Perform a search on the site.

Your currency
Certification
incluse
Certification is included in the price
CPF
mon compte formation
This course is eligible for the CPF
Formateurs
certifiés
Formation dispensée par un formateur spécialisé
Take2
Free exam retake in case of failure

ISO/IEC 27005 Security Risk Manager + EBIOS: Assessing and Treating Information Security Risks

Assessing and treating information security risks using NF ISO 27005 (ISO/IEC 27005 - Security Risk Manager)

Your cybersecurity priorities need to be explained in terms of business risks. Use ISO/IEC 27005 to structure your information security risk approach. Connect the framework’s principles to responsibilities and operational choices to coordinate actions more effectively and substantiate priorities.

Duration
5 days 35 hours
Code
ISO27005SRME-RS Code
CPF
CPF eligible CPF

Use your CPF entitlement to fund this course

This course is eligible for funding through the French Compte Personnel de Formation (CPF).

Presentation

Mastering information systems risk management is crucial to business security and effective operation. Our combined ISO/IEC 27005 Security Risk Manager and EBIOS course provides an in-depth understanding of IT risk management standards and best practices.

You will learn to master the processes and assets essential to information security in accordance with ISO/IEC 27005:2022 and explore recognised methods such as OCTAVE, MEHARI and EBIOS. Developed by ANSSI, EBIOS stands out for its collaborative approach, using realistic threat scenarios for precise risk analysis and effective mitigation strategies.

You will develop complementary risk analysis and management skills essential to designing and implementing a robust information security management system aligned with international standards. This course strengthens your professional expertise, preparing you to navigate the complex information security landscape and address current and future challenges.

Through practical exercises and case studies, the program prepares you for the ISO/IEC 27005 Risk Manager certification examination. Passing it demonstrates your professional ability to establish an information systems risk analysis approach for an organisation using ISO 27005 and the EBIOS method.

Objectives

Learning objectives:

  • Identify sensitive and strategic business processes and their associated information systems using a SWOT analysis.
  • Define the scope of the risk analysis.
  • Develop failure or attack scenarios and prioritise them by criticality.
  • Develop risk treatment plans.
  • Support the company in implementing the treatment plan.
  • Foster an information systems risk management culture.
  • Understand the principles and fundamentals of the EBIOS method.
  • Develop the skills to conduct a complete EBIOS study and analyse, report and communicate its results effectively.
Last update: 24/09/2026