High School IntermediateModule I148 Lessons + Module Test

I14 Security Policies and Risk

Learn how fictional organizations turn security evidence into governance, policies, standards, procedures, risk decisions, third-party oversight, measurable controls, leadership reporting, and accountable improvement.

Module snapshot

8 Lessons

Governance, risk, assets, treatment, policies, suppliers, metrics, and an integrated lab.

Final assessment

25 Questions

One complete module test with hidden answers and explanations.

Portfolio outcome

10 Artifacts

A fictional governance, policy, risk, supplier, and reporting package.

Main Question

How Should an Organization Turn Uncertainty into an Accountable Security Decision?

Security policy and risk work is not a search for perfect certainty. It is a disciplined process for defining the decision, identifying assets and dependencies, gathering evidence, evaluating likelihood and impact, choosing treatment, assigning ownership, documenting exceptions, validating controls, communicating limits, and reviewing the decision as conditions change.

Safety and privacy boundary

Every organization, policy, vendor, risk record, incident, account, identity, system, data set, contract, metric, owner, and decision in this module is fictional. Do not use real private company data, school records, credentials, contracts, internal policies, or confidential risk information.

Module Workflow

Eight Steps from Question to Reviewable Risk Decision

1

Define the decision

State the fictional business question, scope, authority, owners, time window, evidence sources, privacy limits, and expected outcome.

2

Map assets and dependencies

Identify fictional people, systems, data, services, suppliers, locations, recovery needs, and critical business relationships.

3

Identify risk conditions

Separate fictional threats, vulnerabilities, exposure, control gaps, uncertainty, assumptions, and missing evidence.

4

Evaluate likelihood and impact

Use fictional evidence, business context, control health, exposure, history, dependency, and confidence to rank risk.

5

Select treatment and controls

Choose fictional avoidance, reduction, transfer, acceptance, or monitoring with proportionate preventive, detective, corrective, and recovery controls.

6

Document policy and ownership

Assign fictional policy, control, asset, data, third-party, exception, review, and escalation owners.

7

Validate and communicate

Confirm fictional effectiveness, residual risk, evidence limits, metrics, leadership decisions, and approved communication.

8

Review and improve

Track fictional changes, incidents, exceptions, supplier updates, control failures, lessons learned, and scheduled reassessment.

Learning Objectives

What You Will Be Able to Do

Objective 1

Explain the relationship among fictional governance, policy, standards, procedures, controls, risk ownership, and leadership accountability.

Objective 2

Create evidence-based fictional risk assessments that separate observations, assumptions, alternatives, confidence, limitations, and missing information.

Objective 3

Connect fictional assets, data, services, suppliers, dependencies, criticality, recovery needs, and business impact.

Objective 4

Compare fictional risk treatment choices and select proportionate controls with named owners, validation, monitoring, and residual-risk decisions.

Objective 5

Build portfolio-safe fictional policy, exception, third-party, metrics, and risk-reporting artifacts for technical and leadership audiences.

Objective 6

Complete an integrated fictional policies-and-risk case without using any real private data, company systems, or confidential records.

Lesson Path

Complete I14.1 through I14.8 in Order

Lesson 1 of 8

I14.1 Security Governance and Policy Foundations

Open Lesson

Focus

Understand how fictional organizations connect mission, leadership, governance, policy ownership, accountability, ethics, and security responsibilities.

Lab output

Build a fictional governance map showing decision owners, policy owners, control owners, reviewers, exceptions, and escalation paths.

Lesson 2 of 8

I14.2 Risk Identification and Assessment

Open Lesson

Focus

Identify fictional assets, threats, vulnerabilities, exposures, dependencies, control gaps, uncertainty, and business consequences.

Lab output

Create a fictional risk register using evidence, likelihood, impact, confidence, assumptions, owners, and review dates.

Lesson 3 of 8

I14.3 Asset, Data, and Business Impact Analysis

Open Lesson

Focus

Connect fictional systems, data classes, services, users, dependencies, recovery needs, criticality, and mission impact.

Lab output

Build a fictional asset and business-impact map with owners, classifications, recovery priorities, and dependency chains.

Lesson 4 of 8

I14.4 Risk Treatment and Control Selection

Open Lesson

Focus

Compare fictional risk avoidance, reduction, transfer, acceptance, and monitoring while selecting proportionate controls.

Lab output

Design a fictional treatment plan with preventive, detective, corrective, recovery, governance, and compensating controls.

Lesson 5 of 8

I14.5 Security Standards, Procedures, and Exceptions

Open Lesson

Focus

Distinguish policy, standard, procedure, guideline, baseline, exception, waiver, and approval records.

Lab output

Create a fictional policy hierarchy and an exception record with scope, reason, controls, residual risk, expiration, and removal plan.

Lesson 6 of 8

I14.6 Third-Party and Supply Chain Risk

Open Lesson

Focus

Evaluate fictional vendors, partners, service providers, software dependencies, data sharing, access, monitoring, contracts, and exit planning.

Lab output

Build a fictional third-party risk review with due diligence, evidence, access boundaries, incident duties, monitoring, and offboarding.

Lesson 7 of 8

I14.7 Security Metrics, Reporting, and Review

Open Lesson

Focus

Design fictional metrics that connect security evidence, control health, risk reduction, ownership, trends, limitations, and decisions.

Lab output

Create a fictional leadership risk report with technical measures, business meaning, confidence, limits, actions, and review cadence.

Lesson 8 of 8

I14.8 Security Policies and Risk Lab

Open Lesson

Focus

Integrate governance, assets, risk assessment, treatment, policies, exceptions, third parties, metrics, and communication.

Lab output

Complete a fictional risk-governance case and produce a portfolio-ready policy and risk package.

Fictional Evidence Preview

The Northbridge Risk-Governance Case

Throughout Module I14, you will analyze a fictional organization that must update policy, clarify ownership, review a vendor, evaluate an expired exception, prioritize recovery risk, and report uncertainty to leadership without overstating incidents or impact.

A fictional vendor retains access after a project ends.
A critical service has no confirmed recovery owner.
An exception expired but the control gap remains.
A risk dashboard shows a high score, but evidence confidence is only medium.
A policy requires annual review, but the last approval is older than the stated cycle.
No supplied evidence supports a confirmed incident or data disclosure.

Portfolio Outcome

Build a Fictional Security Policy and Risk Package

Each lesson contributes one or more artifacts. By the end of the module, you should have a complete fictional package that shows how evidence, business context, policy ownership, control design, exceptions, suppliers, metrics, and leadership decisions connect.

1Governance and responsibility matrix
2Asset, data, service, and dependency register
3Business-impact and recovery-priority analysis
4Evidence-based risk register
5Risk treatment and control-selection plan
6Policy, standard, procedure, and guideline hierarchy
7Exception and residual-risk register
8Third-party and supply-chain risk review
9Security metrics and leadership reporting package
10Integrated portfolio-safe risk-governance case

Final Assessment

I14 Security Policies and Risk Module Test

After completing all eight lessons, take the exact 25-question module test. The assessment will cover governance, asset and data impact, risk identification, treatment, control selection, policy hierarchy, exceptions, suppliers, metrics, reporting, and integrated risk decisions.

Open Module Test

Module Navigation

Begin Security Policies and Risk