Managing Risk in Information Systems

Code: 3432

5 days

List Tuition : $4,195.00 USD

Course Overview

    Download PDF 

This course provides a unique, in-depth look at how to manage and reduce IT-associated risks. You will learn about the Systems Security Certified Practitioner (SSCP) risk, response, and recovery domain in addition to risk management and its implications on IT infrastructures and compliance. Using examples and exercises, this course incorporates hands-on activities related to fundamentals of risk management, strategies, and approaches for mitigating risk. You will also learn how to create a plan that reduces risk. Additional course assets include case scenarios and handouts and eBook (via CourseSmart).


This course, written by Darril Gibson, author of the book CompTIA Security +: Get Certified, Get Ahead, covers content within the following industry certification exams:

  • Certified Information Systems Security Professional (CISSP) - two content domains covered
  • Security + - 'Compliance and Operational Security' domain covered
  • System Security Certified Practitioner (SSCP) - 'Risk, Response, and Recovery' domain covered
  • National Institute of Standards and Technology (NIST) - 'Incident Response' domain covered
  • 8570.01 - 'Compliance and Operational Security' domain covered

  • Information security analysts
  • Payroll specialists
  • IT infrastructure security specialists
  • People who decide which information technology and cybersecurity products to acquire for their organization
  • Basic concepts of and need for risk management
  • Compliancy laws, standards, best practices, and policies of risk management
  • Components of an effective organizational risk management program
  • Techniques for identifying relevant threats, vulnerabilities, and exploits
  • Risk mitigation security controls
  • Concepts for implementing risk mitigation throughout an organization
  • Perform a business impact analysis for a provided scenario
  • Create a business continuity plan (BCP) based on the findings of a given risk assessment for an organization
  • Create a disaster recovery plan (DRP) based on the findings of a given risk assessment for an organization
  • Create a computer incident response team (CIRT) plan for an organization in a given scenario

1. Risk Management Business Challenges

  • Risk Management Fundamentals
  • Managing Risk: Threats, Vulnerabilities, and Exploits
  • Maintaining Compliance
  • Developing a Risk Management Plan

2. Mitigating Risk

  • Defining Risk Assessment Approaches
  • Performing a Risk Assessment
  • Identifying Assets and Activities to Be Protected
  • Identifying and Analyzing Threats, Vulnerabilities, and Exploits
  • Identifying and Analyzing Risk Mitigation Security Controls
  • Planning Risk Mitigation Throughout the Organization
  • Turning Your Risk Assessment into a Risk Mitigation Plan

3. Risk Mitigation Plans

  • Mitigating Risk with a Business Impact Analysis
  • Mitigating Risk with a Business Continuity Plan
  • Mitigating Risk with a Disaster Recovery Plan
  • Mitigating Risk with a Computer Incident Response Team Plan

General knowledge of networking and management information systems

Request a Discounted Quote

Bring Training to You

Request schedule for this course

Request a Quote for this Class

We provide government and government contractor discounts, please request a quote


total option: 0

Hotel and Travel can be included on your quote.
For immediate response, you can call 1-855-515-2170 or we will provide a quote within 4 business hours. Travel must be booked 14 days before training for rate to apply.

Learn How to Become a Managed Learning Member

Request a Quote

Thank you for requesting a quote, we will be in touch shortly with a quote. If you need immediate assistance, please call 855-515-2170.

Request Other Date

Request date or location you need

Don’t see the date or location you need? Contact us and let us know, we are adding dates and locations daily.