of responsibility.
Requirements
- A basic understanding of IT concepts, office systems, and institutional information handling.
- Experience using information systems, email, shared files, and online services in daily work.
- No programming experience is required.
Audience
- Public sector employees involved in using, managing, or supervising digital information and services.
- IT staff, system administrators, and service management personnel working in government institutions.
- Managers, coordinators, auditors, and compliance personnel responsible for digital security and service quality.
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.
Jack - CFNOC- DND
Course - Micro Focus ArcSight ESM Advanced
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Risk optimization is more clear than the other subjects