Training Module
Information Security Risk Management
Build the capability to make the organisation's information security risk position visible, owned and defensible
Overview
Many ISMS risk registers look complete until a real decision is needed. This module uses the evolving Northstar case to connect business processes, services, primary and supporting information assets, threats, vulnerabilities, control gaps and weak signals to assessment and treatment decisions.
The focus is practical ISMS judgement, not scoring theatre, tool configuration or a control-by-control walkthrough. Participants practise improving risk statements, applying criteria, explaining control rationale, checking SoA traceability, documenting residual-risk acceptance and setting review triggers.
Applicable environments
This module applies to organisations implementing or operating an information security management system (ISMS) in line with ISO/IEC 27001. It focuses on how the standard’s requirements are interpreted and applied in practice within real organisational contexts.
The content is relevant for organisations seeking certification as well as for those using ISO/IEC 27001 as a reference framework to structure responsibilities, processes, and controls in the information security domain.
Target audience
People involved in designing, building, operating, or improving an ISMS aligned with ISO/IEC 27001
Executives and department heads accountable for the effectiveness and performance of an ISMS
Those responsible for processes, policies, assets, risks, and controls related to information security
Auditors of ISO/IEC 27001 who want to deepen their understanding of management-side best practices (not audit technique)
Decision support
Is this module for you?
Agenda
ISMS risk decision trail
Services, assets and exposure
Risk statements and criteria
Assessment judgement and weak signals
Treatment options and control rationale
SoA traceability and residual risk
Review, reporting and assurance
Show detailed agenda...
Learning outcomes
Key outcomes
Identify information security risks from business processes, services, information assets, threats, vulnerabilities and control gaps
Assess ISMS risks using criteria, evidence confidence, weak signals and inherent/current/residual risk distinctions
Translate risk assessment into treatment choices, control rationale, SoA traceability and residual-risk acceptance
Additional capabilities
Distinguish primary information assets, supporting assets, owners, controls, dependencies and assurance needs
Repair vague risk statements and inconsistent criteria so risk artefacts become decision-ready
Use incidents, supplier signals, access exceptions and customer questions as reassessment triggers
Prepare risk information, indicators and assurance wording for management review
Use AI support to challenge artefacts and cluster weak signals without outsourcing accountability
Materials
Learning materials
Slide deck
Participant workbook
Templates & tools
Practical, reusable artefacts to apply the module directly to your organisation.
Information security risk management process and role template
Business process, service and asset exposure mapping worksheet
ISMS risk statement and register template
ISMS risk criteria quality checklist
Treatment, control rationale and SoA traceability worksheet
Residual risk acceptance and review trigger template
AI prompt set and safeguards checklist for ISMS risk review
Confirmation
Certificate of completion
Overview
Dates
Bespoke
Module ID
HAM-IS-S-02
Discipline
ISO standard
Standard clause
6: Planning
8: Operation
Target audience
Delivery
Live virtual delivery
This module is delivered live online and combines conceptual framing, discussion, case work and direct interaction with the instructor.
Custom delivery options
For organisations with specific constraints or learning objectives, the module can be adapted in format or scope, including in-house delivery and contextualised case material.
Upcoming course runs
A public cohort is currently not scheduled. If you register your interest, we will notify you when a new public cohort is scheduled or suitable delivery options become available.
For an optimal learning experience
Prerequisites & preparation
This module is designed as part of a modular training approach. Topics are deliberately distributed across modules and are not repeated in full, in order to avoid unnecessary redundancy. Each module is self-contained and can be taken on its own. Where prior knowledge or experience is helpful, this is indicated below so you can decide whether any preparation is useful for you.
Assumed background
No formal prerequisites. The module teaches the risk-management foundations needed for the ISMS case through concrete case artefacts.
Helpful background includes:
General familiarity with information security or management-system work
Basic understanding of organisational processes, roles and decision-making
Experience discussing organisational risks and trade-offs is useful but not required
Preparatory modules
Supporting modules (optional)
Helpful if you want to deepen related skills, but not required to participate effectively.


