Get in Touch

Course Outline

The curriculum outlines training objectives, module details and learning hours, alongside a recommended reading list:

The current syllabus (PDF)

Overview of content:

1. Concepts and framework of information risk management

  • The necessity for information risk management across the information lifecycle
  • The organizational context for managing risk

2. Information risk management fundamentals

  • Foundational principles of information security
    • Confidentiality, integrity, and availability (CIA)
    • Accountability, nonrepudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
    • Differentiating between information security, cyber security, information risk management, and information assurance
  • Standards and best practice guides for information risk management
  • The information risk management process
    • The four stages: establishing context; risk assessment (identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
    • Risk management methodologies
  • Terminology and definitions
    • Definitions for threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk
    • Strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention

3. Establishing an information risk management programme

  • Requirements for an information risk management programme
    • The Plan-Do-Check-Act model (Deming Cycle)
  • Developing a strategic approach to information risk management
  • Principles of information classification

4. Risk identification

  • Process for identifying information assets (tangible and intangible)
  • Conducting a business impact analysis
  • Performing threat and vulnerability assessments

5. Risk assessment

  • Conducting risk analysis
    • Distinguishing between qualitative, quantitative, and semi-quantitative risk analysis
    • Differences between generic and specific risk analyses
    • Construction and application of a risk matrix
  • Conducting risk evaluation

6. Risk treatment

  • Risk treatment options, controls, and processes
    • Strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention
    • Tactical risk treatment controls: prevention, detection, correction, direction, elimination, impact minimization, monitoring and awareness, deterrence, and recovery
    • Operational risk treatment control types: procedural/people, physical/environmental, and technical/logical
  • Utilizing a risk treatment plan

7. Monitor and review

  • Overview of information risk monitoring
  • Conducting an information risk review

8. Presenting risks and business case

  • Reporting on the progress of the risk management programme
  • Presenting a business case

NobleProg is a BCS Accredited Training Provider.

This course is delivered by an expert NobleProg trainer approved by BCS.

The price covers delivery of the full course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at the participant's convenience under central BCS invigilation). Upon successfully passing the multiple-choice exam (requiring a minimum score of 65%), participants will receive the accredited BCS Practitioner Certificate in Information Risk Management (CIRM). This credential supports professional development for government and other public sector professionals requiring formalized training in risk management practices.

Requirements

There are no formal entry requirements however, delegates will require an understanding of information assurance.

It will be advantageous for candidates to have an understanding of the laws that affect information risk management such as the Data Protection or Freedom of Information regulation. This qualification has been designed for government Information Risk Managers and all those who have responsibility for managing information, whether in the public or the private sector.

 35 Hours

Number of participants


Price per participant

Testimonials (4)

Upcoming Courses

Related Categories