CSE725

Cybersecurity Policy and Risk Management
Post-graduate Program

CSE725: Cybersecurity Policy and Risk Management

Offered: Fall 2025 (current)

Security frameworks: Control frameworks, Program frameworks, Risk frameworks. Understanding risk: Risk concepts, Calibration, Risk assessment and management. Security policy: Purpose of policy, Risk appetite statement, Policy pyramid, Pandemic response planning policy. Program structure: Security functions, Reporting relationships, Three lines of defense, RACI Matrix. Leading modern security initiatives: Maturity model, Advisory board, Behavior model, Cloud security, Zero trust model, Negotiation primer. Detecting and responding to attacks: SIEM goals, Security Operations Center (SOC), Incident handling and response.

Course Objectives

The core objectives of this course are to:
Understand the key elements of security governance of an organization.
Understand NIST cybersecurity frameworks
Design security policies for an organization
Develop a security program structure
Learn modern security initiatives

List of Books

1. To Be Added

Course Outcome

# Description Weight Edit

Course Coordinator

Dr. Md Sadek Ferdous


©2025 BracU CSE Department