Course Outline
Module 1: The Security Context in the Public and Healthcare Sectors
-
Introduction to cybersecurity: Why companies, local governments and public institutions are currently primary targets for attacks (ransomware, data leaks, service paralysis).
-
The cost of incidents: Financial, reputational, and legal consequences of halting the operations.
-
The manager's role: Board liability (including local authorities and directors) and building a security culture within the organization.
Module 2: The Legal Landscape – The NIS2 Directive and the KSC Act
-
The NIS2 Directive: The evolution of regulations, new qualification criteria (essential and important entities), and anticipated financial and administrative sanctions.
-
The National Cybersecurity System Act (KSC): New and existing obligations for state, local government, and healthcare institutions.
-
Incident management: Incident classification, escalation paths, the role of competent CSIRT teams (e.g., CSIRT GOV, CSIRT NASK), and strict timeframes for reporting breaches.
Module 3: Information Security Management System (ISMS)
-
ISMS fundamentals: What a management system is according to the ISO/IEC 27001 standard and the National Interoperability Framework (KRI).
-
Documentation architecture: Which policies, procedures, and instructions are absolutely legally required (e.g., Information Security Policy, incident management procedure).
-
Practical implementation: Access management (principle of least privilege), human resources security, remote work, physical, and environmental security.
Module 4: Risk Management and Business Continuity
-
Risk assessment methodology: How to map processes, identify assets, and assess threats in an office or hospital (a pragmatic approach, compliant with ISO 31000/27005 standards).
-
Risk register: Creating and maintaining a risk register, risk treatment plans (mitigation, transfer, acceptance).
-
Business Continuity Planning (BCP): Business continuity and Disaster Recovery Plans – how to guarantee the functioning of critical public and life-saving services in the event of IT system failures.
Module 5: Supply Chain Security and Vendor Liability
-
The supply chain under NIS2: Your institution's security ends where the security of your weakest vendor ends.
-
Vendor contracts: Key security clauses in agreements with software providers (e.g. document management systems in local governments), cloud computing, and external companies (IT outsourcing, security guards, cleaning services).
-
Partner verification: Methods for auditing and monitoring vendor compliance with the institution's requirements.
Module 6: Periodic Internal Information Security Audit
-
Legal requirements: Why KSC, KRI, and GDPR require regular audits (Who, when, and how often must conduct them?).
-
The audit process from the auditee's perspective: How to prepare the organization, employees, infrastructure, and documentation to successfully pass the inspection.
-
Post-audit activities: Analyzing the audit report, categorizing non-conformities, creating and enforcing corrective plans (CAPA - Corrective and Preventive Actions).
Module 7: Summary and Implementation Steps
-
Managerial Action Plan: The 5 most important steps to take in the organization within the first 30 days post-training.
-
Q&A session: Solving specific problems reported by participants (case studies from their own units).
Requirements
-
No requirement for specialized technical, programming, or engineering knowledge – the training is conducted from a managerial, legal, and process perspective.
-
General knowledge of the organizational structure, key services, and business processes implemented by one's own institution is recommended.
Audience
- Top management and senior executives
- Mayors, city presidents, hospital and healthcare facility directors, directors of subordinate units, and chief financial officers (CFOs).
- Heads of organizational, administrative, and IT departments, Data Protection Officers (DPOs), Information Security / Cybersecurity Plenipotentiaries, and internal auditors.
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
The report and rules setup.