Syllabus
Unit 1
Foundations of Cybersecurity Governance
Principles of cyber-security governance, Assessment of cyber security maturity, Theories of governance – introduction, governance – definitions and topologies, Governance vs Management vs Compliance, Cybersecurity Maturity Models, Cloud governance , Zero Trust governance , AI-driven security governance
Unit 2
Governance of Security Operations
Governance of Security Operations, Tools, methods, and processes – Vulnerability management, Threat management, Security incident management. Security operations center (SOC) and related concepts, Governance of SIEM and SOAR, Digital Forensics Governance, Governance of Cloud SOC and Hybrid SOC.
Unit 3
Cyber Risk Governance and Quantitative Risk Analytics
Information security risk management framework and methodologies, Risk Management Process, Risk Management Frameworks (NIST,ISO), Identifying and modelling information security risks, Qualitative and quantitative risk assessment methods, FAIR, Cyber Insurance and Governance, AI driven risk management in NIST, ISO frameworks.
Unit 4
Security analytics, Threat Intelligence
Basics of security analytics-Threat intelligence and governance- Data driven security governance- User and Entity Behavior Analytics (UEBA), Impact of cognitive security on security governance, Predictive Security Governance, AI-Driven Threat Intelligence and Governance
Unit 5
Compliance, Legal Governance, and Policy-as-Code
Compliance and governance- Industry specific security Policies and compliance-Cyber security Auditing and governance – HIPAA compliance for healthcare – ISO, COBITZ standards – NIST mandates for compliance-PCI-DSS for Finance – Digital Personal Data Protection (DPDP) Act, Intelligent Compliance Monitoring using AI.
Text Books / References
- The Cybersecurity Guide to Governance, Risk, and Compliance: Jason Edwards; Griffin Weaver, Wiley (John Wiley & Sons Ltd.), 2024
- Cyber Security Technology and Governance : Audun Josang, Springer Nature, 2025
- Governance, Risk, and Compliance in Cybersecurity: James Relington, Wiley,2023
- Cybersecurity Governance An Enterprise Risk Management Strategy for Cyber Risk Control:Kok Boon Oh , Giang Hoang , John Sturdy , Sarah Shuaiqi Guo, Springer, 2025.
- NIST CSF 2.0: Your Essential Introduction to Managing Cybersecurity Risks: Andrew Pattison, IT Governance Publishing, 2025
Introduction
The rapid advancement of digital technologies, cloud computing, artificial intelligence, and interconnected systems has significantly increased cyber risks faced by organizations and critical infrastructures. This course provides an advanced understanding of Cybersecurity Governance by integrating governance frameworks, cyber risk management, security operations, compliance, security analytics, and emerging technologies. It focuses on aligning cybersecurity strategies with organizational objectives, regulatory requirements, business resilience, and national cyber policies through frameworks such as NIST CSF, ISO/IEC 27001, and COBIT. The course also introduces modern concepts including Zero Trust governance, AI-driven security governance, cloud governance, AI-driven risk management, and Policy-as-Code to prepare students for research and industry roles in governance, risk, and compliance (GRC).
Evaluation Pattern
CO-PO Mapping
Correlation Levels: 3 = High, 2 = Moderate, 1 = Low
| COs POs |
PO1 |
PO2 |
PO3 |
| CO1 |
3 |
1 |
3 |
| CO2 |
2 |
2 |
3 |
| CO3 |
3 |
3 |
3 |
| CO4 |
3 |
2 |
2 |
| CO5 |
2 |
2 |
3 |
Evaluation Pattern
| Assessment |
Internal |
External |
| Mid Term Exam |
20 |
|
| Assignments |
15 |
|
| Project |
25 |
|
| Final Exam |
|
40 |