ASIS Enterprise Security Risk Management Implementation Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-016
Duration5 days
LevelFoundation to Intermediate
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security teams are increasingly expected to show how physical security, protective services, investigations, travel security and resilience activity protect business objectives rather than simply reduce incidents. ASIS Enterprise Security Risk Management (ESRM) provides a disciplined way to do this: identify the assets that matter, engage the people accountable for them, assess threats and vulnerabilities, and agree proportionate treatments. This course helps practitioners move from site-led or technology-led security decisions to documented, stakeholder-owned risk decisions that can be defended to senior management.

Participants work through the ASIS ESRM approach from organisational context and asset identification to risk assessment, treatment selection, implementation and review. They practise stakeholder mapping, defining risk criteria and appetite, applying likelihood-and-impact scoring, documenting security risks in a register, comparing treatment options, and translating controls into accountable action plans. The course also addresses the practical interface between security, health and safety, business continuity, legal, HR, facilities and operational leadership.

Delivery combines instructor-led explanation with worked examples, facilitated risk workshops and a running organisational case study. Participants use an ESRM implementation workbook to build an asset profile, stakeholder engagement plan, risk assessment, treatment plan, governance model and performance measures. They leave with a completed ESRM implementation pack that can be adapted for their own business unit, site, programme or security transformation initiative, alongside a certificate of completion.

The course suits security professionals and operational leaders who need to establish, refresh or scale an enterprise security risk management programme. It is particularly valuable where security must secure investment, clarify risk ownership, integrate with enterprise risk processes, or demonstrate measurable contribution to organisational objectives.

Course objectives

By the end of this course, participants will be able to:

  • Apply the ASIS ESRM cycle to a defined organisational security risk scenario
  • Map asset owners, stakeholders and decision rights using an ESRM stakeholder map
  • Define security risk criteria, appetite statements and escalation thresholds
  • Conduct an asset-based threat, vulnerability and consequence assessment
  • Build a scored security risk register with inherent and residual risk ratings
  • Evaluate risk treatment options using cost, feasibility, effectiveness and ownership criteria
  • Produce an ESRM implementation roadmap with actions, accountabilities and review dates
  • Design security performance measures and reporting dashboards linked to business objectives

Benefits of attending

For you

  • Gain a structured ASIS ESRM method for leading security risk discussions with asset owners
  • Build credibility with senior stakeholders by presenting security decisions in business-risk terms
  • Create risk registers and treatment plans that show clear ownership beyond the security function
  • Strengthen capability to justify security investment through documented risk reduction and residual-risk decisions
  • Develop a portfolio-ready ESRM implementation pack for use in security management or resilience roles

For your organisation

  • Establish a common asset-based method for prioritising security risks across sites and business units
  • Improve accountability by assigning risk acceptance and treatment decisions to appropriate asset owners
  • Reduce spend on poorly targeted controls by comparing treatment options against defined risk criteria
  • Integrate security risk reporting with enterprise risk, HSE, resilience and operational governance processes
  • Create auditable evidence of risk assessment, treatment decisions, review dates and control performance

Target competencies

Asset-based risk assessmentStakeholder mappingRisk treatment planningSecurity governance designControl effectiveness reviewRisk reporting

Who should attend

  • Security Managers — who need to align security programmes with asset-owner priorities and enterprise risk decisions
  • Corporate Security Directors — who must establish consistent risk governance across sites, regions or business units
  • Security Risk Managers — who need a repeatable method for assessing and treating security risks
  • Business Continuity and Resilience Managers — who coordinate protective measures across operational disruption risks
  • Health, Safety and Environment Managers — who need to integrate security risk ownership with wider operational risk controls
  • Facilities and Operations Managers — who own critical assets and require defensible, proportionate security investments

Requirements and prerequisites

Participants should have a working awareness of their organisation’s security operations, assets, sites or services, and be able to describe common security threats such as theft, unauthorised access, violence, fraud or disruption. Familiarity with basic risk terms—likelihood, consequence, controls and residual risk—is useful but not essential. Participants should be comfortable reviewing simple spreadsheets and organisational documents. No prior ASIS qualification, formal risk-management certification, specialist security technology expertise or advanced Microsoft Excel capability is required. Complete beginners can attend, but should expect to spend time learning the language of enterprise risk and security governance before applying it.

Training methodology

The five days alternate short instructor-led inputs with structured application of the ASIS ESRM method to a running corporate case. Participants analyse asset-owner objectives, facilitate stakeholder conversations, score risks, compare control options and create governance documentation in small groups. The instructor critiques assumptions, evidence quality and treatment choices rather than treating a risk matrix as a purely numerical exercise. Case discussions include security’s interfaces with HSE, facilities, HR and continuity. On the final day, each participant converts the case approach into a practical implementation plan for their own organisation.

Course outline

Day 1: ESRM foundations and organisational context

  • ASIS Enterprise Security Risk Management principles and lifecycle
  • Security as an enabler of organisational objectives
  • Asset-based versus threat-led security planning
  • Organisational context and operating-environment analysis
  • Security risk governance, accountability and decision rights
  • Stakeholder identification and asset-owner engagement
  • Alignment with ISO 31000 risk-management principles

Workshop: Participants create an ESRM context statement and stakeholder map for a case-study organisation, identifying critical assets and accountable owners.

Day 2: Asset identification and security risk assessment

  • Asset categories: people, information, physical assets, operations and reputation
  • Asset value, criticality and dependency analysis
  • Threat identification using internal and external intelligence sources
  • Vulnerability analysis across people, process, technology and premises
  • Likelihood, consequence and uncertainty definitions
  • Inherent risk scoring and risk-matrix calibration
  • Security risk register structure and evidence requirements

Workshop: Participants conduct an asset-based assessment and produce an inherent-risk register for three priority business assets.

Day 3: Risk evaluation and treatment selection

  • Risk appetite, tolerance and escalation thresholds
  • Control identification and control-effectiveness testing
  • Residual-risk assessment and management acceptance
  • Risk avoidance, reduction, transfer and acceptance options
  • Layered security controls and defence-in-depth design
  • Cost, benefit, feasibility and unintended-consequence analysis
  • Treatment-plan ownership, milestones and resource requirements

Workshop: Teams evaluate competing treatment options for a high-risk scenario and produce a prioritised security risk treatment plan.

Day 4: Implementing ESRM across the enterprise

  • ESRM operating model and programme implementation stages
  • Integrating ESRM with HSE, enterprise risk and business continuity processes
  • Security policy, standards and procedure hierarchy
  • Security risk workshop design and facilitation techniques
  • Roles of asset owners, security advisers and executive sponsors
  • Change management for risk-based security practices
  • Data quality, documentation control and audit trails

Workshop: Participants design an ESRM implementation roadmap, including governance forums, stakeholder communications and a 90-day action sequence.

Day 5: Monitoring, reporting and applied implementation planning

  • Key risk indicators and key performance indicators for security
  • Control assurance, testing schedules and exception management
  • Risk review triggers and reassessment cycles
  • Executive security risk reporting and decision papers
  • Dashboard design for residual risk and treatment progress
  • Lessons learned from incidents and near misses
  • Personal ESRM implementation planning and maturity assessment

Workshop: Participants complete and present an ESRM implementation pack containing a risk register, treatment roadmap, governance model and executive reporting outline.

Tools & standards covered

ASIS Enterprise Security Risk Management Guideline, ISO 31000:2018 Risk management — Guidelines, ISO 31010:2019 Risk management — Risk assessment techniques, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No. The course introduces the ASIS ESRM method from first principles, while moving quickly into practical application. Basic familiarity with security operations and common risk terminology is helpful, but no formal qualification is assumed.

For classroom delivery, a laptop is recommended so you can complete and retain the ESRM workbook and spreadsheet-based risk register. Live-online participants need a computer with a reliable connection, microphone and access to Microsoft Excel or compatible spreadsheet software.

It is designed primarily for corporate security managers, security risk practitioners and leaders responsible for security programmes across sites or business units. It also suits HSE, resilience, facilities and operations professionals who share ownership of critical assets and operational risks.

A general course may concentrate on identifying threats, vulnerabilities and controls at a site or project level. ESRM adds asset-owner engagement, organisational objectives, risk governance, treatment accountability and enterprise-level implementation, so security decisions are owned by the business rather than security alone.

You can use the stakeholder map, risk-register structure, treatment-plan template and reporting model with a live asset, site or service. The final implementation plan is designed to help you sequence an ESRM pilot, establish governance and secure early sponsorship.

You will leave with a completed ESRM implementation pack developed through the case study, including asset profiles, stakeholder mapping, a scored risk register, treatment plan, governance model and reporting outline. You will also receive a certificate of completion.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

Security Management Fundamentals for Workplace Protection Training Course

Workplace security managers must protect people, premises, assets and operations while balancing access, service continuity, privacy, budget…

5 Days Certificate

Advanced Security Management for Threat Intelligence Integration Training Course

Security managers in high-risk, regulated and operationally complex environments need more than incident reports and periodic risk registers…

5 Days Certificate

Genetec Security Center for Physical Security Operations Training Course

Physical security teams need to detect, verify, coordinate and document incidents without losing time between cameras, access-control events…

5 Days Certificate

Security Management for Banking Branch and ATM Protection Training Course

Bank branches and ATM estates face a distinct combination of threats: armed robbery, cash-in-transit attack, ATM skimming, card trapping, ex…