Skip to Scheduled Dates
Course Overview
This course develops practitioner-level competencies in building a Digital Value Management System® (DVMS) to transform systemic cyber risk into operational resilience by uniting Fragmented Frameworks and Standards—such as NIST, ITSM, GRC, and ISO—into a single, adaptive Governance, Resilience, and Assurance (GRA) operating system that keeps your digital business running, no matter the disruption.
It builds progressively from mindset and models to systems thinking, governance integration, and continuous improvement, culminating in a capstone synthesis project.
Course Outline
Module 1 – Practitioner Foundations
1.1 Transitioning to a Practitioner’s Mindset
- Differentiate between compliance-driven and practitioner (strategy-risk-aligned) mindsets.
- Understand adaptive, proactive decision-making in cybersecurity operations.
- Identify behaviors and mindsets that enable value creation.
1.2 The 3D Knowledge Model
- Describe X and Y axes of the model for mapping knowledge and dependencies.
- Apply both axes to enhance decision-making and resilience.
1.3 3D Knowledge Model: Z-Axis
- Explore culture and leadership as drivers of practitioner effectiveness.
- Evaluate how culture influences resilience and governance.
- Develop strategies for building generative culture.
1.4 The Role of Questions
- Formulate practitioner-level diagnostic and strategic questions.
- Use inquiry to uncover hidden risks, dependencies, and assumptions.
- Embed questioning as a foundation for proactive cybersecurity.
1.5 Strategy-Risk
- Explain the unity of strategy and risk.
- Apply the space-time analogy to decision-making.
- Evaluate the consequences of siloed strategy and risk management.
Module 2 – Systems Thinking and Operational Integration
2.1 Systems Thinking Fundamentals
- Understand system structure, behavior, and culture in cybersecurity.
- Apply systems tools (causal loops, iceberg, BOT graphs).
- Identify feedback loops and leverage points for resilience.
2.2 Strategy-Risk: Reinforce & Operationalize
- Integrate strategy-risk thinking into daily cybersecurity practices.
- Design cross-functional collaboration processes for alignment.
2.3 Deep Dive into the CPD Model
- Analyze workflows through the CPD (Create-Protect-Deliver) Model.
- Map assurance loops and feedback mechanisms.
2.4 MVC Operationalized by CPD
- Describe how CPD loops enable Minimum Viable Capabilities (MVC).
- Map NIST CSF core functions to CPD and MVC for execution alignment.
2.5 Be the Menace
- Apply use and misuse cases to anticipate threats.
- Integrate adversarial modeling into assurance and measurement planning.
Module 3 – Governance, Capabilities, and Measurement
3.1 DVMS as a Governance Overlay
- Understand DVMS as a system overlay linking governance, strategy, and execution.
- Map workflows to MVCs and assess governance loops.
3.2 Minimum Viable Capabilities (MVC)
- Explain and apply the seven MVCs across workflows.
- Use the 3D Knowledge Model (Z-axis) to identify cultural barriers.
3.3 QO–QM Validation & Metrics
- Apply GQM (Goal–Question–Metric) and QO–QM frameworks.
- Align metrics with strategic outcomes and continuous improvement.
3.4 FastTrack™ Approach
- Sequence capability deployment based on maturity and culture.
- Use governance feedback and cultural diagnostics for dynamic adaptation.
3.5 Risk Team Structure & Collaboration
- Design and assess cross-functional risk teams.
- Integrate DVMS, MVC, and QO–QM in governance and decision-making.
Module 4 – Innovation, Maturity, and Adaptation
4.1 The Four Aspects of Innovation
- Distinguish incremental, sustaining, adaptive, and disruptive innovation.
- Apply systems thinking to identify innovation leverage points.
4.2 Nonlinear Adoption – Revisiting Phases
- Contrast linear and nonlinear adoption models.
- Map feedback loops that drive adaptation and cultural learning.
4.3 DVCMM (Digital Value Capability Maturity Model)
- Define DVCMM levels (0–3) across MVCs.
- Benchmark maturity and link Govern/Assure to capability deployment.
4.4 Bridge to Day 5 – Synthesis Preparation
- Integrate systems thinking, governance, culture, and measurement.
- Formulate a capstone action plan for cyber resilience improvement.
Module 5 – Integration, Improvement, and Mastery
5.1 Continual Improvement & Innovation Loops
- Design feedback mechanisms for single- and double-loop learning.
- Embed continuous improvement into operations and culture.
5.2 Integrating Governance, Measurement, and Culture
- Unify DVMS governance, GQM/QO–QM measurement, and cultural diagnostics.
- Design feedback loops for adaptive improvement and resilience.
5.3 Capstone Synthesis & Practitioner Reflection
- Apply all course models to a real-world cybersecurity challenge.
- Develop an actionable improvement plan aligned with strategy-risk priorities.
- Reflect on practitioner growth and continuous learning.
Assessment and Examination
- Format: Online, proctored, open-book examination.
- Duration: 150 minutes (2.5 hours).
- Questions: 65 multiple-choice (1 correct answer each).
- Weighting: 65 total points; passing score = 39 (60%).
- Focus: Application, analysis, and evaluation (Bloom’s Levels 3–5).
- Resources: Book, slides, and case study materials (unaltered).
- Outcome: Pass/Fail.