Security Risk Management (SRM)
Dates
-
Nov 26 - 27, 2026
Location
ARC Hotel, 140 Slater Street, Ottawa, ON
Cost
$2000 + HST
COURSE SUMMARY
Understanding risk management is an essential part of managing any security program and is knowledge required of senior security officials. The course is planned to provide students the opportunity to get a deeper understanding of key risk management principles and how to assess security risks.
The course builds on knowledge gained in the Assets Protection and Physical Security course about the threat and risk assessment (TRA) process and provides participants with greater depth and understanding on this important activity. It explains in greater detail how to evaluate their key assets, the threat landscape for their organization and how to address vulnerabilities. Participants are shown how risk assessments inform important reporting, program planning and evaluation tools, such as compliance reporting and maturity modelling.
Module l: Risk Evaluation
This process will help students understand how to identify and assess potential sources of risk, including cyber attacks, physical security threats, natural disasters, human error, and ineffective measures, processes, and procedures.
Students will then learn where to find and evaluate information about credible internal and external threats to the organization. They will also learn how to apply risk management modelling by assessing likelihood and consequence to prioritize risks. Using a structured risk management methodology, students will identify, assess, and prioritize factors for strategic planning and integration into the departmental security plan.
Security risk management is an ongoing process that depends on management support and a proactive, adaptable approach to protect people, information, and assets.
Module 2: Evaluation Report
This module teaches students how to prepare a risk assessment report and present risk findings clearly and persuasively so management can make informed decisions. Students will learn to identify the key messages decision-makers need and to integrate the security risk management process into the departmental security plan while ensuring that risks related to all eight security controls are identified, assessed, and considered. The report will outline the risk assessment process and findings and explain how resilience can be strengthened to protect people, information, and assets.
Participants will also gain insight into how security risk assessments support organizational security maturity modelling and compliance reporting.
Participants will receive adaptable examples they can use in their own departments.