ISO 31000 Security Risk Assessment and Treatment Training Course
| Course code | SD-SM-010 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Security Management |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Security managers and HSE professionals are often required to justify controls for threats such as unauthorised access, theft, violence, sabotage, contractor failures and security-related business interruption. Yet many risk registers mix hazards, threats, consequences and controls without a consistent basis for rating likelihood or selecting treatment. This makes it difficult to prioritise investment, explain residual risk to leadership, or demonstrate that security decisions are proportionate and auditable. ISO 31000 provides a disciplined framework for making these decisions across sites, projects, operations and supply chains.
This five-day course applies the ISO 31000:2018 risk management process to security management. Participants establish scope and risk criteria; identify security threats, vulnerabilities and consequences; analyse likelihood and impact; evaluate inherent and residual risk; and select treatment options using control effectiveness, cost, ownership and acceptance criteria. They use techniques from ISO 31010:2019, including structured interviews, risk matrices, bow-tie analysis and control assessment. The course also addresses consultation, communication, monitoring, review, escalation and risk reporting for management decisions.
Delivery combines instructor-led explanation with facilitated workshops built around a realistic multi-site security case. Participants work through a complete assessment, from context statement and asset profile to risk register, treatment plan and assurance measures. Each participant leaves with an ISO 31000-aligned security risk assessment pack containing a risk criteria statement, threat and vulnerability assessment, prioritised risk register, bow-tie control map, treatment actions and review schedule that can be adapted for their own organisation.
The course is designed for practitioners who already contribute to security, HSE, facilities, resilience or operational risk decisions and need a repeatable method rather than another generic risk-awareness programme.
Course objectives
By the end of this course, participants will be able to:
- Define security risk scope, context, stakeholders and risk criteria using the ISO 31000 framework
- Identify security threats, vulnerabilities, assets, consequences and existing controls through structured risk workshops
- Construct likelihood and consequence scales that distinguish inherent risk from residual risk
- Apply ISO 31010 techniques, including risk matrices and bow-tie analysis, to security scenarios
- Evaluate control design and operating effectiveness against preventive, detective and response control objectives
- Prioritise security risks using documented risk appetite, tolerance thresholds and treatment decision criteria
- Develop a costed security risk treatment plan with accountable owners, target dates and assurance measures
- Produce an ISO 31000-aligned security risk register and management report for decision-makers
Benefits of attending
For you
- Build confidence facilitating evidence-based security risk workshops with operational and leadership stakeholders
- Gain a repeatable ISO 31000 method for moving from threat lists to approved treatment actions
- Create risk registers and bow-tie diagrams that demonstrate professional security risk practice
- Strengthen credibility when challenging weak controls or recommending proportionate security investment
- Prepare portfolio evidence for security, risk, resilience or HSE management responsibilities
For your organisation
- Establish a consistent basis for comparing security risks across sites, functions and projects
- Improve capital and operating-security investment decisions through documented treatment priorities
- Reduce unmanaged exposure by assigning risk owners, control owners, deadlines and review triggers
- Provide management with clearer reporting on inherent risk, residual risk and risk acceptance decisions
- Link physical security controls, incident learning and assurance activity within one risk-management process
Target competencies
Who should attend
- Security Managers — who need a defensible method for prioritising site, personnel and asset protection controls
- HSE Managers — who integrate security threats and operational risks within enterprise HSE governance
- Risk Managers — who need to apply a common ISO 31000 process across security risk portfolios
- Facilities Managers — who assess access control, contractor, perimeter and building-security exposures
- Business Continuity Managers — who must connect security events, critical services and recovery priorities
- Operational Managers — who own security risks and need to approve practical treatment actions
Requirements and prerequisites
Participants should have experience of a security, HSE, facilities, operational risk or business continuity environment and be familiar with basic risk terms such as likelihood, consequence, controls and risk register. They should be able to describe the assets, activities and stakeholders relevant to a site, operation or project. Prior experience with ISO 31000, ISO 31010, bow-tie analysis or formal risk scoring is not required; these methods are taught from first principles. No specialist security qualification, statistical software or audit certification is required. Participants benefit most by bringing a non-sensitive example of a current security risk issue.
Training methodology
The instructor introduces each ISO 31000 stage using security examples before participants apply it in guided tables and small-group workshops. A continuing multi-site case requires teams to define risk criteria, analyse access, personnel and asset threats, score risks, test controls and select treatments. Participants use risk-register templates, bow-tie diagrams and decision logs rather than abstract discussion alone. Facilitated peer review tests whether ratings and treatments can be defended to management. The final session converts course outputs into a practical application plan for a participant’s own security environment.
Course outline
Day 1: ISO 31000 foundations for security risk
- ISO 31000:2018 principles, framework and risk management process
- Security risk terminology: assets, threats, vulnerabilities, events and consequences
- Distinguishing security risk from safety hazard, compliance obligation and incident
- Establishing organisational context and external security context
- Defining scope, objectives, boundaries and assumptions for an assessment
- Stakeholder mapping, consultation requirements and information sources
- Designing risk criteria, risk appetite and tolerance thresholds
Workshop: Participants prepare a security risk assessment charter and risk criteria statement for a multi-site operations case.
Day 2: Security risk identification and analysis
- Asset and critical-service identification for security assessments
- Structured threat identification using scenario-based prompts
- Vulnerability assessment across people, premises, processes and technology
- Consequence analysis for safety, operational, financial, legal and reputational effects
- Likelihood estimation using evidence, incident history and exposure factors
- Inherent risk scoring with calibrated likelihood and consequence scales
- Security risk register fields, evidence notes and uncertainty recording
Workshop: Teams build an inherent-risk register for unauthorised access, theft, violence and sabotage scenarios.
Day 3: Control analysis and bow-tie assessment
- Preventive, detective, response and recovery control categories
- Control design effectiveness versus operating effectiveness
- Bow-tie analysis of threats, top events, consequences and barriers
- Escalation factors and barrier degradation mechanisms
- Control ownership, performance standards and assurance evidence
- Residual risk scoring after verified control performance
- Using ISO 31010:2019 techniques to select appropriate analysis depth
Workshop: Participants create a bow-tie diagram and control-assurance checklist for a perimeter breach scenario.
Day 4: Risk evaluation and treatment decisions
- Comparing analysed risk against approved risk criteria
- Risk treatment options: avoid, remove source, reduce likelihood, reduce consequence, share and retain
- Selecting proportionate controls using effectiveness, feasibility and cost considerations
- Developing treatment actions, milestones, owners and resource requirements
- Documenting risk acceptance and escalation authorities
- Managing contractor, supplier and third-party security risk treatments
- Linking treatment plans to security procedures, budgets and capital projects
Workshop: Teams prioritise a risk portfolio and produce a costed treatment plan with accountable action owners.
Day 5: Reporting, review and workplace application
- Security risk dashboards for operational and executive audiences
- Writing concise risk statements and defensible management recommendations
- Key risk indicators, key control indicators and early-warning triggers
- Monitoring treatment completion and control performance
- Review triggers following incidents, organisational change and threat intelligence
- Integrating security risk assessment with incident investigation and business continuity processes
- Implementing an ISO 31000 security risk assessment cycle in the workplace
Workshop: Participants complete and present an ISO 31000-aligned security risk assessment pack and a 90-day implementation plan.
Tools & standards covered
ISO 31000:2018, ISO 31010:2019, BowTieXP, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
21 – 25 Sep 2026Book
Cape Town · USD 4,200 -
28 Sep – 02 Oct 2026Book
Live Online · USD 1,500 -
12 – 16 Oct 2026Book
Dar es Salaam · USD 3,500 -
12 – 16 Oct 2026Book
Live Online · USD 1,500 -
19 – 23 Oct 2026Book
Nairobi · USD 3,000 -
19 – 23 Oct 2026Book
Live Online · USD 1,500 -
26 – 30 Oct 2026Book
Kigali · USD 3,500 -
26 – 30 Oct 2026Book
Nairobi · USD 3,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Security Management
Security Management for Healthcare Facility Protection Training Course
Healthcare facilities must protect patients, staff, visitors, medicines, records and critical services while remaining accessible to people …
ISO 18788 Security Operations Management System Training Course
Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…
ASIS Physical Asset Protection Standard Implementation Training Course
Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV c…
Crime Prevention Through Environmental Design for Facility Security Training Course
Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…