|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/isaca-it-risk-fundamentals/
课程评论:没有评论
**ISACA IT风险基础:完整培训课程** 本课程由ISACA提供,旨在帮助学员掌握信息与技术(I&T)相关的风险管理基础知识。课程内容涵盖了风险管理的各个环节,包括风险识别、优先级排序、应对以及与管理层的沟通。 **课程主要内容分为六个领域:** * **领域一:风险导论与概述 (5%)** * 建立对风险的基本理解。 * 探讨风险与业务功能的联系。 * 讲解“三道防线”的重要性。 * 介绍IT控制的作用。 * **领域二:风险治理与管理 (15%)** * 解释风险治理与管理的结构及其对业务的指导作用。 * 讨论风险偏好、风险容忍度和风险承受能力。 * 介绍风险管理周期。 * **领域三:风险识别 (20%)** * 讲解识别和记录企业面临的风险的过程。 * 讨论资产、威胁和漏洞,以及如何利用它们进行风险识别。 * **领域四:风险评估与分析 (25%)** * 探究风险评估的不同方法。 * 介绍如何使用风险登记册来记录风险。 * 强调风险聚合的重要性。 * **领域五:风险应对 (15%)** * 探讨风险应对策略、控制设计与实施。 * 介绍其他风险应对方法。 * **领域六:风险监控、报告与沟通 (20%)** * 强调风险监控和报告在风险管理过程中的重要性。 * 分析如何根据企业目标选择合适的风险和绩效指标。 * 阐述持续监控和报告的必要性,以应对风险和相关控制的变化。 本课程适合所有希望了解信息技术相关风险管理基础的学员。
Every organisation experiences risk. ISACA's IT Risk Fundamentals Certificate is perfect for anyone wanting to learn about information and technology (I & T)-related risk. Our IT Risk Fundamentals course covers the fundamentals of risk management; from identifying and prioritising risk to responding and communicating the risk to management. You'll learn about six functions throughout the course:Domain 1 - Risk Introduction and Overview (5%): We start by setting a strong foundation and understanding of risk. In this domain we will cover fundamental concepts of IT risk management. We will discuss how risks links to business functions, the importance of the three lines of defense and the role of IT controls.Domain 2 - Risk Governance and Management (15%): We will explain the structure of risk governance and management and how it's used to set a direction for a business. We will discuss risk appetite, risk tolerance, and risk capacity and introduce the risk management cycle.Domain 3 - Risk Identification (20%): Risk identification is the process of spotting and documenting the risks a business faces. It is crucial because only identified risks can be assessed and responded to. In this domain we will talk about assets, threats, and vulnerabilities and how we can use them to identify risk.Domain 4 - Risk Assessment and Analysis (25%): After identifying risk, the next step is to understand its impact on the business. In this domain, we will discuss the different approaches to risk assessments, how to use risk registers to document risks, and the importance of risk aggregation.Domain 5 - Risk Response (15%): After risk has been identified and assessed, decisions need to be made about the appropriate risk response. In this domain we will discuss risk response strategies, control design and implementation and other response approaches.Domain 6 - Risk Monitoring, Reporting and Communication (20%): The monitoring and reporting of risk play an important role in the risk management process. Indicators for risk and performance should be considered carefully and chosen deliberately, based on their alignment with enterprise goals. Because of the changing nature of risk and associated controls, ongoing monitoring and reporting are essential steps in the risk management process.