ISO/IEC 27005 Lead Risk Manager: information security risk management
Cybersecurity priorities must be explainable in terms of business risks. Use ISO/IEC 27005 to structure your information security risk approach. Connect its principles with responsibilities and operational choices to coordinate actions and justify priorities more effectively.
- Duration
- 4.5 days 31 hours
- Code
- ISO27005LRM Code
- Certification
- PECB ISO/IEC 27005 Certification — Information Security Risk Management Certification
Accredited training for the PECB ISO/IEC 27005 Certification — Information Security Risk Management certification.
Presentation
Understanding and managing information systems security risks is essential for business operations. Even a minor incident can have critical consequences. Training in the ISO/IEC 27005:2022 standard is therefore important for becoming a certified risk manager.
ISO 27005 Lead Risk Manager training develops the skills to support organisations in implementing, managing and improving an information security risk management programme. You will also explore risk management approaches including OCTAVE, EBIOS, MEHARI, CRAMM and NIST.
By the end of this 5-day programme, you can take the PECB ISO/IEC 27005:2022 Lead Risk Manager exam. Passing it enables you to apply for one of 3 associated credentials according to your experience (see the Certification tab).
Important: you will receive a pre-course assessment questionnaire to verify the required foundational knowledge and experience.
Objectives
By the end of ISO 27005 Lead Risk Manager training, you will be able to:
- describe risk management concepts and principles based on ISO/IEC 27005 and ISO 31000;
- apply, maintain and improve an information security risk management framework based on ISO/IEC 27005:2022;
- implement information security risk management processes based on ISO/IEC 27005:2022;
- plan and conduct consultation for risk communication;
- monitor, adapt and improve the risk management framework and process using risk management activity results;
- pass the PECB ISO/IEC 27005:2022 Lead Risk Manager exam and earn one of the 3 associated certifications.
Program
Please note: official PECB ISO 27005 Lead Risk Manager course materials are available in French and English.
Day 1: introduction to ISO/IEC 27005 and risk management
- Applicable standards and regulations.
- Information security risk management fundamentals.
- Establishing an information security risk management programme.
- Defining the context.
Day 2: manage risk according to ISO/IEC 27005:2022
- Risk identification.
- Risk analysis.
- Risk evaluation.
- Risk treatment.
Day 3: risk communication, analysis and reporting
- Communication during information security risk consultation.
- Risk recording and reporting.
- Risk monitoring and review.
Day 4: introduction to risk assessment methods
- OCTAVE and MEHARI.
- EBIOS.
- The NIST Cybersecurity Framework.
- CRAMM and TRA.
Day 5: prepare for the PECB ISO 27005 Lead Risk Manager exam
- Review of key points covered throughout the course.
- Detailed introduction to exam structure, format and topics.
- Advice and tips for exam success, including approach and time management.
Audience
This course is intended for:
- managers and team members involved in information security, compliance and risk management;
- people involved in implementing and ensuring compliance with ISO/IEC 27001:2013;
- IT and personal data protection professionals and consultants.
Prerequisites
The following prerequisites apply:
- 5 years of professional risk management experience, including 300 hours in IT risk management;
- sound knowledge of ISO/IEC 27005 and information security risk assessment methods.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
- Case study
Course highlights
Practical exercises based on real cases with 450 pages of documentation; 31 CPD credits; PECB certification exam included in the course fee; if unsuccessful, retake it free within 12 months.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
fr
en