Training in risk management, business continuity and information security: how to choose?

A team may need training because it is about to start implementing ISO 27001. Another may already have the system in place but need to review responsibilities and records. The course may be the same, even though the work to be carried out afterwards is different.

⏱️ Estimated reading time: 4 minutes

When choosing training in risk management, business continuity or information security, the enrolment request should specify that work. This allows business unit management and HR to assess the course programme, select participants and plan when they will apply what they have learnt.

1. Training in risk management: when two departments report ‘high’ risks

Consider a management meeting in which the operations and technology departments present risks rated as ‘high’. The rating appears to allow a comparison, but one department may have focused mainly on financial consequences and the other on service disruption.

Before prioritising them, you need to understand the criteria used. Choose a recent decision and review its record: what consequences were considered, which treatment options were discussed and why was one of them chosen?

Also confirm who has the authority to accept residual risk, meaning the risk that remains after treatment. Where that authority has not been defined, the organisation needs to make a decision; training the person who maintains the risk register will not resolve this on its own.

The Integrated Risk & Resilience Lead Manager course covers these criteria and decisions, drawing on ISO 31000 and ISO/IEC 27005. It is worth considering for those who coordinate risk assessment and treatment or prepare the information management uses to make decisions.

2. ISO 22301: has the alternative to your supplier been tested in an exercise?

Consider a service that depends on an essential supplier. The business continuity plan provides for an alternative, but you need to confirm whether it can maintain priority activities with the resources available and within the required timeframe.

Ask the person responsible for the service to explain how long the disruption can last, what minimum level of operation is required and which resources are needed to maintain it. Compare those answers with the defined recovery objectives.

If exercises have already taken place, review the results: did the alternative work under the conditions tested? What difficulties remain unresolved? If no exercises have taken place, decide what needs to be tested and who needs to take part.

The ISO 22301 Lead Implementer course prepares professionals to organise this work within a Business Continuity Management System (BCMS). The programme covers business impact analysis, strategies, plans, communication and exercises, whether implementing a system or reviewing an existing one.

Are you choosing training for those responsible for risk, continuity or security?

Your enquiry to Behaviour should specify what these people will be doing within the organisation, how many will attend and when the training is planned.

Request a training proposal for your team

3. ISO 27001: responding to a client who asks for evidence

A client asks for records from a review of access to information. To respond, the team needs to locate the procedure, identify who carries it out and gather the most recent records.

The security policy may explain the rules, but it does not show when access was reviewed or by whom. The request requires the team to clarify that distinction between the defined rule and its implementation.

Check a specific control. If no one is responsible for it, assign that responsibility; if there is a procedure but no records, establish whether the work was carried out and how it was documented.

The ISO 27001 Lead Implementer course develops the skills needed to implement and improve an Information Security Management System (ISMS) in accordance with ISO/IEC 27001. For those overseeing an implementation spread across several departments, it covers how to link risks, controls, responsibilities, documentation and performance evaluation.

4. Training in risk management, business continuity and security: who should attend?

A request such as ‘enrol the business continuity lead’ identifies the participant but says little about the choice. Adding ‘to review the business impact analysis and propose an exercise programme’ makes it easier to assess whether the training is suitable.

Before approving enrolment, record the participant’s role, the planned work and who will oversee it. Check with the business unit that the person will have time to attend the course and then carry out that work.

HR needs to align participants and dates with the approved annual budget. When arranging the training, also check the suitability of the content, the training hours to be counted per employee and the supporting documents, taking account of any applicable training obligations.

Team members may need different courses. The person coordinating the continuity of a service and the person responsible for implementing the ISMS will not necessarily have the same training needs.

5. Following up on how training is applied

Before the course, agree an initial piece of work and a date to review it with the participant and their line manager. This could be a proposal for risk criteria, the preparation of a business continuity exercise or an ISMS implementation plan.

On the agreed date, review what has been produced and what is still needed before it can be used. If the exercise depends on another department taking part or the implementation plan is awaiting approval, identify who needs to act and when.

This follow-up also helps distinguish between difficulty applying the knowledge and a decision their manager has yet to make. The participant should know who to turn to in each case.

To request a proposal from Behaviour, explain the work that prompted the training request, the participants’ roles and when they are available to attend.

Request a training proposal for your team

Date:
Author: Behaviour
Copying or reproducing this article is not permitted.