Practitioner Certificate in Information Risk Management
Course Title
Practitioner Certificate in Information Risk Management
Code: CIRM/105
Dates: See Course Schedule
Duration: 5 days
Fee: Contact us for current prices
Description
This training course on Information Risk Management is intended for (but not limited to) those who are involved in the areas of information security and information assurance.
The Information Risk Management training contains a number of practical sessions, designed to build on the ‘taught’ components of the course, and to encourage debate and the sharing of knowledge and experience between students.
The Information Risk Management training course promotes a hands-on approach to Information Risk Management, making use of current international standards, enabling students to make immediate use of the training on their return to their organisations.
Objectives
On completion of the Information Risk Management training, delegates will have a detailed understanding of :
- How the management of information risk will bring about significant business benefits
- How to explain and make full use of information risk management terminology
- How to conduct threat and vulnerability assessments, business impact analyses and risk assessments
- The principles of controls and risk treatment
- How to present the results in a format which will form the basis of a risk treatment plan
- The use of information classification schemes
Target audience of the Information Risk Management Training course
- Individuals responsible for risk analysis and management of information systems
- Individuals who need to understand information risk analysis, assessment and management
- Those needing to make business risk decisions according to the principles of corporate governance
- Security and risk management personnel; business managers; risk decision makers; project and programme managers
Prerequisites
A general understanding of information assurance; no formal qualifications required
Information Risk Management Training Course synopsis
Concepts & Importance of information risk management
- The need for information risk management
- The context of risk in the business
- Review of information security fundamentals
The information risk management environment
- Developing an information risk management strategy
- Information risk management, risk assessment and risk treatment
- Assets
- Information risk management terminology
Stages of information risk management
- Setting the scope
- Business Impact Analysis
- Threat and vulnerability assessment
- Risk determination
- Information risk management controls
Action and implementation
- Information risk management methodologies
- Risk reporting and presentation
- Decision making
- Risk treatment
- Risk monitoring
Information classification schemes
- Classification process
- Classification issues
- Typical classification schemes
Note: – ISEB Accreditation in progress







