This course is designed to provide participants with fundamental knowledge of information security governance and risk management in organizations. Throughout the sessions, key concepts such as strategic security planning, governance and maturity models, as well as risk identification, analysis, and treatment will be explored. The course will draw on recognized standards and methodologies, using a practical approach that will enable participants to apply what they have learned in real-world settings. This course combines a solid theoretical foundation with hands-on activities designed to help participants implement effective plans and actions for security governance and risk management within their respective organizations.