Cyber Security Governance for Government and Public Sector Teams Training Course
| Course code | SD-CS-054 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cyber Security |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Government and public sector organisations must protect citizen data, essential services, operational technology and public trust while working within statutory duties, budget controls, procurement rules and political scrutiny. Cyber security leaders need more than technical controls: they must establish accountable decision rights, convert risk evidence into defensible priorities, govern suppliers and cloud services, and demonstrate that security investment supports mission delivery. This course addresses the gap between cyber operations and the governance structures that senior responsible owners, audit committees, regulators and service leaders expect to see.
Participants learn to design and operate a practical cyber security governance model for a public body. The course covers governance roles and committees, risk appetite and tolerance statements, NIST Cybersecurity Framework 2.0 and NIST RMF application, ISO/IEC 27001 control governance, information asset ownership, third-party assurance, incident escalation, metrics and board reporting. Participants practise building a risk register, defining risk treatment decisions, creating a control assurance plan, and presenting cyber priorities in language suited to executives and non-technical oversight bodies.
Delivery combines instructor-led analysis with government-style case material, including a citizen-services platform, a critical supplier and a reportable security incident. Throughout the week, participants develop a Cyber Security Governance Pack for a realistic public sector organisation. The pack includes a governance operating model, RACI, risk appetite statements, priority risk register, assurance calendar, dashboard design and a 90-day implementation plan that can be adapted for use in their own department, agency, local authority or public service provider.
The course is designed for intermediate to advanced professionals who influence security decisions, assurance or service delivery. It is particularly valuable where cyber governance must work across shared services, legacy estates, regulated information, outsourced providers and multiple accountable stakeholders.
Course objectives
By the end of this course, participants will be able to:
- Design a public sector cyber security governance operating model with accountable roles, forums and escalation routes
- Apply NIST Cybersecurity Framework 2.0 and NIST RMF to structure mission-led cyber risk decisions
- Draft risk appetite and tolerance statements for citizen data, critical services and third-party dependencies
- Build a prioritised cyber risk register using likelihood, impact, control effectiveness and treatment ownership
- Create a RACI matrix for information asset ownership, security control operation and incident decision-making
- Develop a control assurance plan aligned to ISO/IEC 27001:2022 evidence requirements and internal audit needs
- Produce board-level cyber metrics and dashboard narratives that distinguish risk exposure from operational activity
- Construct a 90-day cyber governance implementation roadmap with milestones, dependencies and decision points
Benefits of attending
For you
- Gain a repeatable method for converting technical security concerns into governance decisions senior leaders can approve
- Build credibility when briefing audit committees, senior responsible owners and service directors on cyber risk
- Learn to define accountable ownership across security, digital delivery, data governance and supplier management teams
- Create evidence-led assurance plans that support internal audit, external scrutiny and regulatory enquiries
- Leave with a reusable governance pack and implementation roadmap for a current or future leadership role
For your organisation
- Establish clearer ownership and escalation routes for cyber risks affecting public services and citizen information
- Improve the quality and consistency of cyber risk reporting presented to boards, audit committees and accountable officers
- Reduce unmanaged supplier and cloud risk through defined assurance requirements, contract checkpoints and exception handling
- Create an auditable link between security controls, risk treatment decisions, investment priorities and service outcomes
- Accelerate governance improvements through a participant-produced 90-day plan tailored to organisational constraints
Target competencies
Who should attend
- Cyber Security Managers — who must establish clear accountability and report risk to senior public sector leaders
- Information Security Officers — who translate security policies and technical controls into auditable governance practices
- Digital and IT Service Managers — who own services that must meet security, resilience and assurance obligations
- Risk and Assurance Managers — who need to integrate cyber risk into enterprise risk, audit and committee processes
- Data Protection and Information Governance Leads — who coordinate security responsibilities around sensitive and citizen information
- Procurement and Supplier Management Leaders — who must govern cyber risk across outsourced, cloud and managed service contracts
Requirements and prerequisites
Participants should already understand core cyber security concepts, including assets, threats, vulnerabilities, controls, incidents, access management and risk treatment. Experience working in an IT, digital, risk, audit, information governance or security role is expected, ideally within a government, local authority, health, education, transport or regulated public service environment. Familiarity with risk registers, policy documents and basic reporting to management will be useful. Participants do not need to be penetration testers, security architects, auditors or ISO lead auditors, and no coding, SIEM administration or prior certification in NIST or ISO/IEC 27001 is required.
Training methodology
The programme uses short instructor-led briefings followed by structured application to a public sector scenario. Participants map accountable roles for a citizen-facing service, assess a supplier dependency, score and treat risks, review assurance evidence, and rehearse an executive cyber risk briefing. Group work compares governance choices across central government, local authority and public service contexts without assuming a single operating model. Facilitated peer critique is used to strengthen each participant’s governance pack. The final session converts course outputs into a prioritised 90-day application plan for the participant’s own organisation.
Course outline
Day 1: Public sector cyber governance foundations
- Public accountability, essential service continuity and citizen trust obligations
- Three-lines model and the distinction between management, oversight and assurance
- Cyber governance operating models for departments, agencies and shared-service environments
- Accountable officer, senior responsible owner and information asset owner responsibilities
- Governance forums, terms of reference and decision-rights design
- NIST Cybersecurity Framework 2.0 Govern function and organisational profiles
- Cyber policy hierarchy, standards, exceptions and documented risk acceptance
Workshop: Participants create a governance RACI and committee escalation map for a fictional public benefits platform.
Day 2: Risk, appetite and treatment decisions
- Mission impact analysis for citizen services, sensitive information and critical operations
- NIST Risk Management Framework steps and system authorisation logic
- Risk identification across assets, data flows, people, suppliers and legacy technology
- Likelihood, impact, inherent risk and residual risk scoring methods
- Risk appetite, tolerance thresholds and risk acceptance authority
- Risk treatment options, control selection and investment prioritisation
- Risk register design, ownership fields and decision audit trails
Workshop: Participants produce a prioritised cyber risk register and draft risk appetite statements for the scenario organisation.
Day 3: Control assurance and information governance
- ISO/IEC 27001:2022 governance requirements and Annex A control structure
- Control objectives, control owners and evidence of operating effectiveness
- Information asset inventories, data classification and ownership assignment
- Control assurance plans, testing frequencies and evidence repositories
- Internal audit coordination and management response tracking
- Security exceptions, compensating controls and expiry-based review
- Microsoft Purview use cases for data classification and compliance evidence
Workshop: Participants build a control assurance calendar with named owners, evidence sources, testing methods and remediation checkpoints.
Day 4: Third parties, incidents and oversight reporting
- Supplier segmentation based on service criticality, data access and substitutability
- Security requirements in procurement specifications, contracts and service level agreements
- Third-party due diligence, assurance artefacts and continuous monitoring triggers
- Cloud shared-responsibility governance and service owner accountability
- Incident classification, escalation thresholds and executive decision logs
- Post-incident review governance, lessons learned and corrective action tracking
- ServiceNow GRC workflows for issues, risk treatment and assurance actions
Workshop: Participants assess a managed-service supplier and produce an escalation brief following a simulated data-security incident.
Day 5: Board reporting and governance implementation
- Board-level cyber metrics versus operational security metrics
- Key risk indicators, key control indicators and risk trend interpretation
- Dashboard design for exposure, resilience, control assurance and supplier risk
- Writing executive narratives that explain decisions, uncertainty and residual risk
- Budget cases linking control investment to service and mission outcomes
- Ninety-day governance implementation planning and dependency mapping
- Governance pack review against NIST CSF 2.0 and ISO/IEC 27001:2022
Workshop: Participants present their Cyber Security Governance Pack to a simulated audit committee and finalise a 90-day implementation roadmap.
Tools & standards covered
NIST Cybersecurity Framework 2.0, NIST Risk Management Framework (SP 800-37 Rev. 2), ISO/IEC 27001:2022, ServiceNow GRC
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cyber Security
Cyber Security Leadership for Information Security Managers Training Course
Information security managers are expected to turn technical risk into decisions that executives, auditors, business owners and operational …
Splunk Enterprise Security SIEM Operations Training Course
Security operations teams need more than dashboards and alert queues: they need a repeatable way to determine which detections represent cre…
Advanced Cyber Threat Hunting and Incident Response Training Course
Security operations teams often collect far more telemetry than they can investigate. Advanced adversaries exploit that gap by using legitim…
Cyber Security Risk Oversight for Board Directors Training Course
Board directors are increasingly expected to challenge management on cyber security without becoming operational security specialists. They …