One of the challenges for information and technology (I&T) risk management is to identify important and relevant risk. The use of risk scenarios can enhance the risk management effort by assisting the risk teams understanding and explain risk to the business stakeholders. Additionally, a well-developed scenario provides a realistic and practical view of risk that is more aligned with business objectives, historical events, and emerging threats.
ISACA has developed a brief course that will help break down each aspect of a risk scenario.
By the end of this course, you’ll be able to:
- Define IT risk scenario.
- Describe the benefits of using an IT risk scenario.
- Summarize the structure of an IT risk scenario.
- Explain the key points for developing an IT risk scenario.
- Explain the importance of the risk scenario technique.
- Examine the role of a risk register in a risk scenario.
- List the four major risk responses.
- Define and describe the importance of risk assessment and risk factors.
We have included 10 scenarios with this course as an additional resource. Scenarios included in the toolkit include:
- IT Services Change Management
- Inability to Recruit or Retain IT Staff
- Inadequate Patch/Vulnerability Management
- Security Configuration Intentionally Modified
- Vendor Support Ends
- Phishing attack
- Third-Party Suppliers
- Failure to Implement Regulatory Changes
- Failure to Appreciate Value of Emerging technologies
- Unauthorize access of information
Learners will have access to the course for six months from date of purchase and will earn 1 CPE upon completion. This course has a seat time of approximately 60 minutes and is accessed via the Learning Access tab of your MyISACA dashboard.
Cancellation/Refund Policy
All purchases of online learning courses are final. Access to the online learning courses and materials is immediate upon purchasing; therefore no refunds or exchanges will be provided. Prices subject to change without notice.