ISO/IEC 27005 Security Risk Manager + EBIOS: Assessing and Treating Information Security Risks
Assessing and treating information security risks using NF ISO 27005 (ISO/IEC 27005 - Security Risk Manager)
Your cybersecurity priorities need to be explained in terms of business risks. Use ISO/IEC 27005 to structure your information security risk approach. Connect the framework’s principles to responsibilities and operational choices to coordinate actions more effectively and substantiate priorities.
- Duration
- 5 days 35 hours
- Code
- ISO27005SRME-RS Code
- CPF
- CPF eligible CPF
Presentation
Mastering information systems risk management is crucial to business security and effective operation. Our combined ISO/IEC 27005 Security Risk Manager and EBIOS course provides an in-depth understanding of IT risk management standards and best practices.
You will learn to master the processes and assets essential to information security in accordance with ISO/IEC 27005:2022 and explore recognised methods such as OCTAVE, MEHARI and EBIOS. Developed by ANSSI, EBIOS stands out for its collaborative approach, using realistic threat scenarios for precise risk analysis and effective mitigation strategies.
You will develop complementary risk analysis and management skills essential to designing and implementing a robust information security management system aligned with international standards. This course strengthens your professional expertise, preparing you to navigate the complex information security landscape and address current and future challenges.
Through practical exercises and case studies, the program prepares you for the ISO/IEC 27005 Risk Manager certification examination. Passing it demonstrates your professional ability to establish an information systems risk analysis approach for an organisation using ISO 27005 and the EBIOS method.
Objectives
Learning objectives:
- Identify sensitive and strategic business processes and their associated information systems using a SWOT analysis.
- Define the scope of the risk analysis.
- Develop failure or attack scenarios and prioritise them by criticality.
- Develop risk treatment plans.
- Support the company in implementing the treatment plan.
- Foster an information systems risk management culture.
- Understand the principles and fundamentals of the EBIOS method.
- Develop the skills to conduct a complete EBIOS study and analyse, report and communicate its results effectively.
Program
Round-table introductions:
- Individual participant introductions.
- Exploring each participant’s expectations and objectives.
- Introduction to the training framework.
- Alignment with the specific objectives and challenges of ISO 27005 training.
- Identifying participants’ individual expectations and perspectives.
Part 1: introduction to risk management and ISO 27005
- Understanding and defining risk:
- fundamental definitions of risk and the distinction between risk, threat and vulnerability.
- Understanding ISO/IEC 27005:2022:
- exploring the specific features of the latest version of the standard and its role in information security risk management.
- Identifying sensitive business processes:
- techniques for identifying strategic processes and their associated information systems, using SWOT analysis to align risk treatment decisions with business strategy.
- Establishing a risk management program: steps to develop an ISO 27005-aligned risk management program, including responsibilities and the decision-making process.
Part 2: implementing a risk management process in accordance with ISO 27005
- Defining the scope:
- methods for synthesising information from collaborative working groups and documentation to clearly define the risk analysis scope.
- Developing and prioritising risk scenarios:
- creating failure or attack scenarios based on criticality, working with experts to assess their likelihood and impact.
- Analysing and evaluating risks:
- qualitative and quantitative risk analysis techniques.
- Developing risk treatment plans: creating risk management plans that integrate scenario analysis to propose solutions aligned with the company’s strategic objectives.
Part 3: monitoring and risk management culture
- Implementing the treatment plan:
- strategies for effective implementation of risk treatment plans, including monitoring indicators and lessons learned to assess the effectiveness of actions over time.
- Fostering a risk management culture:
- techniques to encourage information security incident reporting and analysis, strengthening the organisation’s risk management culture.
Part 4: risk analysis using EBIOS
- Introduction.
- Introducing the concept of risk.
- The 5 stages of the EBIOS method.
- Practical application in small groups of 2 to 3 people using a predefined case:
- Essential elements.
Part 5: applying the EBIOS method
- Using the method’s results to inform:
- the SoA (Statement of Applicability).
- the security policy (ISO 27001 requirements).
- the security action plan (ISMS).
- Conducting a risk analysis.
- Expressing needs.
- Vulnerabilities.
Part 6: concluding an EBIOS risk analysis
- Practical application in small groups of 2 to 3 people using a predefined case;
- Risk analysis.
- Security objectives.
- Risk coverage.
Part 7: other methodologies and certification preparation
- Introducing risk assessment methods: exploring OCTAVE, MEHARI and EMR and discussing their integration into the company’s risk management strategy.
- Preparing for the ISO 27005 Security Risk Manager certification examination:
- reviewing key concepts, examination practice and strategies for certification success.
Audience
This course is intended for:
- managers or consultants involved in or responsible for information security within an organisation;
- people responsible for information security risk management;
- information security team members, IT professionals and privacy officers;
- people responsible for maintaining organisational compliance with ISO/IEC 27005 information security requirements;
- project managers, consultants and expert advisers seeking to master information security risk management.
Prerequisites
This course requires:
- a sound understanding of organisational information systems and information security risk assessment methods.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Practical exercises
- Case study
Course highlights
Internationally recognised certification. Practical work based on real cases with 350 pages of documentation; the certification examination is included in the course fee.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en