Zero Trust, Maximum Security: Cyber Risk Strategies for Risk Professionals

In 2010, a cybersecurity industry analyst had an epiphany: increasing sophistication of network security models through the 2000s contributed to a corresponding increasing false sense of security among cybersecurity practitioners. He used his pulpit to appeal for “Zero Trust.” Various solutions in the industry press such as “de-perimeterization” and “data-centric security” existed but were not as intuitive to grasp as the phrase “Zero Trust.” Zero Trust developments have since been fueled by the simple observation that fortifying networks alone does not protect data. Vendors, standards bodies, and regulators started to study this problem and independently came to the same conclusion. What began over a decade ago as a conceptual model is now is a widely accepted methodology for minimizing uncertainty in enforcing least privilege access to systems resources.
 
  Release Date:
July 28, 2025

  Time:
Self-paced

  Presented By:
Jennifer Bayuk, Ph.D., CISA, CISM, CGEIT

  Session Length:
3 Hours

 

About This Course
 

The course is designed to enable and empower risk management professionals to confidently, productively, efficiently, and effectively analyze cybersecurity risk in the context of Zero Trust tenets. Specific topics include:

  • Zero Trust Tenets: "not trust but verify, instead always verify"
  • Historical rationale for Zero Trust
  • Governance Requirements for Zero Trust
  • Zero Trust Industry Standards and Regulatory Landscape
  • Vendor impact on Zero Trust architecture
  • Methods to measure Zero Trust

Attendees are expected to have some level of experience in technology risk management principles and practices, but deep expertise in technology risk management is not required. The seminar enhances the awareness of attendees at all levels on how to leverage their own experience to improve their understanding of cybersecurity risk management.


 
Objectives
 Time
 

The objective of the seminar is to enable and empower risk professionals to confidently, efficiently, and effectively contribute to cybersecurity risk management programs. Specific skills that will be taught in this course include how to:

  • Recognize and explain Zero Trust tenets.
  • Classify access control mechanisms as Zero Trust (non) compliant.
  • Analyze Zero Trust technology at the architecture level.
  • Model cybersecurity risk indicators based on Zero Trust tenets.


Who Should Attend
This course is suitable for all risk professionals.


About Our Expert

  
 

Jennifer L. Bayuk is a Cybersecurity due diligence expert. She has been a Global Financial Services Technology Risk Management Officer, a Wall Street Chief Information Security Officer, a Big 4 Information Risk Management Consultant, a Manager of Information Technology Internal Audit, a Security Architect, a Bell Labs Security Software Engineer, a Professor of Systems Security Engineering, and a Private Cybersecurity Investigator and Expert Witness. She is currently developing Cybersecurity Frameworks and Metrics with Decision Framework Systems, Inc. and consulting independently. Bayuk is a member of the Executive Advisory Board for the Digital Assurance for High Consequence Systems Mission Campaign, a federally funded program to develop the scientific foundation for rigorous, rapid, cost-effective, generalizable digital assurance across high consequence system lifecycles.

Bayuk has numerous publications on cybersecurity management, information technology risk management, information security tools and techniques, cybersecurity forensics, technology-related privacy issues, audit of physical and information systems, security awareness education, systems security architecture, and systems security metrics. She is the author of: Stepping through the IS Audit, Stepping through the InfoSec Program, Enterprise Security for the Executive, and author/editor of: Cyberforensics, Cybersecurity Policy Guidebook, Enterprise Information Security and Privacy, Financial Cybersecurity Risk Management, and Stepping Through Cybersecurity Risk Management. Her most recent book includes a sub-chapter devoted to Zero Trust and in 2023 she led an ISACA Seminar on Zero Trust Architecture.

Bayuk’s direct technology experience spans enterprise architecture, telecommunications networks, operating systems, database management systems, network management systems, software development and support, technology forensics, business continuity, and operations process. She has Masters Degrees in Computer Science and Philosophy, and a PhD in Systems Engineering. Her certifications include CISSP, CISA, CISM, CGEIT, and a NJ State Private Investigator's License.



Continued Risk Learning Credits: 3

PRMIA Continued Risk Learning (CRL) programs provide you with the opportunity to formally recognize your professional development, documenting your evolution as a risk professional. Employers can see that you are not static, making you a highly valued, dynamic, and desirable employee. The CRL program is open to all Contributing, Sustaining, and Risk Leader members, providing a convenient and easily accessible way to submit, manage, track and document your activities online through the PRMIA CRL Center. To request CRL credits, please email [email protected].

Registration
 Membership Type Price
   
 Sustaining, Corporate, and RIM Members $299
 Contributing Member $339
 Non Member $399

If this is your first time accessing the PRMIA website you will need to create a short user profile to register. Save on registration by becoming a member.

 

Register Now

 
When
7/28/2025 - 12/31/2026
Where
Virtual Course

Sign In to Register for Event


Questions?

Contact Us


Looking to further your career?

Become a Member

Sign Up for Mailing List



Questions?

Contact Us


Looking to further your career?

Become a Member

Sign Up for Mailing List