Knowledge Domains
12 areas coveredISO 27001
International standard for establishing, implementing, and continually improving an Information Security Management System (ISMS) to protect organisational assets.
AI / ML
Artificial Intelligence and Machine Learning concepts, model lifecycle management, bias detection, explainability, and the compliance implications of automated decision-making.
GRC
Integrated approach to Governance, Risk management, and Compliance — aligning IT strategy with business objectives while managing uncertainty and regulatory obligations.
Risk Assessment
Structured processes for identifying, analysing, and evaluating threats and vulnerabilities. Covers qualitative and quantitative methods, risk registers, and treatment strategies.
AI Governance
Frameworks and policies ensuring AI systems are trustworthy, transparent, and accountable. Covers EU AI Act, NIST AI RMF, responsible AI principles, and ethical oversight.
HIPAA
Health Insurance Portability and Accountability Act — safeguarding Protected Health Information (PHI) through Privacy, Security, and Breach Notification Rules for covered entities.
GDPR
General Data Protection Regulation governing personal data collection, processing, and rights of EU/EEA data subjects. Includes DPIA requirements, DPO roles, and cross-border transfers.
HITRUST CSF
Common Security Framework harmonising HIPAA, NIST, ISO 27001, and PCI-DSS controls into a certifiable, risk-based framework widely adopted in healthcare and financial services.
Vendor Management
Third-party risk lifecycle covering due diligence, contract controls, ongoing monitoring, and offboarding. Includes SLA governance, sub-processor oversight, and fourth-party risk.
PCI-DSS
Payment Card Industry Data Security Standard protecting cardholder data. Covers network segmentation, encryption, access control, and v4.0 requirements including payment page integrity.
Cloud Security
Controls and architectures securing cloud environments (AWS, Azure, GCP). Includes shared responsibility models, CSPM, infrastructure-as-code security, and CIS Benchmarks.