Training module

Information Security Risk Management

Build the capability to make the organisation's information security risk position visible, owned and defensible

Information SecurityManagement System Manager
Digital lock and data network visualization, representing information security risk management with structured risk assessment, risk treatment, and traceable risk decisions under ISO/IEC 27001.

Information security risk management that holds up in ISMS decisions

Develop the practical judgement behind ISO/IEC 27001 risk work: connecting business processes, services, information assets, threats, vulnerabilities and control gaps to treatment decisions, SoA rationale, residual-risk acceptance and review triggers.

Overview

What this module is about

Many ISMS risk registers look complete until a real decision is needed. This module uses the evolving Northstar case to connect business processes, services, primary and supporting information assets, threats, vulnerabilities, control gaps and weak signals to assessment and treatment decisions.

The focus is practical ISMS judgement, not scoring theatre, tool configuration or a control-by-control walkthrough. Participants practise improving risk statements, applying criteria, explaining control rationale, checking SoA traceability, documenting residual-risk acceptance and setting review triggers.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

work with ISMS risk assessment, treatment, acceptance or management review.

need risk information that explains why controls are selected, excluded or improved.

see weak risk statements, inconsistent criteria, unclear ownership or stale registers.

want to connect business processes, services and information assets to practical risk decisions.

need SoA rationale, residual-risk acceptance and assurance responses to be defensible.

It may not be the best fit if you…

want a short overview of ISO/IEC 27001 clauses only.

are mainly looking for technical hardening, penetration testing or SIEM operation.

need advanced quantitative risk modelling as the main focus.

expect a tool or template to make risk decisions without contextual judgement.

want a full SoA construction, control catalogue or audit execution course.

Agenda

What is taught

7 parts
01ISMS risk decision trail

Read risk artefacts before trusting them

Use core risk concepts through concrete ISMS records

Connect risk, treatment, SoA, acceptance and review

02Services, assets and exposure

Start top-down from business processes and services

Identify primary and supporting information assets

Use classification, criticality and dependencies as impact inputs

03Risk statements and criteria

Separate risks from issues, causes, controls and actions

Repair weak risk statements so they support decisions

Test criteria for consistency, authority and information-security relevance

04Assessment judgement and weak signals

Apply likelihood, impact and evidence confidence without false precision

Distinguish inherent, current and residual risk

Use incidents, supplier notes, access exceptions and assurance questions as reassessment inputs

05Treatment options and control rationale

Compare treatment options against risk effect, constraints and assurance value

Explain how selected controls are expected to change exposure

Clarify dependencies, limits and hand-offs to operational control

06SoA traceability and residual risk

Trace treatment decisions into SoA applicability and rationale

Find weak exclusions, optimistic implementation status and missing evidence

Record residual-risk acceptance with authority, rationale and conditions

07Review, reporting and assurance

Define reassessment triggers for changes, incidents and control signals

Prepare risk and control indicators for management review

Give customer-safe assurance without overstating the risk position

Outcomes

Learning outcomes

01

Identify information security risks from business processes, services, information assets, threats, vulnerabilities and control gaps

02

Assess ISMS risks using criteria, evidence confidence, weak signals and inherent/current/residual risk distinctions

03

Translate risk assessment into treatment choices, control rationale, SoA traceability and residual-risk acceptance

Distinguish primary information assets, supporting assets, owners, controls, dependencies and assurance needs

Repair vague risk statements and inconsistent criteria so risk artefacts become decision-ready

Use incidents, supplier signals, access exceptions and customer questions as reassessment triggers

Prepare risk information, indicators and assurance wording for management review

Use AI support to challenge artefacts and cluster weak signals without outsourcing accountability

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Scheduling

No public run of Information Security Risk Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.

Module facts

Module ID
HAM-IS-S-02
Download fact sheet (PDF, 4.6 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.

Want this module scheduled?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Information Security Risk Management · HAM-IS-S-02

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Information Security Risk Management · HAM-IS-S-02

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.