ข้ามไปยังเนื้อหา
Essential IT Standards for Modern Enterprise
Section 1 : บทนำและพื้นฐาน Foundation : The World of IT Standards
Lesson 1 : Foundation : The World of IT Standards (10 นาที) ตัวอย่าง บทเรียน
Introduction to IT Standard
CIA triad และความสำคัญของ GRC
ภาพรวมมาตรฐานระดับโลก
Key Takeaways
Lesson 2 : มาตรฐานแม่บทด้านความมั่นคงปลอดภัยสารสนเทศที่ทุกคนต้องรู้ ISO/IEC 27001 – The Gold Standard (15 นาที)
ISMS (Information Security Management System) คืออะไร?
วงจร PDCA (Plan-Do-Check-Act) ในการรักษาความปลอดภัย
Context of Organization และ Risk Assessment เบื้องต้น
Key Takeaways and Quiz
Lesson 3 : เจาะลึกมาตรการควบคุม (Controls) ที่ฝ่ายไอทีต้องทำจริง ISO/IEC 27001 Annex A Controls (15 นาที)
ภาพรวม 4 Themes of Controls
Secure coding Standard รู้จักการ Shift Left
Key Takeaways and Quiz
Section 2 : Operational Frameworks (เน้นการปฏิบัติงาน)
Lesson 1 : NIST Cybersecurity Framework (CSF 2.0) กรอบการทำงานที่เน้น “ทำอย่างไรเมื่อเกิดเหตุ”  (ยอดนิยมมากในปัจจุบัน)  (15 นาที)
6 Functions หลัก: Govern, Identify, Protect, Detect, Respond, Recover
Key Takeaways and Quiz
Lesson 2 : ISO/IEC 20000 & ITIL มาตรฐานการบริหารจัดการบริการไอที (IT Service Management)(10 นาที)
IT Service Management (ITSM)
Incident vs. Problem Management
Change Management (การขอเปลี่ยนแปลงระบบอย่างปลอดภัย)
SLA (Service Level Agreement)
Key Takeaways and Quiz
Lesson 3 : Business Continuity (ISO 22301)  เมื่อระบบล่ม เราจะกู้คืนอย่างไร (BCP/DRP) (10 นาที)
ความต่างของ BCP (Business Continuity Plan) และ DRP (Disaster Recovery Plan)
RTO (Recovery Time Objective) vs RPO (Recovery Point Objective)
การซ้อมหนีไฟทางไซเบอร์ (Drill)
Key Takeaways and Quiz
Section 3 : Specific Domains (เจาะลึกเฉพาะด้าน)
Lesson 1 : Cloud Security (CSA STAR & ISO 27017) มาตรฐานสำหรับการใช้งาน Cloud (AWS, Azure, Google Cloud) (10 นาที)
Shared Responsibility Model (ใครรับผิดชอบอะไรบน Cloud)
Cloud Security Alliance (CSA) และ Key Cloud Control
Key Takeaways and Quiz
Lesson 2 : Data Privacy (ISO 27701 & PDPA/GDPR) (15 นาที) การคุ้มครองข้อมูลส่วนบุคคลในมุมมอง IT
PIMS (Privacy Information Management System)
Privacy by Design (การออกแบบระบบให้คำนึงถึงความเป็นส่วนตัว)
สิทธิเจ้าของข้อมูล (Data Subject Rights) ที่ IT ต้องเตรียมระบบรองรับ
Key Takeaways and Quiz
Lesson 3 : Application Security (OWASP ASVS) (10 นาที) มาตรฐานความปลอดภัยสำหรับคนทำ Software/Web
OWASP Top 10 (10 ช่องโหว่ยอดฮิต)
Secure Coding Standard เบื้องต้น
DevSecOps concept
Key Takeaways and Quiz
Section 4 : Conclusion (บทสรุป)
Lesson 1 : Implementation Roadmap จะเริ่มทำมาตรฐาน ต้องเริ่มที่ตรงไหน? (10 นาที)
Gap Analysis
Quick Wins
การขอ Certification
Continuous Improvement
Course completion
หัวข้อก่อนหน้า
บทเรียนถัดไป

Key Takeaways

Scroll to Top
เข้าสู่ระบบ
การเข้าถึง คอร์สเรียน นี้จำเป็นต้องเข้าสู่ระบบ โปรดระบุข้อมูลประจำตัวของคุณที่ด้านล่าง!

ลืมรหัสผ่านใช่ไหม?
ลงทะเบียน
ยังไม่มีบัญชีใช่ไหม? ลงทะเบียนเลย!
ลงทะเบียนบัญชีใหม่