1
Introduction to the principles and framework of ISO 31000
- Standards and regulatory framework: ISO 31000, ISO/TR 301004, ISO/IEC 31010, NIST 800-30, COSO ERM.
- Introduction to the principles and concepts of ISO 31000: Advantages, types of risks.
- Organizational framework of risk management: Design, implementation, continuous improvement.
- Initiating the implementation of the risk management process.
Case study
Risk management principles. Risk management framework and process. Implementation of risk management.
2
Risk management process based on ISO 31000
- Establishing the context: Stakeholders, requirements, objectives, criteria, scope.
- Identifying risks: Assets, risk events and sources, existing security measures, consequences.
- Risk analysis: Consequences, probability, risk level.
- Risk assessment: Risk assessment and prioritization criteria.
- Risk mitigation: Activities, options, mitigation plan, residual risk.
- Accepting risk and managing residual risks.
- Communication and cooperation on risks: Communication plan.
- Risk tracking and review. Continuous improvement of risk management.
Case study
Establishing the context. Risk analysis. Risk mitigation option. Risk monitoring.
3
Risk assessment techniques
- Risk assessment techniques based on ISO/IEC 31010.
- Brainstorming, decision tree, bowie, AIA, FMEA, FMECA, causes-effects, consequence/likelihood matrix.
Case study
Applicable techniques for risk identification and assessment.
4
Certification exam
- Overview of the ISO 31000 PECB certification scheme.
- Fundamental principles and concepts of risk management.
- Risk management framework and process.
- Risk management techniques according to ISO/IEC 31010.
Exam
The seven competency domains are covered by the exam.