Google Cybersecurity Certificate, Course 2: Play It Safe: Manage Security Risks (Study Notes)

    Plain-English notes on risk management, NIST CSF and RMF, security controls, OWASP principles, audits, threat modeling with STRIDE and PASTA, and SIEM dashboards. Includes practice questions with explanations.

    Independent study aid. Not affiliated with or endorsed by Google or Coursera. All explanations and questions are original. Confirm current course content on the official Coursera page.

    1. Course overview

    Course 1 told you what security is. Course 2 shows how organisations decide what to protect and how: finding risks, ranking them, choosing controls, following a framework, checking that it all works, and watching it on dashboards. It is the “thinking like a manager and an analyst” course.

    Core idea

    You cannot protect everything equally, so you rank risks and spend effort where the damage would be greatest.

    Builds on

    CIA triad and the 8 CISSP domains from Course 1.

    Study tip

    Practise with a made-up small business: list its assets, risks and controls on one page.

    2. Weekly breakdown (study plan)

    A suggested five-part plan grouped by topic. Follow the official course order for graded work, as week titles may differ.

    Part 1: The 8 domains and security risk management
    • Domains tell you where a risk lives (policy, data, network, access, testing, operations, software).
    • Risk management is a loop: identify, assess, treat, monitor.
    • Risk is roughly likelihood multiplied by impact. A rare but catastrophic event can outrank a frequent minor one.
    • Treating risk: reduce it (add controls), avoid it (stop the activity), transfer it (insurance, vendor contract) or accept it (low impact, documented decision).
    • Think in terms of threat (danger), vulnerability (gap) and asset value.
    Part 2: Security frameworks, NIST CSF and RMF

    A framework is a ready-made structure so you do not invent a security programme from scratch.

    NIST CSF functionQuestion it answers
    GovernWho decides, and what are our policies and priorities?
    IdentifyWhat do we have and what could go wrong?
    ProtectWhat safeguards stop or limit harm?
    DetectHow do we notice something is happening?
    RespondWhat do we do during an incident?
    RecoverHow do we get back to normal and learn?

    Older CSF versions have five functions without Govern; check which version your course uses. NIST CSF is voluntary guidance.

    NIST RMF is a step-by-step lifecycle for managing risk in a specific system: Prepare, Categorize, Select controls, Implement, Assess, Authorize, Monitor. See NIST RMF.

    Other names to recognise: CIS Controls, ISO/IEC 27001, and regulations such as GDPR, HIPAA and PCI DSS.

    Part 3: Security controls and OWASP principles
    Control typeJobExample
    PreventiveStop it happeningMFA, firewall rule
    DetectiveSpot itLog alerts, cameras
    CorrectiveFix it afterwardsRestore from backup
    DeterrentDiscourage itWarning banner

    Controls are also grouped as administrative (policies, training), technical (software, encryption) and physical (locks, badges).

    OWASP security principles (from the OWASP community) are habits for safer design:

    • Least privilege: minimum access needed.
    • Separation of duties: no one person controls a whole sensitive process.
    • Defense in depth: several layers, so one failure is not fatal.
    • Minimise the attack surface: switch off what you do not use.
    • Fail securely: when something breaks, deny access rather than allow it.
    • Secure defaults and keep it simple: complicated systems hide mistakes.
    • Do not rely on secrecy alone: hiding a design is not protection.
    Part 4: Security audits

    An audit is a structured review of whether security practices meet a standard or policy.

    • Internal audits are run by the organisation’s own staff; external audits by independent parties.
    • Typical flow: set scope and goals, assess risk, check controls against the standard, record gaps, report findings, recommend fixes.
    • Scope says what is in and out; goals say what you want to learn.
    • Findings should be clear to non-technical managers: what is wrong, why it matters, what to do first.
    Part 5: Threat modeling (STRIDE, PASTA) and SIEM dashboards

    Threat modeling means thinking like an attacker before you build or deploy, so you fix weak spots early.

    STRIDEMeaningProperty attacked
    SpoofingPretending to be someone elseAuthentication
    TamperingChanging dataIntegrity
    RepudiationDenying an actionNon-repudiation
    Information disclosureLeaking dataConfidentiality
    Denial of serviceMaking it unavailableAvailability
    Elevation of privilegeGaining extra rightsAuthorization

    PASTA is a seven-stage, risk-centred process: define objectives, define technical scope, break the application down, analyse threats, find vulnerabilities, model attacks, then analyse risk and impact and plan countermeasures. It starts from business goals rather than a checklist.

    SIEM dashboards turn raw logs into visual summaries such as failed logins over time, top source IPs, or alerts by severity. Analysts use them to spot spikes, then drill into the underlying events. A dashboard shows where to look; it does not prove an attack.

    3. 15 must-know terms

    TermPlain meaning
    RiskLikelihood of harm times its impact
    Risk assessmentFinding and ranking risks
    Risk appetiteHow much risk an organisation will tolerate
    FrameworkReusable structure for a security programme
    NIST CSFSix-function guide to managing cyber risk
    NIST RMFLifecycle for managing risk in a system
    Security controlSafeguard that reduces risk
    ComplianceMeeting laws, standards or policies
    AuditStructured check against a standard
    Least privilegeOnly the access you need
    Defense in depthLayered protection
    Attack surfaceAll the ways in an attacker could try
    Threat modelStructured analysis of how a system could be attacked
    SIEMTool that gathers and correlates logs and alerts
    DashboardVisual summary of key security metrics

    4. Three worked examples

    Example 1: Rank two risks

    Scenario: A small shop has (A) customer card data on an old unpatched PC and (B) a printer with a default admin password.

    Reasoning: A has higher impact (payment data, legal penalties) and a known weakness. B is real but lower value. Answer: treat A first (patch, isolate, or move off the old PC), then B (change the password), and record both in a risk register.

    Example 2: Classify controls

    Scenario: The shop adds (1) a door lock, (2) log alerts for repeated failed logins, (3) nightly backups.

    Answer: (1) preventive and physical; (2) detective and technical; (3) corrective and technical. Together they give layered defence.

    Example 3: Apply STRIDE to a login page

    Spoofing: stolen passwords, so add MFA. Tampering: altered requests, so validate input. Repudiation: a user denies actions, so keep logs. Information disclosure: vague errors help attackers, so use generic messages. DoS: floods, so rate limit. Elevation: normal user reaches admin pages, so enforce role checks.

    5. Common mistakes

    • Treating every risk as equal. Ranking by impact and likelihood is the whole point.
    • Confusing CSF with RMF. CSF is a high-level guide of six functions; RMF is a stepwise process for a specific system.
    • Thinking compliance equals security. Passing an audit shows you met a standard, not that you cannot be breached.
    • Mixing control type with control category. Preventive and detective describe the job; administrative, technical and physical describe the form.
    • Mistaking STRIDE for a list of attacks. It is a prompt for asking what could go wrong in a design.
    • Trusting a dashboard blindly. Check the underlying events before escalating.

    6. 10 practice questions (tap to reveal)

    Q1. Name the four ways to respond to a risk.

    Reduce, avoid, transfer, accept. Each is a valid choice depending on cost and impact.

    Q2. A company buys cyber insurance for ransomware losses. Which risk response is this?

    Transfer. The financial impact moves to the insurer, though the risk itself still exists.

    Q3. Which NIST CSF function covers having a tested recovery plan after an outage?

    Recover. It focuses on restoring services and learning from the event.

    Q4. How does RMF differ from CSF in one sentence?

    CSF gives broad outcome areas for an organisation; RMF is a step-by-step lifecycle for authorising and monitoring a particular system.

    Q5. Is a security awareness training programme administrative, technical or physical?

    Administrative. It is a policy and people-based control.

    Q6. A system crashes and, by design, locks all doors rather than leaving them open. Which OWASP principle?

    Fail securely. Failure should not grant access.

    Q7. Why split payment approval between two employees?

    Separation of duties: one person acting alone (or with a stolen account) cannot complete fraud.

    Q8. Which STRIDE category fits an attacker editing a price in transit?

    Tampering. It attacks integrity.

    Q9. What is the main difference between STRIDE and PASTA?

    STRIDE is a quick category checklist of threat types; PASTA is a longer, business-focused process that models attacks and weighs risk.

    Q10. A SIEM dashboard shows a sudden spike in failed logins from one IP. What is the sensible next step?

    Drill into the underlying log events, check the account and source, then follow the playbook (for example, block the IP or reset credentials) and escalate if it looks malicious.

    7. YouTube search links

    8. One-screen revision summary

    • Risk loop: identify, assess, treat (reduce, avoid, transfer, accept), monitor.
    • CSF: Govern, Identify, Protect, Detect, Respond, Recover.
    • RMF: Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor.
    • Controls: preventive, detective, corrective, deterrent; administrative, technical, physical.
    • OWASP habits: least privilege, separation of duties, defense in depth, small attack surface, fail securely.
    • Audit: scope, goals, risk, check controls, report gaps, recommend fixes.
    • STRIDE: Spoofing, Tampering, Repudiation, Information disclosure, DoS, Elevation.
    • PASTA: seven stages, business-first.
    • SIEM dashboard: shows patterns; verify events before acting.

    9. What you should be able to do

    ← Back to hub

    Educational summary for learners; not affiliated with Google or Coursera. Verify details against official course materials. Last reviewed: October 2026.