-

New Toolkit and Course From ISACA Help Practitioners Develop Risk Scenarios

Risk Scenarios Starter Pack is free for ISACA members

SCHAUMBURG, Ill.--(BUSINESS WIRE)--One of the challenges for IT risk management is to identify important and relevant risk, and one of the best ways to do that is through a well-developed risk scenario providing a realistic and practical view of risk that may prevent an enterprise from achieving its business objectives, historical events, and emerging threats. ISACA has developed a Risk Scenarios Starter Pack and concise online course that will help break down each aspect of a risk scenario.

The Risk Scenarios Starter Pack includes 10 sample risk scenarios that practitioners can use and tailor to their specific enterprises. Risk scenarios help improve communication about risk management by constructing a narrative that inspires individuals to act. Using risk scenarios helps the risk team to understand and explain risk to the business process owners and other stakeholders.

The 10 scenarios included in the Risk Scenarios Starter Pack are:

  1. IT Services Change Management
  2. Inability to Recruit or Retain IT Staff
  3. Inadequate Patch/Vulnerability Management
  4. Security Configuration Intentionally Modified
  5. Vendor Support Ends
  6. Phishing Attack
  7. Third-Party Suppliers
  8. Failure to Implement Regulatory Changes
  9. Failure to Appreciate Value of Emerging Technologies
  10. Unauthorized Access of Information

With the online companion course, How to Build a Risk Scenario, practitioners are able to define an IT risk scenario, describe the benefits of using one, summarize the structure of an IT risk scenario, explain the key points for developing an IT risk scenario, and describe the importance of the risk scenario technique. Attendees will receive 1 continuing professional education (CPE) credit.

“Using risk scenarios to overcome the challenge of identifying important and relevant risk brings realism, insight, organizational engagement, improved analysis and structure to the complex matter of IT risk,” says Paul Phillips, ISACA Director of Event Content Development and Risk Professional Practice Lead. “Organizations will benefit from tailoring ISACA’s new risk scenario materials to their specific contexts.”

The How to Build a Risk Scenario course is US$49 for ISACA members US$79 for nonmembers and is available at https://store.isaca.org/s/store#/store/browse/detail/a2S4w000005GYb0EAG. The Risk Scenarios Starter Pack is free for ISACA members and is available at https://store.isaca.org/s/#/store/browse/detail/a2S4w000005GFBmEAO.

ISACA offers additional risk resources, including the Risk Starter Kit, at https://www.isaca.org/resources/it-risk.

About ISACA

ISACA® (www.isaca.org) is a global community advancing individuals and organizations in their pursuit of digital trust. For over 50 years, ISACA has equipped individuals and enterprises with the knowledge, credentials, education, training and community to progress their careers, transform their organizations, and build a more trusted and ethical digital world. ISACA is a professional association and learning organization leveraging the expertise of its more than 165,000 members who work in digital trust fields such as information security, governance, assurance, risk, privacy and quality. It has a presence in 188 countries, including 225 chapters worldwide. In 2020, ISACA launched One In Tech, a philanthropic foundation.

Contacts

Bridget Drufke, bdrufke@isaca.org, +1.847.660.5554

ISACA


Release Versions

Contacts

Bridget Drufke, bdrufke@isaca.org, +1.847.660.5554

Social Media Profiles
More News From ISACA

ISACA, Nasscom Join Hands to Standardize Digital Skills for India’s Workforce

NEW DELHI--(BUSINESS WIRE)--ISACA, a global professional association and learning organization working in digital trust fields serving 185,000 members and operating in more than 190 countries, has exchanged an MoU with IT-ITeS SSC Nasscom, the national standard-setting body for IT skills for the alignment of its credentials to NSQF (National Skill Qualification Framework). Sector Skills Council Nasscom, set up under the aegis of National Skill Development Corporation (NSDC) and Ministry of Skil...

Four Ways to Incorporate AI into Threat Intelligence Programs

SCHAUMBURG, Ill.--(BUSINESS WIRE)--Threat environments have become more complex, especially with the rise of generative AI and the rapid commercialization of the cybercrime ecosystem. Enterprises have also long struggled to realize meaningful value from traditional cyberthreat intelligence programs. However, there are steps that cybersecurity professionals can take to improve the effectiveness of their threat intelligence programs, as outlined in ISACA’s new white paper, Building a Threat-Led C...

AI-Driven Cyber Threats Are the Biggest Concern for Cybersecurity Professionals Going Into 2026, Finds New ISACA Research

LONDON--(BUSINESS WIRE)--Over half (51%) of European IT and cybersecurity professionals fear AI-driven cyber threats and deepfakes will keep them up at night next year, according to new ISACA research. What’s driving this concern is a lack of preparedness for AI-related risks across the industry. Only 14% of respondents feel their organisation is very prepared to manage the risks associated with generative AI solutions in 2026. The majority (82%) feel they are only somewhat prepared, not very p...
Back to Newsroom