Certificate
Course Outline
The syllabus encompasses training objectives, detailed module descriptions, learning hours, and a recommended reading list:
Summary outline:
1. The concepts and framework of information risk management
- The necessity of information risk management (including the lifecycle of information).
- The context of risk within organizations.
2. Information risk management fundamentals
- The fundamentals of information security.
- Confidentiality, integrity, and availability (CIA).
- Accountability, nonrepudiation, authenticity, privacy, secrecy, identification, resilience, and reliability.
- Differentiating between information security, cyber security, information risk management, and information assurance.
- Information risk management standards and good practice guides.
- The process of information risk management.
- The four stages of information risk management: establishing context; conducting risk assessment (identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review.
- Risk management methodologies.
- Information risk terms and definitions.
- The meaning of threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk.
- Strategic risk treatment options, including risk avoidance or termination, risk reduction or modification, risk transference or sharing, risk acceptance or tolerance, and risk retention.
3. Establishing an information risk management programme
- The requirements of an information risk management programme.
- The Plan-Do-Check-Act model, also known as the Deming Cycle.
- Developing a strategic approach to information risk management.
- The principles of information classification.
4. Risk identification
- Identifying information assets (both tangible and intangible).
- Conducting a business impact analysis.
- Conducting threat and vulnerability assessments.
5. Risk assessment
- Undertaking risk analysis.
- Distinguishing between qualitative, quantitative, and semi-qualitative risk analysis and their appropriate applications.
- Differentiating between generic and specific risk analyses.
- Constructing and utilizing a risk matrix.
- Conducting risk evaluation.
6. Risk treatment
- Explaining risk treatment options, controls, and processes.
- The four strategic risk treatment options: risk avoidance or termination; risk reduction or modification; risk transference or sharing; and risk acceptance, toleration, or retention.
- Tactical risk treatment control purposes: prevention, detection, correction, direction, elimination, impact minimization, monitoring and awareness, deterrence, and recovery.
- Three types of operational risk treatment controls: procedural/people, physical/environmental, and technical/logical.
- Explaining the use of a risk treatment plan.
7. Monitor and review
- Explaining information risk monitoring.
- Undertaking an information risk review.
8. Presenting risks and business case
- Reporting and presenting the progress of a risk management programme.
- Presenting a business case.
NobleProg is a BCS Accredited Training Provider.
This course is delivered by an expert NobleProg trainer who has been approved by BCS.
The price includes delivery of the full course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at your convenience under central invigilation by BCS). Upon successfully passing the exam (a multiple-choice format requiring a minimum score of 65%), participants will receive the accredited BCS Practitioner Certificate in Information Risk Management (CIRM).
Requirements
While there are no formal entry requirements, delegates must possess a foundational understanding of information assurance.
It is advantageous for candidates to have knowledge of legislation impacting information risk management, such as Data Protection or Freedom of Information regulations. This qualification is specifically tailored for Information Risk Managers and individuals responsible for managing information assets in both the public and private sectors.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 8000 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (4)
Really enjoyed the topics covered and the way that the trainer ran the session
Richard
Course - BCS Practitioner Certificate in Data Protection
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
1. The BCS test exam questions were often incoherent or not related to the syllabus - which appears to be a trait of BCS course and exams 2. the subject matter was taught reading powerpoint slides full of text - the BCS should be providing at least some diagrammatic content and other visual aids especially as many people learn in very different ways - more than just reading text.
john - UKHO
Course - BCS Practitioner Certificate in Information Assurance Architecture (CIAA)
Speed of response and communication