Faculty Training Institute

FACULTY TRAINING INSTITUTE


Growing Knowledge Professionals

        >>   home >  Course Portfolio  Information Systems Risk Management

 

 

Course Code


ISRM

 

 

Duration


2 day course

 

 

Target Audience


The course will be of direct benefit to anyone whose job involves designing or specifying business systems, processes, business rules and procedures, or managing information systems effort in the organisation.

Typical delegates include business analysts, project managers, users, steering committee members, process modelers, managers and analysts, quality and risk managers, auditors and knowledge managers.

The course is not sufficient for delegates whose core function is risk management, such as auditors or specialist risk managers, although it will serve as an introduction to those topics. Instead it is best suited for delegate for whom an understanding of risk will add value to the quality of the work that they deliver.

 

 

Comments from Past delegates


“Great interaction between participants and very realistic case studies”
SB

“I now have a process which I can apply as a tool to assist me”
NG

“The course covered advanced concepts with advanced candidates”
DB

“The content was excellent and pitched at the correct target audience”
DB

“Very useful & well presented”
EO

“Practical advice and good procedures to follow to identify, document risk and record mitigating actions”
LB

“Challenging and thought provoking”
SL

 

 

 


 

Information Systems Risk Management

Print This Page

Develop vital risk management skills that will help you reduce the negative business impacts caused by weaknesses in your organisation's information systems and processes

 

Course Objectives:

  • Understand and articulate the risks to business from the deployment of information systems

  • Be able to describe the risk management landscape

  • Describe the importance of identifying and managing IS-related risk and security issues in organisations

  • Develop strategies for IS risk management,

  • Recognise the relevance of both human and organisational factors to IS risk

  • Be able to conduct a systems risk assessment and identify controls and measures for risk mitigation and management

Course Overview

With the modern worlds’ increasing dependence on technology-based information systems, the implications of system failure can be profound. Revenue loss, inconvenience, damage to company image, a decline in productivity and complete closures are only some of the possible consequences which can result.

Often companies focus major effort in reducing risks such as fraud or network security breaches but fail to adequately consider the more common risks such as processing errors, information integrity loss and performance issues. Companies also need to encourage an enterprise-wide risk culture

This course focuses on those risks related to the use of information systems in the enterprise and emphasizes that intrinsic controls and risk prevention measures can be designed into systems and processes from the outset.

 

Course Delivery

The course comprises instructor-led training, supplemented by readings, exercises and practical group work.

 

Course Prerequisites

Past candidates have been drawn from a wide variety of backgrounds.  However, the more practical work experience a delegate has, and the more involved they are  in the implementation of information systems projects, the more benefit they will derive from the course.

Course Assessment

There are no formal assessments (exams, tests, presentations etc.) for this course. However, to earn a certificate of attendance, delegates will be required to:

  • attend both course days,

  • actively participate in exercises and discussion workshops.

 

Course Accreditation

FTI was the first IIBA Endorsed Education Provider (EEP) in South Africa, and is the only EEP in SA to hold Charter Status.

Faculty Training Institute was approved as an Approved Education & Training Provider with the ISETT SETA in January 2003. FTI is currently in the process of applying for full accreditation, conditional on the future structure of SAQA and the National Qualifications Framework (NQF). FTI is also actively engaged with various Skills Governing Bodies (SGBs) in ISETT to develop standards and qualifications

This course falls into a category loosely defined by SAQA as ‘vocational short courses’ because it requires less than a year’s full-time study. Academically and intellectually, the course is done at senior undergraduate level, which would equate to level 5-6 on the NQF.  


Course Content

Day 1:

Risk Management Concepts
Components of risk and related constructs, The typical risk management process

Risk Management in the enterprise
Why it is important for organisations to consider risk; Impact of human and organisational factors on risk identification and management; The implications of empowerment, autonomy, decentralisation and organisational culture

Risk Mitigation Measures/ Controls design
The concept of layered control strategies, including the concepts of physical, procedural and embedded control; Business Continuity Management (BCM)

Day 2:

Focus on Information Systems Risks
Taxonomies of IS Risk; Identifying and managing common IS risks, Conducting a Risk assessment; Identify prevention methods; Key types of IS controls including batching, access control, validation, etc

Focus on Fraud and economic crimes
Risks that flow from information abuse, including identity theft, phishing, disclosure, spam, etc. Key controls for preventing economic fraud.
 


© 2010
Faculty Training Institute
Disclaimer

       

Back to
the Top

PO Box 46963, Glosderry, 7702 National ShareCall  (0860 CAREER)   0860 227 337 info@fti.co.za

Cape Town
FTI House, Greenford Office Estate, Punters Way,
Kenilworth, Cape Town, 7708
tel +27 (0) 21 683-4506    Fax +27 (0) 21 683-4717

Johannesburg
FTI Training Centre, Chelsea Office Park,
57 Wessels Road, Rivonia; Sandton
tel +27 (0) 11 807-9478   fax +27 (0) 11 807-9480