ISO 31000 Security Risk Assessment and Treatment Training Course

5 days Security Management Certificate on completion
Course codeSD-SM-010
Duration5 days
LevelIntermediate
CategorySecurity Management
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Security managers and HSE professionals are often required to justify controls for threats such as unauthorised access, theft, violence, sabotage, contractor failures and security-related business interruption. Yet many risk registers mix hazards, threats, consequences and controls without a consistent basis for rating likelihood or selecting treatment. This makes it difficult to prioritise investment, explain residual risk to leadership, or demonstrate that security decisions are proportionate and auditable. ISO 31000 provides a disciplined framework for making these decisions across sites, projects, operations and supply chains.

This five-day course applies the ISO 31000:2018 risk management process to security management. Participants establish scope and risk criteria; identify security threats, vulnerabilities and consequences; analyse likelihood and impact; evaluate inherent and residual risk; and select treatment options using control effectiveness, cost, ownership and acceptance criteria. They use techniques from ISO 31010:2019, including structured interviews, risk matrices, bow-tie analysis and control assessment. The course also addresses consultation, communication, monitoring, review, escalation and risk reporting for management decisions.

Delivery combines instructor-led explanation with facilitated workshops built around a realistic multi-site security case. Participants work through a complete assessment, from context statement and asset profile to risk register, treatment plan and assurance measures. Each participant leaves with an ISO 31000-aligned security risk assessment pack containing a risk criteria statement, threat and vulnerability assessment, prioritised risk register, bow-tie control map, treatment actions and review schedule that can be adapted for their own organisation.

The course is designed for practitioners who already contribute to security, HSE, facilities, resilience or operational risk decisions and need a repeatable method rather than another generic risk-awareness programme.

Course objectives

By the end of this course, participants will be able to:

  • Define security risk scope, context, stakeholders and risk criteria using the ISO 31000 framework
  • Identify security threats, vulnerabilities, assets, consequences and existing controls through structured risk workshops
  • Construct likelihood and consequence scales that distinguish inherent risk from residual risk
  • Apply ISO 31010 techniques, including risk matrices and bow-tie analysis, to security scenarios
  • Evaluate control design and operating effectiveness against preventive, detective and response control objectives
  • Prioritise security risks using documented risk appetite, tolerance thresholds and treatment decision criteria
  • Develop a costed security risk treatment plan with accountable owners, target dates and assurance measures
  • Produce an ISO 31000-aligned security risk register and management report for decision-makers

Benefits of attending

For you

  • Build confidence facilitating evidence-based security risk workshops with operational and leadership stakeholders
  • Gain a repeatable ISO 31000 method for moving from threat lists to approved treatment actions
  • Create risk registers and bow-tie diagrams that demonstrate professional security risk practice
  • Strengthen credibility when challenging weak controls or recommending proportionate security investment
  • Prepare portfolio evidence for security, risk, resilience or HSE management responsibilities

For your organisation

  • Establish a consistent basis for comparing security risks across sites, functions and projects
  • Improve capital and operating-security investment decisions through documented treatment priorities
  • Reduce unmanaged exposure by assigning risk owners, control owners, deadlines and review triggers
  • Provide management with clearer reporting on inherent risk, residual risk and risk acceptance decisions
  • Link physical security controls, incident learning and assurance activity within one risk-management process

Target competencies

Security risk scopingThreat vulnerability analysisRisk criteria designBow-tie control mappingTreatment plan developmentResidual risk reporting

Who should attend

  • Security Managers — who need a defensible method for prioritising site, personnel and asset protection controls
  • HSE Managers — who integrate security threats and operational risks within enterprise HSE governance
  • Risk Managers — who need to apply a common ISO 31000 process across security risk portfolios
  • Facilities Managers — who assess access control, contractor, perimeter and building-security exposures
  • Business Continuity Managers — who must connect security events, critical services and recovery priorities
  • Operational Managers — who own security risks and need to approve practical treatment actions

Requirements and prerequisites

Participants should have experience of a security, HSE, facilities, operational risk or business continuity environment and be familiar with basic risk terms such as likelihood, consequence, controls and risk register. They should be able to describe the assets, activities and stakeholders relevant to a site, operation or project. Prior experience with ISO 31000, ISO 31010, bow-tie analysis or formal risk scoring is not required; these methods are taught from first principles. No specialist security qualification, statistical software or audit certification is required. Participants benefit most by bringing a non-sensitive example of a current security risk issue.

Training methodology

The instructor introduces each ISO 31000 stage using security examples before participants apply it in guided tables and small-group workshops. A continuing multi-site case requires teams to define risk criteria, analyse access, personnel and asset threats, score risks, test controls and select treatments. Participants use risk-register templates, bow-tie diagrams and decision logs rather than abstract discussion alone. Facilitated peer review tests whether ratings and treatments can be defended to management. The final session converts course outputs into a practical application plan for a participant’s own security environment.

Course outline

Day 1: ISO 31000 foundations for security risk

  • ISO 31000:2018 principles, framework and risk management process
  • Security risk terminology: assets, threats, vulnerabilities, events and consequences
  • Distinguishing security risk from safety hazard, compliance obligation and incident
  • Establishing organisational context and external security context
  • Defining scope, objectives, boundaries and assumptions for an assessment
  • Stakeholder mapping, consultation requirements and information sources
  • Designing risk criteria, risk appetite and tolerance thresholds

Workshop: Participants prepare a security risk assessment charter and risk criteria statement for a multi-site operations case.

Day 2: Security risk identification and analysis

  • Asset and critical-service identification for security assessments
  • Structured threat identification using scenario-based prompts
  • Vulnerability assessment across people, premises, processes and technology
  • Consequence analysis for safety, operational, financial, legal and reputational effects
  • Likelihood estimation using evidence, incident history and exposure factors
  • Inherent risk scoring with calibrated likelihood and consequence scales
  • Security risk register fields, evidence notes and uncertainty recording

Workshop: Teams build an inherent-risk register for unauthorised access, theft, violence and sabotage scenarios.

Day 3: Control analysis and bow-tie assessment

  • Preventive, detective, response and recovery control categories
  • Control design effectiveness versus operating effectiveness
  • Bow-tie analysis of threats, top events, consequences and barriers
  • Escalation factors and barrier degradation mechanisms
  • Control ownership, performance standards and assurance evidence
  • Residual risk scoring after verified control performance
  • Using ISO 31010:2019 techniques to select appropriate analysis depth

Workshop: Participants create a bow-tie diagram and control-assurance checklist for a perimeter breach scenario.

Day 4: Risk evaluation and treatment decisions

  • Comparing analysed risk against approved risk criteria
  • Risk treatment options: avoid, remove source, reduce likelihood, reduce consequence, share and retain
  • Selecting proportionate controls using effectiveness, feasibility and cost considerations
  • Developing treatment actions, milestones, owners and resource requirements
  • Documenting risk acceptance and escalation authorities
  • Managing contractor, supplier and third-party security risk treatments
  • Linking treatment plans to security procedures, budgets and capital projects

Workshop: Teams prioritise a risk portfolio and produce a costed treatment plan with accountable action owners.

Day 5: Reporting, review and workplace application

  • Security risk dashboards for operational and executive audiences
  • Writing concise risk statements and defensible management recommendations
  • Key risk indicators, key control indicators and early-warning triggers
  • Monitoring treatment completion and control performance
  • Review triggers following incidents, organisational change and threat intelligence
  • Integrating security risk assessment with incident investigation and business continuity processes
  • Implementing an ISO 31000 security risk assessment cycle in the workplace

Workshop: Participants complete and present an ISO 31000-aligned security risk assessment pack and a 90-day implementation plan.

Tools & standards covered

ISO 31000:2018, ISO 31010:2019, BowTieXP, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No prior ISO 31000 training is required. You should understand basic workplace risk concepts and have experience of a security, HSE, facilities, resilience or operational setting; the course teaches the standard’s process and tools in detail.

A laptop is recommended for live online delivery and useful in the classroom for completing templates. No specialist software is required; exercises use course materials that can be completed in Microsoft Excel, while BowTieXP is demonstrated as an option for structured barrier analysis.

The primary focus is operational and physical security risk: people, premises, assets, access, contractors and disruptive events. The ISO 31000 method can also support cyber-risk interfaces, but this is not a technical cyber-security controls course.

This course applies ISO 31000 directly to security scenarios and security-control decisions, including threat-vulnerability analysis, barrier performance and treatment planning. It does not focus on project risk, procurement risk or a broad enterprise-risk overview.

You can use the assessment charter, criteria, risk register, bow-tie template and treatment-plan structure for site reviews, security upgrades, contractor assessments and post-incident reassessments. The final 90-day plan identifies where to apply the method first in your own organisation.

You leave with a completed security risk assessment pack developed through the course case, including a risk register, bow-tie control map, treatment plan and review schedule. These editable structures can be adapted to your organisation’s reporting format and governance requirements.

Upcoming sessions

  • 21 – 25 Sep 2026
    Cape Town · USD 4,200
    Book
  • 28 Sep – 02 Oct 2026
    Live Online · USD 1,500
    Book
  • 12 – 16 Oct 2026
    Dar es Salaam · USD 3,500
    Book
  • 12 – 16 Oct 2026
    Live Online · USD 1,500
    Book
  • 19 – 23 Oct 2026
    Nairobi · USD 3,000
    Book
  • 19 – 23 Oct 2026
    Live Online · USD 1,500
    Book
  • 26 – 30 Oct 2026
    Kigali · USD 3,500
    Book
  • 26 – 30 Oct 2026
    Nairobi · USD 3,000
    Book

49 more dates — ask us.


Group of 5+?

Request in-house delivery or group rates →

Related courses in Security Management

5 Days Certificate

Security Management for Healthcare Facility Protection Training Course

Healthcare facilities must protect patients, staff, visitors, medicines, records and critical services while remaining accessible to people …

5 Days Certificate

ISO 18788 Security Operations Management System Training Course

Private security operations face heightened scrutiny where services involve guarding, protective security, patrols, access control, secure t…

5 Days Certificate

ASIS Physical Asset Protection Standard Implementation Training Course

Physical asset protection programmes often develop as disconnected projects: a guard contract is renewed, access control is upgraded, CCTV c…

5 Days Certificate

Crime Prevention Through Environmental Design for Facility Security Training Course

Facilities can be secure on paper yet remain vulnerable because entrances are poorly observed, boundaries are ambiguous, public and staff ro…