Course Outline
The syllabus encompasses training objectives, module details, allocated learning hours, and a recommended reading list:
Access the latest syllabus (PDF)
Course Summary:
1. Concepts and Framework of Information Risk Management
- The necessity of information risk management across the information lifecycle
- The role of risk within organisational contexts
2. Fundamentals of Information Risk Management
- Core principles of information security
- Confidentiality, integrity, and availability (CIA)
- Accountability, nonrepudiation, authenticity, privacy, secrecy, identification, resilience, and reliability
- Distinguishing between information security, cyber security, information risk management, and information assurance
- Standards and good practice guidelines for information risk management
- The information risk management process
- The four stages: context establishment; risk assessment (including identification, analysis, evaluation, and treatment); communication and consultation; and monitoring and review
- Various risk management methodologies
- Key terminology and definitions
- Definitions of threats, hazards, vulnerabilities, proximity, likelihood, probability, and risk.
- Strategic risk treatment options: avoidance or termination; reduction or modification; transference or sharing; acceptance or tolerance; and retention
3. Establishing an Information Risk Management Programme
- Essential requirements for a risk management programme
- The Plan-Do-Check-Act model, also known as the Deming Cycle
- Developing a strategic approach to information risk management
- Principles underlying information classification
4. Risk Identification
- Processes for identifying tangible and intangible information assets
- Executing business impact analyses
- Performing threat and vulnerability assessments
5. Risk Assessment
- Conducting risk analysis
- Distinguishing between and appropriately applying qualitative, quantitative, and semiqualitative risk analysis
- Differentiating between generic and specific risk analyses
- Building and utilising risk matrices
- Performing risk evaluation
6. Risk Treatment
- Explaining risk treatment options, controls, and processes
- The four strategic options: risk avoidance or termination; reduction or modification; transference or sharing; and acceptance or toleration or retention
- Tactical control purposes: prevention; detection; correction; direction; elimination; impact minimisation; monitoring and awareness; deterrence; and recovery
- Operational control types: procedural/people; physical/environmental; and technical/logical
- Understanding the implementation of risk treatment plans
7. Monitoring and Review
- Explanation of information risk monitoring
- Conducting information risk reviews
8. Presenting Risks and Business Cases
- Reporting on and presenting the progress of risk management programmes
- Formulating and presenting business cases
NobleProg is a BCS Accredited Training Provider.
This course is delivered by a NobleProg expert trainer approved by BCS.
The fee covers the delivery of the complete course syllabus by an approved BCS trainer and the BCS CIRM exam (which can be taken remotely at your convenience and is centrally invigilated by BCS). Upon successfully passing the exam (a multiple-choice format requiring a minimum score of 65%), participants will receive the accredited BCS Practitioner Certificate in Information Risk Management (CIRM).
Requirements
While there are no formal entry requirements, participants should possess a foundational understanding of information assurance.
Candidates would benefit from familiarity with regulations impacting information risk management, such as Data Protection and Freedom of Information laws. This qualification is specifically designed for Information Risk Managers and individuals responsible for managing information within both public and private sectors.
Custom Corporate Training
Training solutions designed exclusively for businesses.
- Customized Content: We adapt the syllabus and practical exercises to the real goals and needs of your project.
- Flexible Schedule: Dates and times adapted to your team's agenda.
- Format: Online (live), In-company (at your offices), or Hybrid.
Price per private group, online live training, starting from 6500 € + VAT*
Contact us for an exact quote and to hear our latest promotions
Testimonials (4)
Really enjoyed the topics covered and the way that the trainer ran the session
Richard
Course - BCS Practitioner Certificate in Data Protection
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
1. The BCS test exam questions were often incoherent or not related to the syllabus - which appears to be a trait of BCS course and exams 2. the subject matter was taught reading powerpoint slides full of text - the BCS should be providing at least some diagrammatic content and other visual aids especially as many people learn in very different ways - more than just reading text.
john - UKHO
Course - BCS Practitioner Certificate in Information Assurance Architecture (CIAA)
Speed of response and communication