Get in Touch

award icon svg Certificate

Course Outline

The syllabus covers training objectives, module details, allocated learning hours, and a recommended reading list:

Access the latest syllabus (PDF)

Course Overview:

1. Concepts and Framework of Information Risk Management

  • The necessity of information risk management within the information lifecycle
  • The role of risk in the organizational context

2. Fundamentals of Information Risk Management

  • Core principles of information security
    • Confidentiality, integrity, and availability (CIA)
    • Accountability, non-repudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
    • Distinguishing between information security, cyber security, information risk management, and information assurance
  • Relevant standards and best practice guides in information risk management
  • The information risk management process
    • The four stages of information risk management: context establishment; risk assessment (identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
    • Risk management methodologies
  • Terminology and definitions in information risk
    • Definitions of threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk.
    • Strategic risk treatment options, including avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention

3. Establishing an Information Risk Management Programme

  • Requirements for an effective information risk management programme
    • The Plan-Do-Check-Act model, also known as the Deming Cycle
  • Developing a strategic approach to information risk management
  • Principles of information classification

4. Risk Identification

  • Identifying information assets, both tangible and intangible
  • Performing a business impact analysis
  • Conducting threat and vulnerability assessments

5. Risk Assessment

  • Conducting risk analysis
    • Differences and appropriate applications of qualitative, quantitative, and semi-qualitative risk analysis
    • Distinguishing between generic and specific risk analyses
    • Constructing and utilizing a risk matrix
  • Executing risk evaluation

6. Risk Treatment

  • Understanding risk treatment options, controls, and processes
    • Four strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or toleration; and retention
    • Objectives of tactical risk treatment controls: prevention; detection; correction; direction; elimination; impact minimization; monitoring and awareness; deterrence; and recovery
    • Three categories of operational risk treatment controls: procedural/people; physical/environmental; and technical/logical
  • The application of a risk treatment plan

7. Monitoring and Review

  • Understanding information risk monitoring
  • Carrying out an information risk review

8. Presenting Risks and Business Case

  • Reporting and presenting the progress of a risk management programme
  • Presenting a business case

NobleProg is an accredited BCS Training Provider.

This course is taught by an expert NobleProg trainer approved by BCS.

The fee covers delivery of the full course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at your convenience and is centrally invigilated by BCS). Upon successfully passing the exam (a multiple-choice test requiring a minimum score of 65%), participants will earn the accredited BCS Practitioner Certificate in Information Risk Management (CIRM).

Requirements

While there are no formal entry requirements, participants should possess a foundational understanding of information assurance.

Candidates benefit from familiarity with legislation impacting information risk management, such as Data Protection or Freedom of Information regulations. This qualification is specifically designed for Information Risk Managers and individuals responsible for managing information within both public and private sectors.

 35 Hours

Custom Corporate Training

Training solutions designed exclusively for businesses.

  • Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
  • Flexible Schedule: Dates and times adapted to your team's agenda.
  • Format: Online (live), In-company (at your offices), or Hybrid.
Investment

Price per private group, online live training, starting from 8000 € + VAT*

Contact us for an exact quote and to hear our latest promotions

Testimonials (4)

Provisional Upcoming Courses (Contact Us For More Information)

Related Categories