Get in Touch
 Duration 35 hours (5 days)

Course Outline

The curriculum covers training objectives, module details, learning hours, and a recommended reading list:

Access the latest syllabus (PDF)

Course Outline Summary:

1. Concepts and Framework of Information Risk Management

  • The necessity of information risk management within the information lifecycle
  • The role of risk in organizational contexts

2. Fundamentals of Information Risk Management

  • Core principles of information security
    • Confidentiality, integrity, and availability (CIA)
    • Accountability, non-repudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
    • Distinguishing between information security, cyber security, information risk management, and information assurance
  • Standards and best practice guides for information risk management
  • The information risk management process
    • The four key stages: establishing context; risk assessment (including identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
    • Risk management methodologies
  • Information risk terminology and definitions
    • Defining concepts such as threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk.
    • Strategic risk treatment options, including avoidance/termination, reduction/modification, transference/sharing, acceptance/tolerance, and retention

3. Establishing an Information Risk Management Programme

  • Requirements for a robust information risk management programme
    • The Plan-Do-Check-Act (PDCA) model, also known as the Deming Cycle
  • Developing a strategic approach to information risk management
  • Principles of information classification

4. Risk Identification

  • Identifying information assets (both tangible and intangible)
  • Performing business impact analyses
  • Executing threat and vulnerability assessments

5. Risk Assessment

  • Conducting risk analysis
    • Differentiating between qualitative, quantitative, and semi-qualitative risk analysis and their appropriate applications
    • Distinctions between generic and specific risk analyses
    • Creating and utilizing a risk matrix
  • Carrying out risk evaluation

6. Risk Treatment

  • Describing risk treatment options, controls, and processes
    • The four strategic risk treatment options: avoidance/termination, reduction/modification, transference/sharing, acceptance/toleration, and retention
    • Purposes of tactical risk treatment controls: prevention, detection, correction, direction, elimination, impact minimization, monitoring and awareness, deterrence, and recovery
    • Three types of operational risk treatment controls: procedural/people, physical/environmental, and technical/logical
  • Explaining the utilization of a risk treatment plan

7. Monitoring and Review

  • Understanding information risk monitoring
  • Performing information risk reviews

8. Presenting Risks and Business Cases

  • Reporting on and presenting the progress of a risk management programme
  • Presenting a business case

NobleProg is an accredited training provider for BCS.

This course is delivered by an expert NobleProg trainer who has been approved by BCS.

The fee includes instruction on the full course syllabus by an approved BCS trainer and access to the BCS CIRM exam. The exam can be taken remotely at your convenience and is centrally invigilated by BCS. Upon successfully passing the exam (a multiple-choice format requiring a minimum score of 65%), participants will earn the accredited BCS Practitioner Certificate in Information Risk Management (CIRM).

Requirements

While there are no strict formal entry requirements, participants are expected to possess a foundational understanding of information assurance.

It is beneficial for candidates to have familiarity with relevant regulations impacting information risk management, such as Data Protection or Freedom of Information laws. This qualification is specifically designed for Information Risk Managers and professionals responsible for information management across both public and private sectors.

Number of participants


Price per participant

Testimonials (3)

Upcoming Courses

Related Categories