Chat with us, powered by LiveChat

IT Risk Management

This subject is available under ICMS undergraduate degrees, please click the button below to find an undergraduate course for you.

Subject Code:

ICT301A

Subject Type:

Core 

Credit Points:

3 credit points

Pre-requisite/Co-requisite: 

Course level pre-requisite: a total of 24 credit points (15 credit points, including ICT101A, ICT102A, ICT103A, DAT101A from level 100 and 9 credit points from level 200 core subjects) prior enrolling into level 300 core and specialisation subjects. 

Subject Level:

300 

Subject Rationale:

 As an integral part of modern organisations, IT risk management is crucial in establishing robust security systems and mechanisms to safeguard valuable corporate information assets and ensure business continuity by incorporating the three fundamental facets of the overarching IT domain: people, process, and technology.    

 This subject equips students with disciplinary knowledge and skills in IT risk management by providing a comprehensive and rigorous exposition of industry standards, frameworks, and best practices that are applied to manage information security threats and vulnerabilities that negatively impact data confidentiality, integrity, and availability.   

 In this subject, students will explore emerging information security problems with the auxiliary tools and techniques that are systematically used for their holistic governance and management, contemplating business continuity measures and contingency planning. They will also examine legislative, ethical, and corporate social responsibility aspects of IT risk management, including their impact on organisations within an information security context. 

Learning Outcomes:

a) Explore the concepts, principles, standards, frameworks, and regulatory provisions applied in information security risk management (ISRM) and their role in organisational governance and compliance.

b) Critically assess standard approaches to enterprise risk management in an information technology context.

c) Examine a business domain and systematically implement risk management processes, tools, and techniques to address organisational information security issues.

d) Formulate strategies and actions based on sound theory and practice in response to information security risks congruous with multifaceted internal and external organisational factors.

e) Produce ancillary ISRM resources in accordance with industry best practices pertaining to information technology functional areas.

Student Assessment:

Broad Topics to be Covered:

Topic: 
Week 1: Foundations and Concepts of Risk Management 

  • IT, information security, and the role of risk management in People, Process, and Technology framework 
  • Understanding threats, vulnerabilities, and exploits, and their impact on organisations 
  • Risk domains, identification, management, assessment, and handling at a glance 
  • Organisational (internal and external) factors to risk management 
Week 2 – 3: Governance and Compliance: 

  • Laws, legislative instruments, compliance, and ethics in IT information security context 
  • Information security and risk Management standards, principles, and frameworks 
  • Organisational governance and compliance systems and mechanisms 
  • Australian Government information security bodies, initiatives, and approach 
Week 4 – 6: Risk Management Process: Risk Assessment 

  • Risk contexts, identification, and categorisation 
  • Analysing threats, vulnerabilities, and exploits, and their impact on organisations 
  • Cyber risks 
  • Risk evaluation in accordance with internal and external factors 
  • Risk assessment tools and techniques including quantitative and qualitative methods 
  • Communicate & Consult and Monitoring & Review during risk assessment 
  • Translating risk assessment into Risk Management Plan 
Week 7 – 8: Risk Management Process: Risk Treatment 

  • Identifying and analysing risk controls: preventative, detective, and corrective measures 
  • Cyber risks and safeguards 
  • Preparing, implementing, monitoring, and communicating risk treatment plans 
  • Communicate & Consult and Monitoring & Review during risk treatment 
  • Translating risk treatment into Risk Management Plan  
Week 9: Business Impact Analysis, IT Service Delivery and Incident Management 
Week 10: Business Continuity Planning 
Week 11: Disaster Recovery Planning 

Please note that these topics are often refined and subject to change so for up to date weekly topics and suggested reading resources, please refer to the Moodle subject page.