ISO/IEC 27005 Risk Manager: Information Security Risk Management
Information security decisions need an explicit view of risk. Use ISO/IEC 27005 to structure assessment, compare responses and communicate priorities. Build a method that helps security, compliance and risk teams connect protection measures with business needs.
- Duration
- 2.5 days 17 hours
- Code
- ISO27005EN Code
- Certification
- PECB ISO/IEC 27005 Certification — Information Security Risk Management Certification
Accredited training for the PECB ISO/IEC 27005 Certification — Information Security Risk Management certification.
Presentation
Today, knowing and managing risks related to information systems (IS) security is essential for the smooth operation of any organization. Even the smallest incident can have critical consequences for a business. For this reason, it is important to be trained on the ISO/IEC 27005 standard in order to become a certified risk manager.
Our training will provide you with all the necessary skills to master the assets and processes related to information security, in compliance with the ISO/IEC 27005:2022 standard. You will also explore other risk management methods such as OCTAVE, EBIOS, MEHARI, and the EMR method. This training is also highly relevant if you wish to implement an Information Security Management System (ISMS) in line with the ISO/IEC 27001:2022 standard.
At the end of this training, you will take the ISO/IEC 27005 Risk Manager exam. Passing this exam will validate your knowledge and skills and enable you to obtain one of the PECB titles, such as PECB Certified ISO/IEC 27005 Provisional Manager, which does not require any prior professional experience (more information in the Certification section).
Objectives
By the end of the ISO/IEC 27005 Risk Manager training, you will be able to:
- Understand security measures related to information risk management
- Acquire the principles, methodology, and techniques of risk management in compliance with the ISO/IEC 27005:2022 standard
- Understand and apply the rules of the ISO/IEC 27001:2022 standard within information security risk management
- Advise organizations on the most effective risk management practices in the field of information security
- Successfully pass the PECB ISO/IEC 27005:2022 Risk Manager exam and obtain one of the three associated qualifications
Program
Note: The course materials and the PECB ISO/IEC 27005 Risk Manager exam are available in both French and English.
Day 1: Introduction to Risk Management and the ISO/IEC 27005 Standard
- Introduction Round
- Individual introductions
- Exploration of participants’ expectations and objectives
- Introduction to the training framework
- Alignment with specific goals and challenges
- Identification of participants’ expectations and perspectives
- Understanding and defining risk
- Understanding the ISO/IEC 27005:2022 standard
- Identifying critical business processes
- Establishing a risk management program
Day 2: Implementing the Risk Management Process According to ISO/IEC 27005
- Identifying risks
- Analyzing and evaluating risks
- Using the quantitative method to assess risks
- Treating risks
- Accepting and managing residual risks
- Communicating about information security risks
- Monitoring and reviewing risks
Day 3: Overview of Other Information Security Risk Assessment Methods
- OCTAVE method
- MEHARI method
- EBIOS method
- Harmonized EMR methodology
- Exam preparation
- Review of key points covered throughout the training
- Detailed presentation of the exam (structure, format, and topics)
- Tips and strategies for success (methodology, time management, etc.)
Audience
This training is intended for the following audiences:
- Managers and team members involved in information security, compliance, and risk management
- Individuals involved in the implementation and compliance of the ISO/IEC 27001 standard within an organization
- Any IT or data protection professional or consultant
Prerequisites
Attending this training requires the following prerequisite:
- A good knowledge of the ISO/IEC 27005 standard as well as methods for assessing information security risks.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
- Practical exercises based on real case studies with 350 pages of documentation
- 21 CPD credits
- PECB certification exam included in the training fee
- Free retake within 12 months in case of failure
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en