When you enroll in this course, you'll also be enrolled in this Specialization.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate
There are 3 modules in this course
CISM: Enterprise Risk Leadership is the second course of Exam Prep CISM: Certified Information Security Manager Specialization. This course equips learners to explore the fundamental stages of identifying, assessing, and communicating information security risks while aligning risk appetite with organizational objectives. The curriculum dives deep into the technical and strategic aspects of risk assessment, the implementation of robust controls and countermeasures, and the critical role of defining Recovery Time Objectives (RTO) to ensure business continuity.
The course is structured into comprehensive modules, further segmented by Lessons and Video Lectures that blend management-level theory with practical application. This course facilitates learners with approximately 2:00–2:30 hours of video content. To ensure mastery of the material, Graded and Ungraded Quizzes are provided with every module, testing the ability of learners to evaluate impact and monitor risk in real-world business scenarios.
- Module 1: Risk Management Fundamentals
- Module 2: Risk Assessment and Analysis
- Module 3: Risk Treatment and Communication
This course is specifically designed for security leads and management-track professionals who aim to bridge the gap between technical risk assessments and enterprise-wide strategic planning, ensuring that Information Security Risk Management aligns with the organization's risk appetite and long-term business objectives.
By the end of this course, a learner will be able to:
- Establish Continuous Risk Monitoring and Governance.
- Implement Continuous Governance and Communication.
- Master Stakeholder Communication and Reporting.
Welcome to the week 1. In this week, we will dive into the essential frameworks and practical applications of Information Risk Management and Compliance to protect organizational assets.
We will transition into the selection and implementation of Controls and Countermeasures designed to mitigate identified risks effectively. A key focus will be placed on technical recovery metrics, specifically understanding the Recovery Time Objective (RTO) and its role in resilience planning. Finally, we will cover Risk Monitoring and Communication to ensure that risk status is continuously tracked and reported to stakeholders, providing a comprehensive Risk Management Overview that bridges the gap between technical security and executive oversight.
What's included
5 videos2 readings2 assignments
Show info about module content
5 videos•Total 41 minutes
Information Risk Management - Introduction•5 minutes
Information Risk Management and Compliance•13 minutes
Good Information Security Risk Management•7 minutes
Controls Countermeasures•4 minutes
Risk Management Overview•12 minutes
2 readings•Total 25 minutes
Welcome to the Course•15 minutes
Overview of Risk Management Fundamentals•10 minutes
Information Risk Management and Compliance - Knowledge Check•25 minutes
Risk Assessment and Analysis
Module 2•2 hours to complete
Module details
Welcome to Week 2. This week, we will begin by establishing a shared language through Information Security Risk Management Concepts, providing the framework necessary for Implementing Risk Management within any organizational structure. You will engage in a Risk Assessment: Deep Dive to uncover hidden vulnerabilities, followed by an exploration of how to select and validate Controls and Countermeasures. To ensure operational resilience, we will examine the critical role of Recovery Time Objectives (RTO) and the necessity of Testing Response and Recovery Plans under realistic conditions. Finally, we will cover the essential processes for Information Security Risks Assessment and the continuous nature of Risk Monitoring and Communication to keep stakeholders informed of the evolving threat landscape.
What's included
7 videos1 reading2 assignments
Show info about module content
7 videos•Total 47 minutes
Information Security Risk Management Concepts•6 minutes
Implementing Risk Management•5 minutes
Testing Response and Recovery Plans•4 minutes
Risk Assessment•11 minutes
Recovery Time Objectives•2 minutes
Risk Monitoring and Communication•3 minutes
Information Security Risks Assessment•15 minutes
1 reading•Total 10 minutes
Overview of Risk Assessment and Analysis•10 minutes
2 assignments•Total 50 minutes
Risk Assessment and Analysis - Assessment•25 minutes
Information Security Risk Management Concepts - Knowledge Check•25 minutes
Risk Treatment and Communication
Module 3•2 hours to complete
Module details
In this week, we begin with an Information Risk Management - Introduction to align our efforts with business goals, followed by a structured look at the Stages of Information Security and Risk Management to provide a clear roadmap for execution. You will explore Good Practices for Managing Information Risk and learn the nuances of Managing Information Security Risk in dynamic environments. A core focus will be on Developing Cyber Risk Management Strategy to ensure long-term protection, alongside the selection of appropriate Impact Controls to minimize the effects of potential incidents. Finally, we will emphasize the critical human element: Information Risk Management - Communication, ensuring that technical findings are translated into actionable intelligence for executive decision-makers.
Providing certification training since the year 2000, Whizlabs is the pioneer among online training providers across the globe. We are dedicated to helping you learn the skills you need to transform your career in the IT industry.
We provide certification training in the form of Video Courses, Practice Tests, Hands-on Labs and Sandbox in various disciplines such as Cloud Computing, DevOps, Cyber Security, Java, Big Data, Snowflake, CompTIA, Agile, Linux, CCNA, Blockchain, and much more.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Specialization?
When you enroll in the course, you get access to all of the courses in the Specialization, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.
Is financial aid available?
Yes. In select learning programs, you can apply for financial aid or a scholarship if you can’t afford the enrollment fee. If fin aid or scholarship is available for your learning program selection, you’ll find a link to apply on the description page.