Managing Security Operations & Risk
Run the security function like a business: people, risk, metrics, and money.
Tuition
$499
Advanced
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
10 hours
Estimated time
What you will be able to do
- You will be able to oversee the security operations center and the wider security team, setting shift coverage, escalation paths, and service level agreements (SLAs) that keep detection and response on track.
- You will be able to define who owns what across your security functions using a RACI (responsible, accountable, consulted, informed) chart, so nothing important falls between the analyst, the engineer, and the manager.
- You will be able to decide when to build a capability in house and when to use a managed security service provider (MSSP), and hold either choice to measurable outcomes.
- You will be able to run enterprise risk management end to end: identify and rate risks, maintain a risk register, and drive each risk to a documented decision to accept, mitigate, transfer, or avoid.
- You will be able to translate a board-approved risk appetite into operational thresholds your team can act on, and quantify risk in money terms so leaders can weigh it against other business risks.
- You will be able to build a metrics program that separates key performance indicators (KPIs) from key risk indicators (KRIs), and present a dashboard that drives action instead of vanity numbers.
- You will be able to build and defend a security budget, writing a business case that ties every request to risk reduction and weighs return on investment (ROI) against the residual risk you choose to keep.
- You will be able to oversee third-party risk management (TPRM) as a program: tier vendors by risk, set contract and monitoring expectations, and account for concentration and fourth-party risk.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Running the SOC and the Security Function
A manager does not work the alert queue; a manager makes sure the queue gets worked well. This module steps up from analyst to leader. You will learn to design shift coverage and escalation, set service levels for detection and response, and pull real value from your security information and event management (SIEM) and security orchestration, automation, and response (SOAR) platforms. You will also decide how to structure the team, choose when to build a capability in house versus using a managed security service provider (MSSP), and learn how to hold either one accountable.
2 lessons · 5 quiz questions
- 02
Enterprise Risk Management in Practice
This module puts enterprise risk management (ERM) in the manager's hands. You will build and maintain a risk register, rate risks consistently, and drive each one to a documented decision to accept, mitigate, transfer, or avoid. Then you will connect the operation to the boardroom by translating an approved risk appetite into thresholds your team can act on, and by learning when to quantify risk in money terms rather than settling for a red, amber, or green label.
2 lessons · 5 quiz questions · assignment
- 03
Metrics, KPIs, and the Security Budget
You cannot manage what you cannot measure, and you cannot fund what you cannot justify. This module shows how to build a metrics program that leaders act on: choosing a small set of Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) over vanity numbers, then presenting them on a dashboard built for decisions. From there you turn evidence into money, constructing a security budget and a business case that ties every request to risk reduction and weighs each control honestly against its return and the residual risk you choose to keep.
2 lessons · 5 quiz questions
- 04
Vendor and Third-Party Oversight
The risk you manage does not stop at your own perimeter. This module treats vendor and third-party oversight as an ongoing program rather than a one-time questionnaire: how to tier vendors by the risk they carry, set the right expectations in contracts and service level agreements (SLAs), and monitor them over the life of the relationship. You will also handle the risks that surprise managers most, from concentration risk when too much depends on a single supplier to fourth-party risk hiding in your vendors' own suppliers.
2 lessons · 5 quiz questions · assignment