Risk Management in IT Systems: Security Training Course

Derived from: NIST SP 800-30 Rev. 1 Guide for Conducting Risk Assessments
Risk Management in IT Systems: Security Training Course

At a glance

Duration
5 days
Format
Classroom
Cities
Riyadh, Paris, Vienna, Porto, Madrid, San Diego and more
Next session
4 – 8 October 2026, Riyadh
Average fee
5,800 €

Overview

Every information system, from a payroll application to a cloud-hosted customer portal, carries its own set of threats, weaknesses and business consequences. This Risk Management for IT Systems course follows the system-level approach described in NIST guidance for information technology systems. Participants take one sample system through the complete cycle: describing its boundary, data and interfaces; listing threat sources; finding vulnerabilities through scans and configuration reviews; rating likelihood and impact; selecting technical, operational and management controls; weighing their cost against the risk reduced; and writing the risk assessment report and plan of action that system owners and authorising officials sign. This course is delivered by Agile Leaders Training Center.

Who Should Attend

  • Information system owners and application managers accountable for system risk
  • Information security officers and analysts
  • System and network administrators who maintain configurations and patches
  • IT auditors and security assessors
  • Software development and DevSecOps leads

Departments and Industries

Suited to organisations that must assess and authorise individual information systems before and during operation.

  • Information security, IT audit and software engineering
  • IT infrastructure and applications
  • Government IT, banking and payments
  • Hospitals and health information, telecoms and cloud service providers
  • Utilities with SCADA and IT systems

Learning Objectives

By the end of this course, participants will be able to:

  • Analyse an IT system's boundary, hardware, software, data flows and users.
  • Build threat source and vulnerability lists using scan results, CVE data and configuration baselines.
  • Evaluate likelihood and impact on confidentiality, integrity and availability and produce a risk-level matrix.
  • Prioritise technical, operational and management controls and justify them with cost-benefit analysis.
  • Apply security risk activities in each phase of the system development life cycle.
  • Build a system risk assessment report and a plan of action and milestones for residual risk.

Course Agenda

Day 1: IT System Risk in the Development Life Cycle

  • Why IT systems need their own risk assessment
  • Roles: system owner, authorising official, security officer, assessor
  • Risk activities in initiation, development, implementation, operation and disposal
  • Security categorisation by the sensitivity of system data
  • Introducing the case system and agreeing scope and roles for the assessment

Day 2: System Characterisation, Threats and Vulnerabilities

  • Documenting boundary, interfaces and data flows
  • Human, natural and environmental threat sources
  • Vulnerability scanning, penetration test findings and CVE lookups
  • Security configuration baselines and hardening gaps
  • Reviewing existing and planned controls to form threat and vulnerability pairs

Day 3: Likelihood, Impact and Risk Determination

  • Rating likelihood from threat capability and control strength
  • Impact on confidentiality, integrity and availability
  • Building and reading the risk-level matrix
  • Qualitative versus quantitative approaches
  • Documenting results for system owners in a ranked risk register

Day 4: Selecting and Justifying Controls

  • Technical controls: access control, encryption, logging, patching
  • Operational and management controls
  • Accept, avoid, limit or transfer: choosing an option per risk
  • Cost-benefit analysis of proposed safeguards
  • Calculating and accepting residual risk, with control recommendations for the case system

Day 5: Reporting, Authorisation and Continuous Monitoring

  • Writing the risk assessment report
  • Plans of action and milestones for open findings
  • Presenting to the authorising official, with final case report presentations
  • Continuous monitoring and reassessment triggers
  • Sample interview questions for assessors

Practical Exercises

Working in small assessor teams on a web-based records application, participants complete these suggested activities.

  • Suggested activity: fill in the system characterisation worksheet from architecture diagrams and an interview with the system owner.
  • Suggested activity: build threat and vulnerability pairs from the catalogues and sample scan and configuration review outputs.
  • Suggested activity: rate each pair on the likelihood, impact and risk-level matrix.
  • Suggested activity: complete the control selection and cost-benefit worksheet and draft the report and plan of action.

FAQs

Does the course cover enterprise risk management?

No. It stays at the level of individual information systems rather than enterprise or operational risk in general.

Do I need hands-on scanning experience?

No. Participants read and interpret sample scan and configuration review outputs; running scanning tools is not required.

What documents will I produce?

A system description, a threat and vulnerability list, a risk matrix, control recommendations and a risk assessment report with a plan of action.

Conclusion

Participants leave having produced the documents a security assessor actually delivers for an IT system: a system description, threat and vulnerability list, risk matrix, control recommendations and a report with a plan of action, ready to apply to risk management for IT systems in their own organisation.

credits: 5 credit per day

Course Mode: full-time

Provider: Agile Leaders Training Center

Showing 61-76 of 76 events
Image Location Dates Duration Mode Price Actions
Madrid Madrid Week 33, 2027
16 – 20 August 2027
5 Days Onsite €5,700
Milan Milan Week 34, 2027
23 – 27 August 2027
5 Days Onsite €5,700
Manama Manama Week 34, 2027
29 August – 2 September 2027
5 Days Onsite €4,700
Zoom Zoom Week 36, 2027
6 – 10 September 2027
5 Days Online €1,500
Tbilisi Tbilisi Week 36, 2027
6 – 10 September 2027
5 Days Onsite €5,000
Dubai Dubai Week 37, 2027
13 – 17 September 2027
5 Days Onsite €4,500
Amsterdam Amsterdam Week 37, 2027
13 – 17 September 2027
5 Days Onsite €5,700
Geneva Geneva Week 37, 2027
19 – 23 September 2027
5 Days Onsite €6,200
Nairobi Nairobi Week 37, 2027
19 – 23 September 2027
5 Days Onsite €4,500
Tashkent Tashkent Week 37, 2027
19 – 23 September 2027
5 Days Onsite €4,500
Phuket Phuket Week 38, 2027
26 – 30 September 2027
5 Days Onsite €6,000
Rome Rome Week 39, 2027
27 September – 1 October 2027
5 Days Onsite €5,700
New York New York Week 39, 2027
27 September – 1 October 2027
5 Days Onsite €12,000
Amman Amman Week 39, 2027
3 – 7 October 2027
5 Days Onsite €4,100
Casablanca Casablanca Week 40, 2027
4 – 8 October 2027
5 Days Onsite €4,100
Montreux Montreux Week 40, 2027
4 – 8 October 2027
5 Days Onsite €7,500

Frequently asked questions

What does this course cover?

OverviewEvery information system, from a payroll application to a cloud-hosted customer portal, carries its own set of threats, weaknesses and business consequences. This Risk Management for IT Systems course follows the system-level approach described in NIST guidance for information technology systems. Participants take one sample system through the com…

Are training dates available?

Yes. Available dates and destinations are listed in the course dates section on this page.

How can I register?

Choose an available date on this page and complete the registration form, or send a programme enquiry.

Can I download the course brochure?

Yes. Use the brochure download link provided on this page.

This course by city