Course Outline
The curriculum outlines training objectives, module details and learning hours, alongside a recommended reading list:
Overview of content:
1. Concepts and framework of information risk management
- The necessity for information risk management across the information lifecycle
- The organizational context for managing risk
2. Information risk management fundamentals
- Foundational principles of information security
- Confidentiality, integrity, and availability (CIA)
- Accountability, nonrepudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
- Differentiating between information security, cyber security, information risk management, and information assurance
- Standards and best practice guides for information risk management
- The information risk management process
- The four stages: establishing context; risk assessment (identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
- Risk management methodologies
- Terminology and definitions
- Definitions for threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk
- Strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention
3. Establishing an information risk management programme
- Requirements for an information risk management programme
- The Plan-Do-Check-Act model (Deming Cycle)
- Developing a strategic approach to information risk management
- Principles of information classification
4. Risk identification
- Process for identifying information assets (tangible and intangible)
- Conducting a business impact analysis
- Performing threat and vulnerability assessments
5. Risk assessment
- Conducting risk analysis
- Distinguishing between qualitative, quantitative, and semi-quantitative risk analysis
- Differences between generic and specific risk analyses
- Construction and application of a risk matrix
- Conducting risk evaluation
6. Risk treatment
- Risk treatment options, controls, and processes
- Strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention
- Tactical risk treatment controls: prevention, detection, correction, direction, elimination, impact minimization, monitoring and awareness, deterrence, and recovery
- Operational risk treatment control types: procedural/people, physical/environmental, and technical/logical
- Utilizing a risk treatment plan
7. Monitor and review
- Overview of information risk monitoring
- Conducting an information risk review
8. Presenting risks and business case
- Reporting on the progress of the risk management programme
- Presenting a business case
NobleProg is a BCS Accredited Training Provider.
This course is delivered by an expert NobleProg trainer approved by BCS.
The price covers delivery of the full course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at the participant's convenience under central BCS invigilation). Upon successfully passing the multiple-choice exam (requiring a minimum score of 65%), participants will receive the accredited BCS Practitioner Certificate in Information Risk Management (CIRM). This credential supports professional development for government and other public sector professionals requiring formalized training in risk management practices.
Requirements
It will be advantageous for candidates to have an understanding of the laws that affect information risk management such as the Data Protection or Freedom of Information regulation. This qualification has been designed
Testimonials (4)
Really enjoyed the topics covered and the way that the trainer ran the session
Richard
Course - BCS Practitioner Certificate in Data Protection
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
1. The BCS test exam questions were often incoherent or not related to the syllabus - which appears to be a trait of BCS course and exams 2. the subject matter was taught reading powerpoint slides full of text - the BCS should be providing at least some diagrammatic content and other visual aids especially as many people learn in very different ways - more than just reading text.
john - UKHO
Course - BCS Practitioner Certificate in Information Assurance Architecture (CIAA)
Speed of response and communication