Cybersecurity and Compliance Curriculum

11 chapters

Chapters

  1. Lab 2: Running a SCAP Scan
    Cybersecurity and Compliance Curriculum · 5:01
    A hands-on walkthrough of running SCAP security scans using OpenSCAP on Linux virtual machines, teaching listeners how to identify vulnerabilities and apply security benchmarks using the SCAP Security Guide.
  2. Acceptance Is Not Ignorance
    Cybersecurity and Compliance Curriculum · 3:24
    Acceptance Is Not Ignorance dives into one of the most misunderstood concepts in risk management — the deliberate, documented decision to accept a known risk rather than ignore it. Listeners will learn how true risk acceptance requires careful analysis, accountability, and ongoing awareness, not passive neglect.
  3. 1 COSO 2013 Internal Control
    Cybersecurity and Compliance Curriculum · 4:44
    Dive into the COSO 2013 Internal Control framework and its three core objectives — reliable reporting, compliance, and operational efficiency — while exploring how the 2017 update expanded the model to include strategic vision and risk appetite.
  4. Poisoned Dependencies
    Cybersecurity and Compliance Curriculum · 4:19
    A deep dive into the dangerous world of software supply chain attacks, where even trusted, widely-used libraries can become weapons when malicious code is secretly embedded by compromised maintainers or bad actors.
  5. When ACE Breaks Down
    Cybersecurity and Compliance Curriculum · 4:21
    Explore the critical limitations of Access Control Entries (ACE) when time-sensitive security requirements come into play, and discover why static rule-based systems struggle to handle dynamic concepts like Recovery Time Objectives (RTOs) and Recovery Point Objectives (RPOs).
  6. 1 Defining Active-Active
    Cybersecurity and Compliance Curriculum · 4:14
    Dive into the fundamentals of active-active architecture and discover how it differs from active-passive and active-standby models in keeping critical systems resilient and continuously available.
  7. Adaptive Management Principles
    Cybersecurity and Compliance Curriculum · 3:14
    Adaptive management principles come alive through the reality that effective crisis response demands decentralized decision-making and the confidence to act on incomplete information, teaching listeners how to move decisively when 60% certainty is enough to course-correct before conditions worsen.
  8. 4 Dual-Environment Workflow
    Cybersecurity and Compliance Curriculum · 3:15
    Explore the architecture of a dual-environment cybersecurity workflow, where open lab environments foster innovation and AI-assisted development while sensitive Controlled Unclassified Information (CUI) and production systems remain protected within secure GovCloud infrastructure.
  9. The Organizational Relationship After Compliance
    Cybersecurity and Compliance Curriculum · 3:15
    Exploring what happens after a compliance audit concludes, this chapter reveals how cybersecurity teams can shift from a position of crisis-driven authority to building lasting, trust-based relationships within their organizations.
  10. Exercise 3: Framework Mapping
    Cybersecurity and Compliance Curriculum · 3:47
    A hands-on exercise in framework mapping walks through how common cybersecurity requirements like access controls, encryption, and multi-factor authentication align across SOC 2, CMMC, HIPAA, and ISO 27001, helping listeners identify overlapping controls and streamline compliance efforts.
  11. IP Licensing Risk Management
    Cybersecurity and Compliance Curriculum · 4:39
    A cautionary deep-dive into the hidden pitfalls of IP licensing agreements, revealing how startups and businesses can fall victim to cross-licensing traps, territorial restrictions, and audit clauses buried in the fine print.