Course Outline
The syllabus encompasses training objectives, module details, learning hours, and a recommended reading list:
Access the latest syllabus (PDF)
Course Summary:
1. Concepts and Framework of Information Risk Management
- The imperative for information risk management (information lifecycle)
- Understanding the risk context within organizations
2. Fundamentals of Information Risk Management
- Core information security principles:
- Confidentiality, Integrity, and Availability (CIA)
- Accountability, non-repudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
- Distinctions between information security, cyber security, information risk management, and information assurance
- Information risk management standards and best practice guides
- The information risk management process:
- The four stages: context establishment; risk assessment (identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
- Risk management methodologies
- Key information risk terminology:
- Definitions of threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk
- Strategic risk treatment options: avoidance/termination, reduction/modification, transference/sharing, acceptance/tolerance, and retention
3. Establishing an Information Risk Management Programme
- Programme requirements:
- The Plan-Do-Check-Act model (Deming Cycle)
- Developing a strategic approach to information risk management
- Principles of information classification
4. Risk Identification
- Process for identifying information assets (tangible and intangible)
- Conducting a business impact analysis
- Performing threat and vulnerability assessments
5. Risk Assessment
- Executing risk analysis:
- Differences and appropriate applications of qualitative, quantitative, and semi-qualitative risk analysis
- Distinctions between generic and specific risk analyses
- Construction and utilization of risk matrices
- Conducting risk evaluation
6. Risk Treatment
- Explaining risk treatment options, controls, and processes:
- Strategic options: avoidance/termination, reduction/modification, transference/sharing, acceptance/tolerance, and retention
- Tactical control purposes: prevention, detection, correction, direction, elimination, impact minimization, monitoring, awareness, deterrence, and recovery
- Operational control types: procedural/people, physical/environmental, and technical/logical
- Utilizing a risk treatment plan
7. Monitoring and Review
- Explaining information risk monitoring
- Conducting information risk reviews
8. Presenting Risks and Business Case
- Reporting and presenting the progress of a risk management programme
- Presenting a business case
NobleProg is an Accredited Training Provider for BCS.
This course is delivered by an expert NobleProg trainer approved by BCS.
The price covers the delivery of the full course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at your convenience and is centrally invigilated by BCS). Subject to successfully passing the exam (multiple choice, requiring a minimum score of 65%), participants will receive the accredited BCS Practitioner Certificate in Information Risk Management (CIRM).
Requirements
While there are no formal entry requirements, participants are expected to possess a foundational understanding of information assurance.
It is beneficial for candidates to have knowledge of legislation impacting information risk management, such as Data Protection or Freedom of Information regulations. This qualification is tailored for Information Risk Managers and any individuals responsible for managing information assets across both public and private sectors.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6500 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (4)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
1. The BCS test exam questions were often incoherent or not related to the syllabus - which appears to be a trait of BCS course and exams 2. the subject matter was taught reading powerpoint slides full of text - the BCS should be providing at least some diagrammatic content and other visual aids especially as many people learn in very different ways - more than just reading text.
john - UKHO
Course - BCS Practitioner Certificate in Information Assurance Architecture (CIAA)
learning about Basel
Daksha Vallabh - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
Speed of response and communication