Module snapshot
8 Lessons
Governance, risk, assets, treatment, policies, suppliers, metrics, and an integrated lab.
Learn how fictional organizations turn security evidence into governance, policies, standards, procedures, risk decisions, third-party oversight, measurable controls, leadership reporting, and accountable improvement.
Module snapshot
8 Lessons
Governance, risk, assets, treatment, policies, suppliers, metrics, and an integrated lab.
Final assessment
25 Questions
One complete module test with hidden answers and explanations.
Portfolio outcome
10 Artifacts
A fictional governance, policy, risk, supplier, and reporting package.
Main Question
Security policy and risk work is not a search for perfect certainty. It is a disciplined process for defining the decision, identifying assets and dependencies, gathering evidence, evaluating likelihood and impact, choosing treatment, assigning ownership, documenting exceptions, validating controls, communicating limits, and reviewing the decision as conditions change.
Safety and privacy boundary
Every organization, policy, vendor, risk record, incident, account, identity, system, data set, contract, metric, owner, and decision in this module is fictional. Do not use real private company data, school records, credentials, contracts, internal policies, or confidential risk information.
Module Workflow
State the fictional business question, scope, authority, owners, time window, evidence sources, privacy limits, and expected outcome.
Identify fictional people, systems, data, services, suppliers, locations, recovery needs, and critical business relationships.
Separate fictional threats, vulnerabilities, exposure, control gaps, uncertainty, assumptions, and missing evidence.
Use fictional evidence, business context, control health, exposure, history, dependency, and confidence to rank risk.
Choose fictional avoidance, reduction, transfer, acceptance, or monitoring with proportionate preventive, detective, corrective, and recovery controls.
Assign fictional policy, control, asset, data, third-party, exception, review, and escalation owners.
Confirm fictional effectiveness, residual risk, evidence limits, metrics, leadership decisions, and approved communication.
Track fictional changes, incidents, exceptions, supplier updates, control failures, lessons learned, and scheduled reassessment.
Learning Objectives
Objective 1
Explain the relationship among fictional governance, policy, standards, procedures, controls, risk ownership, and leadership accountability.
Objective 2
Create evidence-based fictional risk assessments that separate observations, assumptions, alternatives, confidence, limitations, and missing information.
Objective 3
Connect fictional assets, data, services, suppliers, dependencies, criticality, recovery needs, and business impact.
Objective 4
Compare fictional risk treatment choices and select proportionate controls with named owners, validation, monitoring, and residual-risk decisions.
Objective 5
Build portfolio-safe fictional policy, exception, third-party, metrics, and risk-reporting artifacts for technical and leadership audiences.
Objective 6
Complete an integrated fictional policies-and-risk case without using any real private data, company systems, or confidential records.
Lesson Path
Lesson 1 of 8
Focus
Understand how fictional organizations connect mission, leadership, governance, policy ownership, accountability, ethics, and security responsibilities.
Lab output
Build a fictional governance map showing decision owners, policy owners, control owners, reviewers, exceptions, and escalation paths.
Lesson 2 of 8
Focus
Identify fictional assets, threats, vulnerabilities, exposures, dependencies, control gaps, uncertainty, and business consequences.
Lab output
Create a fictional risk register using evidence, likelihood, impact, confidence, assumptions, owners, and review dates.
Lesson 3 of 8
Focus
Connect fictional systems, data classes, services, users, dependencies, recovery needs, criticality, and mission impact.
Lab output
Build a fictional asset and business-impact map with owners, classifications, recovery priorities, and dependency chains.
Lesson 4 of 8
Focus
Compare fictional risk avoidance, reduction, transfer, acceptance, and monitoring while selecting proportionate controls.
Lab output
Design a fictional treatment plan with preventive, detective, corrective, recovery, governance, and compensating controls.
Lesson 5 of 8
Focus
Distinguish policy, standard, procedure, guideline, baseline, exception, waiver, and approval records.
Lab output
Create a fictional policy hierarchy and an exception record with scope, reason, controls, residual risk, expiration, and removal plan.
Lesson 6 of 8
Focus
Evaluate fictional vendors, partners, service providers, software dependencies, data sharing, access, monitoring, contracts, and exit planning.
Lab output
Build a fictional third-party risk review with due diligence, evidence, access boundaries, incident duties, monitoring, and offboarding.
Lesson 7 of 8
Focus
Design fictional metrics that connect security evidence, control health, risk reduction, ownership, trends, limitations, and decisions.
Lab output
Create a fictional leadership risk report with technical measures, business meaning, confidence, limits, actions, and review cadence.
Lesson 8 of 8
Focus
Integrate governance, assets, risk assessment, treatment, policies, exceptions, third parties, metrics, and communication.
Lab output
Complete a fictional risk-governance case and produce a portfolio-ready policy and risk package.
Fictional Evidence Preview
Throughout Module I14, you will analyze a fictional organization that must update policy, clarify ownership, review a vendor, evaluate an expired exception, prioritize recovery risk, and report uncertainty to leadership without overstating incidents or impact.
Portfolio Outcome
Each lesson contributes one or more artifacts. By the end of the module, you should have a complete fictional package that shows how evidence, business context, policy ownership, control design, exceptions, suppliers, metrics, and leadership decisions connect.
Final Assessment
After completing all eight lessons, take the exact 25-question module test. The assessment will cover governance, asset and data impact, risk identification, treatment, control selection, policy hierarchy, exceptions, suppliers, metrics, reporting, and integrated risk decisions.
Open Module TestModule Navigation