
Begin by embracing IT risk management and learn the fundamental concepts across six sections, aligned with Isaca's IT Risk Fundamentals certificate, to become a well-rounded IT risk manager.
Isaca's risk definition combines likelihood and impact, visualized as a heat map or risk matrix. Risk arises when a threat exploits vulnerabilities, turning potential harm into measurable risk.
Recognize that IT risk management relies on information security and the CIA triad—confidentiality, integrity, and availability—to protect data and systems through controls.
Describe the three lines of defence in risk management: first line ownership by management, second line risk and compliance, and third line internal audits, all guided by the governing body.
outline how policies, standards, and procedures govern IT risk using the apple pie analogy, with policies setting direction, standards detailing requirements, and procedures providing recipes.
Explore risk governance and management, focusing on foresight and strategic direction to reduce risk from the core of the business.
Risk governance mirrors a ship’s navigation system by setting direction, ensuring follow-through, creating a common view of risk, integrating risk management, enabling risk-aware decisions, and verifying controls reduce risk.
Explore the risk universe to define scope for IT risk management, identify assets, the value chain, processes, and infrastructure, and ensure risk identification stays within the business objectives.
Explore the differences between risk appetite, risk tolerance, and risk capacity, visualize them with a heat map and a graph, and understand how management sets these levels across industries.
Map risk management tasks to a RACI matrix to ensure clear accountability, with a single accountable person, and avoid blame. Assign responsible, consulted, and informed roles and keep stakeholders updated.
Identify internal and external threats to IT risk management, from malicious employees to malware, and learn mitigation via background checks, access controls, exit interviews, threat assessments, and threat intelligence.
Threat intelligence collects data from diverse sources, processes it into a common format, analyzes credibility, severity, and impact, and shares findings with the security operations center to enable action.
Define risk scenarios using four elements—threat, effect, asset, and method—and scope them with top-down and bottom-up approaches to improve risk analysis and response.
Build confidence in where risks come from and the techniques to identify them; then learn how to assess risk to understand its impact on the organization.
This lecture uses an onion analogy to explain governance, risk management, and risk assessment as layers, focusing on risk identification, analysis, and evaluation.
Explore qualitative versus quantitative risk analysis, using expert judgment and heatmaps or math models to calculate annual loss expectancy for threats like DDoS attacks.
Explore Monte Carlo risk analysis to quantify vulnerability by comparing threat capability and resistance strength distributions. See how thousands of simulations reveal how stronger defenses reduce vulnerability.
Consolidate identified risks into a single risk register to provide a shared, table-like location with IDs, owners, and dates. This enables consistent comparison and richer detail beyond the risk map.
Assign a single risk owner to monitor and manage a risk in the risk registers, ensuring accountability. Oversee controls and use key risk indicators to track phishing risk.
Learn to analyze risk by evaluating its likelihood and impact, then decide on effective response options and strategies to address risk.
Explore risk responses and strategies by identifying threats, assessing likelihood and impact, and choosing transfer, accept, reduce, or avoid with examples like insurance, cloud risk, phishing controls, and GDPR.
Learn how to reduce risk by applying preventative, detective, and corrective controls across physical, technical, and administrative types.
Define inherent risk as risk existing before controls, residual risk after controls, and current risk at the moment of discussion, all documented in the risk register.
Develop a business case to justify IT risk controls by detailing the expected return on security investment (ROSI) using the annual loss expectancy, mitigation ratio, and cost of the control.
Prioritize risks with equal ratings using a cost of benefit analysis and return on security investment, with backups to prevent ransomware guiding the first action.
Learn how key risk indicators provide early warnings that prevent blind spots in risk management, distinguishing them from KPIs and illustrating lead and lag indicators with patch time examples.
Develop smart key risk indicators aligned to business objectives, using root cause analysis to ensure they are specific, measurable, attainable, relevant, and timely, tailored for CIO, CRO, and CEO.
Understand how accurate data underpins control monitoring and risk decisions by comparing security audits, vulnerability scans, and penetration tests, and learning how to distinguish their roles in assessing control effectiveness.
Master risk reporting to senior management by applying three golden rules: be impactful, visualize clearly, and keep it actionable, with tailored messages for finance, sales, and the CEO.
Complete all sections of the ISACA IT risk fundamentals course and revisit topics in any order as free updates arrive; explore Isaka's IT risk fundamentals study guide and Udemy exams.
Every organisation experiences risk. ISACA’s IT Risk Fundamentals Certificate is perfect for anyone wanting to learn about information and technology (I&T)-related risk. Our IT Risk Fundamentals course covers the fundamentals of risk management; from identifying and prioritising risk to responding and communicating the risk to management. You’ll learn about six functions throughout the course:
Domain 1 - Risk Introduction and Overview (5%): We start by setting a strong foundation and understanding of risk. In this domain we will cover fundamental concepts of IT risk management. We will discuss how risks links to business functions, the importance of the three lines of defense and the role of IT controls.
Domain 2 - Risk Governance and Management (15%): We will explain the structure of risk governance and management and how it's used to set a direction for a business. We will discuss risk appetite, risk tolerance, and risk capacity and introduce the risk management cycle.
Domain 3 - Risk Identification (20%): Risk identification is the process of spotting and documenting the risks a business faces. It is crucial because only identified risks can be assessed and responded to. In this domain we will talk about assets, threats, and vulnerabilities and how we can use them to identify risk.
Domain 4 - Risk Assessment and Analysis (25%): After identifying risk, the next step is to understand its impact on the business. In this domain, we will discuss the different approaches to risk assessments, how to use risk registers to document risks, and the importance of risk aggregation.
Domain 5 - Risk Response (15%): After risk has been identified and assessed, decisions need to be made about the appropriate risk response. In this domain we will discuss risk response strategies, control design and implementation and other response approaches.
Domain 6 - Risk Monitoring, Reporting and Communication (20%): The monitoring and reporting of risk play an important role in the risk management process. Indicators for risk and performance should be considered carefully and chosen deliberately, based on their alignment with enterprise goals. Because of the changing nature of risk and associated controls, ongoing monitoring and reporting are essential steps in the risk management process.