Get in Touch
 Duration 35 hours

Course Outline

The curriculum covers training objectives, module details, estimated learning hours, and a recommended reading list:

View the latest syllabus (PDF)

Course summary:

1. Concepts and framework of information risk management

  • The necessity of information risk management in relation to the information lifecycle.
  • The organizational context of risk.

2. Fundamentals of information risk management

  • Core principles of information security:
    • Confidentiality, integrity, and availability (CIA).
    • Accountability, non-repudiation, authenticity, privacy, secrecy, identification, resilience, and reliability.
    • Distinguishing between information security, cyber security, information risk management, and information assurance.
  • Standards and best practice guides in information risk management.
  • The information risk management process:
    • The four key stages: establishing context, risk assessment (identification, analysis, evaluation, and treatment), communication and consultation, and monitoring and review.
    • Applicable risk management methodologies.
  • Terminology and definitions in information risk:
    • Defining concepts such as threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk.
    • Strategic risk treatment options, including avoidance/termination, reduction/modification, transference/sharing, acceptance/tolerance, and retention.

3. Establishing an information risk management program

  • Requirements for a comprehensive program:
    • Application of the Plan-Do-Check-Act (PDCA) model, also known as the Deming Cycle.
  • Developing a strategic approach to managing information risk.
  • Principles of information classification.

4. Risk identification

  • Processes for identifying information assets, both tangible and intangible.
  • Conducting business impact analyses.
  • Performing threat and vulnerability assessments.

5. Risk assessment

  • Executing risk analysis:
    • Differences and appropriate applications of qualitative, quantitative, and semi-qualitative risk analysis.
    • Distinguishing between generic and specific risk analyses.
    • Constructing and utilizing risk matrices.
  • Conducting risk evaluation.

6. Risk treatment

  • Explaining risk treatment options, controls, and processes:
    • The four strategic options: avoidance/termination, reduction/modification, transference/sharing, acceptance/toleration, and retention.
    • Purposes of tactical controls: prevention, detection, correction, direction, elimination, impact minimization, monitoring, awareness, deterrence, and recovery.
    • Three types of operational controls: procedural/people, physical/environmental, and technical/logical.
  • Utilizing risk treatment plans.

7. Monitor and review

  • Understanding information risk monitoring.
  • Conducting information risk reviews.

8. Presenting risks and the business case

  • Reporting on and presenting the progress of risk management programs.
  • Presenting a compelling business case.

NobleProg is an accredited training provider for BCS.

The course is instructed by a BCS-approved NobleProg expert trainer.

The fee includes delivery of the full syllabus by a BCS-approved trainer and the BCS CIRM exam. The exam can be taken remotely at your convenience under central invigilation by BCS. Upon passing the multiple-choice exam (minimum score of 65%), participants will earn the BCS Practitioner Certificate in Information Risk Management (CIRM).

Requirements

While there are no formal entry prerequisites, participants must possess a foundational understanding of information assurance.

Having familiarity with relevant legislation, such as Data Protection or Freedom of Information regulations, is beneficial. This qualification is specifically designed for Information Risk Managers and individuals responsible for information management within both public and private sectors.

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories