The two-day Certified Data Centre Risk Professional (CDRP) course provides IT, facilities and data centre professionals with a structured approach to identifying, assessing and managing risks within mission-critical environments. You will explore established risk management standards and methodologies and learn how to identify assets, threats, vulnerabilities and existing controls, assess potential consequences and determine appropriate levels of risk.
Through practical exercises and real-world risk scenarios, you will learn how to analyse and evaluate risks affecting areas such as data centre facilities, power, cooling, fire suppression, IT services and cloud environments. The course also covers risk treatment, communication, ongoing monitoring and compliance, helping you reduce the likelihood and impact of incidents while supporting corporate governance and certification processes such as ISO/IEC 27001. The course concludes with the Certified Data Centre Risk Professional (CDRP) examination.

Course Schedule
Course Code: CDRP
Duration: 2 days
Audience
The primary audience for this course is an IT, Facilities or Data Centre Operations professional working in and around the data centre (representing both end-customers and/or service provider/facilitators) and having responsibility to achieve and improve hi-availability and manageability of the data centre, such as: Data centre managers, Operations / Floor / Facility managers, IT managers, Information security managers, Security professionals, Auditors / Risk Managers / Professionals responsible for IT/corporate governance.
Prerequisites
There is no specific prerequisite for the CDRP® course. However, participants who have at least three years' experience in a data centre and/or IT infrastructures will be best suited. This experience may come from a business or IT background where the participant has knowledge of both environments, and understands the mission of their organisation. Attendance of CDCP® is beneficial but not a requirement.
Course Objectives
After completion of the course, the participant will be able to:
- Understand the different standards and methodologies for risk management and assessment
- Establish the required project team for risk management
- Perform the risk assessment, identifying current threats, vulnerabilities and the potential impact based on customised threat catalogues
- Report on the current risk level of the data centre both quantitative and qualitative
- Anticipate and minimise potential financial impacts
- Understand the options for handling risk
- Continuously monitor and review the status of risk present in the data centre
- Reduce the frequency and magnitude of incidents
- Detect and respond to events when they occur
- Meet regulatory and compliance requirements
- Support certification processes such as ISO/IEC 27001
- Support overall corporate and IT governance
Course Content
Introduction to Risk Management
- Risk management concepts
- Senior management and risk
- Enterprise Risk Management (ERM)
- Benefits of risk management
Data Centre Risk and Impact
- Risk in facility, power, cooling, fire suppression, infrastructure and IT services
- Impact of data centre downtime
- Main causes of downtime
- Cost factors in downtime
Standards, Guidelines and Methodologies
- ISO/IEC 27001:2013, ISO/IEC 27005:2011, ISO/IEC 27002:2013
- NIST SP 800-30
- ISO/IEC 31000:2009
- SS507:2008
- ANSI/TIA-942
- Other methodologies (CRAMM, EBIOS, OCTAVE, etc.)
Risk Management Definitions
- Asset
- Availability/Confidentiality/Integrity
- Control
- Information processing facility
- Information security
- Policy
- Risk
- Risk analysis/Risk assessment/Risk evaluation/
- Risk treatment
- Threat/Vulnerability
- Types of risk
Risk Assessment Software
- The need for software
- Automation
- Considerations
Risk Management Process
- The risk management process
- Establishing the context
- Identification
- Analysis
- Evaluation
- Treatment
- Communication and consultation
- Monitoring and review
Project Approach
- Project management principles
- Project management methods
- Scope
- Time
- Cost
- Cost estimate methods
Context Establishment
- General considerations
- Risk evaluation, impact and acceptance criteria
- Severity rating of impact
- Occurrence rating of probability
- Scope and boundaries
- Scope constraints
- Roles & responsibilities
- Training, awareness and competence
Risk Assessment - Identification
- The risk assessment process
- Identification of assets
- Identification of threats
- Identification of existing controls
- Identification of vulnerabilities
- Identification of consequences
- Hands-on exercise: Identification of assets, threats, existing controls, vulnerabilities and consequences
Risk Assessment - Analysis and Evaluation
- Risk estimation
- Risk estimation methodologies
- Assessment of consequences
- Assessment of incident likelihood
- Level of risk estimation
- Risk evaluation
- Hands-on exercise: Assessment of consequences,
- probability and estimating level of risk
Risk Treatment
- The risk treatment process steps
- Risk Treatment Plan (RTP)
- Risk modification
- Risk retention
- Risk avoidance
- Risk sharing
- Constraints in risk modification
- Control categories
- Control examples
- Cost-benefit analysis
- Control implementation
- Residual risk
Communication
- Effective communication of risk management activities
- Benefits and concerns of communication
Risk Monitoring and Review
- Ongoing monitoring and review
- Criteria for review
Risk scenarios
- Risk assessment approach
- Data centre site selection
- Data centre facility
- Cloud computing
- UPS scenarios
- Force majeure
- Organisational shortcomings
- Human failure
- Technical failure
- Deliberate acts
Exam
Exam: Certified Data Centre Risk Professional (CDRP®)
Attendees will take a 1 hour CDRP® exam. The exam is 40 questions, closed book and multiple choice based. The passing mark is 27 out of 40.
Certification & Accreditation
Attendees passing the exam will be awarded the internationally accredited and recognized 'Certified Data Centre Risk Professional' certificate (CDRP®).
CDRP® is globally accredited by EXIN, a fully independent exam and certification institute.
The CDRP® certificate is valid for 3 years, after which recertification is required. Please see the EPI Recertification Program for available options.
Public Schedule
Private Virtual Training (Teams / Zoom)
n/a
Private Onsite Training (at your offices)
n/a
Note
All prices exclude VAT at 20%.
VAT registration number: 450 4347 14
You may also like...
Learn to improve data centre sustainability through energy efficiency, carbon reduction, water, waste and renewable energy management.
2 days
Develop practical skills to manage day-to-day data centre operations, including procedures, maintenance, safety, security, risk and incident management.
3 days
Develop skills to manage high-availability data centre operations, covering SLAs, safety, maintenance, capacity, risk, vendors and resilience.
3 days




