Establishing the foundational GRC program
Defining system boundaries and impact levels
Identifying and tailoring security & privacy controls
Executing the control implementation strategy
Verifying control effectiveness
Verifying system meets all requirements
Ongoing lifecycle management
โBuilding trust by doing the right thing, the right way.โ
Welcome to the world of Governance, Risk, and Compliance โ or GRC for short. This is a big, fancy name for something very simple: making sure organisations run fairly, safely, and by the rules.
Think of GRC like the rules of a game. Without rules, the game is chaos. With good rules, everyone knows what to do, and the game is fun and fair. In business, GRC helps companies avoid trouble, make good decisions, and earn peopleโs trust.
In this module, we will learn what GRC means, why it matters, and how it works. We will use simple words, fun stories, and lots of examples from Nigeria and around the world. Letโs begin!
Imagine a busy market in a Nigerian village. There are many traders selling yams, cassava, and palm oil. But there is a problem โ some traders cheat by using fake weights. Customers lose trust, and the market starts to fail.
The village chief steps in. He creates rules (governance): all weights must be checked every week. He sets up a team to watch for dangers (risk) like dishonest traders. And he makes sure everyone follows the rules (compliance) by having a market inspector.
Soon, the market becomes the most trusted in the region. Customers come from far away, and everyone prospers. That is GRC in action โ rules, risk management, and compliance working together to create success.
Definition: Governance is the system of rules, practices, and processes by which an organisation is directed and controlled.
Why important: Good governance ensures that the organisation is run in a fair, transparent, and accountable way.
Simple explanation: Governance is like the rules of a school. They tell students and teachers what to do, how to behave, and who is in charge.
Real-life example: A companyโs board of directors sets the strategy and oversees management โ thatโs governance.
School example: The school principal and teachers create a code of conduct for students.
Home example: Parents set rules about chores, bedtime, and screen time โ thatโs family governance.
Nigerian example: A church in Lagos has a constitution that guides how it operates โ thatโs governance.
Governance structure (simplified):
Board of Directors
|
Chief Executive Officer (CEO)
|
Department Heads
|
Employees
Definition: Risk is the possibility that something bad could happen.
Why important: If you donโt manage risks, you could lose money, hurt people, or damage your reputation.
Simple explanation: Risk is like crossing a busy road โ there is a chance you could get hit by a car. You manage that risk by looking both ways.
Real-life example: A bank faces the risk of hackers stealing customer data.
School example: The risk of students getting sick during an outbreak โ the school manages it by encouraging hand washing.
Home example: The risk of fire โ you manage it by not leaving the stove on.
Nigerian example: A farmer faces the risk of drought โ he manages it by planting drought-resistant crops.
Risk = Likelihood ร Impact
(how likely ร how bad it would be)
Definition: Compliance means following the rules, laws, and regulations that apply to your organisation.
Why important: If you donโt comply, you can be fined, sued, or even shut down.
Simple explanation: Compliance is like obeying traffic lights. If you run a red light, you get a ticket โ or worse, an accident.
Real-life example: A hospital must comply with health and safety regulations.
School example: Students must comply with the dress code.
Home example: You comply with your parentโs rule to finish homework before watching TV.
Nigerian example: A bank must comply with the Central Bank of Nigeriaโs regulations.
Governance, Risk, and Compliance are like three legs of a stool. If one leg is weak, the stool falls.
Simple explanation: Think of a car โ governance is the steering wheel (direction), risk is the brakes (avoiding danger), and compliance is the seatbelt (safety rules).
Nigerian example: A company that follows GRC principles is more likely to win government contracts and customer loyalty.
| Role | Responsibility |
|---|---|
| Board of Directors | Sets the overall strategy and oversight |
| Chief Risk Officer (CRO) | Manages risk identification and mitigation |
| Compliance Officer | Ensures the organisation follows laws and regulations |
| Internal Audit | Checks if GRC processes are working |
| Employees | Follow the rules and report issues |
Definition: A framework is a set of best practices and guidelines.
Why important: Frameworks help organisations implement GRC consistently.
Popular frameworks:
Risk Management Cycle:
Identify โ Analyse โ Evaluate โ Treat โ Monitor โ (repeat)
Compliance is not just about avoiding fines. Itโs about building a culture of integrity.
Simple explanation: If you do the right thing even when no one is watching, thatโs true compliance.
Nigerian example: A company that pays taxes honestly, even if they could get away with cheating, shows strong compliance culture.
Technology helps GRC by:
Nigerian example: A bank uses software to monitor transactions for suspicious activity โ thatโs GRC technology.
Well done! You have learned the foundations of GRC:
You are now ready to explore deeper into GRC โ congratulations!
Match the GRC term with its definition.
| Term | Definition |
|---|---|
| 1. Governance | A. The chance of something bad happening |
| 2. Risk | B. Following the rules and laws |
| 3. Compliance | C. The system of rules and processes |
| 4. Framework | D. A set of best practices |
(Answers: 1-C, 2-A, 3-B, 4-D)
Scenario: A small business in Lagos sells food online. They collect customer data (names, addresses, payment details). They are not sure about their GRC responsibilities.
Question: What governance, risk, and compliance issues should they consider? What steps should they take?
In groups of 4, pretend you are the GRC team for a new bank. Identify 5 risks, propose governance structures, and list 5 compliance requirements.
Think of a local organisation (school, church, business). Identify its governance structure, one key risk, and one compliance requirement.
Create a simple GRC policy for a school club. Include a mission (governance), a risk register (risk), and a code of conduct (compliance).
Research a Nigerian regulator (CBN, SEC, NITDA). Write a one-page summary of their GRC requirements for businesses.
In Module 2, we will dive deeper into Risk Management. You will learn how to identify, analyse, and treat risks. We will explore risk registers, risk matrices, and real-world case studies. Think about a risk you face in your daily life โ we will learn how to manage it professionally!
You have completed Module 1 โ you are on your way to becoming a GRC Expert! ๐
โHope for the best, but plan for the worst.โ
In Module 1, we learned the big picture of GRC. Now we will focus on one of its most important parts: Risk Management.
Risk is all around us โ in business, in school, at home, and even in our communities. The question is not whether we have risks, but how we manage them.
In this module, we will learn how to spot risks, figure out how dangerous they are, and take steps to protect ourselves. We will use simple language, fun stories, and lots of examples โ including many from Nigeria โ to make risk management easy to understand.
Letโs dive in and become risk-savvy!
Imagine your school is planning a big excursion to a fun park. The teachers are excited, but they also know there are risks โ some students might get lost, it might rain, or a bus could break down.
A wise teacher, Mrs. Ade, decides to manage the risks. She makes a list: students wear bright vests (so they wonโt get lost), they check the weather forecast (and bring umbrellas), and they have a backup bus in case the first one breaks down.
Because of Mrs. Adeโs planning, the excursion goes smoothly. The students have fun, and no one gets hurt. That is risk management โ identifying problems before they happen and taking action.
Definition: Risk management is the process of identifying, analysing, and responding to risks.
Why important: Without risk management, organisations can lose money, damage their reputation, or even go out of business.
Simple explanation: Risk management is like wearing a helmet when you ride a bicycle โ you hope you wonโt fall, but youโre prepared just in case.
Real-life example: A company builds a backup power system so that if the electricity goes out, they can still work.
School example: A school has a fire drill so students know what to do in case of a real fire.
Home example: Your family has a fire extinguisher in the kitchen โ just in case.
Nigerian example: A bank has a security team to prevent robberies โ thatโs risk management.
Risk Management Cycle:
Identify โ Analyse โ Evaluate โ Treat โ Monitor
(and repeat โ it never ends!)
Nigerian example: A company in Nigeria faces the risk of power outages โ thatโs an operational risk.
Definition: Identifying risks means finding out what could go wrong.
Why important: You canโt manage a risk you donโt know about.
How to identify:
Nigerian example: A hotel in Lagos identifies the risk of a fire in the kitchen.
Analysis helps you understand two things:
Simple explanation: A small scratch on your arm is low impact. Breaking a leg is high impact.
Nigerian example: A school analyses the risk of a student getting sick during a trip โ likelihood is possible, impact is moderate.
Not all risks are equal. Some are tiny, and some are huge. You need to prioritise.
Use a risk matrix:
| Likelihood / Impact | Minor | Moderate | Major | Catastrophic |
|---|---|---|---|---|
| Rare | Low | Low | Medium | Medium |
| Unlikely | Low | Medium | Medium | High |
| Possible | Medium | Medium | High | High |
| Likely | Medium | High | High | Extreme |
| Almost certain | High | High | Extreme | Extreme |
Nigerian example: A bank evaluates cyber-attacks as โhighโ risk โ they need to act immediately.
There are four ways to treat risks:
Nigerian example: A company avoids the risk of flooding by building its office on higher ground.
Risks change over time. New risks appear, and old ones may disappear. You need to monitor continuously.
How to monitor:
Nigerian example: A company reviews its risk register every month.
A risk register is a document that lists all the risks, their analysis, and the actions taken.
| Risk ID | Description | Likelihood | Impact | Score | Response | Status |
|---|---|---|---|---|---|---|
| 1 | Cyber attack | Possible | High | High | Reduce | In progress |
| 2 | Power outage | Likely | Medium | High | Transfer (generator) | Done |
| 3 | Fraud | Unlikely | Major | Medium | Accept | Monitoring |
Risk management is not just one personโs job โ itโs everyoneโs responsibility.
Nigerian example: A company in Lagos rewards employees who identify risks โ this builds a strong risk culture.
Nigerian example: A Nigerian bank uses AI to detect fraudulent transactions.
Excellent work! You now understand the heart of GRC โ risk management:
You are now equipped to manage risks in any organisation โ or in your own life!
Match the risk response with its description.
| Response | Description |
|---|---|
| 1. Avoid | A. Move the risk to someone else |
| 2. Reduce | B. Stop the activity |
| 3. Transfer | C. Lower likelihood or impact |
| 4. Accept | D. Acknowledge and do nothing |
(Answers: 1-B, 2-C, 3-A, 4-D)
Scenario: A small retail shop in Abuja has been experiencing theft. They suspect employees might be stealing. The owner is worried about losing money and damaging trust.
Question: What is the risk? How would you analyse it? What response would you recommend? How would you monitor it?
In groups of 4, create a risk register for a school event (e.g., a sports day). Identify 5 risks, analyse them, and propose responses. Present your register to the class.
Think of a risk you face in your daily life (e.g., forgetting your keys, losing your phone). Apply the risk management process: identify, analyse, evaluate, treat, monitor.
Design a risk management plan for a small business of your choice (e.g., a restaurant, a shop, an online store). Include a risk register, risk responses, and a monitoring plan.
Research a real risk that affected a Nigerian company (e.g., a bank fraud, a data breach). Write a one-page report on what happened, how it could have been managed, and what you would recommend.
In Module 3, we will explore Compliance and Regulatory Frameworks. You will learn about the laws and regulations that organisations must follow โ in Nigeria and around the world. We will also look at how compliance is enforced and what happens when it is not followed.
Think about a rule or law you know about โ we will see how it fits into the compliance world!
You have completed Module 2 โ you are a risk management superstar! ๐
โRules are not meant to hold you back โ they keep you safe and fair.โ
In Module 1, we learned the big picture of GRC. In Module 2, we dived into risk management. Now, in Module 3, we focus on Compliance โ the โCโ in GRC.
Compliance is about following the rules. But rules are not just boring documents โ they exist to protect people, build trust, and make sure everyone plays fair. In business, compliance means obeying laws, regulations, and internal policies.
In this module, we will learn about the different types of compliance, who makes the rules, and what happens when you donโt follow them. We will use simple language, fun stories, and examples from Nigeria and around the world.
Letโs become compliance experts!
Imagine a busy junction in Lagos. There are no traffic lights โ cars are honking, people are shouting, and itโs total chaos. No one can cross safely.
Then, the government installs traffic lights. Red means stop, green means go, and yellow means slow down. Everyone follows the rules, and suddenly the junction becomes safe and orderly.
Compliance is like those traffic lights. It creates order, protects people, and makes everything work better. Without rules, we have chaos. With rules, we have safety and fairness.
Definition: Compliance means following the rules โ whether they are laws, regulations, or internal policies.
Why important: Compliance protects organisations from fines, lawsuits, and reputational damage.
Simple explanation: Compliance is like wearing a seatbelt โ you do it to stay safe and avoid getting a ticket.
Real-life example: A company must comply with tax laws by paying taxes on time.
School example: Students must comply with the schoolโs dress code.
Home example: You comply with your parentโs rule to finish homework before playing games.
Nigerian example: A bank must comply with the Central Bank of Nigeriaโs regulations.
Compliance = Following the Rules
Nigerian example: A Nigerian company must comply with NDPR (Nigeria Data Protection Regulation) โ thatโs regulatory compliance.
Nigerian example: The National Information Technology Development Agency (NITDA) enforces data protection rules.
Nigerian example: A company that complies with tax laws builds a good reputation and avoids fines.
What is it? A law that protects the personal data of Nigerians.
Why important: It ensures that companies collect, store, and use personal data responsibly.
Key requirements:
Nigerian example: A bank must get your permission before using your phone number for marketing โ thatโs NDPR compliance.
Nigerian example: A company that violates NDPR can be fined up to 10 million naira or 2% of turnover.
Compliance is not just a checklist โ itโs a culture. Everyone should care about rules.
Nigerian example: A company that celebrates employees who report violations builds a strong compliance culture.
Nigerian example: A bank uses software to monitor transactions for money laundering โ thatโs compliance technology.
| Feature | NDPR (Nigeria) | GDPR (EU) |
|---|---|---|
| Scope | Nigeria | European Union |
| Consent | Required | Required |
| Data breach notification | Within 72 hours | Within 72 hours |
| Fine | Up to โฆ10M or 2% turnover | Up to โฌ20M or 4% turnover |
| Enforcement | NITDA | Data Protection Authorities |
Excellent work! You have learned the essentials of compliance:
You are now equipped to help organisations stay compliant and build trust.
Match the compliance term with its description.
| Term | Description |
|---|---|
| 1. NDPR | A. European data protection law |
| 2. GDPR | B. Nigeria data protection law |
| 3. ISO 27001 | C. Information security management standard |
| 4. Regulator | D. A body that enforces rules |
(Answers: 1-B, 2-A, 3-C, 4-D)
Scenario: A Nigerian e-commerce company collects customer data but does not have a privacy policy. They have never heard of NDPR.
Question: What should they do to comply with NDPR? List at least 5 steps.
In groups of 4, design a compliance training session for employees of a bank. What topics would you cover? How would you make it engaging?
Think of a rule or law you have to follow at school or at home. Why is it important? What happens if you don't follow it?
Create a simple compliance checklist for a small business. Include legal, regulatory, and internal compliance items.
Research the Nigeria Data Protection Regulation (NDPR). Write a one-page summary of its key requirements and how a company can comply.
In Module 4, we will explore Governance Structures and Board Responsibilities. You will learn how boards govern organisations, the role of the company secretary, and how to build an effective board. We will also look at governance best practices and how they apply in Nigeria.
Think about a board you know โ maybe a school board or a company board โ and weโll see what makes it effective!
You have completed Module 3 โ you are a compliance champion! ๐
โGood governance is not about power โ itโs about responsibility.โ
In the first three modules, we learned about GRC basics, risk management, and compliance. Now we turn to the โGโ in GRC โ Governance.
Governance is the system by which organisations are directed and controlled. It is the framework of rules, practices, and processes that guide how an organisation operates. Think of governance as the steering wheel of a car โ it sets the direction.
In this module, we will explore how boards of directors work, their responsibilities, and how they ensure that organisations are run ethically and effectively. We will use simple language, fun stories, and Nigerian examples to make governance easy to understand.
Let's learn how to govern well!
Imagine a large school in Lagos. The school has many students, teachers, and staff. But who decides the school's direction? Who sets the budget? Who hires the principal?
The School Board does. The board is a group of wise people โ parents, community leaders, and educators โ who meet regularly to make important decisions. They set the school's vision, approve the budget, and ensure the principal is doing a good job.
Without the board, the school would lack direction and accountability. The board is the governance of the school โ it ensures the school is run well and serves its students.
Definition: Governance is the system by which organisations are directed and controlled.
Why important: Good governance ensures that organisations are run fairly, transparently, and accountably.
Simple explanation: Governance is like the rules of a game โ they tell everyone what to do and who is in charge.
Real-life example: A company's board of directors sets the strategy and oversees management.
School example: The school board sets policies and hires the principal.
Home example: Parents govern the family by setting rules and making decisions.
Nigerian example: A church in Lagos has a constitution and a board that guides its operations โ that's governance.
Governance = Direction + Oversight + Accountability
Nigerian example: A company with good governance attracts investors and builds trust.
Definition: The board of directors is a group of elected individuals who represent shareholders and oversee the organisation.
Why important: The board provides strategic direction and holds management accountable.
Roles:
Nigerian example: A bank's board includes both executive and independent directors.
Definition: The company secretary is the person who supports the board and ensures it operates effectively.
Why important: They keep the board organised and compliant.
Responsibilities:
Nigerian example: A company secretary ensures that the board follows the Companies and Allied Matters Act.
Boards often create committees to focus on specific areas.
Nigerian example: A Nigerian bank has a risk committee to comply with CBN regulations.
Nigerian example: A company that publishes its annual report shows transparency.
Nigerian example: A bank must comply with CBN's corporate governance code.
| Feature | Executive Director | Non-Executive Director |
|---|---|---|
| Employment | Works for the company | Independent |
| Role | Manages day-to-day | Oversees and advises |
| Independence | Less independent | Independent |
| Example | CEO, CFO | External advisor |
Excellent work! You have learned the essentials of governance:
You are now ready to understand and contribute to effective governance!
Match the governance term with its description.
| Term | Description |
|---|---|
| 1. Board of Directors | A. Supports the board |
| 2. Company Secretary | B. Top governing body |
| 3. Audit Committee | C. Oversees financial reporting |
| 4. CAMA | D. Nigeria's company law |
(Answers: 1-B, 2-A, 3-C, 4-D)
Scenario: A Nigerian company is facing a crisis โ the CEO has been accused of fraud. The board needs to act quickly.
Question: What should the board do? Describe the steps they should take to handle the situation.
In groups of 5, simulate a board meeting. Assign roles: Chairperson, CEO, 2 Non-Executive Directors, and a Company Secretary. Discuss a strategic decision (e.g., expanding to a new city).
Think of an organisation you know (school, church, business). Who governs it? How are decisions made? Write a short report.
Design a board charter for a small Nigerian company. Include the board's purpose, responsibilities, meeting schedule, and committee structure.
Research the corporate governance code of the Securities and Exchange Commission (SEC) Nigeria. Write a one-page summary of its key requirements.
In Module 5, we will explore GRC Integration and Culture. You will learn how governance, risk, and compliance work together โ and how to build a GRC culture in your organisation. We will also look at how to align GRC with business strategy.
Think about how GRC works in your own life โ we will connect it to the bigger picture!
You have completed Module 4 โ you are a governance guru! ๐
Welcome to Module 5! This is a very special module because we will learn about Governance, Risks, and Compliance โ or GRC for short. These are big words, but do not worry! We will break them down into small, easy pieces, just like we break a chocolate bar into squares.
Imagine you are the captain of a big ship. Governance is how you steer the ship, risks are the storms and waves that could trouble you, and compliance is following the rules of the sea. By the end of this module, you will understand how to be a great captain โ whether in a company, a school, or even at home! ๐ข
By the time you finish this module, you will be able to:
Once upon a time, there was a beautiful kingdom called Safeland. The king, King Wise, had a problem: the kingdom's treasure was disappearing, and the roads were not safe. People were worried.
King Wise called his advisors and said, โWe need a plan!โ
First, they made rules for everyone โ no one could take treasure without permission, and every road must have lights. That was governance (the way they ruled).
Next, they looked for risks โ thieves, broken bridges, and storms. They built stronger bridges and hired guards. That was managing risks.
Finally, they checked that everyone followed the rules. They rewarded those who obeyed and taught those who did not. That was compliance (following the rules).
Soon, Safeland became safe and happy! The kingdom grew, and even neighbouring lands came to learn from them. The story of Safeland shows that when we have good governance, we manage risks, and we follow rules, everything works better. ๐ฐ
Definition: Governance is the way a group of people makes decisions and runs things. It is like the โsteering wheelโ of an organisation.
Why important: Without governance, there would be chaos โ nobody would know who is in charge or what to do.
Simple explanation: Governance is the โrules of the gameโ that help a group work together smoothly.
Real-life example: In a school, the principal, teachers, and student council work together to make school rules. That is governance.
School example: Your class has a class monitor who helps the teacher keep order. That is a small governance system.
Home example: At home, parents decide the bedtime rules. That is family governance.
Nigerian example: In a local government area (LGA), the chairman and councillors make decisions about roads and markets. That is governance in Nigeria.
GOVERNANCE = HOW WE MAKE DECISIONS
|
+---> Who decides?
+---> What rules?
+---> How to solve problems?
Definition: A risk is something bad that might happen. It is like a dark cloud that could bring rain.
Why important: If we know about risks, we can prepare and avoid big problems.
Simple explanation: Risk is the chance that something unpleasant could occur.
Real-life example: Carrying your phone without a case โ the risk is that it might fall and break.
School example: Running in the hallway โ the risk is that you could slip and fall.
Home example: Leaving the stove on โ the risk is a fire.
Nigerian example: During rainy season, flooding is a risk. People build drains and raise their belongings to reduce the risk.
RISK = POSSIBLE BAD THING
|
+--> might happen
+--> we can prepare
Definition: Compliance means obeying the rules and laws. It is like following the instructions on a board game.
Why important: When everyone follows the rules, things are fair and safe.
Simple explanation: Compliance is โplaying by the rules.โ
Real-life example: Wearing a seatbelt in a car โ it is the rule, and we comply to stay safe.
School example: Raising your hand before speaking is compliance with school rules.
Home example: Brushing your teeth before bed โ it's a rule in many homes.
Nigerian example: Paying taxes is a form of compliance โ it helps the government build roads and schools.
COMPLIANCE = FOLLOW THE RULES
|
+--> rules exist for safety
+--> fairness
Definition: GRC is the combination of Governance, Risk, and Compliance. They are like three legs of a stool โ if one leg is weak, the stool falls.
Why important: We need all three to keep an organisation strong and healthy.
Simple explanation: Governance makes the rules, Risk looks for dangers, and Compliance checks that we follow the rules.
Real-life example: A bank has a board (governance), they watch out for fraud (risk), and they follow banking laws (compliance).
GRC STOOL
/ | \
GOV RISK COMP
(rules) (danger) (follow)
Definition: Risks can come in different shapes. Some are financial (money), some are physical (safety), and some are reputational (what people think).
Why important: Knowing the type of risk helps us choose the right protection.
Simple explanation: Just like there are different monsters, there are different risks.
School example: Financial risk โ the school might not have enough money for new books. Operational risk โ the school bus breaks down.
RISK TYPES +-------------------+ | Financial | | Operational | | Reputational | | Compliance | +-------------------+
Definition: Risk management means taking steps to reduce or avoid risks. It is like wearing a helmet when cycling.
Why important: It saves us from trouble and helps us stay on track.
Simple explanation: Risk management = think ahead + act smart.
Steps:
Nigerian example: Farmers use weather forecasts to manage the risk of drought. They plant drought-resistant crops.
RISK MANAGEMENT STEPS +--------+ +---------+ +---------+ +---------+ | IDENTIFY| -> | ANALYSE | -> | CONTROL | -> | MONITOR | +--------+ +---------+ +---------+ +---------+
Definition: A governance structure is the way an organisation arranges its leaders and decision-makers. Think of it like a family tree, but for bosses and managers.
Why important: It shows who is responsible for what.
Simple explanation: It is the โchain of commandโ โ who reports to whom.
Real-life example: In a company, the CEO is at the top, then managers, then workers.
School example: Principal โ Vice principal โ Teachers โ Students.
GOVERNANCE STRUCTURE
CEO
|
+----+----+
| |
Manager Manager
| |
Staff Staff
Definition: Compliance tools are things we use to check that rules are followed. They can be checklists, audits, or even cameras.
Why important: They help us catch mistakes before they become big problems.
Simple explanation: Compliance tools are like โrule-checkers.โ
School example: A teacher uses a grade book to check if students did their homework.
Home example: A chore chart helps parents check if children did their chores.
COMPLIANCE TOOLS +---------------+ | Checklists | | Audits | | Reports | | Monitoring | +---------------+
Definition: Policies are written rules that guide decisions. They are like a recipe โ they tell you what to do in different situations.
Why important: Policies make sure everyone knows the rules, so there is no confusion.
Simple explanation: A policy is a โrule book.โ
Nigerian example: Many banks have a policy that customers must show ID before opening an account. This prevents fraud.
POLICY = RULE BOOK
|
+--> what to do
+--> when to do it
Definition: Ethics is knowing what is right and wrong. Integrity is doing the right thing even when no one is watching.
Why important: Good ethics builds trust, and trust is important for any group.
Simple explanation: Ethics = knowing right from wrong. Integrity = doing the right thing.
School example: Returning a lost wallet you found โ that is integrity.
Home example: Telling the truth even if you might get into trouble.
ETHICS + INTEGRITY = GOOD HEART
|
+--> honesty
+--> fairness
Definition: GRC is not only for big companies. We all use GRC every day without knowing it!
Why important: When we understand GRC, we can make better decisions in our own lives.
Simple explanation: You are already a GRC expert โ you just didn't know it!
Everyday example: When you plan a party, you decide who brings what (governance), you think about the weather (risk), and you follow your parents' rules (compliance).
YOUR DAILY GRC +----------------------------+ | GOV: Decide what to wear | | RISK: Will it rain? | | COMP: Wear uniform if rule | +----------------------------+
Definition: In Nigeria, GRC is used in many areas โ from banks to schools to government.
Why important: It helps Nigeria grow and develop safely.
Simple explanation: Nigeria uses GRC to build roads, keep schools safe, and fight corruption.
NIGERIAN GRC +------------------+ | GOV: Constitution| | RISK: NEMA | | COMP: EFCC | +------------------+
Definition: Let's use games to understand GRC.
Example 1: Playing football โ the referee is governance, getting injured is risk, and following the offside rule is compliance.
Example 2: Monopoly board game โ the bank is governance, landing on someone else's property is risk, and paying rent is compliance.
FOOTBALL GRC +---------------------+ | GOV: Referee | | RISK: Injury | | COMP: Offside rule | +---------------------+
Definition: A GRC program is a plan to bring governance, risk, and compliance together.
Why important: It helps organisations achieve their goals safely.
Simple steps:
BUILD GRC PROGRAM 1. GOALS 2. GOVERNANCE 3. RISK ASSESSMENT 4. POLICIES & CONTROLS 5. MONITOR & REVIEW
Definition: GRC brings many good things: better decisions, less trouble, and more trust.
Why important: When GRC is strong, everyone wins โ employees, customers, and the community.
Simple explanation: GRC makes life easier and safer.
BENEFITS OF GRC +-------------------+ | Fewer risks | | More trust | | Smooth operations | +-------------------+
RISK ASSESSMENT STEPS 1. IDENTIFY โ 2. ANALYSE โ 3. EVALUATE โ 4. TREAT โ 5. MONITOR
COMPLIANCE CHECKLIST +-------------------+ | Rule 1: checked | | Rule 2: checked | | Rule 3: pending | +-------------------+
Use storytelling to explain GRC. Encourage children to share their own examples. Use role-play โ let students act as a board (governance), risk managers, and compliance officers. Emphasise that GRC is not scary โ it is helpful.
Discuss GRC at home. Ask your child: โWhat rules do we have at home? What risks do we watch out for? How do we follow rules?โ This makes the concepts real and practical.
Did you know that the โThree Lines of Defenceโ model is used in many organisations to manage risks? The first line is operational management, the second is risk and compliance functions, and the third is internal audit.
GRC FRAMEWORK
+---------------------------+
| GOVERNANCE |
| (Rules, decisions, board) |
+---------------------------+
|
+---------------------------+
| RISK |
| (Assessment, mitigation) |
+---------------------------+
|
+---------------------------+
| COMPLIANCE |
| (Following rules, audits) |
+---------------------------+
RISK MATRIX +----------------+----------------+----------------+ | Likelihood \ Impact | Low | Medium | High | +----------------+----------------+----------------+ | High | Medium Risk | High Risk | Critical Risk | | Medium | Low Risk | Medium Risk | High Risk | | Low | Low Risk | Low Risk | Medium Risk | +----------------+----------------+----------------+
DECISION-MAKING FLOW (Governance)
+-------------------+
| Identify Issue |
+-------------------+
|
+-------------------+
| Gather Information|
+-------------------+
|
+-------------------+
| Discuss Options |
+-------------------+
|
+-------------------+
| Make Decision |
+-------------------+
|
+-------------------+
| Implement & Review|
+-------------------+
| Aspect | Governance | Risk | Compliance |
|---|---|---|---|
| Focus | Rules and leadership | Potential problems | Following rules |
| Who does it? | Board, management | Risk managers | All employees |
| Example | Setting a code of conduct | Assessing flood risk | Submitting reports on time |
| Risk Type | Example | Mitigation |
|---|---|---|
| Financial | Losing money | Budgeting, insurance |
| Operational | Machine breakdown | Regular maintenance |
| Reputational | Bad publicity | Good communication |
Congratulations! You have completed Module 5 on Certified Governance, Risks & Compliance. You learned that:
Remember, GRC is like a superpower โ it helps you make good decisions and keep people safe. You are now ready to apply GRC in your own life and help your community grow.
| Term | Definition |
|---|---|
| 1. Governance | A. Chance of harm |
| 2. Risk | B. Following rules |
| 3. Compliance | C. Decision-making system |
| 4. Ethics | D. Written rule |
| 5. Policy | E. Knowing right from wrong |
Answers: 1-C, 2-A, 3-B, 4-E, 5-D
Scenario 1: You are the head of a school club. The club has โฆ50,000 to spend. Some members want to use the money for a party, but others want to buy books. How would you use governance to decide?
Scenario 2: A company stores customer data. There is a risk of hackers stealing the data. What can the company do to manage this risk?
In groups of 4, create a โGRC planโ for a school event (e.g., Sports Day). Assign roles: Governor (makes decisions), Risk Manager (identifies dangers), Compliance Officer (ensures rules are followed). Present your plan to the class.
Think about a rule at home. Write down: (1) What is the rule? (2) What is the risk if the rule is not followed? (3) How do you comply with the rule? Share with a family member.
Design a โGRC Charterโ for your classroom. Include: (1) Three governance rules (how decisions are made), (2) Three risks you want to manage, and (3) Three compliance rules (must-follow rules). Present it as a poster.
Conduct a simple risk assessment of your classroom. Identify at least five risks (e.g., slippery floor, heavy bags). For each risk, suggest a control measure. Write a one-page report.
Imagine you are the CEO of a new company. Write a one-page GRC policy that covers governance, risk management, and compliance. Be creative!
All answers are provided within the module (see multiple choice, matching, and true/false sections).
In Module 6, we will learn about Internal Controls and Auditing. You will discover how organisations check that everything works properly, just like a teacher checks your homework. Keep practicing what you learned about GRC โ it will help you a lot in the next module!
See you in Module 6! ๐
Welcome to Module 6! In this module, we will learn about Internal Controls and Auditing. These are like the "checks and balances" that make sure everything runs smoothly and honestly.
Imagine you have a piggy bank. You want to make sure your money is safe. You might put it in a locked box (that's a control). And every week, you count your money to make sure none is missing (that's an audit).
In organisations, internal controls are the rules and procedures that protect assets and ensure accuracy. Auditing is the process of checking that these controls are working. By the end of this module, you will understand how to protect things and check that everything is correct.
By the end of this module, you will be able to:
Once upon a time, in a small village, there was a bakery called "Sweet Treats." The baker, Mama Kemi, made delicious cookies. She had a jar where she kept the money from sales.
One day, she noticed that some money was missing. She was confused. She asked her assistants, but nobody knew what happened.
Mama Kemi decided to put controls in place. She got a locked cash box (preventive control). She also started counting the money every evening (detective control). And she made a rule that two people must count together (corrective control).
After that, the money stopped disappearing. But she also decided to have an external auditor, a wise old woman from the next village, to check her records once a month. The auditor would make sure everything was correct.
Mama Kemi's bakery became famous for being honest and trustworthy. People loved buying from her because they knew she was careful with her money and her records.
This story shows that internal controls and auditing help prevent theft, detect errors, and correct problems. They make organisations strong and trusted.
Definition: Internal controls are the policies, procedures, and rules that an organisation puts in place to protect its assets, ensure accuracy, and promote efficiency.
Why important: Without internal controls, things can go wrong โ money can be stolen, mistakes can happen, and chaos can ensue.
Simple explanation: Internal controls are like the safety rules you follow at home to avoid accidents.
Real-life example: In a supermarket, they have cameras (control) to prevent shoplifting.
School example: Teachers keep attendance records to know who is present (control).
Home example: You have a password on your phone to protect your information (control).
Nigerian example: Banks in Nigeria use PIN codes for ATM transactions (control).
INTERNAL CONTROLS +----------------------+ | Protect assets | | Ensure accuracy | | Promote efficiency | +----------------------+
Definition: Preventive controls are designed to stop problems before they happen. They are like a fence that keeps intruders out.
Why important: It is better to prevent a problem than to fix it later.
Simple explanation: Preventive controls are "stop signs" that prevent bad things.
Real-life example: Installing an alarm system in a house prevents burglaries.
School example: Requiring ID cards to enter the school prevents strangers from coming in.
Home example: Locking the front door prevents unwanted visitors.
Nigerian example: Using a password to access a bank account online prevents hackers.
PREVENTIVE CONTROLS +----------------------+ | Alarms | | Locks | | Passwords | | ID cards | +----------------------+
Definition: Detective controls are designed to find problems that have already happened. They are like a smoke alarm that alerts you to a fire.
Why important: If a problem occurs, detective controls help you discover it quickly so you can fix it.
Simple explanation: Detective controls are "lookouts" that watch for trouble.
Real-life example: A cashier count at the end of the day (detective) finds if money is missing.
School example: A teacher checks students' homework to see if they did it (detective).
Home example: Reviewing your spending on a mobile app to see where money went.
Nigerian example: Bank statements (detective) help customers see if there are unusual transactions.
DETECTIVE CONTROLS +----------------------+ | Cash counts | | Reviews | | Audits | | Reports | +----------------------+
Definition: Corrective controls are designed to fix problems after they have been detected. They are like a fire extinguisher that puts out the fire.
Why important: Corrective controls help restore things to normal.
Simple explanation: Corrective controls are "fixers" that repair damage.
Real-life example: If a system crashes, restoring from a backup is a corrective control.
School example: If a student fails a test, the corrective control is extra tutoring to help them improve.
Home example: If you break a glass, cleaning it up and buying a new one is corrective.
Nigerian example: If a company's records are inaccurate, they correct them with reconciliation.
CORRECTIVE CONTROLS +----------------------+ | Backups | | Reconciliation | | Repairs | | Training | +----------------------+
Definition: Auditing is the process of examining and verifying the accuracy of records and controls. It is like a health check for an organisation.
Why important: Auditing ensures that everything is correct and that controls are working.
Simple explanation: Auditing is "checking" or "inspecting" to make sure things are right.
Real-life example: An auditor checks a company's financial statements to ensure they are accurate.
School example: A teacher audits homework to see if students have done it correctly.
Home example: Parents audit your chores to see if you have done them properly.
Nigerian example: The Auditor-General of Nigeria audits government accounts to ensure public funds are properly used.
AUDITING = CHECKING +----------------------+ | Verify accuracy | | Ensure controls work | | Find errors | | Improve processes | +----------------------+
Definition: Internal audits are conducted by employees of the organisation. External audits are conducted by independent third parties.
Why important: Internal audits are ongoing and help management improve. External audits provide an independent opinion and are often required by law.
Simple explanation: Internal audit is like checking your own work. External audit is like having a teacher check your work.
Real-life example: A company has an internal audit department (internal) and hires an external auditor for an annual review.
School example: A student checks their own assignment (internal), and the teacher checks it (external).
Home example: You check your own homework (internal), and a parent checks it (external).
Nigerian example: Banks have internal auditors and are also audited by the Central Bank of Nigeria (external).
INTERNAL VS EXTERNAL +----------------+------------------+ | Internal | External | | Employee | Independent | | Ongoing | Periodic | | Improvement | Compliance | +----------------+------------------+
Definition: The audit process is a series of steps that auditors follow to complete an audit.
Why important: A structured process ensures a thorough and consistent audit.
Simple explanation: The audit process is like a recipe โ you follow the steps to get the best result.
Steps:
School example: A teacher plans a test, conducts it, grades it, and gives feedback (audit process).
AUDIT PROCESS +----------+ +---------+ +----------+ +---------+ | PLANNING |-->|EXECUTION|-->| REPORTING |-->|FOLLOW-UP| +----------+ +---------+ +----------+ +---------+
Definition: Audit evidence is the information that auditors gather to support their conclusions. It is like clues at a crime scene.
Why important: Evidence is the basis for the auditor's opinion.
Simple explanation: Evidence is the "proof" that something is correct.
Types of evidence: Documents (invoices, receipts), observations (watching a process), confirmations (asking third parties), and analytical procedures (comparing numbers).
School example: A teacher checks your test paper (document) to see if you answered correctly.
TYPES OF EVIDENCE +----------------------+ | Documents | | Observations | | Confirmations | | Analytical procedures| +----------------------+
Definition: An audit report is the final document that summarises the auditor's findings and opinion. It is like a report card for an organisation.
Why important: The audit report tells stakeholders if everything is in order or if there are issues.
Simple explanation: The audit report is the final "grade" that auditors give.
Types of opinions:
Nigerian example: The Auditor-General issues a report on the financial management of Nigerian government agencies.
AUDIT OPINIONS +----------------+----------------+ | Unqualified | Everything good| | Qualified | Minor issues | | Adverse | Major problems | | Disclaimer | Could not audit| +----------------+----------------+
Definition: Ethics in auditing means that auditors must be honest, independent, and objective. They must not be influenced by anyone.
Why important: Without ethics, audits would be unreliable and trust would be lost.
Simple explanation: Ethics means doing the right thing even when no one is watching.
Real-life example: An auditor must report a fraud even if the boss asks them to hide it.
School example: A teacher must grade fairly, without favouritism.
Home example: Parents must be fair when resolving disputes between siblings.
Nigerian example: The Financial Reporting Council of Nigeria promotes ethical standards for auditors.
ETHICS IN AUDITING +----------------------+ | Independence | | Objectivity | | Honesty | | Confidentiality | +----------------------+
Definition: The COSO framework is a model that helps organisations design effective internal controls. It has five components.
Why important: COSO provides a common language and structure for internal controls.
Simple explanation: COSO is like a recipe book for making good controls.
Components:
COSO FRAMEWORK +----------------------+ | 1. Control Environment| | 2. Risk Assessment | | 3. Control Activities| | 4. Information & Comm| | 5. Monitoring | +----------------------+
Definition: Nigerian organisations use various internal controls to protect assets and ensure compliance.
Why important: Nigeria's economy relies on effective controls to prevent fraud and mismanagement.
Simple explanation: Nigerian businesses use controls to stay safe and honest.
NIGERIAN CONTROLS +----------------------+ | Banks: Dual control | | TSA: Single account | | Internal Audit | +----------------------+
Definition: Let's understand controls and audits through games.
Example 1: Playing Monopoly โ the banker controls the money (preventive), and players count their money at the end (detective).
Example 2: A lemonade stand โ you lock the cash box (preventive), count money daily (detective), and if you find a shortage, you investigate (corrective).
GAME CONTROLS +----------------------+ | Monopoly: Banker | | Lemonade: Cash count | +----------------------+
Definition: Internal controls are everywhere in daily life, not just in organisations.
Why important: Recognising controls helps us appreciate their importance.
Simple explanation: Internal controls are part of our daily routine.
DAILY CONTROLS +----------------------+ | Alarm clock | | Passwords | | Checklists | +----------------------+
Definition: Strong internal controls bring many benefits to an organisation.
Why important: They help organisations achieve their goals efficiently and effectively.
Simple explanation: Strong controls make things better for everyone.
BENEFITS OF CONTROLS +----------------------+ | Prevent fraud | | Accurate records | | Efficiency | | Trust | +----------------------+
Use real-life objects like a lock and key to illustrate preventive controls. Use a magnifying glass to symbolise detective controls. Role-play an audit scenario where students act as auditors and auditees. Emphasise the importance of honesty and fairness.
Encourage children to identify controls at home. Ask: "What do we do to keep our house safe?" and "How do we check our spending?" Relate these to internal controls. Discuss the importance of honesty in checking work.
Did you know that the first internal auditors were employed by the British East India Company in the 1600s? They were sent to India to check the company's accounts!
CONTROL TYPES +------------------+------------------+------------------+ | Preventive | Detective | Corrective | +------------------+------------------+------------------+ | Lock doors | Check locks | Repair locks | | Passwords | Review logs | Reset passwords | | Training | Audit | Re-train | +------------------+------------------+------------------+
AUDIT PROCESS FLOW
+----------+ +----------+ +----------+ +----------+
| PLANNING |-->| FIELDWORK|-->| REPORTING|-->| FOLLOW-UP|
+----------+ +----------+ +----------+ +----------+
| | | |
+--------------+--------------+--------------+
INTERNAL CONTROL FRAMEWORK (COSO) +-----------------------------------------+ | CONTROL ENVIRONMENT | | (Culture and attitude) | +-----------------------------------------+ | RISK ASSESSMENT | | (Identify risks) | +-----------------------------------------+ | CONTROL ACTIVITIES | | (Policies and procedures) | +-----------------------------------------+ | INFORMATION & COMMUNICATION | | (Sharing information) | +-----------------------------------------+ | MONITORING ACTIVITIES | | (Reviewing controls) | +-----------------------------------------+
| Type | Preventive | Detective | Corrective |
|---|---|---|---|
| Goal | Stop problems | Find problems | Fix problems |
| Example | Lock | Alarm | Repair |
| When used | Before | During/After | After |
| Aspect | Internal Audit | External Audit |
|---|---|---|
| Who does it? | Employees | Independent |
| Frequency | Ongoing | Periodic |
| Purpose | Improvement | Compliance |
| Scope | Broad | Specific |
Congratulations! You have completed Module 6 on Internal Controls & Auditing. You learned that:
Remember, internal controls and auditing are like the safety net and the checker โ they keep organisations safe, honest, and efficient. You are now equipped with the knowledge to understand and appreciate these important practices.
| Term | Definition |
|---|---|
| 1. Preventive | A. Finds problems |
| 2. Detective | B. Fixes problems |
| 3. Corrective | C. Stops problems |
| 4. Internal Audit | D. Independent audit |
| 5. External Audit | E. Internal audit |
Answers: 1-C, 2-A, 3-B, 4-E, 5-D
Scenario 1: A school collects school fees. The principal is worried that some money might be stolen. What controls can be put in place?
Scenario 2: A company suspects that some employees are taking office supplies home. What detective and preventive controls can be implemented?
In groups, design an internal control system for a school tuck shop. Include preventive, detective, and corrective controls. Present your design to the class.
Think of a daily routine (e.g., brushing teeth, doing homework). Identify one preventive, one detective, and one corrective control you use in that routine.
Create a poster showing a "Control Cycle" โ from preventive to detective to corrective controls. Use illustrations and examples.
Conduct a mini-audit of your classroom. Check attendance records, cleanliness, and equipment. Write a one-page report with findings and recommendations.
Imagine you are the auditor of a company. Prepare a mock audit report for a fictional company. Include an opinion and recommendations.
All answers are provided within the module (see multiple choice, matching, and true/false sections).
In Module 7, we will learn about Information Security and Cybersecurity. You will discover how to protect information from hackers and threats. The concepts of controls and auditing will be very helpful!
See you in Module 7! ๐
Welcome to Module 7! In this module, we will learn about Information Security and Cybersecurity. These are like the locks and guards that protect our digital world.
Imagine your personal diary. You would not want anyone to read it without your permission. In the same way, we need to protect our information โ like passwords, photos, and bank details โ from people who should not see them.
In this module, you will learn how to keep information safe, how to spot dangers online, and how to protect yourself and your organisation from cyber attacks. By the end, you will be a cybersecurity hero!
By the end of this module, you will be able to:
Once upon a time, there was a girl named Ada. Ada loved playing online games and sharing photos with her friends. She had an account on a popular social media platform.
One day, Ada received an email that looked like it was from her game. The email said: โYour account has been compromised. Click here to verify your password.โ Ada clicked the link and entered her password.
The next day, Ada couldn't log in. Someone had changed her password and was posting strange things on her account. Ada was sad and confused. She had been phished โ tricked into giving away her password.
Ada told her parents, and they helped her report the problem. They also taught her about cybersecurity. Ada learned to never click on suspicious links and to use strong passwords. She became a cybersecurity expert and now helps others stay safe online.
This story shows that we all need to be careful online. Cybersecurity is our shield against digital dangers.
Definition: Information security is the practice of protecting information from unauthorised access, use, disclosure, disruption, modification, or destruction.
Why important: Information is valuable. If it falls into the wrong hands, it can cause harm โ like identity theft or financial loss.
Simple explanation: Information security is like keeping your secrets safe.
Real-life example: A hospital protects patient records so only doctors can see them.
School example: Your school keeps your grades confidential โ only you and your teacher can see them.
Home example: You have a password on your tablet to protect your photos.
Nigerian example: Banks in Nigeria use encryption to protect customers' financial data.
INFORMATION SECURITY +----------------------+ | Confidentiality | | Integrity | | Availability | +----------------------+
Definition: Cybersecurity is the practice of protecting computers, networks, and data from digital attacks.
Why important: We live in a digital world. Cyber attacks can disrupt businesses, steal money, and invade privacy.
Simple explanation: Cybersecurity is like a digital bodyguard for your devices.
Real-life example: A company uses firewalls and antivirus software to protect its network.
School example: Your school uses filters to block inappropriate websites.
Home example: You have antivirus software on your computer.
Nigerian example: The Nigerian Communications Commission (NCC) promotes cybersecurity awareness.
CYBERSECURITY +----------------------+ | Protect devices | | Secure networks | | Guard data | +----------------------+
Definition: The CIA triad is a model that guides information security. It stands for Confidentiality, Integrity, and Availability.
Why important: All three are essential for strong security.
Simple explanation: CIA is like the three legs of a stool โ if one is weak, the stool falls.
Real-life example: A bank keeps customer balances confidential (C), accurate (I), and available for transactions (A).
CIA TRIAD +----------------------+ | Confidentiality | | Integrity | | Availability | +----------------------+
Definition: Malware is malicious software designed to damage or disrupt devices. It is like a digital virus that makes your computer sick.
Why important: Malware can steal data, spy on you, or lock your files.
Simple explanation: Malware is a bad program that harms your device.
Types: Viruses, worms, trojans, ransomware, spyware.
Real-life example: A ransomware attack locks your files and demands payment.
School example: A computer lab gets a virus from a USB drive.
Home example: Your computer slows down because of spyware.
Nigerian example: Some Nigerian businesses have been hit by ransomware.
MALWARE TYPES +----------------------+ | Viruses | | Worms | | Trojans | | Ransomware | | Spyware | +----------------------+
Definition: Phishing is a trick where attackers pretend to be a trustworthy entity to steal your information, like passwords or credit card numbers.
Why important: Phishing is very common and can fool even smart people.
Simple explanation: Phishing is like a fake fishing hook โ the bait looks real, but it's dangerous.
How it works: You receive an email or message that looks real, but it's from a hacker. You click a link and enter your details, which are stolen.
Real-life example: An email claiming to be from your bank asks you to verify your password.
School example: A student receives a fake message from the school asking for their login details.
Home example: A parent receives a fake invoice asking them to pay.
Nigerian example: โYahoo Yahooโ boys often use phishing to scam people.
PHISHING PROCESS +----------+ +----------+ +----------+ | FAKE EMAIL|-->| CLICK LINK|-->| STEAL DATA| +----------+ +----------+ +----------+
Definition: Authentication is the process of verifying who you are. A password is a common form of authentication.
Why important: Strong authentication prevents unauthorised access.
Simple explanation: Authentication is like showing your ID to enter a building.
Best practices for passwords:
Real-life example: An ATM requires your PIN (first factor) and your card (second factor).
AUTHENTICATION FACTORS +----------------------+ | Something you know | (password) | Something you have | (phone, token) | Something you are | (fingerprint) +----------------------+
Definition: Social engineering is a psychological manipulation technique where attackers trick people into revealing confidential information.
Why important: Humans are often the weakest link in security.
Simple explanation: Social engineering is like a con artist who tricks you into giving away secrets.
Examples: An attacker calls pretending to be IT support and asks for your password.
School example: A stranger asks a student for their school ID number.
Home example: Someone calls saying they are from your phone company and need your account details.
Nigerian example: Scammers often use social engineering to defraud people.
SOCIAL ENGINEERING +----------------------+ | Manipulate trust | | Exploit human nature | | Extract information | +----------------------+
Definition: Data protection involves safeguarding personal information from misuse, unauthorised access, and breaches.
Why important: Everyone has the right to privacy. Data protection laws enforce this.
Simple explanation: Data protection is about respecting people's privacy.
Key principles:
Real-life example: A website asks for your email but promises not to share it.
Nigerian example: The Nigeria Data Protection Regulation (NDPR) protects citizens' data.
DATA PROTECTION PRINCIPLES +----------------------+ | Collect only needed | | Keep secure | | Obtain consent | | Delete when done | +----------------------+
Definition: Encryption is the process of converting information into a code to prevent unauthorised access. It is like a secret language that only authorised people can understand.
Why important: Encryption protects data even if it is intercepted.
Simple explanation: Encryption turns your message into a puzzle that only the right person can solve.
Real-life example: When you send a message on WhatsApp, it is encrypted.
School example: Your school uses encryption to store student records.
Home example: Your Wi-Fi network uses encryption to protect your internet traffic.
Nigerian example: Banks use encryption to secure online transactions.
ENCRYPTION PROCESS
+----------+ +----------+ +----------+
| Plain text|-->| ENCRYPT |-->| Cipher text|
+----------+ +----------+ +----------+
| |
+---------------+--+
|
+----------+ +----------+ +----------+
| Plain text|<- | DECRYPT |<- | Cipher text|
+----------+ +----------+ +----------+
Definition: A firewall is a network security device that monitors and controls incoming and outgoing network traffic. Antivirus software detects and removes malware.
Why important: They are essential defences against cyber threats.
Simple explanation: A firewall is like a security guard at the door, and antivirus is like a doctor that cures infections.
Real-life example: A company uses a firewall to block malicious traffic and antivirus to scan emails.
School example: Your school's network has a firewall to block inappropriate content.
Home example: You have antivirus software on your family computer.
FIREWALL AND ANTIVIRUS +----------------------+ | Firewall: Gatekeeper | | Antivirus: Healer | +----------------------+
Definition: Cybersecurity governance is the framework that ensures an organisation has a clear strategy and accountability for cybersecurity.
Why important: Without governance, cybersecurity efforts can be ad-hoc and ineffective.
Simple explanation: Cybersecurity governance is like having a captain who leads the ship safely.
Components:
Real-life example: A company has a Chief Information Security Officer (CISO) responsible for security.
CYBERSECURITY GOVERNANCE +----------------------+ | Policies | | Risk Management | | Incident Response | | Training | +----------------------+
Definition: Incident response is the process of handling a security breach or attack. It is like an emergency plan for a fire.
Why important: A quick and effective response minimises damage.
Simple explanation: Incident response is your game plan for when things go wrong.
Steps:
School example: If a school's website is hacked, they have a plan to take it offline and fix it.
INCIDENT RESPONSE STEPS
+----------+ +----------+ +----------+
| PREPARE |-->| IDENTIFY |-->| CONTAIN |
+----------+ +----------+ +----------+
| | |
+----------+ +----------+ +----------+
| ERADICATE|-->| RECOVER |-->| LESSONS |
+----------+ +----------+ +----------+
Definition: Nigeria has established several initiatives to enhance cybersecurity.
Why important: These initiatives protect national security and economic interests.
Simple explanation: Nigeria is building a digital shield for its citizens.
NIGERIAN CYBERSECURITY +----------------------+ | NCC: Awareness | | NITDA: Policies | | Cybercrimes Act | | National Policy | +----------------------+
Definition: Let's use fun scenarios to understand cybersecurity.
Example 1: A treasure hunt โ you have a map (data), you use a code (encryption), and you have a password to unlock the chest (authentication).
Example 2: Playing a video game โ you have a character (digital identity), you need to avoid viruses (malware), and you use a shield (firewall) to protect yourself.
GAME CYBERSECURITY +----------------------+ | Map: Data | | Code: Encryption | | Key: Password | | Shield: Firewall | +----------------------+
Definition: Cybersecurity is not just for big companies โ it is for everyone.
Why important: We all have personal information that needs protection.
Simple explanation: Cybersecurity is part of our daily digital life.
DAILY CYBERSECURITY TIPS +----------------------+ | Strong passwords | | Careful with links | | Update software | | Secure Wi-Fi | | Backup data | +----------------------+
Use interactive activities like โspot the phishing emailโ or โcreate a strong password.โ Emphasise that cybersecurity is everyone's responsibility. Relate concepts to school rules and personal safety. Encourage students to share their experiences.
Talk to your children about online safety. Set rules for internet use. Use parental controls to filter content. Lead by example โ follow cybersecurity best practices yourself. Encourage open communication about any suspicious online activity.
Did you know that the world's first ransomware attack happened in 1989? It was called the AIDS Trojan, and it demanded a payment of $189 to unlock files!
CYBERSECURITY DEFENCE IN DEPTH +-----------------------------------------+ | LAYER 1: Physical | | (locks, guards) | +-----------------------------------------+ | LAYER 2: Network | | (firewalls, VPN) | +-----------------------------------------+ | LAYER 3: Host | | (antivirus, patches) | +-----------------------------------------+ | LAYER 4: Application | | (secure coding, authentication) | +-----------------------------------------+ | LAYER 5: Data | | (encryption, backups) | +-----------------------------------------+
PHISHING ATTACK FLOW
+----------+ +----------+ +----------+ +----------+
| ATTACKER |-->| FAKE EMAIL|-->| VICTIM |-->| STEAL |
+----------+ +----------+ +----------+ +----------+
| | | |
+--------------+--------------+--------------+
CYBERSECURITY FRAMEWORK (NIST) +----------+ +----------+ +----------+ +----------+ +----------+ | IDENTIFY |-->| PROTECT |-->| DETECT |-->| RESPOND |-->| RECOVER | +----------+ +----------+ +----------+ +----------+ +----------+
| Threat | Description | Prevention |
|---|---|---|
| Malware | Malicious software | Antivirus, updates |
| Phishing | Fake communications | Verify sender, don't click links |
| Social Engineering | Psychological trick | Awareness, verify identities |
| Aspect | Information Security | Cybersecurity |
|---|---|---|
| Scope | All information | Digital information |
| Focus | Data protection | Network and device protection |
| Examples | Paper records, physical files | Online accounts, networks |
Congratulations! You have completed Module 7 on Information Security and Cybersecurity. You learned that:
Remember, cybersecurity is like a superpower โ it protects us and helps build trust in the digital world. You are now equipped to be a cybersecurity champion!
| Term | Definition |
|---|---|
| 1. Confidentiality | A. Data is accurate |
| 2. Integrity | B. Data is accessible |
| 3. Availability | C. Data is only seen by authorised people |
| 4. Malware | D. Trick to steal information |
| 5. Phishing | E. Malicious software |
Answers: 1-C, 2-A, 3-B, 4-E, 5-D
Scenario 1: You receive an email from "Your Bank" asking you to update your password by clicking a link. The email has several spelling errors. What should you do?
Scenario 2: A friend asks you to share your Netflix password. They promise not to tell anyone. What should you do?
In groups, create a short skit demonstrating a phishing attack and how to avoid it. Perform it for the class.
Create a "Cybersecurity Tips" poster for your home or classroom. Include tips on passwords, phishing, and software updates.
Design a "Cybersecurity Awareness Campaign" for your school. Include posters, announcements, and a presentation. Present your campaign to the class.
Conduct a cybersecurity audit of your home network. Check if you have antivirus, a firewall, and secure passwords. Write a one-page report with recommendations.
Imagine you are a cybersecurity consultant. Create a cybersecurity policy for a fictional small business. Include password policies, data protection, and incident response.
All answers are provided within the module (see multiple choice, matching, and true/false sections).
In Module 8, we will learn about Business Continuity and Disaster Recovery. You will discover how organisations prepare for and recover from emergencies. The concepts of risk management and controls will be very helpful!
See you in Module 8! ๐