
Explore how enterprise risk management integrates with risk governance, defining risk appetite, risk tolerance, and risk culture, and how the CIA SRM framework applies to information security controls.
Develop risk scenarios by analyzing internal and external factors, assess viability against business objectives, and document findings in a risk register and risk profile using top-down and bottom-up governance.
Identify, assess, and evaluate IT risk through risk scenario development, prioritizing threats and vulnerabilities, populating a risk register and risk profile aligned with governance and risk appetite.
Assess risk exposure, select response options, prioritize a risk action plan via cost-benefit analysis, and apply NIST RMF or COBIT to align inherent risk with risk appetite.
Explore risk monitoring in domain 3 by identifying risk owners, applying KPI and KRI metrics, and delivering data extraction, aggregation, analysis, and management reports.
Frame information security controls in the systems development lifecycle, detailing control types, risk-based selection, cost-benefit analysis, metrics, and governance to ensure effective risk management.
This course is provided directly by Mile2®. This official Mile2® video includes an authorized exam prep and exam simulator, available upon request.
The vendor-neutral Certified Information Systems Risk Manager certification is designed for IT and IS professionals who are involved with risk identification, assessment & evaluation, risk response, risk monitoring, IS control design & implementation as well as IS control monitoring & maintenance. The Certified Information Systems Risk Manager training will enable professionals to elevate their understanding in identifying and evaluating entity-specific risk but also aid them in assessing risks associated to enterprise business objectives by equipping the practitioner to design, implement, monitor and maintain risk-based, efficient and effective IS controls.